Conversation
Capture the patterns-side decision for the neutral hybrid/v1 serviceGateways field and its v1 Compose runtime tradeoffs. Co-authored-by: OpenCode Agent <bret.mogilefsky@gsa.gov>
Add the neutral hybrid/v1 serviceGateways schema and validator checks for kit-local Compose gateways, resolved URL exposure, privileged container rejection, and floating image tag warnings. Co-authored-by: OpenCode Agent <bret.mogilefsky@gsa.gov>
ed41751 to
cfce305
Compare
|
AI-assisted review (OpenCode), advisory — needs a human to confirm before it drives a change. Reviewed at head Reading this as a schema change rather than docs+tests: it widens what a kit is allowed to be, letting a kit start host-side Compose services. The ADR is careful and the test file is genuinely thorough (20 cases including degraded paths). Two gaps in the validator, both about the distance between what the ADR asserts in prose and what the code enforces. 1. def _compose_has_privileged_service(compose_doc: object) -> bool:
"""True when any Compose service declares privileged: true."""
return any(
isinstance(service, dict) and service.get("privileged") is True
for service in _compose_services(compose_doc).values()
)I grepped the whole validator for ADR-0003 states the boundary in prose ("a gateway that needs host-level privileges, broad mounts, or Docker socket access is outside this vocabulary"), while the code enforces one keyword. A validator returning 2. Both layers constrain only the entry files in So the schema's "may reference only Compose files shipped inside the kit" is true of the declared list and false of the resulting configuration. Reject One thing I'd like an answer to rather than a change: the trust escalation is documented but not machine-readable. This vocabulary lets a fetched kit start host-side containers, and the control is a sentence — "Remote service-gateway kits must come from trusted kit sources" — with no schema field, no validator check, and nothing telling Also noting, not as a finding: floating image tags are a warning, not an error ( Method: static analysis at head |
|
AI-assisted adversarial review (nexus-agents 1. No schema change in the diff, despite this being described as a schema-level vocabulary (all 5 voters, blocking). The diff touches only 2. Critical: the stated security boundary is documented, not enforced (catfish, severity: critical; confirmed independently by all 5 voters with concrete fixtures). The ADR's premise is that the gateway — not the agent — is the credential/policy enforcement boundary, running outside the agent's reach. The only container-hardening check is
catfish: "checking 3. Path containment is bypassable via Compose's own 4. 5. Host-published ports are accepted as valid endpoint sources (Security, catfish, Scope Steward). 6. ~140 lines of new security-relevant parsing ship with zero tests/fixtures (all 5 voters). No kit in the tree declares 7. ADR numbering collision, confirmed by all 5 voters as requested. Minor/non-blocking, several voters: the closing paren in the The vocabulary concept itself isn't in question (Scope Steward explicitly separated "is this schema idea worth having" — yes — from "is this specific implementation's enforcement real" — no). Given items 2–5 involve genuine container-escape surface in infrastructure every future kit would inherit, I'd treat this one as higher-priority to resolve than a typical implementation-detail review. |
`integrations/isolation/docs/decisions/0003-` was claimed by two open PRs: #416 (serviceGateways vocabulary, opened 2026-09-15) and this one (opened 2026-09-18). The filenames differ, so git merges both cleanly and leaves two ADR-0003s in the same directory — every later "ADR 0003 (isolation)" reference becomes ambiguous. #416 claimed it first and its number is not cited anywhere else, so this PR moves. 0004 is free: `main` has 0001 and 0002, and no other open PR claims it. Only the file name and the H1 change. The "usai-provider ADR 0003" reference at line 353 is a DIFFERENT, kit-local ADR under acq-kits/usai-provider/docs/decisions/ and is deliberately left alone. AI-assisted (OpenCode). Human review and merge still required.
#423's ADR moved from `0003-neutral-model-provider-discovery.md` to `0004-` to clear a collision with #416, which claimed `integrations/isolation/docs/ decisions/0003-` first. Update the two comment references here so they do not dangle once that lands. Comment-only; no behavior change. `node --check` and a YAML parse both pass. AI-assisted (OpenCode). Human review and merge still required.
|
Heads-up, no action needed from you: we've moved out of your way on the ADR number.
You claimed it first and your number isn't cited anywhere outside this PR, so #423 is now ADR 0004 ( Worth noting there's a similar pair still open in quickstart: #507 and #504 both add an My earlier review findings on this PR (the validator's |
Summary
Add the patterns-side neutral hybrid/v1
serviceGatewayskit vocabulary for kit-declared,acq-managed service gateways.This PR includes:
serviceGateways[], v1 kit-local Compose runtime files, requiredruntime.compose.service, sandbox/agent exposure throughexpose.env, and optionalinterface.portonly when inferable from the named Compose service.expose.envvalues mapped tourl.Tracking: GSA-TTS/agentic-coding-quickstart#472
ADR
The ADR is
integrations/isolation/docs/decisions/0003-service-gateways-vocabulary.md.It captures the core decisions:
serviceGateways.runtime.compose.serviceto identify the gateway service in multi-service Compose files.expose.env.Verification
Commands run:
PATH="$PWD/.venv/bin:$PATH" make validate-kitsResult: passed. All 7 acq-kits valid.
Result: passed. 94 tests passed.
Result: passed.
PATH="$PWD/.venv/bin:$PATH" make validateResult: passed. Existing advisory warnings were reported for documented PII/CUI terms and network-tier deep-subdomain review signals.
PATH="$PWD/.venv/bin:$PATH" make generate-checkResult: passed.
INDEX.yamlandCATALOG.mdare up to date.Result: passed. 422 tests passed.
Result: passed.
AI Assistance
This PR was prepared with AI assistance from OpenCode Agent. A human reviewer remains responsible for review and merge.