Skip to main content

Keep — phases complete (local)

Scoreboard (ahead-of-Muse gate, software-test only): AHEAD.md · ./scripts/keep-scoreboard.sh · agent-runtime/src/scoreboard.rs.

PhaseStatusWhere
FluxVM Phase 6Merged (security_profile / measured)zyvorai/fluxvm
Keep 0.1 pilotLive gate twice (happy + deny) on FluxVM hostpilot-runs/ · ./scripts/keep-pilot-gate.sh
Keep 0.1 live proofKeep mode + live e2e path + browser view + credential authoritythis tree
Keep docsIn Fabricdocs/keep/
keepctlScriptscripts/keepctl
Agent runtimePolicy YAML, goals/artifacts, cockpit, export-tokenagent-runtime/
Packaged agentsinfra-ops, migration-op, deploy-op, browser-research, pdf-brief + _fabricexamples/keep-agents/
Keep console viewGoal → task → evidence → approval → outcome + PDF demo home/app/keep · /app/keep/:sessionId
Keep 0.2Soft scaffolding complete + brokered browser; hardware still gatedKEEP-0.2.md · browser/DRIVER.md
Keep Browser 0.3Split-sight, trajectory-as-code, origin IFC, SNI-identity badge, goal tabsbrowser/BROWSER-0.3.md
Host eBPF (FluxVM only)deny_udp + gateway pin; audit egress_connects; freeze on denyFluxVM TC + agent-runtime confine
One-click use casesTable-driven demos (7): drop a file, get an artifact; expect 0 CONNECTdemos/ · examples/keep-agents/<id>/ · keep-demo.sh
Your own use casesDeclarative pack.json (no code) deployed from the console or keepctl deploy; TypeScript agent packs signed with Node and deployed in one commandPACKS.md · Tutorial 19 · Tutorial 20: mail export digest
Run historyArtifact TTL, per-use-case history, line diff between runs, run.finished / run.failed webhook, console /app/keep/history, keepctl run|list|artifacts|diff|audit|approvalskeepctl/README.md
Triggers and batchMulti-file runs (one cell each), signed webhook and watched-folder triggers, keepctl triggerTRIGGERS.md
More file typesdocx, xlsx, pptx, html, eml/mbox extractors, zip fan-out, regex_extract / json_path / table rulesPACKS.md
Model-assisted use casesOpt-in host-side model step: vault-gated endpoint, first-use approval, audited calls, sanitised reply, keepctl grantsMODEL.md
Scenarios and the cell templateSeven scenario packs; node22-agent template and keep-bake-node22-agent.shSCENARIOS.md
Many usersUser tokens, per-user isolation, quotas, usage, revocationTENANCY.md
Phone-signed approvalsDevice enrolment, push relays, signed decisions, keep-phone, test vectorsmobile/README.md
Model choicemodel_socket wired for agents (ctx.model.chat(), CLI harness), any OpenAI-compatible endpointMODELS.md
Phone vendorsBlueprint, reference gateway, benchmark, partial zh-CN consoleVENDORS.md
Install Keep./scripts/deploy keep user@host (needs FluxVM on the host); keepctl doctorPRODUCTION.md · scripts/deploy-keep.sh
Install on Kubernetescharts/zyvor-keep: a hostNetwork DaemonSet beside FluxVM, Keep mode on by default, credential descriptors, secret volumes, a service account. Rendered and schema-checked; never installed in a clusterPRODUCTION.md
Policy changesA risk check (409 until acknowledged) on every policy update; keepctl policy suggest drafts allow rules from an agent's denied requestssentinel/README.md
Egress rules by body and programMCP, JSON-RPC and GraphQL body rules; binaries (which program in the cell may call, from the guest's /proc). The attribution script was run on real Linux, including across a bwrap PID namespace; not in a real cellsentinel/README.md
Operator egress guardZYVOR_AGENT_GUARD_URL: an HTTP service that may refuse any brokered request; fails closedagent-runtime/README.md
Cell hardeningA seccomp syscall filter in the inner container (x86_64). The filter was run under a real bwrap on Linux; not through a real cell or with Chromiumagent-runtime/README.md
GPU cellsgpus in the agent manifest; FluxVM picks free VFIO-bound GPUs under a lock. Picking logic tested; no real GPUagent-runtime/README.md · FluxVM docs/sandbox-gpus.md
Audit exportGET /v1/export/audit?format=ocsf: OCSF-shaped NDJSON, chain hashes carried; not run through the OCSF schema validatorkeepctl/README.md
Credential sourcesA credential's secret from a file, or from HashiCorp Vault (token, AppRole, Kubernetes login); GET /v1/vault/status lists each source. Tested against a mock; no real Vaultvault/README.md
CIKeep workflow: unit tests, demos e2e (7 built-ins, a custom use case, signed pack deploy in Keep mode, against the real runtime and the FluxVM stand-in), stub e2e.github/workflows/keep.yml
TutorialHands-on + pack appendix + demos + your ownTutorial 16 · Tutorial 17 · Tutorial 18 · Tutorial 19

Packaged agents​

PackFabric surface
infra-opsalerts, VMs, lifecycle; restart/remediation behind ask
migration-op/api/migrations + GuestKit inspect/rescue (no Transiva in-repo)
deploy-op/readyz + /health → readiness artifact
browser-researchallowlisted a11y browse → research markdown
pdf-briefPDF → brief.md; no browser; 0 CONNECT
contract-clausescontract PDF → clauses.md; no browser; 0 CONNECT
security-questionnairequestionnaire PDF → answers.md; no browser; 0 CONNECT
meeting-actions.txt/.vtt → actions.md; no browser; 0 CONNECT
log-triagelog file → triage.md; no browser; 0 CONNECT
sbom-summaryCycloneDX/SPDX/SARIF → summary.md; no browser; 0 CONNECT
csv-cleanCSV → clean.csv + report.md; no browser; 0 CONNECT

How to test​

cargo test --manifest-path agent-runtime/Cargo.toml --lib
cargo test --manifest-path agent-runtime/Cargo.toml goals -- --nocapture
./scripts/keep-e2e.sh
# One-click demos, custom use case and signed pack deploy (real runtime + FluxVM stand-in, no VM):
bash agent-runtime/tests/demos-ci.sh
# Lab FluxVM host (template required — soft-pass removed):
KEEP_E2E_TEMPLATE=node22-agent ./scripts/keep-live-lab.sh
# Full pilot (happy + deny, archived logs):
./scripts/keep-pilot-gate.sh
./scripts/keep-pack-demo.sh infra-ops
./scripts/keep-demo-pdf.sh

Honesty​

Measured = software-test. Host can still see the VM until Keep 0.2 + hardware. Guest vsock is healthy on QEMU node22-agent (musl-static guest-agent) and on Firecracker node22-fc (flat ext4 rootfs — see scripts/keep-bake-fc-rootfs.sh). The pilot gate prefers node22-fc when that template is registered.

Not verified live (2026-09-30)​

The controls listed above from "Policy changes" down were built and tested against fakes and, where noted, on real Linux outside a cell. These have not been run: the policy 409 and acknowledge flow, the OCSF export and policy suggest against a live runtime; per-program binaries and the seccomp filter in a real cell (and Chromium under the filter); a GPU cell on real hardware; the credential sources against a real Vault, AppRole or Kubernetes login; the Helm chart in a cluster. Several need the runtime's API token; see TODO.md.

What the demos e2e proves, and what it does not​

agent-runtime/tests/demos-ci.sh runs the real runtime binary against tests/sandbox_stub.py (guest commands run on the CI machine, real pdftotext, no VM). It checks the seven built-in demos and their artifacts, refusal of wrong file types, oversize uploads and unknown ids, spreadsheet-formula neutralisation, deploying and deleting a user-defined use case, keepctl doctor, and, in Keep mode, that an unsigned deploy is refused while a Node-signed one is accepted and a one-byte change to the signed bytes is refused. It does not prove cell isolation or that the host eBPF pin stops a connection: that needs a FluxVM host (keep-live-lab.sh). The freeze-on-connect rule is unit-tested by counting the egress.connect / ebpf.* audit rows it depends on.