Skip to content

Foundation architecture ​

The v1 source builds independent .NET components. Contracts separate provider-neutral types from Azure and PostgreSQL adapters.

The Identity Broker is the host for caller authentication and secret-redemption authorization. It constructs the Key Vault backend and the authorization wrapper; it is a service host in source, not a claim that a service is deployed.

The Foundation Probe resolves provider descriptors and pins binding evidence for acceptance checks. The IDs azure-blob, azure-key-vault, and azure-monitor identify catalog entries; they do not instantiate adapters. AzureProbeOperations separately constructs the Key Vault and Blob classes, while Program registers telemetry composition. The probe is not an agent runtime.

Canonical component overview ​

Structural view of two adapter chains. IObjectStore is implemented by AzureBlobObjectStore, which accesses an Azure Blob container. ISecretRedemption is implemented by AzureKeyVaultSecretRedemption, which accesses Azure Key Vault.
Contract, adapter-library, and external-resource relationships in the v1 source. Host composition and Foundation Probe registration IDs are listed below.

The figure is a structural component view, not runtime request order or deployment topology. AzureBlobObjectStore implements IObjectStore in the Agentweaver.ObjectStore.AzureBlob library. AzureKeyVaultSecretRedemption implements ISecretRedemption in the Agentweaver.Secrets.AzureKeyVault library. The table names the concrete types and their external boundaries.

InterfaceConcrete classLibraryExternal boundary and edge semantics
ISecretRedemption (Agentweaver.Abstractions)AuthorizedSecretRedemptionAgentweaver.IdentityImplements the contract; checks the exact grant and delegates backend redemption through ISecretRedemption.
ISecretRedemption (Agentweaver.Abstractions)AzureKeyVaultSecretRedemptionAgentweaver.Secrets.AzureKeyVaultImplements the backend contract; reads the exact version from Azure Key Vault.
IObjectStore (Agentweaver.Abstractions)AzureBlobObjectStoreAgentweaver.ObjectStore.AzureBlobImplements the contract; reads or writes opaque objects in Azure Blob Storage.

Host composition and Foundation Probe registration IDs ​

Host or IDComposition or registrationMeaning
Identity BrokerConstructs AzureKeyVaultSecretRedemption as an ISecretRedemption backend and constructs AuthorizedSecretRedemption with the grant authority and backend.The wrapper checks actor, project, run, purpose, and exact-version grants before backend redemption. The adapter does not authorize callers.
Foundation ProbeProbeProviderBindings.ResolveAndPin records provider IDs in pin evidence. Separately, AzureProbeOperations constructs AzureBlobObjectStore and AzureKeyVaultSecretRedemption; Program registers telemetry composition.ID-based pinning does not construct adapters; the probe is an acceptance executable, not an application service host.
azure-blobObjectStore provider ID recorded in Foundation Probe binding evidence.Registration ID, not the AzureBlobObjectStore class, library, or constructor.
azure-key-vaultSecretRedemption provider ID recorded in Foundation Probe binding evidence.Registration ID, not the AzureKeyVaultSecretRedemption class, library, or constructor.
azure-monitorTelemetry provider ID recorded in Foundation Probe binding evidence.Registration ID, not an exporter class, library, or model vendor.

Component boundaries and project references ​

ComponentCurrent boundaryDirect project references
Agentweaver.AbstractionsProvider, secret, and object-store contracts.—
Agentweaver.ProvidersIn-memory provider catalog and resolver.Agentweaver.Abstractions
Agentweaver.IdentityTrusted actor and exact run-grant authorization for secret redemption.Agentweaver.Abstractions
Agentweaver.Secrets.AzureKeyVaultExact-version Azure Key Vault adapter.Agentweaver.Abstractions
Agentweaver.Persistence.PostgresService-schema outbox, consumer inbox, and relay library.—
Agentweaver.ObjectStore.AzureBlobOpaque-object Azure Blob adapter.Agentweaver.Abstractions
Agentweaver.TelemetryIn-process OpenTelemetry traces, metrics, and logs.—
Agentweaver.Telemetry.AzureMonitorOpt-in Azure Monitor exporters.Agentweaver.Telemetry
Agentweaver.Identity.BrokerOAuth and secret-redemption host; caller-authentication boundary.Agentweaver.Identity, Agentweaver.Secrets.AzureKeyVault
Agentweaver.FoundationProbeAcceptance-only infrastructure probe executable.Agentweaver.Abstractions, Agentweaver.Providers, Agentweaver.Persistence.Postgres, Agentweaver.Secrets.AzureKeyVault, Agentweaver.ObjectStore.AzureBlob, Agentweaver.Telemetry.AzureMonitor

The repository does not contain the AgentHost, product API, web UI, product MCP server, or application router. It does not contain a published platform image.

The proposed platform architecture remains a Proposed source document.