Skip to content

feat(mcp): add governed managed service lifecycle and runtime bridges - #552

Draft
Pal Lakatos-Toth (pallakatos) wants to merge 10 commits into
public/pr7-governed-servicesfrom
public/pr9-managed-mcp
Draft

feat(mcp): add governed managed service lifecycle and runtime bridges#552
Pal Lakatos-Toth (pallakatos) wants to merge 10 commits into
public/pr7-governed-servicesfrom
public/pr9-managed-mcp

Conversation

@pallakatos

@pallakatos Pal Lakatos-Toth (pallakatos) commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

Current shared dependency and prerequisite refresh

Current head: cb3a24ff71d1719ef35316614c49179577ba085a. Forwarded the same reviewed SRE retirement/preflight updates and verified js-yaml 4.3.2 lock repair; no independent dependency re-resolution or gate waiver. The original runtime audit failure is addressed by the patched dependency, with fresh exact-head hosted qualification required.

The SRE prerequisite still needs the resource-specific built-in-controller/private-ReplicaSet admission correction and complete migration acceptance. This PR remains draft and must not bypass that dependency or merge into an intermediate feature branch. Historical head references below are retained as evidence, not current readiness claims. No main/customer deployment or private Bridge publication is performed.


Publication position

This is the already-planned managed-MCP slice, now composed on #550. #551 must land before #550; this slice follows both. Do not merge into the intermediate feature base. Retarget to kars-bridge only after its predecessor lands and require fresh exact-head qualification. Standalone Kars remains independent of Bridge; the Bridge application remains private.

Complete bounded scope

  • UID/CAS-owned managed resources, exact namespace ownership and non-destructive foreign-resource rejection.
  • Current image/generation-bound protocol readiness, scoped catalogs/invocation and real AGT enforcement.
  • Actual loopback socket authentication for the unauthenticated lane; remote OAuth preserves verified caller identity without borrowing managed Sandbox sessions.
  • Bounded discovery/session/response handling, cleanup and no replay of accepted failures.
  • Both OpenClaw and Hermes runtime bridges, optional managed image build/application support, and real Kind lifecycle cases.
  • Composed SRE privacy, rollout annotations and image-apply preflight retained; no new fake attestation, skill-package or memory acquisition claim.

Evidence and remaining gates

Current head 21a6399055f22987c8f9a665e39ad017dc49d2d8 includes prerequisite 068ae160. Bounded independent automated review closed the identified guard-type and socket-identity findings. Composed local qualification passed 315 selected Rust unit cases, 17 HTTP cases, strict paired Clippy, full OpenClaw/CLI type checking, five runtime HTTP cases and 53 CLI image/application cases. Existing LOC, no-stub and crypto gates pass without waivers. Cached dependencies were used only after missing-runner failures; no dependency-cache symlinks are committed.

Draft: full hosted CI, actual SRE/MCP lifecycle acceptance and genuine human capability-audit signatures remain required. Local source/HTTP evidence is not full migration qualification or human approval. Earlier author waivers for #547#549 do not apply here. No merge to main, customer/H100 deployment, release/image publication or private Bridge source exposure is performed.

Capability audit: docs/security-audits/2026-09-08-managed-mcp.md.

Implement UID-owned managed lifecycle, current protocol readiness, scoped catalogs/invocation, actual socket caller boundaries, runtime bridges and additive image lifecycle. Bounded source review and local Rust/HTTP/runtime qualification are complete; composition and real Kind acceptance remain mandatory before readiness. This local checkpoint does not publish images or change customers.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve both rollout identities, SRE mutation preflight and fatal migration sequencing. Composed local controller/router, HTTP and CLI qualification passed; complete hosted lifecycle and genuine audit sign-offs remain required before landing.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
  • ⚠️ 16 packages with OpenSSF Scorecard issues.

View full job summary

Comment thread sandbox-images/mcp-everything/package-lock.json Fixed
Comment thread sandbox-images/mcp-everything/package-lock.json Fixed
Comment thread sandbox-images/mcp-everything/package-lock.json Fixed
Comment thread sandbox-images/mcp-everything/package-lock.json Fixed
Comment thread sandbox-images/mcp-everything/package-lock.json Fixed
Comment on lines +605 to +613
"node_modules/hono": {
"version": "4.12.29",
"resolved": "https://registry.npmjs.org/hono/-/hono-4.12.29.tgz",
"integrity": "sha512-1hNiRjawYrLq/4m3DQQjPGFg0VZkk4RjQJDff/excI6Dm9BiL75qxGrd7/c6YOxPdq6AscP3LiXhQ6fKFC1Waw==",
"license": "MIT",
"engines": {
"node": ">=16.9.0"
}
},
Comment on lines +605 to +613
"node_modules/hono": {
"version": "4.12.29",
"resolved": "https://registry.npmjs.org/hono/-/hono-4.12.29.tgz",
"integrity": "sha512-1hNiRjawYrLq/4m3DQQjPGFg0VZkk4RjQJDff/excI6Dm9BiL75qxGrd7/c6YOxPdq6AscP3LiXhQ6fKFC1Waw==",
"license": "MIT",
"engines": {
"node": ">=16.9.0"
}
},
Comment on lines +14 to +25
"node_modules/@hono/node-server": {
"version": "1.19.14",
"resolved": "https://registry.npmjs.org/@hono/node-server/-/node-server-1.19.14.tgz",
"integrity": "sha512-GwtvgtXxnWsucXvbQXkRgqksiH2Qed37H9xHZocE5sA3N8O8O8/8FA3uclQXxXVzc9XBZuEOMK7+r02FmSpHtw==",
"license": "MIT",
"engines": {
"node": ">=18.14.1"
},
"peerDependencies": {
"hono": "^4"
}
},
Comment on lines +605 to +613
"node_modules/hono": {
"version": "4.12.29",
"resolved": "https://registry.npmjs.org/hono/-/hono-4.12.29.tgz",
"integrity": "sha512-1hNiRjawYrLq/4m3DQQjPGFg0VZkk4RjQJDff/excI6Dm9BiL75qxGrd7/c6YOxPdq6AscP3LiXhQ6fKFC1Waw==",
"license": "MIT",
"engines": {
"node": ">=16.9.0"
}
},
Comment on lines +914 to +929
"node_modules/qs": {
"version": "6.15.3",
"resolved": "https://registry.npmjs.org/qs/-/qs-6.15.3.tgz",
"integrity": "sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==",
"license": "BSD-3-Clause",
"dependencies": {
"es-define-property": "^1.0.1",
"side-channel": "^1.1.1"
},
"engines": {
"node": ">=0.6"
},
"funding": {
"url": "https://github.com/sponsors/ljharb"
}
},
Pin fast-uri 3.1.6 to cover the six blocking advisory ranges. The local verified cache lacks this patch and registry access is unavailable; generate only the lockfile on a read-only hosted runner with scripts disabled, upload for review, and keep normal security gates unchanged. This temporary preparation job is not application qualification or a release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Apply the exact npm-generated hosted artifact; only fast-uri changes from 3.1.3 to 3.1.6, with matching registry integrity. No other package metadata changes. Remove the temporary lock-preparation workflow and retain every normal dependency/security gate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ependency

Extract MCP binding resolution/rollout annotation logic under the existing reconciler cap without a waiver, retain both SRE/MCP authority paths, and fix Hermes formatting. Paired Rust/Clippy and affected CLI/Python cases pass. Pin the remaining reported ip-address fix and audit the complete generated hosted lock before reviewing it; no vulnerability or approval gate is bypassed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Only ip-address changes to the patched 10.3.1 release; the applied lock is byte-identical to the npm-generated artifact, whose full blocking bulk audit passed. Keep fast-uri pinned to its patched release and remove temporary lock generation. All normal security and dependency review remains enabled.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward the same reviewed retirement preflight and verified js-yaml patch locks from governed services. Preserve managed-MCP source, patched image dependencies and all admission gates. Full composed hosted acceptance remains required; no deployment or merge to main.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The full hosted drift gate found one mismatch: Kubernetes CRD generation removes the boolean additionalProperties:false keyword. Match that generated managed-object schema while retaining the required closed preset enum, nullability and all CEL constraints. The rendered changed block matches the actual hosted canonical Rust output.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Retain resource-specific controller authorization and all tenant/private-workload checks. Full composed migration and managed-MCP acceptance remain required.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…cies

Use reqwest's always-available chunk reader rather than bytes_stream, which the controller-only benchmark build does not enable. Preserve every response-size check, transport failure and JSON/SSE invariant without adding dependency features. Isolated controller check, probe/schema cases and paired strict Clippy pass.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants