feat!: move agentctl and the Sandbox crates from altinn-studio - #136
Merged
Merged
Conversation
martinothamar
added this pull request to stack #137
October 5, 2026 07:16
Contributor
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
martinothamar
force-pushed
the
agentctl/move
branch
from
October 5, 2026 20:19
d01d4db to
45e5579
Compare
martinothamar
marked this pull request as ready for review
October 5, 2026 20:20
Imported verbatim from Altinn/altinn-studio@a117f7c (src/experimental and the root Rust workspace files), without history: - src/experimental/agent and the agentctl docs, changelog and scripts -> agentctl/ - src/experimental/sandbox, sandbox-authorization and sandbox-microsandbox -> sandbox/ - Cargo.toml, Cargo.lock, rust-toolchain.toml, deny.toml, rustfmt.toml, clippy.toml, Makefile, .editorconfig and .cargo/config.toml -> the repository root The workspace does not build at this commit; the next commit adapts it.
Point the workspace members and path dependencies at agentctl/ and sandbox/, and drop the GitHub runner coordinator, which stays in altinn-studio. Pruning Cargo.lock removes only the coordinator and the crates nothing else uses; no dependency is upgraded. The Sandbox crates move to sandbox/core, sandbox/authorization and sandbox/microsandbox, so their folders no longer repeat the parent's name. Their package names are unchanged. The Makefile, make-user-install.ps1 and installation-test.sh now run from the repository root. The .editorconfig rules apply to the Rust workspace paths only, and target/ and build/ are ignored. Files under agentctl/ and sandbox/ check out with LF on every platform, as they did in altinn-studio, because tests and scripts read them byte for byte.
These tests asserted what files declare rather than how agentctl behaves: altinn-studio's agents/ manifests, Dockerfile and skill list, which stay in altinn-studio, and the example manifests and Dockerfiles here. They broke on every legitimate edit of those files and exercised no agentctl code. Tests that use an example only as input stay.
Installers and `agentctl self update` now look for `agentctl/v*` releases in digdir/digdir-agents, and nothing is called experimental any more. The self-development and worktree examples develop this repository. MICROSANDBOX.md keeps only the consumer side of the Microsandbox pin; synchronizing the forks and releasing runtimes is documented in digdir/microsandbox. altinn-studio issues are referenced as Altinn/altinn-studio#N until they are recreated here.
The self-development Agent clones digdir/microsandbox and digdir/libkrunfw beside digdir/digdir-agents, so work that spans the platform and its forks starts from one Agent. gh adds an upstream remote to each fork clone. The changelog skill is adapted from altinn-studio's for agentctl/CHANGELOG.md and agentctl/changelog.sh.
deny.toml allows only the licenses the released binaries contain, for the release targets, and agentctl/notices generates the notices with cargo-about. They also reproduce the license files the dependencies ship, because cargo-about falls back to canonical texts without copyright notices when it cannot identify a file.
rust.yml builds, lints and tests the workspace and checks dependency advisories, sources and licenses; ci.yml runs it when the workspace changes, behind ci-gate. agentctl-release.yml publishes an `agentctl/v*` tag with LICENSE and THIRD_PARTY_NOTICES.md as separate assets, because the installers and the updater accept only the two binaries in an archive. It publishes through a draft, so every asset is attached before the release becomes immutable. The changelog check runs on its own so that toggling skip-changelog does not rerun CI. The root Rust files and these workflows get their own CODEOWNERS entries.
Build against the Microsandbox fork in the digdir organization at its v0.7.4-digdir.3 release tag and install the runtime published with that release. The source matches the previous pin apart from the release location and version, so the runtime behaves the same.
martinothamar
force-pushed
the
agentctl/move
branch
from
October 5, 2026 21:44
45e5579 to
561dfb6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves agentctl and the Sandbox crates from
src/experimentalin Altinn/altinn-studio into this repository, with the Rust workspace at the root. Stacked on #135.Imported verbatim from Altinn/altinn-studio@a117f7c, without history. The first commit is that import, byte for byte; the commits after it adapt it. They are easiest to review one by one.
agentctl/(theagentcrate withagentctlandagentd), andsandbox/core,sandbox/authorizationandsandbox/microsandbox(package names unchanged). The GitHub runner coordinator stays in altinn-studio, which will consume the Sandbox crates from here as Git dependencies.agentctl self updatelook foragentctl/v*releases in digdir/digdir-agents, and nothing is called experimental any more. Existing installs move by rerunning the installer once; Agents and Sessions carry over.deny.tomlallows only the licenses the released binaries contain. Releases publishLICENSEand generated third-party notices as separate assets, since the installers and the updater accept only the two binaries in an archive.rust.yml(build, lint, tests on Linux, macOS and Windows, dependency checks) runs behindci-gate.agentctl-release.ymlpublishesagentctl/v*tags through a draft, so every asset is attached before the release becomes immutable. The changelog check runs on its own, so togglingskip-changelogdoes not rerun CI.No agentctl release is cut here; that follows separately.