Drivers, Backends, and repository boundaries
This chapter defines requirements within the authoritative platform architecture. The implementation status below separates current behavior from remaining design work.
Implementation status
Compute, IAM, Configuration, Secret, ServiceAccount, Plugin, Repo, Channel,
optional Sandbox, and Credential Gateway integrations have current contracts. The
InferenceDriver and general SandboxPolicy enforcement described below remain
planned. Current Channel operations validate credentials and look up provider
directories; runtime messaging is not a general OCC dispatch contract. Current
Sandbox is optional, can provision the dedicated Harness, and
exposes containment facets rather than the full policy interface in this design.
Stock OpenShell deployment remains unsupported. See
Driver development,
Sandbox, and
OpenShell limits for current contracts.
ComputeDriver
ComputeDriver realizes two independently scoped infrastructure lifecycles:
- Namespace-scoped
ensureNamespacecreates or reconciles only the backing tenant infrastructure in the selected runtime targets;deleteNamespaceremoves that Namespace's owned infrastructure across those targets after OCC authorizes deletion of an empty Namespace. The bundled Kubernetes Driver provisions and removes a driver-owned Kubernetes namespace, or reconciles and removes only OCC-owned infrastructure inside a discovered, operator-owned existing namespace in the tenant data plane. Cleanup preserves shared control-plane infrastructure and resources outside the exact owner. - Revision-scoped
prepareRevisioncreates or reuses the exact Agent's configured gateway and realizes the topology pinned in its immutable revision: one embedded OpenClaw process or a separate, nonserving dedicated Harness, following topology placement.retireRevisionstops only that revision's owned runtime while preserving its Agent's gateway and any resources required by the replacement. Agent deletion removes its own gateway and Harness resources across the selected targets.
One selected Compute Driver orchestrates both lifecycles across both runtime
targets. There is no separately selectable GatewayDriver. Namespace lifecycle
observations identify the exact Namespace and report backing-infrastructure
readiness or deletion without repeating the singleton Installation identifier.
Gateway and workload observations identify both the Namespace and owning Agent.
Installation configuration selects the allowed control-plane and tenant
data-plane runtime targets. The Driver resolves exact physical placement for
each operation while preserving the platform Namespace and Agent boundary.
Physical target coordinates, runtime endpoints, and transport credentials are
Driver-owned observations or materializations, not platform resources or
persisted AgentRevision fields. OCC owns the Namespace, gateway lifecycle,
Agent, immutable revision, workload identity, route bindings, authorization
decisions, and desired state. The driver consumes that admitted intent and
reports readiness or failure without changing platform ownership.
The bundled KubernetesComputeDriver and reviewed installed implementations can
be selected in development and production. Gateway reconciliation occurs
during its owner's deployment and revision replacement; gateway removal occurs
when that Agent or its Namespace is deleted. Agent workload preparation cannot
mutate another Agent's gateway or workload or expose the previously active
revision's credentials. Kubernetes independently owns scheduling and the
infrastructure lifecycle when the bundled Driver is selected.
The driver cannot target an unselected location or another platform Namespace, adopt another tenant's resources, change an Agent's configuration, rewrite its revision, select another identity, authorize a platform operation, or grant permissions. Gateway provisioning failure keeps the exact Agent deployment unready without changing Namespace readiness. Agent workload provisioning failure leaves sibling Agents and their gateways untouched and restores or fails closed for the previous active Agent workload. Readiness, activation, rollback, and cleanup account for both targets; partial failure cannot authorize traffic to an inactive revision or orphan resources by treating success in one target as overall success. OCC does not select a fallback target or compute implementation.
SandboxDriver
SandboxDriver enforces the exact SandboxPolicy admitted for one
AgentRevision. Installation configuration selects one implementation.
Before creating a candidate revision, OCC verifies that the selected Driver
supports the complete policy; unsupported, unavailable, or ambiguous
enforcement rejects deployment.
After candidate Agent workload provisioning, the Driver establishes and verifies
containment before the Harness executes Agent turns. The enforcement matches the exact
revision, Namespace, WorkloadIdentity, admitted policy, and applicable
Restrictions. OCC activates the revision only after that containment is
ready. SandboxDriver does not provision workloads, own resources, select
another identity, grant permissions, or replace an Agent's gateway.
Drivers and Backends
A Driver is the common integration boundary for a selected platform capability. OCC selects each Driver implementation through Installation configuration and passes the exact operation, scope, identity, and applicable Restrictions relevant to that capability. After OAG admits the request, the selected authorization Driver evaluates the exact requested operation; an execution Driver receives admitted intent only after OCC verifies that authorization. A Driver reports its decision, readiness, or operational result without acquiring platform-resource ownership or permission to select itself.
| Driver contract | Responsibility |
|---|---|
IAMDriver |
Evaluate the exact platform action and resource using its selected native or external authority. OCCIAMDriver evaluates OCC-owned roles and bindings. |
ServiceAccountDriver |
Create upstream service accounts and separately issue their credentials after exact OCC authorization; privately own Backend bindings and credential lifecycle while the provider retains its independent authority. |
InferenceDriver |
Perform authorized inference against an admitted external-provider model or local model source without exposing provider credentials, secret values, or reusable model credentials to Agent workloads. |
ComputeDriver |
Ensure Namespace infrastructure, store authorized account credentials, and reconcile each Agent's gateway and Harness in their selected runtime targets with exact Namespace, Agent, and revision ownership. |
SandboxDriver |
Enforce and verify the complete admitted containment policy before an Agent workload can execute Agent turns. |
SecretDriver |
Store Namespace-owned secret material and validate safe delivery references. KubernetesSecretDriver is the default. |
CredentialGatewayDriver |
Hold registered credential sources outside Agent workloads and issue per-revision attachments that only its paired SandboxDriver can apply. The OpenShell implementation shares one Backend with the OpenShell Sandbox. |
ChannelDriver |
Realize authorized Namespace-local messaging operations while the messaging provider retains independent authorization and credentials. |
One implementation may satisfy multiple Driver contracts, but OCC selects each
role explicitly. Authority for one role does not grant another role, resource
ownership, or permission. The selected IAMDriver evaluates authorization
before side effects; an effectful Driver handling a caller request runs only
after OAG admits that caller and OCC authorizes the exact operation.
ComputeDriver ensures backing Namespace infrastructure through an
independently authorized Namespace lifecycle operation, then creates each
Agent-owned gateway through that Agent's admitted revision operation. Each
relevant Driver enforces applicable platform Restrictions, and unsupported or
unverifiable enforcement fails closed.
ChatGPTServiceAccountDriver is one concrete implementation of the
ServiceAccountDriver capability. It receives Backend<ChatGPTClient>; the
client owns the configured workspace, trusted transport, and mounted admin
credential. backend[].drivers declares the exact related Driver selections,
and composition injects the Backend into its concrete member. The generic Driver
contract has no Backend identity field. All related Drivers are required. The current ChatGPT Backend requires the selected ServiceAccount
Driver; installed-package Backend injection is deferred. Only the API
entrypoint initializes the client and concrete Driver. The worker shares
nonsecret Backend metadata but receives neither the admin credential nor a
runtime Backend object. The Backend reference owns
the experimental configuration and lifecycle contract.
OCC authorizes account creation and credential issuance separately before any provider or Kubernetes side effect. The concrete Driver creates the provider account, then privately binds its Backend, Driver, account, and workspace identifiers to the exact OCC account and Namespace. Credential issuance persists the provider credential identifier privately for exact deletion and future rotation or reconciliation; the public account contains only a generic credential kind and opaque same-Namespace Secret reference. API-side Compute creates the account-owned canonical Secret. Worker-side Compute materializes the admitted token and workspace into a revision-owned runtime Secret for the exact dedicated Codex workload; see Secret delivery. Operations through a Backend fail closed when provider authority, the exact private binding, tenant-local Secret authority, or compatible dedicated execution is unavailable. OAuth refresh and automated rotation remain deferred.
One Installation-selected InferenceDriver may support server-approved OpenAI
or other provider models and local model sources. The immutable admitted Agent
Configuration and AgentRevision select the exact authorized model target;
local inference does not require a provider account. A denied, unavailable, or
unapproved target cannot fall back to another provider, local model, or
credential. Agent workloads cannot bypass OCC, their selected
InferenceDriver, or applicable model and network Restrictions.
Each AgentRevision pins the selected compute and sandbox implementations.
Installing or upgrading a Driver cannot replace either implementation for an
existing revision. OCC rejects removal while an active or candidate revision
depends on it. A changed runtime selection applies only to a later authorized
deployment. Current authorization, provider authority, and secret access remain
subject to immediate revocation.
Repository layout
Repository layout owns the current source tree. The controller application contains API and worker entrypoints, console assets, composition, Drivers, and Backend clients. Packages own shared contracts, platform state, IAM, and audit. Separate access-gateway, broker, and inference applications or packages are not implemented boundaries; the API and console already exist.
Capability ownership does not require a separate top-level directory. Shared Backend clients are Installation-scoped dependencies rather than Driver capabilities. External providers, accounts, and resources retain their own owners; an OCC ServiceAccount remains a platform representation of an upstream account.
