fix(deploy): refuse ACP-only deploys onto images that predate /acp - #159
Merged
Merged
Conversation
studio#153 already guards the New Fleet wizard's Image-tag <select> against picking Stable (currently 0.9.0, predates openab#1418's /acp gateway support) with ACP enabled — but that guard lives entirely client-side in console/src/deploy.ts. A caller that bypasses the wizard (an MCP client calling deploy_provision_agent directly) sails right through it and reproduces the exact "no adapter configured" crash — which is exactly how this session's "seaturtle" test agent broke, using deploy_provision_agent directly with no chat_platform and the (then-current) default image. Adds check_acp_image_compat(), enforced in both provision_agent (ECS) and provision_agent_k8s — the one place every caller funnels through regardless of front end. Refuses acp_enabled=true + no chat_platform onto an image tag whose parsed version predates 0.10.0-beta.2. Only recognizes openab's own <version>[-beta.N]-<vendor> tag shape; a custom image the caller supplied directly passes through unchecked (can't verify, don't block — same stance resolve_vendor_image_tags already takes). Test plan: - cargo check -p studio-cp: clean - 9 new unit tests for parse_openab_version/check_acp_image_compat (pure, no AWS/k8s I/O) — cargo test -p studio-cp hits the same aws-sdk-ec2 test-cfg OOM on this box PR #153 already documented and deferred to CI 🤖 Generated with Claude Code
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
<select>against picking Stable (currently0.9.0, predates openab#1418's/acpgateway support) while ACP is enabled — but that guard lives entirely client-side inconsole/src/deploy.ts.deploy_provision_agentdirectly) sails right through it and reproduces the exact"no adapter configured"crash — which is exactly how this session'sseaturtletest agent broke: calleddeploy_provision_agentdirectly with nochat_platformand the then-default (Stable) image.check_acp_image_compat(), enforced in bothprovision_agent(ECS) andprovision_agent_k8s— the one place every caller funnels through regardless of front end. Refusesacp_enabled: true+ nochat_platformonto an image tag whose parsed version predates0.10.0-beta.2.<version>[-beta.N]-<vendor>tag shape; a custom image the caller supplied directly passes through unchecked ("can't verify, don't block" — same stanceresolve_vendor_image_tagsalready takes on a failed GHCR/GitHub lookup).Test plan
cargo check -p studio-cp— cleanparse_openab_version/check_acp_image_compat(pure, no AWS/k8s I/O): stable vs. beta parsing, a final release outranking its own betas, refusing0.9.0/0.10.0-beta.1, accepting0.10.0-beta.2+, no-op when ACP is off or a chat_platform is set, and a custom image passing through unverifiedcargo test -p studio-cp— hits the sameaws-sdk-ec2test-cfg OOM on this box PR fix(console): pin Beta channel to a versioned release, default ACP deploys to it #153 already documented and deferred to CI (unrelated to this change —cargo checkcompiles the same code cleanly, and the new tests don't touch AWS/k8s)deploy_provision_agentdirectly withacp_enabled: true, nochat_platform, and a0.9.0-<vendor>image → should be refused with a clear error instead of deploying a broken agent🤖 Generated with Claude Code