Skip to content

refactor(config): adopt api/pkg/agentconfig as the declared config - #103

Merged
gusfcarvalho merged 2 commits into
lisa/agent-config-02-runner-evidence-propsfrom
lisa/agent-config-03-declared-config
Oct 6, 2026
Merged

gusfcarvalho merged 2 commits into
lisa/agent-config-02-runner-evidence-propsfrom
lisa/agent-config-03-declared-config

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 3/11 of the split of #95 (agent remote configuration) into a stack. Review it as the diff against its base branch.

The config file is decoded into agentconfig.Config (the declared form) and
validated with the shared rules, then converted once by toRuntime into the
existing runtime structs, so agentConfigurationHash and evidence identity
stay byte-identical (the golden test from the previous commit proves it).

  • loadBase builds a fresh viper per load with viper's weak decoder, exactly
    as before (R51); CLI flags and the CCF_API_AUTH_* bindings are unchanged.
  • File problems that always loaded stay non-fatal (R34): a bad plugin
    schedule skips that plugin, a negative verbosity or a literal ${env:...}
    outside plugins.*.config is a warning. Everything else is still fatal.
  • Plugins gain enabled (default true); a disabled plugin gets no cron,
    download or run state.
  • IsOCI delegates to agentconfig.IsOCISource so agent and API classify
    sources the same way.
  • Pin compliance-framework/api b53be8f for pkg/agentconfig.

Size: 919 lines changed (go.mod/go.sum excluded). Builds, vets, is gofmt-clean and passes go test -race ./... on its own; the top of the stack is byte-identical to #95 merged with main.

Stack
  1. test: pin agent configuration hashes and evidence seeds #101 test: pin agent configuration hashes and evidence seeds
  2. feat(runner): policy source from the _policy_path label; extra evidence props #102 feat(runner): policy source from the _policy_path label; extra evidence props
  3. 👉 refactor(config): adopt api/pkg/agentconfig as the declared config #103 refactor(config): adopt api/pkg/agentconfig as the declared config
  4. feat(agent): stable instance ID and per-instance state directory #104 feat(agent): stable instance ID and per-instance state directory
  5. feat(agent): AgentRunner primitives for prepare-then-cancel reloads #105 feat(agent): AgentRunner primitives for prepare-then-cancel reloads
  6. feat(agent): prepare-then-cancel config file reloads #106 feat(agent): prepare-then-cancel config file reloads
  7. feat(pluginlib): read the agent library version a plugin binary was built with #107 feat(pluginlib): read the agent library version a plugin binary was built with
  8. feat(agent): report the configuration to the API (remote_config off/report) #108 feat(agent): report the configuration to the API (remote_config off/report)
  9. feat(agentstate): persisted cache for the remote configuration overlay #109 feat(agentstate): persisted cache for the remote configuration overlay
  10. feat(agent): pull and apply remote configuration overlays (apply_safe/apply_all) #110 feat(agent): pull and apply remote configuration overlays (apply_safe/apply_all)
  11. feat(config): ${env:NAME} placeholders in plugin config; ADR 0003 #111 feat(config): ${env:NAME} placeholders in plugin config; ADR 0003

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b0b08454-fc11-4a6e-abcd-cc9c147bb120

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 112): #101 → #102 → #103 → #104 → #105 → #106 → #107 → #108 → #109 → #110 → #111

The config file is decoded into agentconfig.Config (the declared form) and
validated with the shared rules, then converted once by toRuntime into the
existing runtime structs, so agentConfigurationHash and evidence identity
stay byte-identical (the golden test from the previous commit proves it).

- loadBase builds a fresh viper per load with viper's weak decoder, exactly
  as before (R51); CLI flags and the CCF_API_AUTH_* bindings are unchanged.
- File problems that always loaded stay non-fatal (R34): a bad plugin
  schedule skips that plugin, a negative verbosity or a literal ${env:...}
  outside plugins.*.config is a warning. Everything else is still fatal.
- Plugins gain `enabled` (default true); a disabled plugin gets no cron,
  download or run state.
- IsOCI delegates to agentconfig.IsOCISource so agent and API classify
  sources the same way.
- Pin compliance-framework/api b53be8f for pkg/agentconfig.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config-03-declared-config branch from dd36c8f to b3ea689 Compare October 6, 2026 10:27
@ccf-lisa

ccf-lisa Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

PR approved. Marking ready for e2e.

….enabled

Replace the b53be8f pseudo-version with the released v0.21.0, whose
agentconfig.Classify treats re-enabling a disabled plugin as unsafe and
counts only enabled plugins' sources as already used. OPA stays v1.14.1
on both sides.

Show the optional plugins.<p>.enabled key in the README Basic example.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gusfcarvalho
gusfcarvalho merged commit e6e1241 into main Oct 6, 2026
5 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config-03-declared-config branch October 6, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant