BeansHost Agent Cloud

The control plane between
agent code and production.

BeansHost manages the desired state, deployment lifecycle, secure access, observability and governance of AI agents while customer execution stays in a separate runtime plane.

agent-cloud.beanshostSecure

AGENT / PRODUCTION

support-triage

beanshost.yaml · v1alpha1
Valid
checks passed12 / 12Current state
Activity
Live activityUpdated now
10:02

GitHub source connected

10:03

Agent contract detected

10:04

Runtime capabilities checked

10:05

Specification valid

Illustrative workflowChoose Define, Deploy, Observe or Govern
A platform, not a provider dashboard

One operational model across teams, environments and runtimes.

The control plane records what should run and why. Provider adapters turn that desired state into infrastructure. The runtime plane executes agents without putting customer logic or unrestricted cloud credentials inside the control plane.

BEANSHOST CONTROL PLANE

Configuration, coordination and policy.

Organisations, projects, environments, specifications, versions, plans, approvals, access controls, usage and audit history.

CUSTOMER RUNTIME PLANE

Execution, routing and isolation.

Provider runtimes, dispatch, triggers, model calls, queues, workflows, storage, health signals and execution telemetry.

Platform capabilities

The services that make an agent operable.

Every capability is exposed through versioned APIs and event contracts so the platform can support its own interface, delivery pipelines and product integrations.

01

Agent registry and specification

Register ownership, purpose, source, versions and artifacts. Define runtime, health, scaling, models, triggers, secrets, storage, resilience and governance in beanshost.yaml.

02

Deployment orchestrator

Create validated, idempotent deployment plans with approvals, provider selection, retries, promotion, rollback, reconciliation and drift detection.

03

Runtime dispatch

Resolve tenant, project, environment and agent, then route requests to the correct healthy version with quotas, timeouts and execution IDs.

04

Workflow and job execution

Support HTTP, schedules, queues, webhooks and durable multi-step jobs with retry policies, dead-letter handling and human approval callbacks.

05

Portable model gateway

Use a consistent model contract for provider routing, fallback, bring-your-own keys, budgets, token metering, redaction hooks and policy enforcement.

06

Observability and metering

Connect execution records, health, structured logs, trace context, latency, errors, tokens, infrastructure usage, cost estimates and quotas.

07

Identity and access

Apply organisation membership, roles, resource permissions, service accounts, personal access tokens, hashed API keys, rotation, revocation and audit logging.

08

ZonalGuard360 governance

Register agents, request production decisions, block unapproved releases, publish evidence, report policy violations and audit every override.

Provider strategy

Cloudflare is first. Portability is architectural.

The initial provider uses Workers for Platforms, dispatch namespaces, Queues, Workflows, R2, Secrets Store and optional Containers. The domain and application layers depend on portable provider contracts, not Cloudflare SDKs.

AWS, Azure, Google Cloud and Kubernetes adapters are planned. A capability matrix makes provider differences explicit and rejects incompatible agent specifications before deployment.

From repository to governed service

Give every agent a defined
and repeatable operating path.

Open Agent Cloud