monaco

Agentic Go and Python (experimental)

Pay for the work, not for the lease.

For humans

last — ms — J · session — J · $0.20/kJ
:w write · :wq / ZZ write+close · :q close · :fmt gofmt · Ctrl-S write

Not asciinema. Live.

For agents

A program reaches the network only through the proxy: https only, port 443, host names, not IP literals. A response is at most 1 MiB, the exchange at most 2 seconds, and at most 3 redirects. An anonymous session's list is the box's, today example.com, and allow in the request is ignored. POST /v1/session answers with "allow", the list that session got. A session of your own hosts needs a key: Authorization: Bearer <secret> and {"allow":["api.example.org"]}, at most 16 hosts. A wrong key is 401. More than 16 hosts is 400. A refusal names its rule: proxy: host not allowed (not on the list, before DNS), proxy: address refused (the name is metadata, or a DNS answer is not a public address; nothing is dialed), proxy: scheme not allowed (not https), proxy: bad request (an IP literal, or a malformed URL), proxy: too many redirects, proxy: timeout, proxy: too large, proxy: budget exhausted, proxy: unavailable, proxy: no egress (this session has no list).

SID=$(curl -sS -X POST "$ORIGIN/v1/session" | python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')
# the answer includes "allow": ["example.com"]
curl -sS "$ORIGIN/v1/fs" -H 'Content-Type: application/json' \
  -d '{"session":"'"$SID"'","op":"W","path":"get.go","data":"package main\nimport \"io\"\nimport \"net/http\"\nfunc main() {\n\tresp, err := http.Get(\"https://example.com/\")\n\tif err != nil { println(err.Error()); return }\n\tb, _ := io.ReadAll(resp.Body)\n\tresp.Body.Close()\n\tprintln(resp.Status)\n\tprintln(string(b))\n}\n"}'
curl -sS "$ORIGIN/v1/exec" -H 'Content-Type: application/json' \
  -d '{"session":"'"$SID"'","line":"go run get.go"}'