Skip to main content

Authoritative server components

The canonical interactive C4 L3 view opens the Authoritative server and API container into stable responsibilities. It deliberately does not mirror every project, namespace, endpoint, worker, or class.

L3 componentResponsibilityPrincipal implementation areas
API transportFamily-owned REST, MCP, SignalR, OpenAPI, request-context, and HTTP security adaptersAgentstration.Api, Agentstration.*.Api
Identity and authorizationAuthentication, Principals, Workspace access, RBAC, PATs, delegation, and security auditAgentstration.Identity, Agentstration.Identity.Contracts, Agentstration.Security.Contracts
Resource-family servicesFamily-owned resource validation, lifecycle, desired state, and provider-neutral portsAgentstration.Agents, Agentstration.Models.Application, Agentstration.Triggers, Agentstration.Extensions.Aep, Agentstration.Sources, Agentstration.Secrets
Distribution and bootstrapAPI-driven Bootstrap profiles, Pack and Source distribution, generic manifest planning delegated to owning families, and bounded startup initializationAgentstration.Bootstrap.Contracts, Agentstration.ResourceManagement.Contracts, Agentstration.Packs, Agentstration.Sources
Work and Workplace applicationFunctional Work lifecycle, interactions, notifications, projections, and root execution submissionAgentstration.Application, Agentstration.Work, Agentstration.Work.Contracts
Flow engineFlow definitions, immutable publications, durable Flow Runs, and provider-neutral graph executionAgentstration.Flows.*
Runtime executionDurable technical Runs, agent materialization, model resolution, attempts, and normalized eventsAgentstration.Runtime.*, Agentstration.Infrastructure runtime adapters
Tool execution pipelineGoverned Tool catalog, hooks, approvals, MCP publication, and invocationAgentstration.Tools, Agentstration.Tools.Mcp
Scheduling and background processingAPI-driven Trigger administration and run-now commands, plus internal Trigger projection, reconciliation, source refresh, recovery, and bounded hosted workAgentstration.Triggers, Agentstration.Triggers.Api, Agentstration.Infrastructure workers, Agentstration.Web hosting composition

The mapping is supporting evidence, not the identity of a C4 component. A responsibility may span several projects, and a composition project may connect several responsibilities without owning their business behavior.

The principal dependency chain is Work → Flow → Runtime for execution. Flow and Runtime both use the governed Tool execution pipeline; Runtime resolves immutable Agent and profile resources before constructing an executable agent. API transport is the exclusive application entry point for the Console—embedded or independently hosted—and the independently hosted Workplace: their components consume typed HTTP and SignalR clients rather than application or storage implementations. It delegates requests to every public application responsibility, including Distribution and Bootstrap and Trigger scheduling. Background processing is the deliberate second entry mode: hosted workers open explicit scopes and reuse the same services without routing their internal ticks, reconciliation, or recovery work through HTTP.

The focused API transport composition view opens the transport component into the authoritative host, lightweight aggregator, and family-owned API modules. The dynamic architecture views show the principal implemented interactions across the server responsibilities without duplicating their structural ownership.

Relevant decisions include ADR-0005, ADR-0008, ADR-0009, ADR-0010, ADR-0055, ADR-0109, and ADR-0110.