Skip to content

feat(runtime): Phase H#3 — Pydantic-AI first-class runtime - #181

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
feat/pydantic-ai-runtime
May 3, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
feat/pydantic-ai-runtime

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

Adds RuntimeKind::PydanticAi as a first-class runtime joining OpenAIAgents, MAF (Python), Anthropic (Phase H#1, #179), and LangGraph (Phase H#2, #180).

Pydantic-AI is the type-safe Python agent framework from the Pydantic team. Provider-agnostic by design — a single Agent definition can target OpenAI, Azure OpenAI, Anthropic, Gemini, etc.

Closes Phase H#3 of competitive §14.6.

Why a dedicated adapter (vs BYO)

Pydantic-AI users would otherwise re-implement the same provider env-pinning + sentinel logic the LangGraph adapter already solved. Shipping it as a first-class runtime lets users supply only their agent code.

Changes

  • Controller / CRD: PydanticAi enum + PydanticAiConfig struct + image helper + plan_pydantic_ai producer + CRD enum/CEL/property block
  • Runtime adapter: runtimes/pydantic-ai/ — mirrors LangGraph's multi-provider env-pinning strategy (3 provider base URLs, 3 sentinel API keys)
  • Sandbox image: sandbox-images/pydantic-ai/ — Mariner Python 3.12, USER 1000, runtime contract v1
  • Tests: +4 controller unit tests (484 total pass with --test-threads=1); test_runtime_pydantic_ai E2E added to dispatcher and all lane
  • Audit: docs/security-audits/2026-05-03-phase-h3-pydantic-ai-runtime.md

AGT boundary respect

Adapter is a pure bootstrapper (env-pinning + OTel + signal handlers). All trust scoring, policy enforcement, and audit happen in the inference-router which calls into the upstream Microsoft AGT agentmesh crate. No governance logic reimplemented.

Local verification

  • cargo build --package azureclaw-controller — clean
  • cargo clippy --package azureclaw-controller --all-targets -- -D warnings — clean
  • cargo test --package azureclaw-controller -- --test-threads=1 — 484 passed
  • cargo fmt --all — no diff
  • All 8 quick CI gates pass with BASE_REF=origin/dev

Adds RuntimeKind::PydanticAi as a first-class runtime joining
OpenAIAgents, MAF (Python), Anthropic (Phase H#1), and LangGraph
(Phase H#2). Pydantic-AI is the type-safe Python agent framework
from the Pydantic team — provider-agnostic by design (a single
`Agent` definition can target OpenAI, Azure OpenAI, Anthropic,
Gemini, etc.).

Controller / CRD:
* RuntimeKind::PydanticAi enum variant
* RuntimeSpec.pydantic_ai: Option<PydanticAiConfig>
* PydanticAiConfig (python_version + agent_code + entrypoint + extra_env)
* DEFAULT_PYDANTIC_AI_IMAGE + pydantic_ai_default_image() helper
  honouring `PYDANTIC_AI_RUNTIME_IMAGE` env override
* plan_pydantic_ai producer threading python_version into
  RUNTIME_PYTHON_VERSION; user extra_env merged last so it wins
* CRD enum + CEL pair + pydanticAi property block

Runtime adapter (runtimes/pydantic-ai/):
* Mirrors the LangGraph adapter (same multi-provider env-pinning
  strategy) — bootstrap() pins three provider base URLs to the
  router sidecar and substitutes API keys with the
  `router-managed` sentinel. Idempotent.
* Depends on pydantic-ai>=0.0.13,<1 plus the same azure-identity,
  opentelemetry-*, httpx, a2a_agentmesh, agent_sandbox stack.

Sandbox image (sandbox-images/pydantic-ai/):
* FROM mcr.microsoft.com/cbl-mariner/base/python:3.12
* Labels: org.azureclaw.runtime.kind=PydanticAi, contract=v1
* USER 1000, workdir /sandbox/agent
* entrypoint.sh pins all three provider URLs + sentinel API keys
  before exec-ing the user agent

Tests:
* +4 controller unit tests for plan_pydantic_ai (all 484 controller
  tests pass with --test-threads=1)
* test_runtime_pydantic_ai E2E test in tests/e2e/run.sh, registered
  in case dispatcher and the `all` lane

AGT boundary respected: adapter is a pure bootstrapper. All trust
scoring, policy enforcement, and audit happen in the inference-router
which calls into the upstream Microsoft AGT.

Closes Phase H#3 of competitive §14.6.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit e1dbdd3 into dev May 3, 2026
21 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the feat/pydantic-ai-runtime branch May 3, 2026 13:19
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
Adds RuntimeKind::PydanticAi as a first-class runtime joining
OpenAIAgents, MAF (Python), Anthropic (Phase H#1), and LangGraph
(Phase H#2). Pydantic-AI is the type-safe Python agent framework
from the Pydantic team — provider-agnostic by design (a single
`Agent` definition can target OpenAI, Azure OpenAI, Anthropic,
Gemini, etc.).

Controller / CRD:
* RuntimeKind::PydanticAi enum variant
* RuntimeSpec.pydantic_ai: Option<PydanticAiConfig>
* PydanticAiConfig (python_version + agent_code + entrypoint + extra_env)
* DEFAULT_PYDANTIC_AI_IMAGE + pydantic_ai_default_image() helper
  honouring `PYDANTIC_AI_RUNTIME_IMAGE` env override
* plan_pydantic_ai producer threading python_version into
  RUNTIME_PYTHON_VERSION; user extra_env merged last so it wins
* CRD enum + CEL pair + pydanticAi property block

Runtime adapter (runtimes/pydantic-ai/):
* Mirrors the LangGraph adapter (same multi-provider env-pinning
  strategy) — bootstrap() pins three provider base URLs to the
  router sidecar and substitutes API keys with the
  `router-managed` sentinel. Idempotent.
* Depends on pydantic-ai>=0.0.13,<1 plus the same azure-identity,
  opentelemetry-*, httpx, a2a_agentmesh, agent_sandbox stack.

Sandbox image (sandbox-images/pydantic-ai/):
* FROM mcr.microsoft.com/cbl-mariner/base/python:3.12
* Labels: org.azureclaw.runtime.kind=PydanticAi, contract=v1
* USER 1000, workdir /sandbox/agent
* entrypoint.sh pins all three provider URLs + sentinel API keys
  before exec-ing the user agent

Tests:
* +4 controller unit tests for plan_pydantic_ai (all 484 controller
  tests pass with --test-threads=1)
* test_runtime_pydantic_ai E2E test in tests/e2e/run.sh, registered
  in case dispatcher and the `all` lane

AGT boundary respected: adapter is a pure bootstrapper. All trust
scoring, policy enforcement, and audit happen in the inference-router
which calls into the upstream Microsoft AGT.

Closes Phase H#3 of competitive §14.6.

Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant