Skip to content

feat(agent): report the configuration to the API (remote_config off/report) - #108

Merged
gusfcarvalho merged 2 commits into
lisa/agent-config-07-plugin-libfrom
lisa/agent-config-08-config-reports
Oct 6, 2026
Merged

gusfcarvalho merged 2 commits into
lisa/agent-config-07-plugin-libfrom
lisa/agent-config-08-config-reports

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 8/11 of the split of #95 (agent remote configuration) into a stack. Review it as the diff against its base branch.

With api.auth credentials the agent now tells the API what it runs:

  • remote_config (set locally only: file, host env, CLI; R30) selects the
    mode. With credentials and no mode it is report; without credentials it
    is always off (R29). CCF_REMOTE_CONFIG_MODE sets it without a block.
  • In report mode the reconciler sends a config report (hostname, agent
    version, base and effective config, digest, warnings, plugins with their
    agent library version) at startup and whenever it changes, resends it
    after a send error or after 24h, and honours the API's error table:
    404/401/403 back off 10 minutes, 409 pauses reports for an hour, 413
    resends it with the base dropped (R8, R36).
  • base and effective are the unresolved forms, redacted by the API's
    agentconfig rules plus the plugin values that came from CCF_PLUGINS_*
    variables; the effective digest uses the same masking, so it never
    changes when a secret rotates (R24, R25, R55).
  • The heartbeat carries the applied revision (0 for the file) and the
    effective digest unless the mode is off (R11, R45).
  • main passes the goreleaser version to the report.

The apply modes are accepted and reported, but fetching and applying an
overlay lands in the next PR; until then they run the file only.

The report-resend and fetch/409 backoff tests need an overlay to change the report, so they land with #110.

Size: 954 lines changed (go.mod/go.sum excluded). Builds, vets, is gofmt-clean and passes go test -race ./... on its own; the top of the stack is byte-identical to #95 merged with main.

Stack
  1. test: pin agent configuration hashes and evidence seeds #101 test: pin agent configuration hashes and evidence seeds
  2. feat(runner): policy source from the _policy_path label; extra evidence props #102 feat(runner): policy source from the _policy_path label; extra evidence props
  3. refactor(config): adopt api/pkg/agentconfig as the declared config #103 refactor(config): adopt api/pkg/agentconfig as the declared config
  4. feat(agent): stable instance ID and per-instance state directory #104 feat(agent): stable instance ID and per-instance state directory
  5. feat(agent): AgentRunner primitives for prepare-then-cancel reloads #105 feat(agent): AgentRunner primitives for prepare-then-cancel reloads
  6. feat(agent): prepare-then-cancel config file reloads #106 feat(agent): prepare-then-cancel config file reloads
  7. feat(pluginlib): read the agent library version a plugin binary was built with #107 feat(pluginlib): read the agent library version a plugin binary was built with
  8. 👉 feat(agent): report the configuration to the API (remote_config off/report) #108 feat(agent): report the configuration to the API (remote_config off/report)
  9. feat(agentstate): persisted cache for the remote configuration overlay #109 feat(agentstate): persisted cache for the remote configuration overlay
  10. feat(agent): pull and apply remote configuration overlays (apply_safe/apply_all) #110 feat(agent): pull and apply remote configuration overlays (apply_safe/apply_all)
  11. feat(config): ${env:NAME} placeholders in plugin config; ADR 0003 #111 feat(config): ${env:NAME} placeholders in plugin config; ADR 0003

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 72264293-641b-4a73-aaf4-29da256f1163

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 112): #101 → #102 → #103 → #104 → #105 → #106 → #107 → #108 → #109 → #110 → #111

Fixed later in the stack

  • CORE-TEST-001 in cmd/report.go: fixed in #110

@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config-08-config-reports branch from a500b8c to d2576ca Compare October 6, 2026 10:27
@ccf-lisa

ccf-lisa Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

PR approved. Marking ready for e2e.

ccf-lisa Bot and others added 2 commits October 6, 2026 12:51
…eport)

With api.auth credentials the agent now tells the API what it runs:

- remote_config (set locally only: file, host env, CLI; R30) selects the
  mode. With credentials and no mode it is `report`; without credentials it
  is always `off` (R29). CCF_REMOTE_CONFIG_MODE sets it without a block.
- In report mode the reconciler sends a config report (hostname, agent
  version, base and effective config, digest, warnings, plugins with their
  agent library version) at startup and whenever it changes, resends it
  after a send error or after 24h, and honours the API's error table:
  404/401/403 back off 10 minutes, 409 pauses reports for an hour, 413
  resends it with the base dropped (R8, R36).
- base and effective are the unresolved forms, redacted by the API's
  agentconfig rules plus the plugin values that came from CCF_PLUGINS_*
  variables; the effective digest uses the same masking, so it never
  changes when a secret rotates (R24, R25, R55).
- The heartbeat carries the applied revision (0 for the file) and the
  effective digest unless the mode is off (R11, R45).
- main passes the goreleaser version to the report.

The apply modes are accepted and reported, but fetching and applying an
overlay lands in the next PR; until then they run the file only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nt remote_config

The ghcr images were built with a plain go build and no .git in the
context, so their configuration reports said agent_version "dev". The
Dockerfiles take a VERSION build arg (default dev) and pass it through
-X main.version; the publish workflow sets it from the docker metadata
version. goreleaser keeps setting main.version through its default
ldflags.

Show the remote_config block with its defaults in the README Basic
example.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config-08-config-reports branch from d2576ca to 24d4a3c Compare October 6, 2026 15:59
@gusfcarvalho
gusfcarvalho merged commit e76d13a into main Oct 6, 2026
9 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config-08-config-reports branch October 6, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant