Getting started
What works today
Which features you can use now, and which are designed and on the roadmap.
Orchestrator Zero is built in milestones, each ending with a demo. These docs describe both what works and what is planned; planned pages carry a notice at the top.
Works today
| Area | What you can do |
|---|---|
| Servers | Dev mode on SQLite; clusters of servers on PostgreSQL with embedded Temporal; schema migrations on upgrade |
| Nodes | Join with a token or by approval; labels; block and unblock within two seconds; certificates that renew themselves; failover between edges; health scores, with unhealthy nodes drained; a node binary that replaces itself from a signed release, and goes back when the new one reaches no edge; purge, which makes a node remove itself from its machine |
| Tenants | Tenants, each with its own Temporal namespace; tenant secrets sealed with the master key, and delivered to the processes of the plugins that declare them |
| Plugins | Install from Git with an optional ref, locked to a commit, from a folder of a repository and from private repositories with a token; hooks before and after tool calls and at the start and end of jobs; flows of tool, agent and approval steps with CEL, started by name or by a webhook; tools as your own Python MCP servers, PyPI packages, npm packages or remote MCP servers; skills; plugin new, lint, test (evals with recorded model answers), update, remove; a quality gate that runs a new version's evals on a test node and stops a worse version; orchestrator-zero dev with live reload |
| Agents | Pydantic AI agents from plugins; Claude Agent SDK agents through the harness-claude plugin; tools on the job's home node; delegation with oz.delegate; input and output contracts; step, token, time and cost limits |
| Jobs | orchestrator-zero run, job watch, job get, job list, job cancel; the runtime API on the edge; a live stream of what agents write and call, across nodes; approvals for tool calls in requires_approval |
| Models and cost | The LLM gateway for Anthropic and OpenAI-compatible APIs, streaming and server tools included; tokens and cost per call, job, agent and model, web searches included; costs that plugins report for their own services; cost per branch of a job tree; budgets in dollars per job tree and per tenant and month |
| Operations | Health scores per node; metrics for Prometheus; an OpenTelemetry trace per job, across the edge and the nodes; an audit log you can read (orchestrator-zero audit); runtime upgrades that never break a running job, with old and new versions side by side on each node; rollouts of a runtime version or a plugin version, canary first, through health and quality gates, with rollback by themselves; signed releases that the edge mirrors with server dist pull; backups taken while servers run, and restores that check the master key first; operator certificates that renew |
| Web UI | Overview, nodes with the commands to add more and rollouts of a runtime to them, agents you can run, plugins and their rollouts, jobs with a live view and cost per branch, approvals, findings, cost, the audit log, settings; accounts with a role in each tenant (reader, operator, admin or owner) and a separate permission to see what jobs read and wrote |
M5, flows, hooks and quality, is done: make demo-m5 runs plan §3's example, a support-triage plugin built around typed decisions, and a worse version stopped by its quality gate. See Example: support triage.
In progress
- M3's demo against the real Claude API: it runs in CI against a stand-in for the API today.
- M4, the web UI: the pages above work, and
make demo-mvpruns the MVP demo on a two-server cluster with stand-ins; its run against GitHub and the Claude API is next. - M6, operations: budgets per tenant, health scores, metrics, runtime upgrades and rollouts, roles per tenant, signed node self-updates, backups and restores, and purge work, from the CLI and most of them from the web UI.
make demo-m6runs the milestone's demo: every node upgraded while jobs run, and a broken runtime rolled back by itself. Webhook flows reach no harness agent with a shell, every harness tool call passes hooks and approvals, large payloads leave Temporal's histories, and every job is a trace with a waterfall in the web UI. The node's tests run on macOS and Windows once a week. A tenant may have up to 150 agents and flows, the number our load test measured. A plugin's new version rolls out to canary nodes first, on task queues of its own, and rolls back by itself.
Planned
| Milestone | Theme | Highlights |
|---|---|---|
| M7 | Temporal Cloud | Temporal Cloud as a backend, and management running on its own; edges that fall behind step aside; sign-in with OIDC and MFA |
| M8 | Agents in production | Model providers as data, with aliases; local models on the node; contracts for agents and tools; a sandbox for harness sessions and for jobs that outside events start; routines with safe outputs |
| M9 | Studio and governance | A studio to write and test agents, flows and routines; an audit trail of every run; retention and erasure; kill switches; the licence and the editions |
| M10 | v1.0 | Hardening, load tests, and the first public release |