openagentprimitives

module
v0.0.0-...-2769864 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0

README

Open Agent Primitives

A secure way to run enterprise AI agents.

OAP is a set of building blocks for constructing and running enterprise agents. A primitive is a concern every agent has to solve, whatever it does. OAP names six:

  • Agent definition
  • Safe tools
  • Identity & credentials
  • Authorization
  • Channels & continuity
  • Memory & knowledge

Each ships with a working implementation, and every agent is composed from them. OAP runs in your own Kubernetes cluster, on the models and infrastructure you choose.

An enterprise agent holds production credentials and does work the business depends on. Trusting it with that work means answering four questions: what it can reach, who granted that access, what happens when a tool result tells it to do something else, and what is exposed if one component is compromised. OAP is designed for those concerns.

The problem this solves

A credential is the unit of access, and it is usually broader than the task. A token that reaches one git repository normally reaches every repository, and an integration built to expose a service exposes all of it. An agent inherits that whole surface, and the distance between what a task needs and what its credentials permit grows as agents take on more work, because that is when they hold production credentials, touch production systems, and read content that carries instructions.

A model cannot deterministically separate instructions from data, so its judgment is not a dependable place to enforce a boundary. Hardening the prompt does not change that, because a prompt is an instruction rather than an enforcement point. A permission check at the edge, deciding who may start an agent, does not constrain what that agent reaches once it is running across data with many different owners.

Every control in OAP therefore sits outside the model. The platform decides before the call, and the decision does not depend on the agent's cooperation.

Typical agent platform OAP
What an agent can reach Whatever its credentials allow Exactly what you granted
Who decides an action is allowed The model, in the moment The platform, before the call
An injected instruction mid-session Can redirect the agent Cannot widen what it's authorized to do
Tool credentials Shared across tools in one sandbox Held only by the tool that uses them
Restricting an MCP server Needs a narrow upstream token Declared by you, enforced per call
Revoking access Rotate credentials, redeploy One permission graph call
The audit log Append-only, enforced by the store Signed, chained, verifiable offline

What makes it secure

Twenty-seven controls, grouped into six areas. Each area below links into the security model, which documents every control and names the package that implements it.

1. Every action is authorized

Authorization is evaluated per action against a relationship graph that mirrors ownership in your organization: who owns an account, who is on which team, who shared what. Relationships can be written from source systems as the agent runs, so a decision reflects the current state of those systems rather than a cached copy. A failed check can become an approval request routed to whoever holds authority over the resource.

  • What is checked. Tool calls, interactions, memory access, lookups, and preferences all go through the graph.
  • Operation-level rules. One agent can be read-only for one team and read-write for another, instead of building a separate agent per audience.
  • Directory sync. Group memberships from Slack, GitHub, and 1Password sync into SpiceDB, so permissions follow your organization automatically.
  • Four identity modes. An agent acts as itself or as the session's user, and that choice can instead be made by the user when the session opens, with or without a recommendation to confirm. Per-user credentials are held by the platform.
  • Multiplayer sessions. Joining a session, directing it, and running sensitive tools can each require approval.
2. Injected instructions cannot widen what an agent may do

Rather than relying on the model to recognize an injected instruction, OAP places the decision outside the model.

  • Plan gating. The agent states what it intends, a person approves that scope, and every later action is checked against the approved plan. Injected text can change what the model wants to do. It cannot change what the model is allowed to do.
  • Slots. A session commits to the specific resource it is working on, as a relationship that can be written only once. It cannot drift to another resource even when its credentials would reach one.
  • Approvals the model cannot reword. The platform generates the description of the action from the call itself. The model contributes only its reasoning, so it cannot restate the action in different terms.
  • Tool specs. Declare which operations and which resources an MCP server or CLI exposes to an agent, enforced in code at call time. A read-write integration becomes read-only without needing a read-only token.
3. Data reaches only its authorized audience
  • Leakage tracking. Tool responses are tagged with their origin and the tags travel with the data, so the platform can check where data came from against who will receive it before anything leaves.
  • Slot-scoped memory. Sessions share memory only when bound to the same resource, so one customer's context does not reach another customer's sessions. Nothing is shared by default.
  • Secret scrubbing. Mark a tool output as a secret and the model receives an opaque handle. The platform substitutes the real value outside the model.
4. Least privilege by default
  • Opt-in capabilities. Every toolkit, tool spec, and capability an agent has is one someone added deliberately, so a review covers what was added rather than what was left enabled.
  • A sandbox per tool. Each tool holds only its own credentials, so a compromised tool cannot borrow another's access. The orchestrating agent never holds them at all.
  • Sub-agents request their own permissions. Delegation narrows access instead of copying it.
  • Sidecar toolboxes. Run arbitrary code as an MCP server in its own sandbox, started and stopped with the session.
5. Control and oversight

Administrators set requirements and defaults at the cluster, namespace, or agent-class level, and agents inherit them without being able to opt out. Revocation works by removing a relationship, so it takes effect everywhere at once with no credential rotation or redeploy. The audit log is append-only, and each entry is signed and hash-chained, so modification, reordering, and truncation are detectable; oap audit verify checks a session's chains offline. Skills, containers, and MCP servers can be pinned to approved versions. Budgets cap turns, spend, and run time. Pre- and post-call hooks enforce your own policies and can trip a circuit breaker.

6. Isolation in the platform itself

Each content type passes through a sanitizer written for that type's risks, and rendered output is contained under a Content Security Policy without cookie access. The session runner, the operator, and each sanitizer run in separate pods, with micro-VM backing where the cluster provides it. Components dial the control-plane bus with individually minted credentials that grant only their own session's subjects. Each agent ships as one OCI-compliant package, so installation can be gated and reviewed like any other artifact.

Everything else

The capabilities below are common to agent platforms. OAP includes them; they are listed here so the set is complete.

  • You choose the model. Anthropic, OpenAI, or OpenRouter, swappable per deployment.
  • You choose the infrastructure. A laptop, a local cluster, or your own Kubernetes: GKE, EKS, AKS, or self-managed.
  • Channels. Slack, browser, CLI, GitHub, or a signed webhook trigger.
  • Memory and knowledge graph. Structured recall, ranked search, and graph-native queries over what an agent has learned.
  • Built in and swappable. The runner, authorization, approvals, sandboxing, credential handling, memory, and audit all ship built in, and every one can be swapped for something your organization already runs without rebuilding the platform around it.

Quick start

1. Run it locally

Pick the path that fits where you want to run OAP.

Desktop (macOS, Apple Silicon) is the fastest way to a working local OAP. It runs the whole project in a lightweight Linux VM, reachable only from your Mac, with a menubar app for chats, sessions, the admin dashboard, and agent installation. No Kubernetes to set up yourself.

mage desktop:all
open build/desktop/out/oap.app

On first launch, pick a model provider, enter its API key, and set a local admin password. OAP provisions the VM, configures the platform, and installs a demo agent.

Desktop is single-player: good for trying OAP and for developing and demoing agents. Use Kubernetes for anything durable or shared.

Local Kubernetes installs onto a kind cluster for development:

mage build:oap
kind create cluster --name oap-dev
./bin/oap init --local --pinning-mode=warn --wizard

oap init builds and loads images, installs OAP, waits for the platform to come up healthy, and walks you through security settings and model configuration.

2. Install your first agent

Install the pirate example. Its captain installs the vampire translator as a private dependency automatically, with no separate manifest apply and no extra credential to hand it:

./bin/oap agent install examples/pirate-subagent/pirate-captain
./bin/oap agent chat pirate-captain

oap agent install validates and installs the whole agent graph as one unit: definitions, dependency, configuration, and install-time questions. Then oap agent chat opens an interactive terminal conversation with the captain. Ask for both a pirate and a vampire response to see it delegate to the private child agent.

3. Pick a model provider

OAP supports Anthropic, OpenAI, and OpenRouter. Set the default during oap init --wizard, or change it later through agent settings. Nothing about an agent's definition hardcodes a provider.

4. Move to a shared or managed cluster

OAP installs into an existing shared or managed Kubernetes cluster the same way it installs locally. These profiles use durable Postgres-backed storage and images from your own registry. You'll need a registry, external routing with two distinct origins, and a durable artifact store (GKE can provision its own bucket; EKS, AKS, and others take an s3://, azblob://, or gs:// URL).

mage build:oap
./bin/oap init --pinning-mode=warn --wizard --hostname-suffix=my.web.hostname

oap init detects GKE, EKS, or AKS from the cluster when it can, and prompts for whatever it can't. Pass --cluster-kind to skip detection, or provide infrastructure choices directly:

./bin/oap init --cluster-kind=eks \
  --image-registry=<your-registry> \
  --artifact-store-url=s3://your-oap-bucket \
  --pinning-mode=warn --wizard \
  --hostname-suffix=my.web.hostname

See the full deployment guide for OIDC, existing TLS issuers, private routing, cloud-specific storage, and air-gapped registries.

5. Bring your team in

Agents run wherever your team already works: Slack, the browser, the CLI, GitHub, or triggered by a signed webhook from another system. Connect a channel with its own interactive wizard:

./bin/oap channel create --kind slack

oap agent install walks the same wizard automatically for any channel a bundle declares, so installing an agent can connect its channel in one step. Once it's connected:

./bin/oap channel list          # what's wired up
./bin/oap channel test <name>   # confirm it can still reach the channel
./bin/oap channel show <name>   # inspect one channel's config and status

Approval requests land in that same surface, a Slack thread or the browser session, wherever the conversation already is, so nobody has to leave it to grant or deny an action.

6. Turn on the controls

The security model above is configurable. Cluster-wide defaults (circuit breakers, rate limits, data-volume budgets, dependency pinning, prompt-injection detection, URL allow-listing) are set with their own wizard:

./bin/oap settings wizard             # interactive; --defaults for a secure baseline, --dry-run to preview

Dependencies (MCP servers, sidecar toolboxes, skills, toolkits) are pinned to a known-good identity, and drift is reported:

./bin/oap pin status                  # every pinned dependency: strength, digest, drift, age
./bin/oap pin diff <kind> <name>      # compare the pinned baseline against what's live
./bin/oap pin update <kind> <name>    # accept a new baseline after you've reviewed it

--pinning-mode (off, warn, approve, or block) sets how strictly oap init and oap install seed the cluster to hold agents and tools to their pinned versions, from not gating at all up to blocking a drifted dependency outright. And because the audit log is signed and hash-chained, not just written, you can check it independently of whoever wrote it:

./bin/oap audit verify <session>      # recompute and verify a session's audit chain offline

Build an agent by talking to an agent

You don't have to start with manifest files. Agent Builder is an OAP agent whose job is to create other agents. Describe what you need in plain language and it identifies tools, connects accounts through the platform, defines what the new agent may do or must ask permission for, builds it, and lets you test it live.

Each build happens in an isolated workshop. The draft can't touch your live agents, and the builder can't install it into the real environment. When you're satisfied, you get a portable .oap bundle and can submit an installation request for an administrator to review.

oap init leaves Agent Builder off by default, because there is no safe default for who's allowed to start it. Enable it after initialization by naming the people or groups allowed to use it:

./bin/oap install --cluster-kind=local \
  --builder-starters user:$(./bin/oap identity canonical-id you@example.com)

Agent Builder is subject to every control in the security model, like any other OAP agent. It has broad freedom inside its temporary workshop and no authority outside it.

Read the docs

The docs are at openap.org/docs. To run them locally instead:

cd site
pnpm install
pnpm dev

Then open http://localhost:5179 for installation guides, Agent Builder walkthroughs, security concepts, operations, and the CLI and CRD reference.

For architecture and implementation:

Defense in depth, enforced by code

To misuse an OAP agent, an attacker has to get past a plan a human approved, a slot that cannot be reopened, a tool lens that cannot be widened, an authorization check on every call, and a sandbox that never held the credential in the first place. None of them is sufficient alone, and each is built on the assumption that the others may fail.

Contributing

See CONTRIBUTING.md to get set up, and CODE-OF-CONDUCT.md for how we work together. OAP is licensed under Apache 2.0, with separately licensed materials listed in third-party notices. Report vulnerabilities through the security policy.

