Google's Open Agentic Orchestrator

(agentexecutor.io)

223 points | by blazarquasar 3 hours ago

37 comments

  • sigbottle 1 hour ago
    Could someone explain to me what the general workflow is now that people are converging to? I haven't really been catching up with the AI ecosystem but I was looking into agent sandboxes and VM's recently and there's a ton of these startups and tools now. Is giving the agent a temporary scratchbox really that valuable?

    I've been still just like, making VM's with proxmox, then putting my agent in the machine and letting it run free (with my dotfiles setup script making dev env pretty much free, though I could also just make a VM snapshot). What's wrong with that? Is that not the scalable solution for enterprise rn?

    • dbmikus 14 minutes ago
      I'm working on something in the "cloud VMs for agents" space[1], so I have some battle scars and opinions!

      IMO, you want the flexibility to create either: (a) permanent devbox VMs, and (b) per-task VMs

      Some workflows are a lot simpler if the multiple agents share a VM. These are workflows where agents must share state. A simple one we have: making related changes in our public OSS repo and our private repo, and then testing the change.

      And other times you want to split up the tasks onto isolated VMs so they don't interfere with each other (ie run two dev servers without database or port collisions).

      I tweeted a bit about this (https://x.com/dbmikus/status/2099264325231771878) and had a little debate with folks about ephemeral vs persistent VMs for agents

      [1]: https://github.com/gofixpoint/amika

    • briga 58 minutes ago
      I don't think there is really any convergence going on. The agentic ecosystem is continuing to multiply on a daily basis and everyone and their grandma has written a new agent framework--people are stepping over each other to get these new projects out the door.

      That said, I think Google's ADK ecosystem and this new AX platform is promising--I would expect Google to maintain this and other tooling around this for years to come.

      To the Googlers out there: is Google using this at any capacity for internal projects?

      • QuiDortDine 50 minutes ago
        > I would expect Google to maintain this and other tooling around this for years to come

        The same Google that pulls plugs on a whim?

        • verdverm 33 minutes ago
          at least this one is pre-named for past tense when that day arrives /s
    • agentdev001 1 hour ago
      "Is giving the agent a temporary scratchbox really that valuable?"

      Yes, but, wrong layer here. Giving the agent a computer use (a la bash) is what folks are after. A temporary sandbox with lots of control knobs and security bits is how you do that in (as you noted) an enterprise.

    • nl 26 minutes ago
      This sort of works.

      The problem is that you'll end up wanting to run 2 or 3 (or 20, 100, 10,000) agents at once and that gets very hard with a single VM.

      There's also an argument that you should be using a separate sandbox for each code operation a LLM performs (or at least each set of related operations). That's even harder to do with conventional VMs.

    • maxgashkov 1 hour ago
      Compared to enterprise yours is missing egress control and secrets management, if you make the isolation watertight you cripple the agent's performance, and then the careful game of whack-a-mole begins when you stand up local package mirrors, authentication brokers etc. etc.
  • mcoliver 2 hours ago
    I have been happy with Google's Antigravity harness and Jules so looking forward to playing with this. Thanks for sharing. Simultaneously I am looking to also revisit local offline models.

    While I feel like I have a decent understanding of the model landscape I'm feeling a bit lost at which agentic harness to leverage for local models. Hermes, Cline, Aider, Qwen Code, Goose, Pi, OpenCode, something else? I live in the terminal so Desktop UX is a bonus but not a must have.

    Can I modify the antigravity settings/program to point to a local model? Where should I spend my energy?

    • sleepytree 0 minutes ago
      What are you using Jules for? I want to like it but it fails too often. If I could use Gemini 3.8 I would be happy but 3.6 rarely succeeds.
    • zdragnar 1 hour ago
      I'm stuck on Windows, so oh-my-pi has been really nice. The others I've tried such as kilo do alright but tool calling can mess up a bit.

      Only complaint is that connecting the agent harness to my local model took more work getting configured right than I'd like, but that's been true of most harnesses I've tried as well. Most assume you're using a cloud model and local model configuration is a bit of an afterthought.

    • dosinga 1 hour ago
      goose has now native support for local models
      • threecheese 1 hour ago
        What's going on with Goose? Seems like Block donated it to some consortium; I can't tell if that's a good signal or a bad one. With so many "contenders", if Goose is going into maintenance mode it'd be helpful to know.
      • cyanydeez 1 hour ago
        Its docs have zero support
    • wyre 1 hour ago
      Since local models are largest constrained by context window you want to have a tiny system prompt. I know Hax: https://github.com/OleksandrChekhovskyi/hax was designed with local models in mind, but I haven't used it.
    • NamlchakKhandro 1 hour ago
      pi.

      Always Pi.

  • henryjin76 4 minutes ago
    Interesting approach. How does it compare to LangGraph for multi-step agent workflows? The orchestration layer always seems to be the hardest part to get right in practice.
  • dmix 56 minutes ago
    > Task declares the container image and command, compute requests and limits, environment variables [...] Declares listeners the task exposes and an egress allowlist of hosts and ports the sandbox may reach. Use it to restrict an agent to, say, your LLM provider and your Git host.

    I'm planning to buy a whole linux mini-PC to run my agents/code servers for more isolation. Codex/Claude Code let you run prompts on code over ssh (same with most IDEs) even on the desktop apps.

    I wonder if that's going to be the new standard practice. You get a work laptop and an isolated agent box.

    Running access control and network whitelists is always a maintenance challenge and it's easy to make mistakes.

    • dbmikus 9 minutes ago
      I think it will be, but I don't think you need a standalone machine! If you run things inside a VM, you can get safety and control over access and networks

      A standalone machine is nice if you need more compute resources or if you want an always-on machine you can connect to from your laptop, phone, etc.

      It doesn't look like Google's AX is quite the plug-and-play fit for running agents on a computer you own, since it requires setting up a K8S cluster, etc.

      I think what's needed is something like a zero-setup combo of Tailscale and Firecracker

      I'm trying to work towards that with my startup (https://github.com/gofixpoint/amika) but the bring-your-own-computer part doesn't work quite yet.

  • weedfroglozenge 48 minutes ago
    Nobody has a use for this, and anybody who can look at this website and work out what it's for is kidding themselves. Even the demo gif playing just has them pausing a task and resuming the task.
  • Mond_ 2 hours ago
    The reality with releases like this is that I'm 90% sure most Google bigwigs have never heard of it, and it's misleading to label it as "Google's" in the title.

    Yes, it was developed by Google employees, that does not imply it has the full backing of Google, or Deepmind, or GCP. Notably, the website doesn't seem to claim this either.

    • Stagnant 2 hours ago
      It is on Google's github https://github.com/google/ax and the title comes from there.
      • yla92 1 hour ago
        While this one seems like an official Google project, some other projects are not, even if it is on github.com/google

        A random example E.g https://github.com/google/filament#disclaimer

        This is not an officially supported Google product.

      • Mond_ 1 hour ago
        Fair enough, I missed that specific line. The point still stands that I wouldn't expect this to have GDM leadership backing. (If you're planning to use this at all, that matters for how much faith you should have in the product.)
    • dudus 52 minutes ago
      It's got a formal announcement on the blog. 4 months ago.

      https://cloud.google.com/blog/products/ai-machine-learning/a...

    • mynegation 2 hours ago
      I have no insider knowledge but https://x.com/rakyll is working on it and she is tweeting about it and I got the impression there is a quite a team behind it. It looks like an effort in GCP.
      • Mond_ 1 hour ago
        Yes, and one thing to understand about Google is that no AI framework or tool is guaranteed to survive unless it has the explicit backing of Google Deepmind.

        "Effort in GCP" is a red flag. (See Gemini CLI, which was shut down in favor of Antigravity CLI.)

        • panarky 1 hour ago
          Antigravity CLI is far, far superior to Gemini CLI.

          Plant many flowers, keep the ones that bloom and stop watering the ones that don't.

          • Mond_ 1 hour ago
            I agree on both accounts fwiw.
    • foota 2 hours ago
      This /looks/ at least more official. Most unofficial Google projects have a disclaimer in the repo.
    • varun_ch 2 hours ago
      the repo description https://github.com/google/ax is "Google's open agentic orchestrator"
      • verdverm 1 hour ago
        for comparison/contrast, another very related Google project (one employee) on one of their github orgs that comes with the following disclaimer

        > This is not an officially supported Google product. This project is not eligible for the Google Open Source Software Vulnerability Rewards Program.

        https://github.com/GoogleCloudPlatform/scion

    • esseph 1 hour ago
      >The reality with releases like this is that I'm 90% sure most Google bigwigs have never heard of it

      Google has around 200,000 employees. They probably haven't heard of most things Google releases.

  • DanMcInerney 2 hours ago
    I really don't think any of these SOTA labs are doing agentic engineering correctly. Skills are the universal language of all agent harnesses. If you abstract the taste and prescription out of the skills and into guidance docs, then leave the skills as basically just workflow scaffolding, you can build task-specific workflows that work with any harness like Claude Code, Codex, Antigravity, etc. Technically, you only really need 2 skills, work and review, and with these you can build infinitely complex workflows including self-improving loops. I built this out and have been using it for months. It's been extremely nice. https://github.com/DanMcInerney/orchflows
    • cobolcomesback 2 hours ago
      The OP is not really a workflow manager, it’s a workspace manager that facilitates creating controlled environments where your skills can run. Everything you said is compatible with (and complementary of) the OP project.

      With that said, I’ll somewhat disagree with you. I’ve been down the path you’re talking about and while it is incredibly flexible and powerful, it became too difficult to maintain, and too inconsistent between workflow runs, and a pretty hefty waste of tokens to use AI on things that could instead be handled by deterministic scripts. I ended up creating an orchestrator for myself that uses skills as the primary way to tell agents how to execute a step in a workflow, but also directly orchestrates running scripts and managing state in a deterministic way rather than leaving it all up to agents.

    • nl 22 minutes ago
      You really, really need different skills depending on the model.

      If you are using Qwen 27B you need very prescriptive skills.

      If you are using Astra you usually want very minimal skills (because it will follow them but be unnecessarily constrained in some contexts)

      If you are using Fable then it depends - it will take the skills as general guidelines but ignore them a lot more than Astra does. Sometimes this is good, sometimes not at all.

      • DanMcInerney 12 minutes ago
        Right. That's what modular guidance documentation is for. You could have astra.code or qwen.code.api. All reusable in different workflows. Prescription doesn't belong in the skill itself.
    • handfuloflight 2 hours ago
      How does your criticism relate to the specifics of what OP posted? https://github.com/google/ax/blob/main/docs/concepts.md#work... This says it has skill registries.
      • DanMcInerney 2 hours ago
        Overly complex; yaml files, heavy framework. Same mistake as Claude Code's Dynamic Workflows. Why not just use the dehydrated skills as the workflow skeleton and use custom guidance docs to hydrate the skills with taste and preference depending on the domain of the task? Now you can build a library of small workflows that compose into larger workflow, and you can export any workflow as a single skill to be used in other harnesses. For example, I have a code.md. It's really small, just a bit of taste preference. If I'm using it to hydrate orch-work for coding tasks, then maybe I want to create a code.api.md which hydrates for further specificity if the task is about creating APIs. Then when new models come out, I can just delete code.api.md and leave it as code.md for /orch-work to read from within a workflow because newer models won't need as much prescription.
        • verdverm 2 hours ago
          Part of what's happening is this is running on Kubernetes, which is oft described as "Overly complex; yaml files, heavy framework" but has value regardless, as perceived by being an industry standard. All the things you describe are well and good, but do not address how one runs many of them reliably (from an infra stand point)
  • dilyevsky 50 minutes ago
    Interesting, we had developed a very similar framework for our internal agents: https://github.com/apoxy-dev/clrk For us main use-case was intercepting all network I/O including LLM providers, HTTP, and random TCP/UDP calls
  • nullbio 58 minutes ago
    People can afford to run billions of concurrent agents?
    • dbmikus 7 minutes ago
      Not sure about billions, but companies doing evals or RL or training will create really big bursty agent workloads. I think they are the best fit for AX, as opposed to individual dev teams building software, etc.
  • pianopatrick 3 hours ago
    I can understand why it was chosen, but I'm not a fan of writing a bunch of yaml.
    • beeman 2 hours ago
      I assume they expect agents will be writing most of those
  • SillyUsername 1 hour ago
    I've been using https://github.com/mastra-ai/mastra which is pretty similar but has workflow visibility and a number of templates.

    For a generic swarm, workflows aren't too useful which does away with the visibility, so I may give this a try instead.

  • mifydev 25 minutes ago
    Kubernetes is the last thing I wanted to see recreated for agents. It’s like Multics of cloud, now for agents. Complexity for the sake of it, powered by your favourite YAML slop bowl.
  • TomGarden 3 hours ago
    Question: What is Google's track record for where their open source releases end up over time?

    Genuinely not knowledgeable here

    • blazarquasar 2 hours ago
      It depends on where they decide to go with it, I guess. Kubernetes, Go, Tensorflow, Chromium, gRPC are some examples that obviously went incredibly well.
      • calebkaiser 1 hour ago
        Yeah I'm actually less hesitant to try out Google open source projects than I am new Google products. I have no idea if this is accurate or just my impression, but I feel like I've been burned by the "killed by Google" meme almost exclusively on their software products, whereas there are plenty of open source efforts from Google that I think of as stable.

        In addition to the ones you listed, I'd add the V8 runtime, Jax, Protobuf. Even some of their projects that wound up declining in market share (Angular, Tensorflow--both losing share to projects that wound up at Meta, ironically) are still actively maintained and pushed.

        But I'm sure there's also a huge graveyard of open source projects they abandoned that just never hit my radar. Still, at least with their open source stuff, you can fork in the worst case.

    • AlexErrant 3 hours ago
      Well, they're not above forking their own project to patch security holes and never upstreaming the fixes.

      https://grapheneos.social/@GrapheneOS/117282080803799576

      > Google should not be gatekeeping security patches to the standard Android platform code from Android OEMs but that's what they've started doing.

    • joemazerino 2 hours ago
      Maintain it briefly then slowly let it die.
  • jmathai 3 hours ago
    I'm not sure why, exactly. But I don't pay any attention to news like this from Google. I don't know if there's some marketing which has me writing them off or if it's something else.

    What I do know is that the Gemini integration into sheets is surprisingly incapable of performing basic tasks. This is where I expect Google to really shine. I expected Sheets + Gemini to be magical like Google Photos was. I hardly try anymore besides some basic math questions when I don't feel like inputting the formula myself.

    The other thing I know is Google's propensity to sunset products. For many things, it's not a huge deal. And it may not be for this. But, why? When there are alternatives - both open and closed.

    • lkois 32 minutes ago
      Not sure if this is connected, but I've found Gemini pretty hopeless within its own notebooks. I've been doing some job applications, and added cv and docs into a notebook. I then create a new chat to say "here is a job description, help me write a cover letter" or some such.

      After about 3 messages in any given chat, a follow-up to "rewrite that with a more friendly tone" will result in a letter for a completely different job from another chat within the notebook.

    • Melonai 2 hours ago
      On your Sheets + Gemini integration point, I've genuinely tried to give the Gemini integration into Google Docs & Google Sheets a chance. It is so incompetent that it is fully useless to me. I have not gotten a single correct solution each time I tried to use it, even something I consider table stakes. I often write my work reports in Vim in Markdown format, but they need to go to the corporate Google space. No matter how hard I tried, no matter how many prompts I have, it was completely unable to manage the command to "convert the Markdown format markers into native Google Docs markers". And I want to note, this was 2 pages of extremely simple Markdown with no "advanced" patterns, like tables or quotes, I think all I used was heading-marks, bolding, italicizing, and code blocks. This is something I would expect even GPT 3.5 to succeed in, and even more so Luna, but somehow it destroyed the formatting throughout half the document. This leads me to believe that they apply the absolute cheapest model they have there, or they have the model a harness which can barely be considered working. I found it absurd when I found out that they suddenly made this Gemini integration an additional paid plan recently, there's absolutely no way I can consider that in good faith.
      • 0gs 2 hours ago
        sorry if this isn't it. there is a hidden global setting that defaults to off that lets docs play nice with markdown. it's in file > settings i think. super annoying even if this is no help
    • solidasparagus 3 hours ago
      This is an Apache 2.0 open source project
    • SP3269 1 hour ago
      Making Kubernetes a centre of everything. This one, they won’t sunset, because it helps selling GCP services.
    • Ecstatify 3 hours ago
      [dead]
  • prng2021 1 hour ago
    Can someone clarify the use case for this? What's the benefit over this: https://openai.com/index/introducing-the-agents-api/
    • verdverm 24 minutes ago
      you can run it yourself, it's open source, you can use any harness (req. custom image), you can use any token vendor (config)
  • joeyguerra 6 minutes ago
    Am I being gaslighted into thinking over engineered systems are not?
  • kundi 2 hours ago
    Why kubernetes? Seems like an overload
    • prescriptivist 1 hour ago
      Google already has gVisor running in Kubernetes as a product (GKE Sandbox), which provides the security guarantees necessary for secure sandboxes (regular k8s isn't great in this respect). They also have pod snapshots running at scale (which run on gVisor), so you can spin up process(es) and snapshot the memory and fs of a pod at a point in time, ship it to a blob in GCS, and then rehydrate those snapshots very quickly (or fork into new instances), which allows for the fast/cheap startup and suspend times and the instant scaling they advertise here. One of these snapshots can be created in one cluster and spun up in another.

      Not sure if this is an extension of tech they already have had in their systems, but I've experimenting with it to build my own orchestrator and it's been a pretty neat set of tools and abstractions so far.

    • chrismarlow9 2 hours ago
      Future of platforms is operators in k8s to abstract the developer need to the underlying systems. On local it maps to kvm, on gke it maps to their stuff, on AWS to RDS. It's "interfaces" on a platform level so devs can just ask for a thing.

      Overall I agree though, this is a bit of an abuse of that concept.

      EDIT: I'm sure op is familiar with this workflow but I'm being overly verbose to clarify what I think they mean and my thoughts.

    • somewhatrandom9 22 minutes ago
      Agree. Probably an unpopular opinion, but I strongly dislike YAML.

      EDIT: if I HAD to use YAML, I'd prefer KYAML: https://dev.to/mechcloud_academy/goodbye-yaml-hell-meet-kyam...

  • LeBit 1 hour ago
    How does it compare to kagent (https://kagent.dev/)?
  • skapadia 2 hours ago
    Everyone and their mother are vibe coding their own solutions like this, all the time.
  • srcreigh 2 hours ago
    So the agent-substrate checks a _ton_ of boxes. Almost all of the things it offers should be table stakes for everywhere we run not only agents but most software.

    https://github.com/agent-substrate/substrate

    (For context I built something very similar to this the past 2 weeks for my homelab, trying to solve many of these problems. This comment is an edited version of an unreleased blog post I wrote last week.)

    - Run code in secure microVMs or gVisor. Docker is not good enough. Qemu is not good enough. A secure environment for running untrusted code is the bare minimum. I don't see Firecracker in the repo yet, but that's ok the idea is there.

    - Fast resumption. In my homelab, time-to-first-message is around 11-12 seconds. That's half setting up the pod, and half resuming the CLI (e.g. `codex resume ..`). Why resuming? In my homelab agents are commonly blocked waiting for CI or waiting for me to approve an action, in this case I stop their container to keep resource usage low. Then for resumption, you definitely don't want to waste the agents time by giving a new ephemeral disk and forcing them to re-clone and re-build. For microVMs this is not actually straightforward, for example Firecracker only allows block devices, so re-attaching an agents disk workspace requires a custom storage interface

    - Zero Trust. Codex CLI permissions for example are extremely broken. "Can I run this 500 line long command? or allow any command starting with first 100 chars always?" More reasonable grants are needed.

    I don't understand yet how they will surface Zero Trust notifications. In my homelab it's a Forgejo comment linking to an auth service, and a ntfy.sh iOS notification which opens up the auth service.

    I don't get why they to restore the RAM of the agent env. Maybe to fully optimize resumption. Idk, I don't have that much RAM in my homelab, my agents use a ton, testing stuff in Chromium making screenshots for me. I can't keep RAM for 100 workspaces from the past 24 hours in RAM.

    MITM gateway is very cool.

    I'm curious how they will integrate with microVMs. I just wrote yesterday[1] about how there are NO GOOD OPTIONS for this atm. Kata is decent but the attack surface it introduces makes me uncomfortable.

    [1]: https://srcreigh.ca/posts/auditable-kata/

    But anyway, even if this project is abandoned out of the gate by Google, we should be happy, it sets the bar where it should be. I'm excited to learn how they solved these problems differently than I did.

  • mentalgear 2 hours ago
    I don't see a meaningful difference to the 100s of other 'agentic frameworks' that promise to be the one to all solution for all your troubles.

    Would be about time we get benchmarks for these ... so these can also be gamified just like with the LLMs.

    • quadrature 2 hours ago
      what are your points of comparison ?
  • lopatin 2 hours ago
    This is bound to cause some confusion with the other tool called Ax for agentic development: https://axllm.dev/ (which is DSPy for other languages)
  • jauntywundrkind 3 hours ago
    I'd evaluated both Google's Agent Substrate (that underlies Ax) and their Scion project. I really enjoy how Scion operates with existing tools really well. Ax/Agent Substrate is much more a greenfield independent effort, it's own thing.

    I think Scion has so much more mature a disosition: you could write OpenCode plugins that enhance the runner, and use that locally, and use it in Scion. With Ax/Agent Substrate, you are opting in to a pretty huge stack that is just Agent Substrate, that is their runners, their harness, their substrate. I do think their actor model is pretty neat! It's neat having the agent have such primacy! But it feels so much less integrative, is such it's own thing. Scion, to me, is much more interesting an effort, that similarly helps scale out agentic workloads.

    https://github.com/googlecloudplatform/scion

    • solarkraft 2 hours ago
      > you are opting in to a pretty huge stack that is just Agent Substrate, that is their runners, their harness, their substrate

      The website makes me think the contrary: It is described as “low opinion” and explicitly mentions that the running tasks don’t even have to be AI agents. Can you explain in what ways you’re more locked in than the website suggests?

      Scion at the same time talks much more about concrete agents, giving me the opposite initial impression.

      • pama 2 hours ago
        Not GP, but you start with Kubernetes…

        > You need a Kubernetes cluster, ko (brew install ko), a container registry your cluster can pull from, and a reachable Agent Substrate Control API (in-cluster default: api.ate-system.svc.cluster.local:443).

        > make deploy AX_IMAGE_REPO=<your-registry>

        > This deploys Redis, then builds and deploys the control plane images with ko. Everything lands in the ax-system namespace.

      • jauntywundrkind 31 minutes ago
        Indeed, there's much less, and that's lower opinion. But you also can't run normal workloads. You have to build for Agent Substrate / Ax.

        What's nice about Scion is that it runs existing systems. It runs Claude, it runs Code, it runs Pi, it runs OpenCode. By contrast, "low opinion" means build something new, from scratch, atop this brand new platform.

        Note that both of these are designed to work at some scale. Agent Substrate specifically is somewhat coupled to Kubernetes, is my impression, but honestly that's fine with me. Scion can run on Docker, Podman, Apple Container, Kubernetes, or Cloud Run. It's good that we be able to run these relatively quickly, but (especially with LLM assistance) the idea of running some substantial dependencies / services to run these things does not seem like a bad thing. If anything, I'd prefer having some well known services underfoot to these all being recreated afresh.

  • 0xbadcafebee 1 hour ago
    As usual, Google makes it "googley" by building an incompatible monolith with the kitchen sink included.
  • motoboi 2 hours ago
    this is nice, basically virtual threads for kubernetes.
  • verdverm 2 hours ago
    I'm keeping an eye on another Google Cloud orchestrator

    https://googlecloudplatform.github.io/scion/overview/

    Scion wraps the harnesses (9x) we all use every day and is closer to OpenClaw on Kubernetes

  • guluarte 2 hours ago
    I just have a tmux session acting as the orchestrator, and I tell it to report back and direct the other agents working in separate tmux sessions.
    • lantry 2 hours ago
      Dropbox comment
  • Mizza 3 hours ago
    k8sification of AI was always inevitable, if only as a form of salary justification.
  • aeon_ai 1 hour ago
    A DAG?! Holy innovation, Batman!
  • dougame 20 minutes ago
    [flagged]
  • robertclaus 41 minutes ago
    [dead]
  • kevinbaiv 2 hours ago
    [flagged]
  • ihsw 3 hours ago
    [dead]