<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Agent Mesh</title><link>https://google.github.io/agentmesh/</link><description>Recent content on Agent Mesh</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://google.github.io/agentmesh/index.xml" rel="self" type="application/rss+xml"/><item><title>agentmesh-node</title><link>https://google.github.io/agentmesh/docs/reference/agentmesh-node/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/agentmesh-node/</guid><description>&lt;p>&lt;code>agentmesh-node&lt;/code> is the mesh member that runs beside an agent or a service.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-text" data-lang="text">&lt;span class="line">&lt;span class="cl">agentmesh-node join [control-plane-url] [flags] enroll and store a credential
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-node run [flags] run the node
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-node forward egress://&amp;lt;name&amp;gt;:&amp;lt;port&amp;gt; [local-addr] forward a local TCP port to a named egress tunnel
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-node reset [--all] [--yes] forget the credential or everything
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-node state export|import &amp;lt;dir&amp;gt; move the identity to or from a state directory
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-node skill install|list|show manage the agent skill document
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="files">Files&lt;/h2>
&lt;p>The data directory is &lt;code>--data-dir&lt;/code> if set, otherwise &lt;code>$AGENTMESH_DATA_DIR&lt;/code>,
otherwise the user configuration directory of the operating system
(&lt;code>~/.config/agentmesh&lt;/code> on Linux, &lt;code>~/Library/Application Support/agentmesh&lt;/code> on
macOS). It is created with mode &lt;code>0700&lt;/code> and holds:&lt;/p></description></item><item><title>Architecture</title><link>https://google.github.io/agentmesh/docs/concepts/architecture/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/architecture/</guid><description>&lt;p>An agent mesh has a small control plane, one or more routers, and any number
of nodes. The control plane decides who is in the mesh and what they may do.
Routers make the nodes reachable. Nodes do the work: they publish services
and call each other&amp;rsquo;s services on behalf of the agents next to them.&lt;/p>
&lt;pre class="mermaid">flowchart LR
 subgraph cp[&amp;#34;control plane&amp;#34;]
 CP[&amp;#34;agentmesh-control-plane&amp;lt;br/&amp;gt;identity · policy · signing key&amp;#34;]
 DB[(&amp;#34;database&amp;#34;)]
 CP --- DB
 end
 IDP[&amp;#34;identity provider&amp;lt;br/&amp;gt;(OIDC)&amp;#34;]
 R[&amp;#34;agentmesh-router&amp;lt;br/&amp;gt;bootstrap · relay · DHT&amp;#34;]
 A[&amp;#34;agentmesh-node A&amp;#34;]
 B[&amp;#34;agentmesh-node B&amp;#34;]
 AG[&amp;#34;agent&amp;#34;]
 SVC[&amp;#34;your tool or model&amp;#34;]

 CP -. verifies tokens .-&amp;gt; IDP
 R -- lease --&amp;gt; CP
 A -- enroll / refresh --&amp;gt; CP
 B -- enroll / refresh --&amp;gt; CP
 A &amp;lt;--&amp;gt; R
 B &amp;lt;--&amp;gt; R
 A &amp;lt;-. direct when possible .-&amp;gt; B
 AG -- &amp;#34;MCP · OpenAI API&amp;lt;br/&amp;gt;(local)&amp;#34; --&amp;gt; A
 B --- SVC&lt;/pre>
&lt;h2 id="the-control-plane">The control plane&lt;/h2>
&lt;p>&lt;code>agentmesh-control-plane&lt;/code> is an HTTP service backed by SQLite or PostgreSQL. It is
the only component that has to be trusted. It is not on the data path: tool
calls and model requests never pass through it.&lt;/p></description></item><item><title>Exposing services</title><link>https://google.github.io/agentmesh/docs/guides/exposing-services/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/exposing-services/</guid><description>&lt;p>A node does not publish any service by default. You declare the services it
offers in &lt;code>agentmesh-node.yaml&lt;/code>. This guide covers the three kinds of service a
node can serve and what the mesh policy must contain before anyone can reach
them.&lt;/p>
&lt;h2 id="the-configuration-file">The configuration file&lt;/h2>
&lt;p>&lt;code>agentmesh-node&lt;/code> reads &lt;code>agentmesh-node.yaml&lt;/code> from the working directory, or the file
named by &lt;code>--config&lt;/code>. Both &lt;code>join&lt;/code> and &lt;code>run&lt;/code> read it, because labels are
declared at enrollment. A minimal file with one service:&lt;/p></description></item><item><title>Quick start</title><link>https://google.github.io/agentmesh/docs/getting-started/quickstart/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/getting-started/quickstart/</guid><description>&lt;p>This page installs &lt;code>agentmesh-node&lt;/code>, enrolls it in the public &lt;code>bananas.sam-mesh.dev&lt;/code>
testnet, and calls a tool hosted by another node. It takes a few minutes.&lt;/p>
&lt;p>The testnet is a shared developer playground with no uptime commitment. See
&lt;a href="../../#about-the-public-testnets">About the public testnets&lt;/a>. The steps are
the same for any mesh: replace the URL with your own control plane.&lt;/p>
&lt;h2 id="1-install">1. Install&lt;/h2>
&lt;p>On Linux and macOS, the install script downloads the latest release and
places the binaries in &lt;code>/usr/local/bin&lt;/code>:&lt;/p></description></item><item><title>Sandboxed agents</title><link>https://google.github.io/agentmesh/docs/preview/sandboxed-agents/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/sandboxed-agents/</guid><description>&lt;p>An autonomous agent runs untrusted or model-generated code and prompts. To run
one safely, you need two things that work together:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>OS and network confinement&lt;/strong>, provided by a dedicated sandbox runtime
(NVIDIA OpenShell, Kubernetes &lt;code>agent-sandbox&lt;/code> with gVisor or Kata, or Docker
Sandbox &lt;code>docker sbx&lt;/code>), so the process can only talk to the local gateway.&lt;/li>
&lt;li>&lt;strong>Task-scoped authorization and credential brokering&lt;/strong>, provided by Agent Mesh
(&lt;code>agentmesh-node&lt;/code> or &lt;code>agentgateway&lt;/code> + &lt;code>agentmesh-node&lt;/code>), so the sandbox never holds a
standing cloud credential or ambient workload token and can only call the
services, MCP tools, HTTP paths, and cloud resources permitted for its
current task.&lt;/li>
&lt;/ol>
&lt;p>This page shows the four deployment blueprints for connecting sandboxed agents
and multi-hop sub-agents to an Agent Mesh.&lt;/p></description></item><item><title>Testnets</title><link>https://google.github.io/agentmesh/docs/contributing/testnets/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/contributing/testnets/</guid><description>&lt;p>The project runs two public meshes for its own testing and for anyone who
wants to try the software without deploying anything.&lt;/p>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>&lt;/th>
 &lt;th>&lt;code>bananas.sam-mesh.dev&lt;/code>&lt;/th>
 &lt;th>&lt;code>hub.sam-mesh.dev&lt;/code>&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>Built from&lt;/td>
 &lt;td>every push to &lt;code>main&lt;/code>&lt;/td>
 &lt;td>every &lt;code>v*&lt;/code> tag&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Image tag&lt;/td>
 &lt;td>the commit SHA&lt;/td>
 &lt;td>the release version&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Purpose&lt;/td>
 &lt;td>continuous integration of unreleased code&lt;/td>
 &lt;td>the latest release, for interoperability testing&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;p>Both are deployed by &lt;code>.github/workflows/deploy.yaml&lt;/code> to a GKE cluster from
the templates in &lt;code>.github/k8s/&lt;/code>. Each testnet has a control plane Deployment
on PostgreSQL, a router StatefulSet that announces
&lt;code>/dnsaddr/bootstrap.&amp;lt;env&amp;gt;.sam-mesh.dev&lt;/code> (a DNS-sync CronJob keeps the record
current), the console, and a few canary nodes that publish demo services:
the MCP &lt;code>everything&lt;/code> server, an OpenRouter proxy, and a vLLM instance when
one is running. Identity comes from a Dex instance at &lt;code>auth.sam-mesh.dev&lt;/code>
that accepts Google and GitHub logins, and from the cluster&amp;rsquo;s own issuer for
in-cluster workloads.&lt;/p></description></item><item><title>Agent architecture</title><link>https://google.github.io/agentmesh/docs/preview/agent-architecture/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/agent-architecture/</guid><description>&lt;p>This page explains how Agent Mesh authenticates workloads and users, scopes authority
to individual tasks and sub-agent hops, integrates with existing gateways and
sandbox runtimes, and brokers short-lived credentials to external cloud APIs
without placing standing cloud credentials inside the agent environment.&lt;/p>
&lt;h2 id="a-courier-network-for-tasks">A courier network for tasks&lt;/h2>
&lt;p>&lt;img src="../../../images/agent-mesh-courier.svg" alt="The Agent Mesh as a courier network">&lt;/p>
&lt;p>Agent Mesh moves tasks between environments that trust nothing on arrival, the way a
courier network moves parcels between post offices:&lt;/p></description></item><item><title>agentmesh-control-plane</title><link>https://google.github.io/agentmesh/docs/reference/control-plane/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/control-plane/</guid><description>&lt;p>&lt;code>agentmesh-control-plane&lt;/code> admits nodes, mints credentials, holds the mesh policy
and tracks routers. It is an HTTP server over SQLite or PostgreSQL.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-text" data-lang="text">&lt;span class="line">&lt;span class="cl">agentmesh-control-plane [flags] run the server
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-control-plane admin ban --peer &amp;lt;id&amp;gt; ban a node directly in the database
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-control-plane admin unban --peer &amp;lt;id&amp;gt; lift a ban
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="flags">Flags&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Flag&lt;/th>
 &lt;th>Default&lt;/th>
 &lt;th>Meaning&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;code>--issuer&lt;/code>&lt;/td>
 &lt;td>&lt;/td>
 &lt;td>OIDC issuer URL(s), comma-separated. At least one of &lt;code>--issuer&lt;/code> or &lt;code>--workload-issuer&lt;/code> is required. The first issuer is advertised to enrolling nodes on &lt;code>/info&lt;/code>.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--workload-issuer&lt;/code>&lt;/td>
 &lt;td>&lt;/td>
 &lt;td>Workload OIDC issuer(s), comma-separated (&lt;code>&amp;lt;issuer&amp;gt;&lt;/code> or &lt;code>&amp;lt;issuer&amp;gt;=&amp;lt;email-suffix&amp;gt;&lt;/code>, such as &lt;code>https://accounts.google.com=.gserviceaccount.com&lt;/code>). Automatically added to &lt;code>--issuer&lt;/code>. Workload tokens can enroll, refresh, and exchange credentials (&lt;code>/register&lt;/code>, &lt;code>/refresh&lt;/code>, &lt;code>/token/exchange&lt;/code>), and are refused at &lt;code>/user/*&lt;/code> and &lt;code>/oauth/authorize&lt;/code>.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--allowed-audiences&lt;/code>&lt;/td>
 &lt;td>&lt;code>agentmesh-audience&lt;/code>&lt;/td>
 &lt;td>Audiences accepted in OIDC tokens, comma-separated.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--oidc-client-id&lt;/code>&lt;/td>
 &lt;td>first audience&lt;/td>
 &lt;td>OAuth client ID advertised on &lt;code>/info&lt;/code>, for providers where it differs from the audience.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--insecure-skip-tls-verify&lt;/code>&lt;/td>
 &lt;td>&lt;code>false&lt;/code>&lt;/td>
 &lt;td>Skip TLS verification when fetching issuer metadata and keys. For a cluster issuer served with the cluster CA, or a local development issuer.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--bind-address&lt;/code>&lt;/td>
 &lt;td>&lt;code>0.0.0.0:8080&lt;/code>&lt;/td>
 &lt;td>HTTP listen address.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--db-driver&lt;/code>&lt;/td>
 &lt;td>&lt;code>sqlite&lt;/code>&lt;/td>
 &lt;td>&lt;code>sqlite&lt;/code> or &lt;code>postgres&lt;/code>.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--db-dsn&lt;/code>&lt;/td>
 &lt;td>&lt;code>control-plane.db&lt;/code>&lt;/td>
 &lt;td>Database DSN. A PostgreSQL DSN contains a password, so the next two options are preferred for PostgreSQL.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--db-dsn-path&lt;/code>&lt;/td>
 &lt;td>&lt;/td>
 &lt;td>File containing the DSN. Overrides &lt;code>--db-dsn&lt;/code>. Can also be set with &lt;code>AGENTMESH_DB_DSN&lt;/code>.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--admin-token-path&lt;/code>&lt;/td>
 &lt;td>&lt;/td>
 &lt;td>File containing the bearer token for &lt;code>/admin/*&lt;/code> and &lt;code>POST /policies&lt;/code>. Can also be set with &lt;code>AGENTMESH_ADMIN_TOKEN&lt;/code>. Without a token, the admin API cannot be used.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--auto-approve-enrollment&lt;/code>&lt;/td>
 &lt;td>&lt;code>false&lt;/code>&lt;/td>
 &lt;td>Issue credentials for valid bootstrap-token enrollments immediately instead of queueing them for approval.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--biscuit-ttl&lt;/code>&lt;/td>
 &lt;td>&lt;code>24h&lt;/code>&lt;/td>
 &lt;td>Lifetime of each credential. If the OIDC token expires sooner, the credential expires with it.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--oidc-session-ttl&lt;/code>&lt;/td>
 &lt;td>&lt;code>2160h&lt;/code> (90 days)&lt;/td>
 &lt;td>How long a human OIDC enrollment may keep refreshing before the identity must log in again.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--workload-session-ttl&lt;/code>&lt;/td>
 &lt;td>&lt;code>48h&lt;/code>&lt;/td>
 &lt;td>How long a workload OIDC enrollment (&lt;code>--workload-issuer&lt;/code>) may refresh without presenting a fresh platform JWT in &lt;code>TokenRefreshRequest.jwt&lt;/code>.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--key-rotation-interval&lt;/code>&lt;/td>
 &lt;td>&lt;code>24h&lt;/code>&lt;/td>
 &lt;td>How often a new signing key is generated. &lt;code>0&lt;/code> disables rotation.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--key-grace-period&lt;/code>&lt;/td>
 &lt;td>&lt;code>1h&lt;/code>&lt;/td>
 &lt;td>How long a rotated-out key stays accepted. Credentials signed by a retired key cannot be verified or refreshed. Nodes and routers must pull &lt;code>/keys&lt;/code> well within this window (&lt;code>agentmesh-node --control-plane-sync-interval&lt;/code>, &lt;code>agentmesh-router --keys-sync-interval&lt;/code>).&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--lease-duration&lt;/code>&lt;/td>
 &lt;td>&lt;code>15m&lt;/code>&lt;/td>
 &lt;td>How long a router lease lasts without renewal.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--node-retention&lt;/code>&lt;/td>
 &lt;td>&lt;code>720h&lt;/code> (30 days)&lt;/td>
 &lt;td>How long the record of an enrolled node is kept after its session expires. Banned nodes are kept forever. &lt;code>0&lt;/code> keeps every record.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--mesh-reconnect-interval&lt;/code>&lt;/td>
 &lt;td>&lt;code>30s&lt;/code>&lt;/td>
 &lt;td>How often the event publisher re-reads the router leases and dials any router it is not connected to.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--log-level&lt;/code>&lt;/td>
 &lt;td>&lt;code>info&lt;/code>&lt;/td>
 &lt;td>&lt;code>debug&lt;/code>, &lt;code>info&lt;/code>, &lt;code>warn&lt;/code>, &lt;code>error&lt;/code>. &lt;code>LOG_FORMAT=json&lt;/code> selects JSON output.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;h2 id="http-api">HTTP API&lt;/h2>
&lt;p>Every request and response is a message in &lt;code>api/agentmesh.proto&lt;/code>, in one of two
encodings. Routes that mesh components call use binary protobuf
(&lt;code>application/x-protobuf&lt;/code>). Routes for operators and the console use
protojson of the same messages, with proto field names; unknown fields are
rejected. &lt;code>POST /policies&lt;/code> accepts either and answers in the encoding of the
request.&lt;/p></description></item><item><title>Connecting agents</title><link>https://google.github.io/agentmesh/docs/guides/connecting-agents/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/connecting-agents/</guid><description>&lt;p>An agent uses the mesh through the &lt;code>agentmesh-node&lt;/code> that runs on its own machine.
The node is an MCP server, so you can point any MCP client at it. This guide
gives the configuration for the common clients and explains what the agent
gets.&lt;/p>
&lt;h2 id="what-every-client-needs">What every client needs&lt;/h2>
&lt;p>Three values, all printed by &lt;code>agentmesh-node run --daemonize&lt;/code>:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>The endpoint&lt;/strong>: &lt;code>http://127.0.0.1:8080/mcp&lt;/code> (Streamable HTTP).&lt;/li>
&lt;li>&lt;strong>The token&lt;/strong>: the contents of &lt;code>~/.config/agentmesh/api-token&lt;/code>, or the
&lt;code>AGENTMESH_API_TOKEN&lt;/code> you started the node with. It goes in the header
&lt;code>X-Mesh-Authentication: Bearer &amp;lt;token&amp;gt;&lt;/code>.&lt;/li>
&lt;li>&lt;strong>The socket&lt;/strong>: &lt;code>~/.config/agentmesh/agentmesh.sock&lt;/code>. Anything the agent runs in a
shell can use the socket without a token. This is the easier way to reach
the node&amp;rsquo;s &lt;code>/v1&lt;/code> inference endpoint from scripts.&lt;/li>
&lt;/ul>
&lt;p>The node must be running before the client starts. MCP clients start and
manage stdio servers themselves, but &lt;code>agentmesh-node&lt;/code> is an HTTP server that they
connect to. You can run &lt;code>agentmesh-node run --daemonize&lt;/code> as often as you like, so it
is safe to put it in a shell profile or to let the agent run it.&lt;/p></description></item><item><title>Identity and enrollment</title><link>https://google.github.io/agentmesh/docs/concepts/identity/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/identity/</guid><description>&lt;p>Every participant in a mesh, node or router, has a key that it generated
itself and a credential that the control plane issued for that key. Callers
that reach the mesh through a node (workloads, users, and sandboxed agents)
exchange their platform JWTs into delegated credentials bound to that node&amp;rsquo;s
channel, and narrow them offline per task. This page follows credentials from
enrollment and exchange to attenuation, outbound federation, renewal, and
revocation.&lt;/p></description></item><item><title>Security architecture</title><link>https://google.github.io/agentmesh/docs/contributing/security-architecture/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/contributing/security-architecture/</guid><description>&lt;p>This document describes the security architecture and posture of Agent Mesh for
developers and security reviewers. It covers how Agent Mesh acts as an authority,
Policy Decision Point (PDP), and task-scoped credential layer across
environments, what problems it solves, what responsibilities remain with the
surrounding platform, how its cryptographic and policy mechanisms work across
&lt;code>agentmesh-control-plane&lt;/code>, &lt;code>agentmesh-node&lt;/code>, &lt;code>agentmesh-router&lt;/code>, and the native SDKs, and which
extensions are deferred on purpose.&lt;/p>
&lt;hr>
&lt;h2 id="1-current-security-posture-a-courier-network-for-tasks">1. Current security posture: a courier network for tasks&lt;/h2>
&lt;p>&lt;img src="../../../images/agent-mesh-courier.svg" alt="The Agent Mesh as a courier network">&lt;/p></description></item><item><title>Your own mesh</title><link>https://google.github.io/agentmesh/docs/getting-started/your-own-mesh/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/getting-started/your-own-mesh/</guid><description>&lt;p>This page gets a mesh of your own running in a few minutes: a control plane,
a router and a web console on your laptop, in one process called &lt;code>agentmesh-one&lt;/code>.
You then put a member on it, open the console, and see a model that runs on
your machine answer a request from another member. &lt;code>agentmesh-one&lt;/code> runs the same
code as a Kubernetes deployment, so what you learn here applies there too.&lt;/p></description></item><item><title>Agent Mesh Connect (Android)</title><link>https://google.github.io/agentmesh/docs/preview/mobile/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/mobile/</guid><description>&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Preview&lt;/h4>

 Agent Mesh Connect currently supports Android only. There is no iOS app.
The app is tested in CI on an Android emulator. Its screens, the on-device
tools it exposes and the FFI surface may change.

&lt;/div>

&lt;p>Agent Mesh Connect is a Flutter app that runs &lt;code>agentmesh-node&lt;/code> on an Android phone. The Go node is
compiled into a shared library and driven over Dart FFI. The app is the UI
around it, plus a small MCP server that exposes the phone&amp;rsquo;s sensors to the
mesh. A phone enrolled this way is a node like any other. It has a key, a
credential and a peer ID, and it appears in discovery with its
&lt;code>phone-sensors&lt;/code> service.&lt;/p></description></item><item><title>agentmesh-router</title><link>https://google.github.io/agentmesh/docs/reference/router/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/router/</guid><description>&lt;p>&lt;code>agentmesh-router&lt;/code> is a libp2p peer with a stable identity that new nodes connect
to first. It hosts the DHT, relays traffic between nodes that cannot reach
each other, and forwards the control plane&amp;rsquo;s signed events. It has no policy
of its own.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-text" data-lang="text">&lt;span class="line">&lt;span class="cl">agentmesh-router [flags]
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="enrollment">Enrollment&lt;/h2>
&lt;p>A router enrolls like a node, requesting &lt;code>mesh:role:router&lt;/code>, with one of:&lt;/p>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Flag&lt;/th>
 &lt;th>Meaning&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;code>--jwt-path&lt;/code>&lt;/td>
 &lt;td>File containing an OIDC token (a projected service account token, for example).&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--bootstrap-token-path&lt;/code>&lt;/td>
 &lt;td>File containing a bootstrap token minted with &lt;code>&amp;quot;role&amp;quot;: &amp;quot;mesh:role:router&amp;quot;&lt;/code>.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>--oidc-token&lt;/code>, &lt;code>--bootstrap-token&lt;/code>&lt;/td>
 &lt;td>The same tokens as values. Visible in process listings. The file forms are preferred.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;p>The mesh policy must bind the router&amp;rsquo;s identity to &lt;code>mesh:role:router&lt;/code>. The
&lt;code>agentmesh-p2p&lt;/code> Helm chart handles this: its bootstrap job binds the router&amp;rsquo;s
service account and mints a bootstrap token with &lt;code>max_usages&lt;/code> equal to the
replica count.&lt;/p></description></item><item><title>Authorization</title><link>https://google.github.io/agentmesh/docs/concepts/authorization/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/authorization/</guid><description>&lt;p>Authorization in Agent Mesh answers one question: may this caller perform this
operation on this service on this node right now? Four sources contribute to
the answer, and the destination node combines them:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>The caller&amp;rsquo;s credential&lt;/strong> (Block 0 authority facts signed by the control
plane).&lt;/li>
&lt;li>&lt;strong>The standing mesh policy&lt;/strong> (roles, bindings, HTTP narrowings, and egress
destinations distributed by the control plane as Datalog rules).&lt;/li>
&lt;li>&lt;strong>Any appended &lt;code>TaskAuthorizationRule&lt;/code> blocks (&lt;code>tar_block&lt;/code>)&lt;/strong> on the
credential, which narrow authority for a specific task or sub-agent hop.&lt;/li>
&lt;li>&lt;strong>The hosting node&amp;rsquo;s local &lt;code>attenuation&lt;/code> configuration&lt;/strong>.&lt;/li>
&lt;/ol>
&lt;p>Each layer can only narrow what the others allow. If standing policy or any
appended task block denies the request, the answer is no.&lt;/p></description></item><item><title>Reaching services outside the mesh</title><link>https://google.github.io/agentmesh/docs/guides/egress-destinations/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/egress-destinations/</guid><description>&lt;p>An agentic application calls APIs that are not on the mesh: a source
forge, a ticketing system, an internal REST service, a model provider. This
guide puts a &lt;code>agentmesh-node&lt;/code> in front of such a destination as a policy
enforcement point. The application changes one base URL. The admin writes
one policy document. The node decides every request on the method, the
path and the caller, holds the credential the destination needs, and keeps
it out of the application.&lt;/p></description></item><item><title>Headless enrollment</title><link>https://google.github.io/agentmesh/docs/guides/headless-enrollment/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/headless-enrollment/</guid><description>&lt;p>Servers, containers and routers cannot complete an interactive login: there
is no browser, and no person to log in. Such a machine enrolls in one of two
ways: with an OIDC token that it already holds, or with a bootstrap token
that an operator mints for it. This guide covers both, and then explains
what happens when the credential of such a node expires.&lt;/p>
&lt;h2 id="with-an-oidc-token-that-the-workload-already-has">With an OIDC token that the workload already has&lt;/h2>
&lt;p>If the platform gives the workload a token from an issuer that the control
plane trusts, no operator step is needed. Mark workload issuers with
&lt;code>--workload-issuer&lt;/code> on the control plane so workload tokens can enroll,
refresh, and exchange credentials (&lt;code>POST /register&lt;/code>, &lt;code>POST /refresh&lt;/code>,
&lt;code>POST /token/exchange&lt;/code>), while being refused at human operator endpoints
(&lt;code>/user/*&lt;/code>, &lt;code>/oauth/authorize&lt;/code>).&lt;/p></description></item><item><title>agentmesh-one</title><link>https://google.github.io/agentmesh/docs/reference/agentmesh-one/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/agentmesh-one/</guid><description>&lt;p>&lt;code>agentmesh-one&lt;/code> runs a control plane, a router and the web console in one process
on one port. The router&amp;rsquo;s libp2p transport is WebSocket on the same port as
the HTTP API, so a node needs only one &lt;code>https&lt;/code> URL. The same binary is also
the admin client for a running instance.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-text" data-lang="text">&lt;span class="line">&lt;span class="cl">agentmesh-one [flags] run the mesh
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-one token create|list|revoke|qr manage bootstrap tokens on a running instance
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">agentmesh-one admin ban &amp;lt;peer-id&amp;gt; ban a node
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="files">Files&lt;/h2>
&lt;p>Everything lives in &lt;code>--data-dir&lt;/code> (default &lt;code>.&lt;/code>): &lt;code>agentmesh.db&lt;/code> (SQLite), the
router key, &lt;code>join-token&lt;/code> and &lt;code>admin-token&lt;/code> when generated, and &lt;code>bin/&lt;/code> for a
downloaded tunnel connector.&lt;/p></description></item><item><title>Kubernetes</title><link>https://google.github.io/agentmesh/docs/guides/kubernetes/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/kubernetes/</guid><description>&lt;p>This guide deploys a control plane, a router and a console into a cluster
with the &lt;code>agentmesh-p2p&lt;/code> Helm chart, then puts services on the mesh with the
&lt;code>agentmesh-node&lt;/code> chart. The last section lists the settings to change when you
move from a test cluster to one that you keep. The public testnets run this
setup on GKE. Their manifests are in &lt;code>.github/k8s/&lt;/code> in the repository.&lt;/p>
&lt;h2 id="what-gets-deployed">What gets deployed&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Component&lt;/th>
 &lt;th>Kind&lt;/th>
 &lt;th>Notes&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;code>agentmesh-control-plane&lt;/code>&lt;/td>
 &lt;td>Deployment (2 replicas)&lt;/td>
 &lt;td>Stateless. All state is in PostgreSQL.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>PostgreSQL&lt;/td>
 &lt;td>StatefulSet&lt;/td>
 &lt;td>In-cluster by default (&lt;code>database.postgres.deployInternal&lt;/code>). You can point the chart at your own database instead.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>agentmesh-router&lt;/code>&lt;/td>
 &lt;td>StatefulSet&lt;/td>
 &lt;td>A PVC holds &lt;code>router.key&lt;/code>, so the peer ID survives rescheduling.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>agentmesh-console&lt;/code>&lt;/td>
 &lt;td>Deployment&lt;/td>
 &lt;td>Optional (&lt;code>console.enabled&lt;/code>).&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>bootstrap Job&lt;/td>
 &lt;td>Job (post-install hook)&lt;/td>
 &lt;td>Seeds the mesh policy and mints the router&amp;rsquo;s bootstrap token.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Gateway + HTTPRoute&lt;/td>
 &lt;td>Gateway API&lt;/td>
 &lt;td>Optional (&lt;code>gateway.enabled&lt;/code>). Routes the enrollment paths and the console.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;p>The chart does not include an identity provider, and the control plane needs
one to start. The cluster&amp;rsquo;s own OIDC issuer is a good choice, because every
pod can then enroll with a projected service account token and no secret has
to be distributed.&lt;/p></description></item><item><title>Networking and the node API</title><link>https://google.github.io/agentmesh/docs/concepts/networking/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/networking/</guid><description>&lt;p>This page follows a request from an agent to a service on another node:
how the calling node finds the provider, how the two connect, and what the
agent sees at each end.&lt;/p>
&lt;h2 id="the-nodes-local-api">The node&amp;rsquo;s local API&lt;/h2>
&lt;p>An agent does not speak to the mesh directly. It speaks to the &lt;code>agentmesh-node&lt;/code> on
its own machine, through one of two listeners:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>TCP&lt;/strong>, &lt;code>127.0.0.1:8080&lt;/code> by default (&lt;code>--bind-addr&lt;/code>). Every request must
carry the node&amp;rsquo;s API token as &lt;code>X-Mesh-Authentication: Bearer &amp;lt;token&amp;gt;&lt;/code>.&lt;/li>
&lt;li>&lt;strong>A Unix socket&lt;/strong>, &lt;code>&amp;lt;data-dir&amp;gt;/agentmesh.sock&lt;/code> by default (&lt;code>--socket-path&lt;/code>),
created with mode &lt;code>0600&lt;/code>. No token is needed, because only the user who
owns the socket can open it. &lt;code>docker.sock&lt;/code> works the same way.&lt;/li>
&lt;/ul>
&lt;p>You can turn either listener off by passing an empty value. With
&lt;code>--bind-addr=&lt;/code>, the node has no listening port and no secret to manage. This
is a good setup when everything that uses the node runs as the same user.&lt;/p></description></item><item><title>Scale report: what an agent costs</title><link>https://google.github.io/agentmesh/docs/preview/scale-report/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/scale-report/</guid><description>&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Preview&lt;/h4>

 These measurements are of the sandbox datapath described in
&lt;a href="../sandboxed-agents/">Sandboxed agents&lt;/a>. They were recorded on 2026-08-21
at commit &lt;code>e5b2966&lt;/code>, when the boundary spoke SOCKS5. The boundary has since
moved to HTTP &lt;code>CONNECT&lt;/code> and has not been measured again. The shape of the
results is what matters. Single figures are indicative.

&lt;/div>

&lt;p>The design gives every agent its own boundary, which resolves names and
enforces policy on each flow. That sounds expensive. This page measures it.
The method is written down so that the result can be challenged, and a
script is provided so that it can be run again. There are two experiments: a
sweep of boundaries attached to one node, and a thousand agents in microVMs
on one host.&lt;/p></description></item><item><title>Control and data boundaries</title><link>https://google.github.io/agentmesh/docs/concepts/boundaries/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/concepts/boundaries/</guid><description>&lt;p>When you run your own control plane, you decide everything about the mesh.
On the public testnets, someone else decides who joins and what the policy
says. This page lists the decisions that become yours in a dedicated
deployment and the mechanism that enforces each of them.&lt;/p>
&lt;h2 id="what-you-control-in-a-dedicated-deployment">What you control in a dedicated deployment&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Membership.&lt;/strong> Enrollment goes through your identity provider or through
bootstrap tokens that you mint. The bindings in the control plane decide
which identities receive which roles. An identity without a binding cannot
enroll a node.&lt;/li>
&lt;li>&lt;strong>The signing key.&lt;/strong> The control plane generates its Ed25519 signing keys
and stores them in its database. Every credential in the mesh is signed by
one of these keys, and nobody outside the deployment can mint or extend a
credential. The keys rotate on the schedule you set.&lt;/li>
&lt;li>&lt;strong>The policy.&lt;/strong> What each role may call, on which nodes and with which
labels, is stored in your database. It can only be changed with your admin
token or through your console.&lt;/li>
&lt;li>&lt;strong>Revocation.&lt;/strong> A ban takes effect on the next credential refresh (within
the credential TTL, 24 hours by default) and, through the mesh event
channel, immediately on every connected node.&lt;/li>
&lt;li>&lt;strong>Where the software runs.&lt;/strong> Agent Mesh is Apache-2.0, sends no telemetry, and
does not depend on any hosted service. The control plane, routers and
nodes run wherever you put them: a laptop, a private cluster, an
air-gapped network.&lt;/li>
&lt;/ul>
&lt;p>The public testnets give you none of this. They are useful for trying the
software. Do not put anything there that you would not publish.&lt;/p></description></item><item><title>Cloud Run</title><link>https://google.github.io/agentmesh/docs/guides/cloud-run/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/cloud-run/</guid><description>&lt;p>&lt;code>agentmesh-one&lt;/code> serves its HTTP API, the web console, and the router&amp;rsquo;s WebSocket
transport on a single port (&lt;code>8080&lt;/code>), and ships as a pre-built container image
(&lt;code>ghcr.io/google/agentmesh-one:latest&lt;/code>). Because &lt;code>agentmesh-one&lt;/code> automatically infers its
public &lt;code>wss://&lt;/code> router address from Cloud Run&amp;rsquo;s &lt;code>Host&lt;/code> and &lt;code>X-Forwarded-Proto&lt;/code>
headers on &lt;code>/info&lt;/code> and &lt;code>/enroll&lt;/code> and derives a deterministic router &lt;code>PeerID&lt;/code>
from &lt;code>AGENTMESH_ADMIN_TOKEN&lt;/code>, you can deploy a standalone control plane and router to
Google Cloud Run in a single command.&lt;/p></description></item><item><title>GitHub Codespaces</title><link>https://google.github.io/agentmesh/docs/guides/codespaces/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/codespaces/</guid><description>&lt;p>A codespace is a container that GitHub runs for you, with a terminal, an
editor and an &lt;code>https&lt;/code> URL for every port you forward. Started from this
repository, it gives you a control plane of your own with nothing installed
on your machine and no cloud account. &lt;code>agentmesh-one&lt;/code> runs inside it, your laptop
and your phone enroll over the public URL, and your GitHub account pays with
its free Codespaces quota (120 core-hours a month on a Free plan; a 2-core
machine is enough). The same setup lets you develop Agent Mesh, or a program that
uses one of its SDKs, against a mesh that external clients can reach.&lt;/p></description></item><item><title>Node configuration file</title><link>https://google.github.io/agentmesh/docs/reference/node-config/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/node-config/</guid><description>&lt;p>&lt;code>agentmesh-node.yaml&lt;/code> declares what a node is (labels), what it publishes
(services), what it requires from callers (attenuation) and what it requires
from providers (egress). Both &lt;code>agentmesh-node join&lt;/code> and &lt;code>agentmesh-node run&lt;/code> read it from
&lt;code>--config&lt;/code>, by default &lt;code>./agentmesh-node.yaml&lt;/code>. A missing file means an empty
configuration. Unknown keys are an error, because a typo under &lt;code>attenuation&lt;/code>
would otherwise weaken the node without notice.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-yaml" data-lang="yaml">&lt;span class="line">&lt;span class="cl">&lt;span class="nt">version&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;v1alpha1&amp;#34;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">&lt;/span>&lt;span class="nt">labels&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">region&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">eu-west-1&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">team&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">platform&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">&lt;/span>&lt;span class="nt">services&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="nt">type&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">mcp&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">name&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">code-reviewer&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">description&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;Reviews diffs&amp;#34;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">target_url&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;http://127.0.0.1:7777/mcp&amp;#34;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="nt">type&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">mcp&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">name&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">filesystem&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">command&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;npx&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;-y&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;@modelcontextprotocol/server-filesystem&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;/srv/docs&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">env&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">NODE_OPTIONS&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;--max-old-space-size=256&amp;#34;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="nt">type&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">inference&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">name&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">vllm&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">target_url&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;http://127.0.0.1:8000&amp;#34;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">target_auth_path&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">/etc/agentmesh/vllm-key&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="nt">type&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">a2a&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">name&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">triage&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">target_url&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="s2">&amp;#34;http://127.0.0.1:9999&amp;#34;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">&lt;/span>&lt;span class="nt">attenuation&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">rules&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="s1">&amp;#39;maintenance() &amp;lt;- time($t), $t &amp;gt; 2026-12-31T00:00:00Z;&amp;#39;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">checks&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="s1">&amp;#39;check if label(&amp;#34;team&amp;#34;, &amp;#34;platform&amp;#34;);&amp;#39;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">policies&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="s1">&amp;#39;deny if service(&amp;#34;mcp&amp;#34;, &amp;#34;filesystem&amp;#34;), group(&amp;#34;contractors&amp;#34;);&amp;#39;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>- &lt;span class="s1">&amp;#39;deny if maintenance();&amp;#39;&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w">&lt;/span>&lt;span class="nt">egress&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">require_labels&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="w"> &lt;/span>&lt;span class="nt">jurisdiction&lt;/span>&lt;span class="p">:&lt;/span>&lt;span class="w"> &lt;/span>&lt;span class="l">eu&lt;/span>&lt;span class="w">
&lt;/span>&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="version">&lt;code>version&lt;/code>&lt;/h2>
&lt;p>&lt;code>&amp;quot;v1alpha1&amp;quot;&lt;/code>, or omitted (read as &lt;code>v1alpha1&lt;/code>). A node refuses a version it
does not know.&lt;/p></description></item><item><title>Sandboxed Agent</title><link>https://google.github.io/agentmesh/docs/use-cases/sandboxed-agent/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/use-cases/sandboxed-agent/</guid><description>&lt;p>An agent runs in a sandbox with no route into the office: here, a GitHub
codespace. Through the mesh it reaches a model and an MCP server that listen
on loopback in the office, and &lt;code>api.github.com&lt;/code> with a credential it never
holds. The admin decides what it may call, down to the HTTP method and path,
watches every decision, and cuts it off when done.&lt;/p>
&lt;video autoplay loop muted playsinline controls style="width: 100%; border-radius: 8px;">
 &lt;source src="../../../demo-sandboxed-agent.mp4" type="video/mp4">
&lt;/video>
&lt;p>Source: &lt;a href="https://github.com/google/agentmesh/tree/main/development/examples/sandboxed-agent">&lt;code>development/examples/sandboxed-agent/&lt;/code>&lt;/a>.
The scenes, the narration and the recording recipe are in its
&lt;a href="https://github.com/google/agentmesh/blob/main/development/examples/sandboxed-agent/SCRIPT.md">&lt;code>SCRIPT.md&lt;/code>&lt;/a>.&lt;/p></description></item><item><title>Scale experiment: reproducing the thousand-agent run</title><link>https://google.github.io/agentmesh/docs/preview/scale-experiment/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/preview/scale-experiment/</guid><description>&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Preview&lt;/h4>

 The scripts under &lt;code>tests/scale/&lt;/code> and &lt;code>scripts/&lt;/code> are research tooling for the
&lt;a href="../scale-report/">scale report&lt;/a>. They are kept working but are not a
supported product surface.

&lt;/div>

&lt;p>The report says what was measured and what it means. This page says how to
run it again. The setup is one host, one &lt;code>agentmesh-node&lt;/code>, and &lt;em>N&lt;/em> agents. Each
agent is a Firecracker microVM with no network device, and its only way out
is a vsock to its own &lt;code>agentmesh-box&lt;/code>. A thousand agents have been run on one
&lt;code>n2-standard-64&lt;/code>.&lt;/p></description></item><item><title>Mesh policy</title><link>https://google.github.io/agentmesh/docs/reference/policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/policy/</guid><description>&lt;p>The mesh policy is one document held by the control plane: a list of roles,
a list of bindings and a list of egress destinations. It is posted as JSON
(protojson of &lt;code>PolicyConfig&lt;/code> in &lt;code>api/agentmesh.proto&lt;/code>) to &lt;code>POST /policies&lt;/code>, read
back from &lt;code>GET /admin/policy&lt;/code>, edited in the console, or given to
&lt;code>agentmesh-one --policy-file&lt;/code> for first boot.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-json" data-lang="json">&lt;span class="line">&lt;span class="cl">&lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;roles&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;name&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;mesh:role:node&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;allowed_services&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;system://mesh.catalog&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;allowed_labels&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;region=*&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="s2">&amp;#34;team=platform&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">},&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;name&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;developer&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;allowed_services&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;mcp://code-reviewer&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="s2">&amp;#34;mcp://build-runner.*&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="s2">&amp;#34;inference://*&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;allowed_targets&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;group:dev-nodes&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="s2">&amp;#34;node:12D3KooWSpecialNode&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;custom_datalog&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;tier(\&amp;#34;standard\&amp;#34;);&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">},&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;name&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;analyst&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;allowed_services&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;egress://bigquery.googleapis.com&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;allowed_targets&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;*&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;http&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span> &lt;span class="nt">&amp;#34;service&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;egress://bigquery.googleapis.com&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="nt">&amp;#34;methods&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;GET&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="s2">&amp;#34;POST&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span> &lt;span class="nt">&amp;#34;paths&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;/bigquery/v2/projects/my-proj/datasets/*&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">]&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;bindings&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span> &lt;span class="nt">&amp;#34;role&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;mesh:role:node&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="nt">&amp;#34;members&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;group:engineering&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="s2">&amp;#34;user:system:serviceaccount:agentmesh-nodes:calc-mcp-agentmesh-node&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span> &lt;span class="p">},&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span> &lt;span class="nt">&amp;#34;role&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;developer&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="nt">&amp;#34;members&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;group:engineering&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span> &lt;span class="p">},&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span> &lt;span class="nt">&amp;#34;role&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;analyst&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="nt">&amp;#34;members&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;group:analytics&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;egress&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;name&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;bigquery.googleapis.com&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;served_by&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;site=eu&amp;#34;&lt;/span>&lt;span class="p">],&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;broker&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;oidc_federation&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;token_endpoint&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;https://sts.googleapis.com/v1/token&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;audience&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="s2">&amp;#34;//iam.googleapis.com/projects/123/locations/global/workloadIdentityPools/agentmesh/providers/agentmesh-cp&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nt">&amp;#34;scopes&amp;#34;&lt;/span>&lt;span class="p">:&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="s2">&amp;#34;https://www.googleapis.com/auth/bigquery.readonly&amp;#34;&lt;/span>&lt;span class="p">]&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">]&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>The whole document is replaced on every post. Unknown fields are rejected,
so a misspelt key fails the request instead of dropping a grant without
notice.&lt;/p></description></item><item><title>Native SDKs</title><link>https://google.github.io/agentmesh/docs/guides/native-sdks/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/native-sdks/</guid><description>&lt;p>An agent written in JavaScript or Python can be a member of the mesh itself,
with no &lt;code>agentmesh-node&lt;/code> beside it. The SDK enrolls with the control plane, joins
through a router, finds services, calls MCP tools and inference or A2A
endpoints, and answers A2A requests for the agent itself. Every caller of
the agent is checked against the mesh policy before anything reaches your
code.&lt;/p>
&lt;p>This guide takes you from nothing to two programs on a mesh: an agent that
other members can call, and a caller that reaches a service by name and the
agent by its peer ID. Both programs are in the repository under
&lt;a href="https://github.com/google/agentmesh/tree/main/sdk/js/examples">&lt;code>sdk/js/examples&lt;/code>&lt;/a>
and
&lt;a href="https://github.com/google/agentmesh/tree/main/sdk/python/examples">&lt;code>sdk/python/examples&lt;/code>&lt;/a>,
and the repository&amp;rsquo;s tests run them against a real mesh, so what you read
here is what runs.&lt;/p></description></item><item><title>SkyPilot</title><link>https://google.github.io/agentmesh/docs/guides/skypilot/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/guides/skypilot/</guid><description>&lt;p>&lt;a href="https://docs.skypilot.co/">SkyPilot&lt;/a> provisions and manages compute across
Google Cloud, AWS, Azure, OCI, and Kubernetes using your existing cloud
credentials (&lt;code>sky check&lt;/code>). The repository includes a ready-to-run recipe,
&lt;a href="https://github.com/google/agentmesh/blob/main/deploy/skypilot/agentmesh-one.yaml">&lt;code>deploy/skypilot/agentmesh-one.yaml&lt;/code>&lt;/a>,
that deploys a standalone &lt;code>agentmesh-one&lt;/code> control plane and router with a persistent
disk and an outbound Cloudflare HTTPS tunnel (requiring no inbound firewall
rules).&lt;/p>
&lt;p>&lt;em>(Note: While &lt;code>deploy/skypilot/agentmesh-one.yaml&lt;/code> defaults to production VM sizing
(&lt;code>cpus: 2+&lt;/code>, &lt;code>memory: 8+&lt;/code>, matching &lt;code>e2-standard-2&lt;/code> on GCP or &lt;code>t3.large&lt;/code> on AWS),
you can also set &lt;code>cpus: 0.25+&lt;/code> and &lt;code>memory: 1+&lt;/code> to run on cloud provider free
tiers such as GCP &lt;code>e2-micro&lt;/code> or AWS &lt;code>t4g.micro&lt;/code> for testing.)&lt;/em>&lt;/p></description></item><item><title>Node API</title><link>https://google.github.io/agentmesh/docs/reference/node-api/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/reference/node-api/</guid><description>&lt;p>The local API that &lt;code>agentmesh-node run&lt;/code> serves to agents, gateways, and scripts on
the same machine or cluster. It is available on TCP (&lt;code>--bind-addr&lt;/code>, default
&lt;code>127.0.0.1:8080&lt;/code>) and on a Unix socket (&lt;code>--socket-path&lt;/code>, default
&lt;code>&amp;lt;data-dir&amp;gt;/agentmesh.sock&lt;/code>). The Envoy &lt;code>ext_authz&lt;/code> and &lt;code>ext_proc&lt;/code> endpoints are
served on the same listeners.&lt;/p>
&lt;h2 id="authentication">Authentication&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Listener&lt;/th>
 &lt;th>Requirement&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>TCP (&lt;code>--bind-addr&lt;/code>)&lt;/td>
 &lt;td>&lt;code>X-Mesh-Authentication: Bearer &amp;lt;token&amp;gt;&lt;/code> on every request, or &lt;code>Authorization: Bearer &amp;lt;token&amp;gt;&lt;/code> on non-proxy endpoints (&lt;code>/mcp&lt;/code>, &lt;code>/v1/*&lt;/code>, &lt;code>/egress/*&lt;/code>, &lt;code>/oauth/*&lt;/code>), or a client certificate when &lt;code>--tls-ca&lt;/code> is set.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Unix socket (&lt;code>--socket-path&lt;/code>)&lt;/td>
 &lt;td>None required for node-level access (the socket has mode &lt;code>0600&lt;/code>). A caller may still pass an Agent Mesh Task Biscuit or platform JWT in &lt;code>X-Mesh-Authentication&lt;/code> or &lt;code>Authorization&lt;/code> to scope the request to that caller&amp;rsquo;s identity and task rules.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;p>The bearer &lt;code>&amp;lt;token&amp;gt;&lt;/code> accepted by &lt;code>agentmesh-node&lt;/code> can be:&lt;/p></description></item><item><title>Warm Agent Pool</title><link>https://google.github.io/agentmesh/docs/use-cases/warm-agent-pool/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/use-cases/warm-agent-pool/</guid><description>&lt;p>Spread a batch of work across a pool of identical, already-running worker
agents. The pool is built from ordinary mesh MCP services, with no gossip and
no changes to the node.&lt;/p>
&lt;video autoplay loop muted playsinline controls style="width: 100%; border-radius: 8px;">
 &lt;source src="../../../demo-warm-agent-pool.mp4" type="video/mp4">
&lt;/video>
&lt;p>Source: &lt;a href="https://github.com/google/agentmesh/tree/main/development/examples/code-reviewer-pool">&lt;code>development/examples/code-reviewer-pool/&lt;/code>&lt;/a>.&lt;/p>
&lt;h2 id="the-idea">The idea&lt;/h2>
&lt;p>Some agent tools are expensive to start but cheap to reuse: a reviewer that
calls an LLM, a sandbox that boots a runtime, a service that holds a warm
model in memory. You do not want to start one per request, and you do not
want a single instance that handles all your work one job at a time. What
you want is a pool of identical, already-running workers, and something that
hands them out one job at a time.&lt;/p></description></item><item><title>Gemini Buddy</title><link>https://google.github.io/agentmesh/docs/use-cases/gemini-buddy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/use-cases/gemini-buddy/</guid><description>&lt;p>Hold a real multi-turn conversation with a second LLM exposed as an ordinary
mesh service. Your agent never resends the conversation, because the service
remembers its own side.&lt;/p>
&lt;p>Source: &lt;a href="https://github.com/google/agentmesh/tree/main/development/examples/gemini-buddy-mcp">&lt;code>development/examples/gemini-buddy-mcp/&lt;/code>&lt;/a>.&lt;/p>
&lt;h2 id="the-idea">The idea&lt;/h2>
&lt;p>Sometimes you want your agent to talk to another model: for a second
opinion, to discuss a design, or to use a specialist that builds up its own
context over many turns. The simple approach is to carry both conversations
in the orchestrator. Your agent would have to store the other model&amp;rsquo;s
transcript and replay all of it on every turn.&lt;/p></description></item><item><title>Multi-Tier Enterprise Guardrails &amp; Quality Gates</title><link>https://google.github.io/agentmesh/docs/use-cases/multi-tier-guardrails/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/use-cases/multi-tier-guardrails/</guid><description>&lt;video controls playsinline preload="metadata" style="width:100%; border-radius:8px; box-shadow:0 4px 20px rgba(0,0,0,0.4); margin-bottom: 1.5rem;">
 &lt;source src="../../../demo-multi-tier-guardrails.mp4" type="video/mp4">
&lt;/video>
&lt;p>When every developer and team starts shipping AI agents, organizations hit a governance paradox:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>Agent Developers&lt;/strong> want 1-command onboarding from a laptop or Cloud Run without waiting weeks for VPC peering, DNS records, or firewall tickets.&lt;/li>
&lt;li>&lt;strong>Platform &amp;amp; Networking Engineers&lt;/strong> want persistent logical service names (&lt;code>a2a://support.acme&lt;/code>) that survive replica swaps across environments without static proxy limits.&lt;/li>
&lt;li>&lt;strong>Central Security (CISO)&lt;/strong> wants an organization-wide policy floor, automated quality gates before an agent can serve production (&lt;code>env=staging&lt;/code> $\rightarrow$ &lt;code>env=prod&lt;/code>), and zero raw API credentials inside agent containers.&lt;/li>
&lt;li>&lt;strong>Department Leads &amp;amp; Individual End-Users&lt;/strong> want to narrow what an agent can do on &lt;em>their&lt;/em> infrastructure or on &lt;em>their&lt;/em> behalf—even when the organization&amp;rsquo;s baseline policy allows it.&lt;/li>
&lt;li>&lt;strong>Day-2 Operations (SRE)&lt;/strong> needs a correlated audit trail across every hop and a 1-command kill-switch (&lt;code>agentmesh-one admin ban&lt;/code>) if a peer misbehaves.&lt;/li>
&lt;/ol>
&lt;p>The runnable example in &lt;a href="https://github.com/google/agentmesh/tree/main/development/examples/multi-tier-guardrails">&lt;code>development/examples/multi-tier-guardrails/&lt;/code>&lt;/a> walks through all five personas in four acts using &lt;strong>real backends&lt;/strong> and zero changes to Agent Mesh&amp;rsquo;s core code:&lt;/p></description></item><item><title>A2A Chat</title><link>https://google.github.io/agentmesh/docs/use-cases/chat-a2a/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/use-cases/chat-a2a/</guid><description>&lt;p>Hold a multi-turn conversation with an &lt;a href="https://a2a-protocol.org/">A2A&lt;/a>
(Agent2Agent) agent hosted on a remote mesh node, using a stock, unmodified
&lt;code>a2a-sdk&lt;/code> client. There is no Agent Mesh-specific client code. The mesh regenerates
the agent card, and that is enough for the standard SDK to work as it is.&lt;/p>
&lt;p>Source: &lt;a href="https://github.com/google/agentmesh/tree/main/development/examples/chat-a2a">&lt;code>development/examples/chat-a2a/&lt;/code>&lt;/a>.&lt;/p>
&lt;h2 id="the-idea">The idea&lt;/h2>
&lt;p>A2A is how agents talk to each other on the mesh. An agent process that
speaks A2A over HTTP is declared on its node as a &lt;code>type: a2a&lt;/code> service, and
remote peers reach it through the proxy path &lt;code>/mesh/{peer}/a2a/{service}/...&lt;/code>
(see &lt;a href="../../guides/exposing-services/#a2a-agents">A2A agents&lt;/a>).&lt;/p></description></item><item><title>Privacy Policy</title><link>https://google.github.io/agentmesh/docs/privacy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://google.github.io/agentmesh/docs/privacy/</guid><description>&lt;p>&lt;strong>Last Updated:&lt;/strong> September 17, 2026&lt;/p>
&lt;p>This Privacy Policy explains how Agent Mesh Connect (&amp;ldquo;we&amp;rdquo;, &amp;ldquo;us&amp;rdquo;, or &amp;ldquo;our&amp;rdquo;) collects, uses, and protects your information when you use our mobile application.
Agent Mesh Connect is an open-source Agent Mesh network client designed for zero-trust, peer-to-peer connectivity.&lt;/p>
&lt;h2 id="1-information-we-collect">1. Information We Collect&lt;/h2>
&lt;p>To function as a background mesh network node, Agent Mesh Connect requests the following device permissions and data:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Location Data (Foreground and Background):&lt;/strong> We request access to your device&amp;rsquo;s precise and coarse location (&lt;code>ACCESS_FINE_LOCATION&lt;/code>, &lt;code>ACCESS_COARSE_LOCATION&lt;/code>, and &lt;code>ACCESS_BACKGROUND_LOCATION&lt;/code>).&lt;/li>
&lt;li>&lt;strong>Network State:&lt;/strong> We monitor your WiFi and network connections to maintain the mesh tunnel.&lt;/li>
&lt;li>&lt;strong>Node Identity:&lt;/strong> Cryptographic keys (such as Ed25519 root keys), biscuits, and local API tokens used for mesh authentication and zero-trust identity federation.&lt;/li>
&lt;/ul>
&lt;h2 id="2-how-we-use-location-data">2. How We Use Location Data&lt;/h2>
&lt;p>Because Agent Mesh Connect operates as a continuous mesh network router, it requires &lt;strong>Background Location&lt;/strong> access to maintain network stability, handle routing via the Model Context Protocol (MCP), and keep the foreground service alive even when the app is closed.&lt;/p></description></item></channel></rss>