Skip to content

Add allowed_skills to POST /v1/agents/run and fix ephemeral demo - #49

Merged
jameswnl merged 2 commits into
harnessfrom
rspeed-agent-ephemeral-skills-demo-fix
Sep 9, 2026
Merged

jameswnl merged 2 commits into
harnessfrom
rspeed-agent-ephemeral-skills-demo-fix

Conversation

@jameswnl

@jameswnl jameswnl commented Sep 9, 2026

Copy link
Copy Markdown
Owner

No JIRA ticket yet — pr-title-checker will fail until one is added; rename the title once available.

Summary

  • Threads allowed_skills through AgentRunRequest -> StepInput -> raw_step so the ephemeral path (SandboxExecutor -> step_runner -> spawner.spawn) can materialize just that skill subset with per-skill Landlock grants. Also selects request-level MCP server names into raw_step, since step_runner only injects catalog entries whose names a step lists — without this the sandbox never sees request-level MCP servers.
  • The corresponding fix for the actual allowed_skills bug (manifest not granting the skills source directory) landed in lightspeed-agentic-sandbox#12 and is published as quay.io/jameswong/lightspeed-agentic-sandbox:latest.
  • Refactors docs/cloud-agents-demo-curl.sh's seven near-duplicate curl blocks into shared run_agent/submit_workflow/finish_workflow/approval_cycle helpers, updates the ephemeral demo to exercise allowed_skills, and fixes its MCP server URL — kubectl-mcp:8000 was a stale placeholder; the actually-deployed mock (via ~/ws/local-infra's ocp-prod-mcp-pod-status-* targets) is mcp-pod-status-mock:8084.
  • Fixes main.py's OpenAPI servers URL — hardcoded localhost:8080 broke Swagger UI when reverse-proxied; now /.
  • Fixes a pre-existing unused-variable pylint failure in agents.py (username from auth tuple unpack was never used) blocking make verify.

Test plan

  • uv run make format / uv run make verify (ruff, pyright, pydocstyle, black clean on all changed files; remaining pylint findings are pre-existing, in unrelated files not touched by this PR)
  • uv run make test-unit — 3391 passed, 1 skipped, 90.22% coverage
  • Added 3 new unit tests for allowed_skills/raw_step MCP server threading (test_agents_endpoint.py)
  • Live end-to-end verification against the real OCP-prod OpenShell gateway: BASE_URL=... ./docs/cloud-agents-demo-curl.sh agent-ephemeral now returns "status": "completed" with a correct k8s-diag diagnosis, after both the sandbox-image fix and the MCP URL fix

jameswnl and others added 2 commits September 9, 2026 05:00
Threads allowed_skills through AgentRunRequest -> StepInput -> raw_step so
the ephemeral (SandboxExecutor -> step_runner -> spawner.spawn) path can
materialize just that skill subset with per-skill Landlock grants. Also
selects request-level MCP server names into raw_step, since step_runner
only injects catalog entries whose names a step lists.

Refactors docs/cloud-agents-demo-curl.sh's near-duplicate curl blocks into
shared run_agent/submit_workflow/finish_workflow/approval_cycle helpers,
updates the ephemeral demo to exercise the new allowed_skills field, and
fixes its MCP server URL (kubectl-mcp:8000 was a stale placeholder; the
actually-deployed mock is mcp-pod-status-mock:8084).

Fixes main.py's OpenAPI servers URL (hardcoded localhost:8080 broke
Swagger UI when reverse-proxied) and a pre-existing unused-variable
pylint failure in agents.py.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Both ran with mcp_servers: null, so unlike agent-ephemeral they had no
way to actually check pod health -- agent-none returned a generic "I
don't have access" answer and agent-local's claim was ungrounded. Point
both at the same mock pod-status MCP server, reached via
localhost:8084 (port-forwarded) since these spawn modes run in-process
on this machine rather than inside a cluster pod like spawn:ephemeral.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@jameswnl
jameswnl merged commit f97799d into harness Sep 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant