XT.PT The CLI → This story
Filed

Updated 07:17
Reporting
Prelo
Verified by Roger Morais
4 min · 747 words
News The CLI

Agents as code, and the file that remembers which ones are yours

The interesting part is not the YAML but the lockfile, and the three ways the command refuses to run.

Filed09 Sep 2026, 09:00 UTC Length4 min · 747 words ReportingPrelo
Claude Code prompt

Anthropic's Claude Platform release notes for September 3 carry one entry, and it is a shape developers will recognize from Terraform: "Version 1.30.0 of the ant CLI adds ant apply, which creates and updates agents, environments, skills, memory stores, and deployments from files in your repository. Describe each resource in a file, run ant apply, and approve the plan it prints. Commit the claude-lock.json lockfile it writes so that later runs, on your machine or in CI, update the same resources instead of creating new ones."

The documentation page is where the behavior lives, and it is more specific than the announcement.

The plan is the product

A resource is a file whose contents are "the request body you would send to that kind's create endpoint." Agents and deployments are Markdown with YAML frontmatter, where "the frontmatter holds the agent's configuration ... and the body is its system prompt." Environments and memory stores are YAML. A skill is a directory with a SKILL.md at its root, uploaded as one bundle.

Files point at each other by relative path rather than ID: "Wherever the API expects another resource's ID, write the relative path to that resource's file instead." The command "creates them in dependency order and fills in the real IDs," and pins agent and skill references "to the version it just applied," so editing a reviewer agent updates the coordinator that lists it in the same run.

In a terminal the command prints a plan and waits. Answer d for a field-by-field diff; --dry-run prints the same and exits without touching anything.

What the lockfile records

The first run writes claude-lock.json in the current directory. Per resource it stores the kind, the ID, the version, and two hashes:

"./agents/summarizer.md": {
  "kind": "agent",
  "id": "agent_011CYm1BLqPXpQRk5khsSXrs",
  "version": "1",
  "hash": "d23251c8d99b3613a64f3f8d87f5fad4",
  "remote_hash": "1b771bee5bdbf600a5ad972fdac32d94"
}

"The two hashes fingerprint what was last sent and what the API returned. That's how a later run notices an edited file, or a resource changed outside these files." The lockfile also records the organization and workspace, and that is enforced, not advisory: "ant apply refuses credentials that resolve to any other organization or workspace."

Three refusals

The documentation is unusually clear about failure modes, which is what makes the tool worth trusting.

  • Drift. If a resource "was edited, archived, or deleted outside these files (in the Claude Console, for example), the plan ends with This plan cannot be applied: and the reason. The command then exits with refusing to apply." Only --force overrides it.
  • No adoption. "ant apply can't adopt a resource you created in the Console or with ant beta:agents create. Only what's in the lockfile is managed, and applying a file that describes an existing agent creates a second one." The escape hatch is the Console's Export as code, whose download "includes its own claude-lock.json."
  • No terminal. Without one, the command "prints the plan and stops with cannot ask for confirmation without a terminal; re-run with --yes to apply, or --dry-run to see the plan only."

Deleting a file does not delete the resource; it "leaves its resource in place with a warning, and --prune removes it." Renaming a file "therefore declares a new resource and leaves the old one in place until you prune."

The CI trap in Anthropic's own example

The page's CI guidance says to name the directory: "Run ant apply --yes . on your default branch after merge, naming the project directory. A bare ant apply --yes reconciles only files the lockfile already tracks and skips a newly added one." It also says to commit the lockfile "even when the apply step failed partway, because a partial apply still records what it created," and to "Run one apply at a time, because nothing locks the lockfile."

The GitHub Actions workflow in the CLI README, which the docs page links as the complete example, runs the bare form:

      - name: Apply
        run: ant apply --yes

Read together with the docs, that workflow will apply edits to agents it already knows and silently skip a new file added in the same merge. The README's comment on its concurrency: ant-apply line does match the docs: "apply does not guard against concurrent runs itself." The README also authenticates with an OIDC token minted from GitHub rather than a stored key, which is the docs' recommendation as well.

Primary sources: Claude Platform release notes, September 3, 2026, Manage resources as code with ant apply, anthropic-cli README, read 2026-09-08.

Corrections and source documents: contact the desk
Read next →
Read next
Pricing · 4 min

GPT-6 Sol costs what GPT-5.6 Terra did, and exactly what Claude Sonnet 5.5 does

The API · 4 min

Claude Sonnet 5.5 makes thinking: disabled a 400, one of five breaking changes