Skip to content

feat(api): agent instance config reports (12/15) - #480

Merged
gusfcarvalho merged 4 commits into
lisa/agent-config/11-agent-config-syncfrom
lisa/agent-config/12-agent-config-report
Oct 6, 2026
Merged

gusfcarvalho merged 4 commits into
lisa/agent-config/11-agent-config-syncfrom
lisa/agent-config/12-agent-config-report

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 12/15 of the agent remote-configuration stack

This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without docs/, go.sum and Markdown). The last layer's tree is identical to #465, which already has its review history.

Stacked on #479 (lisa/agent-config/11-agent-config-sync). Review and merge in order.

What's in this layer

Twelfth layer of the agent remote-configuration stack (split from #465): PUT /api/agent/instances/{instanceId}/config-report stores an instance's mode, applied/attempted revision, status, redacted base/effective configs, digest, plugins, unsafe changes and warnings. The server validates and bounds the report, rejects NUL characters, re-redacts base/effective, masks secrets in free-text fields (error, warnings, plugin sources, unsafe values, remote-config) and returns 409 at the instance cap. The JSON body reader accepts application/json with parameters (415/413 otherwise).

Size: +1578 -8 = 1586 changed lines (without docs/go.sum).

size-exception: over 1000 LOC because of the tests that cover this layer; the implementation part is well under 1000.

Verification

Each layer builds on its own: go build, go vet (also with -tags integration), golangci-lint run and go test ./... pass, and make swag leaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: e1fe61fc-fb7a-4b7f-af2f-b21395c082f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: REQUEST_CHANGES

1 Blocker.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

Comment thread internal/api/handler/agent_config_sync.go Outdated

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config/12-agent-config-report branch 2 times, most recently from 26847c3 to c4dd9cc Compare October 6, 2026 13:06
ccf-lisa Bot and others added 3 commits October 6, 2026 10:55
Twelfth layer of the agent remote-configuration stack (split from #465): PUT /api/agent/instances/{instanceId}/config-report stores an instance's mode, applied/attempted revision, status, redacted base/effective configs, digest, plugins, unsafe changes and warnings. The server validates and bounds the report, rejects NUL characters, re-redacts base/effective, masks secrets in free-text fields (error, warnings, plugin sources, unsafe values, remote-config) and returns 409 at the instance cap. The JSON body reader accepts application/json with parameters (415/413 otherwise).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
normalizeReport cut error, warning messages, unsafe values and plugin
sources to their length caps before scrubReportText ran, so a secret
straddling a cap no longer matched and its prefix was stored. Masking
now runs after the count caps and before the length caps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
normalizeReport never bounded remote-config, so a report with 100k
trusted_sources (7 MB) was stored with truncated=false, and ListInstances
returns that column for every instance. Cap it like the other summary
columns, after the scrub: at most 100 trusted_sources and 100
overridable_config_flags, each at most 256 bytes JSON-encoded (an over-long
entry is dropped, since a cut glob pattern can widen trust), mode at 32 and
poll_interval at 64 bytes. The encoded block stays within 64 KiB even when
every character is escaped, and the report is marked truncated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config/12-agent-config-report branch from c4dd9cc to 7e1cc5a Compare October 6, 2026 14:24
warnings[].code, unsafe[].safety and unsafe[].reason had no length cap, and
the other caps are on raw bytes, which JSON escaping can grow sixfold ('<',
'&' and control characters encode as \u00XX). One report could make its
instance's listed summary about 21 MB, and a page of 25 instances about
500 MiB.

normalizeReport now cuts code, safety and reason to 64 bytes (cut, not
rejected: a newer agent may send values this API does not know) and keeps
the summary fields (hostname, agent-version, error, warnings, unsafe,
plugins, remote-config) within 3 MiB as encoding/json encodes them with
HTML escaping, the way the instance list does. Over that budget it cuts
the error text to 8 KiB encoded and drops the last entry of the largest
list until the report fits, and marks the report truncated. A plain-text
report at every cap (about 2.9 MB) fits, so it is stored unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

@gusfcarvalho
gusfcarvalho merged commit fda9252 into main Oct 6, 2026
5 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config/12-agent-config-report branch October 6, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant