introspection-harbor
Harbor installed-agent adapter for Introspection Recipes. Install it through
introspection setup --target harbor, then run a task through:
introspection eval run --runner harbor --path evals/refund-task
Select an inherited Recipe agent variant by its declared YAML name:
introspection eval run --runner harbor --path evals/refund-task --agent agent2
The selected agent YAML is the only source of the evaluated model; the CLI and adapter do not apply a separate model override.
What the adapter does
The trial image is the Runtime image the Data Plane published for the Recipe,
so the Recipe (/opt/introspection/recipe), Pi, the Recipes extension, and the
Introspection CLI are already inside it. The adapter installs nothing. Per
trial it:
-
writes a
pilauncher for the image's own Pi when the image has none onPATH(the Operator image already provides one); -
uploads the Harbor instruction, or the CLI-selected replay prompt, as a prompt file and runs the baked Recipe:
pi --recipe /opt/introspection/recipe \ --print --mode json --approve \ @/tmp/introspection-eval-prompt.md
A production-conversation replay runs the same command through
introspection local --replay-context, which creates the temporary native Pi session immediately before Pi starts; -
captures Pi's JSON event stream as
pi.jsonlunder the agent log directory and converts it intotrajectory.json(ATIF) with token usage, cost, and the observed model, whichintrospection eval runverifies against the agent YAML.
Recipe source is never uploaded, patched, or dependency-installed inside the trial. Test a changed Recipe by publishing it as a new Runtime version.
E2B through scoped Data Plane egress
Operator can use E2B without receiving a real E2B, OpenAI, or Anthropic key.
Configure E2B in the Data Plane's sandbox_providers; weight: 0 keeps it out
of normal traffic while allowing an explicitly pinned Operator task to use it.
Then select the Introspection environment class in the arguments forwarded to
Harbor, naming the Runtime's published template:
introspection eval run --runner harbor --path evals/refund-task -- \
--env introspection_harbor.environment:IntrospectionE2BEnvironment \
--environment-kwarg "template_name=$(introspection runtimes get "$RUNTIME_ID" \
--query image_build_metadata.external_image_name -o json | jq -r .)"
Harbor's native E2B implementation still owns preflight, sandbox creation, resources, and networking. The adapter only:
- skips Harbor's template build when
template_namenames a published Runtime template, and defaults the task workdir to the baked Recipe; - copies the scoped public-egress contract (
INTROSPECTION_TOKEN,INTROSPECTION_PUBLIC_EGRESS_URLas the trial'sINTROSPECTION_EGRESS_URL,INTROSPECTION_ENDPOINT_HOSTS, andINTROSPECTION_RELAY_TARGETwhen set) into the trial through Harbor's supportedpersistent_envinput. A template snapshot carries no session state, so this is the only way the baked Pi learns where its egress is. The Data Plane exchanges the locator for credentials at egress; model provider keys never enter the trial; - forwards the host variables named in
INTROSPECTION_HARBOR_PASSTHROUGH_ENV(comma-separated) for direct, non-egress runs such as a laptop trial with a developer's own provider key.
The platform Operator image sets
INTROSPECTION_HARBOR_ENVIRONMENT=introspection_harbor.environment:IntrospectionE2BEnvironment.
When the variable is set, introspection eval run supplies that environment to
Harbor unless the caller explicitly passes --env or -e. Ordinary developer
installs leave it unset, so the same command keeps Harbor's local Docker default.
When none of the three Introspection egress variables are set, the same class adds no egress configuration and Harbor uses E2B's normal environment and credentials. A partial egress contract is rejected rather than silently mixing direct and routed traffic.
Where this is heading
The adapter has two seams: how the Recipe is launched (run) and how the
result is collected (populate_context_post_run). Today the launch executes Pi
inside a Harbor-owned sandbox and the result is read back from that sandbox as
pi.jsonl. A bare pi process exports no telemetry, so nothing from a trial
reaches the platform's conversation store.
The intended end state keeps Harbor as the trial orchestrator but moves both seams onto the platform: the launch becomes a task on the Runtime, and the result is read from that task's conversation and judgement events, which the Runtime already exports. That removes the direct E2B dependency and the file-based verifier from the path, and a Recipe judge becomes the reward.
End-to-end MCP example
recipe-harbor-mcp-agent
runs a Harbor trial in E2B against a published Runtime whose Recipe calls an
authenticated MCP server. See that repository's README for the setup and the
scripts/run-e2b.sh helper.
Metadata
Release files for introspection-harbor 0.4.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| introspection_harbor-0.4.7.tar.gz | 164.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| introspection_harbor-0.4.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 177.3 kB
Release files / introspection_harbor-0.4.7.tar.gz
| Download URL | introspection_harbor-0.4.7.tar.gz |
|---|---|
| Size | 164.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
57168b0c78499365b4796d3257a0599030ee4e31085d88c0e401394e900001fe
|
|
BLAKE2b-256 checksum How to use checksums |
55aaf7233f63959372efb40f55f6f64b562b02702a25cb02be0e1bcad499c523
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency logRelease files / introspection_harbor-0.4.7-py3-none-any.whl
| Download URL | introspection_harbor-0.4.7-py3-none-any.whl |
|---|---|
| Size | 12.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9e5efd63764d59558be661c600bec0d4ba47e2440de43ef8bde50f590283d2cd
|
|
BLAKE2b-256 checksum How to use checksums |
d343579f6973c1b1ebeeebbc89666299e726b848f79db27d19f16202ee65e9ba
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency log