Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
0c16324
chore #12: point the default agent binary at the sibling telos build
metasmile Aug 29, 2026
d96b4c8
fix #12: acquire the agent lock outside the WS read loop select
metasmile Aug 29, 2026
2f1c77f
fix #12: wait for agent readiness and bound test curl timeouts
metasmile Aug 29, 2026
9f94790
fix #12: clean up the launcher process on teardown
metasmile Aug 29, 2026
34d7ae3
fix #12: avoid the shutdown handler wait deadlock
metasmile Aug 29, 2026
e4f02e8
fix #12: survive non-blocking stdio in the terminal client
metasmile Aug 30, 2026
683a722
test #12: verify the chat turn completes end to end
metasmile Aug 30, 2026
f2244d2
test #12: add live real-scenario suite (tool, concurrency, reconnect,…
metasmile Aug 31, 2026
791662f
chore #12: remove the legacy python reference server
metasmile Aug 31, 2026
a86256e
fix #12: raise the ws message cap and debounce thread persistence
metasmile Aug 31, 2026
7373ef6
test #12: add a thread-mention scenario to the live suite
metasmile Sep 1, 2026
3bd7323
test #12: split the scenario suite into deterministic and LLM tiers
metasmile Sep 1, 2026
60eb977
feat: add bearer token auth to HTTP API
metasmile Sep 2, 2026
e996f8e
fix #12: report file search truncation accurately
metasmile Sep 2, 2026
a59dbdd
fix #12: clean up auth token handling and shell header guard
metasmile Sep 2, 2026
f522697
docs #12: document HTTP API authentication
metasmile Sep 2, 2026
ca345e7
fix #12: pin CORS methods and annotate list-handler panic policy
metasmile Sep 2, 2026
48c718f
docs #12: note token file sharing across instances
metasmile Sep 2, 2026
26d6085
chore #12: remove the helix zed fallback agent
metasmile Sep 2, 2026
aca91a9
refactor #12: rename zed to telos across actus
metasmile Sep 2, 2026
e8cbe48
chore #12: point the scenario launch at the tel binary
metasmile Sep 2, 2026
624df95
feat: pass session id to telos process env
metasmile Sep 2, 2026
e45b6bd
test #12: pin the telos launch contract and CORS whitelist
metasmile Sep 2, 2026
a968fbf
fix #12: make scenarios deterministic by default, LLM tier opt-in
metasmile Sep 2, 2026
65f7f1c
fix #12: gate the live LLM chat test behind LLM_CHAT=1
metasmile Sep 2, 2026
d24aa84
ci #12: document the mock-only CI policy
metasmile Sep 2, 2026
ea13205
fix #12: pass server-only checks when the agent is a stub
metasmile Sep 3, 2026
7273fe0
chore #12: relicense actus to Apache-2.0
metasmile Sep 3, 2026
64f8dd5
update license
metasmile Sep 3, 2026
6d26a83
chore #12: add cargo-about license notice system
metasmile Sep 3, 2026
3a6bc24
feat #12: add native reference adapter and decouple telos-specific co…
metasmile Sep 3, 2026
d78706f
chore #12: drop actus CI license gate, keep optional cargo-about tooling
metasmile Sep 3, 2026
8a68e03
chore #12: split Dockerfile into slim runtime and test targets
metasmile Sep 3, 2026
094180c
ci #12: test on the test target and gate publishes on version tags
metasmile Sep 3, 2026
5c3229c
chore #12: remove the unused tokio-stream dependency
metasmile Sep 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Local dev-only nested telos checkout; never part of the build context.
# This directory holds a 1GB+ clone of the separate telos repository and
# would otherwise be uploaded with every build.
agents

# Rust build output
target

# VCS and IDE noise
.git
.DS_Store
*.swp

# Secrets and local environments
.env
.env.local
.env.*.local

# Python caches
__pycache__
*.pyc

# Not needed inside the image
docs
script
.github
13 changes: 11 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,18 +18,27 @@ jobs:

- uses: docker/setup-buildx-action@v4

- name: Build image
- name: Build the test image
run: |
docker buildx build --load \
--target test \
--cache-from type=gha,scope=shared-actus \
--cache-to type=gha,mode=min,scope=shared-actus \
-t actus:ci \
-f Dockerfile .

- name: Run tests
run: |
# Mock-only policy: the agent is a stub (/bin/true) and the chat
# round trip is skipped (ci-skip key plus the LLM_CHAT gate), so
# CI never spends LLM tokens. The suite compiles and runs the Rust
# unit and integration tests (tests/*.rs) and exercises the HTTP
# endpoints; live runs require LLM_CHAT=1 and a real key locally.
# Contract E2E against the fake backend runs in the telos CI
# workflow.
docker run --rm \
-e ZED_BIN=/bin/true \
-e TELOS_BIN=/bin/true \
-e LLM_API_KEY=ci-skip \
--entrypoint ./run.sh \
actus:ci --test

30 changes: 21 additions & 9 deletions .github/workflows/publish-actus-image.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,13 @@
name: Publish actus Docker Image

# Publishing is release-gated: actus is pre-1.0 and has shipped no release
# yet, so ordinary main commits push nothing. Pushing a `v*` tag cuts a
# versioned image (and refreshes `latest`); a manual dispatch publishes a
# `:dev` snapshot for preflight without touching `latest`.
on:
push:
branches: ["main"]
paths:
- "Dockerfile"
- "Cargo.*"
- "src/**"
- ".github/workflows/publish-actus-image.yml"
workflow_dispatch:
push:
tags: ["v*"]

concurrency:
group: "actus-image"
Expand All @@ -19,7 +18,7 @@ env:
IMAGE_NAME: ssccsorg/actus

permissions:
contents: write
contents: read
packages: write

jobs:
Expand All @@ -38,12 +37,25 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4

- name: Derive image tags
id: meta
run: |
if [ "${{ github.event_name }}" = "push" ]; then
# Version tag (for example v0.1.0): tag the image with the
# version and refresh latest.
echo "tags=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.ref_name }},${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest" >>"$GITHUB_OUTPUT"
else
# Manual dispatch: a dev snapshot that never touches latest.
echo "tags=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:dev" >>"$GITHUB_OUTPUT"
fi

- name: Build and push Docker image
uses: docker/build-push-action@v7
with:
context: .
file: Dockerfile
tags: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest
target: runtime
tags: ${{ steps.meta.outputs.tags }}
push: true
cache-from: type=gha,scope=shared-actus
cache-to: type=gha,mode=min,scope=shared-actus
Expand Down
6 changes: 4 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,6 @@ node_modules/
# Python (LightRAG)
__pycache__/

# Helix fork clone (managed by build.sh)
*.py[cod]
*.pyo
*.egg-info/
Expand Down Expand Up @@ -55,5 +54,8 @@ result/

logs

# Pre-compiled binaries (Helix remote_server, etc.)
# Pre-compiled binaries
.bin/

# Nested telos agent repo (separate private repository)
/agents/
49 changes: 37 additions & 12 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 3 additions & 3 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,9 @@
name = "actus"
version = "0.1.0"
edition = "2021"
license = "BUSL-1.1"
license = "Apache-2.0"
description = "Agent execution runtime across a shared knowledge space"
publish = false

[dependencies]
tokio = { version = "1", features = ["full"] }
Expand All @@ -17,13 +18,12 @@ uuid = { version = "1", features = ["v4"] }
chrono = { version = "0.4", features = ["serde"] }
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "json"] }
reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "json", "stream"] }
anyhow = "1.0.102"
tempfile = "3.27.0"
dirs = "6.0.0"
clap = { version = "4", features = ["derive"] }
async-stream = "0.3.6"
tokio-stream = "0.1.18"
walkdir = "2.5.0"
ignore = "0.4.23"
mime_guess = "2.0.5"
Expand Down
76 changes: 50 additions & 26 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,39 +1,63 @@
# ── Zed builder (prebuilt binary from external pipeline) ──────────────

FROM ubuntu:24.04 AS zed-builder

RUN apt-get update && apt-get install -y build-essential curl git \
# ── Actus ─────────────────────────────────────────────────────────────
#
# Targets:
# toolchain system deps + Rust, the source tree, and a warm cargo
# registry (cargo fetch is cached until Cargo.lock changes).
# release FROM toolchain: compiles the release binary.
# test FROM toolchain: adds python3, curl, and git for the
# run.sh --test suite. The suite compiles and runs the Rust
# tests (src unit tests plus the tests/*.rs integration
# tests) and exercises the HTTP endpoints against a live
# server, so pull requests never pay for a release build.
# runtime default target: the slim image published to ghcr. Holds
# only the actus binary plus git (the /v1/git/* endpoints
# spawn the git CLI). TLS comes from the bundled rustls/ring
# stack; ca-certificates provides the root store.
#
# Actus delegates agent execution to the telos process, which is never
# bundled into any of these images; it is located via TELOS_BIN or the
# agent config, keeping the Apache-2.0 actus image free of GPL telos.

FROM ubuntu:24.04 AS toolchain

RUN apt-get update && apt-get install -y \
build-essential \
curl \
&& rm -rf /var/lib/apt/lists/* \
&& curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
&& curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
| sh -s -- -y

ENV PATH="/root/.cargo/bin:${PATH}"
WORKDIR /workspace
COPY helix/build.sh helix/patch/ ./helix/
RUN mkdir -p helix/.bin && bash helix/build.sh --build-only --release

# ── Actus base ────────────────────────────────────────────────────────
# Warm the registry before the sources are copied so the dependency
# download layer is only invalidated when Cargo.lock changes.
COPY Cargo.toml Cargo.lock ./
RUN cargo fetch --locked

FROM ubuntu:24.04 AS base
COPY src/ src/
COPY tests/ tests/
COPY run.sh runner.py terminal.py ./

RUN apt-get update && apt-get install -y build-essential curl git python3 \
&& rm -rf /var/lib/apt/lists/* \
&& curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
FROM toolchain AS release

ENV PATH="/root/.cargo/bin:${PATH}"
WORKDIR /workspace
COPY Cargo.toml Cargo.lock* ./
COPY src/ src/
COPY *.py run.sh ./
RUN cargo build --release
RUN cargo build --release --locked

FROM toolchain AS test

ENTRYPOINT ["./target/release/actus"]
RUN apt-get update && apt-get install -y --no-install-recommends \
python3 \
curl \
git \
&& rm -rf /var/lib/apt/lists/*

# ── Full integration ─────────────────────────────────────────────────
FROM ubuntu:24.04 AS runtime

FROM base AS full
RUN apt-get update && apt-get install -y --no-install-recommends \
git \
ca-certificates \
&& rm -rf /var/lib/apt/lists/*

COPY --from=zed-builder /workspace/helix/.bin/ helix/.bin/
COPY NOTICE.md /
COPY --from=release /workspace/target/release/actus /usr/local/bin/actus

# Default: lean binary only
FROM base
ENTRYPOINT ["/usr/local/bin/actus"]
Loading