Directories

Path Synopsis
cmd
oap command
Package main is the agent-primitives CLI ("oap").
Package main is the agent-primitives CLI ("oap").
oap/internal/agentcmd
The half of `oap agent install` that acts on the channels a bundle declares (oap.Requires.Channels).
The half of `oap agent install` that acts on the channels a bundle declares (oap.Requires.Channels).
oap/internal/aifix
Package aifix is the pluggable "AI fixer" seam for a stalled `oap install` wait.
Package aifix is the pluggable "AI fixer" seam for a stalled `oap install` wait.
oap/internal/apcmd
Package apcmd holds the pieces every `oap` subcommand family needs: the persistent global flags, the kube-client seam built from them, and the generic cobra command factories the per-resource verbs are built out of.
Package apcmd holds the pieces every `oap` subcommand family needs: the persistent global flags, the kube-client seam built from them, and the generic cobra command factories the per-resource verbs are built out of.
oap/internal/aptest
Package aptest holds the fixtures and measurement helpers the `oap` CLI's tests share across command-family packages: a Globals wired to a fake cluster, a runner that captures everything a command wrote, and the terminal-rendering probes the list/table assertions are built on.
Package aptest holds the fixtures and measurement helpers the `oap` CLI's tests share across command-family packages: a Globals wired to a fake cluster, a runner that captures everything a command wrote, and the terminal-rendering probes the list/table assertions are built on.
oap/internal/artifactcmd
Package artifactcmd implements `oap artifact`: inspecting versioned artifacts, their revision trees, and the raw artifactstore behind them.
Package artifactcmd implements `oap artifact`: inspecting versioned artifacts, their revision trees, and the raw artifactstore behind them.
oap/internal/auditcmd
Package auditcmd implements `oap audit`: offline verification of a session's tamper-evident, append-only memory chains.
Package auditcmd implements `oap audit`: offline verification of a session's tamper-evident, append-only memory chains.
oap/internal/buildx
Package buildx holds the `docker buildx` push plumbing shared by the two build paths: oap's own first-party image targets (cmd/oap/internal/installcmd/build.go) and .oap bundle recipes (cmd/oap/internal/imagebuild).
Package buildx holds the `docker buildx` push plumbing shared by the two build paths: oap's own first-party image targets (cmd/oap/internal/installcmd/build.go) and .oap bundle recipes (cmd/oap/internal/imagebuild).
oap/internal/channelcmd
The CLI dispatcher for `oap channel create`.
The CLI dispatcher for `oap channel create`.
oap/internal/channelwizard
What a wizard run leaves behind: the manifests it produced, applied to the cluster, and the record of the run that stays in the operator's scrollback.
What a wizard run leaves behind: the manifests it produced, applied to the cluster, and the record of the run that stays in the operator's scrollback.
oap/internal/chatcmd
Best-effort agent-UI link minter for `oap agent chat`.
Best-effort agent-UI link minter for `oap agent chat`.
oap/internal/classcmd
Package classcmd implements `oap class`: inspecting SpiceboxClass resources, the sandbox image plus capability descriptor an agent runs against.
Package classcmd implements `oap class`: inspecting SpiceboxClass resources, the sandbox image plus capability descriptor an agent runs against.
oap/internal/cliidentity
Package cliidentity caches the identityd-issued identity assertion for the local user.
Package cliidentity caches the identityd-issued identity assertion for the local user.
oap/internal/clilogin
Package clilogin owns the identity the `oap` CLI acts under: the `oap login` / `oap logout` commands, and EnsureIdentity — the hook every command that needs to name its caller goes through.
Package clilogin owns the identity the `oap` CLI acts under: the `oap login` / `oap logout` commands, and EnsureIdentity — the hook every command that needs to name its caller goes through.
oap/internal/clinats
Package clinats loads the CLI's NATS credentials from the cluster and materializes them as on-disk files for apnats.Connect.
Package clinats loads the CLI's NATS credentials from the cluster and materializes them as on-disk files for apnats.Connect.
oap/internal/cliout
Package cliout centralizes oap's user-facing CLI output: consistent prefixes (so every step/warning reads the same) and optional ANSI color.
Package cliout centralizes oap's user-facing CLI output: consistent prefixes (so every step/warning reads the same) and optional ANSI color.
oap/internal/desktop/demo
Package demo embeds the macOS desktop bundle's demo AgentClass — a no-tools `pirate-private` pirate-speak translator (defined in pirate.yaml) so the built-in web chat's agent selector has something to talk to as soon as bring-up finishes.
Package demo embeds the macOS desktop bundle's demo AgentClass — a no-tools `pirate-private` pirate-speak translator (defined in pirate.yaml) so the built-in web chat's agent selector has something to talk to as soon as bring-up finishes.
oap/internal/desktop/menubaricons
Package menubaricons defines the oap desktop menu-bar status icon states and the animator that drives them.
Package menubaricons defines the oap desktop menu-bar status icon states and the animator that drives them.
oap/internal/desktop/menubaricons/assets
Package assets embeds the pre-rendered menu-bar icon PNG frames produced by `mage desktop:icons`.
Package assets embeds the pre-rendered menu-bar icon PNG frames produced by `mage desktop:icons`.
oap/internal/desktop/menubaricons/gen command
Command gen renders the oap desktop menu-bar icon frames to PNG assets.
Command gen renders the oap desktop menu-bar icon frames to PNG assets.
oap/internal/desktop/menubaricons/render
Package render draws the oap desktop menu-bar icon frames as macOS template PNGs (black shape, coverage in the alpha channel).
Package render draws the oap desktop menu-bar icon frames as macOS template PNGs (black shape, coverage in the alpha channel).
oap/internal/desktop/settingsui
Package settingsui is the desktop settings server: a loopback-only, token-gated HTTP server that hosts the "settings" web UI app and exposes the desktop VM's runtime state over a small JSON/SSE API.
Package settingsui is the desktop settings server: a loopback-only, token-gated HTTP server that hosts the "settings" web UI app and exposes the desktop VM's runtime state over a small JSON/SSE API.
oap/internal/desktop/setupui
Package setupui is the backend for the macOS "oap desktop" setup UI: a live timeline of VM bring-up (see desktop.Engine.Up / EngineHooks.Progress) plus a first-run config form.
Package setupui is the backend for the macOS "oap desktop" setup UI: a live timeline of VM bring-up (see desktop.Engine.Up / EngineHooks.Progress) plus a first-run config form.
oap/internal/desktop/vz
Package vz — this file holds the pure, platform-independent half of the lease-based guest-IP discovery: parsing macOS's NAT DHCP lease file and matching a MAC address against it.
Package vz — this file holds the pure, platform-independent half of the lease-based guest-IP discovery: parsing macOS's NAT DHCP lease file and matching a MAC address against it.
oap/internal/desktopcmd
Package desktopcmd implements `oap desktop`, the macOS menubar app: a local VM running a single-node cluster, the setup window that brings it up, and the .oap install flow a double-clicked bundle takes.
Package desktopcmd implements `oap desktop`, the macOS menubar app: a local VM running a single-node cluster, the setup window that brings it up, and the .oap install flow a double-clicked bundle takes.
oap/internal/directorycmd
The credential-creation half of `oap directory configure`.
The credential-creation half of `oap directory configure`.
oap/internal/dotenv
Package dotenv provides a minimal .env-file reader used by oap secret-writing commands (oap identity put-token, oap agent put-key).
Package dotenv provides a minimal .env-file reader used by oap secret-writing commands (oap identity put-token, oap agent put-key).
oap/internal/gatewayhealth
Package gatewayhealth is a registry of per-cloud backend-health provisioners for webd's external-access Gateway.
Package gatewayhealth is a registry of per-cloud backend-health provisioners for webd's external-access Gateway.
oap/internal/health
Package health is oap's registry of cluster components and their health checks.
Package health is oap's registry of cluster components and their health checks.
oap/internal/identitycmd
Package identitycmd implements the three identity command trees: `oap identity` (an agent's AgentIdentity and the credential-setup flows behind it), `oap user-identity` (a person's own credential catalog), and `oap idp` (the cluster's identity provider).
Package identitycmd implements the three identity command trees: `oap identity` (an agent's AgentIdentity and the credential-setup flows behind it), `oap user-identity` (a person's own credential catalog), and `oap idp` (the cluster's identity provider).
oap/internal/imagebuild
Package imagebuild builds a bundle's declared images and delivers them to the current cluster (local node/VM load, or a registry push).
Package imagebuild builds a bundle's declared images and delivers them to the current cluster (local node/VM load, or a registry push).
oap/internal/imageload
Package imageload classifies how a locally-built Docker image reaches the node backing a given kube-context.
Package imageload classifies how a locally-built Docker image reaches the node backing a given kube-context.
oap/internal/imagemode
Package imagemode decides where an oap build sends its images: local :dev tags loaded straight onto the node, or a registry push, and for which platform.
Package imagemode decides where an oap build sends its images: local :dev tags loaded straight onto the node, or a registry push, and for which platform.
oap/internal/initpipeline
Package initpipeline declares the declarative Component model used by the `oap init` install pipeline.
Package initpipeline declares the declarative Component model used by the `oap init` install pipeline.
oap/internal/installcmd
Resolves the cluster kind ONCE, at the CLI edge.
Resolves the cluster kind ONCE, at the CLI edge.
oap/internal/kgcmd
Package kgcmd implements `oap kg`, the knowledge-graph query commands.
Package kgcmd implements `oap kg`, the knowledge-graph query commands.
oap/internal/kube
Package kube provides shared client-go construction for the oap CLI.
Package kube provides shared client-go construction for the oap CLI.
oap/internal/memorycmd
Package memorycmd implements `oap memory`: inspecting, querying, searching and sharing the entries in a session's memory scopes.
Package memorycmd implements `oap memory`: inspecting, querying, searching and sharing the entries in a session's memory scopes.
oap/internal/memstream
Package memstream polls the operator's memory HTTP API and emits new entries as they arrive.
Package memstream polls the operator's memory HTTP API and emits new entries as they arrive.
oap/internal/modeltoken
Package modeltoken resolves a model API-token value from a file, env var, or interactive prompt, and server-side-applies it into a central Secret that the operator can read (carrying the adoption label).
Package modeltoken resolves a model API-token value from a file, env var, or interactive prompt, and server-side-applies it into a central Secret that the operator can read (carrying the adoption label).
oap/internal/pincmd
Package pincmd implements `oap pin`: inspecting and updating the dependency pin baselines for MCPServers, SidecarToolboxes, Skills and SpiceboxToolkits.
Package pincmd implements `oap pin`: inspecting and updating the dependency pin baselines for MCPServers, SidecarToolboxes, Skills and SpiceboxToolkits.
oap/internal/plangatecmd
Package plangatecmd implements `oap plangate`: reading back what the plan gate recorded for a session.
Package plangatecmd implements `oap plangate`: reading back what the plan gate recorded for a session.
oap/internal/portforward
Package portforward wraps client-go's tools/portforward to expose a Service's port (via its backing Pods) on a localhost loopback.
Package portforward wraps client-go's tools/portforward to expose a Service's port (via its backing Pods) on a localhost loopback.
oap/internal/preferencescmd
Package preferencescmd implements `oap preferences`: reading the resolved per-user preferences snapshot a session's agent sees.
Package preferencescmd implements `oap preferences`: reading the resolved per-user preferences snapshot a session's agent sees.
oap/internal/progress
Package progress renders oap install progress as a sequence of named phases.
Package progress renders oap install progress as a sequence of named phases.
oap/internal/publicendpoint
Package publicendpoint is the ONE door through which `oap` creates the cluster's PublicEndpoint.
Package publicendpoint is the ONE door through which `oap` creates the cluster's PublicEndpoint.
oap/internal/sandboxcmd
Package sandboxcmd implements `oap sandbox`: inspecting the SpiceboxSession resources that back an agent's running sandbox pods.
Package sandboxcmd implements `oap sandbox`: inspecting the SpiceboxSession resources that back an agent's running sandbox pods.
oap/internal/sessioncmd
`oap session approve` — force-fire an approval (or denial) decision for a pending approval request, simulating what would happen if the approver clicked Approve / Deny in the channel.
`oap session approve` — force-fire an approval (or denial) decision for a pending approval request, simulating what would happen if the approver clicked Approve / Deny in the channel.
oap/internal/settingscmd
Package settingscmd implements `oap settings`: the cluster-wide agent security-defaults wizard and the apply verb behind it.
Package settingscmd implements `oap settings`: the cluster-wide agent security-defaults wizard and the apply verb behind it.
oap/internal/skillcmd
Package skillcmd implements `oap skill`: managing Skills and SkillSources, namespaced or cluster-scoped.
Package skillcmd implements `oap skill`: managing Skills and SkillSources, namespaced or cluster-scoped.
oap/internal/spicedb
Package spicedb re-exports the canonical SpiceDB authorization schema for the oap CLI (apply-schema + install's bootstrap ConfigMap).
Package spicedb re-exports the canonical SpiceDB authorization schema for the oap CLI (apply-schema + install's bootstrap ConfigMap).
oap/internal/toolscli
Package toolscli holds the CLI-side helpers shared across the kind-agnostic `oap tools` verbs: table/detail rendering, in-cluster name resolution, and the multi-doc YAML walker for apply.
Package toolscli holds the CLI-side helpers shared across the kind-agnostic `oap tools` verbs: table/detail rendering, in-cluster name resolution, and the multi-doc YAML walker for apply.
oap/internal/toolscmd
Package toolscmd — `oap tools gen` opens the agent builder in the browser.
Package toolscmd — `oap tools gen` opens the agent builder in the browser.
oap/internal/transcript
Package transcript renders a session's stored transcript for the terminal: the turns `oap agent run` streams as they land, and the same turns plus interleaved tool-session events `oap session logs` replays afterwards.
Package transcript renders a session's stored transcript for the terminal: the turns `oap agent run` streams as they land, and the same turns plus interleaved tool-session events `oap session logs` replays afterwards.
oap/internal/uihelpers
Package uihelpers contains small render helpers shared across the oap CLI's "show" commands so each command file stays focused on its resource shape.
Package uihelpers contains small render helpers shared across the oap CLI's "show" commands so each command file stays focused on its resource shape.
oap/internal/wait
Package wait provides a generic "poll until condition" helper used by oap init and oap agent run.
Package wait provides a generic "poll until condition" helper used by oap init and oap agent run.
oap/internal/zedctx
Package zedctx is a thin wrapper around the `zed` CLI's context management subcommands (set / use / remove).
Package zedctx is a thin wrapper around the `zed` CLI's context management subcommands (set / use / remove).
internal
cmd/apguest command
Command apguest is the tiny in-VM guest agent baked into the desktop bundle's rootfs (see build/desktop/apguest.service).
Command apguest is the tiny in-VM guest agent baked into the desktop bundle's rootfs (see build/desktop/apguest.service).
cmd/apiadapter command
Command apiadapter is ap-api-adapter: a declarative HTTP→MCP adapter.
Command apiadapter is ap-api-adapter: a declarative HTTP→MCP adapter.
cmd/authzd command
Extractor and Composer are the two seams of the two-call LLM pipeline.
Extractor and Composer are the two seams of the two-call LLM pipeline.
cmd/channelsd command
agentUIMinter is channelsd's implementation of channelkinds.AgentUIMinter.
agentUIMinter is channelsd's implementation of channelkinds.AgentUIMinter.
cmd/channelsd/internal/assetfetch
Package assetfetch is channelsd's HTTP client for the operator's /artifact-bundle/{ns}/{sess}/{render}/bundle route.
Package assetfetch is channelsd's HTTP client for the operator's /artifact-bundle/{ns}/{sess}/{render}/bundle route.
cmd/claudeshim command
Command claudeshim is installed as /opt/ap-toolchains/claude/bin/claude in the ap-toolchain-claude image, taking over the name the sandbox PATH (and the "claude" toolkit's declared target.binary in toolkits/claude.yaml) resolves.
Command claudeshim is installed as /opt/ap-toolchains/claude/bin/claude in the ap-toolchain-claude image, taking over the name the sandbox PATH (and the "claude" toolkit's declared target.binary in toolkits/claude.yaml) resolves.
cmd/extractord command
Command extractord is a small, deliberately powerless HTTP service that wraps the pkg/platform/extract registry.
Command extractord is a small, deliberately powerless HTTP service that wraps the pkg/platform/extract registry.
cmd/leadflowfake command
Command leadflowfake runs pkg/web/uidemo/leadflow as a standalone MCP Streamable HTTP server, for exercising the agent-defined-UI leads console against a real process rather than an in-test httptest.Server.
Command leadflowfake runs pkg/web/uidemo/leadflow as a standalone MCP Streamable HTTP server, for exercising the agent-defined-UI leads console against a real process rather than an in-test httptest.Server.
cmd/operator command
cmd/runner command
Package main is the agentprimitives-runner binary.
Package main is the agentprimitives-runner binary.
cmd/streamclient command
streamclient claims a streaming ToolCall via the spicebox gateway, optionally pipes stdin into the tool, and writes stdout/stderr/exit-info to disk.
streamclient claims a streaming ToolCall via the spicebox gateway, optionally pipes stdin into the tool, and writes stdout/stderr/exit-info to disk.
cmd/webd command
Command webd is the browser-UI host.
Command webd is the browser-UI host.
cmd/websearchd command
htmltotext.go reduces an HTML page's markup to plain text before fetch measures it against its size cap.
htmltotext.go reduces an HTML page's markup to plain text before fetch measures it against its size cap.
cmd/workshop command
Command workshop runs the ap-workshop sidecar: a Streamable-HTTP MCP server that lives inside the plan-2 workshop namespace W and exposes the agent builder's workshop tools (added starting with Task 2) to the builder agent's runner.
Command workshop runs the ap-workshop sidecar: a Streamable-HTTP MCP server that lives inside the plan-2 workshop namespace W and exposes the agent builder's workshop tools (added starting with Task 2) to the builder agent's runner.
magefiles
smoke/echo-mcp command
Command echo-mcp is a tiny MCP-over-HTTP (Streamable HTTP) server used ONLY by the kind-cluster smoke test (mage test:smoke).
Command echo-mcp is a tiny MCP-over-HTTP (Streamable HTTP) server used ONLY by the kind-cluster smoke test (mage test:smoke).
pkg
agent/agentcaps
Package agentcaps resolves AgentClass capability grants.
Package agentcaps resolves AgentClass capability grants.
agent/completion
Package completion is the registry of COMPLETION REQUIREMENTS: conditions a session must satisfy before its agent may declare a round of work finished.
Package completion is the registry of COMPLETION REQUIREMENTS: conditions a session must satisfy before its agent may declare a round of work finished.
agent/completion/kinds/artifactdelivery
Package artifactdelivery registers the `artifact-delivered` completion requirement: a session may not declare its work complete while it owns a Ready ArtifactRender that no respond_to_user ever attached.
Package artifactdelivery registers the `artifact-delivered` completion requirement: a session may not declare its work complete while it owns a Ready ArtifactRender that no respond_to_user ever attached.
agent/completion/kinds/plansteps
Package plansteps registers the `plan-steps-complete` completion requirement: a session may not declare its work complete while steps of its own declared plan are still pending or in progress.
Package plansteps registers the `plan-steps-complete` completion requirement: a session may not declare its work complete while steps of its own declared plan are still pending or in progress.
agent/completion/kinds/triggerconcluded
Package triggerconcluded registers the `trigger-status-concluded` completion requirement: a session whose trigger has a status surface may not declare its work complete while that surface still carries no answer.
Package triggerconcluded registers the `trigger-status-concluded` completion requirement: a session whose trigger has a status surface may not declare its work complete while that surface still carries no answer.
agent/derivevalidator
Package derivevalidator judges whether a derive_tag call's derived content is a faithful transformation of its sources — introducing no information not present in them — using a DEDICATED model.
Package derivevalidator judges whether a derive_tag call's derived content is a faithful transformation of its sources — introducing no information not present in them — using a DEDICATED model.
agent/harness
Package harness defines the agent-harness seam: the swappable component that runs an AgentSession's outer loop.
Package harness defines the agent-harness seam: the swappable component that runs an AgentSession's outer loop.
agent/harness/apnative
Package apnative registers the built-in agent harness: the runner binary running runner.Loop.
Package apnative registers the built-in agent harness: the runner binary running runner.Loop.
agent/harness/fake
Package fake is an in-memory Harness for tests.
Package fake is an in-memory Harness for tests.
agent/harness/registry
Package registry is the global lookup for agent harnesses.
Package registry is the global lookup for agent harnesses.
agent/llm
Package llm defines provider-neutral types and the Provider interface.
Package llm defines provider-neutral types and the Provider interface.
agent/llm/anthropic
Package anthropic adapts the official Anthropic Go SDK to the llm.Provider interface.
Package anthropic adapts the official Anthropic Go SDK to the llm.Provider interface.
agent/llm/fake
Package fake is a scripted llm.Provider for tests.
Package fake is a scripted llm.Provider for tests.
agent/llm/models
Package models is the canonical, provider-neutral registry of built-in model metadata: per-token pricing and capability flags.
Package models is the canonical, provider-neutral registry of built-in model metadata: per-token pricing and capability flags.
agent/llm/openai
Package openai adapts the official OpenAI Go SDK (Chat Completions) to the llm.Provider interface.
Package openai adapts the official OpenAI Go SDK (Chat Completions) to the llm.Provider interface.
agent/llm/openaicompat
Package openaicompat holds the OpenAI-Chat-Completions wire translation shared by every OpenAI-compatible llm.Provider (openai, openrouter).
Package openaicompat holds the OpenAI-Chat-Completions wire translation shared by every OpenAI-compatible llm.Provider (openai, openrouter).
agent/llm/openrouter
Package openrouter adapts OpenRouter's OpenAI-compatible Chat Completions API to llm.Provider, reusing the shared openaicompat wire translation.
Package openrouter adapts OpenRouter's OpenAI-compatible Chat Completions API to llm.Provider, reusing the shared openaicompat wire translation.
agent/llm/providers
Package providers is the LLM-provider factory: it maps a provider name (from AgentSession EffectiveSettings.Model.Provider, a CRD string) to a constructed llm.Provider.
Package providers is the LLM-provider factory: it maps a provider name (from AgentSession EffectiveSettings.Model.Provider, a CRD string) to a constructed llm.Provider.
agent/modality
Package modality lets provider- and capability-aware "surfaces" (tools + prompt instructions) plug into a turn without the runner branching on which one is active.
Package modality lets provider- and capability-aware "surfaces" (tools + prompt instructions) plug into a turn without the runner branching on which one is active.
agent/modality/files/anthropicbridge
Package anthropicbridge implements modality.Bridge (Tier-2 byte transport) against Anthropic's Files API.
Package anthropicbridge implements modality.Bridge (Tier-2 byte transport) against Anthropic's Files API.
agent/modality/registry
Package registry is the process-local registry of modality.Modality implementations.
Package registry is the process-local registry of modality.Modality implementations.
agent/pinnedmessage
Package pinnedmessage derives a triggered session's opening-message status projection from its durable session state.
Package pinnedmessage derives a triggered session's opening-message status projection from its durable session state.
agent/postsession/cost
Package cost is the first post-session reporter: an end-of-session LLM cost estimate.
Package cost is the first post-session reporter: an end-of-session LLM cost estimate.
agent/preview/markup
Package markup is the isolated secondary-LLM that generates sample HTML markup for the css artifact kind's browser preview.
Package markup is the isolated secondary-LLM that generates sample HTML markup for the css artifact kind's browser preview.
agent/restartmarker
Package restartmarker signs and verifies AgentSession.status.pendingRestart: the fork/takeover marker channelsd writes and the operator's restart reconciler acts on.
Package restartmarker signs and verifies AgentSession.status.pendingRestart: the fork/takeover marker channelsd writes and the operator's restart reconciler acts on.
agent/runner
pkg/agent/runner/completion_gate.go
pkg/agent/runner/completion_gate.go
agent/runner/approval/summarizer
Package summarizer is the isolated "What this tool call will do" LLM that lives inside the runner pod and produces the one-sentence approver-facing summary shown in the Slack approval prompt.
Package summarizer is the isolated "What this tool call will do" LLM that lives inside the runner pod and produces the one-sentence approver-facing summary shown in the Slack approval prompt.
agent/runner/channelhistorygate
Package channelhistorygate contains the shared "offer decision" helper internal/cmd/runner and the e2e in-process runner factory both use to decide whether to inject the read_channel_history tool for a session.
Package channelhistorygate contains the shared "offer decision" helper internal/cmd/runner and the e2e in-process runner factory both use to decide whether to inject the read_channel_history tool for a session.
agent/runner/identityadvisor
Package identityadvisor is the isolated "should this turn run as the agent identity or the invoking human's identity" LLM used for AgentClass.spec.identityMode == "dynamic".
Package identityadvisor is the isolated "should this turn run as the agent identity or the invoking human's identity" LLM used for AgentClass.spec.identityMode == "dynamic".
agent/runner/leakagewiring
Package leakagewiring contains the helpers internal/cmd/runner and the e2e in-process runner factory both use to wire the info-leakage gate (`Loop.LookupToolMapping`, `Loop.RequesterCanonicalID`, `Loop.SpiceDBCheck`, `Loop.ChannelKindImpl`).
Package leakagewiring contains the helpers internal/cmd/runner and the e2e in-process runner factory both use to wire the info-leakage gate (`Loop.LookupToolMapping`, `Loop.RequesterCanonicalID`, `Loop.SpiceDBCheck`, `Loop.ChannelKindImpl`).
agent/runner/userprofilegate
Package userprofilegate contains the shared "offer decision" helper internal/cmd/runner and the e2e in-process runner factory both use to decide whether a session's agent may see profile detail about the person speaking.
Package userprofilegate contains the shared "offer decision" helper internal/cmd/runner and the e2e in-process runner factory both use to decide whether a session's agent may see profile detail about the person speaking.
agent/secretout
Package secretout is the per-session, out-of-band store for tool-produced secret values.
Package secretout is the per-session, out-of-band store for tool-produced secret values.
agent/session/lifecycle
Package lifecycle is the pure, I/O-free session state machine.
Package lifecycle is the pure, I/O-free session state machine.
agent/session/state
Package state is the per-session in-memory state framework.
Package state is the per-session in-memory state framework.
agent/session/state/deliveries
Package deliveries is the session-state Kind recording WHICH artifact renders actually reached a user.
Package deliveries is the session-state Kind recording WHICH artifact renders actually reached a user.
agent/session/state/openingsummary
Package openingsummary holds a triggered session's agent-authored enrichment body — the text appended to the pinned opening message.
Package openingsummary holds a triggered session's agent-authored enrichment body — the text appended to the pinned opening message.
agent/session/state/plans
Package plans is the session-state Kind for agent-declared multi-step plans.
Package plans is the session-state Kind for agent-declared multi-step plans.
agent/session/state/triggerstatus
Package triggerstatus is the session-state Kind recording whether the EVENT that started this session has been answered on its own status surface.
Package triggerstatus is the session-state Kind recording whether the EVENT that started this session has been answered on its own status surface.
agent/tool
Package tool defines the unified Tool interface seen by the agent loop.
Package tool defines the unified Tool interface seen by the agent loop.
agent/tool/authfail
Package authfail is the runner's credential-update CORROBORATION recorder: it turns "this tool call failed the way this provider's credentials fail" into the one durable observation the CredentialUpdateRequest reconciler consults when it cannot re-probe the provider to confirm the agent's claim.
Package authfail is the runner's credential-update CORROBORATION recorder: it turns "this tool call failed the way this provider's credentials fail" into the one durable observation the CredentialUpdateRequest reconciler consults when it cannot re-probe the provider to confirm the agent's claim.
agent/tool/mcp
Package mcp — MCPTool struct + method set, separated from synthesize.go so the synthesizer file stays narrowly focused on the spec→tool.Tool pipeline.
Package mcp — MCPTool struct + method set, separated from synthesize.go so the synthesizer file stays narrowly focused on the spec→tool.Tool pipeline.
agent/tool/mcp/labelextract
Package labelextract evaluates the per-MCPServer-tool `labels` blocks: CEL expressions that pull (resourceType, id, label) tuples out of a tool's response so the runner can later substitute human-readable names into approval prompts.
Package labelextract evaluates the per-MCPServer-tool `labels` blocks: CEL expressions that pull (resourceType, id, label) tuples out of a tool's response so the runner can later substitute human-readable names into approval prompts.
agent/tool/meta
pkg/agent/tool/meta/complete_phase.go
pkg/agent/tool/meta/complete_phase.go
agent/tool/meta/capability
Package capability registers the meta-tool capabilities an AgentClass can grant.
Package capability registers the meta-tool capabilities an AgentClass can grant.
agent/tool/operations
Package operations is the per-session audit-trail registry used by new_operation (meta tool) and the sandbox dispatcher to enforce that every external tool call is justified by a logical operation.
Package operations is the per-session audit-trail registry used by new_operation (meta tool) and the sandbox dispatcher to enforce that every external tool call is justified by a logical operation.
agent/tool/originfmt
Package originfmt owns the wire format of a tool's ORIGIN — the string tool.OriginTool.Origin() returns, i.e.
Package originfmt owns the wire format of a tool's ORIGIN — the string tool.OriginTool.Origin() returns, i.e.
agent/tool/sandbox
Package sandbox implements the runner-side sandbox tool dispatch: synthesizing Tool impls from SpiceboxToolspecs, executing them as ToolCall CRs, and fetching their stdout/stderr via the operator's /debug/artifact endpoint.
Package sandbox implements the runner-side sandbox tool dispatch: synthesizing Tool impls from SpiceboxToolspecs, executing them as ToolCall CRs, and fetching their stdout/stderr via the operator's /debug/artifact endpoint.
agent/tool/sidecartoolbox
origin.go: tags sidecar-synthesized tools with their sidecar origin so toolguard's origin-level circuit breaker treats all tools of one sidecar as sharing health.
origin.go: tags sidecar-synthesized tools with their sidecar origin so toolguard's origin-level circuit breaker treats all tools of one sidecar as sharing health.
agent/tool/synthesize
Package synthesize provides the shared "iterate spec → emit tool.Tool" machinery used by every tool-kind runtime adapter (mcp, sandbox, future…).
Package synthesize provides the shared "iterate spec → emit tool.Tool" machinery used by every tool-kind runtime adapter (mcp, sandbox, future…).
agent/toolenvelope
Package toolenvelope defines the untrusted-tool-output envelope: the marked region the runner wraps every tool result in before the model sees it.
Package toolenvelope defines the untrusted-tool-output envelope: the marked region the runner wraps every tool result in before the model sees it.
agent/userprofile
Package userprofile owns the kind-neutral user-profile vocabulary: which fields exist, which are exposed by default, and the single Filter that decides what an agent may see.
Package userprofile owns the kind-neutral user-profile vocabulary: which fields exist, which are exposed by default, and the single Filter that decides what an agent may see.
apis/v1alpha1
Package v1alpha1 contains API Schema definitions for the agentprimitives.authzed.com v1alpha1 API group (Spicebox).
Package v1alpha1 contains API Schema definitions for the agentprimitives.authzed.com v1alpha1 API group (Spicebox).
authz
Package authz is the single home for every runtime authorization decision in agentprimitives.
Package authz is the single home for every runtime authorization decision in agentprimitives.
authz/adoptguard
Package adoptguard gates operator reads of guarded object types (Secret, ConfigMap) to objects the operator legitimately manages — adopted via a CR reference (carrying AdoptedLabel, so present in the label-filtered cache), or on a small fixed-infra allowlist.
Package adoptguard gates operator reads of guarded object types (Secret, ConfigMap) to objects the operator legitimately manages — adopted via a CR reference (carrying AdoptedLabel, so present in the label-filtered cache), or on a small fixed-infra allowlist.
authz/authzd/pipelinehost
Package pipelinehost is authzd's implementation of pipeline.Host.
Package pipelinehost is authzd's implementation of pipeline.Host.
authz/coldstart
Package coldstart holds the cold-start approval action constants and the approval.Decision → action mapping, in an importable package so both the authzd pipeline Host (pkg/authz/authzd/pipelinehost) and the cold-start hook can reference them without importing internal/cmd/authzd (package main).
Package coldstart holds the cold-start approval action constants and the approval.Decision → action mapping, in an importable package so both the authzd pipeline Host (pkg/authz/authzd/pipelinehost) and the cold-start hook can reference them without importing internal/cmd/authzd (package main).
authz/contentguard
The framework-side byte cap on what any Instance is handed to inspect.
The framework-side byte cap on what any Instance is handed to inspect.
authz/contentguard/kinds/promptinjection
Package promptinjection is a content-guard inspector that classifies tool I/O for prompt-injection risk by POSTing text to a co-located ONNX detector sidecar and mapping the risk score to a Finding.
Package promptinjection is a content-guard inspector that classifies tool I/O for prompt-injection risk by POSTing text to a co-located ONNX detector sidecar and mapping the risk score to a Finding.
authz/contentguard/kinds/urlallowlist
Package urlallowlist is a content-guard inspector enforcing a URL policy on tool I/O: an ordered, first-match-wins rule list (like ToolGuardPolicy), each rule matching a URL by domain glob / regex / CEL and carrying its own allow|deny|approve action.
Package urlallowlist is a content-guard inspector enforcing a URL policy on tool I/O: an ordered, first-match-wins rule list (like ToolGuardPolicy), each rule matching a URL by domain glob / regex / CEL and carrying its own allow|deny|approve action.
authz/contentguard/registry
Package registry is the process-wide registry of content-guard inspector kinds.
Package registry is the process-wide registry of content-guard inspector kinds.
authz/engine
Package engine is the top-level runner-facing Engine interface aggregator.
Package engine is the top-level runner-facing Engine interface aggregator.
authz/extract
Package extract defines the Provider interface and shared types the slice-3 binding orchestrator uses to extract entities from user messages.
Package extract defines the Provider interface and shared types the slice-3 binding orchestrator uses to extract entities from user messages.
authz/extract/anthropic
Package anthropic provides an extract.Provider backed by the shared llm.Provider seam.
Package anthropic provides an extract.Provider backed by the shared llm.Provider seam.
authz/guardian/approval
WriteInfoLeakageGrants writes SpiceDB infoleakage_grant tuples on behalf of the runner's write-side info-leakage gate (T13).
WriteInfoLeakageGrants writes SpiceDB infoleakage_grant tuples on behalf of the runner's write-side info-leakage gate (T13).
authz/guardian/grants
Package grants writes, deletes, and checks the per-(session, tool, args) SpiceDB grant tuples behind the tool-approval flow.
Package grants writes, deletes, and checks the per-(session, tool, args) SpiceDB grant tuples behind the tool-approval flow.
authz/guardian/leakage
Package leakage holds types shared between the runner (which implements the information-leakage gate) and the meta respond_to_user tool (which calls the gate and must react differently depending on the outcome).
Package leakage holds types shared between the runner (which implements the information-leakage gate) and the meta respond_to_user tool (which calls the gate and must react differently depending on the outcome).
authz/guardian/schema
Package schema's base.go composes the COMPILE-TIME half of the schema: the scaffold, plus fragments that ship inside the binary rather than arriving from a cluster.
Package schema's base.go composes the COMPILE-TIME half of the schema: the scaffold, plus fragments that ship inside the binary rather than arriving from a cluster.
authz/handoff
Package handoff grades a request to hand a datum to a delegated child.
Package handoff grades a request to hand a datum to a delegated child.
authz/hooks
Package hooks holds the concrete authz lifecycle hooks for the runner.
Package hooks holds the concrete authz lifecycle hooks for the runner.
authz/observe
Package observe evaluates the `observes` blocks declared on a tool, turning one tool result into co-derived subjects and facts.
Package observe evaluates the `observes` blocks declared on a tool, turning one tool result into co-derived subjects and facts.
authz/observe/fromcrd
Package fromcrd converts v1alpha1.ObservesBlock into observe.Block, the single conversion site for both CRD carriers of ObservesBlock (MCPServerTool and SpiceboxToolspecSpec) -- two hand-maintained copies of this converter is the same shape as the silent-drop bug this DSL has already produced (see pkg/tools/mcp/spec.ObservesSpec, whose json tags must match the CRD type's exactly or the round trip drops the value).
Package fromcrd converts v1alpha1.ObservesBlock into observe.Block, the single conversion site for both CRD carriers of ObservesBlock (MCPServerTool and SpiceboxToolspecSpec) -- two hand-maintained copies of this converter is the same shape as the silent-drop bug this DSL has already produced (see pkg/tools/mcp/spec.ObservesSpec, whose json tags must match the CRD type's exactly or the round trip drops the value).
authz/permsurface
Package permsurface enumerates the permission classes an agent's tool envelope can reach.
Package permsurface enumerates the permission classes an agent's tool envelope can reach.
authz/pinning
Package pinning defines the pluggable dependency-pinning abstraction: every kind of swappable dependency an agent opts into (skills, sidecar images, MCP servers, CLI toolkits) has a user-facing ref with a measurable pin strength, a frozen identity it can be resolved to, and a way to detect drift between the recorded baseline and live state.
Package pinning defines the pluggable dependency-pinning abstraction: every kind of swappable dependency an agent opts into (skills, sidecar images, MCP servers, CLI toolkits) has a user-facing ref with a measurable pin strength, a frozen identity it can be resolved to, and a way to detect drift between the recorded baseline and live state.
authz/pinning/kinds/cli
Package cli adapts CLI toolkit binary assertions to the pinning.Kind contract.
Package cli adapts CLI toolkit binary assertions to the pinning.Kind contract.
authz/pinning/kinds/image
Pure OCI image ref helpers.
Pure OCI image ref helpers.
authz/pinning/kinds/mcp
Package mcp adapts MCP server manifest assertions to the pinning.Kind contract.
Package mcp adapts MCP server manifest assertions to the pinning.Kind contract.
authz/pinning/kinds/oap
Package oap adapts .oap agent-container OCI registry refs to the pinning.Kind contract.
Package oap adapts .oap agent-container OCI registry refs to the pinning.Kind contract.
authz/pinning/kinds/skill
Package skill adapts pkg/tools/skills/canonical to the pinning.Kind contract.
Package skill adapts pkg/tools/skills/canonical to the pinning.Kind contract.
authz/pinning/registry
Package registry is the process-wide registry of pinning kinds.
Package registry is the process-wide registry of pinning kinds.
authz/plangate
Package plangate holds the plan gate's value types: the phase model, the frozen approved plan, and the ceiling derived from it.
Package plangate holds the plan gate's value types: the phase model, the frozen approved plan, and the ceiling derived from it.
authz/plangate/hold
Package hold holds the forensic-hold trippers: the things that decide, from observed evidence, that a session should be frozen for review.
Package hold holds the forensic-hold trippers: the things that decide, from observed evidence, that a session should be frozen for review.
authz/precondition
Package precondition compiles a slot precondition — a CEL predicate over the facts recorded about one candidate resource instance — and extracts, up front, the complete set of facts that predicate reads.
Package precondition compiles a slot precondition — a CEL predicate over the facts recorded about one candidate resource instance — and extracts, up front, the complete set of facts that predicate reads.
authz/provenance
Package provenance builds and validates pt-tags: the per-datum record of where a piece of information came from and who may see it.
Package provenance builds and validates pt-tags: the per-datum record of where a piece of information came from and who may see it.
authz/relwrites
Dev/test override that redirects every `user:*` subject to a fixed canonical id before delegating to the real Writer.
Dev/test override that redirects every `user:*` subject to a fixed canonical id before delegating to the real Writer.
authz/resourcedisplay
Package resourcedisplay turns a SpiceDB object id into something a human reads — a short label, and, when the id is itself a URL, a link target.
Package resourcedisplay turns a SpiceDB object id into something a human reads — a short label, and, when the id is itself a URL, a link target.
authz/revocation
Package revocation is the pluggable in-flight revocation mechanism.
Package revocation is the pluggable in-flight revocation mechanism.
authz/revocation/kinds/credential
Package credential is the credential revocation Invalidator.
Package credential is the credential revocation Invalidator.
authz/revocation/kinds/sessionhold
Package sessionhold is the revocation kind that halts a running session's turn loop when a forensic hold is tripped.
Package sessionhold is the revocation kind that halts a running session's turn loop when a forensic hold is tripped.
authz/revocation/kinds/toolorigin
Package toolorigin is the tool-origin revocation Invalidator.
Package toolorigin is the tool-origin revocation Invalidator.
authz/scope
Package scope is the structured per-session permission policy document — Layer 2 of dynamic session scope.
Package scope is the structured per-session permission policy document — Layer 2 of dynamic session scope.
authz/slotspec
Package slotspec is the ONLY place an authz.BoundEntitySpec is constructed from an AgentClass's declared slots.
Package slotspec is the ONLY place an authz.BoundEntitySpec is constructed from an AgentClass's declared slots.
authz/spicedb
Package spicedb wraps the SpiceDB Go client with the channels-specific operations (TouchStartedBy, CheckInteract, ...).
Package spicedb wraps the SpiceDB Go client with the channels-specific operations (TouchStartedBy, CheckInteract, ...).
authz/spicedb/relsource
Package relsource records which in-tree component owns which SpiceDB relations, and refuses a write or delete filter that would touch a relation another component claims.
Package relsource records which in-tree component owns which SpiceDB relations, and refuses a write or delete filter that would touch a relation another component claims.
authz/spicedb/relsource/imports
Package imports blank-imports every in-tree package that registers a relsource.Source carrying real claims, then marks the claim table complete — turning relsource.CheckWrite / CheckDeleteFilter from a fail-closed refusal into the working guard.
Package imports blank-imports every in-tree package that registers a relsource.Source carrying real claims, then marks the claim table complete — turning relsource.CheckWrite / CheckDeleteFilter from a fail-closed refusal into the working guard.
authz/spicedb/schema
Package schema is the single source of truth for the agentprimitives SpiceDB authorization schema.
Package schema is the single source of truth for the agentprimitives SpiceDB authorization schema.
authz/spicedb/toolcheck
Package toolcheck is the SpiceDB implementation of the tool-call authorization gate.
Package toolcheck is the SpiceDB implementation of the tool-call authorization gate.
authz/toolguard
Package toolguard implements per-tool circuit breakers (with exponential backoff as the breaker's recovery schedule) and per-tool rate limits, enforced as PreToolCall/PostToolCall pipeline hooks.
Package toolguard implements per-tool circuit breakers (with exponential backoff as the breaker's recovery schedule) and per-tool rate limits, enforced as PreToolCall/PostToolCall pipeline hooks.
authz/trifecta
Package trifecta derives the three legs whose combination makes a delegation dangerous, and judges them.
Package trifecta derives the three legs whose combination makes a delegation dangerous, and judges them.
authz/untrusted
Package untrusted holds the shared tag names for nonce-delimited untrusted- content envelopes, so the producer (the envelope builder) and the consumers (the runner's strip + the agent prompt) can never drift apart — a drift would silently let untrusted content escape its boundary.
Package untrusted holds the shared tag names for nonce-delimited untrusted- content envelopes, so the producer (the envelope builder) and the consumers (the runner's strip + the agent prompt) can never drift apart — a drift would silently let untrusted content escape its boundary.
authz/validator/core
Package core holds the shared decision/trace types both validator packages — pkg/tools/toolspec/validator (CLI argv) and pkg/tools/mcp/validator (MCP JSON args) — return.
Package core holds the shared decision/trace types both validator packages — pkg/tools/toolspec/validator (CLI argv) and pkg/tools/mcp/validator (MCP JSON args) — return.
bronzethread
Package bronzethread runs whole-session tests from an AUTHORED transcript.
Package bronzethread runs whole-session tests from an AUTHORED transcript.
channels/channelassets
Package channelassets defines the renderer plug-in surface for agent-produced visual artifacts.
Package channelassets defines the renderer plug-in surface for agent-produced visual artifacts.
channels/channelassets/css
Package css — registry init.
Package css — registry init.
channels/channelassets/html
Package html — registry init.
Package html — registry init.
channels/channelassets/image
Package image — registry init.
Package image — registry init.
channels/channelassets/internal/csssanitize
Package csssanitize is the shared CSS string sanitizer, used by the html renderer (for <style> elements and style="..." attributes) and the css renderer (for standalone stylesheets).
Package csssanitize is the shared CSS string sanitizer, used by the html renderer (for <style> elements and style="..." attributes) and the css renderer (for standalone stylesheets).
channels/channelassets/mcpui
Package mcpui — registry init.
Package mcpui — registry init.
channels/channelassets/oap
Package oap — registry init.
Package oap — registry init.
channels/channelassets/registry
Package registry holds the global renderer registry.
Package registry holds the global renderer registry.
channels/channelassets/svg
Package svg — registry init.
Package svg — registry init.
channels/channelevents
Cross-channel authz-messaging vocabulary.
Cross-channel authz-messaging vocabulary.
channels/channelfeatures
Package channelfeatures is the kind-agnostic vocabulary connecting an agent's CAPABILITIES to the transport PERMISSIONS its channel needs.
Package channelfeatures is the kind-agnostic vocabulary connecting an agent's CAPABILITIES to the transport PERMISSIONS its channel needs.
channels/channelinteractions
Package channelinteractions holds the semantic interaction-category registry: the single place a prompt type (tool approval, credential link, identity choice, …) is described.
Package channelinteractions holds the semantic interaction-category registry: the single place a prompt type (tool approval, credential link, identity choice, …) is described.
channels/channelinteractions/categories
Package categories holds the production interaction-category rows.
Package categories holds the production interaction-category rows.
channels/channelinteractions/categories/sessionrelease
Package sessionrelease is the session_release interaction category: the owner-gated approval card that clears a SessionHold (see pkg/apis/v1alpha1/sessionhold_types.go) and hands a forensically-held session back to its owner.
Package sessionrelease is the session_release interaction category: the owner-gated approval card that clears a SessionHold (see pkg/apis/v1alpha1/sessionhold_types.go) and hands a forensically-held session back to its owner.
channels/channelinteractions/testsupport
Package testsupport gives tests a snapshot/restore of the interaction category registry and its decision bindings, so a test that registers or binds a category never leaves the init()-registered production rows wiped for the next test.
Package testsupport gives tests a snapshot/restore of the interaction category registry and its decision bindings, so a test that registers or binds a category never leaves the init()-registered production rows wiped for the next test.
channels/channelkey
Package channelkey holds the canonical channel-key → label-value function.
Package channelkey holds the canonical channel-key → label-value function.
channels/channelkinds
Package channelkinds defines the kind interface implemented by each channel-kind package (slack, browser, local, bento, fake).
Package channelkinds defines the kind interface implemented by each channel-kind package (slack, browser, local, bento, fake).
channels/channelkinds/agent
Package agent is the channel kind for a session-to-session conversation: the counterparty is another AgentSession in the same cluster, not a third-party transport.
Package agent is the channel kind for a session-to-session conversation: the counterparty is another AgentSession in the same cluster, not a third-party transport.
channels/channelkinds/bento
Package bento is the channel kind that schedules inbound messages from an embedded Bento (https://warpstreamlabs.github.io/bento) `generate` input.
Package bento is the channel kind that schedules inbound messages from an embedded Bento (https://warpstreamlabs.github.io/bento) `generate` input.
channels/channelkinds/browser
Package browser is the channel kind for a session a BROWSER is looking at: webd serves the page, the page holds the socket, and this kind's Listener/Sender/StreamDeltaSink run in that host process rather than in channelsd (RelayedByChannelsd reports false).
Package browser is the channel kind for a session a BROWSER is looking at: webd serves the page, the page holds the socket, and this kind's Listener/Sender/StreamDeltaSink run in that host process rather than in channelsd (RelayedByChannelsd reports false).
channels/channelkinds/clienthosted
Package clienthosted holds the plumbing shared by the client-hosted channel kinds — `local` (the `oap` TUI) and `browser` (the built-in web chat).
Package clienthosted holds the plumbing shared by the client-hosted channel kinds — `local` (the `oap` TUI) and `browser` (the built-in web chat).
channels/channelkinds/fake
The "interaction" sub-channel sender for the fake kind: the generic Interaction model's recorder.
The "interaction" sub-channel sender for the fake kind: the generic Interaction model's recorder.
channels/channelkinds/github
Package github is the channel kind that receives GitHub pull-request webhook deliveries.
Package github is the channel kind that receives GitHub pull-request webhook deliveries.
channels/channelkinds/github/appprovision
pkg/channels/channelkinds/github/appprovision/appconfig.go
pkg/channels/channelkinds/github/appprovision/appconfig.go
channels/channelkinds/github/checkruns
Package checkruns is the installation-scoped half of this kind's GitHub REST surface: reading a pull request's head commit, and reading and writing the check runs on it.
Package checkruns is the installation-scoped half of this kind's GitHub REST surface: reading a pull request's head commit, and reading and writing the check runs on it.
channels/channelkinds/kindtest
Package kindtest is the conformance harness every channel kind must pass (design §5).
Package kindtest is the conformance harness every channel kind must pass (design §5).
channels/channelkinds/local
This kind's escaping seam.
This kind's escaping seam.
channels/channelkinds/onepassword
Package onepassword syncs 1Password groups into SpiceDB as onepassword_group#member, so an organizational role — engineers, founders — is a subject the platform can authorize against.
Package onepassword syncs 1Password groups into SpiceDB as onepassword_group#member, so an organizational role — engineers, founders — is a subject the platform can authorize against.
channels/channelkinds/outputbind
Package outputbind resolves the dedicated output Channel for a role=input Channel, derives the outbound routing anchor from it, and — for an inbound that carried no human — derives the line that opens the thread that anchor points at.
Package outputbind resolves the dedicated output Channel for a role=input Channel, derives the outbound routing anchor from it, and — for an inbound that carried no human — derives the line that opens the thread that anchor points at.
channels/channelkinds/registry/crdenumtest
Package crdenumtest reads the Channel CRD's shipped spec enums out of the embedded install bundle, so a test can pin a Go-side list against the CRD itself instead of against a hand-maintained literal: "every channel kind this binary must register" (spec.kind) and "every role a Channel may declare" (spec.role, mirrored by v1alpha1.AllChannelRoles).
Package crdenumtest reads the Channel CRD's shipped spec enums out of the embedded install bundle, so a test can pin a Go-side list against the CRD itself instead of against a hand-maintained literal: "every channel kind this binary must register" (spec.kind) and "every role a Channel may declare" (spec.role, mirrored by v1alpha1.AllChannelRoles).
channels/channelkinds/resolve
Package resolve loads the bound Channel CR, its credentials Secret, and the registered channelkinds.Kind for a channel-attached AgentSession.
Package resolve loads the bound Channel CR, its credentials Secret, and the registered channelkinds.Kind for a channel-attached AgentSession.
channels/channelkinds/slack
pkg/channels/channelkinds/slack/app_home.go
pkg/channels/channelkinds/slack/app_home.go
channels/channelkinds/slack/appprovision
pkg/channels/channelkinds/slack/appprovision/client.go
pkg/channels/channelkinds/slack/appprovision/client.go
channels/channelkinds/slack/fakeslack
Package fakeslack is an in-memory Slack Web API simulator for tests.
Package fakeslack is an in-memory Slack Web API simulator for tests.
channels/channelkinds/wizardkeys
Package wizardkeys holds what more than one channel kind's wizard asks: the answer keys, the prompt text, the shared questions and the validation for the things several kinds pose identically — "what do we call this Channel?", "which AgentClass does it bind to?" and, for a kind that cannot attribute to a human, "which service identity does it act as?"
Package wizardkeys holds what more than one channel kind's wizard asks: the answer keys, the prompt text, the shared questions and the validation for the things several kinds pose identically — "what do we call this Channel?", "which AgentClass does it bind to?" and, for a kind that cannot attribute to a human, "which service identity does it act as?"
channels/channelkinds/wizardrun
Package wizardrun is the client-neutral half of driving a channel kind's setup flow (channelkinds.Wizard): the ORDER of the steps once the answers are in, the collision check that guards them, and the apply that lands what they produced.
Package wizardrun is the client-neutral half of driving a channel kind's setup flow (channelkinds.Wizard): the ORDER of the steps once the answers are in, the collision check that guards them, and the apply that lands what they produced.
channels/channelsd/explainer
Package explainer produces a {what, why} pair describing why an agent session needs the user to link specific credentials.
Package explainer produces a {what, why} pair describing why an agent session needs the user to link specific credentials.
channels/channelsd/explainer/fake
Package fake provides a deterministic Explainer for tests + CI.
Package fake provides a deterministic Explainer for tests + CI.
channels/channelsd/historyresp
Package historyresp serves the read_thread_history runner tool over a NATS request/reply subject.
Package historyresp serves the read_thread_history runner tool over a NATS request/reply subject.
channels/channelsd/outbound
The Channel Deliverable condition: the relay's record of whether the most recent real delivery attempt through a Channel landed.
The Channel Deliverable condition: the relay's record of whether the most recent real delivery attempt through a Channel landed.
channels/channelsd/pinnededit
Package pinnededit derives the desired pinned-opening-message content for a session from its CR.
Package pinnededit derives the desired pinned-opening-message content for a session from its CR.
channels/channelsd/pinnededit/gates/triggeredidle
Package triggeredidle registers the idle-status gate that keeps a triggered, humanless session's pinned status from reading "in progress" forever.
Package triggeredidle registers the idle-status gate that keeps a triggered, humanless session's pinned status from reading "in progress" forever.
channels/channelsd/pipeline
pkg/channels/channelsd/pipeline/credential_linked.go
pkg/channels/channelsd/pipeline/credential_linked.go
channels/channelsd/pipelinehost
Package pipelinehost provides the channelsd implementation of pipeline.Host.
Package pipelinehost provides the channelsd implementation of pipeline.Host.
channels/channelsd/watchdog
Package watchdog is the pure decision core of channelsd's per-session "is the agent silently stuck?" watchdog.
Package watchdog is the pure decision core of channelsd's per-session "is the agent silently stuck?" watchdog.
channels/interact
Package interact is the interaction-kind registry: the generic "what did the human do" seam the /interact HTTP endpoint (webd) dispatches to.
Package interact is the interaction-kind registry: the generic "what did the human do" seam the /interact HTTP endpoint (webd) dispatches to.
channels/notice
Package notice is the authoring seam for one-way user-facing messages: errors, denials, warnings, degradation notices, lifecycle events — everything the system says to a user that is not agent speech, not tool output, and not an approval prompt.
Package notice is the authoring seam for one-way user-facing messages: errors, denials, warnings, degradation notices, lifecycle events — everything the system says to a user that is not agent speech, not tool output, and not an approval prompt.
channels/sessionnotice
Package sessionnotice derives the user-facing statements a session's STATUS implies — "starting up", "waiting for capacity", "paused, retry to continue".
Package sessionnotice derives the user-facing statements a session's STATUS implies — "starting up", "waiting for capacity", "paused, retry to continue".
cli/clikit
Package clikit holds the shared cobra wiring for the agentprimitives server binaries (operator, channelsd, authzd, webd, runner): typed flags whose values may come from the environment, routed through pflag so a malformed env value fails CLOSED at startup instead of silently falling back to a default.
Package clikit holds the shared cobra wiring for the agentprimitives server binaries (operator, channelsd, authzd, webd, runner): typed flags whose values may come from the environment, routed through pflag so a malformed env value fails CLOSED at startup instead of silently falling back to a default.
cli/tui
Package tui is agentprimitives' terminal design system.
Package tui is agentprimitives' terminal design system.
controllers/agentclass
pkg/controllers/agentclass/builderclass.go
pkg/controllers/agentclass/builderclass.go
controllers/agentidentity
Package agentidentity reconciles AgentIdentity CRs.
Package agentidentity reconciles AgentIdentity CRs.
controllers/agentsession
pkg/controllers/agentsession/archive.go
pkg/controllers/agentsession/archive.go
controllers/agentsession/cosidecar
Package cosidecar builds the Kubernetes objects for a container that runs as a co-located sidecar in (or beside) the runner pod: the hardened container, its startup probe, and a NetworkPolicy with runner-only ingress and an egress policy chosen by the caller.
Package cosidecar builds the Kubernetes objects for a container that runs as a co-located sidecar in (or beside) the runner pod: the hardened container, its startup probe, and a NetworkPolicy with runner-only ingress and an egress policy chosen by the caller.
controllers/agentsession/netpolrule
Package netpolrule holds NetworkPolicy rule fragments shared by the per-session pod policies (pkg/controllers/agentsession) and the co-sidecar policies (pkg/controllers/agentsession/cosidecar).
Package netpolrule holds NetworkPolicy rule fragments shared by the per-session pod policies (pkg/controllers/agentsession) and the co-sidecar policies (pkg/controllers/agentsession/cosidecar).
controllers/agentstatus
Package agentstatus writes AgentSession status the way a multi-writer CRD requires: each writer (the operator, channelsd) touches ONLY the fields it changed, so it never reverts a stale field or clears a field a concurrent writer owns.
Package agentstatus writes AgentSession status the way a multi-writer CRD requires: each writer (the operator, channelsd) touches ONLY the fields it changed, so it never reverts a stale field or clears a field a concurrent writer owns.
controllers/agentui
Package agentui reconciles AgentUI CRs: it admits the page — spec.view, or spec.slots compiled into one by the legacy shim — validating it in one pass against the platform component vocabulary (pkg/web/uicomponents), including every oap:generative hook's own contract (a unique name, a registered allowlist, no nesting), and observes both the resulting hook table and an eligibility CEILING (pkg/web/uigrant) onto status — see AgentUIStatus.EligibleTools's doc comment for exactly what that ceiling does and does not mean; it is not the full three-way grant and must not be read as an authorization decision.
Package agentui reconciles AgentUI CRs: it admits the page — spec.view, or spec.slots compiled into one by the legacy shim — validating it in one pass against the platform component vocabulary (pkg/web/uicomponents), including every oap:generative hook's own contract (a unique name, a registered allowlist, no nesting), and observes both the resulting hook table and an eligibility CEILING (pkg/web/uigrant) onto status — see AgentUIStatus.EligibleTools's doc comment for exactly what that ceiling does and does not mean; it is not the full three-way grant and must not be read as an authorization decision.
controllers/artifactrender
Package artifactrender hosts the ArtifactRender CRD reconciler.
Package artifactrender hosts the ArtifactRender CRD reconciler.
controllers/channel
Package channel reconciles Channel CRDs.
Package channel reconciles Channel CRDs.
controllers/clusteridentityprovider
pkg/controllers/clusteridentityprovider/controller.go
pkg/controllers/clusteridentityprovider/controller.go
controllers/clusterskill
pkg/controllers/clusterskill/controller.go
pkg/controllers/clusterskill/controller.go
controllers/clusterskillsource
pkg/controllers/clusterskillsource/controller.go
pkg/controllers/clusterskillsource/controller.go
controllers/conditions
Package conditions wraps k8s.io/apimachinery/pkg/api/meta condition helpers with the project-wide convention of always stamping ObservedGeneration from the owning object's Generation.
Package conditions wraps k8s.io/apimachinery/pkg/api/meta condition helpers with the project-wide convention of always stamping ObservedGeneration from the owning object's Generation.
controllers/credentialupdaterequest
Package credentialupdaterequest hosts the CredentialUpdateRequest reconciler: the operator-side decision of whether an agent's claim that a credential has died justifies putting a credential-entry card in front of a human.
Package credentialupdaterequest hosts the CredentialUpdateRequest reconciler: the operator-side decision of whether an agent's claim that a credential has died justifies putting a credential-entry card in front of a human.
controllers/guardian
Package guardian holds the operator-side controllers that compose per-AgentClass authz requirements (AgentSessionGrants CRs) into the SpiceDB `agentsession` definition.
Package guardian holds the operator-side controllers that compose per-AgentClass authz requirements (AgentSessionGrants CRs) into the SpiceDB `agentsession` definition.
controllers/inboxwake
Package inboxwake tells a session's OWN agent something by the only two means that work when the agent is not blocked in a tool call: append a fixed line to its transcript as an inbound "inbox" turn, then force it awake — the same two effects channelsd's applyWake produces for an ordinary human message (stamp the wake-requested-at annotation, publish the KindUserMessage nudge).
Package inboxwake tells a session's OWN agent something by the only two means that work when the agent is not blocked in a tool call: append a fixed line to its transcript as an inbound "inbox" turn, then force it awake — the same two effects channelsd's applyWake produces for an ordinary human message (stamp the wake-requested-at annotation, publish the KindUserMessage nudge).
controllers/internal/backoff
Package backoff is the shared per-key exponential-backoff tracker used by controllers (agentidentity, useridentity), which run the identical JIT-refresh loop over different identity kinds.
Package backoff is the shared per-key exponential-backoff tracker used by controllers (agentidentity, useridentity), which run the identical JIT-refresh loop over different identity kinds.
controllers/internal/identityrefresh
Package identityrefresh holds the RFC 6749 refresh-token policy shared by the AgentIdentity and UserIdentity refresh reconcilers: classify each type=oauth credential against its Secret, redeem the ones inside the expiry threshold, write the Refresh condition, and schedule the next reconcile.
Package identityrefresh holds the RFC 6749 refresh-token policy shared by the AgentIdentity and UserIdentity refresh reconcilers: classify each type=oauth credential against its Secret, redeem the ones inside the expiry threshold, write the Refresh condition, and schedule the next reconcile.
controllers/internal/reconcile
Package reconcile provides a shared phase-based reconciler skeleton used by every controller in pkg/controllers/*.
Package reconcile provides a shared phase-based reconciler skeleton used by every controller in pkg/controllers/*.
controllers/internal/skillpin
Package skillpin provides pin-record construction helpers shared by controllers.
Package skillpin provides pin-record construction helpers shared by controllers.
controllers/internal/skillspec
Package skillspec holds type-agnostic leaf helpers shared by the SkillSource and ClusterSkillSource controllers, which materialize Skill / ClusterSkill CRs that embed the SAME SkillSpec / SkillStatus.
Package skillspec holds type-agnostic leaf helpers shared by the SkillSource and ClusterSkillSource controllers, which materialize Skill / ClusterSkill CRs that embed the SAME SkillSpec / SkillStatus.
controllers/mcpserver
Package mcpserver reconciles MCPServer CRs.
Package mcpserver reconciles MCPServer CRs.
controllers/monitoring
pkg/controllers/monitoring/monitoring.go
pkg/controllers/monitoring/monitoring.go
controllers/publicendpoint
Package publicendpoint reconciles the PublicEndpoint CR: it opens the tunnel that makes this cluster reachable from the public Internet and publishes where it is reachable on status.url.
Package publicendpoint reconciles the PublicEndpoint CR: it opens the tunnel that makes this cluster reachable from the public Internet and publishes where it is reachable on status.url.
controllers/relationshipsource
pkg/controllers/relationshipsource/controller.go
pkg/controllers/relationshipsource/controller.go
controllers/sessionhold
Package sessionhold hosts the SessionHold reconciler: the operator-side component that publishes the session_release approval card once a hold has been observed Active, and applies the human's decision on it.
Package sessionhold hosts the SessionHold reconciler: the operator-side component that publishes the session_release approval card once a hold has been observed Active, and applies the human's decision on it.
controllers/settings
RevokePublisher is the operator-side detective control pairing with the runner's in-process tool-origin invalidator cache: on every ClusterAgentSettings / AgentSettings reconcile it diffs spec.limits.allowedMCPServers and spec.limits.allowedToolkits against the previous per-CR observation and emits a "tool-origin" revocation on the unified ap.revocation bus for each explicit removal.
RevokePublisher is the operator-side detective control pairing with the runner's in-process tool-origin invalidator cache: on every ClusterAgentSettings / AgentSettings reconcile it diffs spec.limits.allowedMCPServers and spec.limits.allowedToolkits against the previous per-CR observation and emits a "tool-origin" revocation on the unified ap.revocation bus for each explicit removal.
controllers/sidecartoolbox
Package sidecartoolbox reconciles SidecarToolbox CRs: validates the spec (sandbox class, provider ref, CEL constraints), then runs a one-shot probe Pod to confirm the sidecar image is reachable and its live tool list matches the declared allowlist.
Package sidecartoolbox reconciles SidecarToolbox CRs: validates the spec (sandbox class, provider ref, CEL constraints), then runs a one-shot probe Pod to confirm the sidecar image is reachable and its live tool list matches the declared allowlist.
controllers/skill
pkg/controllers/skill/controller.go
pkg/controllers/skill/controller.go
controllers/skillsource
pkg/controllers/skillsource/controller.go
pkg/controllers/skillsource/controller.go
controllers/spiceboxclass
Package spiceboxclass implements the SpiceboxClass controller.
Package spiceboxclass implements the SpiceboxClass controller.
controllers/spiceboxsession
Package spiceboxsession implements the SpiceboxSession controller.
Package spiceboxsession implements the SpiceboxSession controller.
controllers/spiceboxtoolchain
Package spiceboxtoolchain reconciles SpiceboxToolchain CRs.
Package spiceboxtoolchain reconciles SpiceboxToolchain CRs.
controllers/spiceboxtoolkit
Package spiceboxtoolkit reconciles SpiceboxToolkit CRs.
Package spiceboxtoolkit reconciles SpiceboxToolkit CRs.
controllers/spiceboxtoolspec
Package spiceboxtoolspec reconciles SpiceboxToolspec CRs.
Package spiceboxtoolspec reconciles SpiceboxToolspec CRs.
controllers/subagentrequest
Package subagentrequest hosts the SubagentRequest controller: the operator-side component that authorizes and performs delegation.
Package subagentrequest hosts the SubagentRequest controller: the operator-side component that authorizes and performs delegation.
controllers/testenv
Package testenv provides a controller-runtime envtest harness shared across controller test packages.
Package testenv provides a controller-runtime envtest harness shared across controller test packages.
controllers/testenv/idempotency
Package idempotency provides two CI-gate checks for the merge/apply convention in AGENTS.md's "Server-side apply: keep applied fields idempotent; put observations in status":
Package idempotency provides two CI-gate checks for the merge/apply convention in AGENTS.md's "Server-side apply: keep applied fields idempotent; put observations in status":
controllers/testfixtures
Package testfixtures collects test helpers shared across controller test packages.
Package testfixtures collects test helpers shared across controller test packages.
controllers/toolcall
Package toolcall implements the ToolCall controller.
Package toolcall implements the ToolCall controller.
controllers/useridentity
Package useridentity reconciles UserIdentity CRs — the cluster-scoped per-user credential catalog used by identityMode=userPassthrough agents.
Package useridentity reconciles UserIdentity CRs — the cluster-scoped per-user credential catalog used by identityMode=userPassthrough agents.
controllers/webhooks/agentsession
Package agentsession holds the AgentSession identity-pinning admission webhook.
Package agentsession holds the AgentSession identity-pinning admission webhook.
controllers/webhooks/skill
pkg/controllers/webhooks/skill/clusterskill_webhook.go
pkg/controllers/webhooks/skill/clusterskill_webhook.go
controllers/webhooks/subagentrequest
Package subagentrequest holds the admission webhook that makes a SubagentRequest's parent claim provable.
Package subagentrequest holds the admission webhook that makes a SubagentRequest's parent claim provable.
controllers/webhooks/toolcall
Package toolcall holds the ToolCall admission webhook.
Package toolcall holds the ToolCall admission webhook.
controllers/webhooks/workshop
Package workshop holds the admission webhook that is the heart of the agent-builder lockdown (spec layer 1.4): it fires on every write the workshop sidecar's ServiceAccount makes to the workshop-authored kinds, attributes the SA to a session, walks that session's workshop and its SpiceDB `workshop#build` tuple, then enforces the per-kind content rules ordinary RBAC cannot express — no fragment schema, allowlisted sidecar images only, no nested builder, no cross-namespace reference, prefixed cluster-scoped tool CRs only, and per-kind object limits.
Package workshop holds the admission webhook that is the heart of the agent-builder lockdown (spec layer 1.4): it fires on every write the workshop sidecar's ServiceAccount makes to the workshop-authored kinds, attributes the SA to a session, walks that session's workshop and its SpiceDB `workshop#build` tuple, then enforces the per-kind content rules ordinary RBAC cannot express — no fragment schema, allowlisted sidecar images only, no nested builder, no cross-namespace reference, prefixed cluster-scoped tool CRs only, and per-kind object limits.
controllers/webhooks/workspacejob
Package workspacejob constrains Jobs created by a session runner to the workspace reconcile template derived from operator-owned session status.
Package workspacejob constrains Jobs created by a session runner to the workspace reconcile template derived from operator-owned session status.
controllers/workshop
Package workshop hosts the Workshop reconciler: layer 1.2 (the closed RBAC kind set — the runner gets nothing, only <session>-workshop-sa gets the workshop namespace's build kinds) and layer 1.3 (the SpiceDB tuple that binds the workshop to the ONE session allowed to act as it).
Package workshop hosts the Workshop reconciler: layer 1.2 (the closed RBAC kind set — the runner gets nothing, only <session>-workshop-sa gets the workshop namespace's build kinds) and layer 1.3 (the SpiceDB tuple that binds the workshop to the ONE session allowed to act as it).
controllers/workshopprobe
Package workshopprobe — controller.go: the reconciler that turns a WorkshopProbe CR into a run probe.
Package workshopprobe — controller.go: the reconciler that turns a WorkshopProbe CR into a run probe.
controllers/workspacevolume
Package workspacevolume reclaims workspace PersistentVolume OBJECTS whose data can no longer exist: a Released, hostPath-backed volume of the workspace StorageClass, node-affined to a node the cluster no longer has.
Package workspacevolume reclaims workspace PersistentVolume OBJECTS whose data can no longer exist: a Released, hostPath-backed volume of the workspace StorageClass, node-affined to a node the cluster no longer has.
gen/blockcapture
Package blockcapture drives OAP's real Slack channel kind against an in-process Slack API stub and dumps the exact Block Kit JSON the sender serializes.
Package blockcapture drives OAP's real Slack channel kind against an in-process Slack API stub and dumps the exact Block Kit JSON the sender serializes.
gen/claudeexec
Package claudeexec is the shared plumbing for driving the headless `claude` CLI to (re)generate a repo artifact.
Package claudeexec is the shared plumbing for driving the headless `claude` CLI to (re)generate a repo artifact.
gen/clidocs
Package clidocs generates the site's CLI reference: one MDX page per top-level `oap` command family, walked deterministically from the live cobra command tree.
Package clidocs generates the site's CLI reference: one MDX page per top-level `oap` command family, walked deterministically from the live cobra command tree.
gen/crddocs
Package crddocs generates the site's CRD reference: one MDX page per OAP CustomResourceDefinition, from the generated CRD YAML schemas (which carry field descriptions from the Go doc comments, plus types/enums/defaults).
Package crddocs generates the site's CRD reference: one MDX page per OAP CustomResourceDefinition, from the generated CRD YAML schemas (which carry field descriptions from the Go doc comments, plus types/enums/defaults).
gen/mdxutil
Package mdxutil holds the small text helpers the docs generators (clidocs, crddocs) share for emitting MDX safely: escaping prose so it can't open a JSX tag/expression, and rendering strings into frontmatter and table cells.
Package mdxutil holds the small text helpers the docs generators (clidocs, crddocs) share for emitting MDX safely: escaping prose so it can't open a JSX tag/expression, and rendering strings into frontmatter and table cells.
memory
Package memory is the agent-memory framework: the Memory interface (Put/Query/Search/SendSignal), the Kind registry, the Local facade over a pluggable Backend, generic Query and scope semantics, signal dispatch, and the provider-neutral transcript types that flow over the HTTP API.
Package memory is the agent-memory framework: the Memory interface (Put/Query/Search/SendSignal), the Kind registry, the Local facade over a pluggable Backend, generic Query and scope semantics, signal dispatch, and the provider-neutral transcript types that flow over the HTTP API.
memory/assetlimits
Package assetlimits holds size ceilings shared by both sides of the inbound-attachment upload path: pkg/memory/httpsrv (the operator's POST /inbound-asset route, which enforces the ceiling) and pkg/channels/channelsd/pipeline (which clamps its own pre-fetch size check to the same number, so a file the operator will reject is never downloaded in full first).
Package assetlimits holds size ceilings shared by both sides of the inbound-attachment upload path: pkg/memory/httpsrv (the operator's POST /inbound-asset route, which enforces the ceiling) and pkg/channels/channelsd/pipeline (which clamps its own pre-fetch size check to the same number, so a file the operator will reject is never downloaded in full first).
memory/httpclient
Package httpclient is the HTTP client for the operator's memory API.
Package httpclient is the HTTP client for the operator's memory API.
memory/httpsrv
Package httpsrv exposes a memory.Memory over a bearer-authed HTTP API.
Package httpsrv exposes a memory.Memory over a bearer-authed HTTP API.
memory/kinds/all
Package all is a convenience: blank-importing it from a binary triggers the init() registration of every memory Kind.
Package all is a convenience: blank-importing it from a binary triggers the init() registration of every memory Kind.
memory/kinds/approval
Package approval is the memory Kind for approval-flow events (request + outcome).
Package approval is the memory Kind for approval-flow events (request + outcome).
memory/kinds/artifact
Package artifact registers the logical-artifact head Kind.
Package artifact registers the logical-artifact head Kind.
memory/kinds/artifactrevision
Package artifactrevision registers the immutable per-revision Kind of the artifact-versioning system.
Package artifactrevision registers the immutable per-revision Kind of the artifact-versioning system.
memory/kinds/auditkey
Package auditkey implements the "audit_key" memory Kind: the operator's durable witness of which Ed25519 key an AgentSession instance signs its append-only records with.
Package auditkey implements the "audit_key" memory Kind: the operator's durable witness of which Ed25519 key an AgentSession instance signs its append-only records with.
memory/kinds/authz_session_config
Package authz_session_config is the memory Kind for the per-session authz config snapshot: the entity-extraction config plus the two fields authzd derives this session's cold-start authorization policy from.
Package authz_session_config is the memory Kind for the per-session authz config snapshot: the entity-extraction config plus the two fields authzd derives this session's cold-start authorization policy from.
memory/kinds/authzdecision
Package authzdecision is the memory Kind for authz.Check outcomes.
Package authzdecision is the memory Kind for authz.Check outcomes.
memory/kinds/channel_msg_ref
Package channel_msg_ref implements the "channel_msg_ref" memory kind: a sparse index that maps a channel-kind-scoped message reference (Slack: channel_id:thread_ts:message_ts; future kinds: their own) to the turn index where the inbound message was recorded.
Package channel_msg_ref implements the "channel_msg_ref" memory kind: a sparse index that maps a channel-kind-scoped message reference (Slack: channel_id:thread_ts:message_ts; future kinds: their own) to the turn index where the inbound message was recorded.
memory/kinds/coldstarttask
Package coldstarttask is the memory Kind recording the approver's decision for a new session's cold-start scope proposal: which task (cleaned / original / none) the runner should run as the first turn, and whether scope was applied.
Package coldstarttask is the memory Kind recording the approver's decision for a new session's cold-start scope proposal: which task (cleaned / original / none) the runner should run as the first turn, and whether scope was applied.
memory/kinds/contentguardaudit
Package contentguardaudit is the memory Kind for the audit log of content-guard enforcement: per-call content-inspection findings (pass/block/approve), one entry per firing.
Package contentguardaudit is the memory Kind for the audit log of content-guard enforcement: per-call content-inspection findings (pass/block/approve), one entry per firing.
memory/kinds/envelopefact
Package envelopefact is the memory Kind for a fact derived by platform code from a VERIFIED inbound delivery — the signed webhook body that opened or advanced a session.
Package envelopefact is the memory Kind for a fact derived by platform code from a VERIFIED inbound delivery — the signed webhook body that opened or advanced a session.
memory/kinds/extracted_entity
Package extracted_entity is the memory Kind for raw LLM-extracted entity candidates produced by internal/cmd/authzd.
Package extracted_entity is the memory Kind for raw LLM-extracted entity candidates produced by internal/cmd/authzd.
memory/kinds/extraction_state
Package extraction_state is the memory Kind tracking authzd's per-turn extraction lifecycle: pending → complete | failed.
Package extraction_state is the memory Kind tracking authzd's per-turn extraction lifecycle: pending → complete | failed.
memory/kinds/factcontent
Package factcontent holds the content shape the two fact Kinds share.
Package factcontent holds the content shape the two fact Kinds share.
memory/kinds/infoleakageaudit
Package infoleakageaudit is the memory Kind for information-leakage audit events.
Package infoleakageaudit is the memory Kind for information-leakage audit events.
memory/kinds/infoleakagedecision
Package infoleakagedecision is the memory Kind for per-session information- leakage approval decisions.
Package infoleakagedecision is the memory Kind for per-session information- leakage approval decisions.
memory/kinds/infoleakagetaint
Package infoleakagetaint is the memory Kind for per-session taint records.
Package infoleakagetaint is the memory Kind for per-session taint records.
memory/kinds/internal/auditaccessor
Package auditaccessor holds the shared append-one / list-all accessor boilerplate for the simple per-scope audit Kinds.
Package auditaccessor holds the shared append-one / list-all accessor boilerplate for the simple per-scope audit Kinds.
memory/kinds/internal/undecodable
Package undecodable holds the one operator-facing report every Kind accessor owes when a stored Entry will not decode.
Package undecodable holds the one operator-facing report every Kind accessor owes when a stored Entry will not decode.
memory/kinds/label
Package label is the memory Kind for (resourceType, id) → display label tuples extracted from MCP tool responses.
Package label is the memory Kind for (resourceType, id) → display label tuples extracted from MCP tool responses.
memory/kinds/lifecycle
Package lifecycle is the canonical Kind for session/scope-lifecycle signals.
Package lifecycle is the canonical Kind for session/scope-lifecycle signals.
memory/kinds/lineage
Package lineage implements the "lineage" memory kind: bidirectional fork edges that record parent ↔ child relationships between AgentSessions when a user triggers Restart-from-here.
Package lineage implements the "lineage" memory kind: bidirectional fork edges that record parent ↔ child relationships between AgentSessions when a user triggers Restart-from-here.
memory/kinds/metaagentaudit
Package metaagentaudit is the memory Kind for the per-invocation audit log of metaagent decisions.
Package metaagentaudit is the memory Kind for the per-invocation audit log of metaagent decisions.
memory/kinds/metaagentthread
Package metaagentthread is the memory Kind for messages in the metaagent's sub-thread (user mentions + metaagent responses).
Package metaagentthread is the memory Kind for messages in the metaagent's sub-thread (user mentions + metaagent responses).
memory/kinds/observation
Package observation is the memory Kind for a note an agent session writes into a resource-scoped memory pool: free text one session concluded about a resource (a customer, a repo, whatever the resource type is), durable for a later session holding a slot on the same pool to read.
Package observation is the memory Kind for a note an agent session writes into a resource-scoped memory pool: free text one session concluded about a resource (a customer, a repo, whatever the resource type is), durable for a later session holding a slot on the same pool to read.
memory/kinds/observedfact
Package observedfact is the memory Kind for a fact derived from a tool RESULT by a declared `observes` block.
Package observedfact is the memory Kind for a fact derived from a tool RESULT by a declared `observes` block.
memory/kinds/parkedprompt
Package parkedprompt implements the "parked_prompt" memory kind: the durable record of a render-ready prompt a session is parked on, so it can be re-surfaced to a surface that attaches later, or after a restart.
Package parkedprompt implements the "parked_prompt" memory kind: the durable record of a render-ready prompt a session is parked on, so it can be re-surfaced to a surface that attaches later, or after a restart.
memory/kinds/plangateaudit
Package plangateaudit is the memory Kind for the plan gate's authorization record: which plan was approved, which phase was active, and what the gate decided for each permissioned call.
Package plangateaudit is the memory Kind for the plan gate's authorization record: which plan was approved, which phase was active, and what the gate decided for each permissioned call.
memory/kinds/preferenceaccess
Package preferenceaccess is the memory Kind for the audit log of subject-named preference reads: every GET /memory/_preferences?user-ref= request, resolved or not.
Package preferenceaccess is the memory Kind for the audit log of subject-named preference reads: every GET /memory/_preferences?user-ref= request, resolved or not.
memory/kinds/preferencewrite
Package preferencewrite is the memory Kind for the audit log of first-party human writes to user preferences: every direct edit via the Slack App Home (or other UI surfaces) into the acting user's own user_preference scope.
Package preferencewrite is the memory Kind for the audit log of first-party human writes to user preferences: every direct edit via the Slack App Home (or other UI surfaces) into the acting user's own user_preference scope.
memory/kinds/pttag
Package pttag is the memory Kind for per-datum provenance tags.
Package pttag is the memory Kind for per-datum provenance tags.
memory/kinds/pttagcontent
Package pttagcontent is the memory Kind for redacted content held behind a provenance tag.
Package pttagcontent is the memory Kind for redacted content held behind a provenance tag.
memory/kinds/relwritesaudit
Package relwritesaudit is the memory Kind for tuples written by pkg/authz/relwrites after a successful tool call.
Package relwritesaudit is the memory Kind for tuples written by pkg/authz/relwrites after a successful tool call.
memory/kinds/scopeaudit
Package scopeaudit is the memory Kind for the audit log of applied ScopeDeltas — one entry per applied delta.
Package scopeaudit is the memory Kind for the audit log of applied ScopeDeltas — one entry per applied delta.
memory/kinds/sessionscope
Package sessionscope is the memory Kind for the dynamic session scope (Layer 2).
Package sessionscope is the memory Kind for the dynamic session scope (Layer 2).
memory/kinds/systemprompt
Package systemprompt is the memory Kind for the append-only record of the system prompt an agent actually ran under.
Package systemprompt is the memory Kind for the append-only record of the system prompt an agent actually ran under.
memory/kinds/tool_dispatch_snapshot
Package tool_dispatch_snapshot implements the "tool_dispatch_snapshot" memory kind: a record that the runner requested — and the controller committed — a workspace snapshot immediately before a specific tool dispatch with stateImpact ∈ {readwrite, external}.
Package tool_dispatch_snapshot implements the "tool_dispatch_snapshot" memory kind: a record that the runner requested — and the controller committed — a workspace snapshot immediately before a specific tool dispatch with stateImpact ∈ {readwrite, external}.
memory/kinds/toolcatalog
Package toolcatalog is the memory Kind for the append-only record of which tools an agent was OFFERED, and from which turn.
Package toolcatalog is the memory Kind for the append-only record of which tools an agent was OFFERED, and from which turn.
memory/kinds/toolchainaudit
Package toolchainaudit is the memory Kind for the append-only record of toolchain selection.
Package toolchainaudit is the memory Kind for the append-only record of toolchain selection.
memory/kinds/toolguardaudit
Package toolguardaudit is the memory Kind for the audit log of tool-guard enforcement events: breaker trips/recoveries, rate-limit hits, denials and halts.
Package toolguardaudit is the memory Kind for the audit log of tool-guard enforcement events: breaker trips/recoveries, rate-limit hits, denials and halts.
memory/kinds/toolsession
Package toolsession registers the tool_session Kind — one Entry per parsed event from an interactive tool's stream (e.g.
Package toolsession registers the tool_session Kind — one Entry per parsed event from an interactive tool's stream (e.g.
memory/kinds/triggerdelivery
Package triggerdelivery is the memory Kind for the append-only record of the signed webhook delivery that STARTED a session.
Package triggerdelivery is the memory Kind for the append-only record of the signed webhook delivery that STARTED a session.
memory/kinds/turn
Package turn registers the LLM-transcript Kind.
Package turn registers the LLM-transcript Kind.
memory/kinds/uiaction
Package uiaction is the memory Kind for an agent-UI action's lifecycle record: one entry per request ID, rewritten in place as the call progresses (submitted -> awaiting_approval -> running -> settled).
Package uiaction is the memory Kind for an agent-UI action's lifecycle record: one entry per request ID, rewritten in place as the call progresses (submitted -> awaiting_approval -> running -> settled).
memory/kinds/uiviewmodel
Package uiviewmodel is the memory Kind for an agent-UI Tier-1 view-model: one record per (session, ui, hook), rewritten in place each time the agent calls update_view for that hook.
Package uiviewmodel is the memory Kind for an agent-UI Tier-1 view-model: one record per (session, ui, hook), rewritten in place each time the agent calls update_view for that hook.
memory/kinds/uiviewparams
Package uiviewparams is the memory Kind for the agent's own binding-parameter choices on an agent-defined UI: one record per (session, ui), rewritten in place each time the agent calls set_view_params.
Package uiviewparams is the memory Kind for the agent's own binding-parameter choices on an agent-defined UI: one record per (session, ui), rewritten in place each time the agent calls set_view_params.
memory/kinds/userpreference
Package userpreference is the memory Kind for one user's saved preference values, keyed per (classNamespace, className, key) in the user's own scope (memory.UserScope).
Package userpreference is the memory Kind for one user's saved preference values, keyed per (classNamespace, className, key) in the user's own scope (memory.UserScope).
memory/memcopy
Package memcopy provides the turn-anchored memory-copy primitive the AgentSession controller's restart reconciler uses to fork a new session from an existing one.
Package memcopy provides the turn-anchored memory-copy primitive the AgentSession controller's restart reconciler uses to fork a new session from an existing one.
memory/memtest
Package memtest provides Backend test doubles for the memory framework.
Package memtest provides Backend test doubles for the memory framework.
memory/pools
Package pools answers one question: which resource memory pools may this session touch, and in which direction?
Package pools answers one question: which resource memory pools may this session touch, and in which direction?
memory/provenance
Package provenance signs and verifies append-only memory entries: per-publisher Ed25519 signatures over a canonical entry digest, hash-chained per (scope, publisher) for gap/truncation detection.
Package provenance signs and verifies append-only memory entries: per-publisher Ed25519 signatures over a canonical entry digest, hash-chained per (scope, publisher) for gap/truncation detection.
memory/pttagmint
Package pttagmint derives a datum's audience and records its provenance tag.
Package pttagmint derives a datum's audience and records its provenance tag.
memory/publisherkeys
Package publisherkeys is an in-memory publisher→keyID→Ed25519 key store for component publishers (channelsd, authzd, operator).
Package publisherkeys is an in-memory publisher→keyID→Ed25519 key store for component publishers (channelsd, authzd, operator).
memory/sentinel
Package sentinel is the single source of truth for how a memory sentinel error crosses the HTTP wire, in both directions: httpsrv reads Table to pick the response status and stamp Header; httpclient reads it to rebuild the sentinel from Header.
Package sentinel is the single source of truth for how a memory sentinel error crosses the HTTP wire, in both directions: httpsrv reads Table to pick the response status and stamp Header; httpclient reads it to rebuild the sentinel from Header.
memory/tokens
Package tokens maintains a per-AgentSession bearer-token registry.
Package tokens maintains a per-AgentSession bearer-token registry.
metaagent
Package metaagent holds the metaagent module's quarantined input types.
Package metaagent holds the metaagent module's quarantined input types.
metaagent/capability
Package capability holds the metaagent's capability registry: the closed set of session changes an utterance can be classified into.
Package capability holds the metaagent's capability registry: the closed set of session changes an utterance can be classified into.
metaagent/capability/lifecycle
Package lifecycle is the metaagent's subtractive capability: stop the run, revoke a phase approval.
Package lifecycle is the metaagent's subtractive capability: stop the run, revoke a phase approval.
metaagent/capability/scope
Package scope is the metaagent's session-scope capability.
Package scope is the metaagent's session-scope capability.
platform/apimage
Package apimage is the single source of truth for oap's first-party container images: their CLI build-target names, image names, local :dev tags, Dockerfiles, and build contexts.
Package apimage is the single source of truth for oap's first-party container images: their CLI build-target names, image names, local :dev tags, Dockerfiles, and build contexts.
platform/artifacts
Package artifacts holds the cross-cutting versioning logic shared by the artifact_* meta tools, respond_to_user attachment resolution, and the oap artifact CLI.
Package artifacts holds the cross-cutting versioning logic shared by the artifact_* meta tools, respond_to_user attachment resolution, and the oap artifact CLI.
platform/artifactstore/blob
Package blob implements artifactstore.Store over gocloud.dev/blob, giving one implementation across GCS (gs://), S3 (s3://), Azure Blob (azblob://), local disk (file://), and in-process memory (mem://).
Package blob implements artifactstore.Store over gocloud.dev/blob, giving one implementation across GCS (gs://), S3 (s3://), Azure Blob (azblob://), local disk (file://), and in-process memory (mem://).
platform/builderbundle
Package builderbundle assembles the builder .oap: the locked-down agent-builder AgentClass, its workshop SidecarToolbox, the workshop AgentUI, its page compiled from src/ui/page.tsx, and the eight builder-phase Skills, all embedded at build time from src/.
Package builderbundle assembles the builder .oap: the locked-down agent-builder AgentClass, its workshop SidecarToolbox, the workshop AgentUI, its page compiled from src/ui/page.tsx, and the eight builder-phase Skills, all embedded at build time from src/.
platform/capacityfit
Package capacityfit answers "this SpiceboxClass requests more of some resource than this cluster's largest node has — what install-time question should ask the operator to lower it?"
Package capacityfit answers "this SpiceboxClass requests more of some resource than this cluster's largest node has — what install-time question should ask the operator to lower it?"
platform/capacityfit/hook
Package hook builds the install.InstallOpts.ExtraQuestions closure every .oap install surface (the CLI, the macOS desktop installer, admind) wires in unchanged: resolve this cluster's scheduling ceiling once, then hand pkg/platform/capacityfit.Questions the CRs it is asked about plus a seam to read back an already-installed SpiceboxClass.
Package hook builds the install.InstallOpts.ExtraQuestions closure every .oap install surface (the CLI, the macOS desktop installer, admind) wires in unchanged: resolve this cluster's scheduling ceiling once, then hand pkg/platform/capacityfit.Questions the CRs it is asked about plus a seam to read back an already-installed SpiceboxClass.
platform/cloud
Package cloud is the cloud-aware install layer for agentprimitives.
Package cloud is the cloud-aware install layer for agentprimitives.
platform/cloud/aks
Package aks implements the cloud.Strategy for Azure Kubernetes Service clusters.
Package aks implements the cloud.Strategy for Azure Kubernetes Service clusters.
platform/cloud/certmanager
Package certmanager implements the cert-manager + Let's Encrypt TLS strategy for webd's external-access Gateway.
Package certmanager implements the cert-manager + Let's Encrypt TLS strategy for webd's external-access Gateway.
platform/cloud/desktop
Package desktop implements the cloud.Strategy for `oap desktop`'s guest cluster: a network-confined, single-user VM (loopback port-forward only, no public ingress), as against `oap init --local`, which tunnels the same lightweight dev profile publicly.
Package desktop implements the cloud.Strategy for `oap desktop`'s guest cluster: a network-confined, single-user VM (loopback port-forward only, no public ingress), as against `oap init --local`, which tunnels the same lightweight dev profile publicly.
platform/cloud/eks
Package eks implements the cloud.Strategy for Amazon EKS clusters.
Package eks implements the cloud.Strategy for Amazon EKS clusters.
platform/cloud/gke
Package gke provides GKE-specific implementations of pkg/platform/cloud strategies.
Package gke provides GKE-specific implementations of pkg/platform/cloud strategies.
platform/cloud/local
Package local implements the cloud.Strategy for the lightweight developer kind: sqlite memory, an in-memory SpiceDB datastore, a file:// artifact PVC, local :dev images, no digest pinning.
Package local implements the cloud.Strategy for the lightweight developer kind: sqlite memory, an in-memory SpiceDB datastore, a file:// artifact PVC, local :dev images, no digest pinning.
platform/cloud/unmanaged
Package unmanaged implements the cloud.Strategy fallback for clusters that are not identified as a big-three managed cloud (e.g.
Package unmanaged implements the cloud.Strategy fallback for clusters that are not identified as a big-three managed cloud (e.g.
platform/deplogs
Package deplogs disables zerolog's process-global logger for dependencies that use it, so library chatter cannot reach terminals or component logs.
Package deplogs disables zerolog's process-global logger for dependencies that use it, so library chatter cannot reach terminals or component logs.
platform/extract
Package extract turns an uploaded file into agent-readable text.
Package extract turns an uploaded file into agent-readable text.
platform/extract/extractordclient
Package extractordclient is the HTTP client internal/cmd/operator dials extractord (internal/cmd/extractord) with — the network counterpart to pkg/platform/extract's MIME registry, which extractord wraps as a zero-egress HTTP service.
Package extractordclient is the HTTP client internal/cmd/operator dials extractord (internal/cmd/extractord) with — the network counterpart to pkg/platform/extract's MIME registry, which extractord wraps as a zero-egress HTTP service.
platform/extract/tabula
Package tabula adapts github.com/tsawler/tabula (MIT; pure Go on the build path used here — OCR support lives behind the library's own "ocr" build tag, which pulls in a CGO Tesseract binding we never enable) to extract.Extractor.
Package tabula adapts github.com/tsawler/tabula (MIT; pure Go on the build path used here — OCR support lives behind the library's own "ocr" build tag, which pulls in a CGO Tesseract binding we never enable) to extract.Extractor.
platform/extract/text
Package text is the extract.Extractor for formats that are already text: no document-parsing library buys anything over reading to EOF and coercing to valid UTF-8.
Package text is the extract.Extractor for formats that are already text: no document-parsing library buys anything over reading to EOF and coercing to valid UTF-8.
platform/extract/ziparchive
Package ziparchive is the extract.Exploder for ZIP containers.
Package ziparchive is the extract.Exploder for ZIP containers.
platform/identity
Package identity is the single source of truth for the canonical user ID used across SpiceDB writes and CheckPermission calls.
Package identity is the single source of truth for the canonical user ID used across SpiceDB writes and CheckPermission calls.
platform/identity/agentidentity
Package agentidentity persists a replacement value for a credential an AgentIdentity owns — the agent's OWN shared secret, as distinct from the per-person credentials pkg/platform/identity/useridentity writes.
Package agentidentity persists a replacement value for a credential an AgentIdentity owns — the agent's OWN shared secret, as distinct from the per-person credentials pkg/platform/identity/useridentity writes.
platform/identity/authkind
Package authkind defines the per-prefix plug-in surface for AgentIdentity setup routing.
Package authkind defines the per-prefix plug-in surface for AgentIdentity setup routing.
platform/identity/authkind/cli
Package cli is the authkind impl for the "cli" prefix.
Package cli is the authkind impl for the "cli" prefix.
platform/identity/authkind/loader
Package loader blank-imports every authkind impl so a binary gets all of them registered with a single import.
Package loader blank-imports every authkind impl so a binary gets all of them registered with a single import.
platform/identity/authkind/mcp
Package mcp is the authkind impl for the "mcp" prefix.
Package mcp is the authkind impl for the "mcp" prefix.
platform/identity/authkind/registry
Package registry holds the global authkind registry.
Package registry holds the global authkind registry.
platform/identity/authkind/sidecartoolbox
Package sidecartoolbox is the authkind impl for the "toolbox" prefix.
Package sidecartoolbox is the authkind impl for the "toolbox" prefix.
platform/identity/authkind/toolspec
Package toolspec is the authkind impl for the "toolspec" prefix.
Package toolspec is the authkind impl for the "toolspec" prefix.
platform/identity/broker
Package broker defines the token broker: the single seam that turns credential descriptors into injectable tool tokens; the in-process implementation lives in ./inproc.
Package broker defines the token broker: the single seam that turns credential descriptors into injectable tool tokens; the in-process implementation lives in ./inproc.
platform/identity/broker/inproc
Package inproc is the in-process token broker implementation.
Package inproc is the in-process token broker implementation.
platform/identity/credhost
Package credhost answers one question: may this credential be sent to this host?
Package credhost answers one question: may this credential be sent to this host?
platform/identity/credkind
Package credkind is the pluggable driver surface for identity credential types — one Kind per value of AgentCredential.Type / CredentialSource.Type.
Package credkind is the pluggable driver surface for identity credential types — one Kind per value of AgentCredential.Type / CredentialSource.Type.
platform/identity/credkind/federated
Package federated implements the credkind.Kind for type=federated: a credential minted per resolve via an ID-JAG token exchange rather than read from a Secret.
Package federated implements the credkind.Kind for type=federated: a credential minted per resolve via an ID-JAG token exchange rather than read from a Secret.
platform/identity/credkind/githubapp
This file implements the credkind.Kind for type=githubApp: a credential minted on demand from a stored GitHub App private key rather than read directly from a Secret.
This file implements the credkind.Kind for type=githubApp: a credential minted on demand from a stored GitHub App private key rather than read directly from a Secret.
platform/identity/credkind/imports
Package imports blank-imports every credkind so a binary gets the full registry with a single import.
Package imports blank-imports every credkind so a binary gets the full registry with a single import.
platform/identity/credkind/oauth
Package oauth implements the credkind.Kind for type=oauth: a token bundle stored under a FIXED multi-key Secret shape (access_token, refresh_token, expires_at, token_endpoint, client_id, scope).
Package oauth implements the credkind.Kind for type=oauth: a token bundle stored under a FIXED multi-key Secret shape (access_token, refresh_token, expires_at, token_endpoint, client_id, scope).
platform/identity/credkind/registry
Package registry is the process-wide credential-kind registry.
Package registry is the process-wide credential-kind registry.
platform/identity/credkind/registry/registrytest
Package registrytest provides shared credkind registry test helpers, so packages whose tests need to Reset() the registry (to probe an unregistered-type or empty-registry failure mode) don't each hand-roll the same save/restore.
Package registrytest provides shared credkind registry test helpers, so packages whose tests need to Reset() the registry (to probe an unregistered-type or empty-registry failure mode) don't each hand-roll the same save/restore.
platform/identity/credkind/static
Package static implements the credkind.Kind for type=static: a single value read from one named key of one Secret.
Package static implements the credkind.Kind for type=static: a single value read from one named key of one Secret.
platform/identity/credresolve
descriptors.go — the shared, kind-agnostic credential resolver.
descriptors.go — the shared, kind-agnostic credential resolver.
platform/identity/credupdate
Package credupdate holds the credential-update determination: the decision about whether an agent's claim that a credential has died justifies putting a credential-entry form in front of a human.
Package credupdate holds the credential-update determination: the decision about whether an agent's claim that a credential has died justifies putting a credential-entry form in front of a human.
platform/identity/externaltoken
Package externaltoken derives the SpiceDB object id and value hash used by the externaltoken token-use authorization grant.
Package externaltoken derives the SpiceDB object id and value hash used by the externaltoken token-use authorization grant.
platform/identity/federation
Package federation derives an upstream resource access token from a user's enterprise identity via the ID-JAG two-legged exchange (RFC 8693 token-exchange at the IdP → JWT authorization grant at the resource AS).
Package federation derives an upstream resource access token from a user's enterprise identity via the ID-JAG two-legged exchange (RFC 8693 token-exchange at the IdP → JWT authorization grant at the resource AS).
platform/identity/federation/fake
Package fake is a deterministic federation.Minter for tests.
Package fake is a deterministic federation.Minter for tests.
platform/identity/federation/idjag
Package idjag is the vendor-neutral ID-JAG (Identity Assertion JWT Authorization Grant, draft-ietf-oauth-identity-assertion-authz-grant) federation.Minter.
Package idjag is the vendor-neutral ID-JAG (Identity Assertion JWT Authorization Grant, draft-ietf-oauth-identity-assertion-authz-grant) federation.Minter.
platform/identity/idp
Package idp defines the pluggable human-login identity-provider seam: cluster config (ClusterIdentityProvider) names a Kind; the Kind constructs a Provider; identityd drives Begin/Complete and enforces email-verified + allowed-domain policy on the result.
Package idp defines the pluggable human-login identity-provider seam: cluster config (ClusterIdentityProvider) names a Kind; the Kind constructs a Provider; identityd drives Begin/Complete and enforces email-verified + allowed-domain policy on the result.
platform/identity/idp/fakekind
Package fakekind registers an in-process idp kind for tests and the e2e harness.
Package fakekind registers an in-process idp kind for tests and the e2e harness.
platform/identity/idp/googlekind
Package googlekind is the "google" idp kind: the generic oidc kind preset with Google's pinned issuer, an hd= login hint, and a server-side re-check of the hd claim (the hint is UX; the claim check is the enforcement).
Package googlekind is the "google" idp kind: the generic oidc kind preset with Google's pinned issuer, an hd= login hint, and a server-side re-check of the hd claim (the hint is UX; the claim check is the enforcement).
platform/identity/idp/idpscreens
Package idpscreens holds the questions more than one identity-provider kind asks — "which client did you register, what is its secret, and who may sign in with it?" — described once instead of once per kind.
Package idpscreens holds the questions more than one identity-provider kind asks — "which client did you register, what is its secret, and who may sign in with it?" — described once instead of once per kind.
platform/identity/idp/oidckind
Package oidckind implements the generic OIDC idp kind — issuer discovery + code exchange + ID-token verification via go-oidc.
Package oidckind implements the generic OIDC idp kind — issuer discovery + code exchange + ID-token verification via go-oidc.
platform/identity/idp/oidckind/oidctest
Package oidctest provides a fake OIDC issuer (httptest.Server) for testing the oidc and google idp kinds.
Package oidctest provides a fake OIDC issuer (httptest.Server) for testing the oidc and google idp kinds.
platform/identity/idp/passwordkind
Package passwordkind implements the "password" idp.Kind: a non-federated, password-only local IdP for the single-user macOS desktop's /admin console.
Package passwordkind implements the "password" idp.Kind: a non-federated, password-only local IdP for the single-user macOS desktop's /admin console.
platform/identity/passthrough
Package passthrough is the canonical resolver for "which credentials does this AgentClass require under identityMode=userPassthrough?"
Package passthrough is the canonical resolver for "which credentials does this AgentClass require under identityMode=userPassthrough?"
platform/identity/passthroughcatalog
Package passthroughcatalog provides MCPServer-by-credential-name lookup helpers shared between identityd (which routes credential link clicks to the OAuth or PAT flow based on the source MCPServer's Spec.Auth) and channelsd's credential_request watcher (which partitions the missing credentials into per-credential buttons by the same lookup).
Package passthroughcatalog provides MCPServer-by-credential-name lookup helpers shared between identityd (which routes credential link clicks to the OAuth or PAT flow based on the source MCPServer's Spec.Auth) and channelsd's credential_request watcher (which partitions the missing credentials into per-credential buttons by the same lookup).
platform/identity/passthroughlink
Package passthroughlink mints + verifies HMAC-signed deep-links that channelsd sends a passthrough-session's starter and identityd consumes.
Package passthroughlink mints + verifies HMAC-signed deep-links that channelsd sends a passthrough-session's starter and identityd consumes.
platform/identity/passthroughlink/sessionviewlink
Package sessionviewlink mints purpose="session_view" signed deep-links: a long-lived (7-day), shareable bearer capability for the session-view page (pkg/web/webui/sessionview), the shared-transcript mirror of a source channel's conversation.
Package sessionviewlink mints purpose="session_view" signed deep-links: a long-lived (7-day), shareable bearer capability for the session-view page (pkg/web/webui/sessionview), the shared-transcript mirror of a source channel's conversation.
platform/identity/passthroughlink/viewlink
Package viewlink mints webd artifact-view deep-links from a passthroughlink Signer + a live webd base URL.
Package viewlink mints webd artifact-view deep-links from a passthroughlink Signer + a live webd base URL.
platform/identity/provider
Package provider defines the /providers/ library shape and the compile-time embedded catalog of builtin providers.
Package provider defines the /providers/ library shape and the compile-time embedded catalog of builtin providers.
platform/identity/refresh
Package refresh runs RFC 6749 refresh-token grants against an oauth credential's stored token_endpoint, writing the new access_token / refresh_token / expires_at back to the Secret atomically.
Package refresh runs RFC 6749 refresh-token grants against an oauth credential's stored token_endpoint, writing the new access_token / refresh_token / expires_at back to the Secret atomically.
platform/identity/setup
Package setup is the credential-acquisition engine.
Package setup is the credential-acquisition engine.
platform/identity/setup/builtins
Package builtins holds Go-coded setup flows for curated providers.
Package builtins holds Go-coded setup flows for curated providers.
platform/identity/setup/builtins/anthropic_oauth
Package anthropic_oauth is the builtin Go flow for the anthropic-oauth provider.
Package anthropic_oauth is the builtin Go flow for the anthropic-oauth provider.
platform/identity/setup/builtins/flowscreens
Package flowscreens holds the steps more than one credential-setup flow takes: "open the page where this is generated", plus the flow-specific vocabulary a tui.Question is configured with — which address a provider documents itself at, and what shape its token has.
Package flowscreens holds the steps more than one credential-setup flow takes: "open the page where this is generated", plus the flow-specific vocabulary a tui.Question is configured with — which address a provider documents itself at, and what shape its token has.
platform/identity/setup/builtins/github_pat
Package github_pat is the builtin Go flow for the github-pat provider.
Package github_pat is the builtin Go flow for the github-pat provider.
platform/identity/setup/builtins/kubectl_kubeconfig
Package kubectl_kubeconfig is the builtin Go flow for the kubectl-kubeconfig provider.
Package kubectl_kubeconfig is the builtin Go flow for the kubectl-kubeconfig provider.
platform/identity/setup/builtins/loader
Package loader blank-imports every v1 builtin flow so binaries get all of them registered with a single import.
Package loader blank-imports every v1 builtin flow so binaries get all of them registered with a single import.
platform/identity/setup/builtins/oauth_mcp
Package oauth_mcp is the builtin Go flow for the oauth-mcp provider.
Package oauth_mcp is the builtin Go flow for the oauth-mcp provider.
platform/identity/setup/builtins/onepassword_scim
Package onepassword_scim is the builtin Go flow for the onepassword-scim provider.
Package onepassword_scim is the builtin Go flow for the onepassword-scim provider.
platform/identity/setup/builtins/slack_bot_token
Package slack_bot_token is the builtin Go flow for the slack-bot-token provider.
Package slack_bot_token is the builtin Go flow for the slack-bot-token provider.
platform/identity/setup/builtins/tailscale_authkey
Package tailscale_authkey is the builtin Go flow for the tailscale-authkey provider.
Package tailscale_authkey is the builtin Go flow for the tailscale-authkey provider.
platform/identity/setup/llmagent
Package llmagent runs the LLM-driven setup agent for any requirement that lacks a builtin Go flow.
Package llmagent runs the LLM-driven setup agent for any requirement that lacks a builtin Go flow.
platform/identity/setup/llmagent/tools
Package tools holds the LLM-tool implementations for the setup agent.
Package tools holds the LLM-tool implementations for the setup agent.
platform/identity/subjectresolve
Package subjectresolve resolves an agent-supplied user REFERENCE to a canonical platform user, server-side, against records the platform already trusts — never an agent-claimed mapping.
Package subjectresolve resolves an agent-supplied user REFERENCE to a canonical platform user, server-side, against records the platform already trusts — never an agent-claimed mapping.
platform/identity/useridentity
Package useridentity persists credentials on the cluster-scoped UserIdentity CRD and its master credential Secrets, and holds the naming helpers every component derives those names with.
Package useridentity persists credentials on the cluster-scoped UserIdentity CRD and its master credential Secrets, and holds the naming helpers every component derives those names with.
platform/identityd
The AGENT-OWNED half of the credential_update deep-link flow.
The AGENT-OWNED half of the credential_update deep-link flow.
platform/identityd/icons
Package icons hosts identityd's favicon discovery + cache + serve pipeline.
Package icons hosts identityd's favicon discovery + cache + serve pipeline.
platform/kube
Package kube holds small Kubernetes client-config helpers shared by the cmd/ server binaries (channelsd, webd).
Package kube holds small Kubernetes client-config helpers shared by the cmd/ server binaries (channelsd, webd).
platform/kubeyaml
Package kubeyaml splits a multi-document Kubernetes YAML (or JSON) stream into unstructured objects.
Package kubeyaml splits a multi-document Kubernetes YAML (or JSON) stream into unstructured objects.
platform/manifests
Package manifests embeds the kustomize-rendered operator install YAML.
Package manifests embeds the kustomize-rendered operator install YAML.
platform/manifests/crdschematest
Package crdschematest reads field schemas out of the SHIPPED install bundle, so a test asserting a CRD default or enum derives it from generated YAML rather than from the Go marker it is supposed to be checking.
Package crdschematest reads field schemas out of the SHIPPED install bundle, so a test asserting a CRD default or enum derives it from generated YAML rather than from the Go marker it is supposed to be checking.
platform/nats
Package nats provides NATS decentralized-JWT identity generation, per-client user-JWT minting, TLS material, and a connection helper.
Package nats provides NATS decentralized-JWT identity generation, per-client user-JWT minting, TLS material, and a connection helper.
platform/nats/natstest
Package natstest answers one question for tests: given a minted nats.UserGrant, does the NATS server permit this subject?
Package natstest answers one question for tests: given a minted nats.UserGrant, does the NATS server permit this subject?
platform/nats/subjects
Package subjects owns the NATS subject grammar: every subject any AP component publishes on or subscribes to is spelled here, once, and both its concrete and its wildcard form derive from that one spelling.
Package subjects owns the NATS subject grammar: every subject any AP component publishes on or subscribes to is spelled here, once, and both its concrete and its wildcard form derive from that one spelling.
platform/oap
Package oap defines the .oap agent-container format: a single-file, OCI-native bundle describing one AgentClass and its dependency graph.
Package oap defines the .oap agent-container format: a single-file, OCI-native bundle describing one AgentClass and its dependency graph.
platform/oap/channelplan
Package channelplan is everything about a bundle's DECLARED channels (oap.Requires.Channels) that needs the channel-kind registry: linting the declaration today, and planning the install-time wizard runs it drives next.
Package channelplan is everything about a bundle's DECLARED channels (oap.Requires.Channels) that needs the channel-kind registry: linting the declaration today, and planning the install-time wizard runs it drives next.
platform/oap/install
Package install implements the fail-closed checks that gate a .oap install before any cluster write happens.
Package install implements the fail-closed checks that gate a .oap install before any cluster write happens.
platform/oap/instance
Package instance stamps install-identifying labels onto a bundle's CRs and, on --name/collision, prefixes their names and rewrites the naming cross-references between them so the graph stays internally consistent after the prefix is applied.
Package instance stamps install-identifying labels onto a bundle's CRs and, on --name/collision, prefixes their names and rewrites the naming cross-references between them so the graph stays internally consistent after the prefix is applied.
platform/oap/oci
Package oci pushes and pulls .oap agent containers (the OCI-layout tar produced by pkg/platform/oap.Pack) to and from OCI-compliant registries, using oras-go/v2 for the registry-protocol plumbing.
Package oci pushes and pulls .oap agent containers (the OCI-layout tar produced by pkg/platform/oap.Pack) to and from OCI-compliant registries, using oras-go/v2 for the registry-protocol plumbing.
platform/oap/questionscreen
Package questionscreen builds the tui.Screen that asks one oap.Question, whatever collected the question in the first place.
Package questionscreen builds the tui.Screen that asks one oap.Question, whatever collected the question in the first place.
platform/oap/source
Package source builds an oap.Bundle from a place that holds an agent — a folder on disk today, a live cluster (cluster.go), a registry later.
Package source builds an oap.Bundle from a place that holds an agent — a folder on disk today, a live cluster (cluster.go), a registry later.
platform/pipeline
Package pipeline is the generic session-lifecycle interceptor framework.
Package pipeline is the generic session-lifecycle interceptor framework.
platform/podspec
Package podspec builds a sandboxed corev1.Pod from a SpiceboxSession + resolved SpiceboxClass spec.
Package podspec builds a sandboxed corev1.Pod from a SpiceboxSession + resolved SpiceboxClass spec.
platform/podstatus
Package podstatus holds small, controller-agnostic readers over a Pod's runtime status.
Package podstatus holds small, controller-agnostic readers over a Pod's runtime status.
platform/preferences
Package preferences validates and resolves per-user agent preferences: the class-authored schema (AgentClass.spec.userPreferences), the platform admin's globals (AgentSettings.spec.classUserPreferences), and the user's saved values (the user_preference memory kind).
Package preferences validates and resolves per-user agent preferences: the class-authored schema (AgentClass.spec.userPreferences), the platform admin's globals (AgentSettings.spec.classUserPreferences), and the user's saved values (the user_preference memory kind).
platform/relsync
Package relsync defines the seam between the RelationshipSource reconciler and the directories it syncs.
Package relsync defines the seam between the RelationshipSource reconciler and the directories it syncs.
platform/schedfit
Package schedfit answers one question about a cluster: can it EVER schedule a pod that requests this much?
Package schedfit answers one question about a cluster: can it EVER schedule a pod that requests this much?
platform/settings
Package settings folds the four-tier chain — cluster, namespace, AgentClass, AgentSession — into one EffectiveSettings plus the Violations that fold produced.
Package settings folds the four-tier chain — cluster, namespace, AgentClass, AgentSession — into one EffectiveSettings plus the Violations that fold produced.
platform/startup
Package startup provides bounded-retry primitives for process startup steps that depend on other components becoming reachable.
Package startup provides bounded-retry primitives for process startup steps that depend on other components becoming reachable.
platform/workspace
Package workspace defines the Snapshotter interface for capturing and restoring AgentSession workspace PVC contents.
Package workspace defines the Snapshotter interface for capturing and restoring AgentSession workspace PVC contents.
platform/workspacekinds
Package workspacekinds defines the pluggable driver surface for workspace sources — the origin a per-session workspace is cut from (a git repo today; hg, blob storage, or a local directory tomorrow).
Package workspacekinds defines the pluggable driver surface for workspace sources — the origin a per-session workspace is cut from (a git repo today; hg, blob storage, or a local directory tomorrow).
platform/workspacekinds/git
Package git implements the git workspace-source driver: it builds the git commands to materialize a shared read-cache base, sync an overlay to the latest revision, and (Phase 4) apply overlay commits back to the origin.
Package git implements the git workspace-source driver: it builds the git commands to materialize a shared read-cache base, sync an overlay to the latest revision, and (Phase 4) apply overlay commits back to the origin.
platform/workspacekinds/registry
Package registry is the global lookup for workspace-source drivers.
Package registry is the global lookup for workspace-source drivers.
steelthread
Package steelthread captures a live agent session as a replayable bundle.
Package steelthread captures a live agent session as a replayable bundle.
tools/adoptkit
Package adoptkit marks CR-referenced Secrets/ConfigMaps as adopted by the operator — a metadata-only server-side-apply of the adoption label + a per-owner ownership annotation.
Package adoptkit marks CR-referenced Secrets/ConfigMaps as adopted by the operator — a metadata-only server-side-apply of the adoption label + a per-owner ownership annotation.
tools/apiadapter
Package apiadapter is the declarative HTTP-API adapter: a config describing a REST API's operations, and an executor that performs one of them.
Package apiadapter is the declarative HTTP-API adapter: a config describing a REST API's operations, and an executor that performs one of them.
tools/catalog
Package catalog loads a directory of toolkit YAML files and exposes them both as in-memory Toolkit structs and as compact summaries for LLM prompts.
Package catalog loads a directory of toolkit YAML files and exposes them both as in-memory Toolkit structs and as compact summaries for LLM prompts.
tools/cel
Package cel wraps the cel-go runtime with a fixed variable schema and helper function library.
Package cel wraps the cel-go runtime with a fixed variable schema and helper function library.
tools/contract
Package contract defines the kind plug-in surface that the unified `oap tools` CLI consumes.
Package contract defines the kind plug-in surface that the unified `oap tools` CLI consumes.
tools/exec
Package exec wraps client-go's remote command executor behind an interface so controllers can be tested with an in-process fake.
Package exec wraps client-go's remote command executor behind an interface so controllers can be tested with an in-process fake.
tools/exec/fake
Package fake provides an in-process fake for exec.Executor, used by controller and e2e tests.
Package fake provides an in-process fake for exec.Executor, used by controller and e2e tests.
tools/exec/remote
Package remote implements exec.Executor against the Kubernetes API server via the pods/exec subresource.
Package remote implements exec.Executor against the Kubernetes API server via the pods/exec subresource.
tools/kinds/mcp
Package mcp registers the MCPServer Kind with the global tools-kind registry.
Package mcp registers the MCPServer Kind with the global tools-kind registry.
tools/kinds/registry
Package registry holds the global tool-kind registry.
Package registry holds the global tool-kind registry.
tools/kinds/sandbox
Package sandbox registers the SpiceboxToolspec Kind with the global tools-kind registry.
Package sandbox registers the SpiceboxToolspec Kind with the global tools-kind registry.
tools/kinds/sidecartoolbox
Package sidecartoolbox registers the SidecarToolbox Kind with the global tools-kind registry.
Package sidecartoolbox registers the SidecarToolbox Kind with the global tools-kind registry.
tools/mcp/oauth
Package oauth implements OAuth 2.0 + PKCE (RFC 7636) helpers for MCP server authentication.
Package oauth implements OAuth 2.0 + PKCE (RFC 7636) helpers for MCP server authentication.
tools/mcp/probe
Package probe is the Streamable-HTTP MCP client used by the runner (sidecar + MCPServer tool synthesis and dispatch), the operator controllers (MCPServer / SidecarToolbox reachability), and the oap CLI.
Package probe is the Streamable-HTTP MCP client used by the runner (sidecar + MCPServer tool synthesis and dispatch), the operator controllers (MCPServer / SidecarToolbox reachability), and the oap CLI.
tools/mcp/render
Package render produces plain-language descriptions of one MCP tool's effective contract.
Package render produces plain-language descriptions of one MCP tool's effective contract.
tools/mcp/testing
Package testing provides an httptest-backed fake MCP server for probe, dispatch, controller, and CLI tests.
Package testing provides an httptest-backed fake MCP server for probe, dispatch, controller, and CLI tests.
tools/mcp/trust
Package trust renders SEP-1913 trust annotation snapshots in a compact human-readable form.
Package trust renders SEP-1913 trust annotation snapshots in a compact human-readable form.
tools/mcp/validator
Package validator orchestrates per-tool-call validation of MCP server invocations against an MCPServer spec, producing a Decision that mirrors the shape of pkg/tools/toolspec/validator.Decision.
Package validator orchestrates per-tool-call validation of MCP server invocations against an MCPServer spec, producing a Decision that mirrors the shape of pkg/tools/toolspec/validator.Decision.
tools/redact
Package redact replaces sensitive values with stable IDs and emits an ID→descriptor map.
Package redact replaces sensitive values with stable IDs and emits an ID→descriptor map.
tools/sandboxkinds
Package sandboxkinds is the pluggability seam for sandbox backends: the substrate a SpiceboxSession's tools actually execute in.
Package sandboxkinds is the pluggability seam for sandbox backends: the substrate a SpiceboxSession's tools actually execute in.
tools/sandboxkinds/agentsandbox
Package agentsandbox implements the agent-sandbox (sigs.k8s.io) backend: a Sandbox custom resource whose lifecycle a third-party controller owns.
Package agentsandbox implements the agent-sandbox (sigs.k8s.io) backend: a Sandbox custom resource whose lifecycle a third-party controller owns.
tools/sandboxkinds/conformance
Package conformance holds the assertions every sandbox backend must satisfy.
Package conformance holds the assertions every sandbox backend must satisfy.
tools/sandboxkinds/internal/shapecheck
Package shapecheck is a test-support sandbox backend modelling a provider OUTSIDE the cluster: an opaque ID handle, no Kubernetes client, no pod, a native file API and native snapshots.
Package shapecheck is a test-support sandbox backend modelling a provider OUTSIDE the cluster: an opaque ID handle, no Kubernetes client, no pod, a native file API and native snapshots.
tools/sandboxkinds/pod
Package pod implements the built-in sandbox backend: a corev1.Pod built by pkg/platform/podspec.
Package pod implements the built-in sandbox backend: a corev1.Pod built by pkg/platform/podspec.
tools/sandboxkinds/registry
Package registry is the process-wide sandbox-kind registry.
Package registry is the process-wide sandbox-kind registry.
tools/skillbundle
Package skillbundle is the content-addressed store for skill bundles (the gzipped tar of a skill directory: SKILL.md + scripts/ + assets/ + ...).
Package skillbundle is the content-addressed store for skill bundles (the gzipped tar of a skill directory: SKILL.md + scripts/ + assets/ + ...).
tools/skillbundle/memory
Package memory is the in-memory skillbundle.Store backend.
Package memory is the in-memory skillbundle.Store backend.
tools/skillbundle/postgres
Package postgres is the durable postgres skillbundle.Store backend.
Package postgres is the durable postgres skillbundle.Store backend.
tools/skills/canonical
Package canonical parses and manipulates canonical skill names.
Package canonical parses and manipulates canonical skill names.
tools/skills/materialize
Package materialize answers whether a Skill/ClusterSkill's non-local canonical name is actually backed by the SkillSource/ClusterSkillSource that produces it.
Package materialize answers whether a Skill/ClusterSkill's non-local canonical name is actually backed by the SkillSource/ClusterSkillSource that produces it.
tools/skills/skillfetch
Package skillfetch abstracts cloning a git repo at a ref and returning its files + the resolved commit SHA.
Package skillfetch abstracts cloning a git repo at a ref and returning its files + the resolved commit SHA.
tools/skills/skillmd
Package skillmd parses a SKILL.md document: a YAML frontmatter block fenced by "---" lines, followed by the Markdown body.
Package skillmd parses a SKILL.md document: a YAML frontmatter block fenced by "---" lines, followed by the Markdown body.
tools/skills/validate
Package validate enforces the agentskills.io frontmatter constraints plus the project's forward-compat rules (no XML tags, no reserved provider words), and cross-checks the frontmatter name against the canonical skill directory.
Package validate enforces the agentskills.io frontmatter constraints plus the project's forward-compat rules (no XML tags, no reserved provider words), and cross-checks the frontmatter name against the canonical skill directory.
tools/toolchain
Package toolchain defines the pluggable seam by which a resolved toolchain payload is delivered into a sandbox pod.
Package toolchain defines the pluggable seam by which a resolved toolchain payload is delivered into a sandbox pod.
tools/toolchain/claude
Package claude holds launcher-side logic specific to the "claude" toolchain (Claude Code, the inner coding agent running inside the sandbox).
Package claude holds launcher-side logic specific to the "claude" toolchain (Claude Code, the inner coding agent running inside the sandbox).
tools/toolchain/kinds/image
Package image delivers a toolchain payload by running the toolchain's own OCI image as an init container that copies the payload into a shared emptyDir, which the sandbox container then mounts read-only.
Package image delivers a toolchain payload by running the toolchain's own OCI image as an init container that copies the payload into a shared emptyDir, which the sandbox container then mounts read-only.
tools/toolchain/kinds/registry
Package registry is the process-local registry of toolchain delivery Kinds.
Package registry is the process-local registry of toolchain delivery Kinds.
tools/toolchain/resolve
Package resolve turns a class's toolchain names into self-contained, frozen mounts.
Package resolve turns a class's toolchain names into self-contained, frozen mounts.
tools/toolkitstream
Package toolkitstream defines the per-toolkit stream-parser plug-in surface.
Package toolkitstream defines the per-toolkit stream-parser plug-in surface.
tools/toolkitstream/registry
Package registry holds the global parser-factory registry.
Package registry holds the global parser-factory registry.
tools/toolspec
Package toolspec is the root of the tool-invocation validator.
Package toolspec is the root of the tool-invocation validator.
tools/toolspec/effect
Package effect models a subcommand's declared side-effects and resolves templated effect strings.
Package effect models a subcommand's declared side-effects and resolves templated effect strings.
tools/toolspec/llm
Package llm defines the Provider interface and shared request/response types.
Package llm defines the Provider interface and shared request/response types.
tools/toolspec/llm/fake
Package fake provides a fixture-driven Provider for tests.
Package fake provides a fixture-driven Provider for tests.
tools/toolspec/llm/promptlib
Package promptlib holds the prompt-building and JSON-response parsing helpers behind the toolspec llm.Provider.
Package promptlib holds the prompt-building and JSON-response parsing helpers behind the toolspec llm.Provider.
tools/toolspec/parser
Package parser contains the declarative argv parser and the builtin-parser registry.
Package parser contains the declarative argv parser and the builtin-parser registry.
tools/toolspec/parser/builtin
Package builtin is the registry for named in-tree parsers.
Package builtin is the registry for named in-tree parsers.
tools/toolspec/registry
Package registry resolves toolkit references for the operator.
Package registry resolves toolkit references for the operator.
tools/toolspec/render
Package render produces plain-language descriptions of ToolSpecs.
Package render produces plain-language descriptions of ToolSpecs.
tools/toolspec/spec
Package spec defines the ToolSpec type and its YAML loader.
Package spec defines the ToolSpec type and its YAML loader.
tools/toolspec/toolkit
Package toolkit defines the Toolkit type and its YAML loader.
Package toolkit defines the Toolkit type and its YAML loader.
tools/toolspec/validator
Package validator orchestrates parse → structured checks → CEL into a Decision.
Package validator orchestrates parse → structured checks → CEL into a Decision.
tools/websearch
Package websearch provides a swappable, client-dispatched interface for web-search and web-fetch capabilities the gen agent uses to discover CLI tools and MCP servers.
Package websearch provides a swappable, client-dispatched interface for web-search and web-fetch capabilities the gen agent uses to discover CLI tools and MCP servers.
tools/websearch/bravesearch
Package bravesearch implements websearch.Backend against the Brave Search API (api.search.brave.com/res/v1/web/search): a documented HTTP API, authenticated by a single subscription-token header, whose terms permit programmatic (non-browser) access — the three properties this package's backend was chosen for.
Package bravesearch implements websearch.Backend against the Brave Search API (api.search.brave.com/res/v1/web/search): a documented HTTP API, authenticated by a single subscription-token header, whose terms permit programmatic (non-browser) access — the three properties this package's backend was chosen for.
tools/websearch/registry
Package registry is the process-wide web-search-backend registry.
Package registry is the process-wide web-search-backend registry.
tools/workshopmcp
export.go: storeDraft, the sidecar half of the tuple-authorized draft-export route (Task 6, pkg/web/workshopdraftsrv).
export.go: storeDraft, the sidecar half of the tuple-authorized draft-export route (Task 6, pkg/web/workshopdraftsrv).
web/admind
Package admind is the operator-mounted admin API: live session aggregation (CRD watch + NATS overlay), cross-session audit queries, and session kill.
Package admind is the operator-mounted admin API: live session aggregation (CRD watch + NATS overlay), cross-session audit queries, and session kill.
web/admind/agentcred
Package agentcred is the wire contract for replacing an agent's OWN shared credential, plus the client half of it.
Package agentcred is the wire contract for replacing an agent's OWN shared credential, plus the client half of it.
web/admind/audit
Package audit normalizes memory entries from the audit-producing Kinds into one cross-session Event shape, via a per-memory-kind Mapper registry (repo convention: new variants register, consumers don't branch).
Package audit normalizes memory entries from the audit-producing Kinds into one cross-session Event shape, via a per-memory-kind Mapper registry (repo convention: new variants register, consumers don't branch).
web/admind/config
Package config is the resource-projector layer behind the admin UI's Config phase.
Package config is the resource-projector layer behind the admin UI's Config phase.
web/admind/config/projectors
Package projectors holds the per-CRD config.Projector implementations that sit behind the admin UI's Config phase.
Package projectors holds the per-CRD config.Projector implementations that sit behind the admin UI's Config phase.
web/admind/cost
Package cost provides a per-model token price map and cost estimator for the admin dashboard.
Package cost provides a per-model token price map and cost estimator for the admin dashboard.
web/admind/health
Package health computes the admin Overview's cluster-health snapshot: the live up/down state of each first-party platform component plus a namespace pod/replica rollup.
Package health computes the admin Overview's cluster-health snapshot: the live up/down state of each first-party platform component plus a namespace pod/replica rollup.
web/admind/overview
Package overview computes the admin dashboard's Overview payload: token rollups by model and by AgentClass, a 24-hour hourly token time-series, and the top-line KPI scalars.
Package overview computes the admin dashboard's Overview payload: token rollups by model and by AgentClass, a 24-hour hourly token time-series, and the top-line KPI scalars.
web/adminui
Package adminui is the webd plugin for the platform admin UI: the /admin React page plus /admin/api/* reverse-proxy routes to the operator-mounted admind API.
Package adminui is the webd plugin for the platform admin UI: the /admin React page plus /admin/api/* reverse-proxy routes to the operator-mounted admind API.
web/browsersession
Package browsersession creates the cluster objects a browser-channel AgentSession is made of: the ephemeral Channel, its owner-ref'd credentials Secret, and the AgentSession itself, plus the SpiceDB started_by relation that gives the session a resolvable owner.
Package browsersession creates the cluster objects a browser-channel AgentSession is made of: the ephemeral Channel, its owner-ref'd credentials Secret, and the AgentSession itself, plus the SpiceDB started_by relation that gives the session a resolvable owner.
web/gateway
Package gateway provides the streaming gRPC service that connects clients to active ToolCall exec streams in the operator.
Package gateway provides the streaming gRPC service that connects clients to active ToolCall exec streams in the operator.
web/localtunnel
Package localtunnel exposes a local TCP port as a public HTTPS URL for development workflows.
Package localtunnel exposes a local TCP port as a public HTTPS URL for development workflows.
web/localtunnel/ngrok
Package ngrok provides a Tunnel implementation backed by ngrok's Go agent SDK (golang.ngrok.com/ngrok/v2).
Package ngrok provides a Tunnel implementation backed by ngrok's Go agent SDK (golang.ngrok.com/ngrok/v2).
web/localtunnel/registry
Package registry is the process-wide tunnel-provider registry: it maps a PublicEndpointSpec.Provider name (e.g.
Package registry is the process-wide tunnel-provider registry: it maps a PublicEndpointSpec.Provider name (e.g.
web/localtunnel/stub
Package stub provides a deterministic Tunnel implementation for tests.
Package stub provides a deterministic Tunnel implementation for tests.
web/secretoutsrv
Package secretoutsrv exposes an authenticated operator HTTP endpoint that a runner POSTs a captured secret-output value to; the operator (NOT the runner) writes it into the per-session secret-output Secret.
Package secretoutsrv exposes an authenticated operator HTTP endpoint that a runner POSTs a captured secret-output value to; the operator (NOT the runner) writes it into the per-session secret-output Secret.
web/settingseditor
Package settingseditor is the server-agnostic core of the settings editor UI: validation aggregation over the admission-webhook checks plus the pure settings resolver, YAML round-trip for the raw editor, and SSA drift reporting.
Package settingseditor is the server-agnostic core of the settings editor UI: validation aggregation over the admission-webhook checks plus the pure settings resolver, YAML round-trip for the raw editor, and SSA drift reporting.
web/uibindings
Package uibindings is the data-binding resolver contract: the seam a declared component prop's binding (pkg/web/uicomponents.Binding) crosses to become a value, resolved SERVER-SIDE under the viewer's subject.
Package uibindings is the data-binding resolver contract: the seam a declared component prop's binding (pkg/web/uicomponents.Binding) crosses to become a value, resolved SERVER-SIDE under the viewer's subject.
web/uibindings/actionstate
Package actionstate is the "action" uibindings.Resolver: it answers "what is this declared action doing right now, for THIS viewer" out of the ui_action memory records the runner writes.
Package actionstate is the "action" uibindings.Resolver: it answers "what is this declared action doing right now, for THIS viewer" out of the ui_action memory records the runner writes.
web/uibindings/artifactref
Package artifactref is the "artifact" uibindings.Resolver: a read-only resolution of an artifact handle to its rendered bytes, scoped to the viewer's own session exactly the way the artifact-view page's own deps already resolve handles (internal/cmd/webd's artifactViewDeps.ResolveAssetURL) — a handle belonging to a different session simply isn't found within this scope, which is what makes it unresolvable rather than merely unauthorized.
Package artifactref is the "artifact" uibindings.Resolver: a read-only resolution of an artifact handle to its rendered bytes, scoped to the viewer's own session exactly the way the artifact-view page's own deps already resolve handles (internal/cmd/webd's artifactViewDeps.ResolveAssetURL) — a handle belonging to a different session simply isn't found within this scope, which is what makes it unresolvable rather than merely unauthorized.
web/uibindings/memoryref
Package memoryref is the "memory" uibindings.Resolver: a read-only memory.Query scoped to the viewer's own session.
Package memoryref is the "memory" uibindings.Resolver: a read-only memory.Query scoped to the viewer's own session.
web/uibindings/registry
Package registry is the process-wide binding-source resolver registry.
Package registry is the process-wide binding-source resolver registry.
web/uibindings/tool
Package tool is the "tool" uibindings.Resolver: it turns one agent-UI data binding into the same synchronous, readonly-gated app-tool call the runner already answers for MCP-UI widgets.
Package tool is the "tool" uibindings.Resolver: it turns one agent-UI data binding into the same synchronous, readonly-gated app-tool call the runner already answers for MCP-UI widgets.
web/uicomponents
Package uicomponents is the agent-UI component vocabulary: the closed set of renderable types an AgentUI declaration (author-written) or a view-model (agent-written) may name.
Package uicomponents is the agent-UI component vocabulary: the closed set of renderable types an AgentUI declaration (author-written) or a view-model (agent-written) may name.
web/uicomponents/component
Package component holds the Component type in a package that does NOT depend on pkg/web/uicomponents.
Package component holds the Component type in a package that does NOT depend on pkg/web/uicomponents.
web/uicomponents/registry
Package registry is the process-wide agent-UI component registry.
Package registry is the process-wide agent-UI component registry.
web/uidemo/leadflow
Package leadflow is a fabricated CRM MCP server used to demonstrate the agent-defined-UI leads console.
Package leadflow is a fabricated CRM MCP server used to demonstrate the agent-defined-UI leads console.
web/uigrant
Package uigrant computes which tools an agent-defined UI may invoke directly from a browser.
Package uigrant computes which tools an agent-defined UI may invoke directly from a browser.
web/uiselect
Package uiselect is the agent-UI binding selector language: the total, non-executing path expression a uicomponents.Binding uses to say WHICH part of a resolved source value fills a component prop.
Package uiselect is the agent-UI binding selector language: the total, non-executing path expression a uicomponents.Binding uses to say WHICH part of a resolved source value fills a component prop.
web/uiview
Package uiview turns an AgentUI CR plus the agent's stored Tier-1 fragments into the one merged declaration everything downstream reads: the browser bootstrap, a binding-path lookup, an action-name lookup, the live push, and the runner's own write-time validation.
Package uiview turns an AgentUI CR plus the agent's stored Tier-1 fragments into the one merged declaration everything downstream reads: the browser bootstrap, a binding-path lookup, an action-name lookup, the live push, and the runner's own write-time validation.
web/viewurn
Package viewurn owns the view-URN grammar: the stable string that names the browser/TUI surface a session-view inbound came from.
Package viewurn owns the view-URN grammar: the stable string that names the browser/TUI surface a session-view inbound came from.
web/webui
Package webui is the framework for webd's browser UIs: a registry of scoped, two-origin WebUI plug-ins served by one host binary.
Package webui is the framework for webd's browser UIs: a registry of scoped, two-origin WebUI plug-ins served by one host binary.
web/webui/agentui
actions.go serves POST /agent-ui/{ns}/{name}/actions: the browser's only way to INVOKE a declared agent-UI action — the WRITE half of the binding vocabulary, where data bindings (bindings.go) are read-only by construction.
actions.go serves POST /agent-ui/{ns}/{name}/actions: the browser's only way to INVOKE a declared agent-UI action — the WRITE half of the binding vocabulary, where data bindings (bindings.go) are read-only by construction.
web/webui/browserstart
Package browserstart is the ONE reserve -> create -> adopt sequence behind every browser-facing start route.
Package browserstart is the ONE reserve -> create -> adopt sequence behind every browser-facing start route.
web/webui/channelwebhook
Package channelwebhook mounts ONE route that accepts inbound HTTP deliveries for ANY channel kind implementing channelkinds.WebhookReceiver (see pkg/channels/channelkinds/webhook.go).
Package channelwebhook mounts ONE route that accepts inbound HTTP deliveries for ANY channel kind implementing channelkinds.WebhookReceiver (see pkg/channels/channelkinds/webhook.go).
web/webui/chat
Package chat is the transcript view's data plane: a webui.WebUI plugin serving the session-scoped read/write/websocket routes a conversation needs.
Package chat is the transcript view's data plane: a webui.WebUI plugin serving the session-scoped read/write/websocket routes a conversation needs.
web/webui/chatembed
Package chatembed serves the ONE-session browser chat as an embeddable page: GET /chat-embed/{ns}/{name} mounts the transcript data plane's chat view and the shell's startup line for that session, with no tabs, no header and no session list, so another same-origin page (the agent-builder's Test panel, through ap:chat) can frame it.
Package chatembed serves the ONE-session browser chat as an embeddable page: GET /chat-embed/{ns}/{name} mounts the transcript data plane's chat view and the shell's startup line for that session, with no tabs, no header and no session list, so another same-origin page (the agent-builder's Test panel, through ap:chat) can frame it.
web/webui/contenttoken
Package contenttoken mints + verifies short-lived HMAC capability tokens that gate webd's sandbox-origin artifact endpoints: /content (the primary artifact framed by the live-view), /artifacts/a/ (a same-session secondary artifact referenced from the primary via `artifact:HANDLE`), and /mcpui-content + /mcpui-host (an MCP-UI interactive widget framed by the session-view page).
Package contenttoken mints + verifies short-lived HMAC capability tokens that gate webd's sandbox-origin artifact endpoints: /content (the primary artifact framed by the live-view), /artifacts/a/ (a same-session secondary artifact referenced from the primary via `artifact:HANDLE`), and /mcpui-content + /mcpui-host (an MCP-UI interactive widget framed by the session-view page).
web/webui/cspassets
Package cspassets assembles the nonce-authorized <style>/<script> tags a page needs and derives the matching Content-Security-Policy from them.
Package cspassets assembles the nonce-authorized <style>/<script> tags a page needs and derives the matching Content-Security-Policy from them.
web/webui/health
Package health is a trivial built-in WebUI: a public GET /healthz on the trusted origin.
Package health is a trivial built-in WebUI: a public GET /healthz on the trusted origin.
web/webui/interact
Package interact is the webui.WebUI plugin serving the browser's authorized path to act on a session it can view: POST /session/{ns}/{name}/interact dispatches a decoded interaction kind (pkg/channels/interact) through layered, fail-closed gates, and GET /session/{ns}/{name}/interactions reports which kinds this class permits (gate order in handlers.go).
Package interact is the webui.WebUI plugin serving the browser's authorized path to act on a session it can view: POST /session/{ns}/{name}/interact dispatches a decoded interaction kind (pkg/channels/interact) through layered, fail-closed gates, and GET /session/{ns}/{name}/interactions reports which kinds this class permits (gate order in handlers.go).
web/webui/internal/wstest
Package wstest scales the websocket read deadlines the pkg/web/webui tests set on a connection, so a loaded or instrumented box lengthens them instead of failing them.
Package wstest scales the websocket read deadlines the pkg/web/webui tests set on a connection, so a loaded or instrumented box lengthens them instead of failing them.
web/webui/livemirror
Package livemirror holds the shared, session-agnostic logic for replaying a session's durable memory turns into the ordered timeline a live view renders — the piece every mirror of a live conversation (the built-in web chat, the read-only session-view page) needs identically.
Package livemirror holds the shared, session-agnostic logic for replaying a session's durable memory turns into the ordered timeline a live view renders — the piece every mirror of a live conversation (the built-in web chat, the read-only session-view page) needs identically.
web/webui/registry
Package registry holds the global WebUI registry.
Package registry holds the global WebUI registry.
web/webui/sessions
pkg/web/webui/sessions/list.go joins the sessions a subject may interact with (SpiceDB's answer, via LookupInteractableSessions) against their Kubernetes objects (class, phase, title, start time) to build the sidebar list GET /sessions and GET /sessions/api/sessions both render.
pkg/web/webui/sessions/list.go joins the sessions a subject may interact with (SpiceDB's answer, via LookupInteractableSessions) against their Kubernetes objects (class, phase, title, start time) to build the sidebar list GET /sessions and GET /sessions/api/sessions both render.
web/webui/sessionview
Package sessionview is the webui.WebUI plugin serving a SESSION-scoped (not artifact-scoped) shared live view: a read-only mirror of a session's conversation for a subject who can interact with it but was not the session's originating channel.
Package sessionview is the webui.WebUI plugin serving a SESSION-scoped (not artifact-scoped) shared live view: a read-only mirror of a session's conversation for a subject who can interact with it but was not the session's originating channel.
web/webui/webassets
Package webassets embeds the built web UI bundles (pkg/web/webui/webassets/dist, produced by Vite under web/) and exposes the asset filesystem + parsed manifest.
Package webassets embeds the built web UI bundles (pkg/web/webui/webassets/dist, produced by Vite under web/) and exposes the asset filesystem + parsed manifest.
web/workshopdraftsrv
Package workshopdraftsrv exposes the ONE operator route the agent-builder workshop sidecar's export_draft tool (plan 3b, Task 7) posts a drafted .oap bundle to:
Package workshopdraftsrv exposes the ONE operator route the agent-builder workshop sidecar's export_draft tool (plan 3b, Task 7) posts a drafted .oap bundle to:
web/workshopprojectsrv
Package workshopprojectsrv exposes the ONE operator route that lets an agent-builder workshop's builder session project a CREDENTIAL-FREE STAND-IN for another agent it may want to hand work to during REHEARSAL (agent-builder plan 9b, Task 1):
Package workshopprojectsrv exposes the ONE operator route that lets an agent-builder workshop's builder session project a CREDENTIAL-FREE STAND-IN for another agent it may want to hand work to during REHEARSAL (agent-builder plan 9b, Task 1):
web/workshopthreadsrv
Package workshopthreadsrv exposes the ONE operator route that lets an agent-builder workshop's builder session learn who else has already worked the conversation thread it was just pulled into (plan 9a, Task 1):
Package workshopthreadsrv exposes the ONE operator route that lets an agent-builder workshop's builder session learn who else has already worked the conversation thread it was just pulled into (plan 9a, Task 1):
web/workshoptranscriptsrv
Package workshoptranscriptsrv exposes the ONE operator route that lets an agent-builder workshop's builder session read back the transcript of a session run inside that workshop's own namespace to test what the builder built:
Package workshoptranscriptsrv exposes the ONE operator route that lets an agent-builder workshop's builder session read back the transcript of a session run inside that workshop's own namespace to test what the builder built:
x/besteffort
Package besteffort centralizes the "log-and-continue" idiom for operations whose failure is recoverable but whose silent loss would leave operators without diagnostics — AGENTS.md's "Never silently drop errors", learned from a respond_to_user envelope that failed in the channelsd → Slack chain and was swallowed by three layers of `_, _ = …`, leaving the user with no message and no log to grep.
Package besteffort centralizes the "log-and-continue" idiom for operations whose failure is recoverable but whose silent loss would leave operators without diagnostics — AGENTS.md's "Never silently drop errors", learned from a respond_to_user envelope that failed in the channelsd → Slack chain and was swallowed by three layers of `_, _ = …`, leaving the user with no message and no log to grep.
x/browser
Package browser opens a URL in the host's default browser — a single small, dependency-free utility with no better home.
Package browser opens a URL in the host's default browser — a single small, dependency-free utility with no better home.
x/browser/browsertest
Package browsertest is the one seam a test uses to observe or drive browser opening.
Package browsertest is the one seam a test uses to observe or drive browser opening.
x/celbudget
Package celbudget holds the runtime budget every compiled CEL program in this repo carries.
Package celbudget holds the runtime budget every compiled CEL program in this repo carries.
x/celconv
Package celconv converts cel-go evaluation results into plain Go values without asserting on cel-go's internal representations.
Package celconv converts cel-go evaluation results into plain Go values without asserting on cel-go's internal representations.
x/credmask
Package credmask masks credential material for operator-visible output — ToolCall.status.agent.injected[*].masked and the setup engine's "stored as <masked>" line.
Package credmask masks credential material for operator-visible output — ToolCall.status.agent.injected[*].masked and the setup engine's "stored as <masked>" line.
x/debug
Package debug builds the operator's PRODUCTION HTTP mux.
Package debug builds the operator's PRODUCTION HTTP mux.
x/envfallback
Package envfallback resolves an env var that has been renamed, while a deprecated old name still works.
Package envfallback resolves an env var that has been renamed, while a deprecated old name still works.
x/externalurl
Package externalurl provides a live-updating accessor for a service's externally reachable base URL.
Package externalurl provides a live-updating accessor for a service's externally reachable base URL.
x/keyid
Package keyid derives the content address of an Ed25519 public key: the stable identifier a signature carries so a verifier can look the key up, and the invariant that makes a key binding unforgeable — a registry refuses to bind an ID to a key that does not hash to it.
Package keyid derives the content address of an Ed25519 public key: the stable identifier a signature carries so a verifier can look the key up, and the invariant that makes a key binding unforgeable — a registry refuses to bind an ID to a key that does not hash to it.
x/kindregistry
Package kindregistry is the shared implementation behind the project's many string-keyed "kind" registries (channel kinds, artifact renderers, tool kinds, authkinds, idp kinds, pinning kinds, web UIs, toolkit-stream factories, …).
Package kindregistry is the shared implementation behind the project's many string-keyed "kind" registries (channel kinds, artifact renderers, tool kinds, authkinds, idp kinds, pinning kinds, web UIs, toolkit-stream factories, …).
x/llmpricing
Package llmpricing is the pricing-only entry point onto the canonical per-model registry in pkg/agent/llm/models, whose tables it projects.
Package llmpricing is the pricing-only entry point onto the canonical per-model registry in pkg/agent/llm/models, whose tables it projects.
x/safehttp
Package safehttp provides an SSRF-guarded *http.Client.
Package safehttp provides an SSRF-guarded *http.Client.
x/stringsx
Package stringsx holds small, dependency-free string helpers shared across packages that would otherwise duplicate a one-line utility rather than pull in an unrelated domain package just to reuse it.
Package stringsx holds small, dependency-free string helpers shared across packages that would otherwise duplicate a one-line utility rather than pull in an unrelated domain package just to reuse it.
Package providers exposes the embedded provider YAMLs.
Package providers exposes the embedded provider YAMLs.
test
e2e/internal/fakeoauth
Package fakeoauth provides an in-process OAuth/OIDC provider for tests + the Slice-3 OAuth E2E. It implements just enough of the OAuth dance to satisfy pkg/tools/mcp/oauth.Discover, the authorize+token endpoints, and dynamic client registration.
Package fakeoauth provides an in-process OAuth/OIDC provider for tests + the Slice-3 OAuth E2E. It implements just enough of the OAuth dance to satisfy pkg/tools/mcp/oauth.Discover, the authorize+token endpoints, and dynamic client registration.
envtestreap
Package envtestreap kills envtest apiserver/etcd processes that outlived the test binary that started them.
Package envtestreap kills envtest apiserver/etcd processes that outlived the test binary that started them.
oaptest
Package oaptest provides a shared, valid .oap bundle fixture for tests.
Package oaptest provides a shared, valid .oap bundle fixture for tests.
suitelock
Package suitelock serializes the heavyweight test suites across every git worktree of a checkout.
Package suitelock serializes the heavyweight test suites across every git worktree of a checkout.
testparallel
Package testparallel sizes `go test -p` for the envtest-backed tiers.
Package testparallel sizes `go test -p` for the envtest-backed tiers.
testpostgres
Package testpostgres spins up a PostgreSQL container for tests that need a real database, mirroring test/testspicedb's shape: one container per test BINARY (lazily, on first call), an explicit Stop() the package's TestMain calls after m.Run(), and a clean skip when the container cannot be started.
Package testpostgres spins up a PostgreSQL container for tests that need a real database, mirroring test/testspicedb's shape: one container per test BINARY (lazily, on first call), an explicit Stop() the package's TestMain calls after m.Run(), and a clean skip when the container cannot be started.
testspicedb
This file carries NO build tag, unlike the rest of the package, so tooling that never links the fixture itself — the magefile, a reaper — can still name the labels it filters on instead of copying the strings.
This file carries NO build tag, unlike the rest of the package, so tooling that never links the fixture itself — the magefile, a reaper — can still name the labels it filters on instead of copying the strings.
Package toolkits embeds the canonical CLI toolkit YAMLs that ship with the operator binary.
Package toolkits embeds the canonical CLI toolkit YAMLs that ship with the operator binary.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL