Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

System Patterns

Keep credentials behind a service

In the credential-proxy deployment, provider secrets live outside the agent. The agent sends placeholders; the proxy selects the destination route and injects the credential. Local and ordinary Docker launches deliberately hold credentials, so this is a property of the proxy deployment, not of core.

The proxy restricts HTTP by method and destination. With egress control enabled, GET, HEAD, OPTIONS and TRACE pass the method gate; every other method requires an allowed destination. This does not prove that an allowed request leaves external state unchanged.

Cowboy does not guarantee confidentiality of data the agent can read. A prompt-injected worker with permitted outbound access can disclose that data. Keeping provider keys outside the worker does not make its workspace private. See Security Model.

Separate proposal from authority

An agent can prepare a commit or request a rebuild. The bridge and configured host service perform the approved action with their own identity. For declared Git effects, the approval binds the commit and base that the host inspected; the apply step checks them again. See Gated Effects.

Extend configuration before core

Tools, skills, packages and bridges can be registered through Nix modules. Per-agent selectors determine who receives them; the current module interface provides accessors for enabled agents and their homes. Adding such an extension does not require changing the agent state machine. See Plugin Architecture.

Separate shared behavior from host affordances

The two hosts share agent state and semantic commands. Zellij owns terminal navigation; Montana owns the native control socket and component instances. A host must supply both effect handling and the filesystem access its guest uses. Host independence does not imply identical security boundaries.