Skip to content
chatAgent
Esc
↑↓navigate↵open⌘Jpreview
On this page

AgentOS Configuration

AgentOS Configuration

Overview

AgentOS is a V8 isolate + WASM-based virtual OS that runs inside each Rivet actor. It provides a POSIX-compatible environment (filesystem, network, processes) for the Pi Agent instance.

Architectural context: Each Rivet actor contains one AgentOS isolate. The isolate runs the Python Pi Agent Core runtime. AgentOS provides the sandbox; Rivet provides the actor lifecycle; Pi Agent provides the LLM orchestration.

Architecture

graph TB
    subgraph "Rivet Cluster"
        subgraph "Actor: User A"
            AOS_A[AgentOS Isolate<br/>~22 MB]
            PY_A[Python Pi Agent]
            FS_A[Virtual Filesystem]
            NET_A[Virtual Network]
        end
        subgraph "Actor: User B"
            AOS_B[AgentOS Isolate<br/>~22 MB]
            PY_B[Python Pi Agent]
            FS_B[Virtual Filesystem]
            NET_B[Virtual Network]
        end
        subgraph "Actor: User N"
            AOS_N[AgentOS Isolate<br/>~22 MB]
            PY_N[Python Pi Agent]
            FS_N[Virtual Filesystem]
            NET_N[Virtual Network]
        end
    end

    subgraph "Mounted Storage"
        S3[(S3 Bucket)]
        MEM[(In-Memory)]
        HOST[(Host Directory)]
    end

    FS_A -.->|mount| S3
    FS_B -.->|mount| MEM
    FS_N -.->|mount| HOST

    style AOS_A fill:#fff9c4,stroke:#f9a825
    style AOS_B fill:#fff9c4,stroke:#f9a825
    style AOS_N fill:#fff9c4,stroke:#f9a825

Performance

Metric AgentOS Traditional Sandbox
Cold start (p50) 4.8 ms 440 ms (92× slower)
Memory per isolate ~22 MB ~1024 MB (47× more)
Cost (vs Daytona) 254× cheaper Baseline

Configuration

AgentOS Setup Inside Actor

# AgentOS is configured when the actor starts
from rivet import AgentOsConfig

@rivet.actor
class ShoppingAgentActor(Actor):
    class Config:
        agentos = AgentOsConfig(
            permissions=AgentOsPermissions(
                network=True,        # Shopify MCP + WhatsApp API + LLM
                filesystem=True,     # Session state + MCP operations
                processes=False,     # Not needed (security)
                max_memory_mb=128,
            ),
            mounts=[
                # User state (cart, preferences, conversation)
                MountConfig(
                    type="s3",
                    bucket="whatsapp-bot-state",
                    prefix="users/{actor_id}/",
                    target="/state",
                ),
                # Temporary workspace
                MountConfig(type="memory", target="/tmp"),
                # Read-only config
                MountConfig(
                    type="host",
                    source="/app/shared-config",
                    target="/config",
                ),
            ],
            limits=AgentOsLimits(
                max_processes=5,
                max_files=50,
                max_sockets=10,
                max_execution_time_ms=60000,
            ),
        )

Mount Strategy

Mount Type Purpose Access
/state S3 User state (cart, prefs, conversation) Read/Write
/tmp Memory Temporary MCP operations Read/Write (ephemeral)
/config Host Store policies, catalog cache Read-only

Permissions

AgentOsPermissions(
    network=True,        # Allow outbound HTTP (Shopify, WhatsApp, LLM)
    filesystem=True,     # Allow FS operations (state persistence)
    processes=False,     # No subprocess creation (security)
    max_memory_mb=128,   # Generous for agent state + MCP client
)

Resource Limits

AgentOsLimits(
    max_processes=5,         # MCP client + agent runtime
    max_files=50,            # Session files + cache
    max_sockets=10,          # Shopify + WhatsApp + LLM + Redis
    max_execution_time_ms=60000,  # 60s max per message
)

Sandbox Escalation

AgentOS can escalate from V8 isolate to full Linux sandbox when needed:

stateDiagram-v2
    [*] --> V8Isolate: Normal operation
    V8Isolate --> V8Isolate: Standard tool calls
    V8Isolate --> LinuxSandbox: Escalation keyword triggered
    LinuxSandbox --> V8Isolate: Task complete

    note right of V8Isolate
        ~22 MB memory
        4.8 ms cold start
        No native binaries
    end note

    note right of LinuxSandbox
        Full Linux environment
        Native binary support
        Higher resource cost
    end note

For the shopping bot, escalation is unlikely — we only need:

  • HTTP calls (Shopify MCP, WhatsApp API, LLM)
  • File read/write (session state)
  • JSON parsing (product data)

Escalation triggers (if needed):

sandbox_escalation_keywords=["run_binary", "compile_code", "system_command"]

Lifecycle Inside Actor

stateDiagram-v2
    [*] --> ActorCreated: Rivet creates actor
    ActorCreated --> AgentOsInit: on_init()
    AgentOsInit --> AgentRunning: Isolate ready
    AgentRunning --> AgentRunning: on_message() calls
    AgentRunning --> AgentSleeping: 5 min idle
    AgentSleeping --> AgentRunning: Wake on message
    AgentSleeping --> ActorTerminated: 1 hr idle
    ActorTerminated --> [*]

The AgentOS isolate follows the actor’s lifecycle:

  • Created when actor is created
  • Active when actor is running
  • Frozen when actor sleeps
  • Destroyed when actor terminates

Deployment Templates

Platform Template
Docker agentos-docker
AWS (ECS/Lambda) agentos-aws
GCP (Cloud Run) agentos-gcp
Azure agentos-azure
Vercel agentos-vercel
Railway agentos-railway
Fly.io agentos-fly
Kubernetes agentos-helm

Summary

Requirement AgentOS Solution
Per-user isolation V8 isolate (~22 MB each)
Fast cold starts 4.8 ms p50
Persistent state S3 mount
Network access Virtual networking
Low cost 254× cheaper than traditional sandboxes
Scalability Runs inside Rivet actors, thousands per cluster
Native tools Sandbox escalation (if needed)

See Also

Last updated on July 26, 2026