Skip to content

S10.A3: phase2-runtime-openai-agents — first non-OpenClaw native runtime - #69

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-runtime-openai-agents
Apr 28, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-runtime-openai-agents

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

S10.A3 wires RuntimeKind::OpenAIAgents end-to-end through the controller dispatch seam established in S10.A2. This is the first non-OpenClaw native runtime to land on AzureClaw.

After this PR + S10.A4 (MAF) merge, §14.6 column 11 (Multi-runtime hosting) flips fully ✓. S10.A3 alone is partial credit toward that bar.

What ships

  • plan_openai_agents producer in controller::reconciler::runtime — replaces AdapterMissing short-circuit. Adapter image via DEFAULT_OPENAI_AGENTS_IMAGE with OPENAI_AGENTS_RUNTIME_IMAGE env override (whitespace-as-unset).
  • is_byo → is_openclaw polarity flip in the reconciler. OpenAIAgents and BYO share the generic-runtime container shape (container name agent, no OpenClaw-specific env, no admin-token mount). No parallel is_openai_agents flag — single branching point.
  • Sandbox image scaffolding sandbox-images/openai-agents/ — Python 3.12 + openai-agents>=0.1,<0.2. Entrypoint exports OPENAI_BASE_URL=http://127.0.0.1:8443/openai/v1 (router sidecar = only LLM endpoint) and AZURECLAW_PLATFORM_MCP_URL=http://127.0.0.1:8443/platform/mcp (S10.B platform MCP server). Image label org.azureclaw.runtime.contract=v1 recognises the existing BYO contract verifier.
  • 8 new tests (307 → 315 controller, all green).

Hard rules respected (§0.2)

  • ✅ No reimplementation of Signal Protocol / X3DH / Double Ratchet / KNOCK / registry / relay. Class B mesh tools deferred per the runtime-agnostic rule — blocked on upstream AgentMesh-Python availability (docs/internal/agt-upstream-asks.md §3).
  • ✅ No parallel implementation — extends existing RuntimeDeploymentPlan + reuses is_byo shape via polarity flip.
  • ✅ No custom crypto in this slice.
  • ✅ Audit doc with two sign-off slots: docs/security-audits/2026-04-28-phase2-runtime-openai-agents.md.

Deferred

  • In-pod adapter package (azureclaw-runtime-openai-agents PyPI) — AAD shim for Azure OpenAI, AZURE_OPENAI_ENDPOINT rewriting, AGT-init compat, OTel SDK wiring. Dockerfile is contract-labelled but adapter is the immediate follow-up.
  • Class B mesh tools — upstream-blocked. S10.A3 ships Foundry-shim access only via S10.B platform MCP server.
  • Reference example app + e2e Kind test — fold into S10.A4 where ≥2 native runtimes share the e2e harness investment.

Test results

  • Controller: 315 passed, 0 failed (was 307; +8 new, 1 updated).
  • cargo clippy -p azureclaw-controller --all-targets -- -D warnings: clean.
  • cargo fmt --all --check: clean.

PR train

Phase 2 dev tip on top of #65 (S10.A1) → #66 (S10.A2) → #67 (S10.A2.b) → #68 (S10.B) → this PR (S10.A3).

Container Image Scan check expected to fail (no image push pipeline for the new sandbox-images/openai-agents/ scaffolding yet) — admin-merge per the established S10 pattern.

Wires `RuntimeKind::OpenAIAgents` end-to-end through the controller dispatch
seam established in S10.A2:

- New `plan_openai_agents` producer in
  `controller::reconciler::runtime` replaces the `AdapterMissing`
  short-circuit. Adapter image resolves via
  `DEFAULT_OPENAI_AGENTS_IMAGE` (default
  `azureclawacr.azurecr.io/azureclaw-runtime-openai-agents:latest`)
  with `OPENAI_AGENTS_RUNTIME_IMAGE` env override (whitespace-as-unset).
- `python_version` propagates as `RUNTIME_PYTHON_VERSION`
  (deliberately non-reserved prefix so it survives the deployment
  builder's reserved-prefix filter).
- Reconciler `is_byo` flag generalised to `is_openclaw` (positive
  polarity). OpenAIAgents and BYO share the same generic-runtime
  container shape: container name `agent`, no OpenClaw-specific env
  (OPENCLAW_*, FOUNDRY_AGENT_*, FOUNDRY_DEPLOYMENTS), no admin-token
  mount. Single branching point — no parallel `is_openai_agents` flag.
- Sandbox image scaffolding `sandbox-images/openai-agents/` (Dockerfile
  Python 3.12 + `openai-agents>=0.1,<0.2`; entrypoint exports
  `OPENAI_BASE_URL=http://127.0.0.1:8443/openai/v1` and
  `AZURECLAW_PLATFORM_MCP_URL=http://127.0.0.1:8443/platform/mcp`).
- Image declares `LABEL org.azureclaw.runtime.contract=v1` so the
  existing BYO contract verifier recognises it.

Tests: 307 → 315 (+8: default image, env override × 3, python_version
+ extra_env merge, user-extra-wins, entrypoint propagation, agent_code
round-trip, dispatcher wiring). Existing
`plan_returns_adapter_missing_for_each_unwired_non_openclaw_kind`
updated — OpenAIAgents case dropped; 4 cases remain (MAF + 3 Tier-2
placeholders).

Audit doc: docs/security-audits/2026-04-28-phase2-runtime-openai-agents.md.
Class B mesh tools deferred per runtime-agnostic rule (blocked on
upstream AgentMesh-Python). Class A Foundry shims served by S10.B
platform MCP server.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 1ac5c15 into dev Apr 28, 2026
13 of 14 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-runtime-openai-agents branch April 28, 2026 14:23
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
…A3) (#69)

Wires `RuntimeKind::OpenAIAgents` end-to-end through the controller dispatch
seam established in S10.A2:

- New `plan_openai_agents` producer in
  `controller::reconciler::runtime` replaces the `AdapterMissing`
  short-circuit. Adapter image resolves via
  `DEFAULT_OPENAI_AGENTS_IMAGE` (default
  `azureclawacr.azurecr.io/azureclaw-runtime-openai-agents:latest`)
  with `OPENAI_AGENTS_RUNTIME_IMAGE` env override (whitespace-as-unset).
- `python_version` propagates as `RUNTIME_PYTHON_VERSION`
  (deliberately non-reserved prefix so it survives the deployment
  builder's reserved-prefix filter).
- Reconciler `is_byo` flag generalised to `is_openclaw` (positive
  polarity). OpenAIAgents and BYO share the same generic-runtime
  container shape: container name `agent`, no OpenClaw-specific env
  (OPENCLAW_*, FOUNDRY_AGENT_*, FOUNDRY_DEPLOYMENTS), no admin-token
  mount. Single branching point — no parallel `is_openai_agents` flag.
- Sandbox image scaffolding `sandbox-images/openai-agents/` (Dockerfile
  Python 3.12 + `openai-agents>=0.1,<0.2`; entrypoint exports
  `OPENAI_BASE_URL=http://127.0.0.1:8443/openai/v1` and
  `AZURECLAW_PLATFORM_MCP_URL=http://127.0.0.1:8443/platform/mcp`).
- Image declares `LABEL org.azureclaw.runtime.contract=v1` so the
  existing BYO contract verifier recognises it.

Tests: 307 → 315 (+8: default image, env override × 3, python_version
+ extra_env merge, user-extra-wins, entrypoint propagation, agent_code
round-trip, dispatcher wiring). Existing
`plan_returns_adapter_missing_for_each_unwired_non_openclaw_kind`
updated — OpenAIAgents case dropped; 4 cases remain (MAF + 3 Tier-2
placeholders).

Audit doc: docs/security-audits/2026-04-28-phase2-runtime-openai-agents.md.
Class B mesh tools deferred per runtime-agnostic rule (blocked on
upstream AgentMesh-Python). Class A Foundry shims served by S10.B
platform MCP server.

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant