Skip to content

refactor: hard cut Team and Worker CR contracts#1072

Merged
shiyiyue1102 merged 14 commits into
mainfrom
codex/hard-cut-team-worker-cr
Jul 25, 2026
Merged

refactor: hard cut Team and Worker CR contracts#1072
shiyiyue1102 merged 14 commits into
mainfrom
codex/hard-cut-team-worker-cr

Conversation

@shiyiyue1102

Copy link
Copy Markdown
Collaborator

What changed

  • Make Worker CRs the sole owners of runtime configuration, identity, resources, skills, MCP/package settings, channel policy, and lifecycle.
  • Make Team CRs reference existing Workers through spec.workerMembers, with exactly one team_leader.
  • Remove inline Team member specs, registry migration/write-back, legacy annotations, Team-owned Worker runtime reconciliation, and compatibility fallbacks.
  • Update the REST API, agt CLI, authorization, Manager skills/scripts, installers, documentation, Helm CRDs, and integration tests to use the terminal CR model.
  • Preserve Worker CRs when a Team is deleted and block Worker deletion while it is referenced by a Team.

Why

The Team and Worker CRDs are new contracts and do not need migration compatibility. Keeping inline members, registry files, annotations, and CR-backed state in parallel created multiple sources of truth and made ownership ambiguous.

This change hard-cuts the repository to one end-to-end model: Worker owns runtime state; Team owns membership and coordination.

Impact

  • Existing callers must create or update Worker CRs before referencing them from a Team.
  • Old spec.leader, spec.workers, registry files, Team/role annotations, and CLI compatibility flags are no longer accepted.
  • Deleting a Team no longer cascades into deleting its Worker resources.

Validation

  • GOCACHE=/tmp/agentteams-hard-cut-go-cache go test ./...
  • go build ./...
  • Full controller integration suite and focused TestTeam integration tests
  • Shell syntax checks for all changed .sh files
  • PowerShell installer parser validation
  • Controller/Helm Team CRD byte-for-byte comparison
  • git diff --check
  • Targeted scan for removed compatibility identifiers

Change-Id: I656dbec78c738857734391ee43f28e65f617b16e
Change-Id: I236bc6d34682c5e45697e02f1339ed72dcb7e957
@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

❌ Integration Tests Failed (controller-cr / mgr=copaw / wk=hermes)

Commit: 21dadc7
Workflow run: #1722

Test Results
No test output captured.
Debug Log (tail)
No debug logs available.

📦 Download full debug logs & test artifacts

@github-actions

Copy link
Copy Markdown
Contributor

❌ Integration Tests Failed (controller-cr / mgr=copaw / wk=copaw)

Commit: 78266a1
Workflow run: #1714

Test Results
No test output captured.
Debug Log (tail)
No debug logs available.

📦 Download full debug logs & test artifacts

@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

❌ Integration Tests Failed (controller-cr / mgr=openclaw / wk=openclaw)

Commit: b5d175f
Workflow run: #1717

Test Results
No test output captured.
Debug Log (tail)
No debug logs available.

📦 Download full debug logs & test artifacts

@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

📊 CI Metrics Report

Summary

Metric Current Baseline Change
LLM Calls 85 97 -12 ↓ -12.4%
Input Tokens 2586819 2719498 -132679 ↓ -4.9%
Output Tokens 19012 16508 +2504 ↑ +15.2%
Total Tokens 2605831 2736006 -130175 ↓ -4.8%

By Role

Role Metric Current Baseline Change
🧠 Manager LLM Calls 59 72 -13 ↓ -18.1%
Input Tokens 1954542 2092724 -138182 ↓ -6.6%
Output Tokens 12965 10274 +2691 ↑ +26.2%
Total Tokens 1967507 2102998 -135491 ↓ -6.4%
🔧 Workers LLM Calls 26 25 +1 ↑ +4.0%
Input Tokens 632277 626774 +5503 ↑ +0.9%
Output Tokens 6047 6234 -187 ↓ -3.0%
Total Tokens 638324 633008 +5316 ↑ +0.8%

Per-Test Breakdown

Test Mgr Calls Wkr Calls Δ Calls Mgr In Wkr In Mgr Out Wkr Out Δ Tokens Trend
02-create-worker 6 0 +1 ↑ +20.0% 183647 0 854 0 +47513 ↑ +34.7% ⚠️ regressed
03-assign-task 12 5 +4 ↑ +30.8% 377745 115430 2414 806 +186215 ↑ +60.0% ⚠️ regressed
04-human-intervene 12 0 -2 ↓ -14.3% 347711 0 1616 0 +12890 ↑ +3.8% ✅ improved
05-heartbeat 5 0 -2 ↓ -28.6% 163004 0 1175 0 -34025 ↓ -17.2% ✅ improved
06-multi-worker 24 21 -13 ↓ -22.4% 882435 516847 6906 5241 -342768 ↓ -19.5% ✅ improved

Trends

3 test(s) improved (fewer LLM calls)
⚠️ 2 test(s) regressed (more LLM calls)


Generated by AgentTeams CI on 2026-07-25 05:10:37 UTC


📦 Download debug logs & test artifacts

@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

❌ Integration Tests Failed (controller-cr-2 / mgr=copaw / wk=copaw)

Commit: 21dadc7
Workflow run: #1722

Test Results
No test output captured.
Debug Log (tail)
No debug logs available.

📦 Download full debug logs & test artifacts

Change-Id: I3f41015551b028286370a3148895afd6267d2e28
Change-Id: I6823e52a911568ffceb0cf45c37603df28160494
Change-Id: Idd80e2138a060c348fd298363a65604c24547d1f
Change-Id: I1fe49a7dc84bc0ecf849edd7bba5f26db18cb7e1
Change-Id: I82743e6b5b832cf6adc842ea38516509b55b25ca
Change-Id: Ie587682bbdce738655b815bec2984535960071f6
@github-actions

Copy link
Copy Markdown
Contributor

❌ Integration Tests Failed (llm-interaction / mgr=copaw / wk=copaw)

Commit: 883df1f
Workflow run: #1716

Test Results
No test output captured.
Debug Log (tail)
No debug logs available.

📦 Download full debug logs & test artifacts

Change-Id: Ie303a07c558340473d7149638d768cba759d100c
Change-Id: I63e16bd32160d80ff12dc81bb6efe287820437e4
@shiyiyue1102
shiyiyue1102 marked this pull request as ready for review July 24, 2026 05:10
@shiyiyue1102

Copy link
Copy Markdown
Collaborator Author

@johnlanni @Jing-ze @maplefeng-a The latest checks are all passing and this PR is ready for review. Could you take a look when convenient?

@shiyiyue1102
shiyiyue1102 requested review from Sunrisea and maplefeng-a and removed request for Sunrisea July 24, 2026 05:20

@maplefeng-a maplefeng-a left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the hard-cut cleanup. The direction looks aligned with moving Team/Worker to explicit CR ownership, but I think two contract edges should be fixed before this lands:

  1. The "block Worker deletion while referenced by a Team" protection currently only covers the REST API path. DeleteWorker rejects a referenced worker through findTeamForMember, but direct Worker CR deletion still goes through WorkerReconciler's DeletionTimestamp -> reconcileDelete path and removes the finalizer after cleanup. I also do not see a validating webhook/admission path in this PR. That means kubectl delete worker <team-member> can still delete a Worker that is referenced by a Team, which violates the new declarative CR contract. Could we add the same protection on the CR path, preferably via validation/admission, or otherwise clearly narrow the documented guarantee to the REST/CLI path?

  2. validateTeamWorkerMembers still accepts an empty member role (case "", "worker"), but the generated Team CRD now requires workerMembers[].role and restricts it to team_leader|worker. A REST caller that omits the non-leader role can pass server-side validation and then fail at the Kubernetes write layer, likely as a generic 500 because writeK8sError does not map Invalid. Could we either reject empty roles in the REST validator or normalize them to "worker" before writing the CR?

CI is green on the current head; these look like contract/API consistency issues rather than test failures.

Change-Id: I2b2c448d8ea3f8267a428ef925398dd8781940d7
Change-Id: I0b6a028fdb54e22db8e96f4e2676e6474a1fe18a
@shiyiyue1102

Copy link
Copy Markdown
Collaborator Author

Thanks for catching these contract gaps. Fixed in d96f1ed:

  • WorkerReconciler now keeps the Worker finalizer and requeues deletion while any Team still references the Worker, covering direct CR deletion.
  • The REST Team validator now rejects empty member roles before attempting the Kubernetes write.

Validated with the full agentteams-controller test suite (go test ./...).

Change-Id: Ie32c2f73083f19ea0f913edd9e075fcba91616c2
Change-Id: I8a3d34053424a0fe21c98f710f8dba9904f1a0c4
@shiyiyue1102
shiyiyue1102 requested a review from maplefeng-a July 25, 2026 05:33

@maplefeng-a maplefeng-a left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The contract gaps I raised have been addressed, and the current head is green. Approving.

@shiyiyue1102
shiyiyue1102 merged commit 37c31b7 into main Jul 25, 2026
41 of 43 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants