Sympozium 0.10.57 / Celln 0.5.8 — native Harness MLP¶
AgentRun remains the execution envelope. Choose a one-shot task for immediate results, or an enduring native Harness for a conversation whose parent cell retains live context and lends bounded work to disposable per-turn cells. Agent identity, policy, skills and tool permissions remain separate concepts.
Included¶
- UI and YAML selection of native Harness, Celln, enduring lifecycle and approved borrowed tool revisions. The initial toolbox is logical workspace read/write and allowlisted HTTPS fetch; defaults are not grants.
- Real model/tool work in KVM with host-held model credentials, sealed/hash-bound executables, durable turn identities, bounded authority and confirmed teardown.
- Refresh and controller/API restart reconciliation without resubmitting work; explicit context loss when the original owner/parent cannot continue.
- A Linux amd64 host archive, matching digest-pinned parent-controller image, operator-signed starter packaging/admission/configuration and namespace-scoped Kubernetes installation. No signing/model key or pre-approved grant is shipped.
- Authenticated one-shot router migration with durable ownership, distinct execution/discovery credentials, verified TLS and optional private-CA leaf renewal. Existing OCI Harness and ordinary Kubernetes paths remain available.
- A controller cache patch restoring namespace-scoped pod/result discovery when the general controller excludes the dedicated native parent namespace.
Supported limits¶
This is a single-owner Linux amd64/KVM MLP, not arbitrary OCI/Pi/Hermes processes inside a persistent cell. One active turn, approximately 2 KiB native context, finite lease and aggregate budgets remain explicit. Python, shell, checkpoints, pause/resume, nested/parallel turn trees and transparent host-crash recovery are not included. Native files/context are volatile with the parent. Historical journals without qualified process identity remain fenced for operator review; do not clear finalizers or reset journals to make them appear recovered.
Upgrade¶
Apply additive CRDs and RBAC before consumers; update the admission webhook, API and general controller together. Retain existing OCI runtime digests rather than substituting native assets. Reserve a dedicated namespace for the native parent controller. Native-only runtime registration is deliberately not an OCI Ready claim.
Use the installation guide and, where applicable, the one-shot migration guide. Keep the same owner roots and durable journals. Do not overwrite a running owner with a tar extraction; quiesce and confirm cleanup before an owner update.
See framework regression evidence and the integrated starter-system proof.