This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/agent-team/agent_team
Adam Moussa 61ab1f0cd5 fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves)
The P3 dispatcher's default seams shell out to gh/git, but the R720 box has
no gh and a read-only PAT with no Actions scope — so dispatch_apply_verify
returned no run_id and every task parked at verify ("dispatch unresolved").

Add a GitHub-App auth path: the box mints short-lived (~1h) installation
access tokens from the App private key and uses them for the three dispatch
seams, removing the gh dependency.

- agent_team/github_app.py (new): mint_installation_token (RS256 App JWT,
  iss=app_id, iat backdated 60s, exp 9 min; POST /access_tokens) + a lazy
  TokenProvider that caches and re-mints near expiry. Secret-safe: the JWT
  and token are never logged, never in an exception message, never persisted.
- dispatcher.py: app_branch_pusher / app_workflow_dispatcher / app_run_locator
  (additive; gh/git _default_* left untouched). Push auth rides a host-scoped
  http.extraHeader via GIT_CONFIG_* env (token never in argv/ps); the REST
  run locator maps id->databaseId / created_at->createdAt into select_run_id
  and surfaces 4xx promptly instead of silently exhausting the poll window.
- coordinator.py: default_dispatch_node_factory binds the App seams when
  AGENT_TEAM_GH_APP_ID / _INSTALLATION_ID / _PRIVATE_KEY are all set; partial
  or unreadable config logs one warning and falls back to gh-default (never
  raises at serve-start).
- requirements.txt: pin PyJWT, cryptography, requests (App seams + CI fetcher).
- DEPLOY-R720.md / README.md: App dispatch config, permission/scope audit,
  env-precedence check, key rotation/revocation + incident response.

Tests: +18 (test_github_app.py new; dispatcher/coordinator additions) covering
JWT claims, cache/re-mint, token-scrub-on-error, REST field mapping + run-name
correlation, and the partial-env inert fallback. Full suite 1523 passing.
2026-06-24 17:07:01 -04:00
..
db fix(agent-team): init_db drives migrate() so the version stamp actually advances 2026-06-24 12:18:22 -04:00
nodes fix(agent-team): clarifier turn headroom (max_turns=4) so it can finish its JSON 2026-06-24 15:18:28 -04:00
transport fix(agent-team): centralize safe decision mapping + remove free-text abandon hair-trigger 2026-06-24 11:48:04 -04:00
__init__.py Plane 2 foundation: interfaces, SQLite schemas, state-store, billing seam 2026-06-17 15:16:12 -04:00
api.py fix(ws1): harden HTTP API + declare fastapi/uvicorn deps 2026-06-23 12:27:23 -04:00
billing.py Plane 2 foundation: interfaces, SQLite schemas, state-store, billing seam 2026-06-17 15:16:12 -04:00
ci_fetcher.py fix(agent-team): remediate C1 security-review BLOCK (2 HIGH + MED/LOW) 2026-06-23 19:52:04 -04:00
ci_gate.py feat(agent-team): P3 Phase-0 box-side build->dispatch->verify (WIP) 2026-06-23 19:52:04 -04:00
ci_watcher.py fix(agent-team): close P3 async-resume BLOCKs (durable CI-watcher wiring) 2026-06-23 19:52:04 -04:00
coordinator.py fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves) 2026-06-24 17:07:01 -04:00
dashboard.py fix(agent-team): scrub exception text from /api/state + /api/topology errors 2026-06-23 17:28:22 -04:00
deadline_timer.py Add Plane-2 leaf scaffold (pipeline graph, nodes, HITL, transports, CI) 2026-06-17 15:16:12 -04:00
decisions.py fix(agent-team): centralize safe decision mapping + remove free-text abandon hair-trigger 2026-06-24 11:48:04 -04:00
dispatcher.py fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves) 2026-06-24 17:07:01 -04:00
draft_pr_monitor.py feat(agent-team): P3 Phases A/B/E — safety tooling, wiring, docs 2026-06-23 19:52:04 -04:00
github_app.py fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves) 2026-06-24 17:07:01 -04:00
graph.py fix(agent-team): plan-gate approve routes into the build subgraph (not END) 2026-06-24 14:13:11 -04:00
invoker.py fix(agent-team): builder uses agentic invoker config (read-only tools + turn headroom) 2026-06-24 13:13:28 -04:00
invoker_multi.py fix(ws1): skip fastapi TestClient tests when fastapi absent + ruff format 2026-06-23 11:40:46 -04:00
ledger.py feat(agent-team): add pending_questions.kind discriminator + migration (Phase B1) 2026-06-23 21:03:53 -04:00
operator_cli.py Add Plane-2 leaf scaffold (pipeline graph, nodes, HITL, transports, CI) 2026-06-17 15:16:12 -04:00
recovery.py Add Plane-2 leaf scaffold (pipeline graph, nodes, HITL, transports, CI) 2026-06-17 15:16:12 -04:00
responder.py feat(agent-team): one Slack thread per task — root "Task received" message + threaded questions/milestones 2026-06-23 15:49:40 -04:00
resume_worker.py fix(agent-team): close P3 async-resume BLOCKs (durable CI-watcher wiring) 2026-06-23 19:52:04 -04:00
state_store.py Plane 2 foundation: interfaces, SQLite schemas, state-store, billing seam 2026-06-17 15:16:12 -04:00
status_page.py fix(agent-team): scrub exception text from /api/state + /api/topology errors 2026-06-23 17:28:22 -04:00
task_model.py feat(agent-team): resumable plan-review gate in the graph (Phase B2a) 2026-06-23 21:03:53 -04:00
topology.py feat(agent-team): LangGraph-introspected topology + read-only dashboard API 2026-06-23 17:15:16 -04:00