Repository navigation
feat(runtime): Phase H#3 — Pydantic-AI first-class runtime - #181
Merged
Merged
Conversation
Adds RuntimeKind::PydanticAi as a first-class runtime joining OpenAIAgents, MAF (Python), Anthropic (Phase H#1), and LangGraph (Phase H#2). Pydantic-AI is the type-safe Python agent framework from the Pydantic team — provider-agnostic by design (a single `Agent` definition can target OpenAI, Azure OpenAI, Anthropic, Gemini, etc.). Controller / CRD: * RuntimeKind::PydanticAi enum variant * RuntimeSpec.pydantic_ai: Option<PydanticAiConfig> * PydanticAiConfig (python_version + agent_code + entrypoint + extra_env) * DEFAULT_PYDANTIC_AI_IMAGE + pydantic_ai_default_image() helper honouring `PYDANTIC_AI_RUNTIME_IMAGE` env override * plan_pydantic_ai producer threading python_version into RUNTIME_PYTHON_VERSION; user extra_env merged last so it wins * CRD enum + CEL pair + pydanticAi property block Runtime adapter (runtimes/pydantic-ai/): * Mirrors the LangGraph adapter (same multi-provider env-pinning strategy) — bootstrap() pins three provider base URLs to the router sidecar and substitutes API keys with the `router-managed` sentinel. Idempotent. * Depends on pydantic-ai>=0.0.13,<1 plus the same azure-identity, opentelemetry-*, httpx, a2a_agentmesh, agent_sandbox stack. Sandbox image (sandbox-images/pydantic-ai/): * FROM mcr.microsoft.com/cbl-mariner/base/python:3.12 * Labels: org.azureclaw.runtime.kind=PydanticAi, contract=v1 * USER 1000, workdir /sandbox/agent * entrypoint.sh pins all three provider URLs + sentinel API keys before exec-ing the user agent Tests: * +4 controller unit tests for plan_pydantic_ai (all 484 controller tests pass with --test-threads=1) * test_runtime_pydantic_ai E2E test in tests/e2e/run.sh, registered in case dispatcher and the `all` lane AGT boundary respected: adapter is a pure bootstrapper. All trust scoring, policy enforcement, and audit happen in the inference-router which calls into the upstream Microsoft AGT. Closes Phase H#3 of competitive §14.6. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
Adds RuntimeKind::PydanticAi as a first-class runtime joining OpenAIAgents, MAF (Python), Anthropic (Phase H#1), and LangGraph (Phase H#2). Pydantic-AI is the type-safe Python agent framework from the Pydantic team — provider-agnostic by design (a single `Agent` definition can target OpenAI, Azure OpenAI, Anthropic, Gemini, etc.). Controller / CRD: * RuntimeKind::PydanticAi enum variant * RuntimeSpec.pydantic_ai: Option<PydanticAiConfig> * PydanticAiConfig (python_version + agent_code + entrypoint + extra_env) * DEFAULT_PYDANTIC_AI_IMAGE + pydantic_ai_default_image() helper honouring `PYDANTIC_AI_RUNTIME_IMAGE` env override * plan_pydantic_ai producer threading python_version into RUNTIME_PYTHON_VERSION; user extra_env merged last so it wins * CRD enum + CEL pair + pydanticAi property block Runtime adapter (runtimes/pydantic-ai/): * Mirrors the LangGraph adapter (same multi-provider env-pinning strategy) — bootstrap() pins three provider base URLs to the router sidecar and substitutes API keys with the `router-managed` sentinel. Idempotent. * Depends on pydantic-ai>=0.0.13,<1 plus the same azure-identity, opentelemetry-*, httpx, a2a_agentmesh, agent_sandbox stack. Sandbox image (sandbox-images/pydantic-ai/): * FROM mcr.microsoft.com/cbl-mariner/base/python:3.12 * Labels: org.azureclaw.runtime.kind=PydanticAi, contract=v1 * USER 1000, workdir /sandbox/agent * entrypoint.sh pins all three provider URLs + sentinel API keys before exec-ing the user agent Tests: * +4 controller unit tests for plan_pydantic_ai (all 484 controller tests pass with --test-threads=1) * test_runtime_pydantic_ai E2E test in tests/e2e/run.sh, registered in case dispatcher and the `all` lane AGT boundary respected: adapter is a pure bootstrapper. All trust scoring, policy enforcement, and audit happen in the inference-router which calls into the upstream Microsoft AGT. Closes Phase H#3 of competitive §14.6. Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
RuntimeKind::PydanticAias a first-class runtime joining OpenAIAgents, MAF (Python), Anthropic (Phase H#1, #179), and LangGraph (Phase H#2, #180).Pydantic-AI is the type-safe Python agent framework from the Pydantic team. Provider-agnostic by design — a single
Agentdefinition can target OpenAI, Azure OpenAI, Anthropic, Gemini, etc.Closes Phase H#3 of competitive §14.6.
Why a dedicated adapter (vs BYO)
Pydantic-AI users would otherwise re-implement the same provider env-pinning + sentinel logic the LangGraph adapter already solved. Shipping it as a first-class runtime lets users supply only their agent code.
Changes
PydanticAienum +PydanticAiConfigstruct + image helper +plan_pydantic_aiproducer + CRD enum/CEL/property blockruntimes/pydantic-ai/— mirrors LangGraph's multi-provider env-pinning strategy (3 provider base URLs, 3 sentinel API keys)sandbox-images/pydantic-ai/— Mariner Python 3.12, USER 1000, runtime contract v1test_runtime_pydantic_aiE2E added to dispatcher andalllaneAGT boundary respect
Adapter is a pure bootstrapper (env-pinning + OTel + signal handlers). All trust scoring, policy enforcement, and audit happen in the inference-router which calls into the upstream Microsoft AGT
agentmeshcrate. No governance logic reimplemented.Local verification
cargo build --package azureclaw-controller— cleancargo clippy --package azureclaw-controller --all-targets -- -D warnings— cleancargo test --package azureclaw-controller -- --test-threads=1— 484 passedcargo fmt --all— no diffBASE_REF=origin/dev