Craig McLuckie of Stacklok argues that coding agents should not remain tied to a developer’s device and interactive workflow, and presents the open-source Mecatl project as a model for a distributed architecture that separates the agent loop from clients, execution environments, tools, and supporting services.
The value of coding agents is no longer confined to a conversational interface that answers questions. Their practical adoption has been tied to having capable tools, a shared repository and file system, subagents, and skills that preserve what the system learns from previous work. According to Craig McLuckie of Stacklok, the next step is to move these capabilities from the developer’s computer to long-running services and interfaces used by people who may not open a terminal at all.
The problem is that most current agent runtime frameworks were designed around a desktop model: one user, one device, a local file system, and an interactive process that simultaneously combines the user interface, agent loop, isolation, credential storage, tool hosting, and session database. This model suits an individual developer, but becomes less suitable when an organization needs to run hundreds of sessions, enforce precise policies on tools, resume a session after a node failure, or move between different devices.
Separating the Agent Loop from the Rest of the System
McLuckie proposes building what he calls a “cloud-native runtime harness” as a distributed application from the outset, rather than merely placing a desktop framework inside a container. A container may change where the process runs, but it does not break apart the interdependence among its components. At Stacklok, the open-source Mecatl framework was made available for this purpose.
In Mecatl, the core handles the agent loop, including inference, tool-call dispatch, permissions, hooks, and event emission. The other elements connect to it through clear interfaces:
- End-user clients and APIs, including a TUI called mecatui, gRPC and HTTP/SSE interfaces, and a TypeScript SDK.
- Execution environments, workspaces, and command runners in which the agent performs its tasks.
- A tool ecosystem including built-in tools, MCP services over streaming HTTP, skills, and application-specific integrations.
- Supporting services for managing model providers, session state, event logs, identity, and coordination.
What Changes in Practice?
This separation makes the agent loop a component that can be released, deployed, and monitored like any other service. It can run in a terminal, as a service, or on Kubernetes without replacing the loop itself. In the mecak8s guide, workers can be replaced during operation while persistent sessions remain available when a new version is deployed.
Session state and the event log are stored in persistent storage under a coordination model based on a single writer. If a worker fails, a replacement worker can continue from the last saved turn boundary. However, this is not equivalent to a distributed transaction: the operation in progress at the moment of failure is not resumed, and work completed after the last successful save may be lost. The project therefore describes this capability as turn-level continuity, not a guarantee of a complete distributed transaction.
The explicit catalog also makes it possible to restrict the permitted tools, skills, and integrations, with boundaries for permissions, auditing, and the execution environment. Because the client does not own the file system, credentials, or session state, the same loop can serve a terminal, a remote service, an embedded application, or a Kubernetes deployment, and can even connect a web interface, a Slack integration, and a collaborative editor to the same session.
Unresolved Questions
The source emphasizes that Mecatl is still at an early stage, and that the “cloud-native harness” is an architectural direction rather than a completed specification. One of the main issues is determining the identity of the party invoking an external system: the user, the agent, the session, or a multilevel subagent? The project proposes its own SPIFFE trust domain, with the complete delegation chain encoded in a JWT so that receiving systems can make decisions based on the identity chain.
The project is also studying tool paths that go beyond MCP, allowing a tool such as a PDF analyzer to work directly on the file system instead of passing all its inputs and outputs through the model’s context window. The idea of “context attestation” also emerges: issuing, signing, attributing, distributing, and subjecting packaged context to policies like any artifact in a software supply chain.
Editorial reading: The importance of the proposal lies not in launching a new interface, but in redefining the agent as a manageable service rather than a long-lived personal process. However, the source clearly distinguishes between what currently works in Mecatl and what remains in the design phase. Moreover, current continuity does not prevent the loss of work in progress, nor does it yet settle the identity model or direct data transfer between tools. Adopting this model therefore requires a practical assessment of the deployment environment, permission boundaries, and data guarantees before it can be considered a ready replacement for all local agent frameworks.