Repository navigation
phase2(s13): config authority via refs — InferencePolicy + ToolPolicy - #118
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoApr 30, 2026
Merged
Conversation
BREAKING in-place v1alpha1 schema edit (pre-release; no conversion
webhook). Inline inference and tool-policy config on `ClawSandbox` is
removed; the spec now carries same-namespace refs to dedicated
`InferencePolicy` and `ToolPolicy` CRDs which become the single source
of truth.
Schema:
- spec.inference (InferenceConfig) → REMOVED.
- spec.inferenceRef: { name } → NEW, required. References sibling
InferencePolicy CR.
- spec.governance.toolPolicy (string profile name) → REMOVED.
- spec.governance.toolPolicyRef: { name } → NEW. Required when
governance.enabled=true (CEL-enforced).
- New status reasons `InferencePolicyNotFound`,
`ToolPolicyNotFound` — emitted on Degraded when a referenced
CR is missing in the sandbox's namespace.
- Cross-namespace refs are not supported (Api::namespaced lookup;
security invariant — see CHANGELOG).
- Printcolumn updated: `Model` → `InferencePolicy`.
Reconciler (controller/src/reconciler/mod.rs):
- Resolves InferencePolicy after isolation validation:
- 404 → degrade(InferencePolicyNotFound).
- empty .spec.inferenceRef.name → degrade(SpecInvalid).
- other API error → 15s requeue.
- Reads modelPreference.primary.deployment → OPENCLAW_MODEL +
AZURE_OPENAI_DEPLOYMENT (degrade SpecInvalid if empty).
- tokenBudget.{daily,perRequest}Tokens → casts to i64 env vars.
- contentSafety.requirePromptShields (default true).
- When governance.enabled=true, resolves ToolPolicy:
- 404 → degrade(ToolPolicyNotFound).
- resolved metadata.name → tool_policy_profile string used
everywhere previously read from governance.tool_policy
(AGT_POLICY_PROFILE, agt-policy-{name} ConfigMap, include_str!
selection between azureclaw-default.yaml / azureclaw-offload.yaml).
CLI:
- New cli/src/refs.ts: kebabRefName helper + buildInferencePolicy /
buildToolPolicy emitters. `<sandbox>-inference` /
`<sandbox>-toolpolicy` naming, DNS-1123 truncated to 63 chars.
- `azureclaw up` and `azureclaw add` emit a multi-doc bundle
(InferencePolicy + optional ToolPolicy + ClawSandbox) applied as
a single `kubectl apply` of a v1.List manifest.
- `azureclaw migrate from-kagent` always emits an
`<sandbox>-inference` InferencePolicy (preserving kagent
modelConfig as provenance annotation when set), and a synthetic
`<sandbox>-toolpolicy` aggregator whenever governance is on.
- attest.ts POLICY_CR_KINDS recognizes both `inferenceRef` (S13) and
legacy `inferencePolicyRef` shapes during the rollout window.
Helm CRD (deploy/helm/azureclaw/templates/crd.yaml):
- spec.required: ["runtime", "sandbox", "inferenceRef"].
- inferenceRef: { name } with DNS-1123 pattern + non-empty CEL.
- governance.toolPolicyRef: { name } with DNS-1123 pattern.
- governance x-kubernetes-validations: toolPolicyRef.name must be set
when governance.enabled=true.
Tests:
- 381 controller tests passing (added LocalObjectRef round-trip
tests; reuses the existing `crate::mcp_server::LocalObjectRef`
type — same shape, identical semantics).
- 395 CLI tests passing (add.test.ts, from_kagent.test.ts updated).
Examples + fixtures: all clawsandbox.yamls in examples/ and
tests/compat/fixtures/null-provider-*.yaml updated to the new
two-doc shape; tests/e2e/run.sh updated.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
force-pushed
the
phase2-s13-config-authority-refs
branch
from
April 30, 2026 00:57
664c1c3 to
d5382ec
Compare
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…#118) BREAKING in-place v1alpha1 schema edit (pre-release; no conversion webhook). Inline inference and tool-policy config on `ClawSandbox` is removed; the spec now carries same-namespace refs to dedicated `InferencePolicy` and `ToolPolicy` CRDs which become the single source of truth. Schema: - spec.inference (InferenceConfig) → REMOVED. - spec.inferenceRef: { name } → NEW, required. References sibling InferencePolicy CR. - spec.governance.toolPolicy (string profile name) → REMOVED. - spec.governance.toolPolicyRef: { name } → NEW. Required when governance.enabled=true (CEL-enforced). - New status reasons `InferencePolicyNotFound`, `ToolPolicyNotFound` — emitted on Degraded when a referenced CR is missing in the sandbox's namespace. - Cross-namespace refs are not supported (Api::namespaced lookup; security invariant — see CHANGELOG). - Printcolumn updated: `Model` → `InferencePolicy`. Reconciler (controller/src/reconciler/mod.rs): - Resolves InferencePolicy after isolation validation: - 404 → degrade(InferencePolicyNotFound). - empty .spec.inferenceRef.name → degrade(SpecInvalid). - other API error → 15s requeue. - Reads modelPreference.primary.deployment → OPENCLAW_MODEL + AZURE_OPENAI_DEPLOYMENT (degrade SpecInvalid if empty). - tokenBudget.{daily,perRequest}Tokens → casts to i64 env vars. - contentSafety.requirePromptShields (default true). - When governance.enabled=true, resolves ToolPolicy: - 404 → degrade(ToolPolicyNotFound). - resolved metadata.name → tool_policy_profile string used everywhere previously read from governance.tool_policy (AGT_POLICY_PROFILE, agt-policy-{name} ConfigMap, include_str! selection between azureclaw-default.yaml / azureclaw-offload.yaml). CLI: - New cli/src/refs.ts: kebabRefName helper + buildInferencePolicy / buildToolPolicy emitters. `<sandbox>-inference` / `<sandbox>-toolpolicy` naming, DNS-1123 truncated to 63 chars. - `azureclaw up` and `azureclaw add` emit a multi-doc bundle (InferencePolicy + optional ToolPolicy + ClawSandbox) applied as a single `kubectl apply` of a v1.List manifest. - `azureclaw migrate from-kagent` always emits an `<sandbox>-inference` InferencePolicy (preserving kagent modelConfig as provenance annotation when set), and a synthetic `<sandbox>-toolpolicy` aggregator whenever governance is on. - attest.ts POLICY_CR_KINDS recognizes both `inferenceRef` (S13) and legacy `inferencePolicyRef` shapes during the rollout window. Helm CRD (deploy/helm/azureclaw/templates/crd.yaml): - spec.required: ["runtime", "sandbox", "inferenceRef"]. - inferenceRef: { name } with DNS-1123 pattern + non-empty CEL. - governance.toolPolicyRef: { name } with DNS-1123 pattern. - governance x-kubernetes-validations: toolPolicyRef.name must be set when governance.enabled=true. Tests: - 381 controller tests passing (added LocalObjectRef round-trip tests; reuses the existing `crate::mcp_server::LocalObjectRef` type — same shape, identical semantics). - 395 CLI tests passing (add.test.ts, from_kagent.test.ts updated). Examples + fixtures: all clawsandbox.yamls in examples/ and tests/compat/fixtures/null-provider-*.yaml updated to the new two-doc shape; tests/e2e/run.sh updated. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
phase2-s13-config-authority-refs
branch
June 1, 2026 14:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
S13
phase2-config-authority-refsBREAKING in-place v1alpha1 schema edit (pre-release; no conversion webhook).
Inline inference and tool-policy config on
ClawSandboxis removed; thespec now carries same-namespace refs to dedicated
InferencePolicyandToolPolicyCRDs which become the single source of truth.Schema changes
spec.inference: InferenceConfig(provider/model/contentSafety/promptShields/tokenBudget)spec.inferenceRef: { name }— required, siblingInferencePolicyCRspec.governance.toolPolicy: string(profile name)spec.governance.toolPolicyRef: { name }— required whengovernance.enabled=trueApi::namespaced(client, &sandbox_self_ns).Cross-namespace refs are deliberately not supported — a sandbox author
must not be able to "borrow" policies from another tenant.
InferencePolicyNotFound,ToolPolicyNotFoundemitted on
Degradedwhen the referenced CR is missing.Model→InferencePolicy(.spec.inferenceRef.name).Reconciler
controller/src/reconciler/mod.rsresolvesInferencePolicyafterisolation validation and
ToolPolicyafter the governance block isparsed. Hoisted vars
inference_model,content_safety_enabled,prompt_shields_enabled,token_budget_{daily,per_request},tool_policy_profilereplace the previous inline reads. Theagt-policy-{profile}ConfigMap convention and theazureclaw-default.yaml/azureclaw-offload.yamlselection arepreserved — the resolved
ToolPolicy'smetadata.namedoubles as theprofile identifier.
CLI
cli/src/refs.ts:kebabRefNamehelper (DNS-1123 truncated to 63chars) +
buildInferencePolicy/buildToolPolicyemitters.azureclaw upandazureclaw addnow emit a multi-doc bundle(
InferencePolicy+ optionalToolPolicy+ClawSandbox) appliedas a single
kubectl applyof av1.Listmanifest.azureclaw migrate from-kagentalways emits an<sandbox>-inferenceInferencePolicy(preserving kagentmodelConfigas a provenance annotation when set) and a synthetic<sandbox>-toolpolicyaggregator whenever governance is on.attest.tsrecognizes bothinferenceRef(S13) and the pre-S13inferencePolicyRefshape during the rollout window.Test delta
default_model_is_gpt_4_1,default_provider_is_azure_openai,default_inference_*/inference_config_default_has_no_fallback/token_budget_config_*.Added
local_object_ref_round_trips,local_object_ref_default_is_empty_name,inference_ref_round_trips_via_camel_case,governance_tool_policy_ref_serializes_camel_case. Updateddefault_governance_configandsandbox_spec_fields_all_optional.LocalObjectRefis reused from the existingcrate::mcp_server::LocalObjectRef(same shape, identical semantics).add.test.tsupdated to assertspec.inferenceRef.name === "<sandbox>-inference"andspec.governance.toolPolicyRef.from_kagent.test.tsupdatedfor the always-emit-InferencePolicy and
<sandbox>-toolpolicyaggregator semantics; per-tool
ToolPolicycount assertions filterout the aggregator.
Pipeline
cargo fmt --all✅cargo clippy --all-targets -- -D warnings✅cargo test --all✅ (381 controller + 105 router + 26 integration tests)cd cli && npm run lint && npm run typecheck && npm test && npm run build✅helm lint deploy/helm/azureclaw✅Examples and fixtures
All
clawsandbox.yamlinexamples/(basic-agent,confidential-agent,telegram-agent,demo-clawshield/*),tests/compat/fixtures/null-provider-*.yaml, andtests/e2e/run.shupdated to the new two-doc-per-sandbox shape (
InferencePolicythenClawSandbox).Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com