All Classes and Interfaces
Class
Description
The A2A agent card document: the JSON shape A2A
clients fetch from
/.well-known/agent-card.json.Optional A2A protocol features.
The operating organization.
One skill: an A2A client's unit of "what can this agent do".
The A2A gateway prototype: serves a group's discovered
AgentCards as A2A agent cards over HTTP, so A2A clients see an
AgentSpaces fleet through the standard discovery surface.One task's push-notification registration (A2A
tasks/pushNotificationConfig/*).The A2A task-binding shapes: the JSON documents A2A clients exchange with
the gateway, and the two space entry types the binding bridges them to.
The space entry an inbound A2A message becomes.
The result entry an agent completes an
A2aMessages.A2aTaskEntry with.An A2A artifact: a task's output.
An A2A message.
One content part; the v0.1 binding speaks text parts.
A2A task states the binding emits.
An A2A task status.
The A2A task document
message/send and tasks/get return.The full A2A task binding:
message/send
becomes a leased A2aMessages.A2aTaskEntry written into the fleet's space, agents
take and complete it through whatever conflict strategy the space declares,
and task state reads straight out of space semantics with no bookkeeping
protocol of its own:
the entry is readable: no agent holds it, the task is
submitted;
the entry exists but is claimed: an agent holds the take lease, the
task is working;
an A2aMessages.A2aTaskResult with the task's id exists: completed,
and the result text is the task's artifact;
the agent crashed: its take lease lapses, the entry reappears, and the
task honestly reads submitted again, which is the space's
crash-recovery idiom showing through the A2A surface;
the entry is gone and its write lease has passed: no agent took it in
time and none can now, so the task is failed with a status
message saying so.
Translates AgentSpaces
AgentCards to A2aAgentCards.The local advertisement cache of one group (spec §6.3): populated by gossip,
queried local-first, evicting by TTL, and admitting nothing unverified.
Wire form of an anti-entropy delta.
The wire form of a cached advertisement: type tag, the exact canonical
bytes, the issuer's raw key, and the signature over those bytes.
A typed, TTL-bearing discovery document (spec §6.1).
Signs and verifies advertisements (spec P3: every advertisement circulates
signed).
Binds annotated plain objects to spaces (plan §10.3, framework-neutral form):
SpaceTake methods become virtual-thread worker loops with
crash-equals-lease-lapse semantics, SpaceNotify methods become leased
subscriptions, BidFunction methods become AUCTION cost functions, and
an AgentCard is generated from the AgentSpec and the bound
method signatures, then published through discovery so other peers can ask
"who can produce a Finding from a ResearchTask" with no extra code.A capability card describing an agent (spec §6.1): what it can pursue, the entry
types it consumes and produces, and how expensive it tends to be.
The peer vouches that a key belongs to one of its agents (spec §4.2, QA4
A4-7).
Issues and verifies
AgentCertificates (spec §4.2, QA4 A4-7): the
peer signs the canonical CBOR of the unsigned body, and a verifier accepts a
certificate only when the offered peer key hashes to the agent's peer, the
signature verifies under it, the certificate names the agent the caller is
asking about, and it has not lapsed.The identity of a logical agent hosted by a peer (§4.2 of the spec):
AgentID = (PeerID, local-name).Who signs on behalf of one agent (spec §4.2, QA4 A4-7).
Supplies the identity each bound agent signs as (SPEC §4.2, v0.1.13): the
peer-signed form, a renewing subordinate key, a key loaded from the agent
keystore, or a hardware-backed
AgentIdentity of the application's
own.Persistent agent keys (SPEC §4.2, v0.1.13, TODO-9-10-11 B5), so a subordinate
agent keeps its key, and so its attested identity, across restarts.
The application-facing entry point (spec §10.2): a registry of joined groups
and their spaces behind one fluent chain, deliberately in Embabel's
context-narrowing style, where each step returns a narrower typed context and
the terminal operations are the typed
Space verbs:Serves the fleet's A2A gateway when
agentspaces.a2a.enabled=true
(TODO item 7, TECH-SPEC §9.4): the fleet's AgentCards as A2A Agent Cards and
A2A JSON-RPC tasks bound to agentspaces.a2a.space, gated by the same
bearer rule the console uses.Starts the A2A gateway after the fabric and stops it before (TODO item 7):
the same phase discipline as the console lifecycle.
Boots the AgentSpaces fabric from
AgentSpacesProperties (spec §10.1):
one PeerIdentity (keystore-backed or generated), one PeerNode
listening or dial-only (with the optional multicast beacon), one joined group
per configuration entry — founded locally from a string or joined by
self-certifying GroupId URI — with rendezvous-sized discovery, a block
exchange for bulk payloads (§6.1a), advertised and admission-controlled
replicated spaces (§7.5) registered with their writer ids, and the shipped
capability providers on a CapabilityRuntime (§10.5); all navigable
through the AgentSpaces fluent facade, with
AgentSpacesLifecycle driving ticks and card/capability refresh and
AgentSpacesBeanPostProcessor binding annotated beans.Enrolls annotated Spring beans in the fleet (spec §10.3, §10.4, §10.5): any
bean carrying
AgentSpec or space-bound methods (SpaceTake,
SpaceNotify, BidFunction) binds after initialization, which
starts its worker loops, wires its bids, and publishes its AgentCard; a
ProvidesCapability bean implementing CapabilityProvider is
registered on its groups' capability runtimes and advertised.Serves the fleet console when
agentspaces.console.enabled=true
(spec's "the console is one more read-only peer": everything shown derives
from this peer's replicas, membership, and ad cache).Binds the console server to the application's lifecycle: serving begins on
context start, after the fabric itself is up (a later phase than
AgentSpacesLifecycle), and ends first on the way down, so the
console never outlives the state it reports.Base runtime exception for AgentSpaces.
Drives the fabric with the application's lifecycle: on context start, the
node begins ticking (membership probes, anti-entropy, self-advertisement
refresh) and bound agents' cards refresh on their leased cadence (P2); on
context stop, both stop.
Configuration for the AgentSpaces starter (spec §10.1), bound from the
agentspaces prefix:The A2A gateway (
agentspaces.a2a.*, TODO item 7): off by default.The capability providers the starter ships into every networked group
(
agentspaces.capabilities.*, spec §10.5).Command-and-control settings (
agentspaces.console.command.*).The served fleet console (
agentspaces.console.*): off by
default, on with agentspaces.console.enabled=true, at which
point the peer serves the console UI, the HAL+JSON API, and the SSE
activity stream on the configured port.A group's content-key rotation settings (SPEC §11a.3, v0.1.13).
Cryptography settings.
The Embabel bridge (
agentspaces.embabel.*).One group to join.
How bound agents sign (QA4 A4-7 phase 3).
The LAN multicast bootstrap beacon (
agentspaces.multicast.*,
spec §10.1 bootstrap: multicast; off by default).Explicit per-operation grants for the membership-rooted profiles
(
dev-local, mtls; TODO-EFG §4): each list names the
PeerIDs permitted the operation in every networked group; an empty
list leaves the operation open to any admitted member.The identity provider behind the
mtls-oidc and
zero-trust profiles (TODO-EFG §4): issuer,
audience, and jwks-url build the fleet's
OidcAuthorizer and are all required under those profiles
(startup fails fast naming the missing one).One replicated space within a group.
Transport settings (
agentspaces.transport.*, spec §5.6).TLS settings for the TCP transport (
agentspaces.transport.tls.*).Describes an agent class for the fleet: the human- and LLM-readable identity
that becomes its AgentCard (spec §6.1).
The typed client for
aspace:cap/aggregate (spec §8, §10.5): a thin
wrapper over this group's PushSumAggregate, so application code joins
an aggregation epoch and reads the converging fleet average through
spaces.group("g").capability(AggregateClient.class).Resolves
AggregateClients; registered through ServiceLoader.The
aspace:// URI scheme (§4.4 of the spec):
aspace://<groupId>/<spaceName>[#<entryId>].A card describing a data asset (spec §6.1a, the v0.1.1 addendum): the sibling
of the
AgentCard for peers that provide data rather than pursue
goals.The connector SPI (ENTERPRISE §6): one implementation per source system.
One query's answer.
The authorization SPI (security remediation plan §6): answers "may peer P
perform operation O in scope S?"
The finest identity an authorizer can speak about for an operation and
scope (QA4 A4-7 phase 2).
The privileged operations an authorizer arbitrates.
The security profile's answer to "who may act" (TODO-EFG §4, TODO item 6):
one
Authorizer selection for the whole starter, exposed as a bean so
applications pass it to the enforcement points the starter does not wire
itself (RaftLog, DataQueryClient, ConnectorRuntime).Casts this agent's ballot whenever a proposal appears in a vote space (SPEC
§8 QUORUM, §10.3).
Base58 encoding with the Bitcoin alphabet, used (behind a multibase prefix) for
peer, group, and space identifiers.
Authenticates a bearer token presented to one of the fabric's HTTP surfaces
(the fleet console's command routes, the A2A gateway's JSON-RPC surface) and
names the principal behind it.
The authenticated holder of a bearer token.
The
BearerAuthenticator for the mtls-oidc posture (TODO item
7, TODO-EFG §5): the fleet console and the A2A gateway become OAuth2
resource servers, validating an identity-provider JWT on every request
instead of comparing a shared string.The cost function for an
AUCTION space (spec §7.4, plan §10.3): given
a candidate entry, return this agent's cost; the lowest bid across the fleet
wins the entry.Content-addressed block storage and exchange (spec §7.1, §9): large payloads
are stored under their CID (
multibase(sha-256(bytes))), the space
replicates only the reference, and a replica missing a block asks holders with
BLOCK_WANT and verifies the returned BLOCK against the CID
before storing it, which makes integrity and deduplication free.The kind-specific body payloads carried inside
Envelopes.ACK body.
The CHANNEL_HELLO body (spec §5.6): the sender's announcement that it
accepts channel-attested (unsigned) frames on the connection this frame
arrived on.
DIGEST body: the sender's per-stream anti-entropy digests.
PING body.
PING_REQ body: ask the receiver to probe
target for the asker.PULL_RESP body: per-stream deltas the receiver was missing.
RELAY_FRAME body (spec §5.4): a complete signed frame carried for a peer
that cannot be dialed directly.
RUMOR body: one item on a named stream.
Offers a capability service to a group (spec §8).
Produces a typed client for one capability service in one group (spec
§10.5):
spaces.group("g").capability(VoteClient.class) looks up the
factory whose CapabilityClientFactory.clientType() is VoteClient and asks it to
CapabilityClientFactory.create(AgentSpaces.GroupContext) a client over that group's spaces, discovery, and locally
registered providers.Direct capability frames (spec §9,
PIPE_DATA in v0.1 datagram form):
multiplexes one group's PIPE_DATA kind across capabilities by name, so several
capability protocols share the wire without stepping on each other.A provider of one capability service (spec §8, P6).
Injects a typed capability client into a field at bind time, the sibling of
SpaceRef for Layer 4 (SPEC §10.3, §10.5): VoteClient,
AggregateClient, SemanticClient, or any client type the
binder or its group can resolve.The Layer 4 pattern made uniform (spec §8): a provider registers, the runtime
signs and publishes its
CapabilityAdvertisement into the group's
discovery flow, CapabilityRuntime.refreshTick() keeps the leased advertisement fresh
while the provider runs, and consumers discover providers through the same
ad-cache as everything else.One action an agent offers (SPEC §6.1, v0.1.13): the declared pairing of
what one bound method consumes with what it produces, so a planner or the
remote-actions bridge (§10.6) sees exactly the agent's actions instead of
the cross product of its card-level schema lists.
The canonical AgentSpaces codec: CBOR (RFC 8949) for all wire payloads and entry
serialization, with a JSON view for logs and debugging.
The identity-endorsed TLS certificate for channel authentication (spec §5.6).
The enterprise-CA attestation mode (security remediation plan §3/§8, WS4):
the peer's channel certificate is issued by the organization's CA with the
Ed25519 PeerID as a certified attribute (the subject CN), so attesting a
connection means both "the handshake proved possession of this certificate's
key" and "the organization's trust root vouches that this PeerID belongs to
an enrolled agent".
What a
ConsoleCommand may do to the fleet, all under the console
peer's signed identity.The exclusive-take arbitration SPI (spec §7.4).
The conflict-resolution strategies a space may declare for exclusive
take (spec §7.4).Runs one connector (ENTERPRISE §6): publishes the provider's AssetCards
under leases so agents can discover the holdings, and serves the
aspace:cap/data-query protocol from the data space with pull-once
semantics: before executing against the source, the runtime checks whether a
live result for the same canonical hash already exists, and an existing
result costs the source nothing.How current a read must be (spec §7.2).
The command-and-control extension point: one operator action the console can
execute against the fleet.
A form field the console renders for a command's input.
The field's input type, which the UI renders accordingly.
The result of executing a command.
One observed fleet activity, as streamed over
/api/v1/events.The console's extension point: one additional titled section on the served
surface.
The console's queryable model, folded from the three sources the fabric
already maintains: watched spaces (what is the fleet working on),
membership (who is alive), and discovery (who can do what).
One advertisement as the console shows it.
Assembles a
ConsoleView.One group member as the console shows it.
One watched space's live statistics.
Refines the auto-configured console view.
A push-sum contribution returned from a
@SpaceNotify or
@SpaceTake method: instead of writing an entry, the binder starts (or
joins) the aggregate epoch epochId with value as this peer's
share (SPEC §8 aggregate).Decides whether a result entry answers a given request entry.
The live
SpaceCredential entries a CREDENTIAL-admitted
replica holds (SPEC §7.5, TECH-SPEC §7.10), keyed by the credential entry's
id.A revocation of something certified other than a peer identity (SPEC §6.1,
v0.1.13): an agent, one agent key, an X.509 channel leaf, or a join
credential.
What is revoked.
One group's accepted
CredentialRevocations (SPEC §6.1, v0.1.13): the
revocations of agents, agent keys, X.509 leaves, and join credentials, held
for the life of the process and reconciled by anti-entropy like the peer
RevocationRegistry.Authority ranks, highest first.
Decides a verified revocation's authority rank, or
CredentialRevocationRegistry.Authority.NONE
when its issuer may not revoke that target.The agent side of
aspace:cap/data-query (ENTERPRISE §3): fetch data
by asset name and parameters, local-first.One fetch's answer.
The
aspace:cap/data-query entry types (spec §6.1a): agents write
DataQueryEntries.DataQuery entries, connectors take them and complete with
DataQueryEntries.DataResult entries, and the space gives both sides retries,
observability, and decoupling for free.One change a materializing provider pushed (spec §6.1a), leased for the
asset's freshness window so the lease is the retention policy.
One query awaiting a connector.
One answered query, leased for its freshness window.
Builds the spaces the connector protocols flow through (spec §6.1a).
Digest helpers.
A command-and-control directive to the fleet's workers: an entry the
commander writes into the control space and workers honor through a
DirectiveGate.The worker side of command-and-control: a worker attaches a gate to the
control space and consults it before taking work, so a PAUSE, RESUME, or
DRAIN directive the console broadcasts takes effect.
Attaches
DirectiveGates under the profile's Authorizers
(TODO-EFG §4): a worker calls DirectiveGates.attach(Space, String) on the control
space and obeys whichever peers the group's authorizer permits
DIRECTIVE_ISSUER in the scope of the group id — under the membership
profiles the console peer (granted automatically where command-and-control
runs, or listed in agentspaces.security.grants.directive-issuer on
worker nodes), under the OIDC profiles the identity provider's
aspace:directive-issuer[:<group>] scope — without naming a PeerID.The sink a space publishes its signed
SpaceAdvertisement into
(spec §7.5).Layer 2 discovery on one group (spec §6): publish signed advertisements into
the group's gossip, find them local-first in the
AdCache, and escalate
to a scoped, hop-budgeted gossip query when the local cache is not enough.A dot: one replica's uniquely numbered event, the unit of causality in the
OR-Set (spec §7.3).
Parses the duration strings the annotations accept: the Spring-style simple
form (
10m, 500ms, 2h, 30s, 1d) and
ISO-8601 (PT10M), so annotation values read the way Spring Boot
properties do while older ISO values keep working.Ed25519 (RFC 8032), the facade every signature in AgentSpaces goes through.
Activates the Embabel bridge when Embabel is on the application classpath
(spec §10): every
@Agent bean's metadata becomes a published
AgentCard in every joined group (§10.4), with worker loops still declared
through @SpaceTake on actions and bound by the core starter; the
fleet's cards come back as a generated planner agent (§10.6) that deploys
onto the application's AgentPlatform bean automatically.Publishes an Embabel-derived card for every
@Agent bean, into every group (§10.4).Publishes AgentCards from Embabel agent metadata (spec §10.4): the
@Agent description, the goals its @AchievesGoal actions
achieve, and the domain types its @Action methods consume and
produce, all read reflectively so no Embabel artifact is needed at build
time.Reads Embabel agent metadata reflectively by fully qualified annotation name
(spec §10.4), so this module compiles with no Embabel artifact and works
with whichever Embabel version the application ships.
What an Embabel agent declares, in AgentSpaces terms.
The fleet's discovered capabilities as Embabel planner actions (spec §14,
resolved): every
RemoteAction the RemoteActions registry
exposes becomes one typed @Action method on a generated
@Agent class, so Embabel's GOAP planner type-matches remote
capabilities exactly as it matches local actions — a plan can chain a local
action into a remote agent's skill and back, and the remote step is an
ordinary leased space round-trip under the covers.Keeps the Embabel platform's view of the fleet current (spec §10.6,
auto-deploy): once
started with a platform handed to
EmbabelRemoteActionsDeployer.deployWhenReady(Object), it watches the bridge's remote-action
registry and deploys a freshly generated @Agent through
EmbabelRemoteActions.deployTo(Object) whenever the set of actions
changes — the first time cards arrive, when a new card brings a new
capability, and when an expired card takes one away.Deploys the generated remote-fleet agent onto the application's Embabel
AgentPlatform bean automatically (spec §10.6).Maps text to a fixed-dimension vector for similarity ranking (spec §8, the
semantic-discovery capability).
A writer's handle on a published entry: the means of renewing the write lease or
withdrawing the entry early.
The issuer-generated identifier of a space entry (spec §7.1).
The wrapper the space keeps around every written entry (spec §7.1).
The replicated state of one entry (spec §7.3): observed-remove add/remove dot
sets, a last-writer-wins lease register, and a monotone completed flag.
The wire envelope (spec §9): every frame between peers is a CBOR-encoded,
signed envelope.
Frame kinds (spec §9).
A minimal self-signed X.509 certificate for the QUIC handshake, generated
with nothing but the JDK: an EC P-256 key pair, a hand-assembled DER
certificate structure, and a SHA256withECDSA signature.
Loads or creates a peer identity persisted on disk (spec §4.1: the ID is stable
across restarts because the keypair is).
Shared test fixtures: simple entry types and identities used across module tests.
A simple result entry used across tests.
A simple task entry used across tests.
The command-and-control executor: it carries out operator commands against
the fleet under the console peer's own fabric identity.
Assembles a
FleetCommander.One durable C2 audit record, written to the audit space.
Serves a
ConsoleView as the fleet console.Assembles a
FleetConsoleServer.The two-channel gossip bus of one group (spec §5.3).
Sends kind-tagged frames to a specific peer; provided by the peer node.
Receives rumor items on a stream.
The typed
aspace:cap/gossip-learn capability (spec §8): decentralized
model improvement over any MergeableModel.Builder for
GossipLearner.One node's evaluation of one model at the end of an epoch; a metrics-space
entry whose authenticated issuer is the evaluating node.
The
aspace:cap/gossip-learn capability (spec §8) for parameter-vector
models: GossipLearner specialised to double[] under
WeightAveraging, so every exchange is a pairwise mean and the fleet's
models converge to the fleet mean without any parameter server.The founding document of a peer group (spec §5.1).
Gossip-bus parameters for a group (spec §5.3).
Group membership policies (spec §5.1).
Founds self-certifying groups and verifies their founding advertisements
(spec §4.4, §5.1).
The founding document whose canonical CBOR hashes to the GroupID: the
founding fields and the founder's signature over their canonical bytes.
The immutable founding fields of a group: everything a member relies on
that no later party may change.
The self-certifying identifier of a peer group (§4.4, §5.1 of the spec): the
multibase-encoded SHA-256 of the group's founding advertisement bytes.
A symmetric group content key (spec §11, v0.2 security): AES-256-GCM over
entry payloads, so what gossip and anti-entropy carry across the wire is
ciphertext, and only members holding the key can read entry contents.
The
aspace:cap/key-wrap capability (SPEC §11a.2, §11a.3): sealed
per-member distribution of a group's content keys, by epoch.A group's content keys by epoch (SPEC §11a.3, v0.1.13, TODO-9-10-11 workstream D):
epoch 0 is the configured key, and each rotation mints the next epoch with a
cutover instant.
One held key.
Sealed per-member group-key wrap (spec §11, v0.2): delivers a
GroupKey to one recipient so only that recipient can open it.One sealed group key.
Leased membership for one group (spec §5.2): the membership view is fed by
leased PeerAdvertisements arriving over gossip and by direct liveness contact,
and a member that neither gossips nor answers within its TTL is dropped without
ceremony (spec P2).
Membership tuning.
One member's view state.
Callback used by the probe cycle to send PING and PING_REQ frames.
One joined group on a peer: its membership view, its gossip bus, and the
registration point upper layers (discovery, replicated spaces, capabilities)
use to receive frames and publish rumors.
An authorizer scoped to one group (SPEC §11, v0.1.13, review M-4): it
refuses whatever the group has revoked, peers and agents alike, and can
require membership of the group, before asking the authorizer it wraps.
The model-free reference
Embedder (spec §8): the feature-hashing
trick over lowercased word tokens.HKDF (RFC 5869) with HMAC-SHA-256: extract-then-expand key derivation.
A hybrid logical clock (HLC) timestamp: a physical wall-clock component in epoch
milliseconds, a logical counter that disambiguates events within the same
millisecond, and the identifier of the node that issued the timestamp.
A hybrid logical clock (Kulkarni et al.): issues
HlcTimestamps that stay
close to wall-clock time while remaining strictly monotonic on this node and
causally consistent with timestamps received from other nodes.The default
SignatureProvider: the JDK's built-in EdDSA
implementation, exactly the code every AgentSpaces version has run so far.Founder-signed join credentials for
INVITE groups (spec §5.1).Key-file mechanics shared by the peer and agent keystores (TODO-9-10-11 B5):
private keys as PKCS#8 DER, public keys raw; every file written to a
same-directory temp file, flushed, and atomically renamed into place, private
files created owner-only (0600) so no window exists in which another local
user can read them; and every loaded pair proven by a sign/verify (or key
agreement) probe, so a mismatched or half-written pair is refused with a
message naming the files rather than used.
A requested lease duration.
Thrown when an operation requires a live lease and the lease has lapsed: renewing
an expired handle, completing a take whose lease already expired, and so on.
The lease currently attached to an entry record (spec §7.1).
The kind of lease currently held on an entry (spec §7.1).
A complete single-JVM implementation of the
Space API (plan §6): the
full lease semantics of the model, entirely in process.Builder for
LocalSpace.A last-writer-wins register ordered by hybrid logical clock (spec §7.3).
A predicate over a single field value in a
Template condition.Standard field matchers for
Template conditions, intended for static
import: Template.of(Task.class).where("priority", gte(3)).The materializing provider style (spec §6.1a): a connector that pushes
changes into a space as its source changes, alongside (or instead of) the
catalog style
AssetProvider answers on demand.One change the source emitted.
The default
Authorizer (security remediation plan §6): authority is
rooted in the group's admitted membership, with optional explicit grants
narrowing individual operations to named peers.The pluggable admission check behind
POLICY groups (spec §5.1): DID and
verifiable-credential checks, allowlists, and organization-specific rules all
implement this SPI.The mergeable-model SPI of
aspace:cap/gossip-learn (spec §8): how two
peers' models combine on encounter and how a model travels the wire.Minimal multibase support (the IPFS/multiformats convention of prefixing an
encoded string with a character naming its base).
The opt-in LAN bootstrap beacon (spec §10.1
bootstrap: multicast,
roadmap M1).A datagram carrier: a connectionless, unreliable, best-effort way to
broadcast bytes to whoever listens and to hear what others broadcast.
The enterprise
Authorizer (security remediation plan §6, the
mtls-oidc posture): privileged-operation policy lives in the
organization's identity provider, carried as OAuth2 scopes in a JWT whose
subject binding names the peer it authorizes.Reacts once when a vote closes (SPEC §8 QUORUM, §10.3).
The exactly-once worker as one annotation (SPEC §7.4 ORDERED, §8, §10.3):
SpaceTake's contract — take, act, complete-or-lapse — with the take
routed through the space's ordered-log coordinator instead of the space's own
claim race, so the log's commit order decides every take identically on every
member and each entry is completed at most once, fleet-wide.The
ORDERED strategy (spec §7.4) as a coordinator over the
RaftLog: signed take claims are submitted as log commands, the log's
commit order arbitrates identically on every member, and the first valid
committed claim per entry generation wins.Describes a peer: how to reach it and which topology roles it offers
(spec §5.4, §6.1).
One way of reaching a peer.
Optional topology roles a peer may serve for its group (spec §5.4).
The stable cryptographic identity of a peer (§4.1 of the spec):
PeerID = multibase(sha-256(raw-public-key)).A peer's cryptographic identity (spec §4.1): its Ed25519 keypair and the PeerID
derived from the raw public key.
A peer: one process's presence in the AgentSpaces fabric (spec §5).
Builder for
PeerNode.How this node authenticates frames on its connections (spec §5.6).
The leased, signed self-description that travels on the
peers
stream: the canonical bytes of a PeerAdvertisement, the issuer's raw public
key, and the signature over those bytes.Uniform random peer sampling over a group's live membership (spec §5.2).
The direct-pipe surface a capability protocol needs (spec §8 pipes, TECH-SPEC
§8.1): register a handler for one capability type's frames and send frames
to a peer.
Marks a
CapabilityProvider implementation as a capability service
the fleet should advertise (spec §10.5): when such a bean is bound through
the AgentSpaces facade, it is registered on the group's
CapabilityRuntime, which starts it, signs and publishes its
CapabilityAdvertisement, and keeps the advertisement fresh on every
card refresh.The
aspace:cap/aggregate capability (spec §8): gossip aggregation over
the group's capability pipes.The aggregation operators (spec §8:
sum|avg|count|min|max|quantile).The
PushSumAggregate.Mode.QUANTILE declaration: which quantile to read and the
histogram it is read from.The QUIC (RFC 9000) binding of the transport SPI (spec §5.5), on Netty's
incubator QUIC codec over quiche: one bidirectional QUIC stream per peer
connection carries the same length-prefixed frames as the TCP transport, so
everything above the transport — membership, gossip, spaces — runs unchanged.
The
aspace:cap/ordered-log capability (spec §8): a Raft group elected
among a fixed set of volunteering members, exposing an append-ordered log that
backs the ORDERED strategy.Wire messages of the
aspace:cap/ordered-log Raft protocol.Log replication (and heartbeat when
entries is empty).A follower's replication reply.
A client's command forwarded to the leader.
The multiplexing envelope: exactly one field is set.
One replicated log entry.
A candidate's vote request.
A vote reply.
A piece of replicated state that participates in anti-entropy (spec §5.3).
A channel trust whose CRLs are re-read from files on a cadence (SPEC §5.6,
v0.1.13, item 9): an operator, or a sidecar, replaces the CRL files and the
fabric picks them up without a restart.
One remote agent's advertised capability as an invocable action (spec §14,
resolved): a foreign
AgentCard whose consumed and produced schemas
resolve to local types becomes callable, and calling it is a space round-trip
— write the input entry where the remote agent takes from, then await a
result entry that correlates with the request.The delegation target behind every generated
@Action method
(EmbabelRemoteActions): looks the invoked method up by name and runs
its remote action as a space round-trip.The fleet's discovered capabilities as available actions (spec §14, the
"planner sees the fleet" question, resolved): every foreign
AgentCard
in the group's ad-cache whose consumed and produced schemas resolve to local
classes becomes a RemoteAction — name, description, goals, typed
input and output, and an invocation that is a space round-trip.The replicated AgentSpace (spec §7): the same
Space interface as
LocalSpace, backed by the delta-CRDT replica and the group's gossip
bus.Builder for
ReplicatedSpace.The authoritative eject (security remediation plan §9): a statement by the
group's trust root that a peer's identity is no longer legitimate.
What a CA-rooted peer revocation carries to prove itself (SPEC §6.1,
v0.1.13): the revoked peer's channel chain, leaf first, as DER, and the CRL
revoking the leaf, as DER, so a receiver with no fresh CRL of its own can
still verify the CA's statement against its anchors.
One group's accepted revocations (security remediation plan §9, the
authoritative half of the containment loop).
Decides whether a verified revocation is authorized: the seam
that swaps trust roots without touching enforcement.
The wire form: the advertisement's exact canonical bytes with the
issuer's raw key and signature over them, so verification is
byte-stable across hops and languages (the
SignedPeerAd pattern).One group's accepted revocations as every enforcement point asks about them
(SPEC §6.1, v0.1.13): peers by identity, and agents and agent keys under the
freeze rule of
CredentialRevocation.Persists a group's content-key ring (SPEC §11a.3, v0.1.13, review B-2), so
epochs minted by rotation survive restarts: every epoch key is sealed to this
peer's own persisted X25519 key under a binding naming the group, epoch, and
rotator, and the file is written atomically, owner-only, at
<keystore>/content-keys/<group-id>.ring.Maps entry classes to stable schema names and back (spec §7.1, P5).
One named security posture for a whole deployment (security remediation plan
§4): an operator selects a profile and gets a coherent combination of
transport, channel authentication, and authorization, rather than assembling
individual flags and hoping they compose safely.
The typed client for
aspace:cap/semantic-discovery (SPEC §8): find
advertisements by meaning, locally or across the fleet.Resolves the client from the group's locally provided semantic discovery.
The
aspace:cap/semantic-discovery capability (spec §8): lookup by
meaning over the group's advertisements.One ranked match.
The TLS credential this node serves on its channels: a private key and its
certificate chain.
The pluggable Ed25519 implementation seam (PERF1 phase 3).
An advertisement together with its issuer's raw Ed25519 public key and the
signature over the advertisement's canonical CBOR bytes.
A self-certifying group's founding advertisement as it circulates (spec §4.4,
§5.1): the
GroupAdvertisement, the founder's raw Ed25519 public key,
and the founder's signature over the canonical bytes of the advertisement's
founding fields (GroupFounding.FoundingFields).A deterministic in-memory transport fabric for tests (plan §6): every node gets a
Transport whose scheme is mem, addresses are node names, and
delivery is synchronous on the sender's thread.The default schema registry: names a type
<fully.qualified.Name>#v1.The AgentSpace: a typed, leased tuple space (spec §7).
How far an entry's issuer is proven (spec §4.2, QA4 A4-7).
One matched entry with its authenticated writer.
The space admission rule (SPEC §7.5, TECH-SPEC §7.10): whether an agent may
write, take, or complete in a space right now.
ALLOWLIST: the listed agents, and a refusal strikes.AUTHORIZER: one permits question per scope.CREDENTIAL: the issuer, plus holders of a live credential.GROUP: everyone.What an agent is asking to do.
Thrown when an agent the space does not admit attempts a write, take, or
completion (spec §7.5): under
Admission.ALLOWLIST only the listed
agents may mutate the space; everyone in the group may still read.The founding document of a space within a group (spec §7.5).
How a space admits writers and takers (SPEC §7.5).
How a space replicates (SPEC §7.3).
The one-annotation fleet agent, Spring-style: a stereotype that is both a
@Component (so component scanning registers the bean) and an
AgentSpec (so the starter's post-processor enrolls it in the fleet,
starting its worker loops and publishing its AgentCard).Thrown when an operation reaches a space that has been closed.
A space credential (SPEC §7.5, §11a.4): the payload of a reserved entry type
the space's credential issuer writes into the space to admit an agent for
the named scopes.
An event delivered to a
SpaceListener.The kinds of entry event a space emits.
The self-certifying identifier of a space (§4.4 of the spec): the multibase-encoded
SHA-256 of the space's founding advertisement bytes.
Receives
SpaceEvents for a Subscription.The choreography sibling of
SpaceTake: the method is invoked for
every matching entry written to the space, without consuming it, and a
non-void return value is written back as the next entry in the flow — react
to X, produce Y, and Y is some other agent's cue.Thrown when a write or take reaches a space that has become read-only
(spec §7.5): the founders let the space's own lease lapse, or the space was
explicitly marked read-only.
Injects a space handle into an agent field at bind time, so a method body
can write entries mid-flight (progress markers, side outputs, scheduled
writes) without carrying the facade in.
The replica state of one space as a delta-mergeable CRDT (spec §7.3): an OR-Set
of entries keyed by
EntryId, each carrying its own
EntryState.The replicated-worker idiom as one annotation (plan §10.3): the method's
parameter type becomes a take template on the named space, the binder performs
the leased take, invokes the method, and on normal return completes the take,
writing a non-null result back as an entry.
Wire DTOs for replicated-space deltas and anti-entropy.
A rumor delta: one entry state, one signed claim, or both.
One entry's replicated state in wire form, together with the writer's raw
public key so receivers can verify the record signature, and a signature
over the mutable state so receivers can verify the transition itself.
A take claim with its holder's proof: the claim, the holder's raw public
key, and the holder's signature over the claim's canonical bytes.
An anti-entropy delta: everything the remote replica was missing.
A leased event subscription created by
Space.notify(Template, SpaceListener, Lease).The reference
AssetProvider: an in-memory table.A take claim (spec §7.4) as a join-semilattice value, so replicas that merge
the same claims agree on the winner with no coordination.
The take an annotated worker is running right now.
An exclusive, leased hold on a taken entry.
The TCP reference transport (spec §5.5): length-prefixed frames over a socket,
with one virtual thread per connection reading inbound frames.
A typed template for associative matching against space entries (spec §7.2): an
entry type plus zero or more field conditions.
A miniature certificate authority for tests of the enterprise-CA channel
mode: mints a self-signed CA, issues leaf certificates that carry a raw
Ed25519 identity key in the subject CN (the PeerID binding a real enrollment
pipeline would certify), and issues CRLs revoking chosen leaves.
One issued credential: the leaf's key, its certificate, and the chain.
A manually advanced
InstantSource for deterministic tests.The TLS binding of the TCP transport (spec §5.6): the same length-prefixed
frames as
TcpTransport, inside TLS (RFC 8446) with mutual channel
certificates.The transport SPI (spec §5.5, P7).
A bidirectional, frame-oriented connection between two peers.
What a
ChannelTrust concludes about a presented chain at an instant
(SPEC §5.6, v0.1.13): only TrustStatus.Good attests, and only TrustStatus.Revoked
with an authorizing reason can root a peer revocation in the CA.A certificate in the chain had expired at the instant asked about.
The chain validates to an anchor and is not revoked: the CN's PeerID is vouched for.
The chain is empty, unparseable, or its leaf's CN carries no identity key.
A certificate in the chain was not yet valid at the instant asked about.
The chain validates to an anchor, and a CRL signed by its issuer lists the leaf.
No usable revocation information: no CRL from the issuer, or only stale ones.
The chain does not validate to an anchor.
The
aspace:cap/vote capability (spec §8): collective decisions over a
shared vote space.One agent's ballot.
A closed decision.
A proposal put to the group.
The typed client for
aspace:cap/vote (spec §8, §10.5): a thin
wrapper over a VoteCapability bound to this group's vote space, so
application code proposes and votes through
spaces.group("g").capability(VoteClient.class) and never touches the
capability wiring.Resolves
VoteClients; registered through ServiceLoader.The default
MergeableModel: a double[] parameter vector whose
merge is the element-wise mean, so a fleet of models converges to the fleet
mean and every exchange conserves the fleet sum.Encodes, signs, decodes, and verifies wire frames.
An envelope as it travels: signed, or bare on an attested channel.
X25519 (RFC 7748) helpers over the JDK's built-in XDH provider.