Skip to content

Product1 publisher3 min readPublished

Stacklok's Mecatl trades the coding agent's unrestricted shell for a governed tool catalog

Stacklok open-sourced Mecatl, a coding-agent harness split into separate services for organizations that want to run hundreds of sessions on Kubernetes. The company argues that a harness built as one laptop process has to become a distributed system once agents run unattended.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Stacklok's Mecatl trades the coding agent's unrestricted shell for a governed tool catalog
Generated illustration

What happened

  • Stacklok says most coding-agent harnesses run as one process that is at once the UI, agent loop, sandbox, credential store, tool host and session database.
  • In Mecatl, the core engine owns the agent loop, meaning reasoning, tool dispatch, permissions, hooks and event emission, and every other part sits behind explicit interfaces.
  • Mecatl's clients are currently a terminal UI called mecatui, gRPC and HTTP/SSE APIs, and a TypeScript SDK, none of which own the loop.
  • On Kubernetes, Mecatl workers can be replaced during normal operations, and a new engine version can roll out while durable sessions stay put.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Teams already running a laptop harness in a container now have to choose, for every session that must survive a node failure, between losing it and rebuilding around external session state.
  • cost Someone on the platform side has to define, permission and audit every tool a hosted agent may call, and the unrestricted shell never needed that work.
  • constraint Before an agent action that reaches outside the workspace, such as a deploy, runs unattended, it needs its own safeguard, because Mecatl's recovery only goes back to the last saved turn.

A coding agent is partway through a long refactor with no one watching when Kubernetes evicts its pod. In Mecatl, a replacement process picks the session up from the last persisted turn boundary. Session state and event history sit in durable storage under a single-writer model [10]. The replacement does not resume the operation that was in flight, and work after the last successful save can be lost [11]. Stacklok calls this turn-level durability and says it is not a distributed transaction [11]. "It is enough that a pod eviction stops being a conversation-ending event," the company wrote [16].

A laptop harness packed into a container handles that eviction worse. In Stacklok's account, every concern in it is still coupled to one long-lived machine [4]. "Kubernetes taught this industry that a monolith in a container is still a monolith," the post on the CNCF blog says [5][15].

The bigger cost is in the tool layer, and Stacklok spells it out. A desktop harness is useful in large part because it has an unrestricted shell, the company says, and a cloud-native harness does not need one [12]. Mecatl instead exposes purpose-built tools, skills and application integrations through an explicit catalog. Each one sits inside permission, audit and execution-environment boundaries [12]. A hosted agent starts from a catalog of things it is allowed to do [12].

Stacklok is specific about who this is for. It says the desktop design serves a single developer well [14]. The organizations it has in mind want to govern which tools each session may call, survive a node dying mid-task, or start a session on a laptop and pick it up on a phone [3]. It also expects these agent capabilities to reach people who will never open a terminal, and long-running workloads no one sits in front of [13]. The post does not include deployment counts, session volumes or failure rates from a running install. The case rests on design reasoning from the company that wrote the code [1].

Two questions sort the decision for any given workload. The first is whether a person watches the session while it runs. The second is whether every tool it needs can be written down as a list. I'd keep a watched session that needs an open shell on the laptop harness, which is the case Stacklok concedes the desktop design handles well [14]. An unwatched session whose tools fit on a list is the case Mecatl was built for [12][13]. When someone is watching and the tools fit on a list, a container can do the job until session counts or the laptop-to-phone handoff force the split [3]. The hard case is the unwatched session that still wants an unrestricted shell. Cut its tool list down before moving it. A replacement worker restores only the last saved turn, and nobody is at the keyboard to see what happened after it [11].

What to watch

  • Whether Stacklok documents how Mecatl treats a tool call with outside effects that ran after the last persisted turn.
  • Session counts or failure data from an organization running Mecatl in production at the hundreds-of-sessions scale Stacklok describes.
  • Whether other coding-agent harness makers move session state out of the agent process or keep shipping single-process desktop tools.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories