Managed Agents Architecturepublic
Last verified 21 Sep 2026
DigitalOcean Harness Runtime provides managed, hardware-isolated microVM sandboxes with built-in tools such as Chromium to run harnesses and execute arbitrary code. Rich lifecycle APIs preserve conversational history and working state across sessions, letting you pause, resume, and fork work to control costs and adapt to the nonlinear nature of agentic workflows. Scale complete agents such as Claude Code or use sandboxes independently for code execution, all through the same service. See What You Can Build for example use cases.
Managed Agents has two services that work together but scale independently. Harness Runtime runs the agent, and Action Gateway governs the tools it calls. Around them sit the DigitalOcean services an agent reaches for while it works: model inference, storage, and data.
What You Bring
You supply the agent and the credentials. DigitalOcean supplies everything under it.
- An agent. A coding agent or framework you already use, such as Codex CLI, Claude Code, OpenCode, Hermes, or LangGraph, or your own container image. Which one you pick is the adapter.
- A trigger. A CLI command, a webhook, a cron schedule, or a message in the Control Panel.
- Tools and credentials. The provider accounts and API keys the agent needs for services like GitHub, Jira, or your own APIs.
You declare all of it in an environment, written as a YAML environment spec or built in the Control Panel.
Harness Runtime
Harness Runtime provisions one sandbox per session. The sandbox is a lightweight microVM, and isolation is enforced by the hypervisor rather than by container namespaces, so nothing an agent does in one session reaches another session or another customer.
Two things live inside that boundary:
- Your agent, unmodified. The agent or framework runs as it ships. Harness Runtime translates its native output into one event vocabulary rather than changing the agent itself.
- Your workspace. The working directory the agent reads and writes. Repositories, uploaded files, and build artifacts live there.
Sessions pause, resume, checkpoint, fork, and roll back. Pausing preserves the full machine state and stops compute charges, so a session costs you only while it is actively working.
Action Gateway
Action Gateway is a managed MCP endpoint that gives agents access to tools without putting credentials in the model context. Credentials are brokered at execution time: the agent requests a tool call, Action Gateway resolves the credential from Secrets Manager, runs the call, and returns the result. The agent never holds the key.
Behind that single endpoint sit more than 16,000 tools, covering providers such as GitHub, Jira, Stripe, PagerDuty, Sentry, Notion, and Shopify, along with web search, web fetch, browser automation, and any MCP server you host yourself. Per-tool permission policies decide what the agent may call, must ask about, or may never touch.
Action Gateway also works on its own, without Harness Runtime, as an MCP endpoint for any client. See the Action Gateway documentation.
Signals
Signals collects agent and model tracing from both services into one structured event stream. It is not yet available.
Connected Services
Three groups of DigitalOcean services sit alongside a session:
- Inference Engine. Model calls route to more than 75 open and proprietary models, or to your own provider when you configure the environment with its endpoint and key.
- Storage. Artifacts and session state that need to outlive a single run.
- Data services. The records your agents read and update, including Managed Databases, Kafka, and Valkey.
Traffic Separation
Managed Agents separates inbound and outbound traffic because the two differ by orders of magnitude. Inbound is a developer typing a prompt every few minutes. Outbound is every token the model produces, every tool result, and every file change, for every active session at once.
The control path carries session creation, developer input, and billing. The data path carries event streaming and never touches the privileged management network.