Commit Graph
11 Commits
Author SHA1 Message Date
jsahnandClaude Opus 4.8 8dfda00c12 feat(run-agent): send X-Admin-Token so backend AuthGate accepts CI calls
The backend now has a global AuthGateMiddleware: every data route
(workspaces/lookup, upload-agent, sse/...) requires auth, returning
401 {"detail":"authentication required"} otherwise. CI authenticates with
the service token via the X-Admin-Token header (proxies any user_id).

- run_agent_api.py: read ADMIN_API_TOKEN from env, attach X-Admin-Token to
  both httpx clients (all lookup/upload/sse/action/cancel calls); warn if unset
- run-agent.yml: inject ADMIN_API_TOKEN from Gitea repo secret
- Gitea repo secret ADMIN_API_TOKEN registered
- TEST_WORKFLOW.md / .env.example: document ADMIN_API_TOKEN (.env local, secret in CI)

Verified end-to-end: workspaces/lookup for user_id=jhogyu now resolves
(401 -> 200), e.g. Aug_2026_Test -> 3523fa2b-...

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-20 17:02:12 +09:00
jsahnandClaude Opus 4.8 4279fc70ab fix(stage1-part2): give Claude B1-B5 workers localdocs tool (refs #2)
The Claude Part_2 domain workers (Stage_B_B1..B5) had use_tools: [] and
relied entirely on preflight injecting stage1_tmp/task_c_bo/domain_slices/
B{n}.json. In the failing run the executed A0 wrote full-name slices
(B1_Money_Successor.json ...) while preflight expected short names
(B1.json), so nothing was injected and the tool-less workers emitted
tool-call syntax as plain text (<mcp_tool_call>/<function=read_file>) and
produced FAILED/empty output.

The current v.7 A0 already writes short names matching preflight, so the
naming mismatch itself is resolved in this file. This change adds
use_tools: ['localdocs'] (already declared on the stage) so the workers can
read their slice directly if preflight ever misses again — matching the
proven Codex worker design and removing the single point of failure.

Note: domain slices are 255-300KB (~65-90K tokens); llm_bridge caps tool/
injected content at 50K tokens, so slice compaction in A0 is still needed
for full-fidelity output quality.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 10:37:08 +09:00
jsahnandClaude Opus 4.8 d96d6edfd1 fix(stage1-part2): stop R0 hard-crashing on fragile LLM-echoed checks
Task_C_BO_R0_seed_reducer_exception_planner raised RuntimeError (exit 1)
whenever status became BLOCKED, and BLOCKED was triggered by validation
findings that are inherently fragile because they require an LLM (Stage B
workers) to echo values verbatim or stay perfectly in scope:
  - slice_digest_sha256 echo mismatch (all 5 domains)
  - run_fingerprint echo mismatch
  - source meeting-clause refs outside slice/global (B5, 42 findings)

A decrypted postb_seed_ledger.json from the 2026-07-20 run confirmed all
47 blocking failures came from exactly these three check classes (no BLOCK
severity reviews / no budget overflow). Downgrade them from fatal
`failures` to non-fatal `reviews` (candidates preserved, routed to human
review). Genuine contract violations (schema/domain mismatch, worker
FAILED, candidate_ref sequence, forbidden keys, invalid enum) and the
deterministic A0-artifact integrity raises are kept fatal.

Gate simulation on the confirmed inputs: BLOCKED/exit-1 -> READY_WITH_REVIEW,
fan-out restored so R1 exception adjudication can run.

Note: this unblocks the pipeline and flags the issues; the upstream root
cause (Stage B tool-content truncated 66-78K -> 50K tokens) still needs a
slice-compaction fix for output quality.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-21 19:43:01 +09:00
jsahnandClaude Opus 4.8 ecf321b1ab refactor: make user_id a required input, drop hardcoded jsahn default
user_id is now a required workflow_dispatch input (no default) and the
runner validates it is non-empty before doing anything. Removed the
'jsahn' default from the script arg and replaced jsahn with <user_id>
placeholders throughout TEST_WORKFLOW.md so the workflow is not pinned
to one account.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-08 16:06:50 +09:00
jsahn b332d3d24d Add TEST_WORKFLOW.md for executing Agent YAML via Gitea Actions
- Documented the workflow for running Agent YAML using Gitea Actions.
- Included setup instructions for .env file with Gitea token.
- Provided three methods for triggering the workflow: via Gitea API, Gitea web UI, and local script execution.
- Added workflow input reference and prerequisites for server infrastructure.
- Included troubleshooting section for common issues encountered during execution.
2026-07-08 14:00:30 +09:00
jsahnandClaude Opus 4.8 6b8cff4556 feat: select workspace by name via /workspaces/lookup
Add workspace_name input; the runner resolves it to a workspace_id through
GET {api_base}/workspaces/lookup?user_id=... before uploading the agent.
workspace_id remains as an explicit override. Name matching is NFC-normalized
(handles Korean NFD/NFC) with a case-insensitive fallback, and a no-match
error lists the available workspace names. Requires one of name/id.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 16:12:04 +09:00
jsahnandClaude Opus 4.8 1f34c9186f fix: downgrade upload-artifact to v3 for Gitea compatibility
Gitea Actions only supports the v3 artifact protocol; upload-artifact@v4
uses the @actions/artifact v2 API which Gitea (identifying as GHES) rejects
with GHESNotSupportedError. The agent run step itself succeeds; only the
artifact upload was failing.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 15:50:01 +09:00
jsahnandClaude Opus 4.8 e50b6f7d6d fix: use internal container URL for api_base (join runner to backend network)
localhost:8800 fails because act_runner job containers run in their own
network namespace. Point api_base at the backend container on the shared
docker network (http://agent-backend:8000). Requires the runner's
config.yaml container.network to be set to the backend's docker network.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 14:12:08 +09:00
jsahnandClaude Opus 4.8 a96ac2067f fix: default api_base to internal backend URL to bypass OAuth proxy
The public URL (legalpoc.eroomai.com) sits behind a Google OAuth proxy,
so CI requests get 302-redirected to the login page. Point api_base at the
internal backend (http://localhost:8800, served at root without /api prefix)
which the act_runner reaches on the same host. Documents host.docker.internal
and Tailscale fallbacks for containerized runners.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 13:43:42 +09:00
jsahnandClaude Opus 4.8 eb1f1fd398 feat: add Gitea Actions workflow to run agent YAMLs via AgentBackend API
- .gitea/workflows/run-agent.yml: workflow_dispatch with yaml_path input;
  runs a specified agent YAML through upload-agent + SSE (SKILL.md §0.6 path A)
- scripts/run_agent_api.py: SSE runner with auto-confirm on stage_complete
  (with retry), stage_error -> cancel + fail, reconnect on drops,
  --max-runtime guard under the 3h Gitea/act_runner task caps,
  SIGTERM-safe session cancellation, events.jsonl/final_output/summary artifacts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 11:42:52 +09:00
jsahnandClaude Opus 4.8 47dd16a43f chore: ignore .serena/ and .DS_Store everywhere, untrack existing files
- .gitignore: add .serena/ and .DS_Store (both match at any depth)
- untrack 4 .serena files and 155 .DS_Store files (kept on disk)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 11:42:40 +09:00