DigitalOcean Managed Agents: MicroVM Runtime and 16,000-Tool Gateway

October 4, 2026 • news
AI AgentsMCPDevOps

DigitalOcean has launched Managed Agents in public preview, combining two integrated services — a Harness Runtime and an Action Gateway — into a managed deployment layer purpose-built for agentic workloads. The launch targets a concrete operational gap: developers running agents on conventional VMs today must hand-roll context persistence, artifact storage, parallel coordination, spare capacity management, and security-hardened tool access themselves, according to DigitalOcean. Managed Agents moves that plumbing into the platform layer.

Where infrastructure governance rather than model-level guardrails determines safe agent deployment, a managed runtime that enforces isolation and permission boundaries at the infrastructure level is architecturally more defensible than application-level controls bolted onto shared compute.

Harness Runtime: microVM isolation with session lifecycle management

The Harness Runtime provisions lightweight microVMs per agent session, providing isolated compute and storage that developers connect to internal services without public exposure. Each session maintains conversational history and working state across pauses, resumes, and forks — a design that directly addresses the statelessness problem agents encounter on conventional cloud VMs.

Supported harnesses at launch include coding agents (Claude Code, Codex CLI, OpenCode), the general-purpose Hermes agent, and custom agents built with LangGraph. Sessions automatically pause when idle — defined as no active LLM or tool calls — which, as InfoQ reporter Sergio De Simone notes, is a key cost-containment mechanism. The runtime also supports parallel session launching across repositories and tasks, enabling divide-and-conquer, map/reduce, and multi-agent collaboration patterns without the developer managing inter-session coordination.

Action Gateway: governed tool access at scale

The Action Gateway presents a unified MCP endpoint giving agents access to more than 16,000 tools, per DigitalOcean. Integrations span Web Search, Web Fetch, Browser Automation, DigitalOcean's own infrastructure management APIs, and connectors for platforms including GitHub, HubSpot, and Stripe. The gateway enforces centralized permission management — specifying which tools and actions each agent may invoke — and gates sensitive operations behind a human-approval step. Rate limiting, retries, backoff, and timeouts are handled by the gateway rather than delegated to application code, which matters when multiple agents are concurrently hitting the same external systems.

This is the architectural layer that most directly addresses the shared-surface attack vectors that undermine agent security: tool access is governed at infrastructure level, not by prompts or application logic that an adversarial input might override.

Managed Agents vs. Docker Cloud Sandboxes

As InfoQ's De Simone reports, DigitalOcean Managed Agents arrive around the same time as Docker's Cloud Sandboxes, with overlapping capabilities at the sandbox and runtime layers. Both offer microVM isolation and state persistence, but differ in primary orientation.

Dimension DigitalOcean Managed Agents Docker Cloud Sandboxes
Isolation mechanism MicroVM per session MicroVM
State persistence Conversational history + artifacts across pause/resume/fork Persistent sandbox state
Primary focus Production agent infrastructure and orchestration Developer workflows; local-to-cloud sandbox mobility
Tool access layer Action Gateway: 16,000+ tools via unified MCP endpoint Not reported
Permission governance Centralized per-agent tool/action policies; human approval gate Not reported
Availability Public preview Not reported

AI Mastery analysis

The architectural split between Harness Runtime and Action Gateway creates two distinct control planes — useful for auditing and for applying different security policies to different agent classes, but also two surfaces that must stay synchronized in production. If an agent's permission set changes in the gateway, sessions already in flight need a coherent policy on whether those changes apply mid-session or only on restart. DigitalOcean's announcement does not address this consistency boundary, which matters for long-lived or forked sessions against external APIs where permissions might be revoked.

The idle-pause mechanism is the feature most likely to determine real-world economics. Agents frequently block on LLM responses or external API latency, and billing for that wall-clock time on standard VMs is a meaningful cost driver. Seaotter platform architect and founder Ryan Martin, quoted by InfoQ's De Simone, put it directly: "Pause-when-idle + governed tools is the ops pattern that scales." Its value depends entirely on the billing granularity DigitalOcean applies, which has not been disclosed for the public preview.

The 16,000-tool figure for the Action Gateway is large enough to be operationally unwieldy without strong discovery and scoping primitives. Centralized permission management is necessary but not sufficient; teams will need tooling to audit which permissions are actually exercised versus merely granted — mirroring the least-privilege enforcement challenge that production AI systems regularly fail to implement at the architecture layer.

DigitalOcean's positioning is a bet that the developer-cloud market is ready to offload agent infrastructure the same way it offloaded managed databases and Kubernetes control planes. For teams currently stitching together agent runtimes from raw VMs, object storage, and custom retry logic, that trade is worth evaluating even at public-preview maturity. The more durable signal is that infrastructure vendors are now treating agent lifecycle management — pause, resume, fork, governed tool call — as a first-class primitive, not an application-layer concern.

Sources

Frequently asked questions

What two services make up DigitalOcean Managed Agents?

Managed Agents combines a Harness Runtime and an Action Gateway. The Harness Runtime provides isolated microVM compute environments per agent session, while the Action Gateway exposes more than 16,000 tools through a unified MCP endpoint with centralized permission management.

Which agent frameworks does the Harness Runtime support at launch?

At launch, supported harnesses include coding agents Claude Code, Codex CLI, and OpenCode; the general-purpose Hermes agent; and custom agents built with LangGraph. Sessions can be paused, resumed, or forked, and automatically pause when there are no active LLM or tool calls.

What tools and integrations does the Action Gateway provide?

The Action Gateway provides access to more than 16,000 tools via a unified MCP endpoint, per DigitalOcean. Integrations include Web Search, Web Fetch, Browser Automation, DigitalOcean's own infrastructure management APIs, and connectors for GitHub, HubSpot, and Stripe.

How does DigitalOcean Managed Agents differ from Docker Cloud Sandboxes?

As InfoQ's Sergio De Simone reports, both offer microVM isolation and state persistence, but Docker Cloud Sandboxes focus on developer workflows and local-to-cloud sandbox mobility, while DigitalOcean Managed Agents target production infrastructure with broader orchestration and tool support. Docker Cloud Sandboxes' permission governance and tool-access layer were not reported.

What is the idle-pause mechanism in the Harness Runtime, and why does it matter for cost?

Sessions automatically pause when there are no active LLM or tool calls. As Seaotter platform architect and founder Ryan Martin noted (quoted by InfoQ's De Simone), 'Pause-when-idle + governed tools is the ops pattern that scales' — billing for wall-clock idle time on standard VMs is a meaningful cost driver for agent workloads, though DigitalOcean has not disclosed billing granularity for the public preview.

Free interactive tools for the decisions this piece raises.

Related Reading