Skip to content

S10.A2.b: BYO end-to-end deployment + raw_env - #67

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-multi-runtime-byo
Apr 28, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-multi-runtime-byo

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

Promotes RuntimeKind::BYO from "unwired (returns AdapterMissing)" to end-to-end Pod deployment with a documented contract. BYO sandboxes now reach Running state with the agent container shaped correctly for non-OpenClaw runtimes.

Stacks on #66 (S10.A2 dispatch seam). Diff against dev will look bigger than the actual A2.b delta until #66 merges. Net A2.b changes: +411 / -97 across 4 files.

What changed

controller/src/reconciler/runtime.rs

  • New field pub raw_env: Vec<serde_json::Value> on RuntimeDeploymentPlan — captures structural env entries (e.g. valueFrom: secretKeyRef:).
  • RuntimeKind::BYO now routes through Ok(plan_byo(cfg)) (was AdapterMissing).
  • plan_byo populates both runtime_extra_env (flat value: entries) and raw_env (structural entries). Reserved-prefix / NUL / dup name filter applies to raw_env.
  • Tests: plan_returns_adapter_missing_for_each_non_openclaw_kind renamed → ...for_each_unwired_non_openclaw_kind (BYO removed from cases vec); plan_byo_skips_value_from_env_entries extended to assert raw_env populated; new build_runtime_plan_dispatches_byo_to_producer.

controller/src/reconciler/mod.rs

  • is_byo flag derived from runtime_spec.kind.
  • Skipped when is_byo: OPENCLAW_MODEL, OPENCLAW_GATEWAY_TOKEN, FOUNDRY_DEPLOYMENTS, FOUNDRY_AGENT_ID, FOUNDRY_AGENT_TOOLS. Critical: OPENCLAW_GATEWAY_TOKEN references the gateway-token Secret which is OpenClaw-namespace-scoped — a BYO Pod referencing it would CreateContainerConfigError.
  • raw_env consumption block added after the existing runtime_extra_env block; defensive skip on entries missing name.
    • name: agent (BYO) vs openclaw (OpenClaw).
    • command / args set from plan.command / plan.args when Some(...).

Threat model highlights

Threat Mitigation
BYO Pod fails to start because gateway-token Secret doesn't exist Env entry skipped when is_byo
BYO Pod gets gateway port 18789 Skipped when is_byo
BYO Pod gets admin-token mount → could call /agt/trust/* volumeMount skipped when is_byo (defense in depth: router admin endpoints already bind 127.0.0.1 + require admin token)
Reserved env names injected via raw_env valueFrom Reserved-prefix / NUL / dup filter applied to raw_env entries' name field
Container name openclaw → agent breaks tooling azureclaw connect uses port-forward by deployment + port name; post-deployment patches at mod.rs:1102-1160 target inference-router by name lookup — both unaffected (verified by inspection)
Cross-namespace secret read attempt via BYO valueFrom secretKeyRef is namespace-local; BYO sandboxes have their own namespace azureclaw-<name> with no gateway-token Secret provisioned — would CreateContainerConfigError

Tests

  • cargo test --package azureclaw-controller: 307/307 pass (was 306 in S10.A2; +1 = build_runtime_plan_dispatches_byo_to_producer).
  • cargo clippy --package azureclaw-controller --all-targets -- -D warnings: clean.
  • cargo fmt --all -- --check: clean.
  • E2E (Kind): not in this slice — first multi-runtime e2e Kind test lands in S10.A3 (the first slice that ships a runnable non-OpenClaw image).

Out of scope (deferred)

  • BYO strict-mode admission (Phase 2 is warn-only via RuntimeReady Condition; Phase 3).
  • agentCode: configMap and agentCode: inline (only oci + git in Phase 2).
  • OpenAIAgents / MicrosoftAgentFramework runtime wiring → S10.A3 / S10.A4.
  • LLM-client redirection helper for BYO authors. Today's BYO contract: agent must point its OpenAI/AOAI/Anthropic client at 127.0.0.1:8443. Documented in CRD comment + reference. Convenience helper deferred.

Audit doc

  • docs/security-audits/2026-04-28-phase2-multi-runtime-byo.md — full scope / threat model / invariants preserved / test matrix / sign-off / follow-ups.

§14.6 column movement

Column 11 (Multi-runtime hosting) — partial credit. The BYO half of the column-11 ✓ bar (BYO with documented contract) lands here. Full ✓ requires S10.A4 (the second native non-OpenClaw runtime).

Follow-ups (not this PR)

  • S10.A3 — first runnable non-OpenClaw image (Python 3.12 + openai-agents + adapter).
  • S10.A4 — flips column 11 fully ✓.
  • S10.B (phase2-platform-mcp-server) — Foundry-shim platform MCP server in router. Should ship before S10.A3/A4 so adapters become trivial.

🤖 Co-authored with Copilot CLI

Promotes RuntimeKind::BYO from 'unwired (returns AdapterMissing)' to
end-to-end Pod deployment with documented contract.

- RuntimeDeploymentPlan gains raw_env: Vec<serde_json::Value> for
  structural valueFrom passthrough (static value: entries continue
  via runtime_extra_env BTreeMap).
- plan_byo populates both runtime_extra_env (flat) and raw_env
  (structural). Reserved-prefix / NUL / dup name filter applies
  to raw_env entries.
- Reconciler skips OPENCLAW_*/FOUNDRY_AGENT_* env when is_byo.
  Critical: OPENCLAW_GATEWAY_TOKEN references the gateway-token
  Secret which is OpenClaw-namespace-scoped; BYO referencing it
  would CreateContainerConfigError.
- Agent container extracted into a json! binding before the
  deployment macro. Conditional fields: name (agent vs openclaw),

Tests: 307/307 controller pass (+1 = build_runtime_plan_dispatches_
byo_to_producer). Clippy + fmt clean.

Audit: docs/security-audits/2026-04-28-phase2-multi-runtime-byo.md.

Stacks on PR #66 (S10.A2 dispatch seam). Rebase or land sequentially.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 2074be2 into dev Apr 28, 2026
14 of 15 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-multi-runtime-byo branch April 28, 2026 13:18
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
Promotes RuntimeKind::BYO from 'unwired (returns AdapterMissing)' to
end-to-end Pod deployment with documented contract.

- RuntimeDeploymentPlan gains raw_env: Vec<serde_json::Value> for
  structural valueFrom passthrough (static value: entries continue
  via runtime_extra_env BTreeMap).
- plan_byo populates both runtime_extra_env (flat) and raw_env
  (structural). Reserved-prefix / NUL / dup name filter applies
  to raw_env entries.
- Reconciler skips OPENCLAW_*/FOUNDRY_AGENT_* env when is_byo.
  Critical: OPENCLAW_GATEWAY_TOKEN references the gateway-token
  Secret which is OpenClaw-namespace-scoped; BYO referencing it
  would CreateContainerConfigError.
- Agent container extracted into a json! binding before the
  deployment macro. Conditional fields: name (agent vs openclaw),

Tests: 307/307 controller pass (+1 = build_runtime_plan_dispatches_
byo_to_producer). Clippy + fmt clean.

Audit: docs/security-audits/2026-04-28-phase2-multi-runtime-byo.md.

Stacks on PR #66 (S10.A2 dispatch seam). Rebase or land sequentially.

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant