Architecture
Browser dashboard / + static Starlight docs /docs/ | chat, approvals and delegated events over SDK connectionsCodingOrchestrator (Think + Durable Object, name default) | delegate_coding_task, needsApproval: trueOpenCodeAgent (AIChatAgent + structured task envelope) | Sandbox runtime adapterSandbox Durable Object + container (one ID per run, max 3) | OpenCode with dummy Google keyWorker /api/provider/google -> account AI Gateway -> Google model
Worker /api/runs -> retained registryWorker GitHub REST calls -> optional branch and PRWorker /api/github/webhook -> verified acknowledgment onlyThe parent uses Workers AI for planning. Real model-provider and GitHub credentials are not supplied to the container by this implementation. The callback’s authentication remains incomplete; the diagram is not a validated production security boundary.
Source map
Section titled “Source map”| Path | Responsibility |
|---|---|
| src/index.ts | Assets, SDK routes, run API, provider forwarding, webhook |
| src/agents/orchestrator.ts | Planning, approval, delegation, retained registry |
| src/agents/opencode-agent.ts | Sandbox SDK operations, progress and publishing |
| src/runtime.ts | Clone, OpenCode execution, bounded file/diff collection |
| src/provider-gateway.ts | Server-side provider forwarding |
| src/github.ts | GitHub REST publication |
| src/runs.ts and src/transcript.ts | State and transcript helpers |
| client/main.tsx and client/app.tsx | Mounted dashboard |
| docs/ and scripts/ | Static documentation and build checks |
No D1, KV, Queues, R2, Postgres, Redis, or separate frontend service is required. State resides in Agents/Sandbox Durable Objects.
The runtime emits clone/configure/code/collect phases but awaits OpenCode execution; it does not stream every JSON event. The registry stores metadata and summary/error, not separate diff/file fields.
The specification requires Sandbox HTTPS interception, private Git transport credentials, and retained-registry gating of child routes. The present Worker proxy and direct SDK routing do not provide those guarantees. See Readiness.
Alternative runtimes
Section titled “Alternative runtimes”The computer adapter is a guarded refusal, not an implemented runtime. The intended fit of @cloudflare/computer includes persistent SQLite-backed VFS, typed Git operations, agent tools, and Worker-shell/container backends. It is not installed here. Verify current APIs and preview status in the package documentation before implementing it. The code retains the preview-only warning and defaults to Sandbox.
celld is not a deployment target: Workers-compatible execution alone does not provide the managed Sandbox/Containers bindings this repository uses.
Official sources: Agents, Sandbox, Containers, AI Gateway.
