RepoDaily · 2026-08-26 · Infrastructure / Runtime

Apache Maka (Incubating): A Local-First Agent Workspace That Treats the Run Record as the Product

#14 Infrastructure / Runtime TypeScript +538 apache/maka Open repository

An Apache Incubating TypeScript desktop agent that runs tools through one Runtime Host and stores messages, tool calls, and permission decisions as an append-only log on your own machine.

Repo typeInfrastructure / Runtime
Best formacOS Apple Silicon developers who want every model turn, tool call, and permission decision recorded locally in an append-only log
Risk levelMedium: incubating status, early macOS-first release, and breaking changes in the unreleased 0.2.0 line
Time to evaluateHalf a day — clone, npm install at the repo root, npm run build, run one session, then inspect what the ledger captured

Primary question: Is a recoverable, local audit log of agent execution worth more to you than cross-platform maturity today?

91/100

RepoDaily adoption score

RepoDaily rates this as 91/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.

Directional score from RepoDaily sources and adoption notes, not a benchmark.Risk: Medium
100Evidence quality

6 source(s) across 4 source category/categories, plus a RepoDaily-specific evidence module when available.

100Installability

6 workflow step(s), 5 next-action step(s), and 4 command/install signal(s) were detected.

64Maintenance confidence

Trending momentum is +538 stars, with maintenance/release/issue signals counted when present.

96Production readiness

Risk is marked medium, with 6 security note(s) and 4 explicit skip condition(s).

100Differentiation

3 opportunity lens item(s), 4 alternative(s), and 4 type-specific section(s) support differentiation.

68License clarity

License source or license wording is present.

90Agent / AI fit

7 AI/agent-related signal(s) were detected in the article text and metadata.

Project overview

Apache Maka (Incubating) sits at trending rank 14 with 538 stars in this period, and its pitch is unusually concrete for agent tooling: a local-first Agent workspace, written in TypeScript, that inspects projects, runs tools under a sandbox boundary, and records model messages and tool calls as recoverable execution facts — on your machine, through one Runtime Host. Sessions, settings, and run records stay local by default, and you bring the model: a cloud API, a local model, or a compatible gateway.

The design decision that separates Maka from chat-shaped assistants is the record itself. Model messages, tool calls, tool results, permission decisions, and termination events are all written to an append-only log; the UI and the next model call are views of that record, not the only copy. Compaction therefore shortens context without deleting history — the unreleased 0.2.0 line reads model-visible archive placeholders back on demand through bounded ArchiveRead calls instead of eager hydration, so old tool output leaves the prompt but not the evidence.

The second pillar is Runtime Host. Desktop, the terminal, and Maka evaluation all go through it, and the Eval kernel owns only the experiment and its scores. The 0.1.11 release (2026-08-18) expanded Runtime Host from a local execution service into the shared authority for multiple connected Hosts, remote project registration, live run state, and archived session lifecycle, tracked in issues #3097, #3145, #3079, #3074, and #3151. The same release added an installable Maka CLI package with a protected staged npm release pipeline plus cross-platform artifact checks, and brokered Windows AppContainer sandbox support with tighter local IPC ACL enforcement.

Maturity is the honest caveat. The README states the macOS Apple Silicon desktop build is an early public release and that data formats, CLI commands, and experimental capabilities may still change. Windows ships as an unsigned preview, and the Linux badge reads: not yet supported. The project is Apache-2.0 licensed and undergoing incubation at the ASF under the Apache Incubator PMC, which means it has not yet been fully endorsed by the Foundation; DISCLAIMER-WIP records the issues the project already knows about.

Problem it solves

  • Agent transcripts usually live only in the UI: close the window and the reasoning, tool output, and failure cause are gone
  • Context compaction trades evidence for tokens; once old tool results are dropped from history, they cannot be re-read when a bug resurfaces
  • Permission decisions are ephemeral in most assistants — there is no durable answer to who approved which tool call and when
  • Desktop apps, terminal agents, and benchmark harnesses each implement their own execution loop, so behavior and scores drift between surfaces

How it works

  1. Bring a model: cloud API, local model, or a compatible gateway; Maka keeps sessions, settings, and run records local by default
  2. The agent process is the Electron main process plus @maka/core, @maka/runtime, @maka/storage, @maka/ui, builtin tools, and user skills
  3. Every tool call is evaluated by the permission engine at @maka/core/permission against PERMISSION_MODES, TOOL_CATEGORIES, and PERMISSION_POLICY; ask is the default per-session mode
  4. Model messages, tool calls, tool results, permission decisions, and termination events are appended to the run record — the UI and the next model call read from it
  5. When context grows, a Runtime-owned policy prunes old tool output from the next prompt; the 0.2.0 line reads archives back through bounded ArchiveRead calls instead of eager hydration
  6. Desktop, the TUI, and Maka evaluation all connect through Runtime Host; the Eval kernel owns only the experiment and its scores

Architecture read: Runtime Host as the single owner

docs/README.md calls itself the authority map for Maka documentation and warns that code and contract tests remain the final authority when documentation disagrees with the implementation. From that map, the load-bearing pieces are ARCHITECTURE.md for the backend, apps/desktop/README.md and the renderer README for the Electron shell, packages/runtime for the Runtime package, and packages/eval for the evaluation kernel. Runtime Host sits at the center: desktop, terminal, and eval all speak to it, which is what makes one run record portable across surfaces. Adjacent contracts cover runtime resume (architecture/runtime-resume-architecture.md), remote Host setup (runtime-host-remote-access.md), the Work Board (work-board-contract.md), and Agent Swarm (agent-swarm.md).

Internally the shell is consolidating. The unreleased 0.2.0 collapses the RuntimeRunner/Flow/Invocation shell into a single RuntimeKernel — one production owner for backend dispatch, terminal coalescing, stop/drain, and durable continuation admission — while immutable request snapshots stay enforced at AgentRun acceptance and backend dispatch. Typed request() becomes the sole direct Runtime Host operation API, and the 17 forwarding aliases are removed from direct and reconnecting connections. Anyone integrating against the current API should target request(), not the aliases.

Command surface: build steps, TUI navigation, and environment switches

  • Build from source: git clone https://github.com/apache/maka.git, then npm install at the repository root only — CONTRIBUTING.md says never inside a workspace — then npm run build, which builds every workspace in dependency order
  • Toolchain requirements come from the root package.json: Node >=22.19.0 and npm 11.19.0; desktop work additionally needs macOS Apple Silicon
  • In the TUI, /transcript browses long sessions without depending on terminal scrollback, with line, page, and first/last navigation (added in the 0.2.0 line)
  • MAKA_CONTEXT_* environment overrides are ignored after upgrade: compaction and Tool Result pruning can no longer be tuned or disabled, Tool Result pruning set to off is re-enabled, and there is currently no supported replacement opt-out
  • On native Windows and Windows Terminal, taskbar-progress keepalives are disabled by default because repeated OSC 9;4 updates can make Explorer's taskbar unresponsive; MAKA_TASKBAR_PROGRESS=1 re-enables them
  • CLI/TUI distribution and the npm release path are governed by docs/cli-distribution.md and docs/cli-npm-release.md per the docs map

Maintenance risk: incubating, macOS-first, contract in motion

  • The README carries both an ASF incubation disclaimer (not yet fully endorsed by the ASF) and a note that the macOS Apple Silicon build is an early public release whose data formats, CLI commands, and experimental capabilities may still change
  • Platform badges: macOS arm64 released, Windows unsigned preview (baseline defined in docs/windows-support.md), Linux not yet supported
  • 0.1.11 (2026-08-18) is the newest tagged release; 0.2.0 is unreleased and already removes 17 Runtime Host forwarding aliases and re-enables Tool Result pruning with no opt-out
  • Governance is real but young: every PR to main needs an approving committer review plus a passing test check, enforced by .asf.yaml branch protection, and project direction is discussed on [email protected]
  • CONTRIBUTING.md requires a human contributor of record per change and a Generated-by trailer on materially AI-authored commits, following ASF generative tooling guidance

Alternative matrix: what Maka does differently

  • Against OpenHands: Maka is a single-tenant desktop assistant running as your OS account, not a container-sandboxed self-hosted platform — the append-only local ledger is the differentiator
  • Against Codex CLI and Claude Code: Maka is workspace-first (desktop plus TUI) and model-agnostic via cloud API, local model, or gateway, rather than terminal-first and vendor-tied
  • Against hermes-agent: Maka explicitly models its SECURITY.md on NousResearch/hermes-agent's honesty principle — both name the OS as the only real boundary — but Maka adds the permission-decision ledger and a Runtime resume architecture
  • Against plain chat UIs: Maka records tool calls, tool results, permission decisions, and termination events as first-class execution facts, not just conversation turns

Who should pay attention?

Good fit if

  • Developers on macOS Apple Silicon who want an auditable, local record of what an agent actually did
  • Anyone who needs to re-read old tool output after context compaction — the archive stays reachable through bounded ArchiveRead calls
  • Agent benchmarking: Runtime Host owns execution so the Eval kernel owns only experiments and scores, as in the fair multi-arm Eval work and the DeepSeek Harness arm (#2668, #2971, #3176)
  • Contributors: help-wanted and good-first-issue labels exist, and the review pipeline with .asf.yaml branch protection is already enforced

Skip for now if

  • Linux users — the README badge is explicit: Linux not yet supported
  • Anyone needing a stable CLI/API contract before 0.2.0 lands — request() just became the only direct Runtime Host operation API
  • Windows environments that require signed installers — the Windows build is an unsigned preview despite 0.1.11 installer hardening
  • Multi-tenant or server deployments — SECURITY.md defines Maka as a single-tenant personal desktop AI assistant

Risks and cautions

Medium

Apache-2.0 licensed with unusually honest documentation, but incubating, macOS-first, and mid-flight on breaking Runtime Host and context-management changes.

  • Incubation status means the ASF has not fully endorsed the project; DISCLAIMER-WIP records known issues
  • macOS arm64 is an early public release, Windows is an unsigned preview, Linux is unsupported
  • Unreleased 0.2.0 removes 17 forwarding aliases and re-enables Tool Result pruning with no replacement opt-out
  • The README warns that data formats and CLI commands may still change
  • SECURITY.md's core claim: the only enforcement boundary against an adversarial LLM is the operating system — in-process screens such as the permission engine, output redaction, URL allowlists, and query normalization are heuristics on attacker-influenced strings
  • Vulnerability reports go to [email protected] or a private GitHub Security Advisory; public issues for security problems are explicitly rejected
  • The permission engine lives at @maka/core/permission, with PERMISSION_MODES, TOOL_CATEGORIES, and PERMISSION_POLICY as the exact authority; ask is the default per-session mode
  • The Electron renderer receives data only through the preload IPC bridge at apps/desktop/src/preload/preload.ts
  • Named input surfaces: chat input, file reads, web fetches, enabled bot-platform messages, and tool results; the trust envelope includes filesystem, network, Keychain, Microphone, and Screen recording permissions
  • 0.1.11 added brokered Windows AppContainer sandbox support and tightened local IPC ownership and ACL enforcement (#2961, #3179, #3182)

Alternatives to compare

ApproachWhen to useTrade-off
OpenHands
You want self-hosted, container-sandboxed agent execution for a group rather than a single-tenant desktop assistantOpen source; you run the containers and pay for model usage
You want a lean terminal-native coding agent from OpenAI with a small command surfaceOpen-source client; usage billed through your OpenAI account
You want a mature terminal agent tied to Anthropic models and toolingSubscription or API billing; the GitHub repository hosts issues and documentation
You want a research-oriented agent whose security honesty Maka explicitly cites as the model for its own policyOpen source; model costs depend on how you run it

What this trend reveals

Benchmark arms on a shared Runtime Host

Because execution belongs to Runtime Host and the Eval kernel owns only experiments and scores, new benchmark arms slot in the way 0.1.11 added the DeepSeek Harness arm while isolating subject metering from framework accounting.

Read packages/eval via the docs map, reproduce one multi-arm run, and confirm metering isolation before trusting scores.

Remote Runtime Host for a second machine

0.1.11 turned Runtime Host into the shared authority for multiple connected Hosts with remote project registration, live run state, and archived session lifecycle (#3097, #3145, #3079); docs/runtime-host-remote-access.md documents setup.

Register one project from a spare machine by following the remote-access doc, then watch live run state in the desktop build.

Audit tooling over permission decisions

Permission decisions are first-class entries in the append-only log, so an external reviewer can reconstruct approval patterns per session — something chat-transcript exports cannot do.

Run one ask-mode session with mixed approvals and denials, then confirm each decision appears as an entry in the local run record.

Best next action

Run one session, then audit the record it leaves

The fastest way to test Maka's core claim is to give it a small real task in ask mode and then verify that messages, tool results, permission decisions, and the termination event all survived.

  1. Confirm Node >=22.19.0 and npm 11.19.0, then git clone https://github.com/apache/maka.git
  2. Run npm install at the repository root only (never inside a workspace), then npm run build
  3. Start a desktop session on macOS Apple Silicon, let the agent make several tool calls, and answer each permission prompt in ask mode
  4. Open /transcript in the TUI and confirm line-level navigation over the full session beyond terminal scrollback
  5. Read SECURITY.md §2 and ARCHITECTURE.md, then decide whether the OS-as-only-boundary trust model fits the machine you would run it on

RepoDaily verdict

Maka's bet is that agent execution should be recorded, not summarized: an append-only ledger of model messages, tool calls, tool results, permission decisions, and termination events, all routed through one Runtime Host and kept on your machine. That bet is testable today on macOS Apple Silicon under an Apache-2.0 license; committing to production usage should wait until the 0.2.0 Runtime Host contract and context policy settle and Linux support arrives.

Sources