Docs · Source · pip install awrun · The Aither World
The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awrun is one of its 65 bricks — each installs on its own, runs offline, and needs no account.
Start here: Queue two runs at different priorities and watch the urgent one overtake.
GitHub Actions' self-hosted runner queue is FIFO-per-label, opaque, and un-reprioritizable — there is no API to say "run this one next." That is a hard platform limit, not a bug. What that limit produces in practice is a "belt-fed machine gun": everything fires in arrival order, and a low-value build queued a minute earlier blocks a high-value one indefinitely, with no lever to move it up.
awrun does not try to reprioritize GitHub's own queue for other people's
pushes — it can't, and claiming otherwise would be a lie. What it delivers,
completely and correctly, is dynamic priority over the class of run that
actually matters most: work submitted through it — agentic/ADK runs
end-to-end (no GitHub Actions involvement at all), and ad-hoc
workflow_dispatch CI builds, so the order in which we fire them is
finally something a human or an agent can steer while it's in flight.
pip install awrunPython 3.10+. No hard dependencies for the core queue.
A durable, cross-process priority queue (store.py) plus a CLI (cli.py)
and a dispatch loop (dispatcher.py). Modeled directly on
awdk/adk/decisions/store.py — one JSON file per item, atomic
os.replace() writes — with one deliberate improvement: claiming an item is
an os.rename() between status directories (queued/ → claimed/ → ...),
which is a genuine cross-process mutex with no lock file needed, rather than
a Python threading.RLock() that only protects one process.
awrun submit --kind agent --task "verify the fix" --priority 5
awrun submit --kind ci --workflow product-images.yml --ref develop \
--field images=gargbot --field push=true --priority 8
awrun queue # highest priority first, oldest breaks ties
awrun bump r-7f3a9c2e --priority 10 # the literal missing feature
awrun cancel r-7f3a9c2e
awrun status r-7f3a9c2eAITHER_AWRUN_DIR overrides the store location (default
~/.aither/awrun/) — set it in tests and for per-tenant isolation.
Not a new daemon. decisions/store.py already proves a durable, pollable,
cross-process queue doesn't need one — awrun dispatch (via
awrun.dispatcher) runs as a scheduled task or a one-shot --once
invocation, matching AitherOS/config/routines/*.yaml's existing pattern.
Not a replacement for required PR-gate CI, which stays on GitHub Actions'
native triggers. awrun targets ad-hoc dispatches only.
All three kinds below are implemented, routed and self-tested. Dispatch is priority-first ACROSS kinds, not per-kind — the whole point is one queue an urgent item can jump.
| kind | what it runs |
|---|---|
agent |
adk chat <agent> "<task>" |
ci |
gh workflow run <workflow> --ref <ref> -f k=v... |
comet-deploy |
a POST to AitherComet's /deploy, tenant-scoped and cost-gated |
render |
host-registered: a media render; the renderer passes its own run_fns= |
artpack |
host-registered: a character art pack bake |
solve |
host-registered: a problem-solving session |
flow |
a journaled workflow in a child process; resumes by replay |
tunnel |
host-registered: expose or retire a public hostname on a plane (tunnel/pages/worker); submit is authz-gated like comet-deploy |
This section used to say
kind=agentdispatch only, and listkind=ciamong "the next phases", while ci was implemented, routed and covered by a self-test. That cost a real one: a release sat queued behind a saturated runner pool and nobody reached for awrun, because the README said the feature did not exist yet. A capability documented as unbuilt is unbuilt in practice — nobody calls it, so nothing exercises it, so nobody notices it works. A repo-side check now asserts this section against the dispatcher's own routing table, so it cannot drift back.
A run can be parked and continued. It keeps its id, priority and age.
awrun suspend r-7f3a9c2e # queued: parked now. running: its runner is asked to stop
awrun resume r-7f3a9c2e # back in the queue, where it was--kind flow is where this pays. A flow is a journaled workflow, and the run id
is the journal id, so a resumed flow replays the calls it already made instead
of making them again. Measured by this package's own test, which stops a real
child process mid-workflow: of four model calls, the two that had finished were
made exactly once across suspend and resume; only the call that was in flight
when the run stopped was repeated.
awrun submit --kind flow --script research.py --name nightly-research --lineage goal=G-42 --lineage expedition=exp-7 --priority 5Replay trusts the journal, so the journal is digested at suspend and checked at resume: one that changed while parked is refused, not replayed.
A suspended run can also leave the machine. awrun export bundles the run and
its journal and closes the local copy; awrun import lands it suspended on
another queue under the same id. Import verifies before it unpacks -- against
the digest the exporter printed, or against the exporter's public signing key --
and refuses a bundle offered with neither.
apiVersion: awrun/v1
kind: Run
metadata:
name: nightly-research
lineage: {goal: G-42, intent: keep-the-index-fresh}
spec:
kind: flow
priority: 5
limits: {timeout_s: 3600, cpus: 2, memory_mb: 4096}
egress: {hosts: [pypi.org, "*.githubusercontent.com"], proxy: "http://10.89.0.1:3128", network: jail}
isolation: {mode: container, image: "ghcr.io/you/agent:1"}
run: {script: research.py}awrun apply -f runs.yaml converges the queue on the manifest, by name. Applying
it twice is a no-op (unchanged); a new priority is configured; a new spec is
replaced; every document is validated before any is written. apply goes
through the same authorization as submit -- it cannot queue what submit
refuses. JSON manifests need nothing; YAML needs pip install 'awrun[yaml]'.
limits and egress are promises, so a run whose runner cannot keep them is
failed before it starts -- never run unconfined. timeout_s is enforced on
any local run. cpus, memory_mb and egress need isolation: container
(capabilities dropped, no new privileges). egress.hosts: [] means no network
at all. A non-empty allowlist places the run on an INTERNAL container network
whose only exit is awrun egress-proxy, and awrun asks the runtime whether that
network really is internal before it starts anything:
awrun egress-proxy --listen 10.89.0.1:3128 --allow pypi.org --allow '*.githubusercontent.com'The proxy matches the name the client asked for, before any lookup; a listed host opens ports 80 and 443 only; every denial is logged.
lineage records why a run exists (intent, goal, expedition, flow,
plan, notebook, parent_run); awrun queue --lineage goal=G-42 answers
"what is running for this goal". Suspend, resume, cancel, apply, export and
import are written to a hash-chained audit trail before they happen. Set
AWRUN_LIFECYCLE_OPERATORS and they also need a resolved identity session on
that list; set AWRUN_AUDIT_REQUIRED=1 and a change that cannot be recorded does
not happen. pip install 'awrun[governed]'.
python -m pytest tests/
python -m awrun.cli self-test
python -m awrun.dispatcher --self-testStandalone tools that share one idea: replace something you would otherwise have to trust with something you can check.
Each installs on its own, works offline, and needs no account.
| instead of trusting | you check | |
|---|---|---|
| awdk | a framework's idea of how your agents should run | one loop you can read, pointed at a backend you already pay for |
| awskills | that an agent knows your procedure | the procedure written down, versioned, and loadable by any agent |
| awpack | that the pack you want shipped inside somebody's SDK, under whatever licence that SDK happens to carry | the pack as its own versioned artifact, with its own licence, that any agent runtime can install |
| awm | that memory stayed in its lane | tenant:user:project scopes, so a write cannot cross a boundary |
| awdesk | that the agent is somewhere behind a browser tab | a tray icon, a face on your desktop, and the decision card that pops when it needs you |
| awnode | a vendor's cloud with every prompt | a local gateway routing to backends you chose |
| awgraph | that grep found everything | an AST + tree-sitter call graph an agent can traverse |
| awgit | that no one else is editing this file | a lease, refused at commit time if you do not hold it |
| awdelphi | one agent's confident take on a decision | the round trace, the anonymity, and who dissents |
| awclassify | a filename, a folder, or whoever last touched it | doc_type, visibility, audience and topics, with the evidence lines that decided each |
| awtoll | that your tooling is saving you context | the measured token cost of each tool call, and what the alternative cost |
| awseal | that the artifact came from who you think | an Ed25519 seal — the key that verifies is not the key that forges |
| awshare | that the download is intact | content-addressed bundles, verified on fetch |
| awnest | that there is a person on the other end | a verdict with evidence, where "we could not tell" is not "yes" |
| awrena | a leaderboard someone can edit, and votes nobody counted | a scored duel with both answers kept, and a result bound to them |
| awnboard | a share link anyone who sees it can use | an invitation addressed to one person, for one gate, revocable |
| awnix | that the box is what you left it as | an immutable image you built, with atomic rollback |
| awrecover | that the restore worked | a restore that fully lands or does not land at all |
| awstorage | a du you ran last month, and a peers file that says 3 TB free | an inventory snapshot per node with a diff since the last one, and each tree classified re-fetchable or not |
| awrelay | a SaaS in the middle of your agents | findings, alerts and coordination over your own transport |
| awask | that anyone read the paragraph where you asked | the ask itself, with a button that steers the session that raised it |
| awmail | a mailbox somebody else can read | mail your agents send and receive over your own server |
| awswarm | that a model either fits your GPU or it doesn't run at all | a placement plan and an acquisition-probability estimate before you spend on a run |
| awfind | one vendor's idea of the web | results from whichever providers you configured |
| awbrowse | that the page said what you were told | the render, the DOM and the requests it made |
| awvoice | that a cloud vendor may hold your audio | a transcript and a wav from a service you host |
| awvision | a filename and a caption somebody wrote | what a model actually reports about the pixels |
| awscreen | a selector that was true when the page was written | the elements actually rendered, by what they look like |
| awbeads | that a layout your users built survives the next deploy | the arrangement as data you can read back, diff, and hand to another surface |
| awbonsai | that inference always means a request left the machine | a WebGPU model answering on the tab's own GPU, with a consent record logged before it ever loaded |
| gawbbonet | the model to keep a 300-message campaign coherent by itself | campaign facts recalled from scoped memory you can list and edit |
| aitherkvcache | a vendor's quantisation defaults | sub-byte KV cache kernels you can benchmark yourself |
| awrtifact | a hand-rolled split script and a hand-edited worker manifest | byte-verified parts in a release, served with Range + CORS, sizes asserted by a live gate |
| AitherZero | a pile of scripts nobody has numbered | numbered, discoverable automation with declarative playbooks |
| AitherConnect | what a page tells your browser to do | a federated search and desktop bridge you host |
| awreason | a confident paragraph | the phases it went through, and every tool call it made to get there |
| awrecurse | that everything you pasted in was actually read | which slices it opened, and what it concluded from each |
| awprism | the first explanation that fits | the ranked alternatives, and the observation that separates them |
| awrepl | what the agent believes the value is | the value, printed from the live session |
| awreport | that the report you pasted carried no token in it | a redacted report, and the duplicate it merged into instead of filing twice |
| awresearch | a summary of pages nobody opened | every claim against the source it came from |
| awfocus | twelve terminal tabs and a bad memory | one command that names every session, finds any transcript, and opens or steers the one you want |
| awgym | that a world model learned anything from the games it saw | transitions captured from real play, fed back, and the retrodiction score falling on grids it never saw |
| awpredict | a model because it trained without erroring | its prediction against a self-updating lookup, on the rows that are actually novel |
| awevolve | that your optimisation loop is finding anything | every version it kept, the score that version earned, and the edit that produced it |
| awsh | that you already know the name of the command | what it decided your line meant, before it acts on it |
| awmine | that a session's lesson survived the session | a row per outcome, a candidate per lesson, and the transcript line each one came from |
| awrise | that a scheduled agent ran at all, and ran exactly once | a durable record of every wake -- fired, skipped, overlapped or timed out -- each with its reason |
| awkno | that the docs site is up, or that you remember the family | the whole ecosystem in your terminal, with no network at all |
| awwall | that a service only talks to the hosts you think it talks to | an explicit egress allowlist, where a denial names the rule that denied it |
| awembed | a general-purpose embedder that has never seen your code | a held-out split of whole directories, scored teacher vs student vs int8 |
| awtax | a closed tax app's sealed file you can never read again | a plain, provider-neutral schema of every figure, with the page it came from |
| awsettings | that you will remember to re-approve the same thing on every box you work from | one profile, unioned rather than overwritten, with the credentials left behind |
| awavatar | a cloud 3D vendor's opaque task id | a manifest with a sha256, a licence and a rig-audit verdict per file |
awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.
Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.
| repo | what it is | pages |
|---|---|---|
| awdk | Build AI agent fleets — 3 lines, any backend, local or cloud | docs |
| awskills | Portable agent skills — self-contained procedures an agent loads on demand | docs |
| awpack | First-party agent packs — the ones we build, versioned and installable on their own | docs |
| awm | A portable, scoped agent memory | docs |
| awdesk | Aither World Desk -- the desktop body of AitherOS Online: tray, avatars, decision cards, the Living Desktop as an overlay | docs |
| awnode | A lightweight local gateway — bridges your apps to the AI backends you chose | docs |
| awrun (you are here) | A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds. It also judges whether the runner pool is big enough for the queue it is draining, and can ask a host to grow it -- reserving capacity is zero-sum, so a saturated pool needs more of it, not a different share of it | docs |
| awgraph | A semantic code graph for agents — AST + tree-sitter, call graphs | docs |
| awgit | Semantic version control on top of git — edit-ops and leases | docs |
| awdelphi | Anonymous multi-round expert panels — a converged answer with a trace | docs |
| awclassify | Classify any document -- what it is, who may read it, who it is for, what it is about | — |
| awtoll | What every tool call costs you in context, measured from your own transcripts | docs |
| awseal | Sign an artifact so a stranger can verify it | docs |
| awshare | Publish an artifact and fetch it back verified | docs |
| awdit | An append-only audit trail whose gaps are DETECTABLE | docs |
| awbac | Role-based access control that fails closed and explains itself | docs |
| awiam | Who is this caller? A directory and session store that fails honestly | docs |
| awtunnel | Reach a service that has no public address | docs |
| awnest | Prove there is a human before you let them into the nest | docs |
| awrena | Put two agents head to head and get a verdict you can check | docs |
| awnboard | A front gate you can put in front of anything, and hand someone the key to | docs |
| awnix | A Linux you can hand to an agent — immutable base, capabilities included | docs |
| awrecover | Labelled snapshots with an all-or-nothing restore | docs |
| awstorage | Every drive on every node, indexed, classified and diffed -- so you can see what you own before you delete it | docs |
| awrelay | Portable agent messaging — findings, alerts, coordination | docs |
| awask | Your agent asks you a question — and acts on your answer | docs |
| awmail | Give an agent an email address — send, and actually receive | docs |
| awnet | The agentic web — agents host a mesh, and agents join one | docs |
| awswarm | Run one model too big for any single GPU across a pool of small ones | — |
| awfind | A portable search client — query, results, ranking | docs |
| awbrowse | A portable browser client — navigate, console, network, DOM, screenshot | docs |
| awvoice | Hear and speak — transcribe audio, synthesize a voice | docs |
| awvision | See an image — describe it, ask it a question, compare two | docs |
| awscreen | See this machine — what is on screen, and where to click it | docs |
| awkit | Render an agent panel from a tool result — one component, any React app | — |
| awbeads | A spatial canvas for a page — arrange things, connect them, and keep the arrangement | — |
| awbonsai | Run a real model in the visitor's own browser — no server round trip, no upload | — |
| awknowledge | How to run a coding agent so the result survives — the laws, with evidence | docs |
| awbrain | Your history as a wiki of linked markdown — claims pinned to the evidence | — |
| gawbbonet | GobboNet campaigns with a real agent brain — scoped memory, graph recall | docs |
| aitherkvcache | Near-optimal KV cache quantization for LLM inference — sub-byte compression | docs |
| awrtifact | Deliberately chunk artifacts into GitHub release assets — the productized aitherkvcache mirror lane | docs |
| AitherZero | PowerShell 7+ automation framework — numbered, self-describing scripts | docs |
| AitherConnect | Browser extension — federated AI search, page context, and the Living OS overlay | docs |
| awreason | A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer | docs |
| awrecurse | Answer a question over a context far larger than the window — recursively, with the trace kept | docs |
| awprism | Turn a failure into ranked hypotheses — and say what would confirm each one | docs |
| awrepl | A REPL an agent can actually use — state that survives between turns | docs |
| awreport | File a bug report that has already scrubbed your secrets and collapsed the duplicate | — |
| awresearch | Ask a research question, get a cited report you can check | docs |
| awfocus | See, search and steer every Claude session from one command | docs |
| awgym | An ARC training gym — a game a world model can watch, and six roles that play through it | docs |
| awpredict | Predict what your environment does next, and how surprised you were | docs |
| awevolve | Point an agent at a file and a command that scores it, and let it improve | — |
| awsh | Your terminal answers you -- type a question where a command would go | docs |
| awmine | Mine what your agents did -- outcomes, lessons and procedures out of the transcripts they left behind | — |
| awrise | Wake an agent on a schedule, let it do one thing, and put it back to sleep | docs |
| awkno | The man page for the Aither World — every brick, stack and law, offline | docs |
| awwall | Say what a workload may reach, and watch everything else fail closed | docs |
| awrouter | OpenRouter for your own fleet: pick a model backend by cost/latency/ capability, fail over, fit the context window, stream. Standalone, OpenAI-compatible, no Aither-specifics required to be valuable | — |
| awembed | Train an embedding model that knows your corpus, and prove it beats the big one | docs |
| awtax | Turn any tax PDF -- returns, W-2, 1099, statements, even scans -- into structured data you can check | docs |
| awflow | A deterministic workflow runtime — chain agent calls with journal replay and budget control | docs |
| awsettings | Your agent's permissions and config, following you to the next machine | docs |
| awavatar | One character spec in, a rigged, animated, multi-style avatar pack out | docs |