<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Concepts on Agent Mesh</title><link>https://google.github.io/agentmesh/docs/concepts/</link><description>Recent content in Concepts on Agent Mesh</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://google.github.io/agentmesh/docs/concepts/index.xml" rel="self" type="application/rss+xml"/><item><title>Architecture</title><link>https://google.github.io/agentmesh/docs/concepts/architecture/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/architecture/</guid><description>&lt;p>An agent mesh has a small control plane, one or more routers, and any number
of nodes. The control plane decides who is in the mesh and what they may do.
Routers make the nodes reachable. Nodes do the work: they publish services
and call each other&amp;rsquo;s services on behalf of the agents next to them.&lt;/p>
&lt;pre class="mermaid">flowchart LR
 subgraph cp[&amp;#34;control plane&amp;#34;]
 CP[&amp;#34;agentmesh-control-plane&amp;lt;br/&amp;gt;identity · policy · signing key&amp;#34;]
 DB[(&amp;#34;database&amp;#34;)]
 CP --- DB
 end
 IDP[&amp;#34;identity provider&amp;lt;br/&amp;gt;(OIDC)&amp;#34;]
 R[&amp;#34;agentmesh-router&amp;lt;br/&amp;gt;bootstrap · relay · DHT&amp;#34;]
 A[&amp;#34;agentmesh-node A&amp;#34;]
 B[&amp;#34;agentmesh-node B&amp;#34;]
 AG[&amp;#34;agent&amp;#34;]
 SVC[&amp;#34;your tool or model&amp;#34;]

 CP -. verifies tokens .-&amp;gt; IDP
 R -- lease --&amp;gt; CP
 A -- enroll / refresh --&amp;gt; CP
 B -- enroll / refresh --&amp;gt; CP
 A &amp;lt;--&amp;gt; R
 B &amp;lt;--&amp;gt; R
 A &amp;lt;-. direct when possible .-&amp;gt; B
 AG -- &amp;#34;MCP · OpenAI API&amp;lt;br/&amp;gt;(local)&amp;#34; --&amp;gt; A
 B --- SVC&lt;/pre>
&lt;h2 id="the-control-plane">The control plane&lt;/h2>
&lt;p>&lt;code>agentmesh-control-plane&lt;/code> is an HTTP service backed by SQLite or PostgreSQL. It is
the only component that has to be trusted. It is not on the data path: tool
calls and model requests never pass through it.&lt;/p></description></item><item><title>Identity and enrollment</title><link>https://google.github.io/agentmesh/docs/concepts/identity/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/identity/</guid><description>&lt;p>Every participant in a mesh, node or router, has a key that it generated
itself and a credential that the control plane issued for that key. Callers
that reach the mesh through a node (workloads, users, and sandboxed agents)
exchange their platform JWTs into delegated credentials bound to that node&amp;rsquo;s
channel, and narrow them offline per task. This page follows credentials from
enrollment and exchange to attenuation, outbound federation, renewal, and
revocation.&lt;/p></description></item><item><title>Authorization</title><link>https://google.github.io/agentmesh/docs/concepts/authorization/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/authorization/</guid><description>&lt;p>Authorization in Agent Mesh answers one question: may this caller perform this
operation on this service on this node right now? Four sources contribute to
the answer, and the destination node combines them:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>The caller&amp;rsquo;s credential&lt;/strong> (Block 0 authority facts signed by the control
plane).&lt;/li>
&lt;li>&lt;strong>The standing mesh policy&lt;/strong> (roles, bindings, HTTP narrowings, and egress
destinations distributed by the control plane as Datalog rules).&lt;/li>
&lt;li>&lt;strong>Any appended &lt;code>TaskAuthorizationRule&lt;/code> blocks (&lt;code>tar_block&lt;/code>)&lt;/strong> on the
credential, which narrow authority for a specific task or sub-agent hop.&lt;/li>
&lt;li>&lt;strong>The hosting node&amp;rsquo;s local &lt;code>attenuation&lt;/code> configuration&lt;/strong>.&lt;/li>
&lt;/ol>
&lt;p>Each layer can only narrow what the others allow. If standing policy or any
appended task block denies the request, the answer is no.&lt;/p></description></item><item><title>Networking and the node API</title><link>https://google.github.io/agentmesh/docs/concepts/networking/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/networking/</guid><description>&lt;p>This page follows a request from an agent to a service on another node:
how the calling node finds the provider, how the two connect, and what the
agent sees at each end.&lt;/p>
&lt;h2 id="the-nodes-local-api">The node&amp;rsquo;s local API&lt;/h2>
&lt;p>An agent does not speak to the mesh directly. It speaks to the &lt;code>agentmesh-node&lt;/code> on
its own machine, through one of two listeners:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>TCP&lt;/strong>, &lt;code>127.0.0.1:8080&lt;/code> by default (&lt;code>--bind-addr&lt;/code>). Every request must
carry the node&amp;rsquo;s API token as &lt;code>X-Mesh-Authentication: Bearer &amp;lt;token&amp;gt;&lt;/code>.&lt;/li>
&lt;li>&lt;strong>A Unix socket&lt;/strong>, &lt;code>&amp;lt;data-dir&amp;gt;/agentmesh.sock&lt;/code> by default (&lt;code>--socket-path&lt;/code>),
created with mode &lt;code>0600&lt;/code>. No token is needed, because only the user who
owns the socket can open it. &lt;code>docker.sock&lt;/code> works the same way.&lt;/li>
&lt;/ul>
&lt;p>You can turn either listener off by passing an empty value. With
&lt;code>--bind-addr=&lt;/code>, the node has no listening port and no secret to manage. This
is a good setup when everything that uses the node runs as the same user.&lt;/p></description></item><item><title>Control and data boundaries</title><link>https://google.github.io/agentmesh/docs/concepts/boundaries/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/boundaries/</guid><description>&lt;p>When you run your own control plane, you decide everything about the mesh.
On the public testnets, someone else decides who joins and what the policy
says. This page lists the decisions that become yours in a dedicated
deployment and the mechanism that enforces each of them.&lt;/p>
&lt;h2 id="what-you-control-in-a-dedicated-deployment">What you control in a dedicated deployment&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Membership.&lt;/strong> Enrollment goes through your identity provider or through
bootstrap tokens that you mint. The bindings in the control plane decide
which identities receive which roles. An identity without a binding cannot
enroll a node.&lt;/li>
&lt;li>&lt;strong>The signing key.&lt;/strong> The control plane generates its Ed25519 signing keys
and stores them in its database. Every credential in the mesh is signed by
one of these keys, and nobody outside the deployment can mint or extend a
credential. The keys rotate on the schedule you set.&lt;/li>
&lt;li>&lt;strong>The policy.&lt;/strong> What each role may call, on which nodes and with which
labels, is stored in your database. It can only be changed with your admin
token or through your console.&lt;/li>
&lt;li>&lt;strong>Revocation.&lt;/strong> A ban takes effect on the next credential refresh (within
the credential TTL, 24 hours by default) and, through the mesh event
channel, immediately on every connected node.&lt;/li>
&lt;li>&lt;strong>Where the software runs.&lt;/strong> Agent Mesh is Apache-2.0, sends no telemetry, and
does not depend on any hosted service. The control plane, routers and
nodes run wherever you put them: a laptop, a private cluster, an
air-gapped network.&lt;/li>
&lt;/ul>
&lt;p>The public testnets give you none of this. They are useful for trying the
software. Do not put anything there that you would not publish.&lt;/p></description></item></channel></rss>