Control node and worker nodes
openagentix separates deciding from doing.
Control node (control plane)
Section titled “Control node (control plane)”The control node runs the API, the console, authentication and RBAC, the agent registry (all
published agents.md versions), event ingest, the scheduler and run queue, the policy engine
(audit gates and the control agent), the audit trail, the cost ledger and the metrics
endpoint.
It never executes tools itself. A compromised or misbehaving agent therefore never runs inside the process that holds the audit trail, the policies and the credentials catalogue.
Worker nodes (data plane)
Section titled “Worker nodes (data plane)”Each run (or each group of steps of a run) is executed by a short-lived worker that a runner starts. A worker:
- receives a prepared run: the agent definition, the event, a signed short-lived run token and references to the secrets it may use;
- calls the model provider and asks the control node’s policy gate before every tool call;
- streams every step back over an authenticated channel (mTLS or the signed run token);
- is torn down when the run ends; its scoped secrets are revoked.
┌──────────────── control node ────────────────┐ event ───▶ │ ingest → queue → policy engine → audit chain │ │ registry · costs · metrics · RBAC │ └───────▲───────────────┬──────────────────────┘ steps, │ │ run token, agent version, gate queries │ ▼ secret references ┌───────┴──────── worker node ─────────────────┐ │ toolbox image: only the tools this agent needs│ │ egress allowlisted · read-only · non-root │ └──────────────────────────────────────────────┘Toolbox images
Section titled “Toolbox images”Workers run in toolbox images: minimal images that contain only
the binaries an agent declares in runtime.toolbox, built from a catalogue, pinned by digest,
signed and scanned.
What is available when
Section titled “What is available when”| Piece | Status |
|---|---|
| Control node with the same interfaces as later releases | Available in 0.1 |
| In-process and local workers | Available in 0.1 |
| Spawned workers in containers and Kubernetes Jobs (incl. EKS) with toolbox images | Roadmap 0.2 |
| AWS Lambda and CI workers | Roadmap 0.3 |