agents: add config generate to author manifests locally - #1944
Spherrrical wants to merge 1 commit into
Conversation
Writing an agent manifest by hand meant knowing the flat schema and which
env vars wire up inference before you could start a single session. This
adds `harness-runtime config generate`, which authors one locally without
calling the API: flags for agents and CI, and a wizard for people, where
every question maps to a flag so an interactive run is reproducible as a
one-liner.
Inference is the part that is hard to guess, so the wizard asks the one
question that decides it — DigitalOcean Serverless Inference, the agent's
own vendor, or another OpenAI-compatible endpoint — and derives the env,
secret slots, and egress from the answer, pulling the DO model catalog
live rather than shipping a list that goes stale.
Also fixes three defects found while reviewing the surrounding commands:
- `config create` appended warning prose to its own JSON document,
leaving `-o json` unparseable exactly when the API had something to
say. Warnings now ride in the payload's `warnings` field, and print
to stderr in text mode.
- Trigger `--bound-session-id` passed its value through verbatim, so a
session name reached the API as a bogus ID. It now resolves names
like every other session-taking command, on create and update.
- `trigger update --output-email` alone exited 0 having changed
nothing, since the output block was only patched when
`--output-mode` was also set. It now says which flag is missing.
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| - | - | Generic CLI Secret | bf6b278 | commands/agent_config_generate.go | View secret |
| - | - | Generic CLI Secret | bf6b278 | commands/agents_help.go | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Summary
Writing an agent manifest by hand meant knowing the flat schema and which env vars wire up inference before you could start a single session. This adds
doctl harness-runtime config generate, which authors one locally and makes no API call:--no-interactive(and any non-TTY) answers each question with its default.env, secret slots, andegressfrom the answer. The DO model catalog is pulled live rather than shipped as a list that goes stale, filtered to chat-capable models with a free-text escape hatch.--secret NAMEwrites a${NAME}placeholder;--inline-secret NAME=VALUEis the explicit opt-in to a literal value.Also fixes three defects found while reviewing the surrounding commands:
config createappended warning prose to its own JSON document, leaving-o jsonunparseable exactly when the API had something to say. Warnings now ride in the payload'swarningsfield, and print to stderr in text mode.--bound-session-idpassed its value through verbatim, so a session name reached the API as a bogus ID — andlist-reusable-sessionsprints names next to IDs, so the name is what gets copied. It now resolves names like every other session-taking command, on both create and update.trigger update --output-emailon its own exited 0 having changed nothing, since the output block was only patched when--output-modewas also set. It now names the missing flag.cursoris also restored to the known-adapter list, which had drifted from the canonical contract.Test plan
go test ./commands/...passes (TestRegistryLogin/TestRegistryLogoutfail identically on a clean tree in this environment; they need a Docker config)go vet ./commands/clean,gofmtcleanvalidateAgentManifestround-trips on the generated outputexpectdoctl harness-runtime config generatein a git repo, thenconfig create --specthe result