This issue records a proposal. Implementation requires a selected work brief and separate execution approval.
Background and problem
The retained architecture delegates invocation and isolation to provider-neutral backends. Existing agent-images nothingnesses/agent-images#154 already owns the proof that one existing image works with SmolVM.
The distinct agent-flow question concerns enforcement of a role launch contract, not image compatibility.
Proposal
After agreement on the contract, compare these backends on one bounded task:
smol-machines/smolvm.
- Hardened direct Podman.
- Hardened Agent-box.
Reuse relevant nothingnesses/agent-images#154 results. Do not repeat its image proof.
Scope and exclusions
Keep image outputs and compatibility work in agent-images. Exclude image publication and automatic backend adoption. OpenShell remains a later comparison reference, not a selected dependency.
Acceptance criteria
- The comparison identifies exact versions and reproducible contract probes.
- Probes cover:
- Role-specific write access.
- Credentials.
- Network authority.
- Termination.
- Resource controls.
- Worker attempts to bypass the launcher or alter protected state fail, or the report identifies the precise gap.
- Missing or unsafe isolation refuses launch without unsandboxed fallback.
- Results distinguish demonstrated behaviour from assumptions and recommend at most one candidate for separately approved implementation.
Alternatives and open questions
Direct Podman reduces integration work. MicroVM isolation adds a guest-kernel boundary and operational cost. Agent-box can reduce launcher work but needs equivalent hardening evidence. No winner precedes the comparison, under Ground decisions in evidence.
References
This issue records a proposal. Implementation requires a selected work brief and separate execution approval.
Background and problem
The retained architecture delegates invocation and isolation to provider-neutral backends. Existing agent-images nothingnesses/agent-images#154 already owns the proof that one existing image works with SmolVM.
The distinct agent-flow question concerns enforcement of a role launch contract, not image compatibility.
Proposal
After agreement on the contract, compare these backends on one bounded task:
smol-machines/smolvm.Reuse relevant nothingnesses/agent-images#154 results. Do not repeat its image proof.
Scope and exclusions
Keep image outputs and compatibility work in agent-images. Exclude image publication and automatic backend adoption. OpenShell remains a later comparison reference, not a selected dependency.
Acceptance criteria
Alternatives and open questions
Direct Podman reduces integration work. MicroVM isolation adds a guest-kernel boundary and operational cost. Agent-box can reduce launcher work but needs equivalent hardening evidence. No winner precedes the comparison, under Ground decisions in evidence.
References