Skip to content

agents: add config generate to author manifests locally - #1944

Closed
Spherrrical wants to merge 1 commit into
digitalocean:feat/agents-subcommandsfrom
Spherrrical:musa/505a7a84
Closed

Spherrrical wants to merge 1 commit into
digitalocean:feat/agents-subcommandsfrom
Spherrrical:musa/505a7a84

Conversation

@Spherrrical

Copy link
Copy Markdown
Contributor

Summary

Writing an agent manifest by hand meant knowing the flat schema and which env vars wire up inference before you could start a single session. This adds doctl harness-runtime config generate, which authors one locally and makes no API call:

  • Flags for agents and CI, a wizard for people. Every wizard question maps to a flag, so an interactive run is reproducible as a single non-interactive command. --no-interactive (and any non-TTY) answers each question with its default.
  • Inference is the part that's hard to guess, so the wizard asks the one question that decides it — DigitalOcean Serverless Inference (recommended), the agent's own vendor, or another OpenAI-compatible endpoint — and derives the env, secret slots, and egress from the answer. The DO model catalog is pulled live rather than shipped as a list that goes stale, filtered to chat-capable models with a free-text escape hatch.
  • Secrets are declared, not embedded. --secret NAME writes a ${NAME} placeholder; --inline-secret NAME=VALUE is the explicit opt-in to a literal value.
  • The manifest is syntax-highlighted when stdout is a terminal and byte-identical when piped or redirected, so it stays copy-pasteable.

Also fixes three defects found while reviewing the surrounding commands:

  • config create appended warning prose to its own JSON document, leaving -o json unparseable exactly when the API had something to say. Warnings now ride in the payload's warnings field, and print to stderr in text mode.
  • Trigger --bound-session-id passed its value through verbatim, so a session name reached the API as a bogus ID — and list-reusable-sessions prints names next to IDs, so the name is what gets copied. It now resolves names like every other session-taking command, on both create and update.
  • trigger update --output-email on its own exited 0 having changed nothing, since the output block was only patched when --output-mode was also set. It now names the missing flag.

cursor is also restored to the known-adapter list, which had drifted from the canonical contract.

Test plan

  • go test ./commands/... passes (TestRegistryLogin/TestRegistryLogout fail identically on a clean tree in this environment; they need a Docker config)
  • go vet ./commands/ clean, gofmt clean
  • Golden tests for flag-only generation, inference wiring per provider, and validateAgentManifest round-trips on the generated output
  • Highlighting tests assert byte-exactness when unstyled and ANSI-only additions when styled
  • Regression tests for each of the three fixes above
  • Wizard driven end-to-end under a pty via expect
  • Reviewer sanity check: doctl harness-runtime config generate in a git repo, then config create --spec the result

Writing an agent manifest by hand meant knowing the flat schema and which
env vars wire up inference before you could start a single session. This
adds `harness-runtime config generate`, which authors one locally without
calling the API: flags for agents and CI, and a wizard for people, where
every question maps to a flag so an interactive run is reproducible as a
one-liner.

Inference is the part that is hard to guess, so the wizard asks the one
question that decides it — DigitalOcean Serverless Inference, the agent's
own vendor, or another OpenAI-compatible endpoint — and derives the env,
secret slots, and egress from the answer, pulling the DO model catalog
live rather than shipping a list that goes stale.

Also fixes three defects found while reviewing the surrounding commands:

  - `config create` appended warning prose to its own JSON document,
    leaving `-o json` unparseable exactly when the API had something to
    say. Warnings now ride in the payload's `warnings` field, and print
    to stderr in text mode.
  - Trigger `--bound-session-id` passed its value through verbatim, so a
    session name reached the API as a bogus ID. It now resolves names
    like every other session-taking command, on create and update.
  - `trigger update --output-email` alone exited 0 having changed
    nothing, since the output block was only patched when
    `--output-mode` was also set. It now says which flag is missing.
@gitguardian

gitguardian Bot commented Sep 2, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 2 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
- - Generic CLI Secret bf6b278 commands/agent_config_generate.go View secret
- - Generic CLI Secret bf6b278 commands/agents_help.go View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@SSharma-10
SSharma-10 deleted the branch digitalocean:feat/agents-subcommands September 22, 2026 03:54
@SSharma-10 SSharma-10 closed this Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants