A workspace is a machine, not a tab.
Everything in smedja hangs off one object. Understand the workspace and the rest of the product explains itself.
A template names the checkouts, the setup scripts and the size. The workspace lands on a managed runtime or on one of your own.
Setup clones and installs; the agent works in a real shell. Read the transcript as it happens — in the browser, the terminal or on your phone.
The CPU and memory are released and the disk stays. Resume and the working tree is untouched. Idle workspaces pause themselves.
Put away, reversibly. Conversations are kept and searchable — even after the disk itself is wiped.
Runtimes you can reason about
Managed runtimes are this deployment's machines. Your own is a launcher you start on a Linux computer with smedja launcher up, or an agent you install in a Kubernetes cluster you run. Which one a workspace got is on its own page, always.
- Link a launcher to a project, and that project's workspaces can run on your hardware.
- On a Docker launcher a workspace gets a network of its own, and cannot reach your LAN or your tailnet.
- Every workspace is sized by a resource class, with nested Docker where the runtime supports it.
- Set an idle window to pause on, or a lifetime after which a workspace archives itself.
The CLI is the whole product
The web app is one client. The terminal, scripts and agents inside workspaces use the same operations with the same permissions — and smedja mcp hands them to your own agents too.
Templates carry the setup
An image script runs once when the image is built, a startup script on first launch, a connect script every time. Standing instructions and skills go to every agent that works there.
Optimised launches
Optimise a template and smedja builds its setup once, captures the disk, and starts later workspaces from it instead of repeating the work.
Agents that write to each other
Every conversation has an address. Agents in a project can write to each other and people in it can write to any of them; anything further takes a share or a grant.
Services, published
A port a workspace declares gets its own URL. Requests are authorised by smedja and carried in over the workspace's own connection; the workspace accepts no inbound connection at all.
Governance that is quiet until it matters
Absent, not greyed
If your role cannot do it, the control is not there. No dead buttons to hover over for an explanation.
Sponsorship, tracked
Every workspace has someone whose accounts it uses. Remove that person and their workspaces pause with the reason attached, until a project admin takes them over.
One audit trail
Launches, pauses, membership changes and removals land in one log, readable from the CLI.