Skip to content

feat!: move agentctl and the Sandbox crates from altinn-studio - #136

Merged
martinothamar merged 8 commits into
mainfrom
agentctl/move
Oct 5, 2026
Merged

martinothamar merged 8 commits into
mainfrom
agentctl/move

Conversation

@martinothamar

@martinothamar martinothamar commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Moves agentctl and the Sandbox crates from src/experimental in Altinn/altinn-studio into this repository, with the Rust workspace at the root. Stacked on #135.

Imported verbatim from Altinn/altinn-studio@a117f7c, without history. The first commit is that import, byte for byte; the commits after it adapt it. They are easiest to review one by one.

  • Layout: agentctl/ (the agent crate with agentctl and agentd), and sandbox/core, sandbox/authorization and sandbox/microsandbox (package names unchanged). The GitHub runner coordinator stays in altinn-studio, which will consume the Sandbox crates from here as Git dependencies.
  • Release location: installers and agentctl self update look for agentctl/v* releases in digdir/digdir-agents, and nothing is called experimental any more. Existing installs move by rerunning the installer once; Agents and Sessions carry over.
  • Examples: the self-development and worktree examples develop this repository. Self-development also clones digdir/microsandbox and digdir/libkrunfw, and has a changelog skill.
  • Licensing: deny.toml allows only the licenses the released binaries contain. Releases publish LICENSE and generated third-party notices as separate assets, since the installers and the updater accept only the two binaries in an archive.
  • CI and release: rust.yml (build, lint, tests on Linux, macOS and Windows, dependency checks) runs behind ci-gate. agentctl-release.yml publishes agentctl/v* tags through a draft, so every asset is attached before the release becomes immutable. The changelog check runs on its own, so toggling skip-changelog does not rerun CI.
  • Microsandbox: pinned to the v0.7.4-digdir.3 release of digdir/microsandbox, with that release's runtime digests.
  • Tests that only asserted the contents of repository files are dropped, among them the ones over altinn-studio's own Agent definitions.
  • The root Rust files and these workflows get their own CODEOWNERS entries.

No agentctl release is cut here; that follows separately.

@martinothamar
martinothamar added this pull request to stack #137 October 5, 2026 07:16
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 35aac1f4-220f-4094-97bf-23dd01196b6b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@martinothamar martinothamar changed the title agentctl/move feat!: move agentctl and the Sandbox crates from altinn-studio Oct 5, 2026
@martinothamar
martinothamar marked this pull request as ready for review October 5, 2026 20:20
Base automatically changed from agentctl/prep to main October 5, 2026 21:43
Imported verbatim from Altinn/altinn-studio@a117f7c
(src/experimental and the root Rust workspace files), without history:

- src/experimental/agent and the agentctl docs, changelog and scripts
  -> agentctl/
- src/experimental/sandbox, sandbox-authorization and
  sandbox-microsandbox -> sandbox/
- Cargo.toml, Cargo.lock, rust-toolchain.toml, deny.toml, rustfmt.toml,
  clippy.toml, Makefile, .editorconfig and .cargo/config.toml -> the
  repository root

The workspace does not build at this commit; the next commit adapts it.
Point the workspace members and path dependencies at agentctl/ and
sandbox/, and drop the GitHub runner coordinator, which stays in
altinn-studio. Pruning Cargo.lock removes only the coordinator and the
crates nothing else uses; no dependency is upgraded.

The Sandbox crates move to sandbox/core, sandbox/authorization and
sandbox/microsandbox, so their folders no longer repeat the parent's
name. Their package names are unchanged.

The Makefile, make-user-install.ps1 and installation-test.sh now run
from the repository root. The .editorconfig rules apply to the Rust
workspace paths only, and target/ and build/ are ignored. Files under
agentctl/ and sandbox/ check out with LF on every platform, as they did
in altinn-studio, because tests and scripts read them byte for byte.
These tests asserted what files declare rather than how agentctl
behaves: altinn-studio's agents/ manifests, Dockerfile and skill list,
which stay in altinn-studio, and the example manifests and Dockerfiles
here. They broke on every legitimate edit of those files and exercised
no agentctl code. Tests that use an example only as input stay.
Installers and `agentctl self update` now look for `agentctl/v*`
releases in digdir/digdir-agents, and nothing is called experimental
any more. The self-development and worktree examples develop this
repository.

MICROSANDBOX.md keeps only the consumer side of the Microsandbox pin;
synchronizing the forks and releasing runtimes is documented in
digdir/microsandbox. altinn-studio issues are referenced as
Altinn/altinn-studio#N until they are recreated here.
The self-development Agent clones digdir/microsandbox and
digdir/libkrunfw beside digdir/digdir-agents, so work that spans the
platform and its forks starts from one Agent. gh adds an upstream remote
to each fork clone. The changelog skill is adapted from altinn-studio's
for agentctl/CHANGELOG.md and agentctl/changelog.sh.
deny.toml allows only the licenses the released binaries contain, for
the release targets, and agentctl/notices generates the notices with
cargo-about. They also reproduce the license files the dependencies
ship, because cargo-about falls back to canonical texts without
copyright notices when it cannot identify a file.
rust.yml builds, lints and tests the workspace and checks dependency
advisories, sources and licenses; ci.yml runs it when the workspace
changes, behind ci-gate. agentctl-release.yml publishes an
`agentctl/v*` tag with LICENSE and THIRD_PARTY_NOTICES.md as separate
assets, because the installers and the updater accept only the two
binaries in an archive. It publishes through a draft, so every asset is
attached before the release becomes immutable. The changelog check runs
on its own so that toggling skip-changelog does not rerun CI.

The root Rust files and these workflows get their own CODEOWNERS
entries.
Build against the Microsandbox fork in the digdir organization at its
v0.7.4-digdir.3 release tag and install the runtime published with that
release. The source matches the previous pin apart from the release
location and version, so the runtime behaves the same.
@martinothamar
martinothamar merged commit 4de497a into main Oct 5, 2026
13 checks passed
@martinothamar
martinothamar deleted the agentctl/move branch October 5, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant