Skip to content

[EPIC] Forge VNext — budget-aware general agent runtime and installable Workforces #333

Description

@Joncallim

Execution mode: tracking
Canonical architecture: ADR 0014 + docs/forge-vnext-architecture.md

Issue Type

Epic - VNext programme tracking. Do not dispatch this Epic directly to an implementation agent.

Context

Forge is evolving from a coding-focused control plane into a local-first, budget-aware, deterministic-first runtime for installing, governing and operating AI Workforces.

Software Engineering remains the first compatibility/proof Workforce. Forge Core becomes generic Mission/Execution/Resource/Capability/Grant/Operation/Artifact/Gate/Trigger/Budget infrastructure rather than a permanent coding product.

Forge eventually replaces Hermes/HearthBot orchestration. Hermes is requirements/history only: no source/config/state/runtime compatibility or Forge->Hermes fallback is allowed.

Canonical programme invariants:

  1. No always-on LLM parent/orchestrator.
  2. Idle/unchanged operation costs zero model tokens.
  3. Optimize expected cost to a verified outcome subject to a quality floor.
  4. Agents/package prose do not possess authority; Forge lends scoped revocable Grants.
  5. Resource and Capability are distinct.
  6. Workers/verifiers produce evidence; deterministic Gates decide.
  7. Workforce packages are declarative data, not trusted executable plugins.
  8. External side effects use idempotency/reconciliation; ambiguous submission is never blindly retried.
  9. Version/pin anything that can change run behavior/evidence meaning.
  10. Preserve [EPIC] MCP admission, bounded context, and release-readiness trust boundary #172/[FEATURE] Add deterministic operation catalog and typed execution harness #201/[FEATURE] Normalize execution outcomes and stop reasons #185/[FEATURE] Add capability reliability ledger #186 trust foundations unless an explicit migration proves equivalence.
  11. No big-bang rewrite or duplicate orchestration truth.
  12. No model ensembles/voting/latent bridges in this programme.
  13. PostgreSQL is durable orchestration/evidence truth; Redis is reconstructable transport/cache.
  14. Agent dispatch must remain dependency/tracking aware through the [BUG][P0] Make agent readiness dependency-aware and prevent tracking issues from direct dispatch #354 control plane.
  15. Backup restore/database rollback is a distinct recovery class: restored local truth remains quarantined until current external state/authority is reconciled ([FEATURE][RELIABILITY] Add restore quarantine and external-state reconciliation for backup recovery #366).
  16. A Work Package remains the dependency-scoped handoff unit. Routine readiness, sequencing, fan-out/join and handoff are deterministic; downstream Agent Runs receive freshly compiled bounded context rather than supervisor-written transcript summaries ([FEATURE] VNext Phase 1 — deterministic budget, routing, and context economics #335/[FEATURE][ARCH] VNext Phase 1B — deterministic Workflow kernel and artifact-routed dispatch #367).

Desired Outcome

Install a Workforce. Bind the Resources it may use. Grant bounded Capabilities. Give it a Mission. Forge handles deterministic orchestration, budgeting, delegation, execution, verification, evidence, recovery and escalation.

All implementation issues are planned in advance with explicit dependencies and orthogonal checkpoints. Only the current dependency frontier is dispatchable. Tracking Epics remain status/architecture maps, never implementation work orders.

At programme completion, Forge proves Software Engineering, non-repository Deep Research, persistent Trigger-driven operation, safe backup/restore recovery, a bounded Infrastructure Ops side effect and complete HearthBot/Hermes cutover through the same governed runtime.

Tasks

Bootstrap / current-beta hardening

Readiness is now derived by the #354 dependency/tracking control plane. Treat managed readiness labels as projections/cache, not authority; always re-check current Depends on:/tracking state at dispatch time.

Generic runtime phases

Tracking-only Epics

Branch / stale-plan hygiene

Acceptance Criteria

  • Every remaining implementation issue contains Execution mode: implementation, explicit Depends on: metadata, objective acceptance criteria, primary code seams, a PR-sized implementation sequence, out-of-scope boundaries and deep orthogonal checkpoints.
  • Tracking Epics [EPIC] MCP admission, bounded context, and release-readiness trust boundary #172/[EPIC] MCP S6 release proof and external-controller finalization #181/[EPIC] Evidence, verification, and earned-autonomy programme #184/[EPIC] Verification goals and proof-run lifecycle #187/[EPIC] Forge VNext — budget-aware general agent runtime and installable Workforces #333 are never direct implementation dispatch targets.
  • ready-for-agent remains a truthful projection of the dependency frontier rather than template validity.
  • Idle persistent operation makes zero LLM calls when unchanged.
  • Hard Mission budgets block before over-budget provider invocation; every production model call has routing/budget/context/egress evidence.
  • Routine Workflow readiness, sequencing, fan-out/join and handoff consume zero model calls; Work Packages and Artifacts remain the durable handoff/state primitives.
  • Restart/replay does not duplicate confirmed side effects; ambiguous writes reconcile rather than blind retry.
  • Backup restore enters durable quarantine, fences stale runtime state and reconciles current external effects/Triggers/credentials/autonomy/budgets before consequential autonomy resumes.
  • Workers cannot self-verify into authority and child work cannot widen parent Grant/Resource/budget scope.
  • Hostile Resource/package/prompt content cannot widen authority or provider/network egress.
  • Operator cancellation/revocation prevents new side effects/model calls.
  • Running Missions remain pinned across Workforce/package updates.
  • Software Engineering passes two clean generic-runtime release runs including bounded rework/restart.
  • Deep Research completes a non-repository evidence workflow through the same Core.
  • Persistent Missions remain quiescent with zero-token idle and survive restart.
  • Trigger duplicate/replay/self-loop/signature/catch-up cases are bounded and reconstructable.
  • Infrastructure Ops proves ongoing deterministic monitoring plus one explicitly approved bounded recoverable side effect under earned autonomy after the restore/DR gate is proven.
  • Operator reporting exposes evidence/freshness/critical findings without opaque trust scores.
  • HearthBot is only a thin Forge interface and Hermes can be fully stopped/removed without losing retained responsibilities.
  • New implementation branches start from current main only after declared dependencies close; stale pre-VNext branches are not used as implementation bases.

Planning Standard

Before dispatch, every implementation issue must include source-of-truth/authority boundaries, implementation sequence, primary code seams, objective pass conditions, failure/restart/concurrency/privacy/security tests and logical orthogonal checkpoints using .ai/skills/orthogonal-review.md.

Implementation agents should not redesign programme architecture unless a concrete contradiction is proven. If a required contract is missing, fail/block the issue and open a narrow architecture finding rather than inventing a second system.

Later explicit hostile-review addenda/corrections on an implementation issue refine earlier planning. When planning comments conflict, the later explicit correction wins unless current code or an accepted spec has since changed.

Explicit Non-Goals

  • Model ensembles/latent-state bridging.
  • Permanent LLM parent agent.
  • Arbitrary model-authored shell authority.
  • Self-modifying Workforce/runtime code.
  • Automatic generation/trust of executable Workforces.
  • Public Workforce marketplace before provenance/update safety is proven.
  • Distributed Forge clusters / active-active Forge replicas.
  • General auto-merge/deployment authority.
  • Enterprise multi-user RBAC in the initial programme.
  • Importing Hermes code/config/state.
  • A2A/direct agent-to-agent orchestration as a second runtime truth.
  • LangGraph or another agent framework as Forge Core's authoritative workflow/checkpoint store.

Review / Delivery Rule

Every PR follows the repository full independent orthogonal-review protocol. Findings are classified change-blocking vs adjacent; adjacent pre-existing improvements become separate issues rather than causing infinite rework. A phase closes only with objective test/evidence artifacts and explicit residual uncertainty, not a model saying “done.”

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesttracking-onlyREADINESS PROJECTION — Issue is a tracking/umbrella issue and is not implementation-dispatchable.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions