Skip to content

feat(agents): the floating DevOps agent - devops-1, ROBOCO_DEVOPS_ENABLED delegation lane, conventions-declared infra review gate - #1109

Merged
rennf93 merged 16 commits into
slavefrom
feat/devops-agent
Sep 23, 2026
Merged

rennf93 merged 16 commits into
slavefrom
feat/devops-agent

Conversation

@rennf93

@rennf93 rennf93 commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Summary

Implements docs/internal/devops-agent-spec.md (4 stages): one floating DevOps agent (devops-1, Role.DEVOPS, board-team floater on the cell-pr-reviewer-2 template) that authors and reviews infra work on ANY project, RoboCo included. Default-off behind ROBOCO_DEVOPS_ENABLED; flag off is byte-for-byte inert.

Stage 0: identity + headcount (ffeedc2)

  • Role.DEVOPS, devops-1 seeded (UUID ...0004-000000000009), gateway role config with notify_ack, A2A matrix (initiates only to cell_pm/main_pm), GATEWAY_ENABLED_ROLES, image reuse (roboco-agent-dev-be, no new Dockerfile/compose), hummin high-thinking tier, migration 103 (agentrole enum), headcount 25 -> 26 (docs-drift anchor + README), panel roster/labels/fallbacks.

Stage 1: delegation lane (8331c80)

  • The generic dev dispatch path admits a flag-armed devops assignee; full authoring verb set (claim through i_am_done, incl. sync_branch and the NEEDS_REVISION rework edge); claim-team exemption; Board materialization target_agent honored by roadmap/pest_control/coroner materializers.

Stage 2: the infra declaration (ea001fe)

  • Optional infra: glob section on ConventionsStandard (None = shipped DEFAULT_INFRA_GLOBS, [] = opt-out, declared = curated-replaces); round-trips through render_yaml + the panel Conventions tab (no strip-on-save); flag-independent effective_infra_globs accessor; JSONB cache-schema stamp recomputes pre-stamp cache rows instead of masking the declaration.

Stage 3: the review gate (dc84668)

  • Blocking pr_pass precondition: when changed files hit the project's effective infra globs (self-review excluded, waiver path unaffected), a devops verdict for the current head SHA is required; re-arms on head advance. devops-1 co-claims via a marker (primary reviewer's ownership/claim/verbs untouched), records pass verdicts via the new record_devops_review intent, files pr_fail findings under the new devops_review ledger origin. Dispatcher spawns devops-1 after the primary reviewer. Full /api/v1/flow/devops/* router (closed a Stage 1 gap: the verbs had no routes).

Test plan

  • make foundation-check green post-commit at every stage (identity/lifecycle drift, seeds, postgres enum parity, artifact renders)
  • 49 new gate tests + 26 delegation tests + 34 declaration tests (predicate, precondition incl. head-advance re-arm, co-claim isolation, findings origin, dispatch slot, flag-off inertia, schema/merge/serializer round-trips, cache stamp)
  • ruff check + format clean repo-wide, mypy clean on touched modules, xenon clean, panel tsc + vitest green
  • Pre-existing-only failures confirmed identical on a stashed clean-tree baseline

…1 board-team floater on the cell-pr-reviewer-2 template, gateway role config, A2A matrix, agentrole enum migration 103, hummin high-thinking tier, headcount 25 -> 26; inert until a dispatcher routes to it
…S_ENABLED - generic dev dispatch admits the flag-armed floater, the full authoring verb set (claim through i_am_done incl. sync_branch and the NEEDS_REVISION rework edge), claim-team exemption, and Board materialization target_agent honored by the roadmap/pest_control/coroner materializers; flag-off stays byte-for-byte inert
…tions standard - optional infra: glob section on ConventionsStandard (None = defaults, [] = opt-out, declared = curated-replaces), shipped DEFAULT_INFRA_GLOBS, round-trip through render_yaml and the panel Conventions tab, flag-independent effective_infra_globs accessor, and a JSONB cache-schema stamp so pre-stamp cache rows recompute instead of masking the declaration
…marker-based, primary reviewer ownership untouched), a blocking pr_pass precondition requiring a devops verdict for the current head SHA (re-arms on head advance, devops's own pass is its verdict), record_devops_review intent, devops_review findings origin, the /api/v1/flow/devops router, and a dispatcher slot spawning devops-1 after the primary reviewer; glob predicate over the project's effective infra globs with self-review exclusion
@github-actions github-actions Bot added documentation Docs, README, CHANGELOG, governance files area: panel Touches panel/ (Next.js control panel) area: api Touches roboco/api/ (FastAPI routes, schemas, app) area: services Touches roboco/services/ (business logic, side effects) area: alembic Touches alembic/ (database migrations) tests Test suite changes area: gateway Touches roboco/services/gateway/ (Choreographer, verb surface) area: orchestrator Touches roboco/runtime/ (agent spawner, dispatch loops) area: agents Touches agents/ (prompts, role config) labels Sep 20, 2026
@github-actions

Copy link
Copy Markdown

Thanks for opening your first pull request on RoboCo!

Quick checklist before review (most of these are enforced by CI, but worth a glance):

  • make quality — ruff format check, ruff check, mypy, pytest (≥80% coverage), and the rest of the gate
  • Panel changes pass pnpm lint and pnpm exec tsc --noEmit (run from panel/)
  • No # noqa / # type: ignore shortcuts; pre-existing violations in touched files are fixed
  • Added an entry under ## [Unreleased] in CHANGELOG.md
  • Signed the CLA (the bot will prompt you on this PR)
  • Signed your commits — master requires verified signatures (SSH signing setup)
  • Updated any affected docs under docs/

See CONTRIBUTING.md for the full workflow and the Code of Conduct for the community standards we follow.

Welcome aboard — a maintainer will review shortly.

@rennf93 rennf93 self-assigned this Sep 20, 2026
@rennf93 rennf93 moved this from Backlog to In review in RoboCo Kanban Sep 20, 2026
…digest (RUF100, pre-existing from #1079)"

This reverts commit dc84668.
…cker/agent-devops.Dockerfile FROM agent-base with a pinned multi-arch infra toolchain (docker CLI for compose config validation only, no daemon/socket ever, compose plugin, kubectl, helm, terraform, hadolint, yamllint, shellcheck), build service added byte-identically to both compose files, registry pre-pull entry, release.yml IMAGES entry, dockerfile_map + AGENT_IMAGES repoint, image-registry test pin
@github-actions github-actions Bot added ci GitHub Actions and CI configuration build Makefile / Docker / Docker Compose / packaging labels Sep 20, 2026
…ount 26 + org-chart floater line, task-lifecycle.md gains the infra review gate paragraph (globs source, marker co-claim, record_devops_review, devops_review origin, full-second-reviewer ruling, self-review exclusion, delegation lane, flag-off inertia)
… org-chart floater line, infra co-review lifecycle bullet, infra: globs in the conventions paragraph, provider list synced to AGENTS.md (OpenRouter/Nebius/Hummin were missing)
…1110)

The agent image never pre-creates ~/.config/opencode, and main() wrote
opencode.json without mkdir-ing its parent, so every OpenRouter-routed
spawn exited 1 on FileNotFoundError before the CLI ever started (same
crash on fe-dev-1, fe-pm, the auditor). The bash-guard plugin write
already mkdir'd its parents; the config write now does the same.
Regression test mirrors the plugin-write parents test with a missing
.config/opencode prefix.
deploy/nginx.conf includes /etc/nginx/front/active-upstreams.conf (the
blue-green color switch), but docker-compose.registry.yml never mounted
the repo's ./front directory, so fresh `make quickstart` crash-looped
roboco-nginx on the missing include while everything else came up
healthy. The build compose has carried the directory mount since the
2026-09-17 blue-green flip; the registry compose now carries the
byte-identical block. Directory bind, not a file bind: a file bind pins
the inode and deploy-nas.sh's atomic tmp+mv swap would never reach the
running container.

Guard test pins the ./front:/etc/nginx/front:ro mount in BOTH compose
files and that front/active-upstreams.conf exists in the repo, so a
future compose fork cannot reintroduce the fresh-install crash.
fix(providers): mkdir opencode's config home before the render write (#1110)
…ount

fix(compose): registry nginx mounts the front include dir (#1111)
…d the arcs caught four real gaps

Three scripted arcs in tests/e2e_smoke/test_devops_gate.py over the REAL
choreographer verbs: (1) the infra review gate end to end — an assembled
cell->root PR touching DEFAULT_INFRA_GLOBS refuses the primary reviewer's
pr_pass until devops-1 co-claims via claim_gate_review and records a
passed record_devops_review verdict, then composes; both rejections
walked (verdict-less pr_pass, record before co-claim); (2) flag-off
inertia: the identical chain passes with no devops involvement;
(3) the delegation lane: a PM-assigned infra leaf flows through the
normal authoring lifecycle as devops-1.

The arcs immediately paid for themselves — four production gaps fixed:

- roboco/mcp/flow_server.py never exposed record_devops_review: the
  manifest advertised it but a real devops-1 could not record a verdict.
  Tool added + registered.
- content_notes had no devops section entry while i_am_done demands
  dev_notes>=min: the delegation lane could never complete. devops now
  authors the developer section (it IS a worktree author).
- _agent_access_claim_guard had no flag-gated devops exemption (the
  task-level carve-out alone): every delegation-lane claim was wedged
  behind the assigned-cell rule.
- content_actions refused the co-claimant's journal note (the verdict
  verbs demand a learning entry; the marker now authorizes content).

Plus: the smoke harness mounts the flow_devops router (it predated the
feature); devops-1 joins the seeded canonical company (static seed UUID
like main-pm); dev_arc creates nested work-file parents; the i_am_done
files_changed evidence leg forwards the submitting agent instead of the
post-transition assignee; agent-image-smoke.yml gains a devops
toolchain-smoke job (build + every pinned binary executes, no daemon).
test(e2e): the devops gate + delegation lane join the live smoke
@github-actions github-actions Bot added the area: mcp Touches roboco/mcp/ (MCP server entry points) label Sep 21, 2026
@github-actions

This comment was marked as outdated.

… write

The Playwright job carries an explicit permissions block; the devops job
inherited the default read-only token, so its always() PR-comment step
died with 403 Resource not accessible by integration (the build and the
toolchain check themselves passed). Same grant added, and the comment
step now tolerates a missing report file: a failed build never creates
one, and a comment-step ENOENT must not bury the actual failure.
@github-actions

Copy link
Copy Markdown

DevOps image toolchain smoke results

DevOps toolchain smoke check (agent-devops)

docker-cli 28.4.0

@github-actions

Copy link
Copy Markdown

Agent Image Smoke (Playwright) results

Playwright image size delta (real docker inspect sizes)

image before after delta
agent-qa-fe 2096MB 2096MB +0MB
agent-ux 2014MB 2014MB +0MB

Headless chromium launch smoke check

PLAYWRIGHT_SMOKE_OK
PLAYWRIGHT_SMOKE_OK

Playwright MCP server smoke check

Version 0.0.78
Version 0.0.78

Headless browser verification screenshot (ux-qa image)

Screenshot of a live panel page (/login), taken from inside agent-ux:after. See the ux-qa-panel-screenshot build artifact.

@rennf93
rennf93 merged commit e70bb58 into slave Sep 23, 2026
14 checks passed
@github-project-automation github-project-automation Bot moved this from In review to Done in RoboCo Kanban Sep 23, 2026
@rennf93
rennf93 deleted the feat/devops-agent branch September 23, 2026 18:18
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 23, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area: agents Touches agents/ (prompts, role config) area: alembic Touches alembic/ (database migrations) area: api Touches roboco/api/ (FastAPI routes, schemas, app) area: gateway Touches roboco/services/gateway/ (Choreographer, verb surface) area: mcp Touches roboco/mcp/ (MCP server entry points) area: orchestrator Touches roboco/runtime/ (agent spawner, dispatch loops) area: panel Touches panel/ (Next.js control panel) area: services Touches roboco/services/ (business logic, side effects) build Makefile / Docker / Docker Compose / packaging ci GitHub Actions and CI configuration documentation Docs, README, CHANGELOG, governance files tests Test suite changes

Projects

Status: Done

1 participant