No description
This repository has been archived on 2026-09-24. You can view files and clone it, but you cannot make any changes to its state, such as pushing and creating new issues, pull requests or comments.
  • Go 94.3%
  • Go Template 2%
  • JavaScript 1.4%
  • Shell 1.3%
  • Python 0.8%
  • Other 0.2%
Find a file
Ryan Grippeling 84df41b0fe chore(renovate): extend het org-preset op een gepinde versie
Het preset gaat zelf van een gepinde verwijzing uit: default.json draagt een
soak-uitzondering voor preset-updates (die alleen bestaat als er een versie te
bumpen valt) en een pinDigests: false waarvan de beschrijving zegt dat de
verwijzing 'is already pinned to a protected semver release tag'.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 08:04:52 +02:00
.forgejo/workflows fix(ci): stop the licence gate depending on a network tool install 2026-09-11 16:24:08 +02:00
.openhands/skills/team-silver docs(skills): team-silver gates run in CI — the dispatched harness is daemonless 2026-08-28 06:30:23 +02:00
cmd feat(control-plane)!: unify managed execution and verified delivery 2026-09-11 06:27:41 +02:00
docs docs(release): drop the 1.x candidate from the record 2026-09-11 14:37:56 +02:00
internal/ledger docs: make docs/adrs the only ledger, and gate it in go test 2026-07-29 10:26:59 +02:00
LICENSES chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
openspec docs(release): record corrected prerelease publication 2026-09-11 07:13:08 +02:00
ops chore(release): v0.3.0-rc.7 [skip ci] 2026-09-11 14:34:55 +00:00
pkg feat(control-plane)!: unify managed execution and verified delivery 2026-09-11 06:27:41 +02:00
scripts fix(ci): stop the licence gate depending on a network tool install 2026-09-11 16:24:08 +02:00
.gitignore feat: run forensics survive pod/job cleanup — node+pod identity in logs+checkpoints, failure-reason taxonomy, VIK-586 fix 2026-07-28 17:24:21 +00:00
.mailmap chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
.releaserc.cjs fix(release): keep experimental Ploeg releases on zero major 2026-09-11 07:06:20 +02:00
AGENTS.md docs(agents): adopt the estate no-comments rule 2026-09-04 19:17:30 +02:00
CHANGELOG.md chore(release): v0.3.0-rc.7 [skip ci] 2026-09-11 14:34:55 +00:00
CLAUDE.md docs(agents): add CLAUDE.md as a symlink to AGENTS.md 2026-09-01 09:49:52 +02:00
CONTRIBUTING.md chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
go.mod fix(deps): clear the nine CVEs Harbor flags on the ploegd image 2026-08-25 07:09:53 +02:00
go.sum fix(deps): clear the nine CVEs Harbor flags on the ploegd image 2026-08-25 07:09:53 +02:00
LICENSE chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
mise.toml chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
NOTICE chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
package.json chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00
README.md feat(control-plane)!: unify managed execution and verified delivery 2026-09-11 06:27:41 +02:00
renovate.json chore(renovate): extend het org-preset op een gepinde versie 2026-09-22 08:04:52 +02:00
REUSE.toml chore(licence): name the copyright holder and hold Apache-2.0 in CI 2026-09-11 16:00:19 +02:00

Ploeg

Assign a ticket on your own board and Ploeg spins up an ephemeral team of AI agents on your Kubernetes cluster that works it, opens a pull request, reports the outcome, and disappears — every run leased, audited, and crash-safe, with no lock-in on tracker, forge, or agent harness.

An open-source, self-hostable dispatch plane. Bring your own board, forge, and agent harness.

Ploeg is Dutch for a work crew or shift. Teams of specialist agents pick up a ticket, work it, report an outcome, and disappear.

Status: pre-alpha. Ploeg is being extracted from a running autonomous-agent setup (a "dark factory": agents working a ticket board unattended on a homelab Kubernetes cluster). The dispatch core and both executors (KEDA ScaledJob and a KEDA-free CronJob) ship in the chart — opt-in via executor.enabled — and dispatch the originating factory today; a local prototype runs the same core over Docker Compose (see below). Provider write-backs, a Forgejo forge provider, and team manifests are still to come. Watch, don't install.

Human workbench integration

De Vloer is the human surface for Ploeg. The authenticated operator API exposes scoped work, runs, evidence and spending snapshots. An opt-in manual execution path admits a workbench session as one Work Item, Shift and operator Run, with durable commands and explicit pause, cancellation and supervision. Existing unattended executors continue alongside that delegated path.

Management credentials remain in the controller; workers use scoped control and inference capabilities. Operational configuration and recovery distinguish unresolved spending from final accounting. The real cross-service test exercises Ploeg, PostgreSQL and De Vloer together without model calls. The implementation remains pre-alpha; live gateway/cluster qualification and canonical tracker-to-workbench handoff are separate gates.

What Ploeg is

  • A dispatch plane, not a board. Your tracker (Vikunja, Jira, GitHub Issues, …) stays the source of truth for what to do. Ploeg owns how work gets executed: assignment events in, ephemeral agent runs out.
  • Event-driven, never polling. Assigning a ticket fires a webhook; Ploeg spawns a Kubernetes Job for it. No heartbeat crons burning tokens to discover there is no work.
  • Ephemeral by design. Every run is a Job that starts, produces a structured outcome, and dies. Durable state lives in Postgres (work items, leases, checkpoints, outcomes, audit) and in git (branches, PRs) — never in a long-lived agent process.
  • Leased, not labeled. Claims are rows with a TTL renewed by the running Job. A crashed pod releases its ticket mechanically; nothing depends on an agent behaving well at death.
  • Teams of specialists. A work item is claimed by a team — a declarative manifest of specialist roles (implementer, reviewer on a different model family, tester) — not by a single agent identity.
  • Audited end to end. Every mutation, lease, run, and outcome is a Postgres row. Grafana dashboards ship as code.

What Ploeg is not

  • Not another kanban UI. The market has plenty; Ploeg has none.
  • Not a persistent-agent platform (see kagent) or model serving.
  • Not a promise of every integration. Ploeg ships a small, stable provider SPI and two reference providers (Vikunja tracker, Forgejo forge). Further providers are community-owned.

Architecture (v0 sketch)

tracker webhook ─┐                        ┌─> KEDA ScaledJob (per team) ─> agent Job (ephemeral)
forge webhook  ──┼─> ploegd ─> Postgres ──┤        │ lease renewal · checkpoints
                 │   (ingest,  (work items,        └─> outcome report ─> ploegd ─> tracker/forge writeback
                 │    SPI)      leases, runs,
                 └─────────────  audit)  ──────> Grafana (dashboards as code)
  • ploegd — single Go binary: webhook ingest, provider SPI, lease manager, outcome ingestion.
  • Executor — KEDA ScaledJob with the Postgres scaler is the flagship default; executors are pluggable behind the run-API contract (docs/contracts/executor.md) — a KEDA-free CronJob executor ships in the same chart (executor.type).
  • Harness contract — an agent container receives a TaskSpec, must emit an OutcomeReport (schemas). Harness adapters live behind pkg/harness.Adapter: openhands (default), exec (any binary), claude-code — selected per team, along with the agent image, via the team's harness block.

Try the prototype

docker compose -f ops/local/docker-compose.yml up -d --build
ops/local/demo.sh

The demo plays both tracker and agent: a signed Vikunja webhook queues a work item, a claim leases it (FOR UPDATE SKIP LOCKED + TTL lease), checkpoint and outcome complete it, and the audit trail records every step as a Postgres row. Crash-safety is real: claim an item, report nothing, and the sweeper releases the lease and re-queues the item when the TTL expires.

Roadmap

  1. Extraction — core service, Vikunja + Forgejo providers, one harness adapter, audit + dashboards. Exit criterion: the originating dark factory runs on Ploeg in production.
  2. Teams & follow-ups — team manifests, checkpoint/resume, PR-feedback ingestion routed to the owning team, a dry-run grooming worker.
  3. On demonstrated pull — GitHub provider, CRD/operator graduation, agent-sandbox runtimes, further providers by contribution.

License

Code: Apache-2.0.

The name Ploeg and the Ploeg mark are trademarks — §6 of that licence grants no rights in them, deliberately. docs/brand/TRADEMARK.md says what you may do with them without asking (reproduce them, link, say your software works with Ploeg) and the two things that need permission (shipping a fork under the name, implying endorsement). Settled in ADR-0022.