Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
76 commits
Select commit Hold shift + click to select a range
1116bf9
feat(image-resize): migrate to iii-sdk 0.22.0-alpha.2 with namespace …
guibeira Jul 25, 2026
d68bd3f
feat(claude-code): migrate to iii-sdk 0.22.0-alpha.2 with namespace s…
guibeira Jul 25, 2026
5697a57
feat(hermes): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
892ab13
feat(acp): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
a5aba72
feat(opencode): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
4e65a74
feat(pi): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
d5a21df
feat(scrapling): migrate to iii-sdk 0.22.0-alpha.2 with namespace sup…
guibeira Jul 25, 2026
46c1036
feat(approval-gate): migrate to iii-sdk 0.22.0-alpha.2 with namespace…
guibeira Jul 25, 2026
4a51ec2
feat(bridge): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
40c2994
feat(browser): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
1229048
feat(codex): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
eb43c91
feat(context-manager): migrate to iii-sdk 0.22.0-alpha.2 with namespa…
guibeira Jul 25, 2026
22309ad
feat(cron): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
eb68eba
feat(database): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
d597546
feat(devin): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
5cc7eee
feat(fp): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
df2ce7b
feat(github): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
76ecd20
feat(grok): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
3c890a7
feat(harness): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
92ffdfc
feat(http): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
6b9e907
feat(iii-directory): migrate to iii-sdk 0.22.0-alpha.2 with namespace…
guibeira Jul 25, 2026
b55bba8
feat(llm-router): migrate to iii-sdk 0.22.0-alpha.2 with namespace su…
guibeira Jul 25, 2026
d3f676f
feat(mcp): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
adaa47d
feat(memory): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
d7709cd
feat(memory-consolidate): migrate to iii-sdk 0.22.0-alpha.2 with name…
guibeira Jul 25, 2026
e3c5c75
feat(provider-anthropic): migrate to iii-sdk 0.22.0-alpha.2 with name…
guibeira Jul 25, 2026
5f71fd2
feat(provider-kimi): migrate to iii-sdk 0.22.0-alpha.2 with namespace…
guibeira Jul 25, 2026
984b783
feat(provider-llamacpp): migrate to iii-sdk 0.22.0-alpha.2 with names…
guibeira Jul 25, 2026
5ee7d55
feat(provider-openai): migrate to iii-sdk 0.22.0-alpha.2 with namespa…
guibeira Jul 25, 2026
f056a1f
feat(provider-openai-codex): migrate to iii-sdk 0.22.0-alpha.2 with n…
guibeira Jul 25, 2026
49c534c
feat(provider-xai): migrate to iii-sdk 0.22.0-alpha.2 with namespace …
guibeira Jul 25, 2026
aa7ada8
feat(provider-zai): migrate to iii-sdk 0.22.0-alpha.2 with namespace …
guibeira Jul 25, 2026
a0e4121
feat(pubsub): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
02691d5
feat(queue): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
ed05ae1
feat(rbac-proxy): migrate to iii-sdk 0.22.0-alpha.2 with namespace su…
guibeira Jul 25, 2026
c6612db
feat(session-manager): migrate to iii-sdk 0.22.0-alpha.2 with namespa…
guibeira Jul 25, 2026
6d813fe
feat(shell): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
f90f61b
feat(slack): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
daf184f
feat(state): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
a34ed2e
feat(storage): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
90a8f44
feat(telegram-bot): migrate to iii-sdk 0.22.0-alpha.2 with namespace …
guibeira Jul 25, 2026
e47f217
feat(web): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
fad4f91
feat(workflow): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
b3ca385
feat(worktree): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
6fc4073
feat(console): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
5b03847
feat(email): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
0e73bc5
feat(lsp): migrate to iii-sdk 0.22.0-alpha.2 with namespace support
guibeira Jul 25, 2026
acef881
fix(llm-router): route provider->router calls to the worker's namespace
guibeira Jul 25, 2026
614699b
fix(provider-kimi): route router calls to the worker's namespace
guibeira Jul 25, 2026
29e188a
fix(approval-gate): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
39e11d8
fix(context-manager): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
3c26bbd
fix(email): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
5504339
fix(harness): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
837996e
fix(iii-directory): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
6745436
fix(memory): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
d00c563
fix(memory-consolidate): route cross-worker calls to the worker's nam…
guibeira Jul 26, 2026
cd49cda
fix(slack): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
776c6aa
fix(telegram-bot): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
6c6bb7d
fix(workflow): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
4ceea05
fix(worktree): route cross-worker calls to the worker's namespace
guibeira Jul 26, 2026
c672f59
fix(harness): gate dynamic fan-out namespacing on the builtin check
guibeira Jul 26, 2026
d362a3d
fix(email): gate dynamic fan-out namespacing on the builtin check
guibeira Jul 26, 2026
db701d9
fix(workflow): gate dynamic fan-out namespacing on the builtin check
guibeira Jul 26, 2026
73c2077
fix(worktree): gate dynamic fan-out namespacing on the builtin check
guibeira Jul 26, 2026
549d1dc
fix(memory): gate dynamic fan-out namespacing on the builtin check
guibeira Jul 26, 2026
df9d9e3
fix(approval-gate): gate dynamic fan-out namespacing on the builtin c…
guibeira Jul 26, 2026
19a2cdf
fix(iii-directory): gate dynamic fan-out namespacing on the builtin c…
guibeira Jul 26, 2026
2423745
chore(state): bump iii-sdk and iii-helpers to 0.22.0-alpha.3
guibeira Jul 26, 2026
bd0e02a
chore(http): bump iii-sdk and iii-helpers to 0.22.0-alpha.3
guibeira Jul 26, 2026
15cc3a5
chore(pubsub): bump iii-sdk and iii-helpers to 0.22.0-alpha.3
guibeira Jul 27, 2026
7239c54
chore(cron): bump iii-sdk and iii-helpers to 0.22.0-alpha.3
guibeira Jul 27, 2026
914f017
chore(queue): bump iii-sdk and iii-helpers to 0.22.0-alpha.3
guibeira Jul 27, 2026
40dcdae
chore: bump iii-sdk dependencies to 0.22.0-alpha.3
guibeira Jul 27, 2026
b255e85
fix: add namespaces to trigger test fixtures
guibeira Jul 27, 2026
5247369
feat: a worker is told which configuration entry is its own
guibeira Aug 5, 2026
c091959
chore: merge main into SDK migration
guibeira Aug 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions acp/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion acp/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ name = "iii-acp"
path = "src/main.rs"

[dependencies]
iii-sdk = "=0.21.6"
iii-sdk = "=0.22.0-alpha.3"
tokio = { version = "1", features = ["macros", "rt-multi-thread", "io-std", "io-util", "sync", "time", "signal"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
Expand Down
3 changes: 3 additions & 0 deletions acp/src/handler.rs
Original file line number Diff line number Diff line change
Expand Up @@ -704,6 +704,9 @@ fn register_event_subscriber(
function_id: fn_id,
config: json!({ "stream_name": AGENT_EVENTS_STREAM }),
metadata: None,
// Resolve the trigger's target in this worker's namespace so it matches
// where the function was registered (None => engine default).
namespace: iii.namespace(),
}) {
Ok(t) => Some(t),
Err(e) => {
Expand Down
23 changes: 18 additions & 5 deletions approval-gate/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion approval-gate/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ name = "approval_gate"
path = "src/lib.rs"

[dependencies]
iii-sdk = "=0.21.8"
iii-sdk = "=0.22.0-alpha.2"
tokio = { version = "1", features = ["rt-multi-thread", "macros", "sync", "signal", "time"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
Expand Down
31 changes: 26 additions & 5 deletions approval-gate/src/configuration.rs
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,25 @@ use crate::config::WorkerConfig;
/// whole-snapshot replaces the inner `Arc` under the write lock.
pub type ConfigCell = Arc<RwLock<Arc<WorkerConfig>>>;

pub const CONFIG_ID: &str = "approval-gate";
pub const DEFAULT_CONFIG_ID: &str = "approval-gate";

/// The configuration entry this worker owns.
///
/// `III_CONFIG_NAME` when a supervisor set it, else the built-in name. A worker
/// that hardcodes its id turns that id into a global scarce name: two instances
/// share one entry and take turns overwriting it, and each write wakes both.
/// Being told which entry is its own is what lets them differ.
pub fn config_id() -> &'static str {
static ID: std::sync::OnceLock<String> = std::sync::OnceLock::new();
ID.get_or_init(|| {
std::env::var("III_CONFIG_NAME")
.ok()
.map(|value| value.trim().to_string())
.filter(|value| !value.is_empty())
.unwrap_or_else(|| DEFAULT_CONFIG_ID.to_string())
})
.as_str()
}
const CONFIG_FN_ID: &str = "approval::on-config-change";
const CONFIG_RETRIES: u32 = 3;
/// Base backoff between configuration RPC retries; multiplied by the
Expand Down Expand Up @@ -59,7 +77,7 @@ const FILESYSTEM_ACCESS_WATCH_ON_ERROR: &str = "fail_open";
/// value, so this is safe to call every boot).
pub async fn register_config(iii: &IIIClient, seed: Option<&WorkerConfig>) -> Result<(), String> {
let mut payload = json!({
"id": CONFIG_ID,
"id": config_id(),
"name": "Approval Gate",
"description": "Policy and decision surface settings: the deployment \
approval defaults (permission mode for new sessions \
Expand Down Expand Up @@ -98,14 +116,14 @@ async fn should_seed_default_value(iii: &IIIClient) -> Result<bool, String> {
async fn get_config_value(iii: &IIIClient) -> Result<Value, String> {
try_get_config_value(iii)
.await?
.ok_or_else(|| format!("configuration `{CONFIG_ID}` not found"))
.ok_or_else(|| format!("configuration `{config_entry}` not found", config_entry = config_id()))
}

/// Returns `Ok(None)` when the entry does not exist. The engine's
/// missing-entry codes vary in case (`function_not_found`,
/// `STATEMENT_NOT_FOUND`, `NOT_FOUND`), so match case-insensitively.
async fn try_get_config_value(iii: &IIIClient) -> Result<Option<Value>, String> {
match trigger_with_retry(iii, "configuration::get", json!({ "id": CONFIG_ID })).await {
match trigger_with_retry(iii, "configuration::get", json!({ "id": config_id() })).await {
Ok(resp) => Ok(resp.get("value").cloned()),
Err(e) if e.to_ascii_uppercase().contains("NOT_FOUND") => Ok(None),
Err(e) => Err(e),
Expand All @@ -128,6 +146,7 @@ pub fn bind_hook(iii: &IIIClient) {
"on_error": HOOK_ON_ERROR,
}),
metadata: None,
namespace: iii.namespace(),
}) {
Ok(_) => tracing::info!(
trigger_type = "harness::hook::pre-trigger",
Expand Down Expand Up @@ -157,6 +176,7 @@ pub fn bind_filesystem_access_watch_hook(iii: &IIIClient) {
"on_error": FILESYSTEM_ACCESS_WATCH_ON_ERROR,
}),
metadata: None,
namespace: iii.namespace(),
}) {
Ok(_) => tracing::info!(
trigger_type = "harness::hook::post-trigger",
Expand Down Expand Up @@ -258,10 +278,11 @@ pub fn register_config_trigger(iii: &IIIClient, cell: ConfigCell) -> Result<(),
trigger_type: "configuration".to_string(),
function_id: CONFIG_FN_ID.to_string(),
config: json!({
"configuration_id": CONFIG_ID,
"configuration_id": config_id(),
"event_types": ["configuration:updated"],
}),
metadata: None,
namespace: iii.namespace(),
})?;
Ok(())
}
Expand Down
40 changes: 31 additions & 9 deletions approval-gate/src/events.rs
Original file line number Diff line number Diff line change
Expand Up @@ -253,15 +253,36 @@ impl Emitter {
) {
for binding in set.snapshot() {
if binding_matches(&binding.filter, session_id, session_metadata) {
let res = self
.iii
.trigger(TriggerRequest {
function_id: binding.function_id.clone(),
payload: payload.clone(),
action: Some(TriggerAction::Void),
timeout_ms: None,
})
.await;
let request = TriggerRequest {
function_id: binding.function_id.clone(),
payload: payload.clone(),
action: Some(TriggerAction::Void),
timeout_ms: None,
};
let route_ns = self.iii.namespace().filter(|_| {
!matches!(
binding.function_id.split("::").next(),
Some(
"state"
| "stream"
| "queue"
| "pubsub"
| "configuration"
| "cron"
| "http"
| "engine"
| "sandbox"
| "log"
| "secret"
| "kv"
| "iii"
)
)
});
let res = match route_ns {
Some(ns) => self.iii.trigger(request.namespace(ns)).await,
None => self.iii.trigger(request).await,
};
if let Err(e) = res {
tracing::warn!(
function_id = %binding.function_id,
Expand Down Expand Up @@ -314,6 +335,7 @@ mod tests {
function_id: function_id.into(),
config,
metadata: None,
namespace: None,
}
}

Expand Down
45 changes: 26 additions & 19 deletions approval-gate/src/harness.rs
Original file line number Diff line number Diff line change
Expand Up @@ -10,13 +10,16 @@ use iii_sdk::IIIClient;
use serde_json::{json, Value};

pub async fn function_resolve(iii: &IIIClient, payload: Value) -> Result<Value, Error> {
iii.trigger(TriggerRequest {
let request = TriggerRequest {
function_id: "harness::function::resolve".into(),
payload,
action: None,
timeout_ms: None,
})
.await
};
match iii.namespace() {
Some(ns) => iii.trigger(request.namespace(ns)).await,
None => iii.trigger(request).await,
}
}

fn parse_roots(reply: &Value) -> Vec<String> {
Expand All @@ -36,14 +39,16 @@ fn parse_roots(reply: &Value) -> Vec<String> {
/// error on "no grants" — only on transport/RPC failure, e.g. an older
/// harness that doesn't implement this control plane yet).
pub async fn filesystem_grants(iii: &IIIClient, session_id: &str) -> Result<Vec<String>, Error> {
let reply = iii
.trigger(TriggerRequest {
function_id: "harness::filesystem::grants".into(),
payload: json!({ "session_id": session_id }),
action: None,
timeout_ms: None,
})
.await?;
let request = TriggerRequest {
function_id: "harness::filesystem::grants".into(),
payload: json!({ "session_id": session_id }),
action: None,
timeout_ms: None,
};
let reply = match iii.namespace() {
Some(ns) => iii.trigger(request.namespace(ns)).await?,
None => iii.trigger(request).await?,
};
Ok(parse_roots(&reply))
}

Expand All @@ -55,13 +60,15 @@ pub async fn filesystem_grant(
session_id: &str,
root: &str,
) -> Result<Vec<String>, Error> {
let reply = iii
.trigger(TriggerRequest {
function_id: "harness::filesystem::grant".into(),
payload: json!({ "session_id": session_id, "root": root }),
action: None,
timeout_ms: None,
})
.await?;
let request = TriggerRequest {
function_id: "harness::filesystem::grant".into(),
payload: json!({ "session_id": session_id, "root": root }),
action: None,
timeout_ms: None,
};
let reply = match iii.namespace() {
Some(ns) => iii.trigger(request.namespace(ns)).await?,
None => iii.trigger(request).await?,
};
Ok(parse_roots(&reply))
}
1 change: 1 addition & 0 deletions approval-gate/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,7 @@ fn bind_best_effort(
function_id: function_id.to_string(),
config,
metadata: None,
namespace: iii.namespace(),
});
match res {
Ok(_) => tracing::info!(trigger_type, function_id, "trigger binding requested"),
Expand Down
9 changes: 6 additions & 3 deletions approval-gate/src/session.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,14 @@ use iii_sdk::IIIClient;
use serde_json::{json, Value};

pub async fn get(iii: &IIIClient, session_id: &str) -> Result<Value, Error> {
iii.trigger(TriggerRequest {
let request = TriggerRequest {
function_id: "session::get".into(),
payload: json!({ "session_id": session_id }),
action: None,
timeout_ms: None,
})
.await
};
match iii.namespace() {
Some(ns) => iii.trigger(request.namespace(ns)).await,
None => iii.trigger(request).await,
}
}
2 changes: 2 additions & 0 deletions approval-gate/src/testkit/engine.rs
Original file line number Diff line number Diff line change
Expand Up @@ -459,13 +459,15 @@ pub async fn boot(engine: &Engine, opts: BootOpts) -> TestStack {
function_id: "recorder::on_created".to_string(),
config: json!({}),
metadata: None,
namespace: iii.namespace(),
})
.expect("bind pending_created");
iii.register_trigger(RegisterTriggerInput {
trigger_type: PENDING_RESOLVED.to_string(),
function_id: "recorder::on_resolved".to_string(),
config: json!({}),
metadata: None,
namespace: iii.namespace(),
})
.expect("bind pending_resolved");

Expand Down
8 changes: 4 additions & 4 deletions bridge/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion bridge/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ name = "bridge"
path = "src/main.rs"

[dependencies]
iii-sdk = "=0.21.6"
iii-sdk = "=0.22.0-alpha.3"
async-trait = "0.1"
tokio = { version = "1", features = ["rt-multi-thread", "macros", "sync", "signal", "time"] }
serde = { version = "1", features = ["derive"] }
Expand Down
Loading
Loading