Troubleshooting and FAQ#
Runs#
Why does my run not start?#
A run stays Pending until a machine of the workspace can take it. Open
it As a run and press Why?. The usual causes:
- No machine can run agents: machine cannot run agents in OpenShell (its bundle has no OpenShell, Landlock ABI 3 is missing, or it runs workers on its host network). Agents need a Linux machine with kernel 6.2 or newer, the current machine package, and workers off the host network. Update the machine (Update, drain and remove).
- No Assistant on the machine: machine has no Astralyx agent harness. Update the machine package.
- The workspace's quota or pools are full: as for any run (The queue). An agent run asks for 2 cores and 4 GiB.
Why was my run refused when I started it?#
409 BUDGET_EXHAUSTED: a budget of the agent or the workspace is spent for the period. Wait for the next day or month (UTC), or have an admin raise it in Budgets.400 INVALID_AGENTdeployment … has no endpoint yet: the agent's Eos deployment is not ready.400 INVALID_AGENTthe agent's policy with the workspace's guardrails is over 65536 bytes: shorten the policy or a guardrail.
My run failed at once. Where do I look?#
The run's Output (the agent's last words), then its Trace. A run
whose image cannot be pulled, or whose npm install failed (Claude Code and
Codex without an image of their own install from registry.npmjs.org),
fails before its first model call: open it As a run for its events.
Why does my run say waiting for approval?#
A call it made needs a person: see Anemoi → Approvals. The machine
holds it 10 minutes by default (@approval_wait in the policy says more,
up to a day); if nobody decides, the agent is told not yet and may end.
See Handle approvals.
How do I stop a run?#
Delete it: astra astraeus delete <run>, or As a run → delete. Its
receipt is still made.
Tools and policies#
Why is a tool call denied?#
The trace says which rule decided and why:
| Reason | Cause |
|---|---|
| no policy permits it | No permit matches: Anemoi denies by default. Add or widen a rule; use Test a call. |
| <your reason> (rule) | A forbid of the agent's policy, or a workspace or organisation guardrail (Anemoi → Guardrails). |
| requires a person's approval | Permitted only with @approval. |
| budget reached | The run's or a period's budget. |
| WEB_ADDRESS_REFUSED | The web tool never reaches private or internal addresses. |
My forbid on an argument does not work.#
A rule that reads an argument the call does not have does not apply. Guard
it: context.args has path && !(context.args.path like "/work/*").
The agent does not see one of its MCP tools.#
tools/list shows only the tools the policy would allow with no
arguments. Permit the tool by name, or make the rule say what it means for
the list (context.phase == "list" || …).
The agent cannot install a package or clone a repository.#
Its sandbox has no network but the gateway. Add the source to the sandbox policy — Python packages, npm, Clone from GitHub, Hugging Face, Debian packages, one host — and check with Test a host.
Can the agent see my API keys?#
No — not the model's key, not a tool's credential: the gateway adds them on the machine. Only credentials you expose as environment variables are visible to it, and the console warns you when you do.
The Only runs started by a schedule rule denies everything.#
Agent runs are started by people, the API, flows or evaluations; Astraeus schedules start plain runs, not agent runs. With this rule, every tool call of an agent run is denied. Use Only within a time window or Only in business hours instead.
Spending#
What does an agent cost?#
Its sandbox's hours, like any run, and what its model calls cost at the cluster's prices (the vendors' list prices). An Eos deployment costs nothing per token unless priced for the cluster; its GPU hours are in usage. See Budgets, model routes and cost.
The budget was passed by a little.#
Period budgets are summed every few seconds: runs under way may spend about 20 seconds' worth past them. The limit per run is exact to one call.
Can I change the model prices?#
Not from a workspace: prices are the cluster's, read under Budgets → Model prices.
Data and security#
What leaves my machines?#
| Stays on your machines | Reaches Astralyx |
|---|---|
| Inputs, prompts, answers, tool arguments and responses, pages fetched, traces, activity entries | States, reasons, token counts and costs, decisions and refusals counted, approval targets and digests, receipts (digests only), eval scores and short notes, flow step outputs (key=value, at most 4 KiB) |
| Credentials' values, OAuth tokens and client secrets | Credentials' names |
The console shows a run's output, trace and activity by asking its machine when you open them. An approval's arguments are read the same way, never stored.
Can an agent reach my internal network?#
Only through a tool you gave it whose URL is there (an MCP server on your network, say), decided by its policy. Its sandbox has no network; the web tool refuses private and internal addresses.
Can someone tamper with a receipt?#
A changed receipt fails its machine's signature; a forged one fails the cluster's countersignature; a removed one breaks the chain. See Receipts.
What Anemoi does not do yet#
- Triggers: no schedule, webhook or GitHub trigger for agents or flows.
Start runs and executions from your CI or a cron job with the API or
astra(see A nightly flow). - The CLI manages flows and verifies receipts and packs; agents, approvals, budgets, guardrails, evaluations and the marketplace are in the console and the API.
- GPUs are not available inside an agent's sandbox.
- Assistant settings: its step limit (40) and output tokens per call (8 192) are fixed.
- Receipts are not anchored in an external transparency log.
- OpenShell: connect, exec, logs, port forwarding and file sync through the OpenShell CLI are not available (details).