Skip to content

refactor(registry/harleylrn/modules/kiro-cli)!: remove agentapi, tasks and start logic - #1161

Draft
35C4n0r wants to merge 1 commit into
mainfrom
35C4n0r/migrate-kiro-cli
Draft

35C4n0r wants to merge 1 commit into
mainfrom
35C4n0r/migrate-kiro-cli

Conversation

@35C4n0r

@35C4n0r 35C4n0r commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Refactor harleylrn/kiro-cli to install and configure Kiro CLI only, matching the claude-code, codex, copilot, and cursor-cli (#1152) migrations.

  • Replace the agentapi module with coder-utils; drop Tasks/web-app inputs (order, group, report_tasks, cli_app, web_app_display_name, cli_app_display_name, install_agentapi, agentapi_version, agentapi_chat_based_path, ai_prompt, system_prompt, coder_mcp_instructions), the task_app_id output, the start script, and the task-reporting coder MCP server.
  • Install via the official installer (https://cli.kiro.dev/install, temp file + bash -n validation, retrying curl) for latest. Pinned kiro_cli_version or a custom kiro_install_url downloads <url>/<version>/kirocli-<arch>-linux.zip and runs its install.sh, keeping the existing version-pinning and air-gapped support. Skipped when kiro-cli is already on PATH (and matches a pinned version).
  • workdir is now optional (default null) and is created if missing.
  • Add mcp, merged into user-level ~/.kiro/settings/mcp.json (existing servers win on duplicate names; invalid JSON is backed up to .bak), and api_key (KIRO_API_KEY).
  • Keep agent_config (written to ~/.kiro/agents/<name>.json, sets chat.defaultAgent in cli.json while preserving other keys; name validated as a plain file name) and auth_tarball (KIRO_CLI_AUTH_TARBALL). The tarball is now read from that env var at install time instead of being rendered into the script.
  • Remove trust_all_tools and the default agent template: --trust-all-tools moves to the user's coder_app, and without agent_config Kiro's built-in default agent is used.
  • Add scripts output; rewrite README (v2 warning, launcher example) and tests. Bump to 2.0.0.

Important

Not verified end to end, because every Kiro command beyond settings/--version requires a login (no Kiro account available): that the built-in default agent loads ~/.kiro/settings/mcp.json (the docs say user-level servers apply globally), that kiro-cli mcp add without --force keeps the existing server (the --help text says --force overwrites), and that an extracted auth_tarball authenticates 2.26.0. The README screenshot (.images/kiro-cli.png, likely the AgentAPI web UI) is no longer referenced; the image file itself is left in place.

Decision log

Verified against the installed CLI (kiro-cli 2.26.0) and the Kiro docs:

Skill pattern Kiro CLI reality Decision
Pass VERSION to the official installer Installer only installs <channel>/latest and prompts on /dev/tty if ~/.local/bin/kiro-cli exists; versioned archives exist at prod.download.cli.kiro.dev/stable/<ver>/ (no per-version manifest, so no checksum) Official installer for latest; release archive for pinned versions/mirrors; skip install when already present
Model via documented env var No model env var; chat.defaultModel setting and --model flag No model input (none existed before); document --model
managed_settings root-owned policy Enterprise policy is managed in the Kiro console, not a local file Not added
Native mcp add duplicate semantics kiro-cli mcp add requires login, so it cannot run at install time; --force overwrites jq merge into ~/.kiro/settings/mcp.json, existing wins
Workdir trust key No folder-trust prompt; trust is per tool (--trust-all-tools, --trust-tools) Create workdir only; trust_all_tools becomes a launcher flag
Single token env var KIRO_API_KEY (after browser login in precedence; documented for headless use) Add api_key; keep auth_tarball for interactive sessions
Secrets never in the install script Old module rendered auth_tarball into the script Script reads KIRO_CLI_AUTH_TARBALL from the agent env
system_prompt is a Tasks input Default agent template only existed to carry system_prompt and the @coder task tool Removed; set prompt in agent_config instead
Config dir KIRO_HOME overrides ~/.kiro for agents and settings (verified) Honor KIRO_HOME
Setup step Old module ran install.sh --no-confirm (shell-integration setup); official installer sets KIRO_CLI_SKIP_SETUP=1 Skip setup on both paths
AI Gateway Not present pre-migration Out of scope

Testing

  • terraform validate, terraform test (10 passed)
  • bun test main.test.ts (17 passed, container-based)
  • Real installs in codercom/enterprise-node with the rendered install script: official installer (2.26.0), idempotent re-run, then pinned 2.25.0 archive over it; CODER_SCRIPT_BIN_DIR symlink runs kiro-cli chat --help without ~/.local/bin on PATH
  • shellcheck on the rendered install script, prettier, readmevalidation

Generated with Coder Agents.

…s and start logic

- Replace the agentapi module with coder-utils; drop Tasks/web-app inputs, the start script, and the task-reporting coder MCP server.
- Install via the official installer for latest; pinned versions and mirrors use the release archive.
- Make workdir optional; add mcp (merged into ~/.kiro/settings/mcp.json) and api_key (KIRO_API_KEY).
- Keep agent_config and auth_tarball; the tarball is read from its env var instead of being rendered into the script.
- Add scripts output, rewrite README and tests, bump to 2.0.0.
@github-actions

Copy link
Copy Markdown
Contributor

Module Scorecard Check

harleylrn/kiro-cli: first scorecard, 77 / 100

No specific score is required to contribute, but modules with higher scores are more likely to be approved by the Coder team and widely used.

Full scorecard for this PR
Presentation & Onboarding Agent Integration Credential Hygiene Restricted-Environment Readiness Engineering Quality Overall
12 / 17 10 / 25 20 / 20 18.5 / 20 10 / 10 77 / 100
Drilldown

Presentation & Onboarding — 12 / 17

Criterion Max Score Notes
Configuration-mode examples 12 12 README documents multiple major modes with examples: standalone with launcher app (workdir + auth_tarball), MCP servers + custom agent, pinned version / internal mirror (kiro_cli_version, kiro_install_url), install_kiro_cli = false (BYO binary), and script serialization. The Authentication section covers all three auth paths (tarball, API key, device flow). Sensible defaults are shown throughout.
Visual preview 5 0 No embedded image, GIF, or video in the README. The frontmatter icon field references an SVG file, but this is not a visual preview of the module in action.

Credential Hygiene — 20 / 20

Criterion Max Score Notes
Secrets marked sensitive 16 16 Both auth_tarball and api_key are declared with sensitive = true in main.tf. README examples reference var.kiro_cli_auth_tarball (a variable, not an inline literal). No inline secrets appear in any README example. The install script reads credentials from environment variables (KIRO_CLI_AUTH_TARBALL, KIRO_API_KEY), never from the script body.
Non-hardcoded auth path 4 4 README documents three auth paths that avoid pasting raw keys into templates: (1) auth tarball generated on another machine and passed as a sensitive variable, (2) device flow via kiro-cli login in the workspace terminal, (3) API key as a sensitive variable. The tarball and device-flow paths explicitly avoid raw keys in HCL.

Restricted-Environment Readiness — 18.5 / 20

Criterion Max Score Notes
Mirrorable artifact source 5 5 The kiro_install_url variable (default null) overrides the base URL from which Kiro CLI release archives are downloaded. The README "Pinned version or internal mirror" example shows kiro_install_url = "https://artifacts.internal.corp/kiro-cli-releases". The install script uses ARG_INSTALL_URL to construct the archive download URL, replacing the default https://prod.download.cli.kiro.dev/stable.
Bring-your-own binary 10 10 The install_kiro_cli variable (default true) allows disabling installation entirely. When set to false, the module validates that kiro-cli is already on PATH and skips download. README documents: "If install_kiro_cli = false, a working kiro-cli must already be on PATH, or workspace startup fails." The install script also auto-skips when a matching version is already present.
Egress transparency 3 1.5 No dedicated "Network Endpoints" or "Air-gapped Environments" README section exists. The "Pinned version or internal mirror" section does enumerate the two download endpoints (cli.kiro.dev/install, prod.download.cli.kiro.dev/stable) and describes the mirror layout for restricted environments, but it is framed as a configuration example rather than a dedicated egress-transparency section. Half credit for partial, under-documented coverage.
Runs without sudo 2 2 The install script (scripts/install.sh.tftpl) never invokes sudo. All operations target user-local paths: $HOME/.local/bin, $HOME/.kiro, $HOME/.local/share/kiro-cli, and shell profile files in $HOME. No root privileges are required for any step.

Engineering Quality — 10 / 10

Criterion Max Score Notes
Input quality 6 6 All 12 variables have clear descriptions and sensible defaults. kiro_cli_version has a regex validation (`^(latest
Test coverage 4 4 main.tftest.hcl (10 test runs) covers business logic: defaults, workdir trimming, env-var creation for secrets, validation failures (version, MCP, agent_config), and scripts output ordering. main.test.ts (16 tests) covers end-to-end behavior in containers: install paths (official, pinned, mirror, BYO), version-matching skip, download failure, workdir creation, MCP merge/backup, agent config writing, auth tarball extraction, zstd requirement, secret isolation from scripts, and pre/post-install hooks.

Agent Integration — 10 / 25

Criterion Max Score Notes
AI governance 10 0 No mention of Coder AI Gateway or Agent Firewall anywhere in the README or module code. The module installs and configures Kiro CLI but does not document how Coder governs auth, routing, or policy enforcement for the agent.
Dashboard entry point 5 5 The README "Standalone mode with a launcher app" example includes a complete coder_app resource with slug, display_name, icon, open_in = "slim-window", and a command that launches kiro-cli chat --trust-all-tools.
Session continuity 5 0 The README contains a brief NOTE suggesting tmux for one-shot prompts ("a coder_app that attaches to the existing session (for example, with tmux)"), but the module does not implement, configure, or document a session manager, resume mechanism, or session-ID support. This is a user-side tip, not documented module support.
Managed configuration 5 5 The module documents and implements managed MCP configuration (mcp variable merged into ~/.kiro/settings/mcp.json with existing-server-wins semantics) and managed agent settings (agent_config variable written to ~/.kiro/agents/<name>.json and set as chat.defaultAgent in ~/.kiro/settings/cli.json). Both are covered in the "MCP servers and a custom agent" README example with merge/preservation semantics explained.

Overall — 77 / 100

Raw 70.5 / 92 → round(70.5 / 92 × 100) = 77

Tip

You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".


Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant