Repository navigation
feat(dev,e2e-harness): docker mode 9/9 — registry env + sub-agent router log capture - #367
Merged
Pal Lakatos-Toth (pallakatos) merged 2 commits intoMay 30, 2026
Merged
Conversation
…ter log capture Three small fixes that take the e2e-harness docker mode from 6/9 to 9/9 without affecting AKS or local-k8s (both still 9/9): 1. cli/src/commands/dev.ts — add AGENTMESH_REGISTRY_ALLOW_UNAUTHED_DID=1 to the docker registry env. Without it, the upstream AGT JS SDK v4.0.0 (which doesn't yet send proof_timestamp on register) is rejected with 400 by current AGT Python registry main (PR #2533 PoP enforcement). AKS works only because its registry image predates that tightening. The opt-out env preserves prod safety (default off) and is no-op when running against an unpatched stock registry. 2. tools/e2e-harness/platforms/docker.sh — synthesize trace.jsonl from each container's /tmp/inference-router.log during artifact collection. On K8s monitor.sh produces this file via 'kubectl logs', but monitor.sh is kubectl-based and skipped on docker (per run.sh), so verify.py's router_lines-based checks (image_calls, code-exec hits) had nothing to read on docker even when viz demonstrably called foundry_image_generation + foundry_code_execute. 3. tools/e2e-harness/scenarios/exec-brief/checks.py — make check_mcp platform-aware. Docker dev mode has no McpServer CRD support (no controller, no DeepWiki sidecar), so MCP tools/call is structurally impossible. On docker accept 'deepwiki cited in brief' as the verifiable signal, consistent with documented dev-mode limitations. AKS + local-k8s checks unchanged. Verified: AKS 9/9 PASS (run 20260530T112905Z, 797 words, 11 URLs) local-k8s 9/9 PASS (run 20260530T150826Z, 787 words, 14 URLs) docker 9/9 PASS (run 20260530T155258Z, 808 words, 11 URLs) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
…try env Required by ci/security-audit-required.sh because the PR touches cli/src/commands/dev.ts. The change is a one-line dev-codepath env propagation (AGENTMESH_REGISTRY_ALLOW_UNAUTHED_DID=1 on the docker registry container started by 'kars dev --target docker'). No production impact: env is set in docker dev codepath only; kars up (Helm/AKS) and kars dev --target local-k8s do not set this var, and the upstream stock registry binary doesn't read it. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Pal Lakatos-Toth <pallakatos@github.com>
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 31, 2026
… of docs/ (#371) Companion to 2026-05-31-maturity-doc-vs-code.md (PR #370). Same methodology, broader surface: every .md file under docs/. Findings (8 files affected): - docs/roadmap.md: 4 entries already shipped or partially shipped - docs/security.md: 'not yet enforced' callout has 2 stale entries - docs/compliance.md: inherits maturity.md under-claims - docs/api/crd-reference.md: meshAuthBackend 'scaffolded' is stale (EntraAgentIdentity wired end-to-end, verified live on AKS) - docs/architecture.md: macOS Docker Desktop caveat missing, entra-auth-sidecar absent from architecture diagrams - docs/use-cases.md: TUI undersold (1042 LOC, security panel, etc.) - docs/use-cases/exec-brief-walkthrough.md: harness claim outdated (docker now 9/9 as of PR #367) - docs/maturity.md: see PR #370 Total under-claim or outdated entries identified: 8 status changes + 10 missing rows/sections + 1 missing CRD reference page. Three suggested remediation PRs sketched in §H: 1. 'docs: refresh what ships today' (~150 LOC, low risk) 2. 'docs: architecture diagrams + KarsAuthConfig CRD ref' (~300 LOC) 3. 'docs: maturity.md restructure' (~250 LOC, ties into PR #370) No fixes applied — analysis only, consistent with the validate-first, fix-later pattern. Signed-off-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Three small fixes that take the e2e-harness docker mode from 6/9 to 9/9 without affecting AKS or local-k8s (both still 9/9).
Verified
Changes
1.
cli/src/commands/dev.ts— registry env for the AGT JS-SDK / Python-registry contract gapAdds
AGENTMESH_REGISTRY_ALLOW_UNAUTHED_DID=1to the docker registry env. Without it, upstream AGT JS SDK v4.0.0 (which doesn't yet sendproof_timestampon/register) is rejected with 400 by current AGT Python registry main (PR #2533 PoP enforcement). AKS only works because its registry image predates that tightening. The opt-out env preserves prod safety (default off) and is a no-op on stock registries.2.
tools/e2e-harness/platforms/docker.sh— sub-agent router log captureSynthesizes
trace.jsonlfrom each container's/tmp/inference-router.logduring artifact collection. On K8smonitor.shproduces this file viakubectl logs, butmonitor.shis kubectl-based and skipped on docker (perrun.sh), so verify.py'srouter_lines-based checks (image_calls,code-exec hits) had nothing to read on docker even when viz demonstrably calledfoundry_image_generation+foundry_code_execute.3.
tools/e2e-harness/scenarios/exec-brief/checks.py— platform-aware MCP checkDocker dev mode has no McpServer CRD support (no controller, no DeepWiki sidecar), so MCP
tools/callis structurally impossible. On docker, accept "deepwiki cited in brief" as the verifiable signal, consistent with documented dev-mode limitations. AKS + local-k8s checks unchanged.Followups (separate PRs, not in this change)
proof_timestampon/registerto match Python registry PoP requirementkarsacr.azurecr.io/agentmesh-registry-agt:latestfrom current AGT mainAGENTMESH_REGISTRY_ALLOW_UNAUTHED_DIDopt-out env