Landlord
Runs the building. The Landlord turns on compute when an agent is needed, brokers the agent’s turns, and turns it off again when the work is done. It builds and starts only what the Registrar has admitted.
- Design rules
- L1 to L6, §6.4
- Contracts offered
- 1
- Key flows
- 5
On the job
- Wakes an agent from zero and queues a second message behind the running one
- Brokers each turn over the /mailbox long-poll
- Warms down and scales to zero
- Pauses, kills and retires an agent in two stages
Not my job
- Decide who may wake an agent. That is the Bouncer.
- Decide whether the agent may spend. That is the Treasurer.
- Decide what may be built. That is the Registrar.
What Landlord does, step by step
Wake from zero
createRun is the single door every wake passes through: Discord, webhook, schedule, queue, MCP and the console.
A wake arrives. If its messageId already has a run, that run is returned with 200 and nothing starts.
The Landlord asks the Treasurer. Over budget returns 402 and no compute starts.
If the agent already has an active run, the new message is queued and the reply is 202.
The Landlord starts the agent’s task from its admitted image and tells the ingress the agent is starting.
In the container, the Secretary brings the notebook in.
Broker a turn
The agent never accepts an inbound connection. It asks for work.
The agent long-polls /mailbox. The Landlord answers with the next message or holds the request open.
When the turn ends, the agent posts its result through a run callback.
Run state changes are published for live viewing.
Warm down and sleep
Agents scale to zero. The ingress stays up.
No work arrives for the warm-down window.
The Secretary sends the notebook out.
The task stops and the Landlord tells the ingress the agent is idle.
Pause, kill and retire
Operational controls for an agent that must stop.
An operator or an agent owner presses pause. The control plane checks the privilege first.
The run is blocked and compute is stopped. A paused agent is not woken by any trigger.
Retirement runs in two stages (§6.4) and each stage is ledgered.
Build and register an admitted commit
The build is injected into the Registrar’s admission. The Landlord supplies it.
The build runs on the landing zone’s build service and pushes the image to its registry.
The Landlord creates the agent’s identity and its task definition or Cloud Run job.
Contracts Landlord keeps 1 offered
- createRun and the run lifecycleused by Gatekeeper, Bouncer, Timekeeper