dspy.RLM, driven by RLMRunner at src/fleet_rlm/rlm/runner.py. Every Turn starts clean, sees a bounded slice of context, and decides its next step against a fixed delegation ladder.
One Turn, one native RLM
RLMRunner constructs a fresh dspy.RLM for the Turn. There is no long-lived Agent, no ReAct wrapper, and no ambient AgentRuntime state. Turn state lives on the coordinator, and RLM state exists only for the length of that Turn.
The runner composes three inputs before it calls dspy.RLM.acall():
- A Signature describing the Turn’s input and output contract.
- A default instruction fragment set assembled from
src/fleet_rlm/rlm/instructions.py. - A fixed core Tool inventory plus
load_skillandread_skill_resource.
Bounded Signature
Every Signature receives the user request text, a boundedsession_context, bounded skill_cards, and bounded Attachment metadata. Full committed history stays host-side and is reached through the read_session_history Tool.
Instruction composition
src/fleet_rlm/rlm/instructions.py owns the default Fleet Root instruction fragments. The runner composes:
- The base Root fragment.
- REPL guidance for Python execution.
- Tool inventory guidance for the fixed core Tools.
- Optional recursion guidance when the profile enables
rlm_queryandrlm_query_batched. - Verification guidance for evidence review before
SUBMIT. - Bounded-context guidance for
session_context,skill_cards, and Attachments.
Root delegation ladder
The Root selects the cheapest sufficient step for each subproblem. Higher rungs cost more and see more.
The Root always verifies and synthesizes evidence from rung 4 before it emits
SUBMIT.
Skills and progressive disclosure
The bundled Skill catalog isdspy-rlm, long-context, workspace-files, data-analysis, and report-builder. Only bounded Skill Cards appear at startup. A full SKILL.md loads only when the RLM invokes load_skill or when the card is exactly preselected. Declared resources load only after the Skill body.
Without explicit selections the RLM sees the full bundled catalog and may load up to four advertised Skills during the Turn. Explicit skill_selections accept up to four unique entries of {id, expected_version}. Selections advertise, preload, and restrict the Turn to authorized cards. Selections fold into the Turn idempotency fingerprint.
Only data-analysis supplies a custom validated DSPy Signature. report-builder and dspy-rlm are instruction-only. At most one selected Skill may provide a validated DSPy Signature.
Skill Markdown and resources cannot register host Tools. Runtime composition owns the fixed core Tools plus exactly load_skill and read_skill_resource.
Recursive children
RLM_NATIVE_CHILD_DEPTH = 1 is a fixed product invariant. It is not an editable policy value. Recursion is one native level deep.
The daytona-recursive profile enables recursion. The default daytona profile keeps recursion disabled. When enabled, each child receives:
- A fresh Daytona Sandbox with ordinary Daytona egress.
- The same Volume ID mounted at
recursive/<workspace-id>/<run-id>/<call-index>. - No access to the Root
workspaces/<workspace-id>mount. - No Fleet Tools and no host credentials.
recursion_max_parallel_children, which defaults to 2.
See Recursive RLM for the full child lifecycle.
Autonomous memory (opt-in)
rlm.autonomous_memory_categories = [] is the default. When the allowlist is empty the runtime omits propose_memory from the Root Tool inventory entirely.
A non-empty allowlist enables a Root-only, Run-scoped candidate collector. Promotion runs post-commit on a best-effort basis. Promotion is never exactly-once, and callers should treat it as advisory.
Configuration
Model, provider, token, and recursion policy all live inconfig/fleet.toml under the selected profile. Models come from provider-service references, not from environment variables like DSPY_LM_MODEL.
See Configuration for the full profile schema.
See also
Recursive RLM
Child harness lifecycle, sibling fan-out, and evidence synthesis.
Daytona runtime
Sandbox lifecycle, Volume Scope, and workspace mounts.
HTTP API
Turn endpoints, SSE stream, and Attachment upload.
Configuration
Profiles, providers, recursion, and memory policy.