Repository navigation
phase2/inferencepolicy-reconciler — full reconciler + compile + helm CRD (S4) - #54
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoApr 27, 2026
Conversation
…compile + helm CRD (S4) Phase 2 §8 entry 4. Ships the K8s primitive only — `InferencePolicy` is NOT a model-router (per §3 non-compete; model selection sits in Foundry). Sandbox-side budget / guardrail / safety policy CR, compiled to a JSON ConfigMap that the S7 router-side informer will load into the existing PolicyEnvelope. Per user direction 2026-04-27, runtime enforcement substrate stays on Phase 1: `inference-router::budget::TokenBudgetTracker` (env-fed) for tokens, Foundry Content Safety + `safety::report_content_flags_to_agt` → AGT BehaviorMonitor for safety. AGT-Rust 3.3.0 verified against `/Users/pallakatos/Private/Repos/agt/agent-governance-toolkit` — AGT-Python has BudgetTracker, AGT-Rust does not yet; the upstream port is an S7 decision and is explicitly out of scope here. Added: - controller/src/inference_policy.rs — CRD struct + spec sub-types (TokenBudget, ContentSafetyFloor, ModelPreference, ModelRef) + status reusing mcp_server::LocalObjectRef (4th semantic client). - controller/src/inference_policy_compile.rs — pure-fn compile_to_profile + version_hash, deterministic, key-canonical; output shape slots into PolicyEntry.payload, no parallel hot-reload. - controller/src/inference_policy_reconciler.rs — modeled on S3 a2a_agent_reconciler. Field manager azureclaw-controller/inferencepolicy (distinct per §10.4 #1), finalizer azureclaw.azure.com/inferencepolicy-cleanup. Conditions reuse status::conditions; closed-set error_class per §15.3. - 6 CEL admission rules in crd_validations.rs: monthlyTokens >= dailyTokens, monthlyTokens >= perRequestTokens, contentSafety severity ∈ {Safe,Low,Medium,High}, modelPreference primary/fallback non-empty provider+deployment, appliesTo.action ∈ {chat,responses,image,embeddings,*}. - deploy/helm/azureclaw/templates/crd-inferencepolicy.yaml — drift- checked by helm_inferencepolicy_crd_matches_rust_schema. - docs/security-audits/2026-04-27-phase2-inferencepolicy-reconciler.md — AGT boundary verification, STRIDE, out-of-scope list, two sign-offs. Tests: +20 (6 compile + 7 reconciler + 5 admission + 2 helm-drift). Controller suite 193 → 218. Workspace cargo test/fmt/clippy all green. §14.6: strengthens column 7 (Foundry / M365 integration) — primitive lands here; runtime consumers wired in S7. AGT crate pin unchanged: agentmesh = "3.3.0" from crates.io, no fork. `vendor/` directory untouched. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
phase2/inferencepolicy-reconciler
branch
April 27, 2026 16:23
This was referenced Apr 27, 2026
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…compile + helm CRD (S4) (#54) Phase 2 §8 entry 4. Ships the K8s primitive only — `InferencePolicy` is NOT a model-router (per §3 non-compete; model selection sits in Foundry). Sandbox-side budget / guardrail / safety policy CR, compiled to a JSON ConfigMap that the S7 router-side informer will load into the existing PolicyEnvelope. Per user direction 2026-04-27, runtime enforcement substrate stays on Phase 1: `inference-router::budget::TokenBudgetTracker` (env-fed) for tokens, Foundry Content Safety + `safety::report_content_flags_to_agt` → AGT BehaviorMonitor for safety. AGT-Rust 3.3.0 verified against `/Users/pallakatos/Private/Repos/agt/agent-governance-toolkit` — AGT-Python has BudgetTracker, AGT-Rust does not yet; the upstream port is an S7 decision and is explicitly out of scope here. Added: - controller/src/inference_policy.rs — CRD struct + spec sub-types (TokenBudget, ContentSafetyFloor, ModelPreference, ModelRef) + status reusing mcp_server::LocalObjectRef (4th semantic client). - controller/src/inference_policy_compile.rs — pure-fn compile_to_profile + version_hash, deterministic, key-canonical; output shape slots into PolicyEntry.payload, no parallel hot-reload. - controller/src/inference_policy_reconciler.rs — modeled on S3 a2a_agent_reconciler. Field manager azureclaw-controller/inferencepolicy (distinct per §10.4 #1), finalizer azureclaw.azure.com/inferencepolicy-cleanup. Conditions reuse status::conditions; closed-set error_class per §15.3. - 6 CEL admission rules in crd_validations.rs: monthlyTokens >= dailyTokens, monthlyTokens >= perRequestTokens, contentSafety severity ∈ {Safe,Low,Medium,High}, modelPreference primary/fallback non-empty provider+deployment, appliesTo.action ∈ {chat,responses,image,embeddings,*}. - deploy/helm/azureclaw/templates/crd-inferencepolicy.yaml — drift- checked by helm_inferencepolicy_crd_matches_rust_schema. - docs/security-audits/2026-04-27-phase2-inferencepolicy-reconciler.md — AGT boundary verification, STRIDE, out-of-scope list, two sign-offs. Tests: +20 (6 compile + 7 reconciler + 5 admission + 2 helm-drift). Controller suite 193 → 218. Workspace cargo test/fmt/clippy all green. §14.6: strengthens column 7 (Foundry / M365 integration) — primitive lands here; runtime consumers wired in S7. AGT crate pin unchanged: agentmesh = "3.3.0" from crates.io, no fork. `vendor/` directory untouched. Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 2 §8 entry 4 (S4). Ships the K8s primitive only —
InferencePolicyis not a model-router (per §3 non-compete; model selection sits in Foundry). Sandbox-side budget / guardrail / safety policy CR, compiled to a JSON ConfigMap that the S7 router-side informer will load into the existingPolicyEnvelope.AGT boundary (verified 2026-04-27 against agent-governance-toolkit 3.3.0 on disk)
agentmesh.governance.budget::BudgetTracker(token + USD cost, windowed).PolicyEngine,TrustManager,mcp::rate_limit::McpSlidingRateLimiter(call-count),BehaviorMonitor,AuditLogger.cedar-policy+regorusare deps but no native Content-Safety severity-floor module.inference-router::budget(env-fed) for tokens, Foundry Content Safety +safety::report_content_flags_to_agt→ AGTBehaviorMonitorfor safety. The S7 audit doc records the choice between (a) portingBudgetTrackerupstream to AGT-Rust, (b) encoding as a customagentmesh::PolicyRule, or (c) keepingbudget.rsand feeding it fromPolicyEntry.payload.agentmesh = "3.3.0"from crates.io. No fork.vendor/untouched.What lands
controller/src/inference_policy.rs).inference_policy_compile.rs) — deterministic, key-canonical, sha256 version hash.inference_policy_reconciler.rs) — modeled on S3. Field managerazureclaw-controller/inferencepolicy(distinct per §10.4 Bump jsonwebtoken from 9.3.1 to 10.3.0 #1), finalizerazureclaw.azure.com/inferencepolicy-cleanup, Conditions matrix viastatus::conditions, closed-seterror_classper §15.3.deploy/helm/azureclaw/templates/crd-inferencepolicy.yaml) — drift-checked.Reuse map
12 existing seams reused (status::conditions, LocalObjectRef as 4th semantic client, S3 reconciler shape, S2 compile-module shape, helm_drift::canonical_form, PolicyEntry.payload contract, Phase-1 router-side runtime gate, Phase-1
budget::TokenBudgetTracker, Phase-1safety::report_content_flags_to_agt, MS Content Safety severity vocabulary, RFC-3339 formatter). Single new struct: none.Tests: +20
inference_policy_compile::testsinference_policy_reconciler::testscrd_validations::testshelm_drift::testsController suite 193 → 218. Workspace
cargo test/cargo fmt/cargo clippy --all-targets -D warningsall green. CI scripts (no-stubs,no-custom-crypto,check-loc,security-audit-required,no-null-provider-prod,a2a-module-isolation,vendored-patch-audit) all clean. CLI typecheck + lint clean.§14.6 impact
Strengthens column 7 (Foundry / M365 integration) — primitive lands; runtime consumers wired in S7.
Out of scope (deferred)
routes/inference_policy::checkconsumingPolicyEntry.payload→ S7.budget::TokenBudgetTrackerinputs → S7.agentmesh::PolicyEngine→ S7/S13.v1alpha2config-authority migration fromClawSandbox.spec.inference→ S13.