Skip to content

fix(deploy): refuse ACP-only deploys onto images that predate /acp - #159

Merged
brettchien merged 1 commit into
mainfrom
orca/acp-image-compat-guard
Sep 13, 2026
Merged

brettchien merged 1 commit into
mainfrom
orca/acp-image-compat-guard

Conversation

@brettchien

Copy link
Copy Markdown
Contributor

Summary

  • fix(console): pin Beta channel to a versioned release, default ACP deploys to it #153 already guards the New Fleet wizard's Image-tag <select> against picking Stable (currently 0.9.0, predates openab#1418's /acp gateway support) while ACP is enabled — but that guard lives entirely client-side in console/src/deploy.ts.
  • A caller that bypasses the wizard (an MCP client calling deploy_provision_agent directly) sails right through it and reproduces the exact "no adapter configured" crash — which is exactly how this session's seaturtle test agent broke: called deploy_provision_agent directly with no chat_platform and the then-default (Stable) image.
  • Adds check_acp_image_compat(), enforced in both provision_agent (ECS) and provision_agent_k8s — the one place every caller funnels through regardless of front end. Refuses acp_enabled: true + no chat_platform onto an image tag whose parsed version predates 0.10.0-beta.2.
  • Only recognizes openab's own <version>[-beta.N]-<vendor> tag shape; a custom image the caller supplied directly passes through unchecked ("can't verify, don't block" — same stance resolve_vendor_image_tags already takes on a failed GHCR/GitHub lookup).

Test plan

  • cargo check -p studio-cp — clean
  • 9 new unit tests for parse_openab_version/check_acp_image_compat (pure, no AWS/k8s I/O): stable vs. beta parsing, a final release outranking its own betas, refusing 0.9.0/0.10.0-beta.1, accepting 0.10.0-beta.2+, no-op when ACP is off or a chat_platform is set, and a custom image passing through unverified
  • cargo test -p studio-cp — hits the same aws-sdk-ec2 test-cfg OOM on this box PR fix(console): pin Beta channel to a versioned release, default ACP deploys to it #153 already documented and deferred to CI (unrelated to this change — cargo check compiles the same code cleanly, and the new tests don't touch AWS/k8s)
  • Manual: call deploy_provision_agent directly with acp_enabled: true, no chat_platform, and a 0.9.0-<vendor> image → should be refused with a clear error instead of deploying a broken agent

🤖 Generated with Claude Code

studio#153 already guards the New Fleet wizard's Image-tag <select> against
picking Stable (currently 0.9.0, predates openab#1418's /acp gateway
support) with ACP enabled — but that guard lives entirely client-side in
console/src/deploy.ts. A caller that bypasses the wizard (an MCP client
calling deploy_provision_agent directly) sails right through it and
reproduces the exact "no adapter configured" crash — which is exactly how
this session's "seaturtle" test agent broke, using deploy_provision_agent
directly with no chat_platform and the (then-current) default image.

Adds check_acp_image_compat(), enforced in both provision_agent (ECS) and
provision_agent_k8s — the one place every caller funnels through
regardless of front end. Refuses acp_enabled=true + no chat_platform onto
an image tag whose parsed version predates 0.10.0-beta.2. Only recognizes
openab's own <version>[-beta.N]-<vendor> tag shape; a custom image the
caller supplied directly passes through unchecked (can't verify, don't
block — same stance resolve_vendor_image_tags already takes).

Test plan:
- cargo check -p studio-cp: clean
- 9 new unit tests for parse_openab_version/check_acp_image_compat (pure,
  no AWS/k8s I/O) — cargo test -p studio-cp hits the same aws-sdk-ec2
  test-cfg OOM on this box PR #153 already documented and deferred to CI

🤖 Generated with Claude Code
@brettchien
brettchien merged commit c0bfff1 into main Sep 13, 2026
2 checks passed
@brettchien
brettchien deleted the orca/acp-image-compat-guard branch September 13, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant