feat(agent-team): Confluence-writer node (draft → approve gate → dry-run write) [flag-gated] #66
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#66
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feat/agent-team-confluence-node"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Adds a Confluence-writer node to the Plane-2 agent-team pipeline: a
draft → human-approval gate → (dry-run) writelane that lets the pipeline produce Confluence documentation, either as a direct task or as a follow-on to a change it just shipped. Entirely flag-gated behindAGENT_TEAM_CONFLUENCE_ENABLED(default off) — when unset, the graph and daemon are byte-identical to today.Why
The pipeline could build and PR a change but had no way to keep the docs in step. Design
docs/r720-agent-team-design.md§7 Phase 4 (D6/D7) anticipated this: an on-demand write path that drafts an update, gets human approval, and writes as the IT-space-scopedconfluence-botservice account, including Mermaid architecture-map edits.Architecture
Two entry points feed one shared tail:
confluence/client.py— OAuth 2LO (service account) + Basic-auth REST client. Dry-run by default; a livePUThappens only on an explicit apply flag and gate approval. HTTP injected as a seam (no network in tests).confluence/mermaid.py— vendored ADF-only Mermaid editor with macro-count + revert-diff guards, dry-run default (a full-body markdown round-trip has silently destroyed diagrams on page 1540098 before, so ADF-only is load-bearing).nodes/confluence_writer.py(+_llm) — the three nodes + router. The gate reuses theinterrupt()/pending_questions/ responder-resume contract (new ledgerkind='confluence_approval', schema v5 widens the CHECK via an atomic rebuild).coordinator.py— delivers theconfluence_approvalgate to Slack and forwardstask_kind; same crash-isolation as the plan gate.Aligned with the merged #60/#61 builder lesson
The draft node is a reasoning→JSON node, tools-off,
max_turns=4(like the planner) — not an agentic repo-inspecting call. An earlier cut usedmax_turns=8+ read-only tools; #61 proved live that exact config exhausts turns / returns narration, so this branch follows the post-#61 convention and folds any repo context into the prompt instead. Branch is rebased onto currentmain(the invokerallowed_toolsseam now comes from upstream #61, not a local copy).Tests
test_confluence_{client,mermaid,writer,e2e,coordinator}.py, plus v5-migration cases intest_ledger.pyand updatedtest_task_model.pyguards.page_idrequest-path injection, andtask_kindnot forwarded.ruff check+ruff format --checkclean.Outstanding before merge / deploy (gated)
/sh-security-reviewand the GPT-4.1 cross-family review.confluence-botservice account (IT-space-only edit), token into~/secrev.env(mode 600), 90-day rotation (D6/F3).--apply.project_r720_agent_teammemory updates (docs-as-you-go at deploy time).Closes #65 — also wires the agent-team web CI (Prettier + ESLint + Playwright) and enables the toggled-off
ci-websteps; the dashboardvitestconfig is scoped tosrc/so it skips the Playwright e2e specs.@ -0,0 +1,546 @@"""Unit tests for agent_team.confluence.client (OAuth 2LO + basic auth + dry-run updater).CodeQL / Incomplete URL substring sanitization
The string https://seahaven.atlassian.net may be at an arbitrary position in the sanitized URL.
Show more details
Closing: agent-team is being decommissioned (superseded by Open SWE). See removal PR.