Skip to content

phase2/toolpolicy-reconciler — full reconciler + AGT profile compile + helm CRD (S2) - #52

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2/toolpolicy-reconciler
Apr 27, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2/toolpolicy-reconciler

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Phase 2 / S2 — ToolPolicy reconciler

Second Phase 2 slice. Takes ToolPolicy from Phase-1 schema-only to fully reconciled. Same pattern as S1 (phase2/mcp-reconciler, PR #51).

Responsibility boundary (no clash with AGT)

Layer Owner
CRD schema, K8s reconciliation, ConfigMap distribution AzureClaw
decide(), signing, audit chain, trust lattice Upstream Microsoft AGT (agentmesh crate v3.1.0, unmodified)

No fork. No custom policy engine. AzureClaw provides the Kubernetes-native ergonomics; AGT does the work via the Phase 1 PolicyDecisionProvider seam.

What's in this slice

  • controller/src/tool_policy_compile.rs — pure-function compile ToolPolicySpec → AGT JSON profile. Deterministic (BTreeMap key order); sha256-prefix version_hash for change detection.
  • controller/src/tool_policy_reconciler.rs — full reconciler modelled on S1 mcp_server_reconciler.rs. SSA field manager azureclaw-controller/toolpolicy (per §10.4 Bump jsonwebtoken from 9.3.1 to 10.3.0 #1); finalizer azureclaw.azure.com/toolpolicy-cleanup; emits ConfigMap toolpolicy-{name}-profile with key profile.json + azureclaw.azure.com/toolpolicy-version-hash annotation + selector labels for the future S7 router informer.
  • deploy/helm/azureclaw/templates/crd-toolpolicy.yaml — generated by the dumper-test pattern; drift-protected.
  • controller/src/helm_drift.rs generalised for multi-CRD (shared assert_helm_matches_rust helper, per-CRD path constants).
  • Audit doc — docs/security-audits/2026-04-27-phase2-toolpolicy-reconciler.md. §0 enumerates 13 reused Phase 0/1/S1 seams (no-duplication rule from Phase 2 plan §0.2/§0.3).

Tests

  • +12 unit tests (6 in tool_policy_compile::tests, 6 in tool_policy_reconciler::tests)
  • +2 helm-drift tests for the new CRD
  • Controller bins suite: 165 → 177 tests, 0 failures

Verification (all green)

Gate Result
cargo fmt --all -- --check ✅
cargo clippy --all-targets -- -D warnings ✅
cargo test --workspace ✅ 0 failures
ci/no-stubs.sh ✅
ci/no-custom-crypto.sh ✅
ci/check-loc.sh ✅
ci/security-audit-required.sh ✅
ci/no-null-provider-prod.sh ✅
ci/a2a-module-isolation.sh ✅
ci/vendored-patch-audit.sh ✅
Helm CRD drift test ✅ helm_toolpolicy_crd_matches_rust_schema
CLI typecheck / lint ✅

(BASE_REF=origin/dev for the diff-based gates.)

§14.6 impact

  • Strengthens column 4 (A2A 1.2 + AP2): commerce caps + approval + rateLimit now compile end-to-end into a hot-reloadable artifact.
  • Strengthens column 12 (Governance as K8s primitives): second of the five differentiator CRDs goes schema-only → fully reconciled.

Next

S3 phase2/a2aagent-reconciler is next ready (independent of S2 — both compile to the same PolicyEnvelope shape).

…e compile + helm CRD (S2)

Phase 2 slice S2 — ToolPolicy goes from Phase-1 schema-only to fully
reconciled. Operators write Kubernetes-native YAML; upstream Microsoft
AGT (`agentmesh` crate v3.1.0, unmodified) owns the actual policy
decisions via the Phase 1 `PolicyDecisionProvider` seam.

Responsibility boundary (no clash):
* AzureClaw owns: CRD schema, K8s reconciliation, ConfigMap
  distribution, helm/drift detection.
* AGT owns: `decide()`, signing, audit chain, trust lattice. No fork,
  no re-implementation.

Added:
* controller/src/tool_policy_compile.rs — pure spec → AGT JSON profile
  (BTreeMap-backed canonical key order; sha256-prefix version hash).
* controller/src/tool_policy_reconciler.rs — modelled on S1
  mcp_server_reconciler; SSA field manager 'azureclaw-controller/toolpolicy';
  finalizer 'azureclaw.azure.com/toolpolicy-cleanup'; ConfigMap
  'toolpolicy-{name}-profile' with key 'profile.json' + version-hash
  annotation + selector labels for the future S7 router informer.
* deploy/helm/azureclaw/templates/crd-toolpolicy.yaml — generated by
  the dumper-test pattern; drift-protected by helm_drift.rs.
* docs/security-audits/2026-04-27-phase2-toolpolicy-reconciler.md —
  §0 enumerates 13 reused Phase 0/1/S1 seams (no-duplication rule).

Modified:
* controller/src/helm_drift.rs — generalised for multiple CRDs
  (per-CRD path constants + shared assert_helm_matches_rust helper).
* controller/src/main.rs — spawns tool_policy_reconciler::run.
* CHANGELOG.md — S2 entry.

Tests: +12 unit + 2 helm-drift. Controller bins suite 165 → 177, 0
failures. cargo fmt / clippy -D warnings / workspace tests / all
ci/*.sh gates green (BASE_REF=origin/dev).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 4dcfb24 into dev Apr 27, 2026
15 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2/toolpolicy-reconciler branch April 27, 2026 15:16
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
…e compile + helm CRD (S2) (#52)

Phase 2 slice S2 — ToolPolicy goes from Phase-1 schema-only to fully
reconciled. Operators write Kubernetes-native YAML; upstream Microsoft
AGT (`agentmesh` crate v3.1.0, unmodified) owns the actual policy
decisions via the Phase 1 `PolicyDecisionProvider` seam.

Responsibility boundary (no clash):
* AzureClaw owns: CRD schema, K8s reconciliation, ConfigMap
  distribution, helm/drift detection.
* AGT owns: `decide()`, signing, audit chain, trust lattice. No fork,
  no re-implementation.

Added:
* controller/src/tool_policy_compile.rs — pure spec → AGT JSON profile
  (BTreeMap-backed canonical key order; sha256-prefix version hash).
* controller/src/tool_policy_reconciler.rs — modelled on S1
  mcp_server_reconciler; SSA field manager 'azureclaw-controller/toolpolicy';
  finalizer 'azureclaw.azure.com/toolpolicy-cleanup'; ConfigMap
  'toolpolicy-{name}-profile' with key 'profile.json' + version-hash
  annotation + selector labels for the future S7 router informer.
* deploy/helm/azureclaw/templates/crd-toolpolicy.yaml — generated by
  the dumper-test pattern; drift-protected by helm_drift.rs.
* docs/security-audits/2026-04-27-phase2-toolpolicy-reconciler.md —
  §0 enumerates 13 reused Phase 0/1/S1 seams (no-duplication rule).

Modified:
* controller/src/helm_drift.rs — generalised for multiple CRDs
  (per-CRD path constants + shared assert_helm_matches_rust helper).
* controller/src/main.rs — spawns tool_policy_reconciler::run.
* CHANGELOG.md — S2 entry.

Tests: +12 unit + 2 helm-drift. Controller bins suite 165 → 177, 0
failures. cargo fmt / clippy -D warnings / workspace tests / all
ci/*.sh gates green (BASE_REF=origin/dev).

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant