Repository navigation
Add allowed_skills to POST /v1/agents/run and fix ephemeral demo - #49
Merged
Merged
Conversation
Threads allowed_skills through AgentRunRequest -> StepInput -> raw_step so the ephemeral (SandboxExecutor -> step_runner -> spawner.spawn) path can materialize just that skill subset with per-skill Landlock grants. Also selects request-level MCP server names into raw_step, since step_runner only injects catalog entries whose names a step lists. Refactors docs/cloud-agents-demo-curl.sh's near-duplicate curl blocks into shared run_agent/submit_workflow/finish_workflow/approval_cycle helpers, updates the ephemeral demo to exercise the new allowed_skills field, and fixes its MCP server URL (kubectl-mcp:8000 was a stale placeholder; the actually-deployed mock is mcp-pod-status-mock:8084). Fixes main.py's OpenAPI servers URL (hardcoded localhost:8080 broke Swagger UI when reverse-proxied) and a pre-existing unused-variable pylint failure in agents.py. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Both ran with mcp_servers: null, so unlike agent-ephemeral they had no way to actually check pod health -- agent-none returned a generic "I don't have access" answer and agent-local's claim was ungrounded. Point both at the same mock pod-status MCP server, reached via localhost:8084 (port-forwarded) since these spawn modes run in-process on this machine rather than inside a cluster pod like spawn:ephemeral. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No JIRA ticket yet — pr-title-checker will fail until one is added; rename the title once available.
Summary
allowed_skillsthroughAgentRunRequest->StepInput->raw_stepso the ephemeral path (SandboxExecutor->step_runner->spawner.spawn) can materialize just that skill subset with per-skill Landlock grants. Also selects request-level MCP server names intoraw_step, sincestep_runneronly injects catalog entries whose names a step lists — without this the sandbox never sees request-level MCP servers.allowed_skillsbug (manifest not granting the skills source directory) landed in lightspeed-agentic-sandbox#12 and is published asquay.io/jameswong/lightspeed-agentic-sandbox:latest.docs/cloud-agents-demo-curl.sh's seven near-duplicate curl blocks into sharedrun_agent/submit_workflow/finish_workflow/approval_cyclehelpers, updates the ephemeral demo to exerciseallowed_skills, and fixes its MCP server URL —kubectl-mcp:8000was a stale placeholder; the actually-deployed mock (via~/ws/local-infra'socp-prod-mcp-pod-status-*targets) ismcp-pod-status-mock:8084.main.py's OpenAPIserversURL — hardcodedlocalhost:8080broke Swagger UI when reverse-proxied; now/.agents.py(usernamefromauthtuple unpack was never used) blockingmake verify.Test plan
uv run make format/uv run make verify(ruff, pyright, pydocstyle, black clean on all changed files; remaining pylint findings are pre-existing, in unrelated files not touched by this PR)uv run make test-unit— 3391 passed, 1 skipped, 90.22% coverageallowed_skills/raw_stepMCP server threading (test_agents_endpoint.py)BASE_URL=... ./docs/cloud-agents-demo-curl.sh agent-ephemeralnow returns"status": "completed"with a correct k8s-diag diagnosis, after both the sandbox-image fix and the MCP URL fix