Skip to content

feat(deploy): provision-semantic-content production operation - #29

Merged
Knucklessg1 merged 3 commits into
mainfrom
feat/provision-semantic-content-cli
Oct 6, 2026
Merged

Knucklessg1 merged 3 commits into
mainfrom
feat/provision-semantic-content-cli

Conversation

@Knucklessg1

Copy link
Copy Markdown
Member

Adds graph-os-production-ops provision-semantic-content [--served-url URL | GRAPH_OS_SERVED_MCP_URL].

It runs under GraphOS's own verified process session (runtime._mint_process_session) and the served engine bootstrap (_get_engine + _wait_for_engine_materialization). Every step is idempotent:

  1. Ensure the tenant graph (session.graph) exists, via ListGraphs, then CreateGraph Team only when absent.
  2. Ensure each provider's served registration (graph-os, agent-utilities) is live in __commons__. A live registration is left untouched.
  3. For each provider, build the pack (build_connector_content_pack) and obtain EG's binding through ConnectorPack.attest_self_served_catalog. The request pins the pack's server entry, the registry revision and digest, the registration config digest and a content digest, and is fenced by the generation read from catalog_authority_status. The pack is then imported through the SDK EpistemicGraphSink under AU pack_import_authority, with the catalog binding as that binding and the serving principal read via catalog_request_owner_principal.
  4. Reproject and attach_pack on the session graph.
  5. verify_semantic_content. Any failure exits 1 with the privacy-safe JSON error report.

Every EG call targets its graph with use_session(resolve_session().with_graph(g)).

Depends on (pins to bump once merged):

  • epistemic-graph #64 (the attest_self_served_catalog op and its generated sender)
  • agent-utilities #31 (the ActionPolicy rule for connector_pack_import on these two connectors)

Tests: tests/deployment/test_provision_semantic_content.py exercises the real CLI entrypoint. The EG transport is faked at client._send, so the generated senders, models and AU authority run for real. The tests cover a fresh provision, an idempotent re-run, failed verification exiting 1, the required served URL, and registration-digest canonical JSON. ruff and mypy are clean.

🤖 Generated with Claude Code

Knucklessg1 and others added 2 commits October 6, 2026 09:50
Add `graph-os-production-ops provision-semantic-content`. Under GraphOS's
own verified process session and the served engine bootstrap it
idempotently ensures the tenant graph and the served `__commons__`
registrations for each semantic content provider, obtains EG's catalog
binding through ConnectorPack.attest_self_served_catalog (pinned to the
exact server entry of the pack it imports), imports through the SDK sink
under AU's policy-gated pack_import_authority with the EG owner principal,
reprojects and attaches each pack to the session graph, and exits non-zero
unless verify_semantic_content passes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Knucklessg1
Knucklessg1 marked this pull request as ready for review October 6, 2026 18:12
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Knucklessg1
Knucklessg1 merged commit 21017e1 into main Oct 6, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant