Astatide Conductor

Astatide Conductor

Orchestrates persistent task graphs and enforces approval policies for MCP-driven agent workflows, coordinating with Agents Gateway for execution.

Category
访问服务器

README

Astatide Conductor

Persistent objective/task-graph orchestrator for MCP-driven agent workflows.

The Conductor is a durable coordination layer between MCP-capable cockpits and the existing gateway substrate.

What Conductor is

  • A persistent objective orchestrator
  • A task graph manager with durable state
  • An approval and policy enforcement layer
  • A dispatch coordinator to Agents Gateway
  • A high-level MCP cockpit surface

What Conductor is NOT

  • NOT a shell runner
  • NOT a coding agent (Claude, ChatGPT, opencode, Codex)
  • NOT a replacement for Agents Gateway
  • NOT a direct tmux/session manager
  • Does NOT bypass human approval for irreversible actions

Architecture

Any MCP-compatible cockpit (Claude / ChatGPT / Polychat / CLI / future UI)
       |
       v
   CONDUCTOR  ─── single hub (REST + MCP)
       |
   +---+---+---+---+---------+
   |   |   |   |   |         |
   v   v   v   v   v         v
Agents Skills MCP wiki  future gateways
Gateway Gateway Gateway mcp  (mail / calendar / cloud / deploy)

Conductor is the single hub. Gateways are downstream capability providers — the MCP Gateway is one of them, not the parent of Conductor. See docs/gateway-hub.md for the full Gateway Hub reference.

Auth model

Three modes (CONDUCTOR_AUTH__MODE):

Mode Behavior
dev-none No auth (dev/local only). Refuses to boot if CONDUCTOR_ENVIRONMENT=production.
internal-only Requires X-Auth-Internal-Token matching CONDUCTOR_AUTH__INTERNAL_SECRET.
cloudflare-access Cloudflare Access JWT (Cf-Access-Jwt-Assertion) or internal token.

The MCP cockpit surface at /mcp is auth-checked by the same middleware as the REST API. Unauthenticated MCP traffic gets a 401 with a JSON-RPC 2.0 error envelope (code -32001), so cockpits can parse the rejection cleanly:

{"jsonrpc":"2.0","error":{"code":-32001,"message":"..."},"id":null}

REST endpoints keep their normal FastAPI {"detail": "..."} shape — those are not JSON-RPC envelopes.

Skill validation before dispatch

A task that declares required_skills is validated against the Skills Gateway before any state transition in dispatch_task:

  1. created → (validate skills) → ready → dispatched → running
  2. If validation fails: task.skills_validation_failed event is emitted with the missing skills in the payload, the task is left in its original state, no agent_run row is created, no Agents Gateway call is made, and the caller receives a structured error including missing_skills.
  3. If the gateway is not configured (CONDUCTOR_SKILLS_GATEWAY_URL unset or localhost), validation is a no-op and the task dispatches normally.

Capability validation before dispatch

A task may declare required_capabilities in its metadata (a JSON list of dotted capability strings like ["execution.task.create", "external.github"]). Conductor's Gateway Hub validates each capability has at least one configured+enabled provider before any state transition. Missing or degraded capabilities block dispatch and emit a task.capabilities_validation_failed event; passing emits task.capabilities_validated. See docs/gateway-hub.md.

Local dev

uv sync
uv run conductor --help
uv run conductor run --port 8093

Config

cp .env.example .env
# Edit .env as needed

Config precedence: CLI flags > env vars > YAML > defaults.

Testing

uv run pytest -q                       # 390+ tests, all offline (uses mocks)
bash scripts/e2e-local.sh              # 15/15 smoke (offline, pre-existing)
bash scripts/e2e-local-gateway-hub.sh  # 17/17 gateway hub smoke (offline)

Docker

docker compose config
docker compose up -d --build

Live E2E (real gateway)

Two live E2E pathways, both refusing to run without credentials:

Script Scope
scripts/e2e-live-agents.sh Agents Gateway + Skills Gateway
scripts/e2e-live-gateway-hub.sh Agents + Skills + MCP Gateway (+ optional wiki)

See docs/live-e2e.md for the env var list, expected output, and interpretation guide.

Deployment modes

Edge-auth-only personal mode

Cloudflare Access protects hostname. App uses dev-none or internal-only.

Defense-in-depth production mode

Cloudflare Access + app validates Cloudflare Access JWTs.

Known limitations

  • LLM planner is not built; deferred to a later milestone.
  • Autonomous loop mode is not built; deferred.
  • Harness/tmux runtime is not built; only the existing Mock/HTTP Agents Gateway clients are exercised.
  • Live E2E only runs when real gateway credentials are provided. The scripts exit 2 and list the missing env vars otherwise.
  • Skills validation requires Skills Gateway configuration.
  • The MCP Gateway downstream client supports health / version / tools/list / tools/call — a standard MCP surface. Custom gateway deployments with a different surface may need a new client adapter.
  • Capability catalog is static per gateway kind for this milestone. Dynamic discovery is planned for a later milestone.
  • Conductor does NOT run shell commands, NOT bypass Agents Gateway, NOT bypass human approval for irreversible actions.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选