Pimp My IDE / Garage Dispatch
Back to garage
September 25, 2026 | orchestration / harnesses / sandboxes

Your agent manifest is not the machine.

A declarative task can name the workspace and model. The harness still decides how the loop behaves. The runtime still owns isolation and lifecycle. The run still needs proof.

The take: Agent infrastructure gets easier to operate when each layer has one job. Do not let a clean manifest hide an unbounded loop, an untested sandbox, or a missing run receipt.
Open the Runtime Cutaway Bench

Declarative does not mean complete.

Google's AX repository describes three v1alpha1 resources: Task, Workspace, and Model. The task requests work. The workspace can pre-wire Git repositories, Model Context Protocol servers, and skill packages. The model resource holds the platform model configuration.[1]

That split is useful. It also stops before the agent loop. AX says its task runner starts the workspace and runs the agent command. The repository warns that its core concepts, protocols, and specifications can change before a stable release.[1]

The harness owns behavior.

Strands draws the next line. Its SDK runs in the application process and owns turn limits, token budgets, cancellation, stop reasons, tools, memory, sessions, tracing, and evaluations.[3] Those settings decide whether the agent stops, what it may call, and what evidence survives the run.

Scheduling starts the job. The harness decides how the job behaves after ignition.

A manifest that names a model but omits the harness version and loop policy cannot reproduce behavior. Record both. If the harness offers assembled defaults, export the resolved configuration rather than citing the package name alone.

The runtime owns containment and state.

AX runs on Agent Substrate. Substrate describes itself as an execution runtime, not an agent SDK. It maps stateful actors onto workers and manages creation, destruction, suspension, resumption, assignment, and routing.[2]

Substrate also says it is pre-1.0 and makes no backward-compatibility guarantee. Its published density and resume numbers are project claims tied to its own design and demos. They are not measurements of your cluster, workload, or security policy.[2]

Proof needs its own layer.

AX exposes task status and condition transitions through a watch call. Its design stores task state in Redis and sends work to horizontally scaled controllers, which drive tasks toward the requested state through Substrate.[4] A desired state and a live phase are operational facts. They do not prove that the code change was correct.

Keep a separate receipt with the manifest hash, harness version, resolved policy, sandbox image, network policy, task events, revision, test command, and test output. That receipt links what operators requested to what the agent did and what the repository accepted.

Use the four-boundary handoff.

  1. Declare the goal, workspace revision, model route, limits, and stop authority.
  2. Pin the harness package and save its resolved loop, tool, memory, and cancellation policy.
  3. Pin the runtime image and record isolation, network, credentials, state, lease, and cleanup rules.
  4. Attach task events, changed revision, tests, outputs, reviewer, and disposition.
Interactive makeover / architecture X-ray

Runtime Cutaway Bench.

Traditional purpose replaced: one architecture diagram that makes every box look equally responsible. Better version: move the X-ray carriage through four layers. Each detent names its owner, artifact, proof, and limit. The same state writes a copyable handoff card.

Move the X-ray carriage

Use the slider or the four layer buttons. Arrow keys move the slider one detent at a time. The selected layer is an inspection target, not a completion score.

DECLARELAYER 1 / 4
Primary ownerTask manifest and operator

Name the requested work.

Pin the goal, workspace revision, model route, resource limits, and stop authority.

ArtifactVersioned manifest plus workspace and model references
It provesWhat the control plane was asked to run
It does not proveResolved loop policy, containment, or task correctness
Handoff: pass immutable references and explicit ceilings to the harness layer.

Print the runtime handoff card

Before handoffReplace every required marker with a real ID, digest, policy, command, output, or decision. The selected layer changes the inspection focus. It does not fill evidence fields.

Sources read, not vibes

Open the source log
  1. Google AX repository and README: pre-stable warning, Task, Workspace, and Model resources, task lifecycle commands, Substrate prerequisite, and task-runner role.
  2. Agent Substrate repository and README: execution-runtime scope, actor-to-worker mapping, lifecycle responsibilities, sandbox options, project benchmark claims, and pre-1.0 compatibility warning.
  3. Strands Agents repository: in-process harness scope, loop controls, budgets, cancellation, stop reasons, tools, memory, sessions, tracing, evaluations, and resolved configuration.
  4. AX design document: Redis task state, stream-backed work queue, controller responsibilities, task runner, and watch, suspend, and resume calls.
  5. GitHub Trending, September 25, 2026: discovery source for AX and Strands. Trending placement is attention, not technical evidence.

Source boundary: AX and Agent Substrate describe pre-stable software. Their scale and performance statements are project claims, not independent measurements. Strands documents its own harness behavior. This dispatch combines the published ownership boundaries into an operating checklist. The cutaway is a teaching tool, not production telemetry.