DurableTaskSupervisor persists task ownership for replay-aware host handlers. It is opt-in: ordinary Agent.run(), AgentWorker, local approvals, and conversation checkpoints keep their existing lifecycle.
Choose a store
Admit work explicitly
Host admission validates identity, immutable input references, manifest hash, driver version, policy revision, grant references, and budget before creating a task. Tenant/task keys identify records; they do not authenticate callers. Each task is a bounded aggregate containing state, revision, lease/fence, attempts, reservations, and action/approval audit. The default aggregate limit is 2 MB. Keep large inputs and media in retained referenced storage. Workers claim with an identity and execute throughsupervisor.run(). Reserve budget before host model work; reservations do not automatically meter arbitrary provider calls. Shared parent/child budgets require host coordination.
Make effects replay-aware
A driver needs deterministic action IDs and a connector that can reconcile an uncertain external effect. Useactions.execute() inside the supervisor’s handler, with destination, canonical arguments, and connector version.
- Reusing an action ID with different arguments fails.
- Confirmed actions return their retained result reference without redispatch.
- A recovered executing action becomes
unknown. - Unknown actions block the handler until fenced reconciliation establishes an outcome.
MongoDBDurableDocumentConnector provides an append-only MongoDB effect with a unique idempotency key and readable receipt. Other connectors must supply their own evidence. A transient HTTP 404 does not prove an effect never happened. This is not exactly-once execution and does not make arbitrary shell commands, emails, or payments safe to replay.
Persist approval and cancellation
Approval-required actions persist a decision request before suspension and release the lease. A trusted endpoint callsDurableActionLedger.decide() with the reviewer, approval ID, and prepared hash. Approval consumption and dispatch intent commit atomically; a consumed approval cannot authorize another dispatch.
Cancellation first persists cancel_requested. The supervisor aborts local work and waits for tracked actions to settle. It acknowledges canceled only when no executing or unknown action remains. Lease loss prevents stale commits but cannot retract a request already sent to another service.
Deliver and expose tasks
- Durable queue delivery sends wake hints through Redis while the task store owns execution state.
- Event and artifact records persist bounded replay and snapshot references.
- Protocol bridges expose admitted tasks through HTTP, A2A, or MCP Tasks.