A workspace is a multi-file tree whose exact digest can be authorized, executed and audited. A trusted host holds the agent's run; jailed code receives no credential and can only propose bounded operations. Workspaces are an extension over Radia's public API.
Code generation often produces a project rather than one source file. The files must persist between iterations, preserve their version history and materialize as a directory for tools that expect a filesystem.
Radia stores each tree version durably while using temporary directories only for execution. The record model remains the source of identity, provenance and authorization.
The runtime has no workspace, file, path or directory abstraction.
The workspace extension combines a manifest record, artifact records for file contents and a latest-version projection. It uses the same public API as an external application.
extensions/. Application-specific behavior stays in
the application, and the runtime remains limited to records, leases, grants and artifacts.
Structural tests prevent extensions from importing runtime internals. The Git export and the Git server are therefore ordinary clients, not privileged server operations: a push writes versions under the pusher's own permissions.
A manifest record contains a name, tree digest, base version and file list. Each file entry contains a validated path, mode, content digest and artifact id.
{ "name": "landing-page",
"treeDigest": "t1:9f2c...ade1",
"basedOn": "01JB2Q7X4KJ8ZN0R5V3M9WPHTC",
"files": [
{ "path": "index.html", "mode": "100644", "digest": "sha256:4b1e...", "artifactId": "01JB2..." },
{ "path": "style.css", "mode": "100644", "digest": "sha256:c70a...", "artifactId": "01JB2..." },
{ "path": "cat.png", "mode": "100644", "digest": "sha256:8ee3...", "artifactId": "01JB2..." }
] }
Editing writes a new manifest linked to its base version. File bytes are content-addressed, so unchanged files are shared across versions. Concurrent edits from the same base create visible successor branches.
Existing artifacts can be attached without copying their bytes. Attached artifacts become data parents of the manifest, propagating their provenance labels.
NAME FILES VERSIONS TREE OWNER
landing-page 3 7 t1:9f2cade1a4… human:alice
scraper 9 22 t1:07b3e5c918… human:alice
Paths are validated when a manifest is written and again during materialization. The materializer verifies that every resolved file remains within the destination directory.
Radia ships a Deno permission jail for JavaScript, a bubblewrap backend on Linux for available host interpreters, a Seatbelt backend for macOS Python, and a Web Worker backend for a browser tab. Sandbox records describe the guarantees of each backend.
A worker probes a sandbox before advertising it. A backend is available only when the probe confirms the guarantees claimed by its record.
Successful probes determine which execution tools the worker publishes. A host that cannot provide the required isolation does not advertise that runner.
The sandbox and the broker enforce different boundaries. The sandbox restricts ambient host access such as files, processes, storage and network. The broker ensures that code inside the sandbox never possesses a reusable Radia credential and cannot choose the identity, provenance or idempotency of committed operations.
A run writes files into a separate output directory. When execution finishes, the host captures that directory as a new workspace version. The input tree remains immutable and may be shared by concurrent runs.
A binding record associates an agent with a workspace digest. The generic host materializes that version, executes it in the selected jail and claims work through the agent's run.
Promotion rotates grants that are pinned to the workspace digest. The claim permission and executable code version are therefore checked together.
$ radia promote t1:07b3e5c918… --tier prod --pin agent:scraper:take,ack
$ radia pins agent:scraper --tier prod
agent:scraper on 'prod': t1:07b3e5c918…
A host refuses a binding whose digest disagrees with the active grant pin. Rollback promotes a previous digest through the same mechanism. The jail bounds host access, the binding selects code and the grant limits the records that code may process and produce.
Bindings declare which request fields identify input artifacts. The host fetches those artifacts under the agent's authority and places them in the run directory. Outputs name the inputs as parents so their labels propagate.
The analysis example uses promoted workspace stages through one generic host. View the analysis example →
The extension converts a manifest into a path-to-artifact index and mints a short-lived capability over the complete tree. Scriptable content is served from an isolated origin.
Requests match entries in the fixed index and never resolve against a filesystem. Artifact access is authorized when the capability is minted, and the URL expires with that capability.
$ radia workspace-git landing-page --dir /tmp/landing.git
landing-page: 7 versions, 34 objects -> /tmp/landing.git
$ git clone /tmp/landing.git && cd landing && git log --oneline
9c1e4a2 attempt 7: fix the header overlap
04b7f30 attempt 6: add the illustration
…
The same projection can be served over Git HTTP, for clone and for push:
$ radia git-serve
git server on http://127.0.0.1:7790 (reading http://127.0.0.1:7788)
$ git config --global credential.http://127.0.0.1:7790.helper '!radia git-credential'
$ git clone http://127.0.0.1:7790/landing-page.git
$ cd landing-page && $EDITOR index.html
$ git commit -am "tighten the hero copy" && git push
To http://127.0.0.1:7790/landing-page.git
9c1e4a2..d41f2b7 main -> main
$ radia workspaces
NAME FILES VERSIONS TREE OWNER
landing-page 9 8 a41c7f0e2b9d31… human:oidc-alice
Git authenticates as you: the credential helper hands git the login this machine already
holds, from radia login --sso or radia login, and the server
applies that principal's Radia permissions. Revocation stops the next fetch or push.
Push is accepted fast-forward only. Each pushed commit becomes the next version, written
under the pusher's own workspace: put grant, and the commit keeps its id, so a
fetch after a push changes nothing. A force-push, a merge commit, a new or deleted branch, a
symlink or a commit that changes no file is refused with the reason on git's own
! [remote rejected] line. There is no merge: rebase onto the branch and push
again.
Each manifest version becomes a commit, version links become commit parents and trailers refer back to the source record. The exporter writes Git objects directly without invoking Git.
A push imports trees, never history. Each pushed commit's files become a version and its commit id is recomputed from the bytes; Git object identity and rewritable history are not accepted as workspace identity, and Radia records and SHA-256 tree digests remain authoritative.
Anyone who has purged a leaked credential from a repository knows what it costs: every downstream hash changes, every fork force-pushes, every clone is invalidated, signed tags die. Here a file is an artifact, so one payload can be destroyed while the tree digest still verifies and the history still reads.
credentials/prod-db.txt outlives its own contents, and anyone
holding a candidate secret can hash it and confirm that exact value was in that tree. A
destroyed build output or document is gone in every practical sense. A destroyed credential is
unreadable and still confirmable, and its filename is plaintext forever. What this removes is
the blast radius, not the disclosure.
Past that: every file version is attributable to a specific run, the dependency set is inside
the record rather than claimed by a lockfile, a grant can scope which workspace an agent may
touch at all, and labels track whether a file descends from something untrusted. Branch
protection has been approximating that last set for years, and a git hook dies to
--no-verify.
What it does not buy: incremental builds, editor feedback, merge, blame. Git does the storage model better and has thirty years of tooling around it. A workspace is instead a working tree whose every state is a record the runtime can authorize, attest and erase.