Skip to content

Replace actor-facing REST tools with authenticated per-session MCP - #75

Merged
oldsj merged 1 commit into
mainfrom
mcp-tool-channel
Oct 4, 2026
Merged

oldsj merged 1 commit into
mainfrom
mcp-tool-channel

Conversation

@oldsj

@oldsj oldsj commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Replace actor-facing REST tools with authenticated per-session MCP. kagent injects session credentials; tool discovery and invocation enforce the same role restrictions. Main agents manage topics and delegate/manage children; children record notes/decisions and report to their parent.

Persist credential revocation and retryable cleanup. Failed child startup reconciles uncertain creation and disposes the reserved actor before revocation, without replacing it or replaying its brief. Main-thread delivery failures remain recoverable.

Installation requires a fresh database (no upgrade from earlier slices), a dedicated main Agent with idle TTL disabled, native AgentTemplate MCP bindings, compatible kagent session credentials, and the documented pinned stock agentgateway injection path with provider namespace access. A NetworkPolicy-enforcing CNI and verified ingress isolation are required; repeat gateway proof on upgrades.

Validation:

  • make fmt, make lint, and git diff --check passed.
  • 117 fake/offline tests and 57 real PostgreSQL tests passed, with no skips. Actor lifecycle and Kubernetes credential operations were faked.
  • Joint live MCP/CNI proof was not performed. Publication and CI are pending.

Expose role-restricted MCP tools using session credentials injected by
kagent. Persist credential revocation and cleanup, and reconcile reserved
child actors before failing startup without replaying their briefs.

Add the dedicated main Agent configuration, MCP service and network
isolation requirements. Require a fresh database; earlier slices have no
supported upgrade path.
@oldsj
oldsj merged commit 1575f0f into main Oct 4, 2026
4 checks passed
@oldsj
oldsj deleted the mcp-tool-channel branch October 4, 2026 21:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant