Runtime isolation
Sessions run through the tenant's Substrate WorkerPool, using a gVisor sandbox class and a pinned Harness runtime. The platform no longer provides the separate MCP execute tool described by the retired execution design.
A session uses a worker
The tenant baseline declares a WorkerPool and a Harness that references it. The Harness selects the custom kagent runtime image and a tenant-scoped snapshot location. Substrate manages the session’s execution allocation and snapshot/resume lifecycle; an agent definition does not reserve a dedicated Deployment forever.
The configured sandbox class is gVisor. Network and credential policies are separate from this sandbox choice: gVisor alone does not prove that an actor has no credentials or cannot reach an endpoint. The control plane supplies narrowly scoped service access through Substrate’s credential provider and egress configuration. These grants need to agree with the gateway’s authorization.
Tools in this runtime
The custom runtime removes native bash and ask_user registration for both root agents and
subagents. File reading, writing and editing, and skill discovery/loading remain supported according
to the runtime’s configured capabilities. There is no advertised general shell or arbitrary code
execution service. A tool approval is the only pause a task can take, and it arises only from an
imported MCP tool binding with requireApproval; agents created in the console never pause.
The platform MCP endpoint currently registers schedule_wake, list_wakes and cancel_wake when
scheduling is configured. Calls are bound to an agent identity. Brokerage tools use their separate
broker MCP route and market filtering.
The old Job/ConfigMap executor, SandboxClaim warm-pool story, OCI skill init containers and
per-execution deadlines/output caps describe a retired implementation. They are not guarantees of
the current Substrate path. Historical designs stay outside the published site’s build.
Persistence and measurement limits
Session snapshots support suspend/resume. They do not provide the console’s proposed Git workspace
history APIs; workspace history remains unavailable. Compute is measured from the
actor lifecycle records the Substrate API server writes on every committed state change: a session
is charged for the time its actor is running, not for suspended time, worker replicas or snapshot
existence. This is persisted state, not CPU measurement, and crash-detection delay can extend it.
See Compute running seconds.
The public Substrate sandboxing documentation is upstream context; the platform’s pinned runtime and its IaC remain the integration contract.