fleet_frameworks

June 15, 2026 · View on GitHub

The executable form of the fleet-framework cookbook: each file is that cookbook's recipe lifted out of markdown so the DOS-bearing seam is executed and pinned by the suite (tests/test_fleet_framework_examples.py) instead of living only as pasted output. The recipes find each framework's believe-the-agent point — where a worker's "done" is folded into control flow as a fact — and route it through a kernel verdict instead. Read the cookbook for the full argument; run these for the proof.

New to the problem? Running parallel AI agents safely is the framework-agnostic version — the four places concurrent agents contend and the one runnable command for each — before you pick a framework recipe.

FileRecipeNeeds
universal.py0 — the two-function adapter (verify at the "done" seam, arbitrate at the dispatch seam)dos only
langgraph_referee.py1 — a referee node + a verdict-routed edgelanggraph
crewai_verify_tool.py2 — a verify tool + a post-kickoff gatecrewai
autogen_termination.py3 — a termination condition only git can satisfyautogen-agentchat
openai_agents_guardrail.py4 — an output guardrail with a git tripwireopenai-agents
crewai_task_guardrail.py6 — the SHIPPED task guardrail: the retry loop fails on an absent deliverable (dos.drivers.crewai_guardrail, docs/305)dos only
openai_agents_effect_gate.py7 — the SHIPPED output guardrail: the tripwire fires on an absent deliverable (dos.drivers.openai_agents_guardrail, docs/305)openai-agents
in_session_deconflict.py8 — the in-session deconfliction handshake: "another agent is also working here; deconflict with DOS" as one arbitrate call, BEFORE the fan-out — routes a collision instead of stalling on itdos only

Recipe 5 (Claude Code / Claude Agent SDK) has no file here because it needs no adapter for the host wiring — use the shipped surfaces (dos init --hooks claude-code, dos-mcp, the plugin), which enforce the gate at write time. Recipe 8 is the deliberate, in-session twin of that: when you are the agent and want to deconflict BEFORE you fan out (sub-agents, parallel /loop workers, a parallel()/pipeline() stage), the handshake is one arbitrate(my-tree, the-leases-held) call — the same closed verdict whether the "other agent" is your own sibling sub-agent or a foreign runtime. That is the universal-standard framing: deconfliction is a shared protocol over file-tree disjointness, not a per-host feature. Recipes 6 and 7 are the DRIVER form of 2 and 4: where the early recipes wire the oracle in by hand and key on a (plan, phase) the host names, the drivers ship in the package (pip install dos-kernel) and check DECLARED deliverables — a commit, a file, a shipped phase — against read-backs the agent did not author. The swarm-runtime worked example is ../hermes_integration/.

# from the repo root, with dos installed (pip install -e .):
python examples/fleet_frameworks/universal.py

# each framework recipe runs the moment its framework is installed, e.g.:
pip install langgraph
python examples/fleet_frameworks/langgraph_referee.py

Every demo builds its own throwaway git repo (_fixture.make_demo_repo) with one real AUTH1: ship the login endpoint commit, so AUTH1 is verifiably shipped and AUTH2 verifiably is not — no recipe touches the repo you run it from. The workers are scripted liars, no LLM behind them, because the control flow is what's being demonstrated: swap in your real agents; the referee doesn't care who's lying to it.

The matching tests skip cleanly when a framework isn't installed — CI without the frameworks still pins Recipe 0 (the kernel seam itself); a checkout with any of them installed pins that framework's seam too.