Skip to content

fix(cli): normalize chart-owned agent identity env - #537

Closed
Abdou-Scale wants to merge 2 commits into
scaleapi:nextfrom
Abdou-Scale:fix/alg-1134-agentex-chart-version
Closed

Abdou-Scale wants to merge 2 commits into
scaleapi:nextfrom
Abdou-Scale:fix/alg-1134-agentex-chart-version

Conversation

@Abdou-Scale

@Abdou-Scale Abdou-Scale commented Sep 30, 2026 •

Copy link
Copy Markdown

Summary

  • promote legacy AGENT_NAME, WORKFLOW_NAME, and WORKFLOW_TASK_QUEUE custom env values into the Helm chart globals that own those variables
  • preserve precedence: environment env overrides environment globals, while explicit environment globals override legacy manifest env
  • remove promoted keys from API and Temporal worker custom env output so Helm never renders duplicate identity entries
  • reject identity values supplied through credentials or container-specific override paths with an actionable deployment error
  • validate null/scalar global.agent, global.workflow, and temporal-worker overrides before rendering

Root cause

agentex agents deploy could emit the same identity variable twice: once from chart globals and once from manifest/environment custom env. Kubernetes strategic-merge patching then rejected upgrades with a $setElementOrder mismatch, leaving the Reporter rollout unhealthy.

Validation

  • ruff check src/agentex/lib/cli/handlers/deploy_handlers.py tests/lib/cli/test_deploy_handlers.py
  • pytest -o addopts='' -q tests/lib/cli — 88 passed
  • the exact legacy Reporter staging configuration from before the incident normalizes to the expected staging globals with zero identity keys in API or worker custom env
  • live staging release remains healthy: API 2/2, worker 1/1, all pods ready with zero restarts
  • both Greptile findings were validated, fixed in 8afe816, replied to, and resolved

Tracking

  • Linear: ALG-1134
  • Reporter configuration/audit PR: scaleapi/ips-applications#9946

This targets next, per this repository’s development flow. The Reporter application PR remains the immediate repair; this change prevents recurrence after the updated AgentEx SDK/CLI is released and consumed by deployment automation.

RetriggerConfidence Score: 5/5

The PR appears safe to merge; both earlier findings are addressed.

What we checked:

  • Environment identity replaced: No. An environment global wins over a manifest-only value. An environment env value has higher priority.
  • Null identity crashes deploy: No. The handler raises DeploymentError when either identity group is present but is not a mapping.

Summary

The deploy command now moves AGENT_NAME, WORKFLOW_NAME, and WORKFLOW_TASK_QUEUE into their chart globals and removes them from custom environment lists. It also rejects unsupported identity overrides with guidance on where to set them.

  • Environment identity values can override manifest values, while explicit chart values remain when no environment value is provided.
  • Deploy checks identity secrets, container-specific environment entries, and malformed chart override groups.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  M[Manifest env] --> P[Choose identity value]
  E[Environment env] --> P
  G[Environment global] --> P
  P --> H[Helm global identity]
  P --> R[Remove identity from custom env]
Loading

Reviews (2) · Last reviewed commit: "fix(cli): preserve environment identity ..."

Comment thread src/agentex/lib/cli/handlers/deploy_handlers.py Outdated
Comment thread src/agentex/lib/cli/handlers/deploy_handlers.py Outdated
@Abdou-Scale

Copy link
Copy Markdown
Author

Closing because this fix must remain scoped to ips-applications or gps-platform. The implementation will be moved to an approved repository.

@Abdou-Scale
Abdou-Scale deleted the fix/alg-1134-agentex-chart-version branch September 30, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant