Conversation
Implement a separately deployed provider/controller, confined executor, optional mecak8s mTLS client, charts, and mock kind qualification. Keep lifecycle, distributed ownership, and acceptance gaps explicit for draft review. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Hold the actual model stream until both cleanup guards are checked instead of racing a fast finite mock stream. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
JAORMX
added this pull request to stack #1618
September 16, 2026 07:51
Replace the private REST protocol with typed protobuf RPCs over mTLS. Add a real-key kind coding smoke with runtime-only credential loading, UID-pinned Secret cleanup, mock restoration, and independent gRPC artifact and command verification. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Replace finite mock output with a context-bound stream so cancellation assertions do not race normal completion. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Preserve the gRPC execution-provider implementation alongside current command-runner composition and teach canonical self-knowledge about the two optional execution binaries. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Add run claims, transactional reference reconciliation, UID-fenced executor replacement and retirement, schema migration, durable grant revocation, reloadable TLS/keyring authority, deployment limits and release definitions. Qualification and independent review remain in progress. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Close ownership, schema pruning, rotation and termination-proof review findings. Add Calico-backed lifecycle, quota, rotation and failure scenarios, strict release provenance, and operational runbooks. Local production qualification remains blocked by host inotify capacity; CI proof is pending. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Fix CRD admission, termination and replay edges, bounded renewal, exact intent lookup and release provenance. Add real API-server legacy migration and replica/network proof corrections. Final local production qualification is blocked by kernel keyring quota, not reported as passed. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Restore forward-generation trust for new connections, reacquire expired test claims safely, use the post-release epoch, and surface holder start failures without weakening lifecycle checks. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
Restore owner attestation in intent responses, verify presented intermediate chains against current trust, and tie readiness to authoritative state. Qualify phase-scoped claims and recreate endpoint connections after rollouts. Co-Authored-By: Mecatl <mecatl@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stage: production completion (draft, stacked)
Plan: #1579
Base:
plan/native-kubernetes-executionThe operator requested completion of production readiness. This PR now contains the ownership, lifecycle, rotation, deployment, and qualification implementations, but production qualification is not yet complete. No merge or release publication is implied.
Implemented
Verification and current blocker
task test, targeted race suites, lint/actions, build, API check, docs/site and offline demo passed during the production repair iterations. The latest migration/network fixture edits passed full tests, lint, docs and build.kernel.keys.maxkeys=200,kernel.keys.maxbytes=20000): runc cannot create later Pod sandboxes. No host setting was changed by the agent. Operator approval for a temporary increase is pending.Live credential status
A prior typed-gRPC live OpenRouter coding run passed (28,003 input / 783 output tokens, actual Write and exact
go test ./...Shell exit 0, independent gRPC artifact/test verification). That is pre-production-hardening evidence, not proof of this new lifecycle implementation. The final protected live smoke is withheld until deterministic production qualification is green.The supplied OpenRouter credential is read only by the trusted runtime loader, never directly by agent tools/model context. Only the harness receives its run-owned Secret; cleanup is UID-pinned and restores mock mode. No credential was read or staged during the blocked production run.
Scope retained
Foreground Shell and filesystem operations are supported. Git bootstrap, remote project ingestion, background/status/streaming command APIs, schedules, and isolated delegation remain explicitly outside this first production scope. Unobservable-node recovery fails closed without independent fencing proof. Cluster administrators and the selected runtime/CNI remain deployment trust assumptions.