Short definitions of the terms this course uses. The lesson in brackets is where each is explained.
| Term | Meaning |
|---|---|
| A2A | Agent2Agent protocol: how one agent delegates a task to another across a boundary. (Tools and Protocols) |
| Activity | In durable execution, a recorded step with side effects, such as a model or tool call. (Orchestration and Durable Execution) |
| Agent | A model choosing its own next action in a loop, run by a harness. (Anatomy of an Agent) |
| Agent Card | An A2A document describing an agent’s skills and endpoint; signed in v1.0. (Tools and Protocols) |
| Agent Sandbox | The Kubernetes API for stateful, isolated, idle-heavy agent workspaces. (Sandboxes and Tool Execution) |
| AI gateway | The single entry point for model traffic: identity, token limits, routing, fallback. (Model Access and Gateways) |
| Blast radius | The worst outcome if a component is fully compromised. (Trust Boundaries) |
| Checkpoint | Saved agent state from which a task can resume. (Orchestration and Durable Execution) |
| Chunk | A retrievable piece of a document, a few hundred tokens long. (Context and Retrieval) |
| Circuit breaker | Skips a failing route until probes succeed again. (Reliability Patterns) |
| Compaction | Summarising older context so a long task fits the window. (Context Engineering and Memory) |
| Context engineering | Deciding what enters the context window on each call. (Context and Retrieval) |
| Context window | Everything the model sees on one call; a fixed budget. (What a Model Changes) |
| Control plane | Components that decide what should run; not on the request path. (The Layers) |
| Data plane | Components that carry requests. (The Layers) |
| Deterministic control | A control enforced by code or configuration that the model cannot talk its way past. (Trust Boundaries) |
| DRA | Dynamic Resource Allocation: Kubernetes API for requesting devices by attribute. (The Cluster) |
| Durable execution | Recording each step so a task resumes exactly where it stopped. (Orchestration and Durable Execution) |
| Egress control | Restricting where a component may send network traffic. (Sandboxes and Tool Execution) |
| Embedding | A vector representing the meaning of a piece of text. (Context and Retrieval) |
| Endpoint picker | The component that chooses a model-server replica per request. (The Serving Layer) |
| Evaluation | A dataset plus graders that measure quality as a rate. (Evaluation and Quality) |
| Goodput | Throughput that still meets the latency targets. (Compute and Capacity) |
| Harness | The code around the model in an agent: context, tools, policy, budgets, state. (Anatomy of an Agent) |
| Hybrid search | Vector and keyword search combined. (Context and Retrieval) |
| Idempotency key | An identifier that makes a repeated write take effect once. (Orchestration and Durable Execution) |
| InferencePool | The Gateway API resource grouping pods that serve one model. (The Serving Layer) |
| Judge model | A model used to grade another model’s output. (Evaluation and Quality) |
| Lethal trifecta | Private data, untrusted content and an outbound channel in one agent context. (Trust Boundaries) |
| MCP | Model Context Protocol: how an agent reaches tools and data. (Tools and Protocols) |
| Occupancy | The share of capacity in use; the main driver of self-hosted unit cost. (The Layers) |
| Policy layer | Code that approves or denies each proposed tool call. (Anatomy of an Agent) |
| Prefill / decode | Reading the prompt, then generating tokens one at a time. (The Serving Layer) |
| Prefix cache | Reuse of the processed form of a repeated prompt prefix. (State, Memory and Caching) |
| Prompt injection | Text in the context that redirects the model. (What a Model Changes) |
| RAG | Retrieval-augmented generation: answering from fetched context. (Context and Retrieval) |
| Reranker | A model that scores candidate chunks against the question. (Context and Retrieval) |
| Reciprocal rank fusion | A way to merge rankings without comparable scores. (Context and Retrieval) |
| Rule of two | An agent holds at most two legs of the trifecta without human approval. (Trust Boundaries) |
| Sandbox | An isolated environment for running untrusted code. (Sandboxes and Tool Execution) |
| Semantic cache | Returns a stored answer for a similar question; risky across users. (State, Memory and Caching) |
| Skill | A folder of instructions and scripts an agent loads when relevant. (Anatomy of an Agent) |
| Sub-agent | An agent given a narrow task and a fresh context by another agent. (Context Engineering and Memory) |
| Token | The unit a model reads and writes; the unit of cost, latency and limits. (What a Model Changes) |
| Tool calling | The model requests a function call; the harness executes it. (Tools and Protocols) |
| TPOT | Time per output token. (What a Model Changes) |
| TTFT | Time to first token. (What a Model Changes) |
| Workflow | Model calls arranged in a control flow written in advance. (Anatomy of an Agent) |