<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Guides on Agent Mesh</title><link>https://google.github.io/agentmesh/docs/guides/</link><description>Recent content in Guides on Agent Mesh</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://google.github.io/agentmesh/docs/guides/index.xml" rel="self" type="application/rss+xml"/><item><title>Exposing services</title><link>https://google.github.io/agentmesh/docs/guides/exposing-services/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/exposing-services/</guid><description>&lt;p>A node does not publish any service by default. You declare the services it
offers in &lt;code>agentmesh-node.yaml&lt;/code>. This guide covers the three kinds of service a
node can serve and what the mesh policy must contain before anyone can reach
them.&lt;/p>
&lt;h2 id="the-configuration-file">The configuration file&lt;/h2>
&lt;p>&lt;code>agentmesh-node&lt;/code> reads &lt;code>agentmesh-node.yaml&lt;/code> from the working directory, or the file
named by &lt;code>--config&lt;/code>. Both &lt;code>join&lt;/code> and &lt;code>run&lt;/code> read it, because labels are
declared at enrollment. A minimal file with one service:&lt;/p></description></item><item><title>Connecting agents</title><link>https://google.github.io/agentmesh/docs/guides/connecting-agents/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/connecting-agents/</guid><description>&lt;p>An agent uses the mesh through the &lt;code>agentmesh-node&lt;/code> that runs on its own machine.
The node is an MCP server, so you can point any MCP client at it. This guide
gives the configuration for the common clients and explains what the agent
gets.&lt;/p>
&lt;h2 id="what-every-client-needs">What every client needs&lt;/h2>
&lt;p>Three values, all printed by &lt;code>agentmesh-node run --daemonize&lt;/code>:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>The endpoint&lt;/strong>: &lt;code>http://127.0.0.1:8080/mcp&lt;/code> (Streamable HTTP).&lt;/li>
&lt;li>&lt;strong>The token&lt;/strong>: the contents of &lt;code>~/.config/agentmesh/api-token&lt;/code>, or the
&lt;code>AGENTMESH_API_TOKEN&lt;/code> you started the node with. It goes in the header
&lt;code>X-Mesh-Authentication: Bearer &amp;lt;token&amp;gt;&lt;/code>.&lt;/li>
&lt;li>&lt;strong>The socket&lt;/strong>: &lt;code>~/.config/agentmesh/agentmesh.sock&lt;/code>. Anything the agent runs in a
shell can use the socket without a token. This is the easier way to reach
the node&amp;rsquo;s &lt;code>/v1&lt;/code> inference endpoint from scripts.&lt;/li>
&lt;/ul>
&lt;p>The node must be running before the client starts. MCP clients start and
manage stdio servers themselves, but &lt;code>agentmesh-node&lt;/code> is an HTTP server that they
connect to. You can run &lt;code>agentmesh-node run --daemonize&lt;/code> as often as you like, so it
is safe to put it in a shell profile or to let the agent run it.&lt;/p></description></item><item><title>Reaching services outside the mesh</title><link>https://google.github.io/agentmesh/docs/guides/egress-destinations/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/egress-destinations/</guid><description>&lt;p>An agentic application calls APIs that are not on the mesh: a source
forge, a ticketing system, an internal REST service, a model provider. This
guide puts a &lt;code>agentmesh-node&lt;/code> in front of such a destination as a policy
enforcement point. The application changes one base URL. The admin writes
one policy document. The node decides every request on the method, the
path and the caller, holds the credential the destination needs, and keeps
it out of the application.&lt;/p></description></item><item><title>Headless enrollment</title><link>https://google.github.io/agentmesh/docs/guides/headless-enrollment/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/headless-enrollment/</guid><description>&lt;p>Servers, containers and routers cannot complete an interactive login: there
is no browser, and no person to log in. Such a machine enrolls in one of two
ways: with an OIDC token that it already holds, or with a bootstrap token
that an operator mints for it. This guide covers both, and then explains
what happens when the credential of such a node expires.&lt;/p>
&lt;h2 id="with-an-oidc-token-that-the-workload-already-has">With an OIDC token that the workload already has&lt;/h2>
&lt;p>If the platform gives the workload a token from an issuer that the control
plane trusts, no operator step is needed. Mark workload issuers with
&lt;code>--workload-issuer&lt;/code> on the control plane so workload tokens can enroll,
refresh, and exchange credentials (&lt;code>POST /register&lt;/code>, &lt;code>POST /refresh&lt;/code>,
&lt;code>POST /token/exchange&lt;/code>), while being refused at human operator endpoints
(&lt;code>/user/*&lt;/code>, &lt;code>/oauth/authorize&lt;/code>).&lt;/p></description></item><item><title>Kubernetes</title><link>https://google.github.io/agentmesh/docs/guides/kubernetes/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/kubernetes/</guid><description>&lt;p>This guide deploys a control plane, a router and a console into a cluster
with the &lt;code>agentmesh-p2p&lt;/code> Helm chart, then puts services on the mesh with the
&lt;code>agentmesh-node&lt;/code> chart. The last section lists the settings to change when you
move from a test cluster to one that you keep. The public testnets run this
setup on GKE. Their manifests are in &lt;code>.github/k8s/&lt;/code> in the repository.&lt;/p>
&lt;h2 id="what-gets-deployed">What gets deployed&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Component&lt;/th>
 &lt;th>Kind&lt;/th>
 &lt;th>Notes&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;code>agentmesh-control-plane&lt;/code>&lt;/td>
 &lt;td>Deployment (2 replicas)&lt;/td>
 &lt;td>Stateless. All state is in PostgreSQL.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>PostgreSQL&lt;/td>
 &lt;td>StatefulSet&lt;/td>
 &lt;td>In-cluster by default (&lt;code>database.postgres.deployInternal&lt;/code>). You can point the chart at your own database instead.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>agentmesh-router&lt;/code>&lt;/td>
 &lt;td>StatefulSet&lt;/td>
 &lt;td>A PVC holds &lt;code>router.key&lt;/code>, so the peer ID survives rescheduling.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>agentmesh-console&lt;/code>&lt;/td>
 &lt;td>Deployment&lt;/td>
 &lt;td>Optional (&lt;code>console.enabled&lt;/code>).&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>bootstrap Job&lt;/td>
 &lt;td>Job (post-install hook)&lt;/td>
 &lt;td>Seeds the mesh policy and mints the router&amp;rsquo;s bootstrap token.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Gateway + HTTPRoute&lt;/td>
 &lt;td>Gateway API&lt;/td>
 &lt;td>Optional (&lt;code>gateway.enabled&lt;/code>). Routes the enrollment paths and the console.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;p>The chart does not include an identity provider, and the control plane needs
one to start. The cluster&amp;rsquo;s own OIDC issuer is a good choice, because every
pod can then enroll with a projected service account token and no secret has
to be distributed.&lt;/p></description></item><item><title>Cloud Run</title><link>https://google.github.io/agentmesh/docs/guides/cloud-run/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/cloud-run/</guid><description>&lt;p>&lt;code>agentmesh-one&lt;/code> serves its HTTP API, the web console, and the router&amp;rsquo;s WebSocket
transport on a single port (&lt;code>8080&lt;/code>), and ships as a pre-built container image
(&lt;code>ghcr.io/google/agentmesh-one:latest&lt;/code>). Because &lt;code>agentmesh-one&lt;/code> automatically infers its
public &lt;code>wss://&lt;/code> router address from Cloud Run&amp;rsquo;s &lt;code>Host&lt;/code> and &lt;code>X-Forwarded-Proto&lt;/code>
headers on &lt;code>/info&lt;/code> and &lt;code>/enroll&lt;/code> and derives a deterministic router &lt;code>PeerID&lt;/code>
from &lt;code>AGENTMESH_ADMIN_TOKEN&lt;/code>, you can deploy a standalone control plane and router to
Google Cloud Run in a single command.&lt;/p></description></item><item><title>GitHub Codespaces</title><link>https://google.github.io/agentmesh/docs/guides/codespaces/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/codespaces/</guid><description>&lt;p>A codespace is a container that GitHub runs for you, with a terminal, an
editor and an &lt;code>https&lt;/code> URL for every port you forward. Started from this
repository, it gives you a control plane of your own with nothing installed
on your machine and no cloud account. &lt;code>agentmesh-one&lt;/code> runs inside it, your laptop
and your phone enroll over the public URL, and your GitHub account pays with
its free Codespaces quota (120 core-hours a month on a Free plan; a 2-core
machine is enough). The same setup lets you develop Agent Mesh, or a program that
uses one of its SDKs, against a mesh that external clients can reach.&lt;/p></description></item><item><title>Native SDKs</title><link>https://google.github.io/agentmesh/docs/guides/native-sdks/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/native-sdks/</guid><description>&lt;p>An agent written in JavaScript or Python can be a member of the mesh itself,
with no &lt;code>agentmesh-node&lt;/code> beside it. The SDK enrolls with the control plane, joins
through a router, finds services, calls MCP tools and inference or A2A
endpoints, and answers A2A requests for the agent itself. Every caller of
the agent is checked against the mesh policy before anything reaches your
code.&lt;/p>
&lt;p>This guide takes you from nothing to two programs on a mesh: an agent that
other members can call, and a caller that reaches a service by name and the
agent by its peer ID. Both programs are in the repository under
&lt;a href="https://github.com/google/agentmesh/tree/main/sdk/js/examples">&lt;code>sdk/js/examples&lt;/code>&lt;/a>
and
&lt;a href="https://github.com/google/agentmesh/tree/main/sdk/python/examples">&lt;code>sdk/python/examples&lt;/code>&lt;/a>,
and the repository&amp;rsquo;s tests run them against a real mesh, so what you read
here is what runs.&lt;/p></description></item><item><title>SkyPilot</title><link>https://google.github.io/agentmesh/docs/guides/skypilot/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/skypilot/</guid><description>&lt;p>&lt;a href="https://docs.skypilot.co/">SkyPilot&lt;/a> provisions and manages compute across
Google Cloud, AWS, Azure, OCI, and Kubernetes using your existing cloud
credentials (&lt;code>sky check&lt;/code>). The repository includes a ready-to-run recipe,
&lt;a href="https://github.com/google/agentmesh/blob/main/deploy/skypilot/agentmesh-one.yaml">&lt;code>deploy/skypilot/agentmesh-one.yaml&lt;/code>&lt;/a>,
that deploys a standalone &lt;code>agentmesh-one&lt;/code> control plane and router with a persistent
disk and an outbound Cloudflare HTTPS tunnel (requiring no inbound firewall
rules).&lt;/p>
&lt;p>&lt;em>(Note: While &lt;code>deploy/skypilot/agentmesh-one.yaml&lt;/code> defaults to production VM sizing
(&lt;code>cpus: 2+&lt;/code>, &lt;code>memory: 8+&lt;/code>, matching &lt;code>e2-standard-2&lt;/code> on GCP or &lt;code>t3.large&lt;/code> on AWS),
you can also set &lt;code>cpus: 0.25+&lt;/code> and &lt;code>memory: 1+&lt;/code> to run on cloud provider free
tiers such as GCP &lt;code>e2-micro&lt;/code> or AWS &lt;code>t4g.micro&lt;/code> for testing.)&lt;/em>&lt;/p></description></item></channel></rss>