Skip to content

cua

Recipe card from the charly-check plugin (Commands — runtime CLI verbs).

Cua — computer-use driver control from a cua: check verb

Section titled “Cua — computer-use driver control from a cua: check verb”

cua: is a DECLARATIVE check/control verb — authored as cua: <method> inside a candy/box plan check:/run: step. It is NOT a host charly check subcommand: the verb’s implementation lives in the out-of-tree candy/plugin-cua module, and at check time the host dispatches cua: through the provider registry to that out-of-process plugin (the same path jetkvm: / wl: / record: take).

It drives a LIVE desktop through Cua Driver (trycua/cua) — the background computer-use driver that exposes its tools over MCP-over-stdio and a CLI (cua-driver call <tool> '<json>'). The plugin uses the CLI (one process per call, no long-lived client state) and routes every call through the venue’s executor reverse channel, so the driver is driven WHERE IT LIVES (a desktop VM/pod), never on the host running charly.

The method name is the scalar value for a bare-method step (cua: status), or the method: key of the cua: map when the step carries cua-exclusive fields — those live INSIDE the cua: map. Only the shared matchers (stdout:, stderr:, exit_status:) and context:/id:/timeout: stay siblings. All cua: steps are deploy-context only.

READ-ONLY BY DEFAULT — the desktop-safety gate

Section titled “READ-ONLY BY DEFAULT — the desktop-safety gate”

A live desktop is not a throwaway. Every MUTATING method (input, app/window control, recording, the raw call escape hatch) requires allow_control: true; without it the step reports a documented skip naming the gate rather than acting. The classification is an allowlist, so a method added later is read-only by default. Cua Driver’s own permission mode (standard / bounded / unrestricted), declared on the kind: cua entity, remains the authority the plugin passes through.

Read-only: status, doctor, version, list-tools, list-apps, list-windows, get-window-state, get-desktop-state, get-screen-size, screenshot.

Mutating (need allow_control: true): click, double-click, right-click, drag, type, press-key, hotkey, scroll, move-cursor, launch-app, kill-app, bring-to-front, set-window-frame, set-value, recording-start, recording-stop, recording-status, recording-render, call.

delivery: foreground escalates an input action to Cua’s foreground route; the default is background, and a structured refusal (background_unavailable) is never a silent success.

A Cua Fleet image is a KubeVirt containerDisk: an OCI image whose layer holds a bootable guest disk (by default at /disk/disk.img). charly pulls and boots it locally with the container_disk VM source — no KubeVirt required:

omarchy-cua:
vm:
source:
kind: container_disk
image: public.ecr.aws/k5j5w0x5/cua-omarchy-workspace@sha256:…
distro: omarchy