You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Fleet page polish + click-to-filter. The /agents page leads with
summary tiles (agents, shadow, unreachable, unowned, runtimes) that are
clickable to filter the table; the "Needs attention" panel is collapsible and
each entity-backed finding filters the fleet to exactly the affected agents;
probe-discovered "shadow" agents get a ghost mark and a subtle row tint; and
the column chooser is now a clearly-labelled Columns menu. All current-state
and read-only — filtering the live view, not saved views or dashboards.
Audit sweep — find agents nobody registered (ADR 0007). A new SweepDiscoveryProvider lists every Service on a cluster, skips the ones
that are already someone else's job (labeled agentcatalog.io/a2a=true →
Tier A; owned by a runtime CR; suppressed a2a=false), and probes the rest
for a live A2A card — GET-only, well-known paths, each Service's declared
ports (capped), through the kube-apiserver proxy. A card-serving Service is
cataloged with agentcatalog.io/discovery: probe (and a shadow tag); an
unlabeled Service with no card is ignored, not flagged. Off by default
(agentCatalog.sweep.enabled) — it is a port-probing workload, so tell your
security team before enabling; there is no default schedule (one supervised
run on enable, recurring only via sweep.scheduleMinutes). Its own locationKey, so it never clobbers labeled discovery. Doubles as a Tier B
scout: agents on runtimes with no CRD provider yet still show up if they
serve a card.
Fleet health summary — "Needs attention". The /agents page now leads
with a prioritized, severity-ranked list of findings an owner can act on,
derived entirely from signals already collected: unreachable agents (their
card couldn't be fetched), stale entries from a currently-unobservable source,
interface drift, unowned agents, heuristic "unverified LLM workloads",
deployed-but-idle agents, and gateway consumers matching no catalog entity.
Purely derived — no new collectors or stored state — and shows an explicit
"nothing needs attention" state when the fleet is clean.
Security
Dependency advisory. Pinned prismjs to ^1.30.0 via a workspace
resolution to clear GHSA-x7hr-w5r2-h6wg (DOM clobbering) in the transitive
dev/build tree (pulled in as ~1.27.0 via refractor); a
backward-compatible minor bump. The resolution affects this repo's install
tree only — it is not part of the published packages, so consumers are
unaffected either way.