Repository navigation
phase2-migrate-from-kagent: ship azureclaw migrate from-kagent (S9.3) - #64
Merged
Merged
Conversation
One-shot YAML translator from a kagent.dev/v1alpha2 Agent CR (kagent-dev/kagent @ 90212ab) into an AzureClaw resource bundle. Emits: - ClawSandbox (always) - name, namespace, labels with the azureclaw.azure.com/sandbox marker, BYO image direct or --image override for Declarative agents (kagent ADK runtime not bundled), spec.sandbox.network.allowedDomains -> spec.networkPolicy .allowedEndpoints, deployment env -> spec.openclaw.extraEnv (last-literal-wins; valueFrom dropped + warned). - InferencePolicy (only when spec.declarative.modelConfig is set) - provenance-only mapping; carries the kagent ModelConfig name as azureclaw.azure.com/kagent-model-config annotation. Inference enforcement is deliberately NOT migrated. - ToolPolicy (one per (McpServer, toolName) pair) - requireApproval list maps to spec.approval.mode='always'; empty toolNames emits a wildcard ToolPolicy with a warning; type=Agent tools dropped with warning. Original TypedReference preserved as azureclaw.azure.com/kagent-tool-ref annotation; user is warned that an equivalent AzureClaw McpServer must already exist. Hard-fails on lossy translation by default; --allow-lossy waives. Same exit-code grammar as S9.2 convert: 0 ok, 2 invalid input, 4 lossy refused. --dry-run still applies the lossy gate. Aspirational mappings explicitly REJECTED per pre-implementation rubber-duck pass: - ClawAgentIdentity (Phase 4 CRD; not yet schema'd). - McpServer auto-emission (cannot reconstruct upstream endpoints). - InferencePolicy enforcement from ModelConfig (separate CRD). 53 new vitest cases. CLI 382 -> 435. Closes plan section 15.2 #8 (kagent migration tool). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
One-shot YAML translator from a kagent.dev/v1alpha2 Agent CR (kagent-dev/kagent @ 90212ab) into an AzureClaw resource bundle. Emits: - ClawSandbox (always) - name, namespace, labels with the azureclaw.azure.com/sandbox marker, BYO image direct or --image override for Declarative agents (kagent ADK runtime not bundled), spec.sandbox.network.allowedDomains -> spec.networkPolicy .allowedEndpoints, deployment env -> spec.openclaw.extraEnv (last-literal-wins; valueFrom dropped + warned). - InferencePolicy (only when spec.declarative.modelConfig is set) - provenance-only mapping; carries the kagent ModelConfig name as azureclaw.azure.com/kagent-model-config annotation. Inference enforcement is deliberately NOT migrated. - ToolPolicy (one per (McpServer, toolName) pair) - requireApproval list maps to spec.approval.mode='always'; empty toolNames emits a wildcard ToolPolicy with a warning; type=Agent tools dropped with warning. Original TypedReference preserved as azureclaw.azure.com/kagent-tool-ref annotation; user is warned that an equivalent AzureClaw McpServer must already exist. Hard-fails on lossy translation by default; --allow-lossy waives. Same exit-code grammar as S9.2 convert: 0 ok, 2 invalid input, 4 lossy refused. --dry-run still applies the lossy gate. Aspirational mappings explicitly REJECTED per pre-implementation rubber-duck pass: - ClawAgentIdentity (Phase 4 CRD; not yet schema'd). - McpServer auto-emission (cannot reconstruct upstream endpoints). - InferencePolicy enforcement from ModelConfig (separate CRD). 53 new vitest cases. CLI 382 -> 435. Closes plan section 15.2 #8 (kagent migration tool). Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Slice S9.3 —
phase2-migrate-from-kagentCloses §15.2 #8 of the implementation plan ("kagent migration tool").
One-shot YAML translator from a
kagent.dev/v1alpha2 AgentCR(verified directly against
kagent-dev/kagent @ 90212ab go/api/v1alpha2/agent_types.govia GitHub MCP) into an AzureClaw resource bundle.Emits
ClawSandbox(always) — name + namespace + labels (with the deterministicazureclaw.azure.com/sandboxmarker that the emitted ToolPolicies match against), BYO image direct or--imageoverride for Declarative agents (kagent ADK runtime is not bundled),spec.sandbox.network.allowedDomains→spec.networkPolicy.allowedEndpoints, deployment-levelenv→spec.openclaw.extraEnv(last-literal-wins,valueFromdropped + warned).InferencePolicy(only whenspec.declarative.modelConfigis set) — provenance-only mapping; carries the kagent ModelConfig name asazureclaw.azure.com/kagent-model-configannotation. Inference enforcement is not migrated.ToolPolicy(one per(McpServer, toolName)pair) —requireApprovallist maps tospec.approval.mode='always'; emptytoolNamesemits one wildcard ToolPolicy with a warning;type: Agenttools dropped with warning. OriginalTypedReferencepreserved asazureclaw.azure.com/kagent-tool-refannotation; user is warned that an equivalent AzureClawMcpServermust already exist.Hard-fail on lossy by default
Same exit-code grammar as S9.2
convert:0ok,2invalid input / wrong kind / multi-doc / collision,4lossy refused.--allow-lossywaives.--dry-runstill applies the lossy gate.Aspirational mappings explicitly REJECTED
Per pre-implementation rubber-duck critique (14 findings adopted, 0 deferred):
ClawAgentIdentity— Phase 4 CRD perdocs/internal/internal-boundaries.md:28; the plan line 210 mentioning it is overridden by repo reality per slice rule §0.2 security: inference requests bypass policy evaluation entirely (CRITICAL) #7.McpServerauto-emission — we cannot reconstruct upstream MCP endpoints from a kagentTypedReference.InferencePolicyenforcement fromModelConfig— separate CRD; we keep provenance only.Output formats
--format yaml(default) — multi-doc YAML stream, deterministic order:ClawSandbox,InferencePolicy,ToolPolicys sorted by name.--format json— single Kubernetesv1.List(pipes cleanly tokubectl apply -f -).--out-dir <dir>— splits into<kind>-<name>.yamlfiles; refuses to overwrite unless--force.Tests
cli/src/migrate/from_kagent.test.tscovering DNS sanitization edges, hash determinism + collision distinguishability, env projection (last-wins,valueFrom, prior-literal-purge), description truncation, every input gate, label conflict rejection, namespace mismatch warn, Declarative non-runnability + escape hatch, conditional InferencePolicy emit, ToolPolicy fan-out + approval mapping + wildcard emission + dedupe + agent-as-tool drop + headersFrom + allowedHeaders warns, all Declarative + deployment-level lossy fields, networking projection + wildcard warn, bundle ordering, BYO clean happy-path.McpServertool (2 toolNames, 1 requireApproval) + a network allowlist round-trips to a 4-resource bundle that exits 0 with--allow-lossy --image …and exits 4 without--allow-lossy.CI
tsc --noEmit✓ ·oxlint✓ (clean) ·vitest435 ✓ ·ci/no-stubs.sh✓ ·ci/no-custom-crypto.sh✓ ·ci/check-loc.sh✓.Audit doc
docs/security-audits/2026-04-28-phase2-migrate-from-kagent.md— full 12-section template. STRIDE table (13 threats), reuse map (7 existing seams enumerated, 0 parallel-implementations), aspirational-rejection table, failure-mode matrix, CRD round-trip validation, test coverage map.Day-1 use case
azureclaw migrate from-kagent agent.yaml --image my/runtime:v1 --allow-lossy | kubectl apply -f -Operator running kagent declarative agents adopts AzureClaw governance by piping the bundle into
kubectl apply, then hand-edits the emitted ClawSandbox to setspec.inference.{provider,endpoint,model}per their ModelConfig and creates an AzureClawMcpServerfor each kagent McpServer reference.Phase 2 progress
S1 #51 ✓ · S2 #52 ✓ · S3 #53 ✓ · S4 #54 ✓ · S5 #55 ✓ · S6 #56 ✓ · S8 #57 ✓ · S11 #59 ✓ · S11.1 #61 ✓ · S9.1 #62 ✓ · S9.2 #63 ✓ · S9.3 (this PR)
12 of ~14 slices.
Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com