Durable execution
View MarkdownBeta: this feature may change before general availability
An agent run is recorded as it goes. Each effect it has is a step: creating its sandbox, choosing a model for a prompt, each model call and each command in the sandbox. Nodus stores the result of every step the first time it runs. If Nodus restarts, or a machine fails, the run is picked up again and replays from the top: every step that was recorded returns its stored result, and the run continues with the first step that was not.
What this guarantees
Section titled “What this guarantees”- A recorded step never runs again for the same run: no second model call, no second command, no second charge.
- Pure and idempotent steps can retry after an interruption. Nodus model calls reuse their inference key.
- An interrupted sandbox command or model call using your own key can have an uncertain outcome. Its run parks
in
Waitingwith reasonNeedsResolutioninstead of repeating the effect. - A run is picked up again by one dispatcher at a time. If two start, one stops without writing.
- A run that reaches a different step than the one recorded at the same position fails with
NonDeterministicReplay, and its record stays readable.
What survives a restart
Section titled “What survives a restart”The run’s conversation, its answer so far and its status survive, because they come from the recorded steps. The sandbox’s files are not part of the record. If a sandbox is lost, the run creates a new one from the agent’s image and the files are not restored, so keep what must outlive a sandbox in the run’s answer.
The determinism contract
Section titled “The determinism contract”Code that runs between steps must give the same result for the same inputs and step results. Clock reads, random numbers and network calls belong inside steps. Agents on Nodus’s Claude follow this for you: the loop that runs the model and its commands is Nodus’s.
Where the record lives
Section titled “Where the record lives”Step results are encrypted with your organisation’s key. A run’s recorded payloads expire 30 days after it ends; its status, its cost and its step list stay.
When an external outcome is uncertain
Section titled “When an external outcome is uncertain”Inspect the run’s steps and the affected files or external system before starting replacement work. A Started
step means the intent was saved but its outcome was not recorded; it does not prove the command failed or succeeded.
Sending another message does not resume this run. Cancel it with nodus cancel agentrun/<name> to release its
sandbox. The sandbox can continue billing while the run waits. A configured deadline still ends the run.
The managed step-resolution API is not available yet. Do not treat a new run as a safe retry until you have checked the earlier effect.