Repository navigation
Feature/agent sweep - #258
Merged
Merged
Conversation
Remove dead agent rows whose deployment is deleted/missing and that show no sign of life within 30 days (last_heartbeat AND audit_log). Remove rows with structurally invalid deployment_hash unconditionally — these can never authenticate and often leak a raw token in plaintext. The audit_log check protects agents that are alive but failing authentication: last_heartbeat only advances on successful wait/report, while audit_log captures auth_failure entries. Migration 20260113000002 already converted audit_log.created_at to timestamptz — no new migration needed. Includes 9 integration tests covering the key cases from the sweep plan.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces a robust, automated cleanup system for the
agentstable, ensuring that obsolete or malformed agent records are regularly removed. The main changes include new background sweeper logic, supporting database functions, and comprehensive tests for the agent cleanup process.Agent table cleanup and sweeper service:
agent_sweeperservice (src/services/agent_sweeper.rs) that periodically (daily) removes "dead" agent rows (those whose deployment is deleted and have no recent activity) and rows with structurally invaliddeployment_hashvalues. This helps prevent the accumulation of stale or malformed agent records. [1] [2] [3]src/db/agent.rs:sweep_dead: Deletes agents with no live deployment and no recent heartbeat or audit log activity within a retention window (default 30 days).sweep_malformed: Deletes agents whosedeployment_hashdoes not match the expected pattern (e.g., raw agent tokens or empty strings).Testing and validation:
tests/agent_sweep.rs) that covers all major cases for agent row cleanup, including:deployment_hashvalues.Other improvements:
config_contractis included in the project body for each app, preserving policy information during sync operations. [1] [2]These changes collectively improve the reliability, maintainability, and security of the agent management subsystem by ensuring that only valid, relevant agent records persist in the database.