Skip to content

feat(connection): add multi-deployment read-only Jenkins providers #574

Description

@guoxianzhe

Problem

Connection 当前只支持 GitHub、Bitbucket Server、Jira Server 和 Confluence Server,无法让 Direct MCP 或 Delegated Consumer 在不接触 Jenkins 凭证的前提下查询公司多个 Jenkins deployment 的 Job、Build 和 Queue 状态。每个公司 Jenkins deployment 必须进入独立的 ProviderRelease、Credential、Grant、受控 egress 和审计边界,不能共用授权槽位,也不能由调用方提交任意 endpoint 或认证信息。

Scope

  • 建立多 Jenkins deployment 模型:每个经审核的实例使用独立稳定 Provider ID、ProviderRelease、固定 origin、Credential 和 Grant,共享同一个参数化只读 Adapter;不得把多个实例折叠成同一 providerId=jenkins。
  • jenkins-ci 固定为 https://jenkins-ci.agoralab.co;因其现有 OAuth 网关尚无 Connection 机器认证契约,只保留 catalog/adapter 实现,不在 runtime 开放连接。
  • jenkins-release 固定为 http://114.94.148.35:8010,仅在具名 LA3 supervised pilot 中按用户明确接受的残余风险开放;必须由 LA3 白名单直连,不使用代理,不扩展为任意 HTTP Provider,后续仍须迁移到 HTTPS。
  • 使用用户独立提供的 Jenkins username + API Token credential,不接受 Jenkins 登录密码;通过 Jenkins whoAmI API 验证稳定外部账号身份,原始 credential 只在服务端执行边界使用。
  • 提供只读 Action:读取当前用户、列出顶层 Jobs、读取指定 Job、Build、Queue item,以及按 start 游标分页读取 Build console log;Job full name 由服务端编码为 Jenkins folder path,调用方不能提交 URL、header 或 auth mode。
  • 所有请求使用固定 origin、禁止 redirect、限制响应大小并映射认证、权限、404、限流和 Provider 错误;除具名 jenkins-release pilot 外禁止明文 HTTP。
  • 将 Jenkins catalog、Adapter、运行时装配、Connection Web credential 表单和自动化测试接入现有 Provider 流程。
  • Console log 按用户明确要求不做内容脱敏,单次最多返回 256 KiB;授权页面和 Action guide 必须明确日志可能包含敏感构建输出,该结果进入当前调用响应与既有审计/保留边界。
  • ProviderRelease 升级且 auth profile、Credential scope 与稳定外部账号兼容时,用户通过“升级连接”复用服务端 current Credential完成 identity proof,不重新输入只展示一次的 API Token;Token 无效、scope 不足、认证方式变化、换号或主动轮换时才进入“更新凭证”。
  • 不包含触发/停止/重放构建、artifact 内容下载、任意 URL 访问和 Shared Connection;写 Action 另行设计幂等与 reconciliation 契约。

Acceptance criteria

  • AC-1: PRD 和 HLD 明确公司多个 Jenkins deployment 的建模规则,并记录两个固定 deployment、认证、identity proof、Action 范围、写操作排除项和 jenkins-release HTTP pilot 风险边界。
  • AC-2: 用户可以在 Connection Web 用 Jenkins username + API Token 建立 Jenkins Connection;无效 credential、身份缺失或 redirect 均 fail closed,Secret 不出现在响应、日志或审计投影中。
  • AC-3: 已授权 Consumer 可以对 runtime 开放的 jenkins-release 执行 deployment-scoped 的 get_current_user、list_jobs、get_job、get_build、get_build_console 和 get_queue_item Action,且所有网络请求只发往固定 LA3 白名单 origin;jenkins-ci 在机器认证契约确认前不开放连接。
  • AC-7: get_build_console 使用固定 progressive log endpoint,要求 jobFullName、buildNumber 和非负 start,单次最多返回 256 KiB、nextStart 和 moreData;不做内容脱敏,不接受 URL 或任意请求头。
  • AC-8: requiresReconnect 的个人 Connection 可以通过 credential-preserving upgrade 使用 current Credential验证并迁移到 current ProviderRelease;浏览器不接收 Credential,身份不一致、并发 Credential 轮换或 Provider 验证失败时 fail closed,新增 Action 仍单独 preview/consent。
  • AC-4: 未授权 Consumer、其他 Principal、错误 ProviderRelease、任意 URL/路径注入及越权 Jenkins 响应均被拒绝,并且不产生旁路 Provider 请求。
  • AC-5: jenkins-release catalog 可由 runtime 幂等发布并出现在受支持 Provider 列表中,不替换现有 Provider declaration;测试证明两个 Jenkins deployment profile 会产生不同 Provider/Release/Action identity,且共享 Adapter 行为而不共享 endpoint 或 Credential。
  • AC-6: Adapter、runtime wiring、credential form 和核心负向路径具备自动化回归测试;真实环境验证记录实际 deployment、身份、read Action、reauth/revoke 和错误路径,缺少真实凭证时明确标记为人工验证而不声称上线。

Validation

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm check-types
  • pnpm test
  • pnpm build
  • pnpm smoke
  • pnpm docker:build
  • Markdown lint、link check、workflow policy、actionlint 和 git diff --check
  • 使用公司 Jenkins 测试账号执行 credential validation、至少一个 Job/Build/Queue read、reauth、revoke、401/403/404 和 redirect 拒绝验证;不执行任何构建写操作。

Blocked by

None

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-humanHuman implementation on an Issue or pending human validation on a PR

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions