Lilith.
⌕
Editorial illustration: Stacklok moves agents from laptops to Kubernetes, along with enterprise control
Lilith illustration · editorial remix

Stacklok wants to move the agent loop out of a single laptop process and into infrastructure an enterprise can operate. Its open source Mecatl project separates the client, model provider, state store and environment used for sensitive tool execution.

Mecatl breaks the desktop agent into cloud services

The company is led by Kubernetes co-creators Craig McLuckie and Joe Beda. Mecatl, an open source project started in June, keeps the agent loop separate from memory, session state, tool calling and shell commands. State no longer has to remain in JSONL files on a local disk, while sensitive operations can run in a distinct managed environment.

Stacklok already offers ToolHive for operating and governing MCP servers locally or on Kubernetes. It adds an AI Gateway for access control, budgets, reporting and provider routing. The gateway is not yet open source, and the company says it does not currently select a model according to the task.

Platform teams gain the same levers they use for other services

A desktop agent combines code, context, permissions and state in a place that is difficult to govern centrally. A cloud architecture can assign workload identity, restrict tools, log calls and safely pause an agent while it waits for human input. That operational discipline is the main product, not the chat window.

For enterprises already running Kubernetes, the pitch is familiar. An agent can become another workload under existing controls instead of an exception on an employee laptop. Stacklok is also replaying an old cloud strategy: decouple the application from a particular hyperscaler and frontier lab.

Kubernetes can manage execution, but not agent judgment

Mecatl can improve lifecycle management, audit and isolation, but it cannot guarantee sound planning or safe model output. A centrally managed error is still an error, even with better logs. Enterprises must also decide who can change prompts, policies, tools and the data available to an agent.

The business model rests on an enterprise control plane that connects the open source parts through identity, authorization, policy and audit. Stacklok raised a $17.5 million Series A in 2023, then shifted from software supply chain security toward agent infrastructure. That signals an experienced team, but also a product direction that is still settling.

The real test begins across multiple clusters and clouds

A small team can run the open source components relatively easily. Stacklok argues that the hard part arrives across multiple clusters and clouds, where identities, versions, policies and accountability diverge. That is where the decoupled architecture must prove it reduces operational friction.

The useful signals will be recovery of long sessions after failure, safe pauses for a person's decision, the quality of audit trails and portability between model providers. If those scenarios work without bypassing the platform team, the harness starts to look like infrastructure. If they do not, it is another complex layer beneath a still fragile agent.

Lilith's verdict

Stacklok wants to move agents out of an employee's backpack and into the platform team's control room. Cloud will mean more than a longer cable to the model only when a run can be safely paused, traced and restored.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