Repository navigation
phase2/a2aagent-reconciler — full reconciler + AgentCard compile + helm CRD (S3) - #53
Merged
Merged
Conversation
…ile + helm CRD (S3) Closes §14.6 column 4 (A2A 1.2 + AP2 — schema → AgentCard publication path). Mirrors S2's compile-and-publish pattern; router-side mount + JWS signing + trust-store informer wiring deferred to S7. Responsibility boundary: AzureClaw owns the CRD, the K8s reconciliation, the ConfigMap distribution, the helm/drift detection. Upstream Microsoft AGT crate (agentmesh v3.1.0 from crates.io, UNMODIFIED) remains the policy authority. No fork. The vendored vendor/ directory contains only AgentMesh transport (npm SDK + relay/registry) and is unrelated. Also adds S3.5 phase2-a2a-gateway-component to the Phase 2 plan (docs/implementation-plan.md §8 scope item 2a + plan.md slice list) to close ADR-0001 implementation step #4: the public-facing azureclaw-a2a-gateway binary that lets inbound A2A 1.2 federation actually receive traffic. Drafted in Phase 1, binary not yet built; S3 ships the data, S3.5 ships the public edge. Tests: +16 controller unit tests (193 total, was 177). Workspace unchanged otherwise (router 595, integration 26). All gates pass against BASE_REF=origin/dev. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Apr 27, 2026
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…ile + helm CRD (S3) (#53) Closes §14.6 column 4 (A2A 1.2 + AP2 — schema → AgentCard publication path). Mirrors S2's compile-and-publish pattern; router-side mount + JWS signing + trust-store informer wiring deferred to S7. Responsibility boundary: AzureClaw owns the CRD, the K8s reconciliation, the ConfigMap distribution, the helm/drift detection. Upstream Microsoft AGT crate (agentmesh v3.1.0 from crates.io, UNMODIFIED) remains the policy authority. No fork. The vendored vendor/ directory contains only AgentMesh transport (npm SDK + relay/registry) and is unrelated. Also adds S3.5 phase2-a2a-gateway-component to the Phase 2 plan (docs/implementation-plan.md §8 scope item 2a + plan.md slice list) to close ADR-0001 implementation step #4: the public-facing azureclaw-a2a-gateway binary that lets inbound A2A 1.2 federation actually receive traffic. Drafted in Phase 1, binary not yet built; S3 ships the data, S3.5 ships the public edge. Tests: +16 controller unit tests (193 total, was 177). Workspace unchanged otherwise (router 595, integration 26). All gates pass against BASE_REF=origin/dev. Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Phase 2 S3 — full
A2AAgentreconciler. Closes §14.6 column 4 (A2A 1.2 + AP2 — schema → AgentCard publication path). Mirrors S2's compile-and-publish pattern: spec → wire-format AgentCard JSON → ConfigMap. Router-side/.well-known/agent.jsonmount + JWS signing + trust-store informer wiring deferred to S7 (phase2-conditions-ssa-leader).Responsibility boundary (AGT)
AzureClaw owns: CRD schema, K8s reconciliation, ConfigMap distribution, helm/drift detection.
Upstream Microsoft
agentmeshv3.1.0 from crates.io (unmodified) remains the policy authority.No fork of AGT. The vendored
vendor/directory contains only AgentMesh transport (npm SDK + relay/registry from amitayks) and is unrelated.What ships
controller/src/a2a_agent.rs— CRD struct (group/version/kind/shortnamea2a), spec sub-types (A2aSigningKey,TrustThresholds,FederationPeer,PolicyRefs), status.signingKeys[*]shape mirrorsinference-router::a2a::agent_projection::A2aAgentSigningKeySpec1:1 — wire bytes traverse controller → ConfigMap → router with no transformation.controller/src/a2a_agent_compile.rs— purecompile_agent_card(spec, namespace, name) → Value+version_hash(sha256 prefix). 6 unit tests.controller/src/a2a_agent_reconciler.rs— full reconciler. Field managerazureclaw-controller/a2aagent, finalizerazureclaw.azure.com/a2aagent-cleanup, ConfigMapa2aagent-{name}-card. 7 unit tests.controller/src/crd_validations.rs— 4 CEL admission rules (signingKeys non-empty, EdDSA-only, productionMode⇒https, federation in-cluster/external mutual exclusion) + 5 admission tests.controller/src/helm_drift.rs— third helm-drift gate (a2aagent).deploy/helm/azureclaw/templates/crd-a2aagent.yaml— generated by dumper.docs/security-audits/2026-04-27-phase2-a2a-reconciler.md— full audit (§0 reuse map of ~14 seams, STRIDE, OWASP A2A, explicit out-of-scope list, two sign-offs).New slice added: S3.5
phase2-a2a-gateway-componentADR-0001 ("A2A 1.0 ingress — single gateway, router never publicly exposed") is Accepted. Phase 1 shipped 8 of its 9 implementation steps; only step #4 (the gateway binary itself) was missing. Without it, only outbound A2A is usable end-to-end. S3 ships the AgentCard data; S3.5 ships the public edge that lets inbound A2A 1.2 federation actually receive traffic.
Added to:
docs/implementation-plan.md§8 scope item 2a.plan.mdslice list (between S3 and S4).Tests
Gates (BASE_REF=origin/dev)
cargo fmt --all -- --checkcargo build --allcargo test --workspacecargo clippy --all-targets -- -D warningsci/check-loc.shci/no-stubs.shci/no-custom-crypto.shci/security-audit-required.shci/no-null-provider-prod.shci/a2a-module-isolation.shci/vendored-patch-audit.shnpm run typechecknpm run lintMerge
Same cadence as S1/S2: squash + admin merge once Rust CI is green; container scan deferred to the dev → main integration cadence.
Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com