Skip to content

feat: agent execution realms — run agent steps through runner backends - #598

Open
hertznsk wants to merge 10 commits into
microsoft:mainfrom
hertznsk:agent-execution-realm
Open

hertznsk wants to merge 10 commits into
microsoft:mainfrom
hertznsk:agent-execution-realm

Conversation

@hertznsk

@hertznsk hertznsk commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Step 7 of the execution-architecture series tracked in #527: agent steps now execute through the runner-backend seam (RunnerBackend.run_agent), so an agent — together with its stdio MCP servers, skills, plugins, and session state — can run in a chosen execution realm instead of only in-process. Workflows without realm profiles behave byte-for-byte as before.

Execution realms

  • execution.profile on agent steps selects a realm: local (today's in-process behavior, unchanged), Docker, or ACA. Model provider and execution placement are orthogonal (provider: copilot|openai|claude + any realm).
  • Docker realm: a lease-lived runner container per (workspace lease, runner identity) serving requests over a docker exec streaming bridge to a loopback-bound runner — no published ports, works with a remote DOCKER_HOST, no bind mounts (skills/plugins arrive via the run bundle with staged path mapping into /workspace).
  • Wire protocol v2 with an honest /health handshake: a stale image fails at realm startup with a named rebuild instruction, not mid-run.

Runner

  • Agent component delivery: skill_directories, custom_agents, per-call env_overlay, and execution_id on the wire; the runner stops dropping components.
  • Multi-provider inner factory (copilot, openai, claude) with instance ownership keyed by the merged configuration; other providers get a named 400.
  • POST /interrupt with per-execution targeting: concurrent calls are interrupted individually, unknown ids 404, terminal ids 409, partial results framed honestly; hosts degrade gracefully on images without the feature.
  • Per-call secret hygiene: the redactor scrubs inner-provider credentials, env-overlay values, and MCP server env/header values from every frame and error.

Secrets

  • Agent-scope secret bindings deliver to remote realms through the per-call env overlay — precisely to the spawn environment of stdio MCP children, never to the model SDK, host, or runner process environment. Reserved credential names are rejected statically; undeliverable combinations (no reachable stdio MCP consumer) are rejected at compile/validate time, not at runtime.

ACA

  • Re-issued as an execution backend behind an environment-profile aca: block, with lease-owned session identifiers and the transport extracted from the provider.
  • Legacy provider: aca keeps working unchanged through a compatibility facade (identical wire requests and identifier semantics, verified by equivalence tests) and now emits a once-per-run deprecation notice pointing at the profile form.
  • The conductor.providers.aca_protocol shim is removed; imports migrate to conductor.runner.protocol.

Validation & pinning

  • Capability-driven compile/validate rules replace hardcoded backend checks; manifest pins realm material (runner image, inner provider) with None-exclusion so existing manifests are stable.
  • Full acceptance matrix: agent × {local, docker ± runner_image, aca} × {bare validate, validate --environment, compile, run}.

Tests & CI

  • Fake-runner contract matrix (NDJSON ordering, malformed streams, interrupt targeting, overlay isolation across overlapping calls, factory per provider), local byte-parity and zero-noise spies, canonical event-sequence parity between local and docker realms, streaming fake docker CLI (incl. Windows .cmd mechanics), and a docker-integration lane that builds the runner image from the PR head SHA (fetchability-checked) with staged-skill, concurrency, cancel-cleanup/sweep, and interrupt end-to-end cases.

Docs: docs/design/agent-realms.md, docs/configuration.md, docs/workflow-syntax.md, docs/providers/aca.md (deprecation + migration guide), runnable examples (examples/docker-agent-realm.yaml, examples/aca-profile.yaml), and a towncrier fragment.

Test plan

  • make test — full suite green (12,998 passed; the only parallel-mode failures are three known Rich-render wrapping flakes that pass serially).
  • make check — ruff + format + ty clean (4 pre-existing unused-ignore warnings in the untouched claude_agent_sdk.py).
  • make validate-examples green; conductor validate examples/docker-agent-realm.yaml --environment … resolves the realm offline.
  • Docker-integration tests pass against a real local daemon (remote-DOCKER_HOST case env-gated).
  • Windows-focused path/pipe handling audited (.cmd shim mechanics, binary-safe NDJSON pipes, case-insensitive host-path matching for staged mapping).

Part of the PR series for #527.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant