Configuration, coordination and policy.
Organisations, projects, environments, specifications, versions, plans, approvals, access controls, usage and audit history.
BeansHost manages the desired state, deployment lifecycle, secure access, observability and governance of AI agents while customer execution stays in a separate runtime plane.
AGENT / PRODUCTION
GitHub source connected
Agent contract detected
Runtime capabilities checked
Specification valid
The control plane records what should run and why. Provider adapters turn that desired state into infrastructure. The runtime plane executes agents without putting customer logic or unrestricted cloud credentials inside the control plane.
Organisations, projects, environments, specifications, versions, plans, approvals, access controls, usage and audit history.
Provider runtimes, dispatch, triggers, model calls, queues, workflows, storage, health signals and execution telemetry.
Every capability is exposed through versioned APIs and event contracts so the platform can support its own interface, delivery pipelines and product integrations.
Register ownership, purpose, source, versions and artifacts. Define runtime, health, scaling, models, triggers, secrets, storage, resilience and governance in beanshost.yaml.
Create validated, idempotent deployment plans with approvals, provider selection, retries, promotion, rollback, reconciliation and drift detection.
Resolve tenant, project, environment and agent, then route requests to the correct healthy version with quotas, timeouts and execution IDs.
Support HTTP, schedules, queues, webhooks and durable multi-step jobs with retry policies, dead-letter handling and human approval callbacks.
Use a consistent model contract for provider routing, fallback, bring-your-own keys, budgets, token metering, redaction hooks and policy enforcement.
Connect execution records, health, structured logs, trace context, latency, errors, tokens, infrastructure usage, cost estimates and quotas.
Apply organisation membership, roles, resource permissions, service accounts, personal access tokens, hashed API keys, rotation, revocation and audit logging.
Register agents, request production decisions, block unapproved releases, publish evidence, report policy violations and audit every override.
The initial provider uses Workers for Platforms, dispatch namespaces, Queues, Workflows, R2, Secrets Store and optional Containers. The domain and application layers depend on portable provider contracts, not Cloudflare SDKs.
AWS, Azure, Google Cloud and Kubernetes adapters are planned. A capability matrix makes provider differences explicit and rejects incompatible agent specifications before deployment.