AI & LLMs

Self-hosted AI agent platform for GitLab reaches 133 releases

The langgraph-harness project, a self-hosted AI coding agent for GitLab, has reached 133 releases with a 67% comment acceptance rate.

Illustration of a self-hosted AI agent system with security shields and git integration
Illustration created for this article

A self-hosted AI coding agent platform designed specifically for GitLab has reached a significant milestone in its development lifecycle. The project, known as langgraph-harness, was published by vrajpal-jhala on GitHub and has accumulated 133 releases since becoming battle-tested in production during mid-2026. This open-source tool enables teams to automate merge request reviews, resolve work items, and maintain project context through persistent memory, all while keeping data within their own infrastructure.

What happened

The langgraph-harness platform operates as a comprehensive suite of four distinct harnesses built on a shared foundation. It integrates directly with GitLab to perform automated code reviews, issue resolution, and interactive chat sessions. Unlike simple polling scripts, the system reacts to webhook events to trigger merge request reviews, reading diffs and drafting comments without manual intervention. For more complex tasks, it can assign itself to GitLab issues or tasks, running inside isolated Kata Containers VMs to generate draft merge requests and respond to follow-up comments on the same branch.

The project distinguishes itself through its robust architecture and transparency regarding its operational history. As of September 29, 2026, the platform reported a 67% comment acceptance rate across more than 1,000 reviews. The developer has documented every failure and fix in the project’s development history, providing a clear trail of how the system evolved. The platform uses persistent checkpoints to ensure that if a run misbehaves—such as entering a loop or skipping a check—it can be caught, corrected, and resumed rather than restarted from scratch.

Key details

  • The project has reached 133 releases and is licensed under the MIT License.
  • It achieved a 67% comment acceptance rate across 1,000+ reviews as of September 29, 2026.
  • Code-changing runs occur inside Kata Containers VMs, providing dedicated guest kernels for isolation.
  • The backend uses an Elysia API server running a LangGraph agent with persistent checkpoints.
  • Sensitive tool calls in the chat interface pause for explicit human approval before execution.
  • The system supports multiple LLM providers including OpenRouter, Gemini, Groq, Ollama, and sglang.

Background

LangGraph is a framework used to build stateful, multi-actor applications with large language models. In this context, it allows the AI agent to maintain a consistent state across long-running tasks, such as reviewing a complex merge request or resolving a multi-step issue. The use of Kata Containers is significant for security-conscious teams. Unlike standard containerization that relies on syscall interception, Kata Containers provide a lightweight virtual machine with its own kernel. This ensures that if the AI agent executes malicious or erroneous code during a task, it is contained within a strict sandbox, protecting the host server and other services.

Webhooks are the primary mechanism that triggers these automated actions. When a developer pushes code or opens a merge request in GitLab, a webhook sends a payload to the langgraph-harness API. This event-driven approach is more efficient than polling, as it reduces latency and server load. However, relying on webhooks requires precise configuration of endpoints and secrets to ensure that only authorized requests from GitLab can trigger the AI agents. Misconfigured webhooks can lead to missed events or security vulnerabilities if sensitive headers are exposed.

Why it matters

For teams that self-host their software, maintaining control over AI interactions is a growing priority. Public AI services often require sending proprietary code to external servers, which may violate compliance policies or intellectual property agreements. By self-hosting langgraph-harness, organizations can leverage advanced AI capabilities for code review and task resolution while keeping all data, including source code and internal discussions, within their private network. The ability to use local LLM instances via Ollama or sglang further enhances this privacy, allowing teams to run models without any external API calls.

The operational resilience provided by persistent checkpoints is another critical factor for production environments. AI agents can sometimes enter infinite loops or fail to complete tasks due to ambiguous instructions. In traditional setups, this might require manual restarts and loss of progress. With langgraph-harness, the system detects these anomalies and corrects them mid-run, preserving the context and work already completed. This reliability is essential for teams looking to integrate AI into their daily workflows without increasing the burden on human supervisors.

What you can do

  • Review the project’s documented development history to understand common failure modes and fixes.
  • Set up a GitLab OAuth app and personal access token with API scope to enable secure integration.
  • Configure Kata Containers for any agent tasks that involve generating or modifying code.
  • Implement webhook validation to ensure only legitimate GitLab events trigger the AI agents.
  • Test the chat interface with sensitive tool calls to verify that human approval gates function correctly.
  • Monitor the BullMQ queue state via the React admin UI to manage concurrency and debounced re-reviews.

More news

All news