[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:zh":3,"public-menus:all":38,"post:managed-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose:zh":205,"related:post:managed-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose:zh:1":1774},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","zh","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":1773},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":872,"featuredImage":873,"featuredImageAlt":874,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":875,"publishedAt":876,"createdAt":877,"updatedAt":878,"seoLocalePaths":879,"categories":888,"author":901,"translations":906},"475","托管代理框架与自托管代理循环：你得到什么，失去什么","managed-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"目录\">\u003Cstrong class=\"editorjs-toc__title\">目录\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-6\" class=\"editorjs-toc__link\">错误：把自托管当作一个单一决策\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-10\" class=\"editorjs-toc__link\">三种常被称为“自托管”的架构\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-12\" class=\"editorjs-toc__link\">双平面模型\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-15\" class=\"editorjs-toc__link\">托管式执行框架：你实际获得了什么\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-19\" class=\"editorjs-toc__link\">托管式执行框架：你需要放弃什么\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-23\" class=\"editorjs-toc__link\">自托管执行环境：中间架构\u003C\u002Fa>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-1\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-27\" class=\"editorjs-toc__link\">何时自托管执行就足够了\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-29\" class=\"editorjs-toc__link\">何时你可能也需要拥有执行框架\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-33\" class=\"editorjs-toc__link\">控制升级测试\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-36\" class=\"editorjs-toc__link\">当你拥有执行框架时，运维负担会非线性增长\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-40\" class=\"editorjs-toc__link\">安全边界：自托管计算不会自动使代理私有\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-44\" class=\"editorjs-toc__link\">延迟和成本：控制可以移动瓶颈，而不是消除瓶颈\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-47\" class=\"editorjs-toc__link\">生产决策矩阵\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-49\" class=\"editorjs-toc__link\">混合不是妥协——它通常是清晰的架构\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-53\" class=\"editorjs-toc__link\">什么会改变这个答案？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-56\" class=\"editorjs-toc__link\">局限性\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-59\" class=\"editorjs-toc__link\">结论\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-62\" class=\"editorjs-toc__link\">常见问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-64\" class=\"editorjs-toc__link\">术语表\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-66\" class=\"editorjs-toc__link\">主要来源与延伸阅读\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Cp>“自托管代理”这个说法如今至少隐藏了三种不同的架构。你可以使用由 OpenAI 托管计算资源的托管式执行框架，也可以使用连接到你自己运营的基础设施的托管式执行框架，或者自行运行执行框架和代理循环。这些选择在控制权、恢复能力、上下文管理、安全性、延迟和运维负担方面有着截然不同的影响。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">直接回答\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">&lt;strong&gt;不要把“托管”和“自托管”当作一个二选一的决定来对待。&lt;\u002Fstrong&gt; 将&lt;strong&gt;执行框架平面&lt;\u002Fstrong&gt;与&lt;strong&gt;执行平面&lt;\u002Fstrong&gt;分开考虑。托管式执行框架仍然可以使用自托管计算资源。自托管环境让你能够控制文件、软件包、网络访问和执行，而无需自己拥有代理循环。只有当你需要控制编排、生命周期、模型路由假设或托管式执行框架无法暴露的运行时行为时，才需要自行运行执行框架。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">截至 2026 年 9 月 25 日\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">OpenAI 的 Agents API 处于公开测试阶段，其架构可能会演变。当前文档将 OpenAI 托管的 Codex 执行框架与执行环境分开，并明确支持自托管环境。OpenAI 还通过 Codex SDK 单独暴露 Codex 执行框架，供你运营的基础设施使用。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">本文使用的模型\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">下文中的执行框架平面\u002F执行平面模型和控制升级测试是本文提出的实用架构工具。它们并非正式的厂商术语。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-6\">错误：把自托管当作一个单一决策\u003C\u002Fh2>\n\u003Cp>在传统软件中，“自托管”通常意味着应用程序运行在你控制的基础设施上。代理系统使这个定义变得复杂，因为运行时可以被拆分。模型与工具的循环可以在一个地方运行，而代码执行、文件和私有网络访问则在另一个地方进行。\u003C\u002Fp>\n\u003Cp>OpenAI 当前的 Agents API 架构明确体现了这种拆分：OpenAI 运行执行框架，而执行环境可以不存在、由 OpenAI 托管或自托管。因此，自托管环境并不意味着代理循环是自托管的。\u003C\u002Fp>\n\u003Cp>这种区分很重要，因为许多团队选择了比实际需要更复杂的运行时。他们想要私有网络访问或自定义软件包，于是断定整个代理都必须自托管，结果意外地承担了本可以保持托管的上下文管理、编排、恢复和生命周期管理。\u003C\u002Fp>\n\u003Ch2 id=\"section-10\">三种常被称为“自托管”的架构\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">架构\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">谁运行执行框架？\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">代码\u002F文件在哪里执行\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">你主要拥有什么\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">托管式执行框架 + 托管式环境\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台托管的沙箱\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用程序、工具、产品逻辑、授权\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">托管式执行框架 + 自托管环境\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你的容器、虚拟机、笔记本电脑、私有云或其他计算资源\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">环境配置、网络、文件和生命周期；平台仍然拥有执行框架\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自行运营的执行框架\u002F代理循环\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你选择的环境\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架进程、编排、上下文策略、托管、恢复、执行和应用程序生命周期\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-12\">双平面模型\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">将执行框架平面与执行平面分开\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">平面\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">它拥有什么\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">需要问的问题\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">执行框架平面\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">执行平面\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">应用平面\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">关键架构结论\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">你可以自托管&lt;strong&gt;执行平面&lt;\u002Fstrong&gt;而不自托管&lt;strong&gt;执行框架平面&lt;\u002Fstrong&gt;。这通常是最合适的中间方案。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-15\">托管式执行框架：你实际获得了什么\u003C\u002Fh2>\n\u003Cp>托管式执行框架消除的不仅仅是一个 while 循环。OpenAI 当前的 Agents API 管理会话、编排、上下文压缩和恢复。Anthropic 在托管代理方面的工作描述了同样的更广泛动机：执行框架包含关于模型行为的假设，而这些假设需要随着模型的改进而演变。\u003C\u002Fp>\n\u003Cp>这意味着好处不仅仅是更少的代码行数。平台可以更新运行时行为、长周期上下文处理、子代理协调和恢复，而无需每个应用团队重新构建这些机制。\u003C\u002Fp>\n\u003Cul>\u003Cli>更少的应用自有编排代码。\u003C\u002Fli>\u003Cli>托管的持久会话行为。\u003C\u002Fli>\u003Cli>托管的上下文压缩和恢复。\u003C\u002Fli>\u003Cli>能够随模型能力演变的运行时。\u003C\u002Fli>\u003Cli>更简单地采用平台原生的子代理和长时间运行代理功能。\u003C\u002Fli>\u003Cli>对于差异化不在于执行框架本身的团队，可能降低运维负担。\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2 id=\"section-19\">托管式执行框架：你需要放弃什么\u003C\u002Fh2>\n\u003Cp>将执行框架委托出去，也意味着委托出部分控制权。你的应用不再拥有迭代、上下文策略、编排和运行时演进的每一个细节。平台更新可以改进系统，但也可能改变你的产品隐式依赖的行为。\u003C\u002Fp>\n\u003Cp>这带来了一种不同的工程需求：强大的评估、明确的产品边界，以及一个集成层，防止托管会话行为成为你的业务事实来源。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">托管式执行框架的权衡\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">在运维层面意味着什么\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">更少的循环控制\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你不能假设每个编排细节都由应用定义\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台演进\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架行为可能在你的代码不变的情况下改进或改变\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">供应商特定的生命周期\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">会话、事件和恢复语义成为集成接口的一部分\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性边界\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台追踪必须与应用审计数据关联\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可移植性成本\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">以后迁移到另一个执行框架可能不仅仅是更换模型端点\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-23\">自托管执行环境：中间架构\u003C\u002Fh2>\n\u003Cp>OpenAI 的自托管环境模型很重要，因为它将私有计算与执行框架所有权解耦。平台仍然运行 Codex 执行框架，而执行器在你的环境中运行，并通过出站连接接收命令。\u003C\u002Fp>\n\u003Cp>你控制资源调配、文件、依赖、网络访问和清理。因此，执行框架可以针对私有基础设施或自定义软件工作，而无需将整个代理运行时迁移到你的应用中。\u003C\u002Fp>\n\u003Cp>代价是生命周期责任。你的应用必须将会话映射到计算资源，避免重复调配，重新连接环境，协调关闭，并保留任何必须比环境存活更久的文件。\u003C\u002Fp>\n\u003Ch3 id=\"section-27\">何时自托管执行就足够了\u003C\u002Fh3>\n\u003Cul>\u003Cli>代理需要访问私有 VPC 或内部服务。\u003C\u002Fli>\u003Cli>代理需要自定义二进制文件、软件包、驱动程序或系统软件。\u003C\u002Fli>\u003Cli>工作负载必须在你控制的硬件或云账户上运行。\u003C\u002Fli>\u003Cli>文件必须保留在受控环境中。\u003C\u002Fli>\u003Cli>你需要自己的沙箱提供商或隔离模型。\u003C\u002Fli>\u003Cli>你想要平台管理的编排，但由基础设施控制的执行。\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2 id=\"section-29\">何时你可能也需要拥有执行框架\u003C\u002Fh2>\n\u003Cp>当执行框架本身成为产品差异化或约束集的一部分时，拥有执行框架就变得合理。OpenAI 当前的运行时概览将 Codex SDK 定位为在你运营的基础设施中运行 Codex 执行框架，而当你想要自己拥有代理循环时，Responses 是更低层级的选择。\u003C\u002Fp>\n\u003Cp>关键在于识别一个真正存在于执行框架层面而非执行层面的需求。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">需求\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">执行层面问题还是执行框架层面问题？\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">可能的方向\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">私有数据库访问\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">托管式执行框架 + 自托管环境可能就足够了\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自定义 Linux 软件包\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">托管式执行框架 + 自托管环境\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自定义 GPU 硬件\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在支持的情况下使用托管式执行框架 + 自托管环境\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自定义代理停止逻辑\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自行运营的执行框架 \u002F 自定义循环\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">每一步都进行跨提供商模型路由\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自定义循环或你运营的执行框架\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自定义上下文压缩算法\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如果托管运行时无法暴露该能力，则自行运营执行框架\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">产品所需的确定性编排语义\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自行运营的执行框架或严格控制的自定义循环\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">仅本地部署且不依赖托管式执行框架的产品\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行框架层面 + 执行层面\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自行运营的运行时\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-33\">控制升级测试\u003C\u002Fh2>\n\u003Cp>使用满足实际需求的最少自托管架构。一次只升级一层控制。\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">控制升级测试\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 从应用边界开始\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">无论代理运行时如何，都将领域事实、授权和重要业务操作保留在你自己的产品中。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 询问代理是否需要本地执行\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">如果不需要，那么没有专用环境的托管式执行框架可能就足够了。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 询问平台托管的计算是否可接受\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">如果可以，使用托管环境，避免不必要的基础设施所有权。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 如果不行，自托管执行层面\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">连接你自己的环境，以满足私有网络、文件、软件包或受控计算的需求。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 重新评估剩余约束\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">如果需求现在已满足，就停止。不要仅仅为了架构对称而自托管执行框架。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 仅针对执行框架需求升级到执行框架所有权\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">当编排、上下文策略、生命周期或可移植性确实需要时，才拥有 Codex 执行框架或自定义代理循环。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 证明额外控制值得额外运维\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在承诺之前，对可靠性、延迟、成本、恢复、可观测性和工程负担进行基准测试。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-36\">当你拥有执行框架时，运维负担会非线性增长\u003C\u002Fh2>\n\u003Cp>自运营循环在演示中听起来很简单：调用模型、检查工具调用、执行工具、追加结果、重复。生产环境增加了持久状态、重试、重复事件、取消、审批、上下文溢出、工具超时、进程重启、跟踪持久化、背压、并发工作和部分副作用后的恢复。\u003C\u002Fp>\n\u003Cp>Anthropic 的长期运行代理研究反复表明，框架设计对性能有实质性影响。他们在长期运行应用程序开发方面的工作使用显式规划、结构化产物和评估代理，因为朴素循环往往会丢失进度或过早终止。因此，框架是生产逻辑，而不是管道。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">如果你拥有框架，你还需要回答\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">为什么重要\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">持久会话状态\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">进程会重启；长期运行的工作必须正确恢复\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">上下文压缩\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">历史最终会超出实际工作上下文\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具幂等性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">重试不得重复不可逆的副作用\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">取消和中断\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">用户和系统需要停止或重定向工作\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">部分执行后的恢复\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">即使代理从未收到结果，工具也可能成功\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">并发\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">多个任务、工作者或代理可能触及共享状态\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最终输出不足以调试运行时故障\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">版本控制\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">即使提示保持不变，框架更新也可能改变行为\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">评估\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行时变更需要在代表性轨迹上进行回归测试\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-40\">安全边界：自托管计算不会自动使代理私有\u003C\u002Fh2>\n\u003Cp>自托管执行环境控制命令运行的位置和文件所在的位置，但托管框架和模型交互仍然跨越服务边界。因此，团队应明确映射数据流，而不是将“自托管”用作隐私属性的简写。\u003C\u002Fp>\n\u003Cp>OpenAI 的自托管执行器使用受限的环境凭据和出站连接。这是有用的隔离，但你的应用程序仍然需要自己的规则来处理机密、私有网络暴露、用户到环境的隔离、文件保留、工具授权和数据分类。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">重要区别\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">&lt;strong&gt;基础设施控制、执行隔离和数据治理边界相关但不相同。&lt;\u002Fstrong&gt;请分别决定它们。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-44\">延迟和成本：控制可以移动瓶颈，而不是消除瓶颈\u003C\u002Fh2>\n\u003Cp>自托管可能会减少一些数据路径或环境启动成本，但也可能增加配置时间、WebSocket 生命周期、冷启动、沙箱清理、可观测性基础设施和工程开销。托管环境可能每单位计算成本更高，但在低量或不规则量下运营成本更低。\u003C\u002Fp>\n\u003Cp>正确的比较是总系统成本：模型和工具使用、环境时间、基础设施、工程努力、待命负担、故障恢复以及较慢迭代的成本。\u003C\u002Fp>\n\u003Ch2 id=\"section-47\">生产决策矩阵\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">约束\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">托管框架 + 托管环境\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">托管框架 + 自托管环境\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">自运营框架 \u002F 循环\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最快进入生产\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">强\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">中等\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最弱\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">私有网络执行\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">弱 \u002F 取决于连接设计\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">强\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">强\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自定义包 \u002F 系统软件\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">中等\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">强\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">强\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">框架级控制\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">低\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">低\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最高\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运营负担\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最低\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">中等\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最高\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可移植性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最低\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">中等\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如果有意设计，可能最高\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">上下文策略控制\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台管理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台管理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用程序控制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">执行基础设施控制\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">低\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">高\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">高\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">从托管框架更新中受益的能力\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最高\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最高\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你负责采用\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最适合\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在产品\u002F工具层差异化的团队\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要私有\u002F自定义计算而不拥有编排的团队\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行时语义本身就是需求的团队\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-49\">混合不是妥协——它通常是清晰的架构\u003C\u002Fh2>\n\u003Cp>托管框架与自托管执行不是“半自托管”。这是有意的关注点分离。平台拥有长周期代理运行时的复杂性，而你的基础设施拥有执行、私有连接和文件。\u003C\u002Fp>\n\u003Cp>该边界类似于其他云架构：托管控制平面，客户控制的数据或执行平面。重要的设计工作是定义它们之间的契约——会话身份、环境身份、凭据、文件、工具权限、生命周期事件和清理。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fopenai-agents-api-vs-agents-sdk-vs-responses-api-what-should-you-build-on-in-2026\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">OpenAI Agents API vs Agents SDK vs Responses API：2026 年你应该构建在什么之上？\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">对 OpenAI 当前代理界面的运行时所有权比较，以及每个控制边界应归属何处。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读运行时比较 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-53\">什么会改变这个答案？\u003C\u002Fh2>\n\u003Cp>如果托管框架暴露更多的运行时控制，如果自托管框架获得更简单的持久会话和恢复原语，或者如果法规要求整个代理循环和模型交互保持在你运营的基础设施内，那么建议会改变。\u003C\u002Fp>\n\u003Cp>它也会随着模型能力的变化而变化。Anthropic 明确指出，随着模型改进，harness 假设可能会过时。今天必不可少的控制机制，以后可能变得不再必要，而新的模型能力则可能产生新的治理要求。\u003C\u002Fp>\n\u003Ch2 id=\"section-56\">局限性\u003C\u002Fh2>\n\u003Cp>本文区分的是架构职责；它并不声称某一种托管模型普遍更安全、更便宜或更可靠。这些结果取决于实现、工作负载、合规要求、团队技能和提供商行为。\u003C\u002Fp>\n\u003Cp>OpenAI Agents API 仍处于公开测试阶段，不同供应商的托管代理产品暴露出不同的边界。双平面模型旨在帮助比较这些架构，而不假设每个供应商都使用相同的术语。\u003C\u002Fp>\n\u003Ch2 id=\"section-59\">结论\u003C\u002Fh2>\n\u003Cp>有用的问题不是“我们应该自托管代理吗？”而是：我们实际需要控制哪个平面？\u003C\u002Fp>\n\u003Cp>如果需求是私有计算、自定义包、本地文件或内部网络访问，就自托管执行平面，并保持 harness 托管。如果需求是编排语义、上下文策略、提供商控制或运行时生命周期本身，那么 harness 所有权可能是合理的。只按需求所要求的程度升级控制。\u003C\u002Fp>\n\u003Ch2 id=\"section-62\">常见问题\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">托管 harness 与自托管代理运行时\u003C\u002Fh3>\u003Cdiv id=\"faq1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">OpenAI Agents API 的自托管环境是自托管代理吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不完全是。OpenAI 仍然运行托管的 Codex harness，而你的基础设施运行用于命令、文件和本地工具的执行环境。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">什么时候自托管环境就足够了？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">当你的需求涉及私有网络访问、自定义包、受控文件、特定硬件或基础设施策略，而不是控制代理循环本身时，它通常就足够了。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">什么时候我应该自己运行 harness？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">当你需要自定义编排语义、自定义上下文管理、提供商路由、仅本地运行时行为，或其他位于代理循环而非执行环境中的需求时，可以考虑拥有 harness。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">自托管会自动提高安全性吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不会。它改变的是你控制哪些组件。安全性取决于所有组件之间的数据流、隔离、凭据、工具权限、网络、日志记录和生命周期设计。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">拥有代理循环的主要运营成本是什么？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">你需要负责持久状态、上下文管理、重试、取消、恢复、可观测性、并发、运行时升级以及 harness 变更的评估。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-64\">术语表\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">关键架构术语\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"harness-plane\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Harness 平面\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">负责循环执行、编排、上下文管理、会话连续性和恢复的代理运行时层。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"execution-plane\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">执行平面\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">运行命令、执行代码以及访问文件、包和本地资源的环境。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"managed-harness\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">托管 harness\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">其运行时、会话管理和编排由平台提供商运营的代理 harness。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"self-hosted-environment\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">自托管环境\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">由应用程序所有者运营的计算和文件，而单独的代理 harness 可能仍托管在其他地方。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"self-operated-harness\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">自运营 harness\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">其循环、托管、上下文策略和生命周期由应用程序团队运营的代理运行时。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"control-escalation-test\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">控制升级测试\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">一种决策方法，仅当需求无法在较低控制层满足时，才增加基础设施和运行时所有权。\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-66\">主要来源与延伸阅读\u003C\u002Fh2>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Farchitecture\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — Agents API 架构\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前托管 harness、执行环境和应用服务器之间的分离。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Fenvironments\u002Fself-hosted\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — 自托管沙箱\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">客户运营的执行环境如何连接到托管 harness，以及哪些生命周期职责仍由应用程序承担。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Fenvironments\u002Flifecycle\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — 沙箱生命周期\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">自托管计算的配置、重新连接、防止重复环境和清理职责。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — 代理运行时选项\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">按托管与应用程序运营职责对 Agents API、Codex SDK 和 Responses API 的当前比较。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fblog\u002Fcodex-as-a-platform\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — 作为平台的 Codex\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">面向希望获得更深运行时控制的应用程序的开源 Codex harness 和集成层。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fmanaged-agents\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Anthropic — 扩展托管代理：将大脑与手解耦\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">关于托管代理架构的讨论，以及为什么 harness 假设需要随模型能力而演进。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-harnesses-for-long-running-agents\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Anthropic — 面向长期运行智能体的高效执行框架\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">工程经验表明，长期运行智能体的性能在很大程度上取决于执行框架的设计与持久化工件。\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":871},1790365779029,[214,222,228,236,243,249,254,259,264,269,274,299,304,334,341,346,351,356,370,375,380,385,408,413,418,423,428,433,445,450,455,460,495,500,505,533,538,543,548,583,588,593,598,604,609,614,619,624,669,674,679,684,693,698,703,708,713,718,723,728,733,738,743,769,774,802,807,817,826,835,844,853,862],{"id":215,"data":216,"type":220,"tunes":221},"-PDI7SJcNl",{"title":217,"maxLevel":218,"minLevel":219},"目录",3,2,"tableOfContents",{},{"id":223,"data":224,"type":226,"tunes":227},"intro",{"text":225},"“自托管代理”这个说法如今至少隐藏了三种不同的架构。你可以使用由 OpenAI 托管计算资源的托管式执行框架，也可以使用连接到你自己运营的基础设施的托管式执行框架，或者自行运行执行框架和代理循环。这些选择在控制权、恢复能力、上下文管理、安全性、延迟和运维负担方面有着截然不同的影响。","paragraph",{},{"id":229,"data":230,"type":234,"tunes":235},"direct",{"body":231,"title":232,"variant":233},"\u003Cstrong>不要把“托管”和“自托管”当作一个二选一的决定来对待。\u003C\u002Fstrong> 将\u003Cstrong>执行框架平面\u003C\u002Fstrong>与\u003Cstrong>执行平面\u003C\u002Fstrong>分开考虑。托管式执行框架仍然可以使用自托管计算资源。自托管环境让你能够控制文件、软件包、网络访问和执行，而无需自己拥有代理循环。只有当你需要控制编排、生命周期、模型路由假设或托管式执行框架无法暴露的运行时行为时，才需要自行运行执行框架。","直接回答","info","callout",{},{"id":237,"data":238,"type":234,"tunes":242},"current",{"body":239,"title":240,"variant":241},"OpenAI 的 Agents API 处于公开测试阶段，其架构可能会演变。当前文档将 OpenAI 托管的 Codex 执行框架与执行环境分开，并明确支持自托管环境。OpenAI 还通过 Codex SDK 单独暴露 Codex 执行框架，供你运营的基础设施使用。","截至 2026 年 9 月 25 日","warning",{},{"id":244,"data":245,"type":234,"tunes":248},"note",{"body":246,"title":247,"variant":244},"下文中的执行框架平面\u002F执行平面模型和控制升级测试是本文提出的实用架构工具。它们并非正式的厂商术语。","本文使用的模型",{},{"id":250,"data":251,"type":42,"tunes":253},"h-mistake",{"text":252,"level":219},"错误：把自托管当作一个单一决策",{},{"id":255,"data":256,"type":226,"tunes":258},"p-mistake-1",{"text":257},"在传统软件中，“自托管”通常意味着应用程序运行在你控制的基础设施上。代理系统使这个定义变得复杂，因为运行时可以被拆分。模型与工具的循环可以在一个地方运行，而代码执行、文件和私有网络访问则在另一个地方进行。",{},{"id":260,"data":261,"type":226,"tunes":263},"p-mistake-2",{"text":262},"OpenAI 当前的 Agents API 架构明确体现了这种拆分：OpenAI 运行执行框架，而执行环境可以不存在、由 OpenAI 托管或自托管。因此，自托管环境并不意味着代理循环是自托管的。",{},{"id":265,"data":266,"type":226,"tunes":268},"p-mistake-3",{"text":267},"这种区分很重要，因为许多团队选择了比实际需要更复杂的运行时。他们想要私有网络访问或自定义软件包，于是断定整个代理都必须自托管，结果意外地承担了本可以保持托管的上下文管理、编排、恢复和生命周期管理。",{},{"id":270,"data":271,"type":42,"tunes":273},"h-three",{"text":272,"level":219},"三种常被称为“自托管”的架构",{},{"id":275,"data":276,"type":297,"tunes":298},"three-table",{"content":277,"stretched":43,"withHeadings":14},[278,283,288,292],[279,280,281,282],"架构","谁运行执行框架？","代码\u002F文件在哪里执行","你主要拥有什么",[284,285,286,287],"托管式执行框架 + 托管式环境","平台","平台托管的沙箱","应用程序、工具、产品逻辑、授权",[289,285,290,291],"托管式执行框架 + 自托管环境","你的容器、虚拟机、笔记本电脑、私有云或其他计算资源","环境配置、网络、文件和生命周期；平台仍然拥有执行框架",[293,294,295,296],"自行运营的执行框架\u002F代理循环","你","你选择的环境","执行框架进程、编排、上下文策略、托管、恢复、执行和应用程序生命周期","table",{},{"id":300,"data":301,"type":42,"tunes":303},"h-two-plane",{"text":302,"level":219},"双平面模型",{},{"id":305,"data":306,"type":332,"tunes":333},"plane-comparison",{"rows":307,"title":321,"layout":297,"columns":322},[308,313,317],{"id":309,"label":310,"values":311},"harness","执行框架平面",[312,312,312],"",{"id":314,"label":315,"values":316},"execution","执行平面",[312,312,312],{"id":318,"label":319,"values":320},"application","应用平面",[312,312,312],"将执行框架平面与执行平面分开",[323,326,329],{"id":324,"label":325},"plane","平面",{"id":327,"label":328},"owns","它拥有什么",{"id":330,"label":331},"questions","需要问的问题","comparison",{},{"id":335,"data":336,"type":234,"tunes":340},"key-consequence",{"body":337,"title":338,"variant":339},"你可以自托管\u003Cstrong>执行平面\u003C\u002Fstrong>而不自托管\u003Cstrong>执行框架平面\u003C\u002Fstrong>。这通常是最合适的中间方案。","关键架构结论","success",{},{"id":342,"data":343,"type":42,"tunes":345},"h-managed",{"text":344,"level":219},"托管式执行框架：你实际获得了什么",{},{"id":347,"data":348,"type":226,"tunes":350},"p-managed-1",{"text":349},"托管式执行框架消除的不仅仅是一个 while 循环。OpenAI 当前的 Agents API 管理会话、编排、上下文压缩和恢复。Anthropic 在托管代理方面的工作描述了同样的更广泛动机：执行框架包含关于模型行为的假设，而这些假设需要随着模型的改进而演变。",{},{"id":352,"data":353,"type":226,"tunes":355},"p-managed-2",{"text":354},"这意味着好处不仅仅是更少的代码行数。平台可以更新运行时行为、长周期上下文处理、子代理协调和恢复，而无需每个应用团队重新构建这些机制。",{},{"id":357,"data":358,"type":368,"tunes":369},"managed-list",{"meta":359,"items":360,"style":367},{},[361,362,363,364,365,366],"更少的应用自有编排代码。","托管的持久会话行为。","托管的上下文压缩和恢复。","能够随模型能力演变的运行时。","更简单地采用平台原生的子代理和长时间运行代理功能。","对于差异化不在于执行框架本身的团队，可能降低运维负担。","unordered","list",{},{"id":371,"data":372,"type":42,"tunes":374},"h-managed-cost",{"text":373,"level":219},"托管式执行框架：你需要放弃什么",{},{"id":376,"data":377,"type":226,"tunes":379},"p-managed-cost-1",{"text":378},"将执行框架委托出去，也意味着委托出部分控制权。你的应用不再拥有迭代、上下文策略、编排和运行时演进的每一个细节。平台更新可以改进系统，但也可能改变你的产品隐式依赖的行为。",{},{"id":381,"data":382,"type":226,"tunes":384},"p-managed-cost-2",{"text":383},"这带来了一种不同的工程需求：强大的评估、明确的产品边界，以及一个集成层，防止托管会话行为成为你的业务事实来源。",{},{"id":386,"data":387,"type":297,"tunes":407},"managed-cost-table",{"content":388,"stretched":43,"withHeadings":14},[389,392,395,398,401,404],[390,391],"托管式执行框架的权衡","在运维层面意味着什么",[393,394],"更少的循环控制","你不能假设每个编排细节都由应用定义",[396,397],"平台演进","执行框架行为可能在你的代码不变的情况下改进或改变",[399,400],"供应商特定的生命周期","会话、事件和恢复语义成为集成接口的一部分",[402,403],"可观测性边界","平台追踪必须与应用审计数据关联",[405,406],"可移植性成本","以后迁移到另一个执行框架可能不仅仅是更换模型端点",{},{"id":409,"data":410,"type":42,"tunes":412},"h-self-env",{"text":411,"level":219},"自托管执行环境：中间架构",{},{"id":414,"data":415,"type":226,"tunes":417},"p-self-env-1",{"text":416},"OpenAI 的自托管环境模型很重要，因为它将私有计算与执行框架所有权解耦。平台仍然运行 Codex 执行框架，而执行器在你的环境中运行，并通过出站连接接收命令。",{},{"id":419,"data":420,"type":226,"tunes":422},"p-self-env-2",{"text":421},"你控制资源调配、文件、依赖、网络访问和清理。因此，执行框架可以针对私有基础设施或自定义软件工作，而无需将整个代理运行时迁移到你的应用中。",{},{"id":424,"data":425,"type":226,"tunes":427},"p-self-env-3",{"text":426},"代价是生命周期责任。你的应用必须将会话映射到计算资源，避免重复调配，重新连接环境，协调关闭，并保留任何必须比环境存活更久的文件。",{},{"id":429,"data":430,"type":42,"tunes":432},"h-enough",{"text":431,"level":218},"何时自托管执行就足够了",{},{"id":434,"data":435,"type":368,"tunes":444},"enough-list",{"meta":436,"items":437,"style":367},{},[438,439,440,441,442,443],"代理需要访问私有 VPC 或内部服务。","代理需要自定义二进制文件、软件包、驱动程序或系统软件。","工作负载必须在你控制的硬件或云账户上运行。","文件必须保留在受控环境中。","你需要自己的沙箱提供商或隔离模型。","你想要平台管理的编排，但由基础设施控制的执行。",{},{"id":446,"data":447,"type":42,"tunes":449},"h-own-harness",{"text":448,"level":219},"何时你可能也需要拥有执行框架",{},{"id":451,"data":452,"type":226,"tunes":454},"p-own-1",{"text":453},"当执行框架本身成为产品差异化或约束集的一部分时，拥有执行框架就变得合理。OpenAI 当前的运行时概览将 Codex SDK 定位为在你运营的基础设施中运行 Codex 执行框架，而当你想要自己拥有代理循环时，Responses 是更低层级的选择。",{},{"id":456,"data":457,"type":226,"tunes":459},"p-own-2",{"text":458},"关键在于识别一个真正存在于执行框架层面而非执行层面的需求。",{},{"id":461,"data":462,"type":297,"tunes":494},"requirements-table",{"content":463,"stretched":43,"withHeadings":14},[464,468,472,474,477,481,484,487,490],[465,466,467],"需求","执行层面问题还是执行框架层面问题？","可能的方向",[469,470,471],"私有数据库访问","执行层面","托管式执行框架 + 自托管环境可能就足够了",[473,470,289],"自定义 Linux 软件包",[475,470,476],"自定义 GPU 硬件","在支持的情况下使用托管式执行框架 + 自托管环境",[478,479,480],"自定义代理停止逻辑","执行框架层面","自行运营的执行框架 \u002F 自定义循环",[482,479,483],"每一步都进行跨提供商模型路由","自定义循环或你运营的执行框架",[485,479,486],"自定义上下文压缩算法","如果托管运行时无法暴露该能力，则自行运营执行框架",[488,479,489],"产品所需的确定性编排语义","自行运营的执行框架或严格控制的自定义循环",[491,492,493],"仅本地部署且不依赖托管式执行框架的产品","执行框架层面 + 执行层面","自行运营的运行时",{},{"id":496,"data":497,"type":42,"tunes":499},"h-control-test",{"text":498,"level":219},"控制升级测试",{},{"id":501,"data":502,"type":226,"tunes":504},"p-control-intro",{"text":503},"使用满足实际需求的最少自托管架构。一次只升级一层控制。",{},{"id":506,"data":507,"type":531,"tunes":532},"control-flow",{"steps":508,"title":498,"orientation":530},[509,512,515,518,521,524,527],{"label":510,"description":511},"1. 从应用边界开始","无论代理运行时如何，都将领域事实、授权和重要业务操作保留在你自己的产品中。",{"label":513,"description":514},"2. 询问代理是否需要本地执行","如果不需要，那么没有专用环境的托管式执行框架可能就足够了。",{"label":516,"description":517},"3. 询问平台托管的计算是否可接受","如果可以，使用托管环境，避免不必要的基础设施所有权。",{"label":519,"description":520},"4. 如果不行，自托管执行层面","连接你自己的环境，以满足私有网络、文件、软件包或受控计算的需求。",{"label":522,"description":523},"5. 重新评估剩余约束","如果需求现在已满足，就停止。不要仅仅为了架构对称而自托管执行框架。",{"label":525,"description":526},"6. 仅针对执行框架需求升级到执行框架所有权","当编排、上下文策略、生命周期或可移植性确实需要时，才拥有 Codex 执行框架或自定义代理循环。",{"label":528,"description":529},"7. 证明额外控制值得额外运维","在承诺之前，对可靠性、延迟、成本、恢复、可观测性和工程负担进行基准测试。","auto","processFlow",{},{"id":534,"data":535,"type":42,"tunes":537},"h-ops",{"text":536,"level":219},"当你拥有执行框架时，运维负担会非线性增长",{},{"id":539,"data":540,"type":226,"tunes":542},"p-ops-1",{"text":541},"自运营循环在演示中听起来很简单：调用模型、检查工具调用、执行工具、追加结果、重复。生产环境增加了持久状态、重试、重复事件、取消、审批、上下文溢出、工具超时、进程重启、跟踪持久化、背压、并发工作和部分副作用后的恢复。",{},{"id":544,"data":545,"type":226,"tunes":547},"p-ops-2",{"text":546},"Anthropic 的长期运行代理研究反复表明，框架设计对性能有实质性影响。他们在长期运行应用程序开发方面的工作使用显式规划、结构化产物和评估代理，因为朴素循环往往会丢失进度或过早终止。因此，框架是生产逻辑，而不是管道。",{},{"id":549,"data":550,"type":297,"tunes":582},"ops-table",{"content":551,"stretched":43,"withHeadings":14},[552,555,558,561,564,567,570,573,576,579],[553,554],"如果你拥有框架，你还需要回答","为什么重要",[556,557],"持久会话状态","进程会重启；长期运行的工作必须正确恢复",[559,560],"上下文压缩","历史最终会超出实际工作上下文",[562,563],"工具幂等性","重试不得重复不可逆的副作用",[565,566],"取消和中断","用户和系统需要停止或重定向工作",[568,569],"部分执行后的恢复","即使代理从未收到结果，工具也可能成功",[571,572],"并发","多个任务、工作者或代理可能触及共享状态",[574,575],"可观测性","最终输出不足以调试运行时故障",[577,578],"版本控制","即使提示保持不变，框架更新也可能改变行为",[580,581],"评估","运行时变更需要在代表性轨迹上进行回归测试",{},{"id":584,"data":585,"type":42,"tunes":587},"h-security",{"text":586,"level":219},"安全边界：自托管计算不会自动使代理私有",{},{"id":589,"data":590,"type":226,"tunes":592},"p-sec-1",{"text":591},"自托管执行环境控制命令运行的位置和文件所在的位置，但托管框架和模型交互仍然跨越服务边界。因此，团队应明确映射数据流，而不是将“自托管”用作隐私属性的简写。",{},{"id":594,"data":595,"type":226,"tunes":597},"p-sec-2",{"text":596},"OpenAI 的自托管执行器使用受限的环境凭据和出站连接。这是有用的隔离，但你的应用程序仍然需要自己的规则来处理机密、私有网络暴露、用户到环境的隔离、文件保留、工具授权和数据分类。",{},{"id":599,"data":600,"type":234,"tunes":603},"sec-callout",{"body":601,"title":602,"variant":241},"\u003Cstrong>基础设施控制、执行隔离和数据治理边界相关但不相同。\u003C\u002Fstrong>请分别决定它们。","重要区别",{},{"id":605,"data":606,"type":42,"tunes":608},"h-cost",{"text":607,"level":219},"延迟和成本：控制可以移动瓶颈，而不是消除瓶颈",{},{"id":610,"data":611,"type":226,"tunes":613},"p-cost-1",{"text":612},"自托管可能会减少一些数据路径或环境启动成本，但也可能增加配置时间、WebSocket 生命周期、冷启动、沙箱清理、可观测性基础设施和工程开销。托管环境可能每单位计算成本更高，但在低量或不规则量下运营成本更低。",{},{"id":615,"data":616,"type":226,"tunes":618},"p-cost-2",{"text":617},"正确的比较是总系统成本：模型和工具使用、环境时间、基础设施、工程努力、待命负担、故障恢复以及较慢迭代的成本。",{},{"id":620,"data":621,"type":42,"tunes":623},"h-matrix",{"text":622,"level":219},"生产决策矩阵",{},{"id":625,"data":626,"type":297,"tunes":668},"decision-matrix",{"content":627,"stretched":43,"withHeadings":14},[628,633,638,641,643,647,650,653,657,660,663],[629,630,631,632],"约束","托管框架 + 托管环境","托管框架 + 自托管环境","自运营框架 \u002F 循环",[634,635,636,637],"最快进入生产","强","中等","最弱",[639,640,635,635],"私有网络执行","弱 \u002F 取决于连接设计",[642,636,635,635],"自定义包 \u002F 系统软件",[644,645,645,646],"框架级控制","低","最高",[648,649,636,646],"运营负担","最低",[651,649,636,652],"可移植性","如果有意设计，可能最高",[654,655,655,656],"上下文策略控制","平台管理","应用程序控制",[658,645,659,659],"执行基础设施控制","高",[661,646,646,662],"从托管框架更新中受益的能力","你负责采用",[664,665,666,667],"最适合","在产品\u002F工具层差异化的团队","需要私有\u002F自定义计算而不拥有编排的团队","运行时语义本身就是需求的团队",{},{"id":670,"data":671,"type":42,"tunes":673},"h-hybrid",{"text":672,"level":219},"混合不是妥协——它通常是清晰的架构",{},{"id":675,"data":676,"type":226,"tunes":678},"p-hybrid-1",{"text":677},"托管框架与自托管执行不是“半自托管”。这是有意的关注点分离。平台拥有长周期代理运行时的复杂性，而你的基础设施拥有执行、私有连接和文件。",{},{"id":680,"data":681,"type":226,"tunes":683},"p-hybrid-2",{"text":682},"该边界类似于其他云架构：托管控制平面，客户控制的数据或执行平面。重要的设计工作是定义它们之间的契约——会话身份、环境身份、凭据、文件、工具权限、生命周期事件和清理。",{},{"id":685,"data":686,"type":691,"tunes":692},"ref-runtime",{"url":687,"title":688,"excerpt":689,"ctaLabel":690},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fopenai-agents-api-vs-agents-sdk-vs-responses-api-what-should-you-build-on-in-2026","OpenAI Agents API vs Agents SDK vs Responses API：2026 年你应该构建在什么之上？","对 OpenAI 当前代理界面的运行时所有权比较，以及每个控制边界应归属何处。","阅读运行时比较","referralArticle",{},{"id":694,"data":695,"type":42,"tunes":697},"h-change",{"text":696,"level":219},"什么会改变这个答案？",{},{"id":699,"data":700,"type":226,"tunes":702},"p-change-1",{"text":701},"如果托管框架暴露更多的运行时控制，如果自托管框架获得更简单的持久会话和恢复原语，或者如果法规要求整个代理循环和模型交互保持在你运营的基础设施内，那么建议会改变。",{},{"id":704,"data":705,"type":226,"tunes":707},"p-change-2",{"text":706},"它也会随着模型能力的变化而变化。Anthropic 明确指出，随着模型改进，harness 假设可能会过时。今天必不可少的控制机制，以后可能变得不再必要，而新的模型能力则可能产生新的治理要求。",{},{"id":709,"data":710,"type":42,"tunes":712},"h-limit",{"text":711,"level":219},"局限性",{},{"id":714,"data":715,"type":226,"tunes":717},"p-limit-1",{"text":716},"本文区分的是架构职责；它并不声称某一种托管模型普遍更安全、更便宜或更可靠。这些结果取决于实现、工作负载、合规要求、团队技能和提供商行为。",{},{"id":719,"data":720,"type":226,"tunes":722},"p-limit-2",{"text":721},"OpenAI Agents API 仍处于公开测试阶段，不同供应商的托管代理产品暴露出不同的边界。双平面模型旨在帮助比较这些架构，而不假设每个供应商都使用相同的术语。",{},{"id":724,"data":725,"type":42,"tunes":727},"h-conclusion",{"text":726,"level":219},"结论",{},{"id":729,"data":730,"type":226,"tunes":732},"p-conclusion-1",{"text":731},"有用的问题不是“我们应该自托管代理吗？”而是：我们实际需要控制哪个平面？",{},{"id":734,"data":735,"type":226,"tunes":737},"p-conclusion-2",{"text":736},"如果需求是私有计算、自定义包、本地文件或内部网络访问，就自托管执行平面，并保持 harness 托管。如果需求是编排语义、上下文策略、提供商控制或运行时生命周期本身，那么 harness 所有权可能是合理的。只按需求所要求的程度升级控制。",{},{"id":739,"data":740,"type":42,"tunes":742},"h-faq",{"text":741,"level":219},"常见问题",{},{"id":744,"data":745,"type":744,"tunes":768},"faq",{"items":746,"title":767},[747,751,755,759,763],{"id":748,"answer":749,"question":750},"faq1","不完全是。OpenAI 仍然运行托管的 Codex harness，而你的基础设施运行用于命令、文件和本地工具的执行环境。","OpenAI Agents API 的自托管环境是自托管代理吗？",{"id":752,"answer":753,"question":754},"faq2","当你的需求涉及私有网络访问、自定义包、受控文件、特定硬件或基础设施策略，而不是控制代理循环本身时，它通常就足够了。","什么时候自托管环境就足够了？",{"id":756,"answer":757,"question":758},"faq3","当你需要自定义编排语义、自定义上下文管理、提供商路由、仅本地运行时行为，或其他位于代理循环而非执行环境中的需求时，可以考虑拥有 harness。","什么时候我应该自己运行 harness？",{"id":760,"answer":761,"question":762},"faq4","不会。它改变的是你控制哪些组件。安全性取决于所有组件之间的数据流、隔离、凭据、工具权限、网络、日志记录和生命周期设计。","自托管会自动提高安全性吗？",{"id":764,"answer":765,"question":766},"faq5","你需要负责持久状态、上下文管理、重试、取消、恢复、可观测性、并发、运行时升级以及 harness 变更的评估。","拥有代理循环的主要运营成本是什么？","托管 harness 与自托管代理运行时",{},{"id":770,"data":771,"type":42,"tunes":773},"h-glossary",{"text":772,"level":219},"术语表",{},{"id":775,"data":776,"type":775,"tunes":801},"glossary",{"title":777,"entries":778},"关键架构术语",[779,783,786,790,794,798],{"term":780,"anchor":781,"definition":782},"Harness 平面","harness-plane","负责循环执行、编排、上下文管理、会话连续性和恢复的代理运行时层。",{"term":315,"anchor":784,"definition":785},"execution-plane","运行命令、执行代码以及访问文件、包和本地资源的环境。",{"term":787,"anchor":788,"definition":789},"托管 harness","managed-harness","其运行时、会话管理和编排由平台提供商运营的代理 harness。",{"term":791,"anchor":792,"definition":793},"自托管环境","self-hosted-environment","由应用程序所有者运营的计算和文件，而单独的代理 harness 可能仍托管在其他地方。",{"term":795,"anchor":796,"definition":797},"自运营 harness","self-operated-harness","其循环、托管、上下文策略和生命周期由应用程序团队运营的代理运行时。",{"term":498,"anchor":799,"definition":800},"control-escalation-test","一种决策方法，仅当需求无法在较低控制层满足时，才增加基础设施和运行时所有权。",{},{"id":803,"data":804,"type":42,"tunes":806},"h-sources",{"text":805,"level":219},"主要来源与延伸阅读",{},{"id":808,"data":809,"type":815,"tunes":816},"src-openai-architecture",{"link":810,"meta":811},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Farchitecture",{"image":812,"title":813,"description":814},{"url":312},"OpenAI — Agents API 架构","当前托管 harness、执行环境和应用服务器之间的分离。","linkTool",{},{"id":818,"data":819,"type":815,"tunes":825},"src-openai-selfhosted",{"link":820,"meta":821},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Fenvironments\u002Fself-hosted",{"image":822,"title":823,"description":824},{"url":312},"OpenAI — 自托管沙箱","客户运营的执行环境如何连接到托管 harness，以及哪些生命周期职责仍由应用程序承担。",{},{"id":827,"data":828,"type":815,"tunes":834},"src-openai-lifecycle",{"link":829,"meta":830},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Fenvironments\u002Flifecycle",{"image":831,"title":832,"description":833},{"url":312},"OpenAI — 沙箱生命周期","自托管计算的配置、重新连接、防止重复环境和清理职责。",{},{"id":836,"data":837,"type":815,"tunes":843},"src-openai-runtime",{"link":838,"meta":839},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents",{"image":840,"title":841,"description":842},{"url":312},"OpenAI — 代理运行时选项","按托管与应用程序运营职责对 Agents API、Codex SDK 和 Responses API 的当前比较。",{},{"id":845,"data":846,"type":815,"tunes":852},"src-openai-platform",{"link":847,"meta":848},"https:\u002F\u002Fdevelopers.openai.com\u002Fblog\u002Fcodex-as-a-platform",{"image":849,"title":850,"description":851},{"url":312},"OpenAI — 作为平台的 Codex","面向希望获得更深运行时控制的应用程序的开源 Codex harness 和集成层。",{},{"id":854,"data":855,"type":815,"tunes":861},"src-anthropic-managed",{"link":856,"meta":857},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fmanaged-agents",{"image":858,"title":859,"description":860},{"url":312},"Anthropic — 扩展托管代理：将大脑与手解耦","关于托管代理架构的讨论，以及为什么 harness 假设需要随模型能力而演进。",{},{"id":863,"data":864,"type":815,"tunes":870},"src-anthropic-harness",{"link":865,"meta":866},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-harnesses-for-long-running-agents",{"image":867,"title":868,"description":869},{"url":312},"Anthropic — 面向长期运行智能体的高效执行框架","工程经验表明，长期运行智能体的性能在很大程度上取决于执行框架的设计与持久化工件。",{},"2.31","“自托管代理”可能意味着截然不同的架构。本指南区分了托管式运行框架、自托管执行环境和完全自主运营的代理循环——并说明了团队实际需要哪种控制边界。","\u002Fuploads\u002F2026\u002F09\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose-1790352403475-kj10jh.webp","managed-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose-1790352403475-kj10jh","PUBLISHED","2026-09-25T12:05:00.000Z","2026-09-25T16:05:38.279Z","2026-09-25T19:49:39.069Z",{"en":880,"de":881,"sr":882,"es":883,"fr":884,"it":885,"ru":886,"zh":887},"\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Fde\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Fsr\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Fes\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Ffr\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Fit\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Fru\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose","\u002Fzh\u002Fblog\u002Fmanaged-agent-harness-vs-self-hosted-agent-loop-what-you-gain-what-you-lose",[889,893,897],{"id":890,"name":891,"slug":892},89,"评估框架","evaluation-harness",{"id":894,"name":895,"slug":896},78,"优化闭环","optimization-loop",{"id":898,"name":899,"slug":900},91,"监控（质量\u002F漂移）","monitoring",{"id":902,"login":903,"email":904,"displayName":905},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[907,1456],{"lang":908,"title":909,"content":910,"contentJson":911,"excerpt":1455},"en","Managed Agent Harness vs Self-Hosted Agent Loop: What You Gain, What You Lose","{\"time\":1790352404508,\"blocks\":[{\"id\":\"-PDI7SJcNl\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"The phrase “self-hosted agent” now hides at least three different architectures. You can use a managed harness with OpenAI-hosted compute, a managed harness connected to infrastructure you operate, or run the harness and agent loop yourself. Those choices have very different implications for control, recovery, context management, security, latency, and operational burden.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"\u003Cstrong>Do not choose between “managed” and “self-hosted” as if they were one binary decision.\u003C\u002Fstrong> Separate the \u003Cstrong>harness plane\u003C\u002Fstrong> from the \u003Cstrong>execution plane\u003C\u002Fstrong>. A managed harness can still use self-hosted compute. A self-hosted environment gives you control over files, packages, network access and execution without requiring you to own the agent loop. Run the harness yourself only when you need control over orchestration, lifecycle, model-routing assumptions, or runtime behaviour that a managed harness cannot expose.\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Current as of 25 September 2026\",\"body\":\"OpenAI's Agents API is in public beta and its architecture can evolve. Current documentation separates the OpenAI-hosted Codex harness from the execution environment and explicitly supports self-hosted environments. OpenAI also exposes the Codex harness separately through the Codex SDK for infrastructure you operate.\"},\"tunes\":{}},{\"id\":\"note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"The model used in this article\",\"body\":\"The Harness Plane \u002F Execution Plane model and Control Escalation Test below are practical architecture tools proposed here. They are not formal vendor terminology.\"},\"tunes\":{}},{\"id\":\"h-mistake\",\"type\":\"header\",\"data\":{\"text\":\"The mistake: treating self-hosting as one decision\",\"level\":2},\"tunes\":{}},{\"id\":\"p-mistake-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"In conventional software, “self-hosted” usually means the application runs on infrastructure you control. Agent systems complicate that definition because the runtime can be split. The model-and-tool loop can run in one place while code execution, files and private-network access happen somewhere else.\"},\"tunes\":{}},{\"id\":\"p-mistake-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI's current Agents API architecture makes this split explicit: OpenAI runs the harness, while the execution environment can be absent, OpenAI-hosted, or self-hosted. A self-hosted environment therefore does not mean the agent loop is self-hosted.\"},\"tunes\":{}},{\"id\":\"p-mistake-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This distinction matters because many teams choose a more complex runtime than they need. They want private-network access or custom packages, conclude that the entire agent must be self-hosted, and accidentally take ownership of context management, orchestration, recovery and lifecycle that could have remained managed.\"},\"tunes\":{}},{\"id\":\"h-three\",\"type\":\"header\",\"data\":{\"text\":\"Three architectures that are often called “self-hosted”\",\"level\":2},\"tunes\":{}},{\"id\":\"three-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Architecture\",\"Who runs the harness?\",\"Where code\u002Ffiles execute\",\"What you primarily own\"],[\"Managed harness + managed environment\",\"Platform\",\"Platform-hosted sandbox\",\"Application, tools, product logic, authorization\"],[\"Managed harness + self-hosted environment\",\"Platform\",\"Your container, VM, laptop, private cloud or other compute\",\"Environment provisioning, networking, files and lifecycle; platform still owns harness\"],[\"Self-operated harness \u002F agent loop\",\"You\",\"Your chosen environment\",\"Harness process, orchestration, context strategy, hosting, recovery, execution and application lifecycle\"]]},\"tunes\":{}},{\"id\":\"h-two-plane\",\"type\":\"header\",\"data\":{\"text\":\"The two-plane model\",\"level\":2},\"tunes\":{}},{\"id\":\"plane-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Separate the harness plane from the execution plane\",\"layout\":\"table\",\"columns\":[{\"id\":\"plane\",\"label\":\"Plane\"},{\"id\":\"owns\",\"label\":\"What it owns\"},{\"id\":\"questions\",\"label\":\"Questions to ask\"}],\"rows\":[{\"id\":\"harness\",\"label\":\"Harness plane\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"execution\",\"label\":\"Execution plane\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"application\",\"label\":\"Application plane\",\"values\":[\"\",\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"key-consequence\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Key architectural consequence\",\"body\":\"You can self-host the \u003Cstrong>execution plane\u003C\u002Fstrong> without self-hosting the \u003Cstrong>harness plane\u003C\u002Fstrong>. That is often the right middle ground.\"},\"tunes\":{}},{\"id\":\"h-managed\",\"type\":\"header\",\"data\":{\"text\":\"Managed harness: what you actually gain\",\"level\":2},\"tunes\":{}},{\"id\":\"p-managed-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A managed harness removes more than a while-loop. OpenAI's current Agents API manages sessions, orchestration, context compaction and recovery. Anthropic's work on managed agents describes the same broader motivation: harnesses contain assumptions about model behaviour, and those assumptions need to evolve as models improve.\"},\"tunes\":{}},{\"id\":\"p-managed-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"That means the benefit is not only fewer lines of code. The platform can update runtime behaviour, long-horizon context handling, subagent coordination and recovery without requiring every application team to rebuild those mechanisms.\"},\"tunes\":{}},{\"id\":\"managed-list\",\"type\":\"list\",\"data\":{\"style\":\"unordered\",\"meta\":{},\"items\":[\"Less application-owned orchestration code.\",\"Managed durable-session behaviour.\",\"Managed context compaction and recovery.\",\"A runtime that can evolve with model capabilities.\",\"Simpler adoption of platform-native subagent and long-running-agent features.\",\"Potentially lower operational burden for teams whose differentiation is not the harness itself.\"]},\"tunes\":{}},{\"id\":\"h-managed-cost\",\"type\":\"header\",\"data\":{\"text\":\"Managed harness: what you give up\",\"level\":2},\"tunes\":{}},{\"id\":\"p-managed-cost-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Delegating the harness also delegates some control. Your application no longer owns every detail of iteration, context strategy, orchestration and runtime evolution. A platform update can improve the system, but it can also change behaviour your product implicitly depended on.\"},\"tunes\":{}},{\"id\":\"p-managed-cost-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This creates a different kind of engineering requirement: strong evals, explicit product boundaries and an integration layer that prevents managed-session behaviour from becoming your business source of truth.\"},\"tunes\":{}},{\"id\":\"managed-cost-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Managed-harness trade-off\",\"What it means operationally\"],[\"Less loop control\",\"You cannot assume every orchestration detail is application-defined\"],[\"Platform evolution\",\"Harness behaviour can improve or change without your code changing\"],[\"Vendor-specific lifecycle\",\"Sessions, events and recovery semantics become part of the integration surface\"],[\"Observability boundary\",\"Platform traces must be joined with application audit data\"],[\"Portability cost\",\"Moving to another harness later may require more than swapping model endpoints\"]]},\"tunes\":{}},{\"id\":\"h-self-env\",\"type\":\"header\",\"data\":{\"text\":\"Self-hosted execution environment: the middle architecture\",\"level\":2},\"tunes\":{}},{\"id\":\"p-self-env-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI's self-hosted environment model is important because it decouples private compute from harness ownership. The platform still runs the Codex harness, while an executor runs inside your environment and receives commands over an outbound connection.\"},\"tunes\":{}},{\"id\":\"p-self-env-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"You control provisioning, files, dependencies, network access and cleanup. The harness can therefore work against private infrastructure or custom software without requiring the entire agent runtime to move into your application.\"},\"tunes\":{}},{\"id\":\"p-self-env-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The cost is lifecycle responsibility. Your application must map sessions to compute, avoid duplicate provisioning, reconnect environments, coordinate shutdown and preserve any files that must outlive the environment.\"},\"tunes\":{}},{\"id\":\"h-enough\",\"type\":\"header\",\"data\":{\"text\":\"When self-hosted execution is enough\",\"level\":3},\"tunes\":{}},{\"id\":\"enough-list\",\"type\":\"list\",\"data\":{\"style\":\"unordered\",\"meta\":{},\"items\":[\"The agent needs access to a private VPC or internal service.\",\"The agent needs custom binaries, packages, drivers or system software.\",\"The workload must run on hardware or cloud accounts you control.\",\"Files must remain inside a controlled environment.\",\"You need your own sandbox provider or isolation model.\",\"You want platform-managed orchestration but infrastructure-controlled execution.\"]},\"tunes\":{}},{\"id\":\"h-own-harness\",\"type\":\"header\",\"data\":{\"text\":\"When you may need to own the harness too\",\"level\":2},\"tunes\":{}},{\"id\":\"p-own-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Owning the harness becomes justified when the harness itself is part of your product differentiation or constraint set. OpenAI's current runtime overview positions the Codex SDK for running the Codex harness in infrastructure you operate, while Responses is the lower-level option when you want to own the agent loop yourself.\"},\"tunes\":{}},{\"id\":\"p-own-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The key is to identify a requirement that genuinely lives in the harness plane, not the execution plane.\"},\"tunes\":{}},{\"id\":\"requirements-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Requirement\",\"Execution-plane problem or harness-plane problem?\",\"Likely direction\"],[\"Private database access\",\"Execution plane\",\"Managed harness + self-hosted environment may be sufficient\"],[\"Custom Linux packages\",\"Execution plane\",\"Managed harness + self-hosted environment\"],[\"Custom GPU hardware\",\"Execution plane\",\"Managed harness + self-hosted environment where supported\"],[\"Custom agent stopping logic\",\"Harness plane\",\"Self-operated harness \u002F custom loop\"],[\"Cross-provider model routing at every step\",\"Harness plane\",\"Custom loop or harness you operate\"],[\"Custom context-compaction algorithm\",\"Harness plane\",\"Self-operated harness if the managed runtime cannot expose it\"],[\"Deterministic orchestration semantics required by product\",\"Harness plane\",\"Self-operated harness or tightly controlled custom loop\"],[\"Local-only product deployment with no managed harness dependency\",\"Harness plane + execution plane\",\"Self-operated runtime\"]]},\"tunes\":{}},{\"id\":\"h-control-test\",\"type\":\"header\",\"data\":{\"text\":\"The Control Escalation Test\",\"level\":2},\"tunes\":{}},{\"id\":\"p-control-intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Use the least self-hosted architecture that satisfies the actual requirement. Escalate control one layer at a time.\"},\"tunes\":{}},{\"id\":\"control-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Control Escalation Test\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Start with the application boundary\",\"description\":\"Keep domain truth, authorization and consequential business actions in your own product regardless of agent runtime.\"},{\"label\":\"2. Ask whether the agent needs local execution\",\"description\":\"If not, a managed harness without a dedicated environment may be enough.\"},{\"label\":\"3. Ask whether platform-hosted compute is acceptable\",\"description\":\"If yes, use a managed environment and avoid unnecessary infrastructure ownership.\"},{\"label\":\"4. If not, self-host the execution plane\",\"description\":\"Connect your own environment for private network, files, packages or controlled compute.\"},{\"label\":\"5. Re-evaluate the remaining constraint\",\"description\":\"If the requirement is now satisfied, stop. Do not self-host the harness simply for architectural symmetry.\"},{\"label\":\"6. Escalate to harness ownership only for harness requirements\",\"description\":\"Own the Codex harness or custom agent loop when orchestration, context strategy, lifecycle or portability genuinely requires it.\"},{\"label\":\"7. Prove the extra control is worth the extra operations\",\"description\":\"Benchmark reliability, latency, cost, recovery, observability and engineering burden before committing.\"}]},\"tunes\":{}},{\"id\":\"h-ops\",\"type\":\"header\",\"data\":{\"text\":\"Operational burden grows nonlinearly when you own the harness\",\"level\":2},\"tunes\":{}},{\"id\":\"p-ops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A self-operated loop sounds simple in a demo: call model, inspect tool call, execute tool, append result, repeat. Production adds durable state, retries, duplicate events, cancellation, approval, context overflow, tool timeouts, process restarts, trace persistence, backpressure, concurrent work and recovery after partial side effects.\"},\"tunes\":{}},{\"id\":\"p-ops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Long-running-agent research from Anthropic repeatedly shows that harness design materially affects performance. Their work on long-running application development uses explicit planning, structured artifacts and evaluator agents because naïve loops tend to lose progress or terminate prematurely. The harness is therefore production logic, not plumbing.\"},\"tunes\":{}},{\"id\":\"ops-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"If you own the harness, you also need an answer for\",\"Why it matters\"],[\"Durable session state\",\"Processes restart; long-running work must resume correctly\"],[\"Context compaction\",\"History eventually exceeds practical working context\"],[\"Tool idempotency\",\"Retries must not repeat irreversible side effects\"],[\"Cancellation and interruption\",\"Users and systems need to stop or redirect work\"],[\"Recovery after partial execution\",\"A tool may succeed even if the agent never receives the result\"],[\"Concurrency\",\"Multiple tasks, workers or agents can touch shared state\"],[\"Observability\",\"Final output is insufficient for debugging runtime failures\"],[\"Versioning\",\"Harness updates can change behaviour even when prompts remain constant\"],[\"Evaluation\",\"Runtime changes need regression testing across representative trajectories\"]]},\"tunes\":{}},{\"id\":\"h-security\",\"type\":\"header\",\"data\":{\"text\":\"Security boundary: self-hosting compute does not automatically make the agent private\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sec-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A self-hosted execution environment controls where commands run and where files live, but the managed harness and model interaction still cross the service boundary. Teams should therefore map data flows explicitly rather than use “self-hosted” as shorthand for a privacy property.\"},\"tunes\":{}},{\"id\":\"p-sec-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI's self-hosted executor uses restricted environment credentials and outbound connections. That is useful isolation, but your application still needs its own rules for secrets, private-network exposure, user-to-environment isolation, file retention, tool authorization and data classification.\"},\"tunes\":{}},{\"id\":\"sec-callout\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Important distinction\",\"body\":\"\u003Cstrong>Infrastructure control, execution isolation and data-governance boundaries are related but not identical.\u003C\u002Fstrong> Decide them separately.\"},\"tunes\":{}},{\"id\":\"h-cost\",\"type\":\"header\",\"data\":{\"text\":\"Latency and cost: control can move bottlenecks rather than remove them\",\"level\":2},\"tunes\":{}},{\"id\":\"p-cost-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Self-hosting may reduce some data-path or environment-startup costs, but it can also add provisioning time, WebSocket lifecycle, cold starts, sandbox cleanup, observability infrastructure and engineering overhead. A managed environment may cost more per unit of compute while being cheaper to operate at low or irregular volume.\"},\"tunes\":{}},{\"id\":\"p-cost-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The correct comparison is total system cost: model and tool usage, environment time, infrastructure, engineering effort, on-call burden, failure recovery and the cost of slower iteration.\"},\"tunes\":{}},{\"id\":\"h-matrix\",\"type\":\"header\",\"data\":{\"text\":\"A production decision matrix\",\"level\":2},\"tunes\":{}},{\"id\":\"decision-matrix\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Constraint\",\"Managed harness + managed environment\",\"Managed harness + self-hosted environment\",\"Self-operated harness \u002F loop\"],[\"Fastest path to production\",\"Strong\",\"Moderate\",\"Weakest\"],[\"Private-network execution\",\"Weak \u002F depends on connectivity design\",\"Strong\",\"Strong\"],[\"Custom packages \u002F system software\",\"Moderate\",\"Strong\",\"Strong\"],[\"Harness-level control\",\"Low\",\"Low\",\"Highest\"],[\"Operational burden\",\"Lowest\",\"Medium\",\"Highest\"],[\"Portability\",\"Lowest\",\"Medium\",\"Potentially highest if intentionally designed\"],[\"Context strategy control\",\"Platform-managed\",\"Platform-managed\",\"Application-controlled\"],[\"Execution infrastructure control\",\"Low\",\"High\",\"High\"],[\"Ability to benefit from managed harness updates\",\"Highest\",\"Highest\",\"You own adoption\"],[\"Best fit\",\"Teams differentiating at product\u002Ftool layer\",\"Teams needing private\u002Fcustom compute without owning orchestration\",\"Teams whose runtime semantics are themselves a requirement\"]]},\"tunes\":{}},{\"id\":\"h-hybrid\",\"type\":\"header\",\"data\":{\"text\":\"Hybrid is not a compromise — it is often the clean architecture\",\"level\":2},\"tunes\":{}},{\"id\":\"p-hybrid-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A managed harness with self-hosted execution is not “half self-hosted.” It is an intentional separation of concerns. The platform owns long-horizon agent-runtime complexity, while your infrastructure owns execution, private connectivity and files.\"},\"tunes\":{}},{\"id\":\"p-hybrid-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"That boundary resembles other cloud architectures: managed control plane, customer-controlled data or execution plane. The important design work is defining the contract between them — session identity, environment identity, credentials, files, tool permissions, lifecycle events and cleanup.\"},\"tunes\":{}},{\"id\":\"ref-runtime\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fopenai-agents-api-vs-agents-sdk-vs-responses-api-what-should-you-build-on-in-2026\",\"title\":\"OpenAI Agents API vs Agents SDK vs Responses API: What Should You Build On in 2026?\",\"excerpt\":\"A runtime-ownership comparison of OpenAI's current agent surfaces and where each control boundary belongs.\",\"ctaLabel\":\"Read the runtime comparison\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The recommendation changes if managed harnesses expose substantially more runtime control, if self-hosted harnesses gain simpler durable-session and recovery primitives, or if regulation requires the entire agent loop and model interaction to remain inside infrastructure you operate.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"It also changes with model capability. Anthropic explicitly notes that harness assumptions can become stale as models improve. A control mechanism that is essential today may become unnecessary later, while a new model capability can create a new governance requirement.\"},\"tunes\":{}},{\"id\":\"h-limit\",\"type\":\"header\",\"data\":{\"text\":\"Limitations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-limit-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"This article separates architecture responsibilities; it does not claim that one hosting model is universally more secure, cheaper or more reliable. Those outcomes depend on implementation, workload, compliance requirements, team skill and provider behaviour.\"},\"tunes\":{}},{\"id\":\"p-limit-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The OpenAI Agents API is still in public beta, and managed-agent products from different vendors expose different boundaries. The two-plane model is intended to help compare those architectures without assuming that every vendor uses identical terms.\"},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The useful question is not “Should we self-host the agent?” It is: Which plane do we actually need to control?\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"If the requirement is private compute, custom packages, local files or internal-network access, self-host the execution plane and keep the harness managed. If the requirement is orchestration semantics, context strategy, provider control or runtime lifecycle itself, then harness ownership may be justified. Escalate control only as far as the requirement demands.\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"FAQ\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Managed harnesses and self-hosted agent runtimes\",\"items\":[{\"id\":\"faq1\",\"question\":\"Is an OpenAI Agents API self-hosted environment a self-hosted agent?\",\"answer\":\"Not completely. OpenAI still runs the managed Codex harness, while your infrastructure runs the execution environment used for commands, files and local tools.\"},{\"id\":\"faq2\",\"question\":\"When is a self-hosted environment enough?\",\"answer\":\"It is often enough when your requirements concern private-network access, custom packages, controlled files, specific hardware or infrastructure policy rather than control over the agent loop itself.\"},{\"id\":\"faq3\",\"question\":\"When should I run the harness myself?\",\"answer\":\"Consider harness ownership when you need custom orchestration semantics, custom context management, provider routing, local-only runtime behaviour, or another requirement that lives in the agent loop rather than the execution environment.\"},{\"id\":\"faq4\",\"question\":\"Does self-hosting automatically improve security?\",\"answer\":\"No. It changes which components you control. Security depends on data flow, isolation, credentials, tool permissions, networking, logging and lifecycle design across all components.\"},{\"id\":\"faq5\",\"question\":\"What is the main operational cost of owning the agent loop?\",\"answer\":\"You become responsible for durable state, context management, retries, cancellation, recovery, observability, concurrency, runtime upgrades and evaluation of harness changes.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key architecture terms\",\"entries\":[{\"term\":\"Harness plane\",\"definition\":\"The agent-runtime layer responsible for loop execution, orchestration, context management, session continuity and recovery.\",\"anchor\":\"harness-plane\"},{\"term\":\"Execution plane\",\"definition\":\"The environment in which commands run, code executes and files, packages and local resources are accessed.\",\"anchor\":\"execution-plane\"},{\"term\":\"Managed harness\",\"definition\":\"An agent harness whose runtime, session management and orchestration are operated by a platform provider.\",\"anchor\":\"managed-harness\"},{\"term\":\"Self-hosted environment\",\"definition\":\"Compute and files operated by the application owner while a separate agent harness may remain managed elsewhere.\",\"anchor\":\"self-hosted-environment\"},{\"term\":\"Self-operated harness\",\"definition\":\"An agent runtime whose loop, hosting, context strategy and lifecycle are operated by the application team.\",\"anchor\":\"self-operated-harness\"},{\"term\":\"Control Escalation Test\",\"definition\":\"A decision method that increases infrastructure and runtime ownership only when a requirement cannot be satisfied at a lower-control layer.\",\"anchor\":\"control-escalation-test\"}]},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and further reading\",\"level\":2},\"tunes\":{}},{\"id\":\"src-openai-architecture\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Farchitecture\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Agents API Architecture\",\"description\":\"Current separation between the hosted harness, execution environment and application server.\"}},\"tunes\":{}},{\"id\":\"src-openai-selfhosted\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Fenvironments\u002Fself-hosted\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Self-hosted sandboxes\",\"description\":\"How customer-operated execution environments connect to the managed harness and which lifecycle responsibilities remain with the application.\"}},\"tunes\":{}},{\"id\":\"src-openai-lifecycle\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Fenvironments\u002Flifecycle\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Sandbox lifecycle\",\"description\":\"Provisioning, reconnection, duplicate-environment prevention and cleanup responsibilities for self-hosted compute.\"}},\"tunes\":{}},{\"id\":\"src-openai-runtime\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Agent runtime options\",\"description\":\"Current comparison of Agents API, Codex SDK and Responses API by managed versus application-operated responsibilities.\"}},\"tunes\":{}},{\"id\":\"src-openai-platform\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fblog\u002Fcodex-as-a-platform\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Codex as a platform\",\"description\":\"Open-source Codex harness and integration layers for applications that want deeper runtime control.\"}},\"tunes\":{}},{\"id\":\"src-anthropic-managed\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fmanaged-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Anthropic — Scaling Managed Agents: Decoupling the brain from the hands\",\"description\":\"Discussion of managed-agent architecture and why harness assumptions need to evolve with model capability.\"}},\"tunes\":{}},{\"id\":\"src-anthropic-harness\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-harnesses-for-long-running-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Anthropic — Effective harnesses for long-running agents\",\"description\":\"Engineering lessons showing that long-running agent performance depends materially on harness design and persistent artifacts.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":912,"blocks":913,"version":1454},1790352404508,[914,918,922,927,932,937,941,945,949,953,957,980,984,1005,1010,1014,1018,1022,1033,1037,1041,1045,1067,1071,1075,1079,1083,1087,1098,1102,1106,1110,1142,1146,1150,1176,1180,1184,1188,1222,1226,1230,1234,1239,1243,1247,1251,1255,1298,1302,1306,1310,1317,1321,1325,1329,1333,1337,1341,1345,1349,1353,1357,1377,1381,1401,1405,1412,1419,1426,1433,1440,1447],{"id":215,"data":915,"type":220,"tunes":917},{"title":916,"maxLevel":218,"minLevel":219},"Contents",{},{"id":223,"data":919,"type":226,"tunes":921},{"text":920},"The phrase “self-hosted agent” now hides at least three different architectures. You can use a managed harness with OpenAI-hosted compute, a managed harness connected to infrastructure you operate, or run the harness and agent loop yourself. Those choices have very different implications for control, recovery, context management, security, latency, and operational burden.",{},{"id":229,"data":923,"type":234,"tunes":926},{"body":924,"title":925,"variant":233},"\u003Cstrong>Do not choose between “managed” and “self-hosted” as if they were one binary decision.\u003C\u002Fstrong> Separate the \u003Cstrong>harness plane\u003C\u002Fstrong> from the \u003Cstrong>execution plane\u003C\u002Fstrong>. A managed harness can still use self-hosted compute. A self-hosted environment gives you control over files, packages, network access and execution without requiring you to own the agent loop. Run the harness yourself only when you need control over orchestration, lifecycle, model-routing assumptions, or runtime behaviour that a managed harness cannot expose.","Direct answer",{},{"id":237,"data":928,"type":234,"tunes":931},{"body":929,"title":930,"variant":241},"OpenAI's Agents API is in public beta and its architecture can evolve. Current documentation separates the OpenAI-hosted Codex harness from the execution environment and explicitly supports self-hosted environments. OpenAI also exposes the Codex harness separately through the Codex SDK for infrastructure you operate.","Current as of 25 September 2026",{},{"id":244,"data":933,"type":234,"tunes":936},{"body":934,"title":935,"variant":244},"The Harness Plane \u002F Execution Plane model and Control Escalation Test below are practical architecture tools proposed here. They are not formal vendor terminology.","The model used in this article",{},{"id":250,"data":938,"type":42,"tunes":940},{"text":939,"level":219},"The mistake: treating self-hosting as one decision",{},{"id":255,"data":942,"type":226,"tunes":944},{"text":943},"In conventional software, “self-hosted” usually means the application runs on infrastructure you control. Agent systems complicate that definition because the runtime can be split. The model-and-tool loop can run in one place while code execution, files and private-network access happen somewhere else.",{},{"id":260,"data":946,"type":226,"tunes":948},{"text":947},"OpenAI's current Agents API architecture makes this split explicit: OpenAI runs the harness, while the execution environment can be absent, OpenAI-hosted, or self-hosted. A self-hosted environment therefore does not mean the agent loop is self-hosted.",{},{"id":265,"data":950,"type":226,"tunes":952},{"text":951},"This distinction matters because many teams choose a more complex runtime than they need. They want private-network access or custom packages, conclude that the entire agent must be self-hosted, and accidentally take ownership of context management, orchestration, recovery and lifecycle that could have remained managed.",{},{"id":270,"data":954,"type":42,"tunes":956},{"text":955,"level":219},"Three architectures that are often called “self-hosted”",{},{"id":275,"data":958,"type":297,"tunes":979},{"content":959,"stretched":43,"withHeadings":14},[960,965,970,974],[961,962,963,964],"Architecture","Who runs the harness?","Where code\u002Ffiles execute","What you primarily own",[966,967,968,969],"Managed harness + managed environment","Platform","Platform-hosted sandbox","Application, tools, product logic, authorization",[971,967,972,973],"Managed harness + self-hosted environment","Your container, VM, laptop, private cloud or other compute","Environment provisioning, networking, files and lifecycle; platform still owns harness",[975,976,977,978],"Self-operated harness \u002F agent loop","You","Your chosen environment","Harness process, orchestration, context strategy, hosting, recovery, execution and application lifecycle",{},{"id":300,"data":981,"type":42,"tunes":983},{"text":982,"level":219},"The two-plane model",{},{"id":305,"data":985,"type":332,"tunes":1004},{"rows":986,"title":996,"layout":297,"columns":997},[987,990,993],{"id":309,"label":988,"values":989},"Harness plane",[312,312,312],{"id":314,"label":991,"values":992},"Execution plane",[312,312,312],{"id":318,"label":994,"values":995},"Application plane",[312,312,312],"Separate the harness plane from the execution plane",[998,1000,1002],{"id":324,"label":999},"Plane",{"id":327,"label":1001},"What it owns",{"id":330,"label":1003},"Questions to ask",{},{"id":335,"data":1006,"type":234,"tunes":1009},{"body":1007,"title":1008,"variant":339},"You can self-host the \u003Cstrong>execution plane\u003C\u002Fstrong> without self-hosting the \u003Cstrong>harness plane\u003C\u002Fstrong>. That is often the right middle ground.","Key architectural consequence",{},{"id":342,"data":1011,"type":42,"tunes":1013},{"text":1012,"level":219},"Managed harness: what you actually gain",{},{"id":347,"data":1015,"type":226,"tunes":1017},{"text":1016},"A managed harness removes more than a while-loop. OpenAI's current Agents API manages sessions, orchestration, context compaction and recovery. Anthropic's work on managed agents describes the same broader motivation: harnesses contain assumptions about model behaviour, and those assumptions need to evolve as models improve.",{},{"id":352,"data":1019,"type":226,"tunes":1021},{"text":1020},"That means the benefit is not only fewer lines of code. The platform can update runtime behaviour, long-horizon context handling, subagent coordination and recovery without requiring every application team to rebuild those mechanisms.",{},{"id":357,"data":1023,"type":368,"tunes":1032},{"meta":1024,"items":1025,"style":367},{},[1026,1027,1028,1029,1030,1031],"Less application-owned orchestration code.","Managed durable-session behaviour.","Managed context compaction and recovery.","A runtime that can evolve with model capabilities.","Simpler adoption of platform-native subagent and long-running-agent features.","Potentially lower operational burden for teams whose differentiation is not the harness itself.",{},{"id":371,"data":1034,"type":42,"tunes":1036},{"text":1035,"level":219},"Managed harness: what you give up",{},{"id":376,"data":1038,"type":226,"tunes":1040},{"text":1039},"Delegating the harness also delegates some control. Your application no longer owns every detail of iteration, context strategy, orchestration and runtime evolution. A platform update can improve the system, but it can also change behaviour your product implicitly depended on.",{},{"id":381,"data":1042,"type":226,"tunes":1044},{"text":1043},"This creates a different kind of engineering requirement: strong evals, explicit product boundaries and an integration layer that prevents managed-session behaviour from becoming your business source of truth.",{},{"id":386,"data":1046,"type":297,"tunes":1066},{"content":1047,"stretched":43,"withHeadings":14},[1048,1051,1054,1057,1060,1063],[1049,1050],"Managed-harness trade-off","What it means operationally",[1052,1053],"Less loop control","You cannot assume every orchestration detail is application-defined",[1055,1056],"Platform evolution","Harness behaviour can improve or change without your code changing",[1058,1059],"Vendor-specific lifecycle","Sessions, events and recovery semantics become part of the integration surface",[1061,1062],"Observability boundary","Platform traces must be joined with application audit data",[1064,1065],"Portability cost","Moving to another harness later may require more than swapping model endpoints",{},{"id":409,"data":1068,"type":42,"tunes":1070},{"text":1069,"level":219},"Self-hosted execution environment: the middle architecture",{},{"id":414,"data":1072,"type":226,"tunes":1074},{"text":1073},"OpenAI's self-hosted environment model is important because it decouples private compute from harness ownership. The platform still runs the Codex harness, while an executor runs inside your environment and receives commands over an outbound connection.",{},{"id":419,"data":1076,"type":226,"tunes":1078},{"text":1077},"You control provisioning, files, dependencies, network access and cleanup. The harness can therefore work against private infrastructure or custom software without requiring the entire agent runtime to move into your application.",{},{"id":424,"data":1080,"type":226,"tunes":1082},{"text":1081},"The cost is lifecycle responsibility. Your application must map sessions to compute, avoid duplicate provisioning, reconnect environments, coordinate shutdown and preserve any files that must outlive the environment.",{},{"id":429,"data":1084,"type":42,"tunes":1086},{"text":1085,"level":218},"When self-hosted execution is enough",{},{"id":434,"data":1088,"type":368,"tunes":1097},{"meta":1089,"items":1090,"style":367},{},[1091,1092,1093,1094,1095,1096],"The agent needs access to a private VPC or internal service.","The agent needs custom binaries, packages, drivers or system software.","The workload must run on hardware or cloud accounts you control.","Files must remain inside a controlled environment.","You need your own sandbox provider or isolation model.","You want platform-managed orchestration but infrastructure-controlled execution.",{},{"id":446,"data":1099,"type":42,"tunes":1101},{"text":1100,"level":219},"When you may need to own the harness too",{},{"id":451,"data":1103,"type":226,"tunes":1105},{"text":1104},"Owning the harness becomes justified when the harness itself is part of your product differentiation or constraint set. OpenAI's current runtime overview positions the Codex SDK for running the Codex harness in infrastructure you operate, while Responses is the lower-level option when you want to own the agent loop yourself.",{},{"id":456,"data":1107,"type":226,"tunes":1109},{"text":1108},"The key is to identify a requirement that genuinely lives in the harness plane, not the execution plane.",{},{"id":461,"data":1111,"type":297,"tunes":1141},{"content":1112,"stretched":43,"withHeadings":14},[1113,1117,1120,1122,1125,1128,1131,1134,1137],[1114,1115,1116],"Requirement","Execution-plane problem or harness-plane problem?","Likely direction",[1118,991,1119],"Private database access","Managed harness + self-hosted environment may be sufficient",[1121,991,971],"Custom Linux packages",[1123,991,1124],"Custom GPU hardware","Managed harness + self-hosted environment where supported",[1126,988,1127],"Custom agent stopping logic","Self-operated harness \u002F custom loop",[1129,988,1130],"Cross-provider model routing at every step","Custom loop or harness you operate",[1132,988,1133],"Custom context-compaction algorithm","Self-operated harness if the managed runtime cannot expose it",[1135,988,1136],"Deterministic orchestration semantics required by product","Self-operated harness or tightly controlled custom loop",[1138,1139,1140],"Local-only product deployment with no managed harness dependency","Harness plane + execution plane","Self-operated runtime",{},{"id":496,"data":1143,"type":42,"tunes":1145},{"text":1144,"level":219},"The Control Escalation Test",{},{"id":501,"data":1147,"type":226,"tunes":1149},{"text":1148},"Use the least self-hosted architecture that satisfies the actual requirement. Escalate control one layer at a time.",{},{"id":506,"data":1151,"type":531,"tunes":1175},{"steps":1152,"title":1174,"orientation":530},[1153,1156,1159,1162,1165,1168,1171],{"label":1154,"description":1155},"1. Start with the application boundary","Keep domain truth, authorization and consequential business actions in your own product regardless of agent runtime.",{"label":1157,"description":1158},"2. Ask whether the agent needs local execution","If not, a managed harness without a dedicated environment may be enough.",{"label":1160,"description":1161},"3. Ask whether platform-hosted compute is acceptable","If yes, use a managed environment and avoid unnecessary infrastructure ownership.",{"label":1163,"description":1164},"4. If not, self-host the execution plane","Connect your own environment for private network, files, packages or controlled compute.",{"label":1166,"description":1167},"5. Re-evaluate the remaining constraint","If the requirement is now satisfied, stop. Do not self-host the harness simply for architectural symmetry.",{"label":1169,"description":1170},"6. Escalate to harness ownership only for harness requirements","Own the Codex harness or custom agent loop when orchestration, context strategy, lifecycle or portability genuinely requires it.",{"label":1172,"description":1173},"7. Prove the extra control is worth the extra operations","Benchmark reliability, latency, cost, recovery, observability and engineering burden before committing.","Control Escalation Test",{},{"id":534,"data":1177,"type":42,"tunes":1179},{"text":1178,"level":219},"Operational burden grows nonlinearly when you own the harness",{},{"id":539,"data":1181,"type":226,"tunes":1183},{"text":1182},"A self-operated loop sounds simple in a demo: call model, inspect tool call, execute tool, append result, repeat. Production adds durable state, retries, duplicate events, cancellation, approval, context overflow, tool timeouts, process restarts, trace persistence, backpressure, concurrent work and recovery after partial side effects.",{},{"id":544,"data":1185,"type":226,"tunes":1187},{"text":1186},"Long-running-agent research from Anthropic repeatedly shows that harness design materially affects performance. Their work on long-running application development uses explicit planning, structured artifacts and evaluator agents because naïve loops tend to lose progress or terminate prematurely. The harness is therefore production logic, not plumbing.",{},{"id":549,"data":1189,"type":297,"tunes":1221},{"content":1190,"stretched":43,"withHeadings":14},[1191,1194,1197,1200,1203,1206,1209,1212,1215,1218],[1192,1193],"If you own the harness, you also need an answer for","Why it matters",[1195,1196],"Durable session state","Processes restart; long-running work must resume correctly",[1198,1199],"Context compaction","History eventually exceeds practical working context",[1201,1202],"Tool idempotency","Retries must not repeat irreversible side effects",[1204,1205],"Cancellation and interruption","Users and systems need to stop or redirect work",[1207,1208],"Recovery after partial execution","A tool may succeed even if the agent never receives the result",[1210,1211],"Concurrency","Multiple tasks, workers or agents can touch shared state",[1213,1214],"Observability","Final output is insufficient for debugging runtime failures",[1216,1217],"Versioning","Harness updates can change behaviour even when prompts remain constant",[1219,1220],"Evaluation","Runtime changes need regression testing across representative trajectories",{},{"id":584,"data":1223,"type":42,"tunes":1225},{"text":1224,"level":219},"Security boundary: self-hosting compute does not automatically make the agent private",{},{"id":589,"data":1227,"type":226,"tunes":1229},{"text":1228},"A self-hosted execution environment controls where commands run and where files live, but the managed harness and model interaction still cross the service boundary. Teams should therefore map data flows explicitly rather than use “self-hosted” as shorthand for a privacy property.",{},{"id":594,"data":1231,"type":226,"tunes":1233},{"text":1232},"OpenAI's self-hosted executor uses restricted environment credentials and outbound connections. That is useful isolation, but your application still needs its own rules for secrets, private-network exposure, user-to-environment isolation, file retention, tool authorization and data classification.",{},{"id":599,"data":1235,"type":234,"tunes":1238},{"body":1236,"title":1237,"variant":241},"\u003Cstrong>Infrastructure control, execution isolation and data-governance boundaries are related but not identical.\u003C\u002Fstrong> Decide them separately.","Important distinction",{},{"id":605,"data":1240,"type":42,"tunes":1242},{"text":1241,"level":219},"Latency and cost: control can move bottlenecks rather than remove them",{},{"id":610,"data":1244,"type":226,"tunes":1246},{"text":1245},"Self-hosting may reduce some data-path or environment-startup costs, but it can also add provisioning time, WebSocket lifecycle, cold starts, sandbox cleanup, observability infrastructure and engineering overhead. A managed environment may cost more per unit of compute while being cheaper to operate at low or irregular volume.",{},{"id":615,"data":1248,"type":226,"tunes":1250},{"text":1249},"The correct comparison is total system cost: model and tool usage, environment time, infrastructure, engineering effort, on-call burden, failure recovery and the cost of slower iteration.",{},{"id":620,"data":1252,"type":42,"tunes":1254},{"text":1253,"level":219},"A production decision matrix",{},{"id":625,"data":1256,"type":297,"tunes":1297},{"content":1257,"stretched":43,"withHeadings":14},[1258,1261,1266,1269,1271,1275,1279,1282,1286,1289,1292],[1259,966,971,1260],"Constraint","Self-operated harness \u002F loop",[1262,1263,1264,1265],"Fastest path to production","Strong","Moderate","Weakest",[1267,1268,1263,1263],"Private-network execution","Weak \u002F depends on connectivity design",[1270,1264,1263,1263],"Custom packages \u002F system software",[1272,1273,1273,1274],"Harness-level control","Low","Highest",[1276,1277,1278,1274],"Operational burden","Lowest","Medium",[1280,1277,1278,1281],"Portability","Potentially highest if intentionally designed",[1283,1284,1284,1285],"Context strategy control","Platform-managed","Application-controlled",[1287,1273,1288,1288],"Execution infrastructure control","High",[1290,1274,1274,1291],"Ability to benefit from managed harness updates","You own adoption",[1293,1294,1295,1296],"Best fit","Teams differentiating at product\u002Ftool layer","Teams needing private\u002Fcustom compute without owning orchestration","Teams whose runtime semantics are themselves a requirement",{},{"id":670,"data":1299,"type":42,"tunes":1301},{"text":1300,"level":219},"Hybrid is not a compromise — it is often the clean architecture",{},{"id":675,"data":1303,"type":226,"tunes":1305},{"text":1304},"A managed harness with self-hosted execution is not “half self-hosted.” It is an intentional separation of concerns. The platform owns long-horizon agent-runtime complexity, while your infrastructure owns execution, private connectivity and files.",{},{"id":680,"data":1307,"type":226,"tunes":1309},{"text":1308},"That boundary resembles other cloud architectures: managed control plane, customer-controlled data or execution plane. The important design work is defining the contract between them — session identity, environment identity, credentials, files, tool permissions, lifecycle events and cleanup.",{},{"id":685,"data":1311,"type":691,"tunes":1316},{"url":1312,"title":1313,"excerpt":1314,"ctaLabel":1315},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fopenai-agents-api-vs-agents-sdk-vs-responses-api-what-should-you-build-on-in-2026","OpenAI Agents API vs Agents SDK vs Responses API: What Should You Build On in 2026?","A runtime-ownership comparison of OpenAI's current agent surfaces and where each control boundary belongs.","Read the runtime comparison",{},{"id":694,"data":1318,"type":42,"tunes":1320},{"text":1319,"level":219},"What would change this answer?",{},{"id":699,"data":1322,"type":226,"tunes":1324},{"text":1323},"The recommendation changes if managed harnesses expose substantially more runtime control, if self-hosted harnesses gain simpler durable-session and recovery primitives, or if regulation requires the entire agent loop and model interaction to remain inside infrastructure you operate.",{},{"id":704,"data":1326,"type":226,"tunes":1328},{"text":1327},"It also changes with model capability. Anthropic explicitly notes that harness assumptions can become stale as models improve. A control mechanism that is essential today may become unnecessary later, while a new model capability can create a new governance requirement.",{},{"id":709,"data":1330,"type":42,"tunes":1332},{"text":1331,"level":219},"Limitations",{},{"id":714,"data":1334,"type":226,"tunes":1336},{"text":1335},"This article separates architecture responsibilities; it does not claim that one hosting model is universally more secure, cheaper or more reliable. Those outcomes depend on implementation, workload, compliance requirements, team skill and provider behaviour.",{},{"id":719,"data":1338,"type":226,"tunes":1340},{"text":1339},"The OpenAI Agents API is still in public beta, and managed-agent products from different vendors expose different boundaries. The two-plane model is intended to help compare those architectures without assuming that every vendor uses identical terms.",{},{"id":724,"data":1342,"type":42,"tunes":1344},{"text":1343,"level":219},"Conclusion",{},{"id":729,"data":1346,"type":226,"tunes":1348},{"text":1347},"The useful question is not “Should we self-host the agent?” It is: Which plane do we actually need to control?",{},{"id":734,"data":1350,"type":226,"tunes":1352},{"text":1351},"If the requirement is private compute, custom packages, local files or internal-network access, self-host the execution plane and keep the harness managed. If the requirement is orchestration semantics, context strategy, provider control or runtime lifecycle itself, then harness ownership may be justified. Escalate control only as far as the requirement demands.",{},{"id":739,"data":1354,"type":42,"tunes":1356},{"text":1355,"level":219},"FAQ",{},{"id":744,"data":1358,"type":744,"tunes":1376},{"items":1359,"title":1375},[1360,1363,1366,1369,1372],{"id":748,"answer":1361,"question":1362},"Not completely. OpenAI still runs the managed Codex harness, while your infrastructure runs the execution environment used for commands, files and local tools.","Is an OpenAI Agents API self-hosted environment a self-hosted agent?",{"id":752,"answer":1364,"question":1365},"It is often enough when your requirements concern private-network access, custom packages, controlled files, specific hardware or infrastructure policy rather than control over the agent loop itself.","When is a self-hosted environment enough?",{"id":756,"answer":1367,"question":1368},"Consider harness ownership when you need custom orchestration semantics, custom context management, provider routing, local-only runtime behaviour, or another requirement that lives in the agent loop rather than the execution environment.","When should I run the harness myself?",{"id":760,"answer":1370,"question":1371},"No. It changes which components you control. Security depends on data flow, isolation, credentials, tool permissions, networking, logging and lifecycle design across all components.","Does self-hosting automatically improve security?",{"id":764,"answer":1373,"question":1374},"You become responsible for durable state, context management, retries, cancellation, recovery, observability, concurrency, runtime upgrades and evaluation of harness changes.","What is the main operational cost of owning the agent loop?","Managed harnesses and self-hosted agent runtimes",{},{"id":770,"data":1378,"type":42,"tunes":1380},{"text":1379,"level":219},"Glossary",{},{"id":775,"data":1382,"type":775,"tunes":1400},{"title":1383,"entries":1384},"Key architecture terms",[1385,1387,1389,1392,1395,1398],{"term":988,"anchor":781,"definition":1386},"The agent-runtime layer responsible for loop execution, orchestration, context management, session continuity and recovery.",{"term":991,"anchor":784,"definition":1388},"The environment in which commands run, code executes and files, packages and local resources are accessed.",{"term":1390,"anchor":788,"definition":1391},"Managed harness","An agent harness whose runtime, session management and orchestration are operated by a platform provider.",{"term":1393,"anchor":792,"definition":1394},"Self-hosted environment","Compute and files operated by the application owner while a separate agent harness may remain managed elsewhere.",{"term":1396,"anchor":796,"definition":1397},"Self-operated harness","An agent runtime whose loop, hosting, context strategy and lifecycle are operated by the application team.",{"term":1174,"anchor":799,"definition":1399},"A decision method that increases infrastructure and runtime ownership only when a requirement cannot be satisfied at a lower-control layer.",{},{"id":803,"data":1402,"type":42,"tunes":1404},{"text":1403,"level":219},"Primary sources and further reading",{},{"id":808,"data":1406,"type":815,"tunes":1411},{"link":810,"meta":1407},{"image":1408,"title":1409,"description":1410},{"url":312},"OpenAI — Agents API Architecture","Current separation between the hosted harness, execution environment and application server.",{},{"id":818,"data":1413,"type":815,"tunes":1418},{"link":820,"meta":1414},{"image":1415,"title":1416,"description":1417},{"url":312},"OpenAI — Self-hosted sandboxes","How customer-operated execution environments connect to the managed harness and which lifecycle responsibilities remain with the application.",{},{"id":827,"data":1420,"type":815,"tunes":1425},{"link":829,"meta":1421},{"image":1422,"title":1423,"description":1424},{"url":312},"OpenAI — Sandbox lifecycle","Provisioning, reconnection, duplicate-environment prevention and cleanup responsibilities for self-hosted compute.",{},{"id":836,"data":1427,"type":815,"tunes":1432},{"link":838,"meta":1428},{"image":1429,"title":1430,"description":1431},{"url":312},"OpenAI — Agent runtime options","Current comparison of Agents API, Codex SDK and Responses API by managed versus application-operated responsibilities.",{},{"id":845,"data":1434,"type":815,"tunes":1439},{"link":847,"meta":1435},{"image":1436,"title":1437,"description":1438},{"url":312},"OpenAI — Codex as a platform","Open-source Codex harness and integration layers for applications that want deeper runtime control.",{},{"id":854,"data":1441,"type":815,"tunes":1446},{"link":856,"meta":1442},{"image":1443,"title":1444,"description":1445},{"url":312},"Anthropic — Scaling Managed Agents: Decoupling the brain from the hands","Discussion of managed-agent architecture and why harness assumptions need to evolve with model capability.",{},{"id":863,"data":1448,"type":815,"tunes":1453},{"link":865,"meta":1449},{"image":1450,"title":1451,"description":1452},{"url":312},"Anthropic — Effective harnesses for long-running agents","Engineering lessons showing that long-running agent performance depends materially on harness design and persistent artifacts.",{},"2.31.6","“Self-hosted agent” can mean very different architectures. This guide separates the managed harness, self-hosted execution environment, and fully self-operated agent loop—and shows which control boundary teams actually need.",{"lang":7,"title":208,"content":210,"contentJson":1457,"excerpt":872},{"time":212,"blocks":1458,"version":871},[1459,1462,1465,1468,1471,1474,1477,1480,1483,1486,1489,1497,1500,1514,1517,1520,1523,1526,1531,1534,1537,1540,1550,1553,1556,1559,1562,1565,1570,1573,1576,1579,1592,1595,1598,1609,1612,1615,1618,1632,1635,1638,1641,1644,1647,1650,1653,1656,1671,1674,1677,1680,1683,1686,1689,1692,1695,1698,1701,1704,1707,1710,1713,1722,1725,1735,1738,1743,1748,1753,1758,1763,1768],{"id":215,"data":1460,"type":220,"tunes":1461},{"title":217,"maxLevel":218,"minLevel":219},{},{"id":223,"data":1463,"type":226,"tunes":1464},{"text":225},{},{"id":229,"data":1466,"type":234,"tunes":1467},{"body":231,"title":232,"variant":233},{},{"id":237,"data":1469,"type":234,"tunes":1470},{"body":239,"title":240,"variant":241},{},{"id":244,"data":1472,"type":234,"tunes":1473},{"body":246,"title":247,"variant":244},{},{"id":250,"data":1475,"type":42,"tunes":1476},{"text":252,"level":219},{},{"id":255,"data":1478,"type":226,"tunes":1479},{"text":257},{},{"id":260,"data":1481,"type":226,"tunes":1482},{"text":262},{},{"id":265,"data":1484,"type":226,"tunes":1485},{"text":267},{},{"id":270,"data":1487,"type":42,"tunes":1488},{"text":272,"level":219},{},{"id":275,"data":1490,"type":297,"tunes":1496},{"content":1491,"stretched":43,"withHeadings":14},[1492,1493,1494,1495],[279,280,281,282],[284,285,286,287],[289,285,290,291],[293,294,295,296],{},{"id":300,"data":1498,"type":42,"tunes":1499},{"text":302,"level":219},{},{"id":305,"data":1501,"type":332,"tunes":1513},{"rows":1502,"title":321,"layout":297,"columns":1509},[1503,1505,1507],{"id":309,"label":310,"values":1504},[312,312,312],{"id":314,"label":315,"values":1506},[312,312,312],{"id":318,"label":319,"values":1508},[312,312,312],[1510,1511,1512],{"id":324,"label":325},{"id":327,"label":328},{"id":330,"label":331},{},{"id":335,"data":1515,"type":234,"tunes":1516},{"body":337,"title":338,"variant":339},{},{"id":342,"data":1518,"type":42,"tunes":1519},{"text":344,"level":219},{},{"id":347,"data":1521,"type":226,"tunes":1522},{"text":349},{},{"id":352,"data":1524,"type":226,"tunes":1525},{"text":354},{},{"id":357,"data":1527,"type":368,"tunes":1530},{"meta":1528,"items":1529,"style":367},{},[361,362,363,364,365,366],{},{"id":371,"data":1532,"type":42,"tunes":1533},{"text":373,"level":219},{},{"id":376,"data":1535,"type":226,"tunes":1536},{"text":378},{},{"id":381,"data":1538,"type":226,"tunes":1539},{"text":383},{},{"id":386,"data":1541,"type":297,"tunes":1549},{"content":1542,"stretched":43,"withHeadings":14},[1543,1544,1545,1546,1547,1548],[390,391],[393,394],[396,397],[399,400],[402,403],[405,406],{},{"id":409,"data":1551,"type":42,"tunes":1552},{"text":411,"level":219},{},{"id":414,"data":1554,"type":226,"tunes":1555},{"text":416},{},{"id":419,"data":1557,"type":226,"tunes":1558},{"text":421},{},{"id":424,"data":1560,"type":226,"tunes":1561},{"text":426},{},{"id":429,"data":1563,"type":42,"tunes":1564},{"text":431,"level":218},{},{"id":434,"data":1566,"type":368,"tunes":1569},{"meta":1567,"items":1568,"style":367},{},[438,439,440,441,442,443],{},{"id":446,"data":1571,"type":42,"tunes":1572},{"text":448,"level":219},{},{"id":451,"data":1574,"type":226,"tunes":1575},{"text":453},{},{"id":456,"data":1577,"type":226,"tunes":1578},{"text":458},{},{"id":461,"data":1580,"type":297,"tunes":1591},{"content":1581,"stretched":43,"withHeadings":14},[1582,1583,1584,1585,1586,1587,1588,1589,1590],[465,466,467],[469,470,471],[473,470,289],[475,470,476],[478,479,480],[482,479,483],[485,479,486],[488,479,489],[491,492,493],{},{"id":496,"data":1593,"type":42,"tunes":1594},{"text":498,"level":219},{},{"id":501,"data":1596,"type":226,"tunes":1597},{"text":503},{},{"id":506,"data":1599,"type":531,"tunes":1608},{"steps":1600,"title":498,"orientation":530},[1601,1602,1603,1604,1605,1606,1607],{"label":510,"description":511},{"label":513,"description":514},{"label":516,"description":517},{"label":519,"description":520},{"label":522,"description":523},{"label":525,"description":526},{"label":528,"description":529},{},{"id":534,"data":1610,"type":42,"tunes":1611},{"text":536,"level":219},{},{"id":539,"data":1613,"type":226,"tunes":1614},{"text":541},{},{"id":544,"data":1616,"type":226,"tunes":1617},{"text":546},{},{"id":549,"data":1619,"type":297,"tunes":1631},{"content":1620,"stretched":43,"withHeadings":14},[1621,1622,1623,1624,1625,1626,1627,1628,1629,1630],[553,554],[556,557],[559,560],[562,563],[565,566],[568,569],[571,572],[574,575],[577,578],[580,581],{},{"id":584,"data":1633,"type":42,"tunes":1634},{"text":586,"level":219},{},{"id":589,"data":1636,"type":226,"tunes":1637},{"text":591},{},{"id":594,"data":1639,"type":226,"tunes":1640},{"text":596},{},{"id":599,"data":1642,"type":234,"tunes":1643},{"body":601,"title":602,"variant":241},{},{"id":605,"data":1645,"type":42,"tunes":1646},{"text":607,"level":219},{},{"id":610,"data":1648,"type":226,"tunes":1649},{"text":612},{},{"id":615,"data":1651,"type":226,"tunes":1652},{"text":617},{},{"id":620,"data":1654,"type":42,"tunes":1655},{"text":622,"level":219},{},{"id":625,"data":1657,"type":297,"tunes":1670},{"content":1658,"stretched":43,"withHeadings":14},[1659,1660,1661,1662,1663,1664,1665,1666,1667,1668,1669],[629,630,631,632],[634,635,636,637],[639,640,635,635],[642,636,635,635],[644,645,645,646],[648,649,636,646],[651,649,636,652],[654,655,655,656],[658,645,659,659],[661,646,646,662],[664,665,666,667],{},{"id":670,"data":1672,"type":42,"tunes":1673},{"text":672,"level":219},{},{"id":675,"data":1675,"type":226,"tunes":1676},{"text":677},{},{"id":680,"data":1678,"type":226,"tunes":1679},{"text":682},{},{"id":685,"data":1681,"type":691,"tunes":1682},{"url":687,"title":688,"excerpt":689,"ctaLabel":690},{},{"id":694,"data":1684,"type":42,"tunes":1685},{"text":696,"level":219},{},{"id":699,"data":1687,"type":226,"tunes":1688},{"text":701},{},{"id":704,"data":1690,"type":226,"tunes":1691},{"text":706},{},{"id":709,"data":1693,"type":42,"tunes":1694},{"text":711,"level":219},{},{"id":714,"data":1696,"type":226,"tunes":1697},{"text":716},{},{"id":719,"data":1699,"type":226,"tunes":1700},{"text":721},{},{"id":724,"data":1702,"type":42,"tunes":1703},{"text":726,"level":219},{},{"id":729,"data":1705,"type":226,"tunes":1706},{"text":731},{},{"id":734,"data":1708,"type":226,"tunes":1709},{"text":736},{},{"id":739,"data":1711,"type":42,"tunes":1712},{"text":741,"level":219},{},{"id":744,"data":1714,"type":744,"tunes":1721},{"items":1715,"title":767},[1716,1717,1718,1719,1720],{"id":748,"answer":749,"question":750},{"id":752,"answer":753,"question":754},{"id":756,"answer":757,"question":758},{"id":760,"answer":761,"question":762},{"id":764,"answer":765,"question":766},{},{"id":770,"data":1723,"type":42,"tunes":1724},{"text":772,"level":219},{},{"id":775,"data":1726,"type":775,"tunes":1734},{"title":777,"entries":1727},[1728,1729,1730,1731,1732,1733],{"term":780,"anchor":781,"definition":782},{"term":315,"anchor":784,"definition":785},{"term":787,"anchor":788,"definition":789},{"term":791,"anchor":792,"definition":793},{"term":795,"anchor":796,"definition":797},{"term":498,"anchor":799,"definition":800},{},{"id":803,"data":1736,"type":42,"tunes":1737},{"text":805,"level":219},{},{"id":808,"data":1739,"type":815,"tunes":1742},{"link":810,"meta":1740},{"image":1741,"title":813,"description":814},{"url":312},{},{"id":818,"data":1744,"type":815,"tunes":1747},{"link":820,"meta":1745},{"image":1746,"title":823,"description":824},{"url":312},{},{"id":827,"data":1749,"type":815,"tunes":1752},{"link":829,"meta":1750},{"image":1751,"title":832,"description":833},{"url":312},{},{"id":836,"data":1754,"type":815,"tunes":1757},{"link":838,"meta":1755},{"image":1756,"title":841,"description":842},{"url":312},{},{"id":845,"data":1759,"type":815,"tunes":1762},{"link":847,"meta":1760},{"image":1761,"title":850,"description":851},{"url":312},{},{"id":854,"data":1764,"type":815,"tunes":1767},{"link":856,"meta":1765},{"image":1766,"title":859,"description":860},{"url":312},{},{"id":863,"data":1769,"type":815,"tunes":1772},{"link":865,"meta":1770},{"image":1771,"title":868,"description":869},{"url":312},{},"Post erfolgreich abgerufen",{"items":1775,"source":1817,"manualIds":1818,"manualMatchedIds":1819},[1776,1783,1790,1797,1804,1810],{"id":1777,"slug":1778,"title":1779,"excerpt":1780,"featuredImage":1781,"publishedAt":1782},"455","zbt-z8102ax-dual-sim-failover-test","ZBT Z8102AX 双SIM卡故障切换：有效功能、缺失功能及固件需改进之处","ZBT Z8102AX是一款双SIM卡5G OpenWrt路由器，但仅具备双SIM卡硬件并不等同于智能故障切换。该路由器能识别SIM卡并成功连接，但自动切换、调制解调器恢复、基于信号的决策以及清晰的故障切换逻辑仍需更深入的测试。","\u002Fuploads\u002F2026\u002F06\u002Fopenwrt-router-review-dual-sim-03-1781620592829-7t77j7.webp","2026-06-16T10:40:00.000Z",{"id":1784,"slug":1785,"title":1786,"excerpt":1787,"featuredImage":1788,"publishedAt":1789},"362","suchmaschinen-webcrawler-suchsoftware-und-suchergebnissen","搜索引擎优化：实现顶级排名的可靠工作流程","搜索引擎优化（SEO）的详细分析，包括其技术基础、网络爬虫的作用，以及实现有机搜索排名前列的战略步骤。","\u002Fuploads\u002F2026\u002F03\u002Fsuchmaschinen-webcrawler-suchsoftware-und-suchergebnissen-1774865001795-5wv0cw.webp","2023-04-12T13:03:00.000Z",{"id":1791,"slug":1792,"title":1793,"excerpt":1794,"featuredImage":1795,"publishedAt":1796},"459","ollama-is-not-the-product-building-production-ready-open-llm-applications","Ollama 并非产品：构建可投入生产的开源大语言模型应用","使用Ollama运行本地模型很简单。但构建一个可用于生产环境的开源大语言模型（Open-LLM）应用则更具挑战性：它需要RAG（检索增强生成）、访问控制、供应商抽象、评估、日志记录、部署规范，以及围绕模型构建受控的应用层。","\u002Fuploads\u002F2026\u002F06\u002Follama-is-not-the-product-building-production-ready-open-llm-applications-1782679361640-h0usqf.webp","2026-06-28T16:39:00.000Z",{"id":1798,"slug":1799,"title":1800,"excerpt":1801,"featuredImage":1802,"publishedAt":1803},"364","tipps-fuer-die-verbesserung-der-seo-suchmaschinenoptimierung","Mastering the SEO Workflow: Essential Optimization Strategies for Organic Growth","A structured SEO workflow is crucial for sustainable organic growth. Learn the ten foundational strategies, from keyword research and technical optimization to content quality and performance analysis.","\u002Fuploads\u002F2026\u002F03\u002Ftipps-fuer-die-verbesserung-der-seo-suchmaschinenoptimierung-1774866098131-hwkzrg.webp","2024-01-26T06:35:00.000Z",{"id":1805,"slug":892,"title":1806,"excerpt":1807,"featuredImage":1808,"publishedAt":1809},"434","全面评估指南：精通LLM性能评估","本指南详细介绍了评估工具（Evaluation Harness），这是一个在企业级LLMOps流程中严格评估大型语言模型（LLM）能力的关键框架。您将学习其设置方法、最佳实践以及高级技巧，以确保模型基准测试与优化的可靠性。","\u002Fuploads\u002F2026\u002F04\u002Fevaluation-harness-1775466944495-4s0xv2.webp","2026-03-01T17:50:00.000Z",{"id":1811,"slug":1812,"title":1813,"excerpt":1814,"featuredImage":1815,"publishedAt":1816},"469","rag-failed-but-which-layer-actually-failed-a-diagnostic-method","RAG失败了——但究竟是哪一层真正失败了？一种诊断方法","当RAG答案出错时，将问题归咎于检索或模型过于笼统。这种诊断方法将来源覆盖、查询构建、检索、排序、上下文组装、生成、证据归因和时效性逐一隔离，从而使实际故障能够被复现并修复。","\u002Fuploads\u002F2026\u002F09\u002Frag-failed-but-which-layer-actually-failed-a-diagnostic-method-1790350847177-pior4c.webp","2026-09-24T19:39:00.000Z","fallback",[],[]]