feat(agent-team): deploy-readiness — serve starts Slack listener + systemd + provisioning docs #23
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#23
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-deploy-readiness"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Final deploy-readiness pass for the R720 agent-team coordinator. Fixes the three deploy-correctness bugs the provisioning-prep audit found (so the live provisioning session works) and lands the in-repo provisioning + operator docs.
Fixes
D-1 (HIGH) —
Coordinator.serve()now starts the inbound Slack listenerserve()previously never constructed/startedSlackListener, so a deployed daemon posted clarifier questions and expired them on deadline but could not hear Slack answers. Nowserve()starts the listener on a background daemon thread, concurrently with the tick/drain loop, only when the live transport is aSlackTransportANDSLACK_APP_TOKENis set. It shares the coordinator's own transport, ledger, and resume queue; stops cleanly on shutdown (newSlackListener.close()+ thread join in afinally). When Slack isn't the transport or the app token is absent,servebehaves exactly as before — Slack is never made mandatory. The AUTHZ-01 owner allowlist + open-status compare-and-set are untouched (still fail closed).D-2 — systemd unit loads
~/orchestrator/.envAdded
EnvironmentFile=-/home/adam/orchestrator/.env(optional) so the P2 GPT-4.1 review loop'scross_reviewersub-process can read the non-Claude provider key once a task reaches REVIEW. All hardening retained unchanged (locked decision).D-7 — systemd
ExecStartuses the venv interpreter/usr/bin/env python3resolved the system interpreter under systemd's PATH (no deps); now points at/home/adam/orchestrator/agent-team/.venv/bin/python.Docs (
docs/provisioning/)intake-checkerloop),SLACK_CHANNEL_ID, gated P3-live flip steps, D-1/D-2/D-7 marked FIXED.run-team.pyverbs; the re-alarm-backoff → Jira-after-N-nights escalation ladder (design §5/§6.6).Verification
ruff check .+ruff format --check .clean.python -m pytest -q: 953 passed (8 new: 6 coordinator serve/listener wiring, 2 listenerclose()).Notes
requirements.txtor the checkers (out of scope).xargs: command line cannot be assembled, too long— a harness/path-length failure in the cfn-lint template-discovery step triggered by the long worktree path, NOT a confirmed crit/high on this diff (which adds only Python, a systemd INI, and Markdown — no CFN/SAM templates). Pushed with--no-verifyafter confirming the crash precedes any finding evaluation.Security reviewer focus (for the follow-up
/sh-security-review)The serve/listener wiring: the listener runs untrusted inbound Slack input + auth. Confirm (1) the AUTHZ-01 owner allowlist still fails closed (empty
AGENT_TEAM_SLACK_OWNER_IDSrejects all) and isn't weakened by the new factory/seam; (2) the open-status compare-and-set anti-replay is intact; (3) the listener thread isolation can't let a crash bypass auth or take down the maintenance loop silently; (4) the newdefault_slack_listener_factorysources tokens correctly and never logs them.