Skip to content

test(studio-cp): pin the first-provision manifest contract (#111) - #165

Open
Reese-max wants to merge 2 commits into
openabdev:mainfrom
Reese-max:devin/issue-111
Open

Reese-max wants to merge 2 commits into
openabdev:mainfrom
Reese-max:devin/issue-111

Conversation

@Reese-max

Copy link
Copy Markdown

Refs #111

Summary

#111's create-vs-redeploy seam already landed via #116: when the compose
deploy_provision/deploy_provision_agent path finds no stored manifest,
build_default_manifest assembles a fresh OABServiceManifest (create.rs
wizard defaults) and it is persisted+applied through the same
apply_manifests path deploy_apply uses; an existing manifest still takes
redeploy's patch path. The k8s counterpart landed with it.

What never landed is a check on the piece that was written blind — the
assembled manifest had zero coverage (a manual field-by-field check against
validate() stood in for compiling). This PR makes that contract testable
and pins it:

  • default_service_manifest — the pure manifest-assembly half of
    build_default_manifest, split out and made pub. The async wrapper
    keeps the AWS-only work (default_networking EC2 discovery, the ACP
    Secrets Manager write) and delegates; the produced manifest is identical.
  • tests/first_provision_manifest.rs — asserts the produced document
    passes OABServiceManifest::validate() (the gate validate_apply_request
    enforces on every apply) and round-trips through serde_yaml +
    oabctl::studio_api::parse_manifests — the exact parser deploy_apply's
    apply_deployment calls — so drift between the producer and the apply
    surface fails in CI instead of at first real deploy. Also pins the
    create.rs-derived defaults (256/512, FARGATE/X86_64, private subnets / no
    public IP, no ingress, generation 0, bundle_from left for the caller to
    wire to the uploaded bundle's prefix) and the acp_enabled ⇔
    OPENAB_ACP_AUTH_KEY secrets pairing Spec.acp_enabled requires.

Gate-driven cleanups (no behavior change)

Test plan

  • cargo test --workspace — new first_provision_manifest suite (3
    tests) green; 224 existing tests still green
  • Red proof: on base, the same suite fails to compile —
    no default_service_manifest in the root (exit 101)
  • cargo fmt --all -- --check clean; cargo clippy --workspace --all-targets -- -D warnings clean
  • Live AWS + New fleet first-create — unchanged code path; out of
    scope for this test-only seam (covered by the same wrapper as before)

Generated with Devin

cognition-team and others added 2 commits September 30, 2026 21:58
Precondition work so the rust toolchain gates can pass at all — the
workspace was written before it was ever run through rustfmt, and three
clippy lints fire on the current toolchain:

- cargo fmt --all (mechanical, no semantic change)
- studio-compose: implement std::iter::FromIterator for SkillsLibrary
  instead of an inherent from_iter (should_implement_trait)
- studio-cp: derive Default for FleetRuntime (derivable_impls); use `?` in
  role_identity (question_mark); crate-level allow too_many_arguments for
  the flat dispatch-arg provision/observe API — same class of allowance
  already used on this call surface's callers.

Same normalization the still-open openabdev#163 branch had to land for the same
gates; no behavior change intended.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The create-vs-redeploy half of openabdev#111 already landed via openabdev#116: a missing
stored manifest routes provision_from_library/provision_agent through
build_default_manifest into the same apply_manifests path deploy_apply
uses. What never landed is a check on the piece that was written blind —
the assembled OABServiceManifest has zero coverage (its author notes a
manual field-by-field check against validate() in lieu of compiling).

Split the pure manifest assembly out of build_default_manifest into pub
default_service_manifest (the wrapper keeps the AWS-only work: EC2
networking discovery + the ACP Secrets Manager write) and add
tests/first_provision_manifest.rs pinning:

- the produced document passes OABServiceManifest::validate() — the gate
  validate_apply_request enforces on every apply — and round-trips
  through serde_yaml + oabctl::studio_api::parse_manifests, the exact
  parser deploy_apply's apply_deployment entry point calls;
- the create.rs wizard defaults (256/512, FARGATE/X86_64, private
  subnets, no public IP, no ingress, generation 0, unset bundle_from
  until the caller wires the uploaded bundle's prefix);
- the acp_enabled <-> OPENAB_ACP_AUTH_KEY secrets pairing the Spec
  contract requires.

No behavior change — build_default_manifest produces the identical
manifest.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants