Replace actor-facing REST tools with authenticated per-session MCP - #75
Merged
Merged
Conversation
Expose role-restricted MCP tools using session credentials injected by kagent. Persist credential revocation and cleanup, and reconcile reserved child actors before failing startup without replaying their briefs. Add the dedicated main Agent configuration, MCP service and network isolation requirements. Require a fresh database; earlier slices have no supported upgrade path.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace actor-facing REST tools with authenticated per-session MCP. kagent injects session credentials; tool discovery and invocation enforce the same role restrictions. Main agents manage topics and delegate/manage children; children record notes/decisions and report to their parent.
Persist credential revocation and retryable cleanup. Failed child startup reconciles uncertain creation and disposes the reserved actor before revocation, without replacing it or replaying its brief. Main-thread delivery failures remain recoverable.
Installation requires a fresh database (no upgrade from earlier slices), a dedicated main Agent with idle TTL disabled, native AgentTemplate MCP bindings, compatible kagent session credentials, and the documented pinned stock agentgateway injection path with provider namespace access. A NetworkPolicy-enforcing CNI and verified ingress isolation are required; repeat gateway proof on upgrades.
Validation:
make fmt,make lint, andgit diff --checkpassed.