Skip to main content
The runtime determines how an agent’s inner loop runs — how each turn calls the model, interprets intent, and invokes tools. The default runtime is built on Google ADK’s execution flow and works out of the box; you can also switch the execution backend or inject shared processing logic into the flow, without changing the agent itself.

Default runtime

The ADK runtime is the default and needs no extra configuration:

Switch the execution backend

Use runtime to select the inner-loop execution backend:

Use the Codex runtime

The Codex runtime requires openai-codex, which is not installed with VeADK by default. Install the required dependencies before using it:
By default, the Codex runtime does not request interactive approval and can execute commands, read and write files, and access the network from its host or container. Enable it only for trusted workloads. In production, use a least-privilege isolated container and restrict the credentials, files, and network destinations it can access.
The model name, API endpoint, and API key still come from the agent’s model configuration:
Tools and skills use the standard Agent configuration; the Codex runtime does not require a separate registration path:
  • function tools in tools are exposed as callable tools to the model;
  • an MCPToolset in tools supports tool discovery and invocation;
  • skills loaded through SkillToolset or VeADK’s legacy entry are made available through the Codex skill mechanism.

Configure transient-error retries

When the Codex runtime calls the model backend, it retries transient failures such as rate limits, server errors, overloads, and timeouts. It retries at most twice by default. Use these environment variables to change the behavior:

Use PiAgent

The VeADK Python package does not vendor the PiAgent binary. The runtime checks the following locations in order:
  1. the executable referenced by PIAGENT_BINARY;
  2. the managed cache under PIAGENT_INSTALL_DIR, which defaults to ~/.cache/veadk/piagent;
  3. if the cache is missing, a downloaded and verified PiAgent release.
Automatic installation requires access to the PiAgent release host. In offline or restricted networks, install the binary in advance and set PIAGENT_BINARY.

Request processing

Without touching business logic, you can inject shared cross-cutting processing into each run. Pass a processor to run_processor, for example to enforce login via identity authentication:
When unset, the default processor is used and behavior is unchanged. VeADK ships AuthRequestProcessor as a ready-made implementation for identity authentication.

Custom processors

Every processor subclasses the abstract base BaseRunProcessor and implements its process_run(runner, message) method. That method returns a decorator wrapping the run’s event stream, letting you:
  • inject logic before and after the whole run (auth, logging, monitoring);
  • intercept, rewrite, or inject events produced during the run;
  • build control logic such as retries on top of that.
Last modified on September 19, 2026