Agent-Kernel Integration
Role in Mnemose
agent-kernel is the remote host execution substrate that lets Mnemose operate against customer machines without embedding host access directly inside the always-on control-plane services.
Mnemose interacts with the kernel through two bounded-context surfaces:
@mnemose/mcp-mnemose-kernelsexposeskernel.listandkernel.invokeas MCP tools to platform personas.services/kernel-brokermaintains enrolled remote kernels, validates approved sessions, and forwards JSON-RPC invocations over mTLS WebSocket.
Control Flow
platform-ops persona -> mcp-mnemose-kernels -> Mnemose command spine -> kernel-broker -> remote agent-kernel -> host capability toolRead-only kernel tools can run without an approved elevated session. Mutating tools such as fs_write, cmd_exec, and shell_* require a KernelSession approval with a tier and TTL that the broker enforces before dispatch.
Transport Modes
| Mode | Used By | Notes |
|---|---|---|
| stdio MCP | Local development and direct runtime spawning | Suitable when the agent process owns the kernel lifecycle |
| WebSocket MCP | Remote Mnemose-managed kernels | Requires enrollment token exchange and mTLS certificate issuance |
Session and Audit Model
enrollKernelprovisions a new kernel identity and bootstrap token.requestKernelSessionrequests temporary access for mutating tool use.approveKernelSessionordenyKernelSessionrecords the control-plane decision.revokeKernelretires an enrolled host.- Every dispatched invocation is written to the Mnemose event log as a durable audit event.
Documentation Sources
| Location | Purpose |
|---|---|
apps/agent-kernel/README.md | Installation, tool catalog, CLI, troubleshooting |
apps/agent-kernel/docs/index.md | Project orientation and generated-doc entry point |
apps/agent-kernel/docs/architecture.md | Rust workspace and transport architecture |
services/kernel-broker/src/server.ts | Broker-side request handling and session enforcement |
packages/kernel-protocol/src/index.ts | Shared Mnemose TypeScript schemas for broker and control-plane flows |
Constraints
- Mnemose and agent-kernel communicate over protocol boundaries, not shared runtime code.
- Broker-issued policy is authoritative for remote dispatch; the kernel enforces its own immutable startup permission tier in addition to broker checks.
- API documentation for Mnemose-side schemas belongs in the TypeDoc output for
@mnemose/kernel-protocol.