Skip to content

feat: a skills GitHub App source for agent-manager's skill resolution - #506

Closed
teemow wants to merge 2 commits into
mainfrom
feat/skills-github-app
Closed

teemow wants to merge 2 commits into
mainfrom
feat/skills-github-app

Conversation

@teemow

@teemow teemow commented Oct 10, 2026

Copy link
Copy Markdown
Member

Problem

A lab's agent-manager resolves skills either anonymously (60 requests an hour per egress address, shared by the machine) or with a static token. A lab should reach GitHub as a GitHub App. agent-manager's chart already takes a read-only skills App (skills.github.app.secretName), but agentlab cannot wire it. Fixes #505.

Proposed solution

  • githubApp in agentlab.yaml (configure --github-app-id, --github-app-installation-id, --github-app-private-key-source): public ids plus a reference to the private key, validated (complete, numeric ids, the key a reference, not together with githubToken.source, which the chart refuses too).
  • Every up/platform writes the Secret agentlab-github-app in agent-platform before the install. agentlab server-side-applies app-id and installation-id, and beekeeper secret copy --to-secret patches private-key, which agentlab never reads; a failed placement fails the run.
  • The values set agent-manager.skills.github.app.secretName instead of tokenSecret. The portal and the migrate Job keep a $GITHUB_TOKEN if one is given, since they take a token only.
  • discover names the App and its preflight checks the secret tooling. The refreshSkills SKIP hints name the App. Documented in docs/agents.md and docs/cli.md.

Acceptance criteria

  • Unit tests: config validation; the render wires the App and drops tokenSecret; nothing changes without an App or on the 3.x line; the ids are applied, the key is handed to the tooling and never written by agentlab, and a failed placement fails.
  • The live proof (agents-test refreshSkills authenticated as the App) follows on a lab once the skills App exists; this PR ships as an RC.

(Written by an agent.)

@teemow
teemow requested a review from a team as a code owner October 10, 2026 21:47
@teemow

teemow commented Oct 10, 2026

Copy link
Copy Markdown
Member Author

Replaced by the same change as one commit in #507, so the PR's history carries no test fixture gitleaks takes for a key. (Written by an agent.)

@teemow teemow closed this Oct 10, 2026
@teemow
teemow deleted the feat/skills-github-app branch October 10, 2026 21:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A skills GitHub App source for agent-manager's skill resolution

1 participant