DEV Community

Emery Li
Emery Li

Posted on

A Link-State Ledger for Local-First Agent Placement

A developer opens a half-finished refactor on a regional train, with the repository cloned and the local tests already green. The hotspot shows two bars, then drops to none, then returns after a long and uneven delay. A remote agent host would accept the job, but the same drop would strand a patch that is already in flight. Placement therefore starts from the path that exists now, not from a model name that looked strong on a slide.

The opening scene is a composite illustration for placement practice, not a field report from a named team. No latency figure in this note comes from a measured commute, a vendor dashboard, or a published benchmark. The numbers below are policy placeholders that a team can replace after it runs its own probes. The method still applies when those placeholders change, because the gate reads labels rather than a frozen measurement.

Treat the link as its own axis

Model quality does not describe a tunnel that vanishes between stations and then returns with a different address. A fast remote completion is useless when the response never arrives before the laptop sleeps or the session expires. A local model may feel slower on a large context, yet it still runs after the radio disappears. Placement should therefore score the path before anyone argues about checkpoints, vendors, or a preferred hosting style.

Three constraints usually collide on that path, and each one can veto a hop by itself. Round-trip time decides whether an interactive edit stays tolerable for the person sitting at the keyboard. Secret class decides whether a prompt, a diff, or an environment file may leave the machine at all. Offline need decides whether the job must still finish after the link dies midway through the task.

A free remote server can win on latency and still lose on secrets or on survival. Winning a single column is not the same thing as earning the right to leave the laptop. The next section names the link states that feed those three constraints into one auditable table.

Name three link states

The gate uses three names, and each name maps to a placement rule that a reviewer can audit later. Offline means that no route to the chosen host survived a full probe window on this attempt. Degraded means a route existed, but loss, jitter, or a timeout already failed the written budget. Stable means repeated probes stayed inside the budget and no secret rule blocks the move itself.

Offline keeps every step on the laptop, including planning notes that would otherwise be uploaded with the job. Degraded allows a local classification of the task, then holds the payload until the link improves or the developer accepts a smaller plan. Stable permits a remote run only after secret scanning and a residency line in the local journal. These names are operational labels for the gate, not a claim about any provider uptime or region coverage.

Read the placement table

The table joins link state, secret class, and offline need into one placement outcome for the current job. Each row is a rule a reviewer can point at, rather than a preference for whichever host felt faster this morning. Read the row that matches the probe, then ignore every row that describes a nicer network than the one in hand.

Link state Secret class Must finish if the link dies Placement
Offline Any Any Stay on the laptop and queue a later retry
Degraded Restricted Yes Stay local and shrink the task
Degraded Public scaffold only No Hold the payload until the state is stable
Stable Restricted Any Stay local; remote side sees redacted summaries only
Stable Public scaffold only No Remote host is eligible
Stable Public scaffold only Yes Remote host only with a resumable local journal

Restricted means tokens, customer data, private keys, or source that the team has not cleared for upload. Public scaffold means generated files the team already treats as shareable, such as boilerplate with no embedded credentials. The table is a policy sketch for this workflow, and teams should replace rows with their own handling rules. A row that looks convenient is not a clearance to upload material the security review has not seen.

Run the gate in order

The steps assume a developer machine with Python 3.11 and a repository checkout that already contains the prompt and the diff. The probe is an unexecuted example for teaching the gate, and it has not been timed on a live network. It is not a production client, and it does not call a vendor SDK or claim a measured error rate.

  1. Write the latency budget into one local file before any hop toward a remote host is attempted. A budget of 800 milliseconds for a health probe is a starting policy, not a measured guarantee on any network. Interactive editing often needs a tighter budget than a background indexing job that can safely wait. Record the chosen number in the job note so a later reader can see why the gate fired.

  2. Classify the payload before a host is chosen for the bytes that would leave the machine. Search the staged diff and the prompt file for obvious key material, then refuse the remote path if a match appears. A simple scan will miss split secrets and clever encodings, so a human still owns the final clearance. The scan exists to catch the obvious leak, not to certify that the working tree is safe for upload.

  3. Probe the chosen path three times and keep the worst successful sample for the placement decision. One lucky packet should not mark a tunnel stable for the rest of the working afternoon. If any probe fails, the state becomes degraded or offline according to whether a route existed at all. Store the three samples beside the decision so the journal can explain a later dispute about the hop.

  4. Apply the table and append the decision to a local journal that never leaves the laptop. The journal remains on disk even when a later step is allowed to run on a remote host. That record is what lets a reviewer reconstruct placement after the train has left the tunnel. Without the journal, a stable morning can be mistaken for standing permission during an unstable afternoon.

  5. Ship only the artifact that the winning row of the table actually allows onto the wire. For a stable link and a public scaffold, a remote server can absorb a long context that would heat the laptop all commute. For every other row, the laptop keeps the bytes and the remote host is not invited into the job. If the state flips after shipping has started, new bytes stop and the journal records the abort reason.

Command and probe sketch

# Unexecuted example. Replace the host and paths before any real run.
python3 link_gate.py --host example.invalid --budget-ms 800 --samples 3 --paths ./prompt.md ./diff.patch --journal ./.local/placement-journal.jsonl

# Unexecuted example. Inspect the newest local decision after a dry classification.
tail -n 1 ./.local/placement-journal.jsonl
Enter fullscreen mode Exit fullscreen mode
# Unexecuted example. Adapt hosts, budgets, and secret rules before use.
import time
import subprocess
from pathlib import Path

BUDGET_MS = 800
PROBE_HOST = 'example.invalid'  # operator-approved host only
SAMPLES = 3
SECRET_HINTS = ('BEGIN PRIVATE KEY', 'api_key', 'AWS_SECRET', 'password=')

def classify_secrets(paths: list[Path]) -> str:
    for path in paths:
        text = path.read_text(errors='ignore')
        if any(hint in text for hint in SECRET_HINTS):
            return 'restricted'
    return 'public_scaffold'

def probe_once(host: str) -> tuple[bool, float]:
    start = time.perf_counter()
    result = subprocess.run(
        ['nc', '-z', '-G', '2', host, '443'],
        capture_output=True,
    )
    elapsed_ms = (time.perf_counter() - start) * 1000
    return result.returncode == 0, elapsed_ms

def link_state(host: str) -> tuple[str, float]:
    samples = [probe_once(host) for _ in range(SAMPLES)]
    reached = [ok for ok, _ in samples]
    times = [ms for ok, ms in samples if ok]
    if not any(reached):
        return 'offline', float('inf')
    worst = max(times) if times else float('inf')
    if not all(reached) or worst > BUDGET_MS:
        return 'degraded', worst
    return 'stable', worst

def place(state: str, secret_class: str, must_finish_offline: bool) -> str:
    if state == 'offline' or secret_class == 'restricted':
        return 'laptop'
    if state == 'degraded':
        return 'laptop' if must_finish_offline else 'hold'
    if must_finish_offline:
        return 'remote_with_local_journal'
    return 'remote_eligible'
Enter fullscreen mode Exit fullscreen mode

The sketch uses a reserved invalid host so nobody can mistake the sample address for a live endpoint. Operators should substitute a host they are allowed to probe, and they should confirm that a TCP check matches their real health route. A passing probe still says nothing about model quality, queue depth, or the current token price. Application latency needs a separate check that the team is already permitted to run against that host.

The nc flags in the sketch are illustrative, because BSD and GNU netcat do not share the same timeout switch. A team should swap in a probe it already trusts, such as a permitted HTTP health request with a hard timeout. The sample also assumes a Unix-like nc binary, so Windows hosts need a different reachability check before the function is useful. Until that swap happens, the Python function only documents the decision shape and should not be copied into a cron job.

Where a free server earns the hop

Disclosure: This article was prepared as part of MonkeyCode's product outreach.

A remote run earns its place when the link is stable and the payload is already cleared as a public scaffold. In that narrow case, a free server option can take a long rewrite that would otherwise pin a laptop fan all commute. Free model access matters there too, because cost no longer blocks a comparison between a local checkpoint and a hosted model. Both availability claims are operator-supplied for this draft, and they are not a promise that any quota or duration stays fixed.

Current model names, numeric quotas, and rental terms are omitted on purpose from this note entirely. Those facts change, and a reader should read the project pages the operator maintains before planning capacity around them. The laptop still owns the journal, the secret scan, and the right to abort a hop that no longer matches the table. If a later probe flips to degraded, new bytes stop leaving even when an earlier hop already succeeded.

MonkeyCode fits as one eligible remote target when its free model access and free server option are available to the account. It does not replace the gate, and a different host with the same residency rules would occupy the same table row. Readers who already keep a local journal can confirm the live offer, then point the probe at a host they are permitted to use.

Limitations and poor fits

The probe measures reachability, not the time a model spends before the first useful token returns to the client. A health port can answer quickly while a queue sits quietly for minutes, so tail latency needs an application check of its own. The secret scan is a hint list, and it will miss values that are split, encoded, or injected only at runtime. Offline completion assumes the laptop already holds the model or the tools required to finish the accepted slice of work.

This approach is a poor fit for teams that handle regulated data and still lack a written upload policy. It is also a poor fit for anyone who needs a certified uptime figure, a named hardware profile, or a guaranteed free quota. None of those facts is established by the sketch or by the operator-supplied availability claims in this note. Developers who paste raw environment files into prompts should fix that habit before any remote placement is even considered.

A machine with neither a local model nor a stable link cannot finish the accepted slice under this policy. The honest outcome is a queued job on the laptop, rather than a forced upload of an uncleared payload. The table will not invent connectivity, and it will not launder a restricted diff into a public scaffold after the fact. Teams that need a formal threat model should treat this note as a checklist starter, not as their completed security review.

Keep the decision beside the repository

Link state, secret class, and offline need can be scored before a single payload byte leaves the laptop. The table is small enough to keep in the repository, and the probe is small enough to rerun when the train enters another tunnel. A free remote server remains a useful exit ramp after those checks pass, and only after those checks pass. The journal, not a marketing page, is what should decide the next hop for this class of work.

Top comments (0)