Repository navigation
feat: runtime allowed-agent registration via admin API - #17
Merged
Merged
Conversation
ThetaSinner
reviewed
Aug 17, 2026
`registered_at` records when an agent was first allowed, so re-POSTing a key to correct its label no longer resets the clock. The admin route carries the existing timestamp forward and returns 200 instead of 201; the stores stay last-write-wins so all three backends behave alike. DELETE followed by POST remains the way to get a fresh timestamp.
ThetaSinner
approved these changes
Aug 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First half of #13: a progenitor (or any allowed agent) can now be registered at runtime instead of editing
allowed_agentsin the config and redeploying — no more dependency loop between the progenitor node and the joining service.AllowedAgentStore(memory / sqlite / Cloudflare KV; backend followssession.store).agent_allow_listaccepts agents from the static config list OR the store — existing deployments are unaffected.POST/GET/DELETE /v1/admin/allowed-agents, bearer-authenticated by the newagent_registration.admin_secretconfig; mounted only when configured. Mirrors the dynamic linker registration pattern./v1/admin/*wildcard on the linker middleware would have 403'd the new routes whenever both admin secrets were configured.src/routes/admin-linkers.tsis touched for exactly this reason, with a combined-admin regression test.Operational notes:
KvAllowedAgentStoreyet; Workers deployments must construct one in their worker entry (same pre-existing gap as the linker admin routes).hc_auth_approval's job).agent_allow_listwill createallowed-agents.dbnext to the sessions db on upgrade.agent_allow_listis inauth_methods; the server warns at startup otherwise.