Architecture

Two planes, one operator.

The command plane controls live sessions. The context plane keeps what happened. Both run on hardware you control.

Where Drover fits

Six layers. Drover is the middle three.

Hover or tap a layer to see its contents and status.

MCPHTTP API
Adapters

Interaction

Shipped

Where you make the next decision: the phone, a chat or a terminal.

  • Drover iOS app (source build, beta)Shipped
  • Drover web cockpitShipped
  • Chat through an orchestratorYou bring it
  • Terminal, also from the appShipped

Orchestration

You bring it

Agents that plan work and delegate it. They use Drover through MCP and the HTTP API.

  • OpenClawYou bring it
  • HermesYou bring it
  • Any other agent, script or CI jobYou bring it

Continuity

In progress

Keeps work alive across restarts, hosts and harnesses. Partly shipped. This is the direction of the project.

  • Session identity across restarts and hostsShipped
  • Handoff between harnessesShipped
  • Wake-ups and status back to the orchestratorIn progress
  • Goal-level progressRoadmap

Context

Shipped

The durable record of each session, and the tools that return it to the next session.

  • Event historyShipped
  • Recall and searchShipped
  • Session summaries (opt-in)Shipped
  • Handoff and project briefsShipped
  • Portable profile with privacy tiersShipped

Execution

Shipped

The hub routes each operation. A daemon on each host owns the sessions, processes and files.

  • Hub routing to direct and relay hostsShipped
  • Sessions and worktrees on the host daemonShipped
  • Approvals (Claude Code today) and interruptsShipped
  • A structured adapter for each harness, and a terminalShipped

Harnesses and compute

You bring it

Each native harness keeps its own models, sign-in, tools and sandbox. It runs on a machine you own.

  • Claude CodeYou bring it
  • CodexYou bring it
  • AntigravityYou bring it
  • DeepSeek HarnessYou bring it
  • More as adapters are addedRoadmap

Capacity and governance

In progress

The limits and rules across the stack: remaining quota, cost, credentials and data location.

  • Provider quota windowsShipped
  • Measured cost vs subscription usageShipped
  • Credentials and scopesShipped
  • Privacy and data residencyShipped
  • AuditRoadmap
Inside Drover

Command plane above, context plane below.

Drover architectureTwo planes inside one trusted operator boundary. In the command plane, operator clients (the iOS app, the web cockpit and CLI, and orchestrators) call drover-server over the /harness API. The server routes operations to drover-harnessd on each host, directly or over an outbound relay, and the host daemon owns the agent processes. In the context plane, events from harness sessions and collectors enter a single ingest path that writes to the PostgreSQL control store with a transactional outbox. A fenced exporter publishes facts to DuckLake. Reads run in a disposable query child that checks a serving proof, and feed summaries, the MCP server, the cockpit and the iOS app.Single trusted operator boundarylocalhost / private LAN / Tailscale onlyNo public-internet exposureDevice + host credentials · no RBAC or tenantsCOMMAND PLANE · LIVE CONTROLInteractive session control, routing, streaming events and terminal I/OCONTEXT PLANE · DURABLE MEMORYcapture · normalize · export · verify · derive · recall/harness:7081dial-outoperational stateagent eventsOperator clientsiOS appWeb cockpit / CLIOrchestratorsOpenClaw, Hermes, your scriptsdrover-serverCENTRAL MACHINEFleet API:7080HTTP + WebSocketControl storePostgreSQL · fleet stateCommand coordinatorRoutes operations; never executes remote commands itselfOne hub. It knows the fleet and routes intent.Harness hosts1..N MACHINESdrover-harnessd:7081sessions · adapters · PTY · terminal streamDirect hostprivate inboundRelay hostoutbound dialClaude Code · Codex · Antigravity · DeepSeek HarnessActivity sourcesharness sessionsdrover-collect + hooksOpenClaw + Hermesoptional OTLP spansSingle ingest pathnormalize identifiersattribute repositorydeduplicate recordsevent + preview +outbox, atomicallyControl storePostgreSQL authorityfleet · sessions · payloadstransactional outboxderived-memory jobsportable profileLake exporterone fenced ownerfrozen batchesimmutable receiptsack after commitDuckLakePostgreSQL catalogParquet data filesappend-only factssnapshot historyQuery childdisposable process5 s deadlinememory-cappedserving proof +epoch, or refuseDerive + retrievesummaries, briefs,embeddingsMCP /mcp :7077cockpit · iOS appcoding agentsConsistencyControl reads: PostgreSQL, read-your-writesLake reads: eventually consistent, exported in batchesVerified selection only; proof failure refuses the readlive control / routingcontext flowasync / derivedPostgreSQL serves control. DuckLake serves verified analytical reads.

On a small screen, scroll the diagram sideways.

Data flow

Follow one turn.

  1. 1

    You send a turn

    The hub finds the session and forwards the turn to its host.

  2. 2

    The host does the work

    The host daemon passes the turn to the agent through a harness adapter.

  3. 3

    The hub writes each event once

    One transaction records the event, its payload, a preview and an outbox entry.

  4. 4

    An exporter publishes facts

    With DuckLake selected, one fenced exporter publishes batches with a receipt.

  5. 5

    Workers derive memory

    With a model backend, workers write summaries, briefs and embeddings.

  6. 6

    Reads verify or refuse

    A query child checks the serving proof. It returns a verified result or "unavailable".

Components

What each component owns.

ComponentRuns onOwns
iOS, web and CLI clientsYour devicesPresentation and authenticated requests
drover-server (hub)One central machineFleet API, pairing, relay, ingest, exporter, MCP
drover-harnessd (host daemon)Each hostAgent processes, adapters, terminals, a local spool
drover-collect and hooksSource hostsParsing of agent logs
PostgreSQL control storeCentral storageFleet state, payloads, outbox, derived memory, profile
DuckLake catalog and Parquet filesAnalytical storageEvent facts, export receipts, snapshot history
Query childCentral machineOne bounded, verified analytical read

Listeners

InterfaceDefault portProtocolAuthentication
Fleet API and web cockpit7080HTTP and WebSocketBearer credential or session cookie
Host daemon7081HTTP and WebSocketBearer credential
MCP7077Streamable HTTP at /mcpBearer credential. Loopback only.
OTLP (optional, off by default)4317gRPCLoopback by default

Each central listener binds to localhost by default.

Storage

Two stores, two jobs.

PostgreSQL control store

The authority for operational state: hosts, sessions, credentials, events, the outbox, summaries and the profile.

Use your own PostgreSQL, or let the installer manage a local PostgreSQL 17 container.

DuckLake lake

Append-only facts for analytics. A lake is a PostgreSQL catalog and Parquet data files.

You select DuckLake explicitly. A failed read does not fall back to older history.

DuckDB

Each host keeps a local DuckDB spool. DuckDB is also a compatibility control store for existing single-machine installs.

Backups

A complete backup is the control store, the DuckLake catalog and each data file the catalog references. Roadmap Automated off-site backup is not shipped.

Privacy model

Your data stays on your machines.

Self-hosted

There is no Drover cloud and no Drover account.

Private networks

Use localhost, a private LAN or a private Tailscale network. Do not expose Drover to the internet.

One trust domain

Drover has no user accounts or roles. It does not sandbox what an agent runs.

Read Security and privacy. For full detail, see docs/architecture.md and the threat model.