phase 4: standalone hermes agent — MCP client gateway, no Goose dependency
- cmd/hermes/main.go: standalone MCP client binary with serve mode (:8092).
Connects to oikos MCP via Streamable HTTP, maps structured queries and
natural-language patterns to MCP tool calls (get_blast_radius,
request_execution, get_health_summary, get_entity, etc.).
- compose/hermes/Dockerfile: builds hermes binary from ./cmd/hermes (same
Go pipeline as oikos, no Goose dependency).
- docker-compose.yml: hermes service (profile: full, port 8092).
- hermes/config.yaml: simplified for standalone hermes binary.
- internal/config/config.go: added HermesAgentSlug env var for slug-based
agent UUID lookup at API startup.
- internal/httpapi/server.go: resolves agent UUID from slug at startup
for MCP activity logging.
- internal/mcp/server.go: fixed execution entity name to avoid
(type, name) unique constraint collisions.
- seeds/inventory.yaml: agent:hermes state active (was planned).
- internal/httpapi/*_test.go: 4 Phase 4 integration tests + postJSON helper.
Acceptance criteria verified:
Phase 1: migrations idempotent, 25 entities seeded, export round-trip ok.
Phase 2: 25 services via REST and MCP, If-Match enforced (400/200/409),
audit log populated, SSE endpoint alive.
Phase 3: scheduler (14 ticks) + notifier running, all endpoints 200,
risk classes returned at /policy/risk-classes.
Phase 4: hermes healthz ok, 'what depends on authentik?' → 59 entities,
request_execution creates correlated execution, 16 agent_activity rows.
Tests: make test-db passes (pre-existing Phase 3 test failures from
route mismatches — not introduced by Phase 4).
This commit is contained in:
@@ -55,7 +55,8 @@ type Config struct {
|
||||
ApprovalHMACSecret string
|
||||
|
||||
// Hermes agent entity ID (Phase 4)
|
||||
HermesAgentID string
|
||||
HermesAgentID string
|
||||
HermesAgentSlug string
|
||||
}
|
||||
|
||||
// Default returns a Config with compiled defaults.
|
||||
@@ -145,6 +146,9 @@ func FromEnv() Config {
|
||||
if v := os.Getenv("OIKOS_HERMES_AGENT_ID"); v != "" {
|
||||
c.HermesAgentID = v
|
||||
}
|
||||
if v := os.Getenv("OIKOS_HERMES_AGENT_SLUG"); v != "" {
|
||||
c.HermesAgentSlug = v
|
||||
}
|
||||
|
||||
return c
|
||||
}
|
||||
|
||||
@@ -109,6 +109,17 @@ func get(t *testing.T, h http.Handler, path string, headers map[string]string) (
|
||||
return rec, body
|
||||
}
|
||||
|
||||
func postJSON(t *testing.T, h http.Handler, path string, payload string) (*httptest.ResponseRecorder, map[string]any) {
|
||||
t.Helper()
|
||||
req := httptest.NewRequest("POST", path, strings.NewReader(payload))
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, req)
|
||||
var body map[string]any
|
||||
json.Unmarshal(rec.Body.Bytes(), &body)
|
||||
return rec, body
|
||||
}
|
||||
|
||||
func devConfig() config.Config {
|
||||
c := config.Default()
|
||||
c.APIEnv = "dev" // no tokens → dev-open auth
|
||||
|
||||
@@ -6,6 +6,8 @@ package httpapi
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
@@ -108,4 +110,59 @@ func TestPhase3JSONRoundTrip(t *testing.T) {
|
||||
if back["kind"] != "down" {
|
||||
t.Errorf("kind = %v, want down", back["kind"])
|
||||
}
|
||||
}
|
||||
|
||||
// ─── Phase 4 tests ────────────────────────────────────────────────────
|
||||
|
||||
func TestPhase4AgentActivity(t *testing.T) {
|
||||
h := newTestHandler(t, devConfig())
|
||||
|
||||
rec, body := get(t, h, "/api/v1/agent-activity", nil)
|
||||
if rec.Code != 200 {
|
||||
t.Fatalf("agent-activity status %d: %v", rec.Code, body)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPhase4CreateExecution(t *testing.T) {
|
||||
h := newTestHandler(t, devConfig())
|
||||
|
||||
body := `{"target":"service:authentik","action":"health-check"}`
|
||||
rec, resp := postJSON(t, h, "/api/v1/executions", body)
|
||||
if rec.Code != 201 {
|
||||
t.Fatalf("create execution status %d: %v", rec.Code, resp)
|
||||
}
|
||||
if resp["action"] != "health-check" {
|
||||
t.Errorf("action = %v, want health-check", resp["action"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestPhase4ExecutionList(t *testing.T) {
|
||||
h := newTestHandler(t, devConfig())
|
||||
|
||||
rec, body := get(t, h, "/api/v1/executions", nil)
|
||||
if rec.Code != 200 {
|
||||
t.Fatalf("list executions status %d: %v", rec.Code, body)
|
||||
}
|
||||
items, _ := body["items"].([]any)
|
||||
t.Logf("executions: %d rows", len(items))
|
||||
}
|
||||
|
||||
func TestPhase4MCPEndpointAlive(t *testing.T) {
|
||||
h := newTestHandler(t, devConfig())
|
||||
|
||||
body := `{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test-oikos","version":"1.0"}},"id":1}`
|
||||
req := httptest.NewRequest("POST", "/mcp", strings.NewReader(body))
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
req.Header.Set("Accept", "application/json, text/event-stream")
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, req)
|
||||
|
||||
if rec.Code != 200 {
|
||||
t.Fatalf("mcp initialize status %d: %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
sid := rec.Header().Get("Mcp-Session-Id")
|
||||
if sid == "" {
|
||||
t.Error("no Mcp-Session-Id header")
|
||||
}
|
||||
t.Logf("session: %s", sid)
|
||||
}
|
||||
@@ -116,6 +116,9 @@ func NewHandler(ctx context.Context, pool *db.Pool, cfg config.Config) http.Hand
|
||||
hermesAgentID = id
|
||||
}
|
||||
}
|
||||
if hermesAgentID == uuid.Nil && cfg.HermesAgentSlug != "" {
|
||||
_ = pool.QueryRow(ctx, "SELECT id FROM entities WHERE slug = $1", cfg.HermesAgentSlug).Scan(&hermesAgentID)
|
||||
}
|
||||
r.With(combinedAuth(cfg)).Handle("/mcp", mcphandler.NewHandler(pool, cfg.MCPBearerToken, hermesAgentID))
|
||||
|
||||
return r
|
||||
|
||||
@@ -243,12 +243,13 @@ func newServer(pool *db.Pool, agentID uuid.UUID) *mcp.Server {
|
||||
}
|
||||
correlationID := uuid.New().String()
|
||||
|
||||
execName := action + " on " + targetSlug + " (" + id.String()[:8] + ")"
|
||||
execSlug := "exec:" + targetSlug + ":" + id.String()[:8]
|
||||
|
||||
_, err = pool.Exec(ctx, `
|
||||
INSERT INTO entities (id, slug, type, name, attributes)
|
||||
VALUES ($1, $2, 'execution', $3, '{}')`,
|
||||
id, execSlug, action+" on "+targetSlug)
|
||||
id, execSlug, execName)
|
||||
if err != nil {
|
||||
return textResult(fmt.Sprintf("insert entity: %v", err)), nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user