Registrar
Keeps the register of every agent, skill and system, and decides what may be deployed. Only a pinned, admitted commit runs. The Registrar never builds an image and never answers an HTTP request.
- Design rules
- L3, L4, SK1 to SK5, E10
- Contracts offered
- 4
- Key flows
- 5
On the job
- Records each agent and pins its repository and commit
- Admits or refuses a commit, with a reason
- Registers skills and runs the factory’s checks on their code
- Keeps the versioned deployment configuration and the systems store
Not my job
- Build the image. The Landlord supplies the build.
- Decide who may deploy. That is the Bouncer.
What Registrar does, step by step
Register an agent
L3. The record holds a pinned source, never a moving branch.
An admin registers a repository. checkRepoUrl validates it.
The Registrar resolves the commit and stores the agent record as <registryDir>/<id>.json.
ContractAgentRegistry →The registration is ledgered.
Admit a commit
L4. Only a pinned, admitted commit deploys.
The build checks the commit is 40 hex characters, scans for hard-coded secrets, requires tests and runs them, then builds and pushes the image.
A refusal carries one reason: no_tests, tests_failed, source_unavailable, hardcoded_secret, build_failed, push_failed or not_supported.
The result and its reason are ledgered.
Adopt a shared skill
SK1 to SK5. A skill is code the factory checks before an agent may use it.
The skill’s manifest is fetched and its path checked.
SkillChecker runs the factory’s checks on the skill’s code. The landing zone supplies the build service that runs them.
Versions compare by semver; an agent adopts a version and the adoption is recorded.
Version an agent’s deployment configuration
SK3. The record that says how an agent runs, and who owns it.
Each change writes a new version under <agent>/<version>.json. configHash is stable when no owners are set.
The store is versioned, which allows point-in-time restore (R1).
The Bouncer reads the owner list from here to derive agent-owner.
Define a system
E10. A system is an external service the factory knows how to reach.
An admin defines a system. It is written through to <dir>/<id>/<version>.json with a ledger row for each change.
The Keymaster derives its connection provider from the system definition.
Contracts Registrar keeps 4 offered
- admitused by Landlord
- AgentRegistryused by Landlord, Keymaster
- VersionedConfigStoreused by Bouncer
- SystemsStoreused by Keymaster