The implementer: the agent that writes code
The implementer is the role that edits code: it works through each of up to 8 subtasks inside the task's git worktree, with Bash, Read, Edit, Write and Glob as its 5 tools.
Role
Once a plan is approved and split, the implementer turns each subtask into commits. It is the pipeline role that writes files during a normal run. It works in the task's worktree, so the main checkout and other tasks stay untouched.
Its commits stay on the task branch until mark-done, when they are squashed into one and pushed.
Tools and boundaries
The role may run shell commands, read, edit and create files, and list paths. With agent containers on, each run happens in a per-invocation Docker container with all capabilities dropped and no new privileges.
On the fallback path, a kernel Landlock ruleset limits writes to the worktree, the repository's .git directory, the home directory, /tmp and /dev. Toolchains are read-only.
In container mode, network access goes through an allowlisting proxy. Code-writing roles reach only a default host list plus the hosts the workspace adds, and the proxy refuses any private or loopback address.
Narrow retries
Sometimes the run returns successfully but changed no files, often because of an empty model completion. DevFlow then re-runs it once, and a second empty result counts as a failure. A transient provider error, such as a 429 or 529 response, is retried with bounded backoff.
The final build check
After all subtasks, the configured build command runs again for each repository. On a code failure, a rework subtask goes back to this role, at most 2 times.
A missing toolchain, a memory kill or an unreachable registry is classed as an environment problem instead. The task then fails with a message saying what to fix, and no rework starts.
FAQ
Which model does the DevFlow implementer use to write code?
The DevFlow implementer uses whatever model the workspace sets for this role, or the task's own override. DevFlow's model analytics can suggest a cheaper model once it has 10 verified subtasks to compare.
Can the DevFlow implementer reach the internet?
In container mode, the DevFlow implementer reaches the internet only through the egress proxy, and only to the default host list plus the extra hosts your workspace allows.