Skip to content

feat(authz): agent configure/sync actions and per-route agent guards (10/15) - #478

Open
ccf-lisa[bot] wants to merge 1 commit into
lisa/agent-config/09-instance-lifecyclefrom
lisa/agent-config/10-agent-authz
Open

ccf-lisa[bot] wants to merge 1 commit into
lisa/agent-config/09-instance-lifecyclefrom
lisa/agent-config/10-agent-authz

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Part 10/15 of the agent remote-configuration stack

This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without docs/, go.sum and Markdown). The last layer's tree is identical to #465, which already has its review history.

Stacked on #477 (lisa/agent-config/09-instance-lifecycle). Review and merge in order.

What's in this layer

Tenth layer of the agent remote-configuration stack (split from #465): the agent resource gains configure (write an agent's overlay) and sync (an agent fetching its overlay and reporting) in the manifest and Cedar roles; the builtin PDP requires the admin check for users on agent:* and lets agent service accounts only register, ingest and sync (R39); /admin/agents list/get need agent:read while writes and key routes stay admin:manage (R40).

Size: +258 -21 = 279 changed lines (without docs/go.sum).

Verification

Each layer builds on its own: go build, go vet (also with -tags integration), golangci-lint run and go test ./... pass, and make swag leaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1b7dbae3-13c5-408a-bad3-f7f7df9bfa03

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Tenth layer of the agent remote-configuration stack (split from #465): the agent resource gains configure (write an agent's overlay) and sync (an agent fetching its overlay and reporting) in the manifest and Cedar roles; the builtin PDP requires the admin check for users on agent:* and lets agent service accounts only register, ingest and sync (R39); /admin/agents list/get need agent:read while writes and key routes stay admin:manage (R40).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gusfcarvalho
gusfcarvalho force-pushed the lisa/agent-config/10-agent-authz branch from 2669fef to 883dfab Compare October 5, 2026 19:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants