Skip to content

docs: sync schemas and specs with source changes#6214

Merged
lpcox merged 3 commits into
mainfrom
docs/schema-sync-2026-07-14-aedff7def8f81df4
Jul 15, 2026
Merged

docs: sync schemas and specs with source changes#6214
lpcox merged 3 commits into
mainfrom
docs/schema-sync-2026-07-14-aedff7def8f81df4

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Summary

Updates docs/awf-config-spec.md to reflect changes from commit 18817f9 (feat: rename --security-mode to --legacy-security, deprecate --enable-api-proxy).

Changes

  • Added security.legacySecurity--legacy-security CLI mapping
  • Added security.securityMode--security-mode as deprecated (backward compat)
  • Marked apiProxy.enabled--enable-api-proxy as deprecated (API proxy is always enabled)

Note: docs/awf-config.schema.json was already updated in the source commit itself.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Generated by Schema & Spec Sync · 34.8 AIC · ⌖ 6.87 AIC · ⊞ 5.7K ·

- Add security.legacySecurity → --legacy-security CLI mapping
- Add security.securityMode → --security-mode as deprecated
- Mark apiProxy.enabled → --enable-api-proxy as deprecated

Triggered by commit 18817f9 (feat: rename --security-mode to --legacy-security, deprecate --enable-api-proxy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@lpcox
lpcox marked this pull request as ready for review July 14, 2026 23:40
Copilot AI review requested due to automatic review settings July 14, 2026 23:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the AWF configuration specification for renamed and deprecated security options.

Changes:

  • Documents security.legacySecurity.
  • Marks legacy security mode and API proxy flags deprecated.
  • Notes that the API proxy is always enabled.
Show a summary per file
File Description
docs/awf-config-spec.md Updates config-to-CLI mappings and deprecation notes.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Medium

Comment thread docs/awf-config-spec.md
- `network.isolation` → `--network-isolation` *(experimental; enforces egress via Docker network topology instead of host iptables)*
- `network.topologyAttach[]` → `--topology-attach <name>` *(repeatable; requires `network.isolation: true`)*
- `apiProxy.enabled` → `--enable-api-proxy`
- `apiProxy.enabled` → `--enable-api-proxy` *([DEPRECATED] API proxy is always enabled; this flag is ignored)*
@lpcox

lpcox commented Jul 15, 2026

Copy link
Copy Markdown
Collaborator

@copilot address review feedback

Copilot AI commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

@copilot address review feedback

Done in commit docs: mark apiProxy.enabled deprecated in schema and spec. Changes made:

  • docs/awf-config.schema.json: apiProxy.enabled now carries "deprecated": true and a description stating it is ignored; the environment and excludeEnv descriptions no longer reference apiProxy.enabled as a conditional switch.
  • docs/awf-config-spec.md §9.3: Replaced the "API Proxy Disabled" section with a deprecation note explaining the property is silently ignored, --enable-api-proxy is ignored, and --no-enable-api-proxy is rejected at runtime.
  • docs/awf-config-spec.md §9.4: "Credential Exclusion Requires API Proxy" rewritten as "Credential Exclusion" — removed the two-path conditional (enabled vs non-proxy mode) and replaced with a single normative statement that the sidecar always handles exclusion.

Copilot finished work on behalf of lpcox July 15, 2026 00:48
Copilot AI requested a review from lpcox July 15, 2026 00:48
@github-actions

Copy link
Copy Markdown
Contributor Author

✅ Copilot review passed with no inline comments.

@github-actions[bot] Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Documentation Preview

Documentation build failed for this PR. View logs.

Built from commit 9d25da1

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

🔑 Smoke Copilot PAT PAT auth validated. All systems operational. ✅

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Contribution Check completed successfully!

PR #6214 follows the applicable CONTRIBUTING.md guidelines: it is a documentation-only schema/spec sync, so no new functionality or tests are required; documentation and file placement are appropriate, and the PR description clearly explains the changes and references the source commit.

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

🔌 Smoke Services — All services reachable! ✅

@github-actions

Copy link
Copy Markdown
Contributor Author

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Build Test Suite completed successfully!

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

🦎🔮 Smoke gVisor Codex reports failed. gVisor + Codex compatibility issue detected.

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Copilot BYOK (Direct)

Test Result
GitHub.com connectivity
File write/read
BYOK inference (api-proxy → api.githubcopilot.com)
GitHub MCP connectivity

Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com

Overall: PASS 🟢 — @lpcox

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Claude Engine Validation

Check Result
API status ✅ PASS
gh check ✅ PASS
File status ✅ PASS

Overall result: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Generated by Smoke Claude for #6214 · 56.1 AIC · ⊞ 3.3K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: PAT Auth Validation

Test Result
GitHub MCP connectivity ✅ (tool available)
GitHub.com HTTP ⚠️ pre-step data not injected
File write/read ⚠️ pre-step data not injected

Auth mode: PAT (COPILOT_GITHUB_TOKEN)

⚠️ Template variables were not substituted — pre-computed results unavailable. Workflow configuration issue.

Overall: INCONCLUSIVE

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

🔑 PAT report filed by Smoke Copilot PAT
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

🔬 Smoke Test Results

Test Result
GitHub MCP ✅ Connected
GitHub.com HTTP ⚠️ Pre-step data unavailable
File Write/Read ⚠️ Pre-step data unavailable

⚠️ Template variables (${{ steps.smoke-data.outputs.* }}) were not expanded — workflow pre-step likely failed.

Overall: PARTIAL PASS (engine connectivity verified, pre-step data missing)

PR Author: @lpcox

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Services Connectivity

  • Redis PING: ❌ Network unreachable
  • PostgreSQL pg_isready: ❌ No response
  • PostgreSQL SELECT 1: ❌ Network unreachable

Result: FAILhost.docker.internal (172.17.0.1) is unreachable. Service containers may not be running or host networking is not bridged.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: API Proxy OpenTelemetry Tracing

Scenario Result Notes
1. Module Loading ✅ Pass otel.js loads successfully; exports: startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled + internal symbols
2. Test Suite ✅ Pass 39/39 tests pass in otel.test.js (ProxyAwareOtlpExporter, FileSpanExporter, shutdown)
3. Env Var Forwarding ✅ Pass OTEL_* vars forwarded via agent-environment-credentials (tests at line 260 of src/services/agent-environment-credentials.test.ts)
4. Token Tracker Integration ✅ Pass onUsage callback present in token-tracker-http.js; setTokenAttributes sets gen_ai.usage.input_tokens/output_tokens per GenAI semantic conventions
5. OTEL Diagnostics i️ N/A No live container run; span export path verified via code (ProxyAwareOtlpExporter routes through Squid proxy)

All scenarios pass. OTEL tracing integration is correctly implemented.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Chroot Version Comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.13 Python 3.12.3 ❌ NO
Node.js v24.18.0 v22.23.1 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Not all runtimes match between host and chroot environment.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

🔬 Smoke Test: Docker Sbx — Results

Test Result
GitHub MCP Connectivity ✅ PASS (MCP reachable)
GitHub.com HTTP ⚠️ N/A (pre-step data not interpolated)
File Write/Read ⚠️ N/A (pre-step data not interpolated)

Pre-computed step outputs (${{ steps.smoke-data.outputs.* }}) were not interpolated — raw expressions passed to agent. Core MCP connectivity verified.

Overall: PARTIAL — infrastructure reachable, pre-step data unavailable.

📰 BREAKING: Report filed by Smoke Docker Sbx
Add label ready-for-aw to run again

@lpcox

lpcox commented Jul 15, 2026

Copy link
Copy Markdown
Collaborator

@copilot merge main

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Gemini Engine Validation

Overall status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

💎 Faceted by Smoke Gemini
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

🐳🔮 Docker sbx + Codex

  • GitHub MCP: ✅
  • github.com: ✅ (200)
  • smoke file: ✅
  • example.com blocked: ❌ (200)
  • Overall: FAIL

🐳🔮 Docker sbx + Codex smoke test by Smoke Docker Sbx Codex
Add label test-docker-sbx-codex to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

🐳🏗️ Docker Sbx Build Test Results

Test Status
GitHub.com connectivity
Node.js build (npm ci && npm run build)
Node.js tests (Jest subset)
Go build (color, uuid)
Go tests (color, uuid)
Network isolation

Overall: FAIL

🐳🏗️ Docker sbx build test by Smoke Docker Sbx Build Test
Add label test-docker-sbx-build to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

🐳🟣 Docker sbx + Claude

  • ✅ GitHub MCP connectivity (list PRs)
  • ✅ github.com connectivity (HTTP 200)
  • ✅ File write/read
  • ❌ Network isolation — example.com returned HTTP 200 (expected block/timeout)

Overall: FAIL

🐳🟣 Docker sbx + Claude smoke test by Smoke Docker Sbx Claude
Add label test-docker-sbx-claude to run again

Copilot AI commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

@copilot merge main

Done — merged origin/main (tip 5eeaf428) into this branch at f162ce40. No conflicts.

Copilot finished work on behalf of lpcox July 15, 2026 14:31
@github-actions

Copy link
Copy Markdown
Contributor Author

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Generated by Build Test Suite for #6214 · 143 AIC · ⊞ 6.9K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Merged PRs: fix: exclude GITHUB_TOKEN from agent container when API proxy is enabled | fix: update CI workflow tests for new compiler action path format
Queried PRs: chore: update model-to-API mapping (2026-07-15) | chore: bump typescript-eslint packages to 8.64.0
GitHub title: ✅
File write: ✅
Discussion comment: ✅
Build: ❌
Overall status: FAIL

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • awmgmcpg
  • registry.npmjs.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"
    - "registry.npmjs.org"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@lpcox
lpcox merged commit dc9e5eb into main Jul 15, 2026
24 of 25 checks passed
@lpcox
lpcox deleted the docs/schema-sync-2026-07-14-aedff7def8f81df4 branch July 15, 2026 14:51
github-actions Bot added a commit that referenced this pull request Jul 15, 2026
PR #6214 updated docs/awf-config.schema.json to mark apiProxy.enabled as
deprecated and update environment descriptions, but did not apply the same
changes to src/awf-config-schema.json, causing schema drift.

This commit copies the docs schema to src to restore identical copies.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants