Tag
#adr
27 pages tagged #adr.
Decisions adr/ 27 pages
Why the hub may POST one fixed sentence to a URL the operator runs when something starts waiting on the human, what that refines in the push deferral, and why Web Push stays deferred.
Why a version can be held live and mutated in place while an agent writes it, and why the artifact's public URL keeps serving the last sealed version throughout.
Every agent has an identity and a trust level; trusted reads all, untrusted is confined to its spaces.
Why an agent posting a question or an approval may say how long it can wait, why the hub then resolves that one item as itself, and why this is not retention.
The human interface is a responsive, mobile-first PWA served from the same binary.
Human and agent interaction is asynchronous mailboxes, with no real-time chat in v1.
Protected artifacts are encrypted in the browser; the server stores ciphertext only.
Why the hub carries what needs an agent's attention on the next tool result it makes, and offers standing subscriptions, instead of a push channel or a per-harness poll.
A single binary and a single engine, with no microservices, CRDTs, or consensus.
The agent surface is MCP; A2A is a later optional facade, not the base protocol.
No automatic expiry ships; the human is the garbage collector, and retention is a per-layer concept.
AgentFS is vendored and its engine patched so the binary links exactly one engine.
The hub store, session brains, and artifacts all run on the Turso Database Rust engine.
The default deployment is a container behind a reverse proxy; an embedded tailnet endpoint is optional and experimental.
The hub is the single writer per session file and serialises writers in process.
Why the UI is held by Playwright Test, Vitest, Stylelint, TypeScript and mutation testing rather than by pattern-matching scripts over source text.
The human surface keeps an in-app notification and a freshness stream instead of a browser push service.
Full-text search over the same engine backs both the MCP tools and the PWA.
Why the engine returns search rows unordered and the hub scores them, and what would change it.
A session brain has one owner, another agent takes it over or branches from it without the human, and the hub chooses which of the two it is.
stdio MCP is a proxy to the one running hub, a small CLI serves harness hooks, and both read the same env-style settings.
A calm, mailroom-like PWA with a fixed token set, a no-emoji rule, and an accessibility build gate.
An agent cannot leave unbounded open items on the human; the writer refuses past a configurable cap.
There is no vendor cloud and no brain off the node; the node is the central solution.
One AgentFS file per project behind the same wrapper, reached by the brain tools with a store argument and written with a content-hash compare-and-set.
A token names who is calling rather than which agent, every call authenticates, ordinary projects are open to any token, and a confidential project is reached by grant and is absent to everyone else.
The hub wraps the real AgentFS per session and is the single writer for each file.