How it works

01 Create a Phaser

Alice

Create a Phaser

Create a micro-VM using the Beams CLI or API.

tsh phasers add

Inside Teleport Cloud

An ephemeral micro-VM

Beams provisions a Cloud Hypervisor micro-VM with virtualized networking, delegated identity, snapshots for your agentic workload.

Role inherited from Alice
zero-standing-privileges

AlicePhaser / micro-VM
Cloud infrastructure

Layer 0 / Foundation

Cloud Hypervisor micro-VM

The Cloud Hypervisor micro-VM cycles every 12 hours and uses fresh builds to prevent CVEs.

12-hour lifecycle / fresh build

Alice Agent / Beam 01
Zero standing privileges
K8s prod

01 / Delegated identity

Troubleshoot an application crash

Beams security model starts an agent with zero standing privileges. The agent proposes execution plans to be reviewed by a user or a model.

Delegate identity with zero standing privileges. Allow execution plans.

Task: troubleshoot application crash in prod/app

Alice assigns the task

Illustrative review flow. Alice assigns a crash investigation to an agent with zero standing privileges. A model approves a read-only log plan; Alice denies a production restart: Too risky, find other means. No executor starts for the denied plan. Approval returns to the requesting agent before it dispatches the approved plan to a separate execution beam. Only the executor connects to Kubernetes, through the Protocol-Aware Proxy in the virtual network. Results return to the requester; its privileges never change. Commands and approvals are simulated. A restart is not a guaranteed fix.

Phaser A Beam 01 / image v1 /home / retained h42

01 / Phaser lifecycle

Rotate the beam. Keep the Phaser.

Each beam (the underlying micro-VM) cycles and rebuilds every 12 hours. Fresh builds minimize CVE exposure. The data mounted in /home in the Phaser is retained.

Phaser: persistent agent environment
Beam: replaceable micro-VM

Phaser A persists across beam rotations.

Teleport Cloud Phaser

01 / Connectivity

Cloud discovery

Beams continuously discovers cloud accounts in your organization.

AWS organization / prod + dev

Illustrative creation sequence: Alice delegates the zero-standing-privileges role to the Phaser. The role is inherited only when the delegation arrives; it does not grant standing resource access. No commands are executed and no cloud resources are created. Each scene plays once and holds. Scene 2 is an exploded logical view of the same Phaser; the container runs inside the VM, not above a separate machine. Use the component controls to inspect each part. Use Play to continue or watch a completed scene again. Scene 3 illustrates a retained Phaser environment across 12-hour beam rotations. A fresh base image replaces the micro-VM, not the /home checkpoint. A fork copies /home into a separate Phaser with its own runtime; private keys are not copied. Build commands and revise/evaluate cycles are illustrative: no commands run, and snapshot restores do not guarantee model improvement. Scene 4 shows illustrative AWS account and resource discovery, IAM enrollment, scoped authorization and concurrent audit capture. The zero-standing-privileges role does not itself grant resource access: the illustrated policy permits pod reads in prod/app and model inference before requests are sent. Astra and GLM 5 are illustrative model labels, not verified Bedrock model IDs or availability claims. Kubernetes and database traffic use the Protocol-Aware Proxy; only model inference uses the LLM proxy. Both proxies are inside the virtual network. Risk scores and summaries are simulated, not actual analysis.