1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
# The summariser, hosted as an A2A 1.0 peer:
#
# agentplane serve examples/served.yaml \
# --url http://localhost:8080 \
# --policy examples/serve-policy.cedar \
# --tokens examples/serve-tokens.yaml \
# --store /tmp/served.redb
#
# One line differs from `summariser.yaml`, and it is the interesting one.
apiVersion: agentplane.hupe1980.github.io/v1alpha1
kind: Agent
metadata:
spec:
execution:
identity:
role: "Summarise a support ticket"
constraints: "One sentence. No speculation."
capabilities:
models:
privileged:
output:
schema:
type: object
required:
properties:
budgets:
security:
# Required to be *served*, and not to be run locally. A message from an A2A
# peer arrives labelled `Internal` — it came from outside — while `--input`
# on the command line is the operator's own and arrives `Public`. The
# default egress ceiling is `Public`, so without this line the peer's text
# cannot reach the model and every served run fails with
# `sensitivity Internal exceeds sink 'model.complete' ceiling Public`.
#
# That refusal is the design working: an agent that may talk to strangers
# says so in the reviewed file, rather than acquiring the permission by
# being put behind a socket.
max_sensitivity_egress: internal