Anvil Agents docs
Operator documentation for the standalone Kubernetes agent operator: install paths, composition, harnesses, streams, security, and day-two operations. Diagrams are first-class.

Getting started
Credential-free Kind path, prerequisites, and the first successful AgentRun.

Architecture
How the controller resolves runs, materializes payloads, and owns Jobs.

Composition
Profiles, harnesses, skill sets, and tool sets as independent lifecycles.

Agent runtime
Append-only AgentRun semantics and resource ownership.
Start here
Core concepts

Architecture
How the controller resolves runs, materializes payloads, and owns Jobs.

Composition
Profiles, harnesses, skill sets, and tool sets as independent lifecycles.

Agent runtime
Append-only AgentRun semantics and resource ownership.

Harnesses
Codex, OpenCode, Hermes, OpenClaw, Grok Build, Pi, and custom runners.
Operate
CLI
anvil-agentctl for runs, auth sessions, and diagnosis.
Operations
Day-2 install, upgrades, and operational boundaries.
Observability
Labels, logs, and collector-neutral telemetry hooks.
Live run stream
OIDC API, SSE streams, and the Anvil Agents Console.
Archive
Terminal retention and PostgreSQL archive behavior.
Security
RBAC, secrets, GitOps locks, and API trust boundaries.
Security and release
Release gates and security program for published artifacts.
Volume copy
AgentDataVolume copy workflows for durable agent homes.
Integrate
Distributed workloads
Spreading heavy agent Jobs across cluster capacity.
Adverse sources
AdverseSituation and AdverseSignal integrations.
Knowledge and tools
Skills, tools, and external service contracts.
Migration from Anvil Primaris
Moving off the in-tree agent runtime to standalone anvil-agents.
Release on Primaris
Hazy Forge consumer release notes for anvil-primaris overlays.