Skip to content

Architecture

System Execution Architecture
Account-owned deployment · cloud validation pending
Stage 01 Entry Surfaces
Web Dashboard /app/

React 19 single-page app with task launcher, live diff review, and run inspector.

Slack ChatOps @AI Coworker

Interactive Block Kit approval cards and thread execution updates.

GitHub Webhook HMAC SHA-256

Signature-verified push and issue acknowledgment endpoint.

↓ Transport: Agent SDK RPC & WebSockets
Stage 02 Edge Orchestrator
CodingOrchestrator DO Think + Durable Object

Coordinates run state and approval-gated delegation; planning behavior depends on configured model/bindings.

Human Approval Gate needsApproval: true

Approval is required by default before dispatch; narrowly configured unattended automation is an exception.

Retained Run Registry /api/runs

Persistent run state, task parameters, duration tracking, and status timestamps.

↓ Approved Delegation: Spin Up Ephemeral Container
Stage 03 Isolated Sandbox
OpenCodeAgent AIChatAgent DO

Structured task envelope managing lifecycle phases: Clone → Configure → Code → Collect.

Cloudflare Sandbox gVisor MicroVM

Sandbox container with configured instance type, Git, and Node. The 2026-09-24 container dry run was blocked; cloud runtime validation is pending.

Multi-Harness Runtime OpenCode / Claude / Codex

Harness adapters are implemented; OpenCode was exercised locally through launch, while Claude Code and Codex have not completed live API runs.

↓ Provider egress forwarding (account credentials required)
Stage 04 Egress & Output
Cloudflare AI Gateway BYOK Credentials

Provider-backed harnesses receive dummy keys; Worker forwards supported provider traffic via the configured AI Gateway. Successful inference depends on account configuration.

Diff Collector Git Intent-to-Add

Captures unified diffs and changed files; packages clean commit envelope.

GitHub Pull Request REST Publication

Can publish an approved result as a PR when configured; cloud publication is not established by current verification.

The parent uses Workers AI for planning. Real model-provider and GitHub credentials are not supplied to the container by this implementation. Provider traffic is intercepted at Sandbox egress; there is no public /api/provider/google route. Access JWT verification and provider-forwarding controls are implemented and unit-tested. A forged Access identity header was rejected in a deployed-Worker check recorded 2026-09-24; no cloud end-to-end coding run is recorded. The diagram is an implementation map, not a production security certification.

Path Responsibility
apps/backend/src/index.ts Assets, SDK routes, run API, provider forwarding, webhook
apps/backend/src/agents/orchestrator.ts Planning, approval, delegation, retained registry
apps/backend/src/agents/opencode-agent.ts Sandbox SDK operations, progress and publishing
apps/backend/src/runtime.ts Clone, harness execution, bounded file/diff collection
apps/backend/src/provider-gateway.ts Provider request sanitization and forwarding helpers
apps/backend/src/github.ts GitHub REST publication
apps/backend/src/runs.ts and src/transcript.ts State and transcript helpers
apps/frontend/src/router.tsx, src/routes/__root.tsx, and src/routes/app.tsx TanStack Start dashboard shell and /app route
docs/ and scripts/ Static documentation and build checks

No D1, KV, Queues, R2, Postgres, Redis, or separate frontend service is required. State resides in Agents/Sandbox Durable Objects.

The runtime emits clone/configure/code/collect phases but awaits OpenCode execution; it does not stream every JSON event. The registry stores metadata and summary/error, not separate diff/file fields.

The specification requires Sandbox HTTPS interception, private Git transport credentials, and retained-registry gating of child routes. The present Worker proxy and direct SDK routing do not provide those guarantees. See Readiness.

The computer adapter is a guarded refusal, not an implemented runtime. The intended fit of @cloudflare/computer includes persistent SQLite-backed VFS, typed Git operations, agent tools, and Worker-shell/container backends. It is not installed here. Verify current APIs and preview status in the package documentation before implementing it. The code retains the preview-only warning and defaults to Sandbox.

celld is not a deployment target: Workers-compatible execution alone does not provide the managed Sandbox/Containers bindings this repository uses.

Official sources: Agents, Sandbox, Containers, AI Gateway.