Skip to content
Draft
Show file tree
Hide file tree
Changes from 61 commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
4b27491
feat(memory): add pluggable OMS backends
sozercan Aug 1, 2026
61198a0
Merge remote-tracking branch 'origin/main' into pluggable-memory
sozercan Aug 1, 2026
04d7599
fix(ci): match rendered Helm hook weights
sozercan Aug 1, 2026
40d9adc
fix(e2e): send caller-owned memory fields
sozercan Aug 1, 2026
3d270f0
fix(memory): propagate task transaction tokens
sozercan Aug 1, 2026
ce2b1cf
fix(memory): parallelize namespace dispatch
sozercan Aug 1, 2026
7c7ee63
fix(api): enforce attached transaction token constraints
sozercan Aug 1, 2026
fb154a5
fix(memory): harden remote result handling
sozercan Aug 1, 2026
fa4afb6
fix(api): honor optional internal memory auth
sozercan Aug 1, 2026
a1396e8
fix(memory): preserve governed trust invariants
sozercan Aug 1, 2026
4ae121b
fix(oms): reject expired search continuations
sozercan Aug 1, 2026
de820cc
fix(memory): preserve remote search continuations
sozercan Aug 1, 2026
dfc27e9
fix(oms): isolate KD6 tenant locking
sozercan Aug 1, 2026
959ad4d
fix(tools): bind child transaction token identity
sozercan Aug 1, 2026
cfedd2f
fix(api): preserve composite task transaction identity
sozercan Aug 1, 2026
5c7b6b5
fix(memory): complete capped legacy pages
sozercan Aug 1, 2026
35fbdb1
fix(cli): preserve operation location namespace
sozercan Aug 1, 2026
e02cb19
fix(memory): align recall bounds and accounting
sozercan Aug 1, 2026
64154e5
fix(memory): include tombstones in remote search
sozercan Aug 1, 2026
5de3813
fix(api): add memory operation cursors
sozercan Aug 1, 2026
42323fc
fix(memory): add checkpoint-fenced purge controls
sozercan Aug 1, 2026
da62eea
fix(oms): release failed search reservations
sozercan Aug 1, 2026
dc23805
fix(memory): close governance review gaps
sozercan Aug 1, 2026
e9b5029
fix(auth): provision direct task transaction tokens
sozercan Aug 1, 2026
22f464a
fix(memory): close remaining review gaps
sozercan Aug 1, 2026
90a124f
fix(auth): close transaction and memory scope gaps
sozercan Aug 1, 2026
74d93ec
fix(memory): harden resolution and purge fences
sozercan Aug 1, 2026
4fa5326
fix(memory): close authorization and lifecycle gaps
sozercan Aug 1, 2026
b902b55
fix(memory): harden long-running governance paths
sozercan Aug 1, 2026
65394ce
fix(memory): preserve namespace and deleted filters
sozercan Aug 1, 2026
37b6649
fix(memory): harden delegated tokens and snapshot retention
sozercan Aug 1, 2026
561c97f
fix(memory): close circuit and batch search reads
sozercan Aug 1, 2026
26fc725
fix(memory): preserve legacy search governance
sozercan Aug 1, 2026
1e05742
fix(memory): harden backend CLI and helm cleanup
sozercan Aug 2, 2026
23d73e5
fix(auth): chain task token renewals safely
sozercan Aug 2, 2026
01026a4
fix(auth): preserve approvals across token rotation
sozercan Aug 2, 2026
65813e9
fix(helm): neutralize failed preflight grants
sozercan Aug 2, 2026
fae086a
fix(ci): accept cleaned Helm tombstones
sozercan Aug 2, 2026
174f9ec
refactor(memory): move KD6 adapter out of tree
sozercan Aug 2, 2026
4afb8c6
fix(oms): honor adapter pagination limits
sozercan Aug 2, 2026
594b5e6
fix(auth): retry transient task token refresh failures
sozercan Aug 2, 2026
d966802
fix(auth): retry initial task token exchanges safely
sozercan Aug 2, 2026
93e6fe9
fix(memory): enforce advertised search input limits
sozercan Aug 2, 2026
dd5dbf6
fix(oms): size conformance fixtures from capabilities
sozercan Aug 2, 2026
a5774ce
fix(api): reject conflicting memory namespaces
sozercan Aug 2, 2026
9dcf35c
fix(memory): verify remote materialization state
sozercan Aug 2, 2026
4f7c5de
fix(auth): retry transient token authority reads
sozercan Aug 2, 2026
72bada4
fix(auth): retry token setup and persistence
sozercan Aug 2, 2026
285aad6
fix(memory): close pagination and response bounds
sozercan Aug 2, 2026
f5aef71
fix(memory): preserve replay and legacy pagination
sozercan Aug 2, 2026
c3e4cf3
fix(memory): preserve incomplete recall pages
sozercan Aug 2, 2026
2896dbd
fix(memory): enforce response and cursor bounds
sozercan Aug 3, 2026
30e8d2c
test(sqlite): reuse runtime session name constant
sozercan Aug 3, 2026
43c7ccb
fix(memory): stabilize cursor replay and ttl bounds
sozercan Aug 3, 2026
2e52a6a
fix(memory): harden cursor replay and identity tracking
sozercan Aug 3, 2026
ea48eb6
fix(memory): close cursor quota and search gaps
sozercan Aug 3, 2026
76e80d7
test(memory): bound fallback cursor replay
sozercan Aug 3, 2026
8a5035e
fix(memory): redact durable provenance metadata
sozercan Aug 3, 2026
5f86b91
fix(memory): align proposal and recovery lifecycle
sozercan Aug 3, 2026
258deac
fix(memory): enforce negotiated search bounds
sozercan Aug 3, 2026
5bbd3f1
fix(memory): enforce runtime search capabilities
sozercan Aug 3, 2026
965d414
chore(ci): clarify rendered secret manifest variable
sozercan Aug 3, 2026
417eb5e
Merge branch 'main' into pluggable-memory
sozercan Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
223 changes: 212 additions & 11 deletions .github/workflows/helm-chart.yml

Large diffs are not rendered by default.

7 changes: 6 additions & 1 deletion .github/workflows/release-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,9 @@ permissions:
contents: write
pull-requests: write

env:
MEMORY_RELEASE_STAGE: foundation

concurrency:
group: release-pr-${{ github.event.inputs.release_version || github.ref_name }}
cancel-in-progress: false
Expand Down Expand Up @@ -100,7 +103,9 @@ jobs:

helm lint cmd/build/helmify/static
helm lint charts/orka
test "$(helm show crds charts/orka | grep -c '^kind: CustomResourceDefinition$')" -eq 19
test "$(helm show crds charts/orka | grep -c '^kind: CustomResourceDefinition$')" -eq 20
test "$(awk '$1 == "memory.orka.ai/release-stage:" { print $2; exit }' cmd/build/helmify/static/Chart.yaml)" = "${MEMORY_RELEASE_STAGE}"
test "$(awk '$1 == "memory.orka.ai/release-stage:" { print $2; exit }' charts/orka/Chart.yaml)" = "${MEMORY_RELEASE_STAGE}"
git diff --check

- name: Create release pull request
Expand Down
49 changes: 40 additions & 9 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ on:
- "v*"

env:
MEMORY_RELEASE_STAGE: foundation
REGISTRY: ghcr.io
IMAGE_PREFIX: ${{ github.repository }}

Expand Down Expand Up @@ -66,14 +67,20 @@ jobs:
echo "Tag ${tag} requires charts/orka appVersion ${tag}; found ${app_version}." >&2
exit 1
fi
chart_memory_release_stage=$(awk '$1 == "memory.orka.ai/release-stage:" { print $2; exit }' charts/orka/Chart.yaml)
if [[ "${chart_memory_release_stage}" != "${MEMORY_RELEASE_STAGE}" ]]; then
echo "Release artifact requires memory stage ${MEMORY_RELEASE_STAGE}; found ${chart_memory_release_stage:-missing}." >&2
exit 1
fi

diff --no-dereference --recursive --unified manifest_staging/charts/orka charts/orka
diff --no-dereference --recursive --unified manifest_staging/deploy deploy
helm lint charts/orka
test "$(helm show crds charts/orka | grep -c '^kind: CustomResourceDefinition$')" -eq 19
test "$(helm show crds charts/orka | grep -c '^kind: CustomResourceDefinition$')" -eq 20

rendered_chart=$(mktemp)
trap 'rm -f "${rendered_chart}"' EXIT
foundation_activation_error=$(mktemp)
trap 'rm -f "${rendered_chart}" "${foundation_activation_error}"' EXIT
helm template release-validation charts/orka \
--namespace orka-system \
--set-string workers.harnessWrapper.auth.token=mock-token \
Expand All @@ -90,9 +97,20 @@ jobs:
echo "Expected two rendered runtime images; found ${#runtime_images[@]}." >&2
exit 1
fi
for image_ref in "${runtime_images[@]}"; do
if [[ "${image_ref##*:}" != "${expected_version}" ]]; then
echo "Tag ${tag} requires runtime image ${image_ref} to use ${expected_version}." >&2
expected_runtime_images=(
"${REGISTRY}/${IMAGE_PREFIX}:${expected_version}"
"${REGISTRY}/${IMAGE_PREFIX}/agent-harness-wrapper:${expected_version}"
)
for expected_image in "${expected_runtime_images[@]}"; do
matches=0
for image_ref in "${runtime_images[@]}"; do
if [[ "${image_ref}" == "${expected_image}" ]]; then
matches=$((matches + 1))
fi
done
if [[ ${matches} -ne 1 ]]; then
echo "Tag ${tag} requires exactly one rendered runtime image ${expected_image}." >&2
printf 'Rendered runtime image: %s\n' "${runtime_images[@]}" >&2
exit 1
fi
done
Expand All @@ -102,12 +120,25 @@ jobs:
while IFS= read -r worker_line; do
worker_refs+=("${worker_line#*=}")
done < <(grep -E "^[[:space:]]+- --${worker}-worker-image=" "${rendered_chart}")
if [[ ${#worker_refs[@]} -ne 1 || "${worker_refs[0]##*:}" != "${expected_version}" ]]; then
echo "Tag ${tag} requires exactly one rendered ${worker} worker image using ${expected_version}." >&2
expected_worker_ref="${REGISTRY}/${IMAGE_PREFIX}/${worker}-worker:${expected_version}"
if [[ ${#worker_refs[@]} -ne 1 || "${worker_refs[0]}" != "${expected_worker_ref}" ]]; then
echo "Tag ${tag} requires exactly one rendered ${worker} worker image ${expected_worker_ref}." >&2
exit 1
fi
done

if helm template release-validation-foundation charts/orka \
--namespace orka-system \
--set controller.memoryBackend.enabled=true \
--set controller.memoryBackend.activationEnabled=true \
--set controller.memoryBackend.crdsReadyOverride=true \
--set-string controller.memoryBackend.clusterId=release-validation \
>/dev/null 2>"${foundation_activation_error}"; then
echo "Foundation release chart unexpectedly enabled remote memory activation." >&2
exit 1
fi
grep -Fq 'controller.memoryBackend.activationEnabled is unavailable in the foundation release artifact' "${foundation_activation_error}"

- name: Package promoted chart
run: |
set -euo pipefail
Expand All @@ -121,8 +152,8 @@ jobs:
echo "Expected exactly one packaged Orka chart, found ${#chart_packages[@]}." >&2
exit 1
fi
if [[ $(helm show crds "${chart_packages[0]}" | grep -c '^kind: CustomResourceDefinition$') -ne 19 ]]; then
echo "Packaged Orka chart must contain exactly 19 CRDs." >&2
if [[ $(helm show crds "${chart_packages[0]}" | grep -c '^kind: CustomResourceDefinition$') -ne 20 ]]; then
echo "Packaged Orka chart must contain exactly 20 CRDs." >&2
exit 1
fi

Expand Down
31 changes: 30 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,36 @@ manifests: controller-gen kustomize ## Generate canonical and Gatekeeper-style s
}; \
trap cleanup EXIT; \
mkdir -p "$$tmp/deploy" "$$tmp/charts/orka"; \
"$(KUSTOMIZE)" build config/default -o "$$tmp/deploy/orka.yaml"; \
"$(KUSTOMIZE)" build config/default | \
awk ' \
function flush_doc() { \
if (doc == "") return; \
docs[++count] = doc; \
prioritized[count] = index(doc, "orka.ai/task-provenance-policy:") > 0 && \
(index(doc, "\nkind: ValidatingAdmissionPolicy\n") > 0 || doc ~ /^kind: ValidatingAdmissionPolicy\n/ || \
index(doc, "\nkind: ValidatingAdmissionPolicyBinding\n") > 0 || doc ~ /^kind: ValidatingAdmissionPolicyBinding\n/); \
deployment[count] = index(doc, "\nkind: Deployment\n") > 0 || doc ~ /^kind: Deployment\n/; \
doc = ""; \
} \
function emit_doc(text) { \
if (emitted) print "---"; \
print text; \
emitted = 1; \
} \
$$0 == "---" { flush_doc(); next } \
{ doc = doc (doc == "" ? "" : ORS) $$0 } \
END { \
flush_doc(); \
inserted = 0; \
for (i = 1; i <= count; i++) { \
if (!inserted && deployment[i]) { \
for (j = 1; j <= count; j++) if (prioritized[j]) emit_doc(docs[j]); \
inserted = 1; \
} \
if (!prioritized[i]) emit_doc(docs[i]); \
} \
if (!inserted) for (j = 1; j <= count; j++) if (prioritized[j]) emit_doc(docs[j]); \
}' > "$$tmp/deploy/orka.yaml"; \
"$(KUSTOMIZE)" build \
--load-restrictor LoadRestrictionsNone \
cmd/build/helmify | go run ./cmd/build/helmify -output-dir "$$tmp/charts/orka"; \
Expand Down
Loading