3.4 KiB
3.4 KiB
Current Status — agent-platform
Date: 2026-07-06
Repository: https://forgejo.media-on.de/Leopoldadmin/agent-platform
Local path: /a0/usr/workdir/agent-platform/
Branch: main
Commit: 347ccb0 ("fix: C3 case-insensitive Bearer prefix + S1 MCP asyncio.Lock (closes 2 xfail)")
Visibility: public (verified, no secrets in tree)
App version (api.py): 0.3.0
1. Release phase
Phase: Release Handoff (Gate 7 of 7: intake → requirements → architecture → UI (n/a) → implementation → test → deployment → release).
Cadence: 3rd release_auditor call this project (matches the 3-block release-auditor rule).
Decision (this audit): HOLD — see RELEASE_NOTES.md § "Promote decision".
| Gate | Result |
|---|---|
| intake | PASS (PLAN.md §1–§9 present, problem + outcome stated) |
| requirements | PASS_WITH_NOTES (B-IDs and C-IDs in code + tests, but no standalone requirements.md) |
| architecture | PASS (PLAN.md §2–§6, 2-container compose, MCP via /mcp path) |
| UI design | N/A (server-side HTMX UI, no separate design phase) |
| implementation | PASS_WITH_NOTES (matches architecture; residual C/D/M/X issues tracked) |
| test | PASS (pytest: 19 passed, 2 xpassed — see test_report.md in docs/) |
| deployment | PASS (Coolify staging healthy, compose + Traefik labels durable) |
| release | PASS_WITH_NOTES (RELEASE_NOTES.md, rollback plan, secrets handling) |
2. Deploy status
| Env | Status | URL |
|---|---|---|
| Staging (Coolify) | healthy (200, mcp_server reachable, 1 agent) | https://staging.agent-platform.media-on.de |
| Production | NOT DEPLOYED — pending HOLD resolution | n/a |
Coolify identifiers:
- Project UUID:
xht8vwszdqrk9biytxzsopu6 - Resource UUID:
n27nquozfhcgbph182ivbht3
Last known good image tag: 4847d3eb05ab324273d80c4594956b1a79483fe9.
3. Live state (last verified during this audit)
/health→ 200,mcp_server: "reachable",agents: 1,llm_model: deepseek/deepseek-v4-flash./api/agents(Bearerw6M…0W0) → 200, one agent (example, source=code, 6 allowed_tools).- Both containers (
agent-platform,mcp-tools) healthy inCoolify. - Caveat 1:
LLM_API_KEYempty in Coolify env →/api/chat/*returns 500 until set./health, CRUD, UI all work. - Caveat 2: Master
AUTH_TOKENis currently the staging one — must be rotated before production (seeRELEASE_NOTES.md§ "Production checklist").
4. Next action (single, unambiguous)
- Promoter (human): resolve HOLD blockers in
RELEASE_NOTES.md:- Set
LLM_API_KEYin Coolify env (any LLM provider). - Decide whether to land SSRF hardening (S2) + auth-event audit (S5) before promotion, or accept the residual risk in writing.
- Rotate
AUTH_TOKENfor production.
- Set
- Release auditor: re-run this audit after the two patches above (small, ≤ S-effort each).
- Deploy agent: clone compose to a new production Coolify resource, swap
FQDN, bind productionAUTH_TOKEN+LLM_API_KEY, redeploy. - No further code changes to
agent_platform/unless HOLD blockers resolve into code.
5. Open block-level context
- 3 blocks completed this project (per 3-block release-auditor rule).
- Audit + reviewer block-compaction calls do NOT count toward the 3-task limit.
- Pending: next_steps left implicit via
RELEASE_NOTES.md§ "Production checklist"; will be added tonext_stepDB once HOLD is cleared.