Skip to content

Compare backend enforcement at the agent-flow contract boundary #28

Description

@nothingnesses

This issue records a proposal. Implementation requires a selected work brief and separate execution approval.

Background and problem

The retained architecture delegates invocation and isolation to provider-neutral backends. Existing agent-images nothingnesses/agent-images#154 already owns the proof that one existing image works with SmolVM.

The distinct agent-flow question concerns enforcement of a role launch contract, not image compatibility.

Proposal

After agreement on the contract, compare these backends on one bounded task:

  • smol-machines/smolvm.
  • Hardened direct Podman.
  • Hardened Agent-box.

Reuse relevant nothingnesses/agent-images#154 results. Do not repeat its image proof.

Scope and exclusions

Keep image outputs and compatibility work in agent-images. Exclude image publication and automatic backend adoption. OpenShell remains a later comparison reference, not a selected dependency.

Acceptance criteria

  • The comparison identifies exact versions and reproducible contract probes.
  • Probes cover:
    • Role-specific write access.
    • Credentials.
    • Network authority.
    • Termination.
    • Resource controls.
  • Worker attempts to bypass the launcher or alter protected state fail, or the report identifies the precise gap.
  • Missing or unsafe isolation refuses launch without unsandboxed fallback.
  • Results distinguish demonstrated behaviour from assumptions and recommend at most one candidate for separately approved implementation.

Alternatives and open questions

Direct Podman reduces integration work. MicroVM isolation adds a guest-kernel boundary and operational cost. Agent-box can reduce launcher work but needs equivalent hardening evidence. No winner precedes the comparison, under Ground decisions in evidence.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    proposalProposed work without implementation approval.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions