All Classes and Interfaces

Class
Description
The A2A agent card document: the JSON shape A2A clients fetch from /.well-known/agent-card.json.
Optional A2A protocol features.
The operating organization.
One skill: an A2A client's unit of "what can this agent do".
The A2A gateway prototype: serves a group's discovered AgentCards as A2A agent cards over HTTP, so A2A clients see an AgentSpaces fleet through the standard discovery surface.
One task's push-notification registration (A2A tasks/pushNotificationConfig/*).
The A2A task-binding shapes: the JSON documents A2A clients exchange with the gateway, and the two space entry types the binding bridges them to.
The space entry an inbound A2A message becomes.
The result entry an agent completes an A2aMessages.A2aTaskEntry with.
An A2A artifact: a task's output.
An A2A message.
One content part; the v0.1 binding speaks text parts.
A2A task states the binding emits.
An A2A task status.
The A2A task document message/send and tasks/get return.
The full A2A task binding: message/send becomes a leased A2aMessages.A2aTaskEntry written into the fleet's space, agents take and complete it through whatever conflict strategy the space declares, and task state reads straight out of space semantics with no bookkeeping protocol of its own: the entry is readable: no agent holds it, the task is submitted; the entry exists but is claimed: an agent holds the take lease, the task is working; an A2aMessages.A2aTaskResult with the task's id exists: completed, and the result text is the task's artifact; the agent crashed: its take lease lapses, the entry reappears, and the task honestly reads submitted again, which is the space's crash-recovery idiom showing through the A2A surface; the entry is gone and its write lease has passed: no agent took it in time and none can now, so the task is failed with a status message saying so.
Translates AgentSpaces AgentCards to A2aAgentCards.
The local advertisement cache of one group (spec §6.3): populated by gossip, queried local-first, evicting by TTL, and admitting nothing unverified.
Wire form of an anti-entropy delta.
The wire form of a cached advertisement: type tag, the exact canonical bytes, the issuer's raw key, and the signature over those bytes.
A typed, TTL-bearing discovery document (spec §6.1).
Signs and verifies advertisements (spec P3: every advertisement circulates signed).
Binds annotated plain objects to spaces (plan §10.3, framework-neutral form): SpaceTake methods become virtual-thread worker loops with crash-equals-lease-lapse semantics, SpaceNotify methods become leased subscriptions, BidFunction methods become AUCTION cost functions, and an AgentCard is generated from the AgentSpec and the bound method signatures, then published through discovery so other peers can ask "who can produce a Finding from a ResearchTask" with no extra code.
A capability card describing an agent (spec §6.1): what it can pursue, the entry types it consumes and produces, and how expensive it tends to be.
The peer vouches that a key belongs to one of its agents (spec §4.2, QA4 A4-7).
Issues and verifies AgentCertificates (spec §4.2, QA4 A4-7): the peer signs the canonical CBOR of the unsigned body, and a verifier accepts a certificate only when the offered peer key hashes to the agent's peer, the signature verifies under it, the certificate names the agent the caller is asking about, and it has not lapsed.
The identity of a logical agent hosted by a peer (§4.2 of the spec): AgentID = (PeerID, local-name).
Who signs on behalf of one agent (spec §4.2, QA4 A4-7).
Supplies the identity each bound agent signs as (SPEC §4.2, v0.1.13): the peer-signed form, a renewing subordinate key, a key loaded from the agent keystore, or a hardware-backed AgentIdentity of the application's own.
Persistent agent keys (SPEC §4.2, v0.1.13, TODO-9-10-11 B5), so a subordinate agent keeps its key, and so its attested identity, across restarts.
The application-facing entry point (spec §10.2): a registry of joined groups and their spaces behind one fluent chain, deliberately in Embabel's context-narrowing style, where each step returns a narrower typed context and the terminal operations are the typed Space verbs:
Serves the fleet's A2A gateway when agentspaces.a2a.enabled=true (TODO item 7, TECH-SPEC §9.4): the fleet's AgentCards as A2A Agent Cards and A2A JSON-RPC tasks bound to agentspaces.a2a.space, gated by the same bearer rule the console uses.
Starts the A2A gateway after the fabric and stops it before (TODO item 7): the same phase discipline as the console lifecycle.
Boots the AgentSpaces fabric from AgentSpacesProperties (spec §10.1): one PeerIdentity (keystore-backed or generated), one PeerNode listening or dial-only (with the optional multicast beacon), one joined group per configuration entry — founded locally from a string or joined by self-certifying GroupId URI — with rendezvous-sized discovery, a block exchange for bulk payloads (§6.1a), advertised and admission-controlled replicated spaces (§7.5) registered with their writer ids, and the shipped capability providers on a CapabilityRuntime (§10.5); all navigable through the AgentSpaces fluent facade, with AgentSpacesLifecycle driving ticks and card/capability refresh and AgentSpacesBeanPostProcessor binding annotated beans.
Enrolls annotated Spring beans in the fleet (spec §10.3, §10.4, §10.5): any bean carrying AgentSpec or space-bound methods (SpaceTake, SpaceNotify, BidFunction) binds after initialization, which starts its worker loops, wires its bids, and publishes its AgentCard; a ProvidesCapability bean implementing CapabilityProvider is registered on its groups' capability runtimes and advertised.
Serves the fleet console when agentspaces.console.enabled=true (spec's "the console is one more read-only peer": everything shown derives from this peer's replicas, membership, and ad cache).
Binds the console server to the application's lifecycle: serving begins on context start, after the fabric itself is up (a later phase than AgentSpacesLifecycle), and ends first on the way down, so the console never outlives the state it reports.
Base runtime exception for AgentSpaces.
Drives the fabric with the application's lifecycle: on context start, the node begins ticking (membership probes, anti-entropy, self-advertisement refresh) and bound agents' cards refresh on their leased cadence (P2); on context stop, both stop.
Configuration for the AgentSpaces starter (spec §10.1), bound from the agentspaces prefix:
The A2A gateway (agentspaces.a2a.*, TODO item 7): off by default.
The capability providers the starter ships into every networked group (agentspaces.capabilities.*, spec §10.5).
Command-and-control settings (agentspaces.console.command.*).
The served fleet console (agentspaces.console.*): off by default, on with agentspaces.console.enabled=true, at which point the peer serves the console UI, the HAL+JSON API, and the SSE activity stream on the configured port.
A group's content-key rotation settings (SPEC §11a.3, v0.1.13).
Cryptography settings.
The Embabel bridge (agentspaces.embabel.*).
One group to join.
How bound agents sign (QA4 A4-7 phase 3).
The LAN multicast bootstrap beacon (agentspaces.multicast.*, spec §10.1 bootstrap: multicast; off by default).
 
Explicit per-operation grants for the membership-rooted profiles (dev-local, mtls; TODO-EFG §4): each list names the PeerIDs permitted the operation in every networked group; an empty list leaves the operation open to any admitted member.
The identity provider behind the mtls-oidc and zero-trust profiles (TODO-EFG §4): issuer, audience, and jwks-url build the fleet's OidcAuthorizer and are all required under those profiles (startup fails fast naming the missing one).
One replicated space within a group.
Transport settings (agentspaces.transport.*, spec §5.6).
TLS settings for the TCP transport (agentspaces.transport.tls.*).
Describes an agent class for the fleet: the human- and LLM-readable identity that becomes its AgentCard (spec §6.1).
The typed client for aspace:cap/aggregate (spec §8, §10.5): a thin wrapper over this group's PushSumAggregate, so application code joins an aggregation epoch and reads the converging fleet average through spaces.group("g").capability(AggregateClient.class).
Resolves AggregateClients; registered through ServiceLoader.
The aspace:// URI scheme (§4.4 of the spec): aspace://<groupId>/<spaceName>[#<entryId>].
A card describing a data asset (spec §6.1a, the v0.1.1 addendum): the sibling of the AgentCard for peers that provide data rather than pursue goals.
The connector SPI (ENTERPRISE §6): one implementation per source system.
One query's answer.
The authorization SPI (security remediation plan §6): answers "may peer P perform operation O in scope S?"
The finest identity an authorizer can speak about for an operation and scope (QA4 A4-7 phase 2).
The privileged operations an authorizer arbitrates.
The security profile's answer to "who may act" (TODO-EFG §4, TODO item 6): one Authorizer selection for the whole starter, exposed as a bean so applications pass it to the enforcement points the starter does not wire itself (RaftLog, DataQueryClient, ConnectorRuntime).
Casts this agent's ballot whenever a proposal appears in a vote space (SPEC §8 QUORUM, §10.3).
Base58 encoding with the Bitcoin alphabet, used (behind a multibase prefix) for peer, group, and space identifiers.
Authenticates a bearer token presented to one of the fabric's HTTP surfaces (the fleet console's command routes, the A2A gateway's JSON-RPC surface) and names the principal behind it.
The authenticated holder of a bearer token.
The BearerAuthenticator for the mtls-oidc posture (TODO item 7, TODO-EFG §5): the fleet console and the A2A gateway become OAuth2 resource servers, validating an identity-provider JWT on every request instead of comparing a shared string.
The cost function for an AUCTION space (spec §7.4, plan §10.3): given a candidate entry, return this agent's cost; the lowest bid across the fleet wins the entry.
Content-addressed block storage and exchange (spec §7.1, §9): large payloads are stored under their CID (multibase(sha-256(bytes))), the space replicates only the reference, and a replica missing a block asks holders with BLOCK_WANT and verifies the returned BLOCK against the CID before storing it, which makes integrity and deduplication free.
The kind-specific body payloads carried inside Envelopes.
ACK body.
The CHANNEL_HELLO body (spec §5.6): the sender's announcement that it accepts channel-attested (unsigned) frames on the connection this frame arrived on.
DIGEST body: the sender's per-stream anti-entropy digests.
PING body.
PING_REQ body: ask the receiver to probe target for the asker.
PULL_RESP body: per-stream deltas the receiver was missing.
RELAY_FRAME body (spec §5.4): a complete signed frame carried for a peer that cannot be dialed directly.
RUMOR body: one item on a named stream.
Offers a capability service to a group (spec §8).
Produces a typed client for one capability service in one group (spec §10.5): spaces.group("g").capability(VoteClient.class) looks up the factory whose CapabilityClientFactory.clientType() is VoteClient and asks it to CapabilityClientFactory.create(AgentSpaces.GroupContext) a client over that group's spaces, discovery, and locally registered providers.
Direct capability frames (spec §9, PIPE_DATA in v0.1 datagram form): multiplexes one group's PIPE_DATA kind across capabilities by name, so several capability protocols share the wire without stepping on each other.
A provider of one capability service (spec §8, P6).
Injects a typed capability client into a field at bind time, the sibling of SpaceRef for Layer 4 (SPEC §10.3, §10.5): VoteClient, AggregateClient, SemanticClient, or any client type the binder or its group can resolve.
The Layer 4 pattern made uniform (spec §8): a provider registers, the runtime signs and publishes its CapabilityAdvertisement into the group's discovery flow, CapabilityRuntime.refreshTick() keeps the leased advertisement fresh while the provider runs, and consumers discover providers through the same ad-cache as everything else.
One action an agent offers (SPEC §6.1, v0.1.13): the declared pairing of what one bound method consumes with what it produces, so a planner or the remote-actions bridge (§10.6) sees exactly the agent's actions instead of the cross product of its card-level schema lists.
The canonical AgentSpaces codec: CBOR (RFC 8949) for all wire payloads and entry serialization, with a JSON view for logs and debugging.
The identity-endorsed TLS certificate for channel authentication (spec §5.6).
The enterprise-CA attestation mode (security remediation plan §3/§8, WS4): the peer's channel certificate is issued by the organization's CA with the Ed25519 PeerID as a certified attribute (the subject CN), so attesting a connection means both "the handshake proved possession of this certificate's key" and "the organization's trust root vouches that this PeerID belongs to an enrolled agent".
What a ConsoleCommand may do to the fleet, all under the console peer's signed identity.
The exclusive-take arbitration SPI (spec §7.4).
The conflict-resolution strategies a space may declare for exclusive take (spec §7.4).
Runs one connector (ENTERPRISE §6): publishes the provider's AssetCards under leases so agents can discover the holdings, and serves the aspace:cap/data-query protocol from the data space with pull-once semantics: before executing against the source, the runtime checks whether a live result for the same canonical hash already exists, and an existing result costs the source nothing.
How current a read must be (spec §7.2).
The command-and-control extension point: one operator action the console can execute against the fleet.
A form field the console renders for a command's input.
The field's input type, which the UI renders accordingly.
The result of executing a command.
One observed fleet activity, as streamed over /api/v1/events.
The console's extension point: one additional titled section on the served surface.
The console's queryable model, folded from the three sources the fabric already maintains: watched spaces (what is the fleet working on), membership (who is alive), and discovery (who can do what).
One advertisement as the console shows it.
Assembles a ConsoleView.
One group member as the console shows it.
One watched space's live statistics.
Refines the auto-configured console view.
A push-sum contribution returned from a @SpaceNotify or @SpaceTake method: instead of writing an entry, the binder starts (or joins) the aggregate epoch epochId with value as this peer's share (SPEC §8 aggregate).
Decides whether a result entry answers a given request entry.
The live SpaceCredential entries a CREDENTIAL-admitted replica holds (SPEC §7.5, TECH-SPEC §7.10), keyed by the credential entry's id.
A revocation of something certified other than a peer identity (SPEC §6.1, v0.1.13): an agent, one agent key, an X.509 channel leaf, or a join credential.
What is revoked.
One group's accepted CredentialRevocations (SPEC §6.1, v0.1.13): the revocations of agents, agent keys, X.509 leaves, and join credentials, held for the life of the process and reconciled by anti-entropy like the peer RevocationRegistry.
Authority ranks, highest first.
Decides a verified revocation's authority rank, or CredentialRevocationRegistry.Authority.NONE when its issuer may not revoke that target.
The agent side of aspace:cap/data-query (ENTERPRISE §3): fetch data by asset name and parameters, local-first.
One fetch's answer.
The aspace:cap/data-query entry types (spec §6.1a): agents write DataQueryEntries.DataQuery entries, connectors take them and complete with DataQueryEntries.DataResult entries, and the space gives both sides retries, observability, and decoupling for free.
One change a materializing provider pushed (spec §6.1a), leased for the asset's freshness window so the lease is the retention policy.
One query awaiting a connector.
One answered query, leased for its freshness window.
Builds the spaces the connector protocols flow through (spec §6.1a).
Digest helpers.
A command-and-control directive to the fleet's workers: an entry the commander writes into the control space and workers honor through a DirectiveGate.
The worker side of command-and-control: a worker attaches a gate to the control space and consults it before taking work, so a PAUSE, RESUME, or DRAIN directive the console broadcasts takes effect.
Attaches DirectiveGates under the profile's Authorizers (TODO-EFG §4): a worker calls DirectiveGates.attach(Space, String) on the control space and obeys whichever peers the group's authorizer permits DIRECTIVE_ISSUER in the scope of the group id — under the membership profiles the console peer (granted automatically where command-and-control runs, or listed in agentspaces.security.grants.directive-issuer on worker nodes), under the OIDC profiles the identity provider's aspace:directive-issuer[:<group>] scope — without naming a PeerID.
The sink a space publishes its signed SpaceAdvertisement into (spec §7.5).
Layer 2 discovery on one group (spec §6): publish signed advertisements into the group's gossip, find them local-first in the AdCache, and escalate to a scoped, hop-budgeted gossip query when the local cache is not enough.
A dot: one replica's uniquely numbered event, the unit of causality in the OR-Set (spec §7.3).
Parses the duration strings the annotations accept: the Spring-style simple form (10m, 500ms, 2h, 30s, 1d) and ISO-8601 (PT10M), so annotation values read the way Spring Boot properties do while older ISO values keep working.
Ed25519 (RFC 8032), the facade every signature in AgentSpaces goes through.
Activates the Embabel bridge when Embabel is on the application classpath (spec §10): every @Agent bean's metadata becomes a published AgentCard in every joined group (§10.4), with worker loops still declared through @SpaceTake on actions and bound by the core starter; the fleet's cards come back as a generated planner agent (§10.6) that deploys onto the application's AgentPlatform bean automatically.
Publishes an Embabel-derived card for every @Agent bean, into every group (§10.4).
Publishes AgentCards from Embabel agent metadata (spec §10.4): the @Agent description, the goals its @AchievesGoal actions achieve, and the domain types its @Action methods consume and produce, all read reflectively so no Embabel artifact is needed at build time.
Reads Embabel agent metadata reflectively by fully qualified annotation name (spec §10.4), so this module compiles with no Embabel artifact and works with whichever Embabel version the application ships.
What an Embabel agent declares, in AgentSpaces terms.
The fleet's discovered capabilities as Embabel planner actions (spec §14, resolved): every RemoteAction the RemoteActions registry exposes becomes one typed @Action method on a generated @Agent class, so Embabel's GOAP planner type-matches remote capabilities exactly as it matches local actions — a plan can chain a local action into a remote agent's skill and back, and the remote step is an ordinary leased space round-trip under the covers.
Keeps the Embabel platform's view of the fleet current (spec §10.6, auto-deploy): once started with a platform handed to EmbabelRemoteActionsDeployer.deployWhenReady(Object), it watches the bridge's remote-action registry and deploys a freshly generated @Agent through EmbabelRemoteActions.deployTo(Object) whenever the set of actions changes — the first time cards arrive, when a new card brings a new capability, and when an expired card takes one away.
Deploys the generated remote-fleet agent onto the application's Embabel AgentPlatform bean automatically (spec §10.6).
Maps text to a fixed-dimension vector for similarity ranking (spec §8, the semantic-discovery capability).
A writer's handle on a published entry: the means of renewing the write lease or withdrawing the entry early.
The issuer-generated identifier of a space entry (spec §7.1).
The wrapper the space keeps around every written entry (spec §7.1).
The replicated state of one entry (spec §7.3): observed-remove add/remove dot sets, a last-writer-wins lease register, and a monotone completed flag.
The wire envelope (spec §9): every frame between peers is a CBOR-encoded, signed envelope.
Frame kinds (spec §9).
A minimal self-signed X.509 certificate for the QUIC handshake, generated with nothing but the JDK: an EC P-256 key pair, a hand-assembled DER certificate structure, and a SHA256withECDSA signature.
Loads or creates a peer identity persisted on disk (spec §4.1: the ID is stable across restarts because the keypair is).
Shared test fixtures: simple entry types and identities used across module tests.
A simple result entry used across tests.
A simple task entry used across tests.
The command-and-control executor: it carries out operator commands against the fleet under the console peer's own fabric identity.
Assembles a FleetCommander.
One durable C2 audit record, written to the audit space.
Serves a ConsoleView as the fleet console.
Assembles a FleetConsoleServer.
The two-channel gossip bus of one group (spec §5.3).
Sends kind-tagged frames to a specific peer; provided by the peer node.
Receives rumor items on a stream.
The typed aspace:cap/gossip-learn capability (spec §8): decentralized model improvement over any MergeableModel.
Builder for GossipLearner.
One node's evaluation of one model at the end of an epoch; a metrics-space entry whose authenticated issuer is the evaluating node.
The aspace:cap/gossip-learn capability (spec §8) for parameter-vector models: GossipLearner specialised to double[] under WeightAveraging, so every exchange is a pairwise mean and the fleet's models converge to the fleet mean without any parameter server.
The founding document of a peer group (spec §5.1).
Gossip-bus parameters for a group (spec §5.3).
Group membership policies (spec §5.1).
Founds self-certifying groups and verifies their founding advertisements (spec §4.4, §5.1).
The founding document whose canonical CBOR hashes to the GroupID: the founding fields and the founder's signature over their canonical bytes.
The immutable founding fields of a group: everything a member relies on that no later party may change.
The self-certifying identifier of a peer group (§4.4, §5.1 of the spec): the multibase-encoded SHA-256 of the group's founding advertisement bytes.
A symmetric group content key (spec §11, v0.2 security): AES-256-GCM over entry payloads, so what gossip and anti-entropy carry across the wire is ciphertext, and only members holding the key can read entry contents.
The aspace:cap/key-wrap capability (SPEC §11a.2, §11a.3): sealed per-member distribution of a group's content keys, by epoch.
A group's content keys by epoch (SPEC §11a.3, v0.1.13, TODO-9-10-11 workstream D): epoch 0 is the configured key, and each rotation mints the next epoch with a cutover instant.
One held key.
Sealed per-member group-key wrap (spec §11, v0.2): delivers a GroupKey to one recipient so only that recipient can open it.
One sealed group key.
Leased membership for one group (spec §5.2): the membership view is fed by leased PeerAdvertisements arriving over gossip and by direct liveness contact, and a member that neither gossips nor answers within its TTL is dropped without ceremony (spec P2).
Membership tuning.
One member's view state.
Callback used by the probe cycle to send PING and PING_REQ frames.
One joined group on a peer: its membership view, its gossip bus, and the registration point upper layers (discovery, replicated spaces, capabilities) use to receive frames and publish rumors.
An authorizer scoped to one group (SPEC §11, v0.1.13, review M-4): it refuses whatever the group has revoked, peers and agents alike, and can require membership of the group, before asking the authorizer it wraps.
The model-free reference Embedder (spec §8): the feature-hashing trick over lowercased word tokens.
HKDF (RFC 5869) with HMAC-SHA-256: extract-then-expand key derivation.
A hybrid logical clock (HLC) timestamp: a physical wall-clock component in epoch milliseconds, a logical counter that disambiguates events within the same millisecond, and the identifier of the node that issued the timestamp.
A hybrid logical clock (Kulkarni et al.): issues HlcTimestamps that stay close to wall-clock time while remaining strictly monotonic on this node and causally consistent with timestamps received from other nodes.
The default SignatureProvider: the JDK's built-in EdDSA implementation, exactly the code every AgentSpaces version has run so far.
Founder-signed join credentials for INVITE groups (spec §5.1).
Key-file mechanics shared by the peer and agent keystores (TODO-9-10-11 B5): private keys as PKCS#8 DER, public keys raw; every file written to a same-directory temp file, flushed, and atomically renamed into place, private files created owner-only (0600) so no window exists in which another local user can read them; and every loaded pair proven by a sign/verify (or key agreement) probe, so a mismatched or half-written pair is refused with a message naming the files rather than used.
A requested lease duration.
Thrown when an operation requires a live lease and the lease has lapsed: renewing an expired handle, completing a take whose lease already expired, and so on.
The lease currently attached to an entry record (spec §7.1).
The kind of lease currently held on an entry (spec §7.1).
A complete single-JVM implementation of the Space API (plan §6): the full lease semantics of the model, entirely in process.
Builder for LocalSpace.
A last-writer-wins register ordered by hybrid logical clock (spec §7.3).
A predicate over a single field value in a Template condition.
Standard field matchers for Template conditions, intended for static import: Template.of(Task.class).where("priority", gte(3)).
The materializing provider style (spec §6.1a): a connector that pushes changes into a space as its source changes, alongside (or instead of) the catalog style AssetProvider answers on demand.
One change the source emitted.
The default Authorizer (security remediation plan §6): authority is rooted in the group's admitted membership, with optional explicit grants narrowing individual operations to named peers.
The pluggable admission check behind POLICY groups (spec §5.1): DID and verifiable-credential checks, allowlists, and organization-specific rules all implement this SPI.
The mergeable-model SPI of aspace:cap/gossip-learn (spec §8): how two peers' models combine on encounter and how a model travels the wire.
Minimal multibase support (the IPFS/multiformats convention of prefixing an encoded string with a character naming its base).
The opt-in LAN bootstrap beacon (spec §10.1 bootstrap: multicast, roadmap M1).
A datagram carrier: a connectionless, unreliable, best-effort way to broadcast bytes to whoever listens and to hear what others broadcast.
The enterprise Authorizer (security remediation plan §6, the mtls-oidc posture): privileged-operation policy lives in the organization's identity provider, carried as OAuth2 scopes in a JWT whose subject binding names the peer it authorizes.
Reacts once when a vote closes (SPEC §8 QUORUM, §10.3).
The exactly-once worker as one annotation (SPEC §7.4 ORDERED, §8, §10.3): SpaceTake's contract — take, act, complete-or-lapse — with the take routed through the space's ordered-log coordinator instead of the space's own claim race, so the log's commit order decides every take identically on every member and each entry is completed at most once, fleet-wide.
The ORDERED strategy (spec §7.4) as a coordinator over the RaftLog: signed take claims are submitted as log commands, the log's commit order arbitrates identically on every member, and the first valid committed claim per entry generation wins.
Describes a peer: how to reach it and which topology roles it offers (spec §5.4, §6.1).
One way of reaching a peer.
Optional topology roles a peer may serve for its group (spec §5.4).
The stable cryptographic identity of a peer (§4.1 of the spec): PeerID = multibase(sha-256(raw-public-key)).
A peer's cryptographic identity (spec §4.1): its Ed25519 keypair and the PeerID derived from the raw public key.
A peer: one process's presence in the AgentSpaces fabric (spec §5).
Builder for PeerNode.
How this node authenticates frames on its connections (spec §5.6).
The leased, signed self-description that travels on the peers stream: the canonical bytes of a PeerAdvertisement, the issuer's raw public key, and the signature over those bytes.
Uniform random peer sampling over a group's live membership (spec §5.2).
The direct-pipe surface a capability protocol needs (spec §8 pipes, TECH-SPEC §8.1): register a handler for one capability type's frames and send frames to a peer.
Marks a CapabilityProvider implementation as a capability service the fleet should advertise (spec §10.5): when such a bean is bound through the AgentSpaces facade, it is registered on the group's CapabilityRuntime, which starts it, signs and publishes its CapabilityAdvertisement, and keeps the advertisement fresh on every card refresh.
The aspace:cap/aggregate capability (spec §8): gossip aggregation over the group's capability pipes.
The aggregation operators (spec §8: sum|avg|count|min|max|quantile).
The PushSumAggregate.Mode.QUANTILE declaration: which quantile to read and the histogram it is read from.
The QUIC (RFC 9000) binding of the transport SPI (spec §5.5), on Netty's incubator QUIC codec over quiche: one bidirectional QUIC stream per peer connection carries the same length-prefixed frames as the TCP transport, so everything above the transport — membership, gossip, spaces — runs unchanged.
The aspace:cap/ordered-log capability (spec §8): a Raft group elected among a fixed set of volunteering members, exposing an append-ordered log that backs the ORDERED strategy.
Wire messages of the aspace:cap/ordered-log Raft protocol.
Log replication (and heartbeat when entries is empty).
A follower's replication reply.
A client's command forwarded to the leader.
The multiplexing envelope: exactly one field is set.
One replicated log entry.
A candidate's vote request.
A vote reply.
A piece of replicated state that participates in anti-entropy (spec §5.3).
A channel trust whose CRLs are re-read from files on a cadence (SPEC §5.6, v0.1.13, item 9): an operator, or a sidecar, replaces the CRL files and the fabric picks them up without a restart.
One remote agent's advertised capability as an invocable action (spec §14, resolved): a foreign AgentCard whose consumed and produced schemas resolve to local types becomes callable, and calling it is a space round-trip — write the input entry where the remote agent takes from, then await a result entry that correlates with the request.
The delegation target behind every generated @Action method (EmbabelRemoteActions): looks the invoked method up by name and runs its remote action as a space round-trip.
The fleet's discovered capabilities as available actions (spec §14, the "planner sees the fleet" question, resolved): every foreign AgentCard in the group's ad-cache whose consumed and produced schemas resolve to local classes becomes a RemoteAction — name, description, goals, typed input and output, and an invocation that is a space round-trip.
The replicated AgentSpace (spec §7): the same Space interface as LocalSpace, backed by the delta-CRDT replica and the group's gossip bus.
Builder for ReplicatedSpace.
The authoritative eject (security remediation plan §9): a statement by the group's trust root that a peer's identity is no longer legitimate.
What a CA-rooted peer revocation carries to prove itself (SPEC §6.1, v0.1.13): the revoked peer's channel chain, leaf first, as DER, and the CRL revoking the leaf, as DER, so a receiver with no fresh CRL of its own can still verify the CA's statement against its anchors.
One group's accepted revocations (security remediation plan §9, the authoritative half of the containment loop).
Decides whether a verified revocation is authorized: the seam that swaps trust roots without touching enforcement.
The wire form: the advertisement's exact canonical bytes with the issuer's raw key and signature over them, so verification is byte-stable across hops and languages (the SignedPeerAd pattern).
One group's accepted revocations as every enforcement point asks about them (SPEC §6.1, v0.1.13): peers by identity, and agents and agent keys under the freeze rule of CredentialRevocation.
Persists a group's content-key ring (SPEC §11a.3, v0.1.13, review B-2), so epochs minted by rotation survive restarts: every epoch key is sealed to this peer's own persisted X25519 key under a binding naming the group, epoch, and rotator, and the file is written atomically, owner-only, at <keystore>/content-keys/<group-id>.ring.
Maps entry classes to stable schema names and back (spec §7.1, P5).
One named security posture for a whole deployment (security remediation plan §4): an operator selects a profile and gets a coherent combination of transport, channel authentication, and authorization, rather than assembling individual flags and hoping they compose safely.
The typed client for aspace:cap/semantic-discovery (SPEC §8): find advertisements by meaning, locally or across the fleet.
Resolves the client from the group's locally provided semantic discovery.
The aspace:cap/semantic-discovery capability (spec §8): lookup by meaning over the group's advertisements.
One ranked match.
The TLS credential this node serves on its channels: a private key and its certificate chain.
The pluggable Ed25519 implementation seam (PERF1 phase 3).
An advertisement together with its issuer's raw Ed25519 public key and the signature over the advertisement's canonical CBOR bytes.
A self-certifying group's founding advertisement as it circulates (spec §4.4, §5.1): the GroupAdvertisement, the founder's raw Ed25519 public key, and the founder's signature over the canonical bytes of the advertisement's founding fields (GroupFounding.FoundingFields).
A deterministic in-memory transport fabric for tests (plan §6): every node gets a Transport whose scheme is mem, addresses are node names, and delivery is synchronous on the sender's thread.
The default schema registry: names a type <fully.qualified.Name>#v1.
The AgentSpace: a typed, leased tuple space (spec §7).
How far an entry's issuer is proven (spec §4.2, QA4 A4-7).
One matched entry with its authenticated writer.
The space admission rule (SPEC §7.5, TECH-SPEC §7.10): whether an agent may write, take, or complete in a space right now.
ALLOWLIST: the listed agents, and a refusal strikes.
AUTHORIZER: one permits question per scope.
CREDENTIAL: the issuer, plus holders of a live credential.
GROUP: everyone.
What an agent is asking to do.
Thrown when an agent the space does not admit attempts a write, take, or completion (spec §7.5): under Admission.ALLOWLIST only the listed agents may mutate the space; everyone in the group may still read.
The founding document of a space within a group (spec §7.5).
How a space admits writers and takers (SPEC §7.5).
How a space replicates (SPEC §7.3).
The one-annotation fleet agent, Spring-style: a stereotype that is both a @Component (so component scanning registers the bean) and an AgentSpec (so the starter's post-processor enrolls it in the fleet, starting its worker loops and publishing its AgentCard).
Thrown when an operation reaches a space that has been closed.
A space credential (SPEC §7.5, §11a.4): the payload of a reserved entry type the space's credential issuer writes into the space to admit an agent for the named scopes.
An event delivered to a SpaceListener.
The kinds of entry event a space emits.
The self-certifying identifier of a space (§4.4 of the spec): the multibase-encoded SHA-256 of the space's founding advertisement bytes.
Receives SpaceEvents for a Subscription.
The choreography sibling of SpaceTake: the method is invoked for every matching entry written to the space, without consuming it, and a non-void return value is written back as the next entry in the flow — react to X, produce Y, and Y is some other agent's cue.
Thrown when a write or take reaches a space that has become read-only (spec §7.5): the founders let the space's own lease lapse, or the space was explicitly marked read-only.
Injects a space handle into an agent field at bind time, so a method body can write entries mid-flight (progress markers, side outputs, scheduled writes) without carrying the facade in.
The replica state of one space as a delta-mergeable CRDT (spec §7.3): an OR-Set of entries keyed by EntryId, each carrying its own EntryState.
The replicated-worker idiom as one annotation (plan §10.3): the method's parameter type becomes a take template on the named space, the binder performs the leased take, invokes the method, and on normal return completes the take, writing a non-null result back as an entry.
Wire DTOs for replicated-space deltas and anti-entropy.
A rumor delta: one entry state, one signed claim, or both.
One entry's replicated state in wire form, together with the writer's raw public key so receivers can verify the record signature, and a signature over the mutable state so receivers can verify the transition itself.
A take claim with its holder's proof: the claim, the holder's raw public key, and the holder's signature over the claim's canonical bytes.
An anti-entropy delta: everything the remote replica was missing.
A leased event subscription created by Space.notify(Template, SpaceListener, Lease).
The reference AssetProvider: an in-memory table.
A take claim (spec §7.4) as a join-semilattice value, so replicas that merge the same claims agree on the winner with no coordination.
The take an annotated worker is running right now.
An exclusive, leased hold on a taken entry.
The TCP reference transport (spec §5.5): length-prefixed frames over a socket, with one virtual thread per connection reading inbound frames.
A typed template for associative matching against space entries (spec §7.2): an entry type plus zero or more field conditions.
A miniature certificate authority for tests of the enterprise-CA channel mode: mints a self-signed CA, issues leaf certificates that carry a raw Ed25519 identity key in the subject CN (the PeerID binding a real enrollment pipeline would certify), and issues CRLs revoking chosen leaves.
One issued credential: the leaf's key, its certificate, and the chain.
A manually advanced InstantSource for deterministic tests.
The TLS binding of the TCP transport (spec §5.6): the same length-prefixed frames as TcpTransport, inside TLS (RFC 8446) with mutual channel certificates.
The transport SPI (spec §5.5, P7).
A bidirectional, frame-oriented connection between two peers.
What a ChannelTrust concludes about a presented chain at an instant (SPEC §5.6, v0.1.13): only TrustStatus.Good attests, and only TrustStatus.Revoked with an authorizing reason can root a peer revocation in the CA.
A certificate in the chain had expired at the instant asked about.
The chain validates to an anchor and is not revoked: the CN's PeerID is vouched for.
The chain is empty, unparseable, or its leaf's CN carries no identity key.
A certificate in the chain was not yet valid at the instant asked about.
The chain validates to an anchor, and a CRL signed by its issuer lists the leaf.
No usable revocation information: no CRL from the issuer, or only stale ones.
The chain does not validate to an anchor.
The aspace:cap/vote capability (spec §8): collective decisions over a shared vote space.
One agent's ballot.
A closed decision.
A proposal put to the group.
The typed client for aspace:cap/vote (spec §8, §10.5): a thin wrapper over a VoteCapability bound to this group's vote space, so application code proposes and votes through spaces.group("g").capability(VoteClient.class) and never touches the capability wiring.
Resolves VoteClients; registered through ServiceLoader.
The default MergeableModel: a double[] parameter vector whose merge is the element-wise mean, so a fleet of models converges to the fleet mean and every exchange conserves the fleet sum.
Encodes, signs, decodes, and verifies wire frames.
An envelope as it travels: signed, or bare on an attested channel.
X25519 (RFC 7748) helpers over the JDK's built-in XDH provider.