Skip to content

Factory

The factory is the controller that turns a labelled issue into runs, narrates progress on the issue, meters each run’s tokens and owns the kill switch. It is the only component that creates runs, so every run has a task and a budget. This page describes the design; what runs today is on the status page.

The factory, from issue to merge. A maintainer labels a GitHub issue factory/ready; intake snapshots it, and triage picks the task’s class, team and budget. The Task controller runs the team as sequential agent runs in one room: an implementer, then a reviewer, and a tester in the larger teams. Kueue admits each sandbox. The implementer opens a PR; a maintainer’s “Request changes” review becomes a new run on the same branch. The merge gate, policy-bot and a separate merger App, merges only low-risk classes with green CI; every other PR waits for a human. The run meter revokes a run at its token cap, and the kill switch, a stop ConfigMap or a label on a pinned control issue, pauses intake and stops every task

Source: docs/architecture/ai-platform.drawio, page 5.

From issue to merge

StepWhat happens
IntakeA maintainer adds factory/ready to an issue. The factory takes a snapshot of it, so a later edit does not change a task already under way, and comments with the run id, branch, budget and a watch link. A task already running refuses a second label
TriageOnce per task: which class it is (for example docs-links), which team of roles works it, and how big a budget it gets. A refusal is explained in a comment. What triage predicts only chooses the team and the budget; risk is enforced on the diff at merge time
TeamsRoles run as sequential AgentRuns in one room, on one agent/<task> branch: an implementer, then a reviewer, with a tester in larger teams. Only the implementer writes
ReviseA GitHub review with “Request changes” becomes the input of a new run on the same branch. /factory retry tries again after a failure
Merge gateOnly low-risk classes, and only with green CI and the policy agreeing: docs-links and revert (the factory’s revert of an auto-merged docs-links change). Everything else waits for a human. Until everything is built and merged, the gate runs in shadow mode: it says what it would merge, and merges nothing
Kill switchOne task: the label factory/stop. Every task: the stop ConfigMap, or a label on a pinned control issue

The developer’s view of the same journey is in the user guide.

Components and software

ComponentSoftwareWhat it doesWhy this software
Task controllerA Go controller (controller-runtime)Turns a labelled issue into a task: snapshot, a room, the team’s runs on its branch; narrates on the issue. Starts a reviewer after the implementer, and turns “Request changes” into a new runThe only component that creates runs, so every run has a task and a budget
AdmissionKueueQueues sandboxes so a burst of tasks waits instead of overloading the node pool. Until it lands, the factory’s own caps bound concurrencyThe Kubernetes-native job queue, with quotas
Run meter and kill switchPart of the controllerThe run meter revokes any run, hand-launched ones included, at its token cap. The agent-factory-stop ConfigMap pauses intake and stops every task; so does a label on a pinned control issueControls that act from outside the sandbox
Merge gatepolicy-bot and a merger GitHub AppDecides which agent PRs may merge themselves (only low-risk classes, green CI), then arms GitHub’s auto-merge. A separate App holds that right, and only itThe policy lives in the repository and is reviewable; the right to merge is isolated from everything else
Admission policyKyvernoDenies AgentRun creation to anyone but the factoryOne path in, so no run escapes its budget

Controls

BoundaryMechanism
SpendPer-run deadline; the factory’s run meter revokes a run at its token cap; token budgets at the gateway; at most 20 tasks a day
MergeOnly low-risk classes (docs-links, revert) auto-merge, through policy-bot and a separate merger App; everything else waits for a human
Stopkubectl -n agent-system create configmap agent-factory-stop pauses intake and stops every task; one label on a pinned control issue also refuses new runs and revokes every running one

The sandbox, identity and GitHub boundaries are on Runtime → Security boundaries. The factory design has the full merge policy, gate paths and the five-layer kill switch.