<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Preview on Agent Mesh</title><link>https://google.github.io/agentmesh/docs/preview/</link><description>Recent content in Preview on Agent Mesh</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://google.github.io/agentmesh/docs/preview/index.xml" rel="self" type="application/rss+xml"/><item><title>Sandboxed agents</title><link>https://google.github.io/agentmesh/docs/preview/sandboxed-agents/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/sandboxed-agents/</guid><description>&lt;p>An autonomous agent runs untrusted or model-generated code and prompts. To run
one safely, you need two things that work together:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>OS and network confinement&lt;/strong>, provided by a dedicated sandbox runtime
(NVIDIA OpenShell, Kubernetes &lt;code>agent-sandbox&lt;/code> with gVisor or Kata, or Docker
Sandbox &lt;code>docker sbx&lt;/code>), so the process can only talk to the local gateway.&lt;/li>
&lt;li>&lt;strong>Task-scoped authorization and credential brokering&lt;/strong>, provided by Agent Mesh
(&lt;code>agentmesh-node&lt;/code> or &lt;code>agentgateway&lt;/code> + &lt;code>agentmesh-node&lt;/code>), so the sandbox never holds a
standing cloud credential or ambient workload token and can only call the
services, MCP tools, HTTP paths, and cloud resources permitted for its
current task.&lt;/li>
&lt;/ol>
&lt;p>This page shows the four deployment blueprints for connecting sandboxed agents
and multi-hop sub-agents to an Agent Mesh.&lt;/p></description></item><item><title>Agent architecture</title><link>https://google.github.io/agentmesh/docs/preview/agent-architecture/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/agent-architecture/</guid><description>&lt;p>This page explains how Agent Mesh authenticates workloads and users, scopes authority
to individual tasks and sub-agent hops, integrates with existing gateways and
sandbox runtimes, and brokers short-lived credentials to external cloud APIs
without placing standing cloud credentials inside the agent environment.&lt;/p>
&lt;h2 id="a-courier-network-for-tasks">A courier network for tasks&lt;/h2>
&lt;p>&lt;img src="../../../images/agent-mesh-courier.svg" alt="The Agent Mesh as a courier network">&lt;/p>
&lt;p>Agent Mesh moves tasks between environments that trust nothing on arrival, the way a
courier network moves parcels between post offices:&lt;/p></description></item><item><title>Agent Mesh Connect (Android)</title><link>https://google.github.io/agentmesh/docs/preview/mobile/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/mobile/</guid><description>&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Preview&lt;/h4>

 Agent Mesh Connect currently supports Android only. There is no iOS app.
The app is tested in CI on an Android emulator. Its screens, the on-device
tools it exposes and the FFI surface may change.

&lt;/div>

&lt;p>Agent Mesh Connect is a Flutter app that runs &lt;code>agentmesh-node&lt;/code> on an Android phone. The Go node is
compiled into a shared library and driven over Dart FFI. The app is the UI
around it, plus a small MCP server that exposes the phone&amp;rsquo;s sensors to the
mesh. A phone enrolled this way is a node like any other. It has a key, a
credential and a peer ID, and it appears in discovery with its
&lt;code>phone-sensors&lt;/code> service.&lt;/p></description></item><item><title>Scale report: what an agent costs</title><link>https://google.github.io/agentmesh/docs/preview/scale-report/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/scale-report/</guid><description>&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Preview&lt;/h4>

 These measurements are of the sandbox datapath described in
&lt;a href="../sandboxed-agents/">Sandboxed agents&lt;/a>. They were recorded on 2026-08-21
at commit &lt;code>e5b2966&lt;/code>, when the boundary spoke SOCKS5. The boundary has since
moved to HTTP &lt;code>CONNECT&lt;/code> and has not been measured again. The shape of the
results is what matters. Single figures are indicative.

&lt;/div>

&lt;p>The design gives every agent its own boundary, which resolves names and
enforces policy on each flow. That sounds expensive. This page measures it.
The method is written down so that the result can be challenged, and a
script is provided so that it can be run again. There are two experiments: a
sweep of boundaries attached to one node, and a thousand agents in microVMs
on one host.&lt;/p></description></item><item><title>Scale experiment: reproducing the thousand-agent run</title><link>https://google.github.io/agentmesh/docs/preview/scale-experiment/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/scale-experiment/</guid><description>&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Preview&lt;/h4>

 The scripts under &lt;code>tests/scale/&lt;/code> and &lt;code>scripts/&lt;/code> are research tooling for the
&lt;a href="../scale-report/">scale report&lt;/a>. They are kept working but are not a
supported product surface.

&lt;/div>

&lt;p>The report says what was measured and what it means. This page says how to
run it again. The setup is one host, one &lt;code>agentmesh-node&lt;/code>, and &lt;em>N&lt;/em> agents. Each
agent is a Firecracker microVM with no network device, and its only way out
is a vsock to its own &lt;code>agentmesh-box&lt;/code>. A thousand agents have been run on one
&lt;code>n2-standard-64&lt;/code>.&lt;/p></description></item></channel></rss>