Repository navigation
phase2/toolpolicy-reconciler — full reconciler + AGT profile compile + helm CRD (S2) - #52
Merged
Conversation
…e compile + helm CRD (S2)
Phase 2 slice S2 — ToolPolicy goes from Phase-1 schema-only to fully
reconciled. Operators write Kubernetes-native YAML; upstream Microsoft
AGT (`agentmesh` crate v3.1.0, unmodified) owns the actual policy
decisions via the Phase 1 `PolicyDecisionProvider` seam.
Responsibility boundary (no clash):
* AzureClaw owns: CRD schema, K8s reconciliation, ConfigMap
distribution, helm/drift detection.
* AGT owns: `decide()`, signing, audit chain, trust lattice. No fork,
no re-implementation.
Added:
* controller/src/tool_policy_compile.rs — pure spec → AGT JSON profile
(BTreeMap-backed canonical key order; sha256-prefix version hash).
* controller/src/tool_policy_reconciler.rs — modelled on S1
mcp_server_reconciler; SSA field manager 'azureclaw-controller/toolpolicy';
finalizer 'azureclaw.azure.com/toolpolicy-cleanup'; ConfigMap
'toolpolicy-{name}-profile' with key 'profile.json' + version-hash
annotation + selector labels for the future S7 router informer.
* deploy/helm/azureclaw/templates/crd-toolpolicy.yaml — generated by
the dumper-test pattern; drift-protected by helm_drift.rs.
* docs/security-audits/2026-04-27-phase2-toolpolicy-reconciler.md —
§0 enumerates 13 reused Phase 0/1/S1 seams (no-duplication rule).
Modified:
* controller/src/helm_drift.rs — generalised for multiple CRDs
(per-CRD path constants + shared assert_helm_matches_rust helper).
* controller/src/main.rs — spawns tool_policy_reconciler::run.
* CHANGELOG.md — S2 entry.
Tests: +12 unit + 2 helm-drift. Controller bins suite 165 → 177, 0
failures. cargo fmt / clippy -D warnings / workspace tests / all
ci/*.sh gates green (BASE_REF=origin/dev).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Apr 27, 2026
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…e compile + helm CRD (S2) (#52) Phase 2 slice S2 — ToolPolicy goes from Phase-1 schema-only to fully reconciled. Operators write Kubernetes-native YAML; upstream Microsoft AGT (`agentmesh` crate v3.1.0, unmodified) owns the actual policy decisions via the Phase 1 `PolicyDecisionProvider` seam. Responsibility boundary (no clash): * AzureClaw owns: CRD schema, K8s reconciliation, ConfigMap distribution, helm/drift detection. * AGT owns: `decide()`, signing, audit chain, trust lattice. No fork, no re-implementation. Added: * controller/src/tool_policy_compile.rs — pure spec → AGT JSON profile (BTreeMap-backed canonical key order; sha256-prefix version hash). * controller/src/tool_policy_reconciler.rs — modelled on S1 mcp_server_reconciler; SSA field manager 'azureclaw-controller/toolpolicy'; finalizer 'azureclaw.azure.com/toolpolicy-cleanup'; ConfigMap 'toolpolicy-{name}-profile' with key 'profile.json' + version-hash annotation + selector labels for the future S7 router informer. * deploy/helm/azureclaw/templates/crd-toolpolicy.yaml — generated by the dumper-test pattern; drift-protected by helm_drift.rs. * docs/security-audits/2026-04-27-phase2-toolpolicy-reconciler.md — §0 enumerates 13 reused Phase 0/1/S1 seams (no-duplication rule). Modified: * controller/src/helm_drift.rs — generalised for multiple CRDs (per-CRD path constants + shared assert_helm_matches_rust helper). * controller/src/main.rs — spawns tool_policy_reconciler::run. * CHANGELOG.md — S2 entry. Tests: +12 unit + 2 helm-drift. Controller bins suite 165 → 177, 0 failures. cargo fmt / clippy -D warnings / workspace tests / all ci/*.sh gates green (BASE_REF=origin/dev). Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 2 / S2 — ToolPolicy reconciler
Second Phase 2 slice. Takes
ToolPolicyfrom Phase-1 schema-only to fully reconciled. Same pattern as S1 (phase2/mcp-reconciler, PR #51).Responsibility boundary (no clash with AGT)
decide(), signing, audit chain, trust latticeagentmeshcrate v3.1.0, unmodified)No fork. No custom policy engine. AzureClaw provides the Kubernetes-native ergonomics; AGT does the work via the Phase 1
PolicyDecisionProviderseam.What's in this slice
controller/src/tool_policy_compile.rs— pure-function compileToolPolicySpec → AGT JSON profile. Deterministic (BTreeMap key order); sha256-prefixversion_hashfor change detection.controller/src/tool_policy_reconciler.rs— full reconciler modelled on S1mcp_server_reconciler.rs. SSA field managerazureclaw-controller/toolpolicy(per §10.4 Bump jsonwebtoken from 9.3.1 to 10.3.0 #1); finalizerazureclaw.azure.com/toolpolicy-cleanup; emits ConfigMaptoolpolicy-{name}-profilewith keyprofile.json+azureclaw.azure.com/toolpolicy-version-hashannotation + selector labels for the future S7 router informer.deploy/helm/azureclaw/templates/crd-toolpolicy.yaml— generated by the dumper-test pattern; drift-protected.controller/src/helm_drift.rsgeneralised for multi-CRD (sharedassert_helm_matches_rusthelper, per-CRD path constants).docs/security-audits/2026-04-27-phase2-toolpolicy-reconciler.md. §0 enumerates 13 reused Phase 0/1/S1 seams (no-duplication rule from Phase 2 plan §0.2/§0.3).Tests
tool_policy_compile::tests, 6 intool_policy_reconciler::tests)Verification (all green)
cargo fmt --all -- --checkcargo clippy --all-targets -- -D warningscargo test --workspaceci/no-stubs.shci/no-custom-crypto.shci/check-loc.shci/security-audit-required.shci/no-null-provider-prod.shci/a2a-module-isolation.shci/vendored-patch-audit.shhelm_toolpolicy_crd_matches_rust_schema(BASE_REF=origin/dev for the diff-based gates.)
§14.6 impact
Next
S3
phase2/a2aagent-reconcileris next ready (independent of S2 — both compile to the samePolicyEnvelopeshape).