Skip to content
Proposals/Switch Crush config to .crushrc with sourced hos
proposaldeveloperP5High impactCCrush

Switch Crush config to .crushrc with sourced host overrides

Crush v0.88.0 adds .crushrc (JSON still works). Put shared providers, models, permissions, and MCPs in crushrc, source a gitignored file for machine-specific overrides, and use the new Bedrock SSO re-auth plus permissions deny so agents stay reliable and scoped.

Why this loop

v0.88.0 starts the migration from JSON to a more flexible .crushrc, with a local .crushrc override, crush.sh discovery, and verb-first builtins (provider/model/mcp/lsp/hook add/remove, permissions allow/deny, option reset). Existing JSON still loads; Crush only warns when JSON and crushrc keys actually conflict. The documented pattern—source a separate file from a dotfiles-managed crushrc and gitignore that file—lets teams share config while keeping HOSTNAME checks, skill-path, and tokens off-repo. Permissions deny now hides tools from the agent. AWS Bedrock SSO gets a real auth UX and automatic turn retry after token refresh, so long sessions no longer die silently. Anthropic security refusals and DuckDuckGo rate limits now surface in the TUI instead of empty/stop behavior. MCP OAuth loading and header handling were fixed, so crushrc mcp add with Authorization headers is the right way to attach servers. Do not invent the 31 omitted commits; start from the published crushrc docs and the builtins shown in the release.

Proposed actions

  1. Create a shared crushrc (global crush.sh or repo .crushrc) using verb-first builtins from https://github.com/charmbracelet/crush/tree/main/docs/config, e.g. provider add ollama --type ollama --base-url "http://localhost:11434/v1" then model add ollama/llama3.3 --name "Llama 3.3" --context-window 128000
  2. Add source "$XDG_CONFIG_HOME/crush-local.sh" to crushrc, put that file in .gitignore, and inside it gate host-only settings (if [[ $HOSTNAME == "your-machine" ]]; then option skill-path "$HOME/your-skills"; fi) so dotfiles stay shareable
  3. Replace JSON permission lists with crushrc lines: permissions allow view edit and permissions deny <tool> to hide tools from the agent; use option reset when you need to wipe a list option
  4. Declare MCPs in crushrc instead of ad-hoc JSON, e.g. mcp add github --type http --url "https://api.githubcopilot.com/mcp/" --header Authorization "Bearer $GITHUB_TOKEN", then complete Crush's OAuth browser flow when a server requires it
  5. For AWS Bedrock SSO, complete Crush's in-app auth when tokens expire (see #2886); leave the session running so the turn retries automatically after re-auth instead of restarting the agent

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

AGENTS.md / CLAUDE.md / GEMINI.md rule update

DevAgentRadar → Repo Harness Rule Patch

Goal: update our repository's permanent harness instructions based on this release.

Update the file that tool actually reads. Do not dump everything into one file.

  • Claude Code → CLAUDE.md plus .claude/ (skills, hooks, settings, agents, commands). It does not read AGENTS.md natively; start CLAUDE.md with @AGENTS.md.
  • Codex, Copilot, Cursor, Factory Droid, Grok Build, Roo Code, Goose, OpenCode, Amp, Zed, Aider → AGENTS.md.
  • Gemini CLI / Antigravity → GEMINI.md. AGENTS.md only if context.fileName is set.
  • Cursor glob-scoped rules → .cursor/rules/*.mdc (plain .md is ignored), not a second constitution.
  • Codex MCP → .codex/config.toml, not .mcp.json.
  • Copilot extra instructions → .github/copilot-instructions.md; custom agents → .github/agents/.
  • Windsurf → .windsurf/rules (do not assume AGENTS.md).
  • Cline → .clinerules.
  • Procedures → a skill (SKILL.md). Enforcement the model must not skip → a hook. Isolated roles → subagents.
  • Do not fork the same rule into three tool files.

Context

Assistant: Crush Proposal: Switch Crush config to .crushrc with sourced host overrides Summary: Crush v0.88.0 adds .crushrc (JSON still works). Put shared providers, models, permissions, and MCPs in crushrc, source a gitignored file for machine-specific overrides, and use the new Bedrock SSO re-auth plus permissions deny so agents stay reliable and scoped. Primary source: https://github.com/charmbracelet/crush/releases/tag/v0.88.0

Why it matters

v0.88.0 starts the migration from JSON to a more flexible .crushrc, with a local .crushrc override, crush.sh discovery, and verb-first builtins (provider/model/mcp/lsp/hook add/remove, permissions allow/deny, option reset). Existing JSON still loads; Crush only warns when JSON and crushrc keys actually conflict. The documented pattern—source a separate file from a dotfiles-managed crushrc and gitignore that file—lets teams share config while keeping HOSTNAME checks, skill-path, and tokens off-repo. Permissions deny now hides tools from the agent. AWS Bedrock SSO gets a real auth UX and automatic turn retry after token refresh, so long sessions no longer die silently. Anthropic security refusals and DuckDuckGo rate limits now surface in the TUI instead of empty/stop behavior. MCP OAuth loading and header handling were fixed, so crushrc mcp add with Authorization headers is the right way to attach servers. Do not invent the 31 omitted commits; start from the published crushrc docs and the builtins shown in the release.

Suggested actions

  1. Create a shared crushrc (global crush.sh or repo .crushrc) using verb-first builtins from https://github.com/charmbracelet/crush/tree/main/docs/config, e.g. provider add ollama --type ollama --base-url "http://localhost:11434/v1" then model add ollama/llama3.3 --name "Llama 3.3" --context-window 128000
  2. Add source "$XDG_CONFIG_HOME/crush-local.sh" to crushrc, put that file in .gitignore, and inside it gate host-only settings (if [[ $HOSTNAME == "your-machine" ]]; then option skill-path "$HOME/your-skills"; fi) so dotfiles stay shareable
  3. Replace JSON permission lists with crushrc lines: permissions allow view edit and permissions deny <tool> to hide tools from the agent; use option reset when you need to wipe a list option
  4. Declare MCPs in crushrc instead of ad-hoc JSON, e.g. mcp add github --type http --url "https://api.githubcopilot.com/mcp/" --header Authorization "Bearer $GITHUB_TOKEN", then complete Crush's OAuth browser flow when a server requires it
  5. For AWS Bedrock SSO, complete Crush's in-app auth when tokens expire (see #2886); leave the session running so the turn retries automatically after re-auth instead of restarting the agent

Config surfaces this release may change

  • MCP servers — check your repo before applying
  • skills — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/crush-v0-88-0-switch-crush-config-to-crushrc-with-sourced-host-overrides and mark Applied, Skipped, or Failed. Proposal id: bafb4d45-e123-4ea7-a16a-c0e167232797

Instructions:

  1. Read the existing context files and settings for the tools in this repo.
  2. Draft an explicit Git diff. Update ONLY agent harness rules or tool configuration.
  3. Call out deprecated flags, obsolete habits, or changed permission boundaries.
  4. Do not touch application logic.

Start with the proposed diff and say which layer and which tool's file it belongs in.

agentmcpmodelpricingsecurityRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

CCrushv0.88.0Jul 31, 2026

v0.88.0

Hey! Hope everybody had a great week. · We were pretty productive at Charm and we're releasing some cool stuff today. · Yep, .crushrc has come! You existing JSON config still works, but we just started migrating to something a lot more flexible! · An example on why this is cool: if you manage Crush config in a dotfiles repo, you can still have machine-specific overrides by using source to call a separate file that will be in your .gitignore. · I'm sure there are many other use cases. · +110 more changes
Verified excerpt — the source's own words

.crushrc is here!

Hey! Hope everybody had a great week. We were pretty productive at Charm and we're releasing some cool stuff today.

Bash configuration! (.crushrc)

Yep, .crushrc has come! You existing JSON config still works, but we just started migrating to something a lot more flexible!

An example on why this is cool: if you manage Crush config in a dotfiles repo, you can still have machine-specific overrides by using source to call a separate file that will be in your .gitignore. I'm sure there are many other use cases.

To read the full documentation on this, read this document.

See a snipped so you have an idea on how it looks:


# Add Ollama.

provider add ollama --type ollama --base-url "http://localhost:11434/v1"

# Register a model on Ollama.

model add ollama/llama3.3 --name "Llama 3.3" --context-window 128000

# Auto-approve some tools.

permissions allow view edit

# Add an MCP server

mcp add github \
  --type http \
  --url "https://api.githubcopilot.com/mcp/" \
  --header Authorization "Bearer $GITHUB_TOKEN"

# Load some extra config

source "$XDG_CONFIG_HOME/squid-config.sh"

Excerpt ends here — this release continues at the source ↗.

Primary source ↗