Control Plane
How request validation, workflow coordination, identity, policy, scheduling and durable execution state are intended to fit together.
Responsibilities
The control plane accepts and validates project requests, applies identity and permission checks, records workflow/task state, reserves budgets, selects a worker and tracks the current execution attempt. It is the coordinating authority, not the agent runtime itself.
Planned modules
- API gateway, request validation and idempotency keys.
- Project membership, roles and policy evaluation.
- Task manager with invariants and append-oriented event history.
- Workflow engine for dependencies, ready tasks and aggregation.
- Scheduler for worker filtering, ranking, capacity reservation and fenced leases.
- VPS registry for enrollment, labels, heartbeat, capacity and operational state.
- Secrets references, budget ledger, audit trail and approval records.
Durability model
PostgreSQL is the proposed source of truth. The design groups attempt creation, resource reservation, lease assignment and outbox event in a transaction. After a controller restart, the scheduler reads durable state and reconciles expired leases. A stale worker must not overwrite a newer fencing generation.
Local supervision is a separate layer
Agent Orchestrator can provide local session and adapter patterns. Distributed orchestration adds fleet identity, placement, cross-server durable state, reservations, lease expiry and recovery. Reusing a local supervisor does not supply these platform components.
Illustrative interface shape
Proposed API — Subject to Change{
"workflow": {
"state": "QUEUED",
"tasks": [{"key": "research-01", "capability": "research"}],
"policy": {"budget": "project-scoped", "approval": "required-for-risky-actions"}
}
}This JSON is an illustrative contract sketch, not a released endpoint or supported request format.