Architecture
React 19 single-page app with task launcher, live diff review, and run inspector.
Interactive Block Kit approval cards and thread execution updates.
Signature-verified push and issue acknowledgment endpoint.
Coordinates run state and approval-gated delegation; planning behavior depends on configured model/bindings.
Approval is required by default before dispatch; narrowly configured unattended automation is an exception.
Persistent run state, task parameters, duration tracking, and status timestamps.
Structured task envelope managing lifecycle phases: Clone → Configure → Code → Collect.
Sandbox container with configured instance type, Git, and Node. The 2026-09-24 container dry run was blocked; cloud runtime validation is pending.
Harness adapters are implemented; OpenCode was exercised locally through launch, while Claude Code and Codex have not completed live API runs.
Provider-backed harnesses receive dummy keys; Worker forwards supported provider traffic via the configured AI Gateway. Successful inference depends on account configuration.
Captures unified diffs and changed files; packages clean commit envelope.
Can publish an approved result as a PR when configured; cloud publication is not established by current verification.
The parent uses Workers AI for planning. Real model-provider and GitHub credentials are not supplied to the container by this implementation. Provider traffic is intercepted at Sandbox egress; there is no public /api/provider/google route. Access JWT verification and provider-forwarding controls are implemented and unit-tested. A forged Access identity header was rejected in a deployed-Worker check recorded 2026-09-24; no cloud end-to-end coding run is recorded. The diagram is an implementation map, not a production security certification.
Source map
Section titled “Source map”| Path | Responsibility |
|---|---|
| apps/backend/src/index.ts | Assets, SDK routes, run API, provider forwarding, webhook |
| apps/backend/src/agents/orchestrator.ts | Planning, approval, delegation, retained registry |
| apps/backend/src/agents/opencode-agent.ts | Sandbox SDK operations, progress and publishing |
| apps/backend/src/runtime.ts | Clone, harness execution, bounded file/diff collection |
| apps/backend/src/provider-gateway.ts | Provider request sanitization and forwarding helpers |
| apps/backend/src/github.ts | GitHub REST publication |
| apps/backend/src/runs.ts and src/transcript.ts | State and transcript helpers |
| apps/frontend/src/router.tsx, src/routes/__root.tsx, and src/routes/app.tsx | TanStack Start dashboard shell and /app route |
| docs/ and scripts/ | Static documentation and build checks |
No D1, KV, Queues, R2, Postgres, Redis, or separate frontend service is required. State resides in Agents/Sandbox Durable Objects.
The runtime emits clone/configure/code/collect phases but awaits OpenCode execution; it does not stream every JSON event. The registry stores metadata and summary/error, not separate diff/file fields.
The specification requires Sandbox HTTPS interception, private Git transport credentials, and retained-registry gating of child routes. The present Worker proxy and direct SDK routing do not provide those guarantees. See Readiness.
Alternative runtimes
Section titled “Alternative runtimes”The computer adapter is a guarded refusal, not an implemented runtime. The intended fit of @cloudflare/computer includes persistent SQLite-backed VFS, typed Git operations, agent tools, and Worker-shell/container backends. It is not installed here. Verify current APIs and preview status in the package documentation before implementing it. The code retains the preview-only warning and defaults to Sandbox.
celld is not a deployment target: Workers-compatible execution alone does not provide the managed Sandbox/Containers bindings this repository uses.
Official sources: Agents, Sandbox, Containers, AI Gateway.
