Skip to content

slice-5b: egressMode enum replaces learnEgress bool - #297

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
slice-5b-egress-mode-enum
May 13, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
slice-5b-egress-mode-enum

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Slice 5b — egressMode enum (DoD #3)

Replaces ClawSandbox.spec.networkPolicy.learnEgress: bool with
egressMode: Strict | Learn enum. Default = Learn. The Approval
variant is deferred to Slice 5c (no consumer yet per principles §5).

No back-compat shim — the repo has no live deployments yet, so
the legacy field was removed cleanly rather than deprecated.

Changes

  • controller/src/crd.rs — new EgressMode enum with
    #[derive(Default)] and #[default] on Learn. Replaces
    NetworkPolicyConfig.learn_egress.
  • controller/src/reconciler/mod.rs — emits EGRESS_MODE=strict|learn.
    No back-compat EGRESS_LEARN_MODE.
  • inference-router/src/routes/mod.rs — consumes EGRESS_MODE,
    defaults to Learn when unset.
  • inference-router/src/spawn/mod.rs — sub-agent reader/producer
    migrated. Internal SpawnRequest.learn_egress retained (not wire).
  • deploy/helm/azureclaw/templates/crd.yaml — learnEgress removed
    from schema.
  • cli/src/commands/* — every CR producer/reader migrated.
  • tools/headlamp-plugin/src/index.tsx — all 4 egress readers
    consume egressMode directly.
  • docs/use-cases.md, docs/egress-proxy.md — samples updated.

Verification

  • cargo build --workspace ✅
  • cargo clippy --workspace --all-targets -- -D warnings ✅
  • cargo test -p azureclaw-controller --bin azureclaw-controller ✅ 562 passed
  • cargo test -p azureclaw-inference-router --lib ✅ 849 passed
  • cd cli && npm run typecheck ✅
  • cd cli && npm test ✅ 692 passed | 2 skipped
  • cd tools/headlamp-plugin && npm run build ✅

Closes Slice 5 DoD #3.

Replaces ClawSandbox.spec.networkPolicy.learnEgress: bool with
egressMode: Strict | Learn across controller, router, CLI, Headlamp,
helm CRD, and docs. Default = Learn. The Approval variant is deferred
to Slice 5c (no consumer yet per principles §5).

No back-compat shim: repo has no live deployments yet, so the legacy
field was removed cleanly. Slice 5b DoD #3 closed.

- controller/src/crd.rs: new EgressMode enum with #[derive(Default)]
  and #[default] on Learn. Replaces NetworkPolicyConfig.learn_egress.
- controller/src/reconciler/mod.rs: emits EGRESS_MODE=strict|learn
  (no back-compat EGRESS_LEARN_MODE).
- inference-router/src/routes/mod.rs: consumes EGRESS_MODE, defaults
  to Learn when unset.
- inference-router/src/spawn/mod.rs: sub-agent reader/producer
  migrated. Internal SpawnRequest.learn_egress retained (not wire).
- deploy/helm/azureclaw/templates/crd.yaml: learnEgress removed
  from schema; egressMode enum-validated.
- cli/src/commands/{add,policy,handoff,handoff/helpers,up/sandbox_bringup,
  dev/local-k8s,operator/actions}.ts: every CR producer/reader migrated.
- tools/headlamp-plugin/src/index.tsx: all 4 egress readers consume
  egressMode directly.
- docs/use-cases.md, docs/egress-proxy.md: samples updated.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 2031d81 into dev May 13, 2026
21 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the slice-5b-egress-mode-enum branch May 13, 2026 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant