# DEVX-181: Emit runner resource leases for CI molecule jobs (S08 producer side) ## Problem GRM-173 (S08) shipped consumer-side runner leases: `runner-cleanup.sh` honors `org.oblachno.lease-until` / `org.oblachno.owner` labels on containers, volumes, and networks. But no CI producer emits them: molecule containers/networks created on the runner's host rootless Docker socket carry only `owner=molecule`, so a pressure/critical cleanup can still wipe a molecule object that is stopped for a moment mid-run. Docker labels cannot be added post-creation — producers must emit them at create time. ## Approach REQ-1: New `devx.molecule.lease` module computing `MOLECULE_LEASE_UNTIL` (epoch = now + TTL, default 4h) and `MOLECULE_OWNER` (`run--` from GITEA_*/GITHUB_* env, else `local-`), with `emit_github_env()` appending them to `$GITHUB_ENV` and a Click CLI printing `KEY=value` lines. REQ-2: `start_docker.main()` emits the lease env after a successful Docker start — every molecule CI job already calls it, so no workflow edits are needed. REQ-3: Consumers (infra/grm `molecule.yml`) add platform labels `org.oblachno.lease-until: "${MOLECULE_LEASE_UNTIL:-0}"` and `org.oblachno.owner: "${MOLECULE_OWNER:-molecule-local}"` — `0` is already expired, so local/unset runs keep today's unleased behavior. Downstream changes land in the infra and grm repos. ## Test Plan - `tests/unit/test_molecule_lease.py` covers `lease_owner` env precedence and fallbacks, `lease_env` arithmetic, `emit_github_env` write/no-op, and the CLI — 100% coverage enforced by `make pytest-cov`. - Existing `test_start_docker.py` still green (emission is additive). ## Deploy Plan - Merge via auto-merge → post-merge releases and publishes devx; infra and grm pin bumps consume it via their molecule.yml label additions. ## Rollback Plan - Revert the merge; `start_docker` stops exporting the vars and molecule interpolation falls back to expired leases (`:-0`). ## Acceptance Criteria - [x] REQ-1: `devx.molecule.lease` computes both env vars and writes them to `$GITHUB_ENV` when set. - [x] REQ-2: `start_docker` exports lease env on success without changing its existing behavior contract. - [x] REQ-3: the label contract (`org.oblachno.lease-until`, `org.oblachno.owner`) is exposed as module constants for consumers.