Skip to content

phase2/inferencepolicy-reconciler — full reconciler + compile + helm CRD (S4) - #54

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2/inferencepolicy-reconciler
Apr 27, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2/inferencepolicy-reconciler

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Phase 2 §8 entry 4 (S4). Ships the K8s primitive only — InferencePolicy is not a model-router (per §3 non-compete; model selection sits in Foundry). Sandbox-side budget / guardrail / safety policy CR, compiled to a JSON ConfigMap that the S7 router-side informer will load into the existing PolicyEnvelope.

AGT boundary (verified 2026-04-27 against agent-governance-toolkit 3.3.0 on disk)

  • AGT-Python 3.3.0 has agentmesh.governance.budget::BudgetTracker (token + USD cost, windowed).
  • AGT-Rust 3.3.0 does NOT have it yet. It exposes PolicyEngine, TrustManager, mcp::rate_limit::McpSlidingRateLimiter (call-count), BehaviorMonitor, AuditLogger. cedar-policy + regorus are deps but no native Content-Safety severity-floor module.
  • Per user direction, S4 ships only the primitive. Runtime enforcement stays on Phase 1: inference-router::budget (env-fed) for tokens, Foundry Content Safety + safety::report_content_flags_to_agt → AGT BehaviorMonitor for safety. The S7 audit doc records the choice between (a) porting BudgetTracker upstream to AGT-Rust, (b) encoding as a custom agentmesh::PolicyRule, or (c) keeping budget.rs and feeding it from PolicyEntry.payload.
  • AGT crate pin unchanged: agentmesh = "3.3.0" from crates.io. No fork. vendor/ untouched.

What lands

  • CRD struct + 5 spec sub-types (controller/src/inference_policy.rs).
  • Pure compile module (inference_policy_compile.rs) — deterministic, key-canonical, sha256 version hash.
  • Reconciler (inference_policy_reconciler.rs) — modeled on S3. Field manager azureclaw-controller/inferencepolicy (distinct per §10.4 Bump jsonwebtoken from 9.3.1 to 10.3.0 #1), finalizer azureclaw.azure.com/inferencepolicy-cleanup, Conditions matrix via status::conditions, closed-set error_class per §15.3.
  • 6 CEL admission rules (token-budget consistency × 2, severity closed set, primary/fallback non-empty × 2, action closed set).
  • Helm CRD (deploy/helm/azureclaw/templates/crd-inferencepolicy.yaml) — drift-checked.
  • Audit doc with two sign-offs.

Reuse map

12 existing seams reused (status::conditions, LocalObjectRef as 4th semantic client, S3 reconciler shape, S2 compile-module shape, helm_drift::canonical_form, PolicyEntry.payload contract, Phase-1 router-side runtime gate, Phase-1 budget::TokenBudgetTracker, Phase-1 safety::report_content_flags_to_agt, MS Content Safety severity vocabulary, RFC-3339 formatter). Single new struct: none.

Tests: +20

Module New tests
inference_policy_compile::tests 6
inference_policy_reconciler::tests 7
crd_validations::tests 5
helm_drift::tests 2

Controller suite 193 → 218. Workspace cargo test / cargo fmt / cargo clippy --all-targets -D warnings all green. CI scripts (no-stubs, no-custom-crypto, check-loc, security-audit-required, no-null-provider-prod, a2a-module-isolation, vendored-patch-audit) all clean. CLI typecheck + lint clean.

§14.6 impact

Strengthens column 7 (Foundry / M365 integration) — primitive lands; runtime consumers wired in S7.

Out of scope (deferred)

  • Router-side informer wiring → S7.
  • VAP for content-safety floor cluster-minimum → S7 §7.14.
  • routes/inference_policy::check consuming PolicyEntry.payload → S7.
  • Replacing env-fed budget::TokenBudgetTracker inputs → S7.
  • Cedar/Rego policy emission for content-safety floors via agentmesh::PolicyEngine → S7/S13.
  • v1alpha2 config-authority migration from ClawSandbox.spec.inference → S13.

…compile + helm CRD (S4)

Phase 2 §8 entry 4. Ships the K8s primitive only — `InferencePolicy` is
NOT a model-router (per §3 non-compete; model selection sits in
Foundry). Sandbox-side budget / guardrail / safety policy CR, compiled
to a JSON ConfigMap that the S7 router-side informer will load into the
existing PolicyEnvelope.

Per user direction 2026-04-27, runtime enforcement substrate stays on
Phase 1: `inference-router::budget::TokenBudgetTracker` (env-fed) for
tokens, Foundry Content Safety + `safety::report_content_flags_to_agt`
→ AGT BehaviorMonitor for safety. AGT-Rust 3.3.0 verified against
`/Users/pallakatos/Private/Repos/agt/agent-governance-toolkit` —
AGT-Python has BudgetTracker, AGT-Rust does not yet; the upstream port
is an S7 decision and is explicitly out of scope here.

Added:
- controller/src/inference_policy.rs — CRD struct + spec sub-types
  (TokenBudget, ContentSafetyFloor, ModelPreference, ModelRef) + status
  reusing mcp_server::LocalObjectRef (4th semantic client).
- controller/src/inference_policy_compile.rs — pure-fn
  compile_to_profile + version_hash, deterministic, key-canonical;
  output shape slots into PolicyEntry.payload, no parallel hot-reload.
- controller/src/inference_policy_reconciler.rs — modeled on S3
  a2a_agent_reconciler. Field manager azureclaw-controller/inferencepolicy
  (distinct per §10.4 #1), finalizer
  azureclaw.azure.com/inferencepolicy-cleanup. Conditions reuse
  status::conditions; closed-set error_class per §15.3.
- 6 CEL admission rules in crd_validations.rs:
  monthlyTokens >= dailyTokens, monthlyTokens >= perRequestTokens,
  contentSafety severity ∈ {Safe,Low,Medium,High},
  modelPreference primary/fallback non-empty provider+deployment,
  appliesTo.action ∈ {chat,responses,image,embeddings,*}.
- deploy/helm/azureclaw/templates/crd-inferencepolicy.yaml — drift-
  checked by helm_inferencepolicy_crd_matches_rust_schema.
- docs/security-audits/2026-04-27-phase2-inferencepolicy-reconciler.md
  — AGT boundary verification, STRIDE, out-of-scope list, two sign-offs.

Tests: +20 (6 compile + 7 reconciler + 5 admission + 2 helm-drift).
Controller suite 193 → 218. Workspace cargo test/fmt/clippy all green.

§14.6: strengthens column 7 (Foundry / M365 integration) — primitive
lands here; runtime consumers wired in S7.

AGT crate pin unchanged: agentmesh = "3.3.0" from crates.io, no fork.
`vendor/` directory untouched.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 9766201 into dev Apr 27, 2026
15 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2/inferencepolicy-reconciler branch April 27, 2026 16:23
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
…compile + helm CRD (S4) (#54)

Phase 2 §8 entry 4. Ships the K8s primitive only — `InferencePolicy` is
NOT a model-router (per §3 non-compete; model selection sits in
Foundry). Sandbox-side budget / guardrail / safety policy CR, compiled
to a JSON ConfigMap that the S7 router-side informer will load into the
existing PolicyEnvelope.

Per user direction 2026-04-27, runtime enforcement substrate stays on
Phase 1: `inference-router::budget::TokenBudgetTracker` (env-fed) for
tokens, Foundry Content Safety + `safety::report_content_flags_to_agt`
→ AGT BehaviorMonitor for safety. AGT-Rust 3.3.0 verified against
`/Users/pallakatos/Private/Repos/agt/agent-governance-toolkit` —
AGT-Python has BudgetTracker, AGT-Rust does not yet; the upstream port
is an S7 decision and is explicitly out of scope here.

Added:
- controller/src/inference_policy.rs — CRD struct + spec sub-types
  (TokenBudget, ContentSafetyFloor, ModelPreference, ModelRef) + status
  reusing mcp_server::LocalObjectRef (4th semantic client).
- controller/src/inference_policy_compile.rs — pure-fn
  compile_to_profile + version_hash, deterministic, key-canonical;
  output shape slots into PolicyEntry.payload, no parallel hot-reload.
- controller/src/inference_policy_reconciler.rs — modeled on S3
  a2a_agent_reconciler. Field manager azureclaw-controller/inferencepolicy
  (distinct per §10.4 #1), finalizer
  azureclaw.azure.com/inferencepolicy-cleanup. Conditions reuse
  status::conditions; closed-set error_class per §15.3.
- 6 CEL admission rules in crd_validations.rs:
  monthlyTokens >= dailyTokens, monthlyTokens >= perRequestTokens,
  contentSafety severity ∈ {Safe,Low,Medium,High},
  modelPreference primary/fallback non-empty provider+deployment,
  appliesTo.action ∈ {chat,responses,image,embeddings,*}.
- deploy/helm/azureclaw/templates/crd-inferencepolicy.yaml — drift-
  checked by helm_inferencepolicy_crd_matches_rust_schema.
- docs/security-audits/2026-04-27-phase2-inferencepolicy-reconciler.md
  — AGT boundary verification, STRIDE, out-of-scope list, two sign-offs.

Tests: +20 (6 compile + 7 reconciler + 5 admission + 2 helm-drift).
Controller suite 193 → 218. Workspace cargo test/fmt/clippy all green.

§14.6: strengthens column 7 (Foundry / M365 integration) — primitive
lands here; runtime consumers wired in S7.

AGT crate pin unchanged: agentmesh = "3.3.0" from crates.io, no fork.
`vendor/` directory untouched.

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant