The current seamAcpConfig.stream is runtime-only. Production configuration selects provider and model, then uses NDJSON over stdin and stdout.

Choose the owner before the carrier.

Per request

Simple and disposable, with startup cost and no continuity.

Per tenant

Strong workspace and credential separation with higher process density.

Per trust domain

Share only a reviewed capability and policy boundary.

Shared connection

Efficient, but every Session shares one teardown lifetime.

A gateway owns five contracts.

01supervision

Exact artifact, clean stdout, deadlines, generations, bounded restart.

02correlation

Requests and reverse permissions return to one authenticated owner.

03affinity

Every Session stays on the connection that created it.

04delivery

Declare cancel, replay, or durable job behavior on disconnect.

05teardown

Close admission, drain, cancel at deadline, and verify exit.

Alwaysauthorization

Tenant identity comes from server state, never model or client arguments.

Do not expose raw stdio as an unauthenticated socket.

Use opaque tenant-bound handles, quotas, replay limits, permission expiry, log redaction, and a container-class boundary for untrusted code.

Failure must stay generation-scoped.

A child restart invalidates its Session ids. A malformed stdout frame terminates that generation. A rolling deploy stops admission before drain. No old handle may silently alias a new process.

Primary evidence.

Make ownership explicit.

The complete guide includes topology choices, an identity ledger, five hosting contracts, an HTTP resource model, failure routing, security minimums, and fourteen acceptance tests.

Read the complete guide