Files
jsahnandClaude Opus 4.8 8dfda00c12 feat(run-agent): send X-Admin-Token so backend AuthGate accepts CI calls
The backend now has a global AuthGateMiddleware: every data route
(workspaces/lookup, upload-agent, sse/...) requires auth, returning
401 {"detail":"authentication required"} otherwise. CI authenticates with
the service token via the X-Admin-Token header (proxies any user_id).

- run_agent_api.py: read ADMIN_API_TOKEN from env, attach X-Admin-Token to
  both httpx clients (all lookup/upload/sse/action/cancel calls); warn if unset
- run-agent.yml: inject ADMIN_API_TOKEN from Gitea repo secret
- Gitea repo secret ADMIN_API_TOKEN registered
- TEST_WORKFLOW.md / .env.example: document ADMIN_API_TOKEN (.env local, secret in CI)

Verified end-to-end: workspaces/lookup for user_id=jhogyu now resolves
(401 -> 200), e.g. Aug_2026_Test -> 3523fa2b-...

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-20 17:02:12 +09:00

135 lines
6.0 KiB
YAML

# 지정한 Agent YAML 을 AgentBackend API 로 실행하는 Gitea Actions 워크플로우.
#
# 사용법: Gitea 저장소 → Actions 탭 → "Run Agent YAML via API" → Run workflow
# yaml_path 에 repo 상대경로 입력, 예:
# Case_02_Comparison_Research/YAML_Prompts/1. Stage_1/v.5/Stage_1_Part_4.yml
#
# 요구사항:
# - 저장소 설정에서 Actions 활성화 + act_runner 등록 (runs-on: ubuntu-latest 라벨)
# - 러너가 백엔드에 내부 주소로 접근 가능해야 함 (아래 api_base 참고)
# - Gitea repo secret 'ADMIN_API_TOKEN' 등록 (백엔드 AuthGate 서비스 토큰)
#
# 인증 (중요):
# (1) 네트워크: 공개 URL(legalpoc.eroomai.com)은 OAuth 프록시 뒤라 CI 에서 302.
# localhost:8800 도 job 컨테이너 자신을 가리켜 못 닿음.
# → act_runner job 컨테이너를 AgentBackend 도커 네트워크에 붙이고 내부 컨테이너
# 주소(http://agent-backend:8000, /api 접두사 없음)로 직접 호출.
# 러너 config.yaml 의 container.network = 백엔드 네트워크(보통
# agentbackend_agent-network, docker network ls 로 확인).
# (2) 앱 인증: 백엔드에 전역 AuthGate 가 있어 모든 데이터 라우트(workspaces/lookup,
# upload-agent, sse/... 전부)가 인증을 요구한다. CI 는 서비스 토큰을
# X-Admin-Token 헤더로 보낸다(어느 user_id 로든 대리 호출 허용). 스크립트가
# ADMIN_API_TOKEN 환경변수를 읽어 자동으로 헤더에 넣는다. 값은 Gitea secret
# 'ADMIN_API_TOKEN' 에서 주입(아래 env). 로컬 실행 시에는 .env 로 제공.
#
# 실행 흐름 (SKILL.md §0.6 경로 A):
# workspaces/lookup(이름→UUID) → upload-agent 등록 → SSE start →
# stage_complete 자동 confirm → execution_complete
# stage_error 발생 시 세션을 cancel 하고 실패 처리한다.
# 전체 이벤트 로그 / final_output / summary 는 아티팩트로 저장된다.
# ※ workspace_name(작업실 이름) 또는 workspace_id(UUID) 중 하나는 반드시 지정.
#
# 실행 시간 상한 (주의):
# Gitea 의 [actions] ENDLESS_TASK_TIMEOUT 과 act_runner 의 runner.timeout 기본값이
# 각각 3h 라서, timeout-minutes 를 아무리 크게 줘도 3h 에서 강제 종료된다.
# 강제 종료되면 if: always() 아티팩트 업로드도 건너뛰므로,
# 스크립트의 --max-runtime(기본 9000s=150m) 이 먼저 세션을 정리하고 종료하도록
# max_runtime < timeout-minutes(175m) < 3h 순서를 유지한다.
# 3h 이상 돌려야 하면: app.ini 의 ENDLESS_TASK_TIMEOUT, act_runner config 의
# runner.timeout, 아래 timeout-minutes, max_runtime 입력을 모두 함께 올릴 것.
name: Run Agent YAML via API
on:
workflow_dispatch:
inputs:
yaml_path:
description: '실행할 Agent YAML 경로 (repo 상대경로)'
required: true
type: string
user_id:
description: 'AgentBackend user_id (필수)'
required: true
type: string
workspace_name:
description: '작업실 이름 (예: 팬아웃 테스트). GET /workspaces/lookup 으로 UUID 자동 해석'
required: false
default: ''
type: string
workspace_id:
description: '작업실 UUID 직접 지정(override). 비우면 workspace_name 으로 해석'
required: false
default: ''
type: string
user_input:
description: 'Agent 에 전달할 user_input'
required: false
default: ''
type: string
start_stage_index:
description: '시작 stage 인덱스 (0-based)'
required: false
default: '0'
type: string
api_base:
description: 'AgentBackend API base URL (내부 컨테이너 주소, /api 접두사 없음)'
required: false
default: 'http://agent-backend:8000'
type: string
max_runtime_seconds:
description: '총 실행 시간 상한(초). Gitea/act_runner 3h 상한보다 짧게'
required: false
default: '9000'
type: string
jobs:
run-agent:
runs-on: ubuntu-latest
timeout-minutes: 175
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Install dependencies
run: python -m pip install --quiet httpx httpx-sse
- name: Run agent via API
env:
# 백엔드 전역 AuthGate 통과용 서비스 토큰 (Gitea repo secret 에 등록 필요)
ADMIN_API_TOKEN: ${{ secrets.ADMIN_API_TOKEN }}
YAML_PATH: ${{ inputs.yaml_path }}
API_BASE: ${{ inputs.api_base }}
AGENT_USER_ID: ${{ inputs.user_id }}
AGENT_WORKSPACE_NAME: ${{ inputs.workspace_name }}
AGENT_WORKSPACE_ID: ${{ inputs.workspace_id }}
AGENT_USER_INPUT: ${{ inputs.user_input }}
START_STAGE_INDEX: ${{ inputs.start_stage_index }}
MAX_RUNTIME_SECONDS: ${{ inputs.max_runtime_seconds }}
# '=' 형식 필수: 값이 '-' 로 시작하는 자유 텍스트여도 argparse 가 값으로 인식
run: |
python scripts/run_agent_api.py \
--yaml-path="$YAML_PATH" \
--api-base="$API_BASE" \
--user-id="$AGENT_USER_ID" \
--workspace-name="$AGENT_WORKSPACE_NAME" \
--workspace-id="$AGENT_WORKSPACE_ID" \
--user-input="$AGENT_USER_INPUT" \
--start-stage-index="$START_STAGE_INDEX" \
--max-runtime="$MAX_RUNTIME_SECONDS" \
--output-dir=agent_run_output
# Gitea Actions 는 아티팩트 v3 프로토콜만 지원한다. upload-artifact@v4 는
# @actions/artifact v2 API 를 써서 Gitea(GHES 로 식별됨)에서 거부되므로 v3 사용.
- name: Upload run artifacts
if: always()
uses: actions/upload-artifact@v3
with:
name: agent-run-${{ github.run_number }}
path: agent_run_output/
if-no-files-found: warn