The repositories
The platform separates the wire contract, runtime, browser clients, documentation, skills and infrastructure. Repository names below are identifiers; private repositories are not public links.
| Repository | Owns | Output |
|---|---|---|
api | Protobuf contract | Generated clients vendored by consumers |
platform-api | Connect API, broker MCP and custom kagent runtime build | Platform/broker image and pinned runtime image |
skills | Git plugin package and skill instructions/resources | A commit baked into the runtime image |
web | Marketing and agent console | GitHub Pages site |
admin | Operator console | GitHub Pages site |
docs | Published source-backed prose and unpublished design index | GitHub Pages site |
iac | Shared infrastructure, image pins and deployment graph | Terraform-managed resources |
agents | Archived historical BYO runtime | No current Harness deployment output |
Contract and server
api has a Buf workflow for format, lint and breaking-change checks. Publishing to the Buf Schema
Registry is disabled in that workflow; consumers vendor from Git. Generated code is an artifact of
the contract, not a second place to edit behavior. The backend’s make sync-api refreshes its
vendored contract before regeneration.
platform-api owns Go server behavior and integration adapters. Its main image contains the API
and broker MCP binaries. Its runtime/kagent directory builds the patched upstream runtime with
pinned source, a pinned base image and pinned skills. The archived agents repository does not
supply that image.
Local backend checks use the repository Makefile. Provider-backed paths need their configured credentials and services; an offline unit-test pass does not verify deployment or provider acceptance. The image promotion contract is described on The deploy path.
Browser clients and docs
web and admin are SvelteKit applications. Their checked-in package scripts define type checks,
unit tests where present, dead-code checks and static builds. Public build configuration includes
API and Firebase settings; secrets do not belong in a browser bundle. Admin permissions are always
checked by the API.
docs uses SvelteKit 2, Svelte 5, mdsvex and the shared Tailwind/shadcn-svelte component approach.
Published Markdown lives in src/routes/**/+page.md; src/lib/nav.ts owns navigation. Run npm ci, npm run check and npm run build against the current lockfile. Internal prerendered
links fail the build when broken.
The docs repository’s design/README.md indexes historical and active design material by owner and
status. design/ and source-verification notes remain outside the published routes and static
assets. They are not evidence of deployed behavior and must not be moved into the public build by
an incidental folder cleanup.
Infrastructure
iac owns gcp/platform, github, gcp/workloads and the separate native Stripe configuration.
The first three use an explicit dependency graph for CI selection and apply order. Workloads plans
contact Kubernetes/Helm APIs, so they require the platform and a reachable cluster.
Terraform controls custom domains and GitHub Pages configuration. Each site builds and publishes its
own static artifact. .nojekyll, the Pages-compatible 404.html fallback and the configured base path
are part of the site deployment contract.