Cove: The Local AI Agent Runtime That Treats Every Thread Like a Living Process

A deep dive into the warm pool, session durability, Markdown memory, and approval gates that turn stateless model calls into inspectable, stateful agent sessions.

8 min read • View on GitHub • More from mhingston

A wide desk scene shows a chat thread on a laptop connected by a physical line to a glass container pod, with files, a SQLite cylinder, and an approval stamp nearby. It explains that the agent session lives in a local workspace instead of floating as a disposable prompt.
Cove's core idea is not chat. It is continuity. A thread points to a container, a filesystem, and a local record of state that can be revisited later.
Key Takeaways

Most agent products start with the model and work backward. Cove starts with the workspace. The thread, the filesystem, the container, and the approval gate are the real product. The chat interface is just the front door.

That shift matters because it changes the unit of continuity. In a normal assistant, context lives in prompts and transcripts. In Cove, context lives in a local runtime that can sleep, wake up, and keep its shape.

Why Cove Feels More Like a Runtime Than a Chat App

Cove maps a conversation thread to a persistent session, then binds that session to a container and a host-side directory. The result is simple to describe and easy to miss: when you come back, you are not reconstructing an agent. You are re-entering one.

That makes the system feel closer to a small operating environment than a chatbot. The model is still central, but it no longer owns the whole experience. The runtime does.

The Session Is the Product

This is the backbone: a thread becomes a session, a session becomes a container, and the container keeps a filesystem and local state that survive beyond one turn.

The simplest way to read the architecture is as a chain: thread_id to session to container to session file to SQLite. That chain is what makes a return visit meaningful. The agent does not rebuild its world from scratch each time.

This is also why the system is inspectable. The session is not hidden in a vendor blob. It is visible as a local object with a directory, a database record, and a running process attached to it.

How the Warm Pool Cheats Cold Start

A close-up view shows several pre-warmed containers sitting on a rack like charged batteries. One container is being relabeled for a named session while a clock hand barely moves, illustrating how adoption avoids startup delay.
The warm pool is the clever part. A generic running container is claimed, relabeled, and turned into a named session without paying the full startup tax.

This is the move that makes Cove feel responsive. Instead of spawning a new container every time a session wakes up, it keeps a pool of ready ones on hand. When a request lands, a warm container can be adopted into the session quickly.

ProblemCold start modelCove's warm pool
Latency on resumeContainer startup slows the first turnA pre-spawned container is already waiting
Session bindingA new process must be assembledA running container is adopted into a named session
Operator experienceFeels like booting a toolFeels like reopening a workspace
System costEvery request pays setup overheadSetup is amortized across ready capacity

That design does not remove complexity. It just moves it to a place where the latency cost is predictable. For a local operator, that trade-off is often worth it because the first-token experience becomes usable instead of awkward.

Cove's Memory Is a Folder You Can Open

The memory layer is intentionally boring in the best way. Markdown-backed knowledge and SQLite persistence make the agent's state something you can open, edit, diff, and back up with normal tools. That is a much stronger story than a hidden memory service.

The important consequence is trust. If an agent remembers the wrong thing, you do not have to file a ticket into an opaque platform. You can inspect the file, change the note, and keep moving. Memory becomes a workspace artifact, not a mystery.

Memory approachWhat you can inspectWho owns the edits
Opaque vendor memoryUsually nothing beyond chat historyThe platform
Vector store behind an APIIndex behavior, not the content shapeThe application
Markdown plus SQLiteThe actual notes and recordsThe operator

That is especially appealing for developers who already think in files. A folder of Markdown is not fashionable. It is legible. And legibility is a feature when the thing doing the remembering can also execute commands.

The API Is a Bridge, Not the Brain

The OpenAI-compatible layer is useful because it lowers the adoption barrier. Existing clients can talk to Cove without learning a new shape. But that surface should not be mistaken for the architecture itself.

Under the hood, the proxy materializes transcript context, injects persona settings, and routes execution into the local session. The interface looks familiar. The execution model is the point.

Approvals Are the Real Safety Valve

Local autonomy sounds great until the agent gets shell access and starts acting faster than you can read. Cove answers that with an approval gate. It gives the human a chance to pause execution before a sensitive action lands.

That is the right instinct for this category. If you are going to give an agent a filesystem, credentials, and process-level reach, you need a governance layer that is lighter than policy theater and stronger than hope.

Safety modelStrengthWeakness
No approvalsFast and frictionlessEasy to regret
Manual review on every actionVery safeToo slow for real work
Targeted approval gatesBalanced controlStill requires attention

Cove is not trying to make danger disappear. It is trying to make danger visible enough that a single operator can manage it. That is a practical safety model, not a decorative one.

What Cove Replaces, and What It Does Not

Cove is a strong fit for people who want ownership of the agent's memory, workspace, and execution boundary. It is not trying to be the biggest cloud platform or the most abstract orchestration framework. It is optimizing for control, visibility, and local durability.

AlternativeWhat it optimizes forWhat Cove does differently
Hosted assistantsConvenience and managed infrastructureKeeps state and execution local
Generic orchestration frameworksComposable workflowsMakes the session itself durable
Ephemeral chat appsLow-friction conversationTurns a thread into a persistent process

That makes the trade-off clear. Cove asks you to carry the operational burden of containers, SQLite, and approvals. In return, you get something far more interesting than a chat app: a local runtime you can understand, resume, and inspect.