Work / AI Systems
Redl
A local-first AI workbench: model store, chat, a gated coding agent and a multi-agent Council in one Tauri app.
- Rust
- Tauri 2
- tokio
- reqwest (streaming)
- React 19
- TypeScript
- Vite 7
- Tailwind CSS 4
- Monaco
- SQLite
- Ollama
- Hugging Face Hub API
- Anthropic and OpenAI-compatible APIs
- Vitest
TL;DR
- A desktop app with a Rust core: find a model on Hugging Face, see whether it fits your GPU, pull it, chat with it, point a coding agent at a real repo, or convene a multi-agent Council.
- The coding agent speaks a plain-text protocol, so any model that can follow a format can drive it, and every edit waits on an approve-or-reject diff.
- I wrote the product brief and the Council blueprint, directed Claude Code through 15 commits in about eleven hours, and pitched Redl to investors in San Francisco in July 2026.
The problem
Running models locally means juggling four tools: a model hub, a runtime, a chat window and an editor. None of them tells you before a multi-gigabyte download whether a model will even fit in your GPU’s memory. Coding agents mostly assume native tool calling, which many local models don’t support. And a single model answering alone has no second opinion.
What I built
Redl is one Tauri app with a Rust core and a React front end.
- Store. Rust queries the Hugging Face Hub, groups GGUF quantizations and sums their shards, then reads the machine’s hardware to badge which models fit in VRAM. It streams Ollama pulls with cancel.
- Runtime. Redl finds, spawns and stops the Ollama process, and it never kills an instance it didn’t start.
- Chat. Streaming tokens over Tauri events, history in SQLite, a per-chat system prompt and temperature.
- Code. A Monaco editor bundled locally, a file tree and attach-to-chat. File access is jailed to the workspace, and tests check that
../and/etcescapes are rejected. - Agent. An in-house loop that emits fenced read, list, search, edit, create and run blocks. Reads run automatically, edits become diff cards, and shell commands are gated.
- Council. An editable pyramid of agents: four specialists, then a proposer, a critic and a red team, then a judge. Each seat can be routed to local Ollama or to an OpenAI-compatible or Anthropic model, and a memory-budget recommender tells you when to run local seats one at a time or move them to the cloud.
- Secrets. Provider API keys stay in the Rust process and never reach the UI.
Key decisions
- Decision: a text protocol instead of native tool calling. Why: any model that can follow a format can drive the agent, including small local ones. Trade-off: the parser has to find action blocks in free-form output and tolerate the model’s formatting drift.
- Decision: Rust owns the systems work: processes, downloads, hardware, files and keys. Why: the UI never touches a secret or an arbitrary path. Trade-off: every capability needs a typed Tauri command in both languages.
- Decision: Aider-style SEARCH/REPLACE hunks for edits. Why: small, reviewable diffs that survive a model rewriting whitespace. Trade-off: a hunk whose search text has drifted too far fails and has to be retried.
- Decision: per-seat model routing in the Council. Why: seats can mix local and cloud models to fit the machine. Trade-off: by default every seat runs the same local model, so the seats share its blind spots.
The hard part
Making an agent safe and model-agnostic without native tool calling. The protocol is plain fenced text, so the parser has to find action blocks inside whatever the model writes around them. SEARCH/REPLACE hunks have to apply even when the model’s whitespace drifts from the file on disk.
The permission model splits actions three ways. Reads auto-run, because they can’t change anything. Edits become diff cards the user approves or rejects. Shell runs are gated. All of it runs inside the workspace jail, so a confused or adversarial model output can’t reach outside the project. Eleven unit tests cover the agent loop, and a gated end-to-end test drives it against a real local model through Ollama.
Results
- Built in 15 commits between the afternoon of July 13, 2026 and just after midnight.
- 20 unit tests (agent 11, Council 9) and 3 Rust tests, plus gated end-to-end tests for both the agent and the Council.
- Pitched Redl to investors in San Francisco in July 2026.
- Redl became the base for my next builds: I forked it into Quorum, a local M&A diligence app that reused its Council engine, and then into Concord.
What I’d do next
- Run one prompt across several models side by side and flag where they diverge, with a disagreement score. The Council synthesizes toward one answer today; this would show where the models split.
- Signing and notarization, an updater and a public release.
- The P(error | models agree) vs P(error | models disagree) benchmark from The Council.
Links
- Code: not public yet, walkthrough on request.
- Descendants: Concord, then Warrant + Forge
- The research thread: The Council
Verified numbers
| Metric | Value | Source |
|---|---|---|
| Commits from first line to working app (Jul 13 → 14, 2026) | 15 | local: CONCORD-TRANSFER/repos/redl.bundle |
| Coding-agent unit tests | 11 | local: redl/src/lib/agent.test.ts |
| Council unit tests | 9 | local: redl/src/lib/council.test.ts |
| Default Council seats (layers 4 → 3 → 1) | 8 | local: redl/src/lib/councilDefaults.ts:26-44 |
| Pitched to investors | San Francisco, Jul 2026 | mitansh-confirmed 2026-09-22 |