Skip to content

fix(agent): normalize controller-owned registry identities - #725

Merged
scttbnsn merged 2 commits into
dev/v1.7from
fix/portwing-native-registry
Aug 14, 2026
Merged

fix(agent): normalize controller-owned registry identities#725
scttbnsn merged 2 commits into
dev/v1.7from
fix/portwing-native-registry

Conversation

@scttbnsn

@scttbnsn scttbnsn commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Closes #687

What changed

  • normalize complete controller-owned Portwing image records through the existing configured-provider path
  • use the canonical registry name, URL, credentials, and image identity before persistence and native refresh
  • preserve traditional agent behavior and partial-event handling
  • cover initial inventory and subsequent Portwing event ingestion

Verification

  • RED: both inventory and event paths retained registry.name=unknown and skipped the native registry query
  • GREEN: affected AgentClient/image-comparison suite 607/607
  • full backend 12,872 tests at 100% coverage on the fix commit
  • full pre-push gate passed in 276 seconds after current-dev integration
  • live exact-commit tri-tool smoke returned watch-now HTTP 200, queried hub.public, detected BusyBox 1.36.1, made 46 native Docker GETs, and made zero legacy watcher POSTs

Changelog

  • ✨ Added controller-side normalization for Portwing containers from Docker transport watchers.
  • 🔧 Changed inventory and incremental event handling to use configured registry identity, URL, credentials, and image identity.
  • 🔧 Preserved traditional agent normalization and partial-event handling.
  • 🐛 Fixed controller-owned registry checks for agent-synced containers.
  • ✨ Added tests for anonymous Docker Hub registration, image normalization, and native watcher identity.
  • 🔧 Verified affected tests, the backend suite, the pre-push gate, and live tri-tool smoke tests.

@vercel

vercel Bot commented Aug 14, 2026

Copy link
Copy Markdown

Deployment failed for project drydock-website with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/codeswhat?upgradeToPro=build-rate-limit

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8daa41d1-4685-4e63-a9cf-aa2ea1f84c4a

📥 Commits

Reviewing files that changed from the base of the PR and between 4fc35c7 and f8bb4f6.

📒 Files selected for processing (2)
  • app/agent/AgentClient.test.ts
  • app/agent/AgentClient.ts

📝 Walkthrough

Walkthrough

AgentClient now imports normalizeContainer and applies it to containers received through controller-native Docker transport when a registry URL is configured. Controller-owned enrichment remains after normalization. Tests type and reset mocked registry state, register an anonymous public Hub, and verify normalized Docker Hub data for marker-mode inventory and incremental watcher events.

Possibly related PRs

  • CodesWhat/drydock#650: Introduces the controller-owned Docker transport extended by this normalization change.
  • CodesWhat/drydock#651: Adds the controller-native transport and watcher infrastructure used by these AgentClient changes.
  • CodesWhat/drydock#512: Earlier AgentClient changes are extended with controller-side Docker image and registry normalization.

Merge Risk: ⚪ Minimal · up to f8bb4

This change normalizes controller-owned registry identities while preserving existing agent behavior; no actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 2
✅ Passed checks (2 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The changes implement controller-side normalization for Docker transport during initial inventory and incremental events, addressing the controller execution boundary in issue [#687].
Out of Scope Changes check ✅ Passed The implementation and tests remain limited to controller-owned registry normalization, native watcher identity, and preservation of traditional agent behavior.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/portwing-native-registry

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@scttbnsn

Copy link
Copy Markdown
Contributor Author

@greptileai Review exact head f8bb4f635ae72fe01dd3f2eeb8ba3eb40e070283. Review the Portwing controller-owned Docker ingest boundary: exact marker gating, configured registry/provider normalization, credential and image-name semantics, preservation of controller enrichment, partial/legacy event behavior, and native watch-now registry lookup.

@greptile-apps

greptile-apps Bot commented Aug 14, 2026

Copy link
Copy Markdown

Greptile Summary

The PR normalizes complete controller-owned Portwing container images through configured registry providers before persistence and native refresh, while retaining the existing enrichment-preservation behavior.

  • Gates normalization to Docker API watchers using controller execution and Portwing events.
  • Canonicalizes registry identity, URL, credentials selection, and image name through normalizeContainer.
  • Adds inventory and incremental-event coverage for Docker Hub normalization and native watcher refresh.

Confidence Score: 5/5

The PR appears safe to merge with no actionable defects identified in the changed normalization paths.

The controller-owned transport gate precisely matches Portwing Docker API watchers, complete image records are normalized before persistence and native refresh, and controller enrichment remains preserved afterward.

Important Files Changed

Filename Overview
app/agent/AgentClient.ts Adds narrowly gated provider normalization before controller enrichment preservation; no concrete changed-code defect was established.
app/agent/AgentClient.test.ts Adds regression coverage for canonical Docker Hub identities in initial inventory and subsequent Portwing event refresh paths.

Reviews (1): Last reviewed commit: "chore: merge dev/v1.7 into native regist..." | Re-trigger Greptile

@biggest-littlest biggest-littlest left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact final head. Controller-transport gating, provider normalization, enrichment preservation, legacy behavior, live tri-tool proof, and the complete CI/reviewer gates are covered.

@scttbnsn
scttbnsn merged commit b36c396 into dev/v1.7 Aug 14, 2026
21 of 26 checks passed
@scttbnsn
scttbnsn deleted the fix/portwing-native-registry branch August 14, 2026 09:55
scttbnsn added a commit that referenced this pull request Aug 14, 2026
## Summary

Promote the reviewed v1.7.0-rc.1 changes from the literal `dev/v1.7`
branch to `main`.

## Verified source

- Reviewed dev source before reconciliation:
`82ca66e40b193c9e6b877b0a5c3a0579085111ca` (tree
`9c3f314f34c5b464b06f75be869e1304d228aca2`)
- Topology-only reconciliation commit:
`192c039210a4a620648e182c711e3e6801038d80`
- Exact promotion head after review fix:
`e9f983275ec2bde0213e7edb24014320565e05ea`
- Target main before promotion:
`a70d406e58e6d1af91cdb34138783774b5115c32`
- Promoted tree: `8ba3389237783f634a46cb54622915bbbd969756`
- `main..dev` binary patch SHA-256:
`54a5312eb98ba3b94e96bfcf30894a6de656c1d2723f964be636f88353cf3e80`
- Reconciliation first-parent diff SHA-256:
`e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`

The reconciliation commit has parents `[82ca66e, a70d406]`, preserves
the reviewed dev tree exactly, and has an empty first-parent diff. The
final one-file test commit closes the promotion review finding by
pinning the exact HTTP redirect allowlist in both #606 release-note
bullets.

## First-parent ledger

- `514f015a` fix(agents): make edge poll interval configurable (#723)
- `4fc35c7f` fix(agents): surface edge exec end reasons (#724)
- `b36c396e` fix(agent): normalize controller-owned registry identities
(#725)
- `e0869448` fix(registries): propagate manifest created fetch failures
(#726)
- `82ca66e4` docs(release): update v1.7.0-rc.1 notes (#727)
- `192c0392` chore(release): reconcile main ancestry for v1.7 RC
- `e9f98327` test(release): enforce redirect allowlist in notes

No tag or release is cut by this PR. Release dispatch remains blocked
until the exact merged-main source, tree, archive, workflow, Dockerfile,
and digest inputs are recomputed and acknowledged.

Closes #688
Closes #635
Closes #687
Closes #606

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Changelog

✨ Added configurable `DD_PORTWING_POLL_INTERVAL` with a 300-second
default and validation fallback.

✨ Added Edge exec reason propagation through `endCallback` and session
cleanup.

✨ Added controller-side container registry normalization for Docker
transport.

✨ Added registry handling for permitted HTTP redirects while preserving
other metadata-fetch errors.

✨ Added release documentation and tests for configuration, redirects,
release identity, and required issue links.

🔧 Changed translated README release-note anchors to `2026-08-14`.

🗑️ Removed the obsolete `.gitleaksignore` entry for the deleted
WebSocket test.

## Concerns

- Recompute and acknowledge merged-main release inputs before enabling
release dispatch.
- Verify the controller-side registry normalization does not diverge
from agent-side normalization.
- Confirm the HTTP redirect allowlist covers only approved statuses.
- Confirm all consumers handle the new optional
`EdgeAgentAdapter.startExec` `endCallback` reason.
- Do not create a tag or release from this promotion.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Crowdin Bot <support+bot@crowdin.com>
Co-authored-by: Test <test@example.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants