JavaScript authoring. Durable execution.
Switchyard workflows look like ordinary JavaScript orchestration, but durability belongs to recorded Switchyard operations rather than the lifetime of a Node/JS process.
The authoring model
A workflow defines run(ctx). Normal local computation can happen between operations. Calls on ctx are the durable boundaries that Switchyard records and can replay.
function run(ctx) {
const implementation = ctx.agent({
repo: ctx.params.repo,
branch: ctx.params.branch,
file: "src/router.go",
append: "// bounded implementation step"
});
const check = ctx.check({ repo: ctx.params.repo, branch: ctx.params.branch });
const review = ctx.review({ repo: ctx.params.repo, branch: ctx.params.branch });
if (!review.approved) {
ctx.wait_approval({ reason: "review requires direction" });
}
return { implementation, check, review };
}
Durable operations
| Operation | Purpose | Durability implication |
|---|---|---|
ctx.agent(...) | Run a role-scoped executor against isolated repository state. | Execution/result are recorded so a completed Agent effect is not repeated after replay. |
ctx.check(...) | Run deterministic validation. | Result becomes a reusable durable step. |
ctx.review(...) | Produce structured review state/findings. | Findings remain attached to the engineering history. |
ctx.parallel(...) | Express independent durable branches. | Each child operation keeps an explicit durable identity. |
ctx.wait_approval(...) | Pause for policy/human direction. | The run can remain waiting across process restarts. |
ctx.integrate(...) | Request canonical integration. | Still subject to queue freshness/policy rather than direct Agent canonical writes. |
Replay-from-top, not serialized JavaScript stacks
step identity = (run_id, step_key, op, args_hash)
process restarts
└─ workflow function starts again
├─ completed step → return recorded result
├─ in-flight step → bounded retry
└─ new step → record intent, execute, record result
Switchyard deliberately does not attempt to serialize arbitrary JS closures or VM stack frames. Durability is explicit at Switchyard operations, which keeps the execution model inspectable and testable.
What the crash gate proved
During CP7 the control plane was killed during a running durable workflow and restarted. The already-completed Agent step replayed its recorded result instead of creating another repository effect; the in-flight sleep retried; later Agent/check steps executed once. Earlier false-positive crash tests were rejected before this final gate, which is useful evidence that the final claim is real rather than ceremonial.
Governance and bounds
- Step budgets cap how much a workflow may execute.
- Child spawning/recursion is bounded rather than allowing an unbounded Agent tree.
- Cancellation is durable state, not merely killing one process.
- Organisation policy can constrain workflow budgets and Agent file access.
- Human approval is a policy option, not a universal mandatory bottleneck.