Skip to content

Feature/agent sweep - #258

Merged
vsilent merged 2 commits into
devfrom
feature/agent-sweep
Sep 18, 2026
Merged

vsilent merged 2 commits into
devfrom
feature/agent-sweep

Conversation

@vsilent

@vsilent vsilent commented Sep 18, 2026

Copy link
Copy Markdown
Collaborator

This pull request introduces a robust, automated cleanup system for the agents table, ensuring that obsolete or malformed agent records are regularly removed. The main changes include new background sweeper logic, supporting database functions, and comprehensive tests for the agent cleanup process.

Agent table cleanup and sweeper service:

  • Added a new agent_sweeper service (src/services/agent_sweeper.rs) that periodically (daily) removes "dead" agent rows (those whose deployment is deleted and have no recent activity) and rows with structurally invalid deployment_hash values. This helps prevent the accumulation of stale or malformed agent records. [1] [2] [3]
  • Implemented two database functions in src/db/agent.rs:
    • sweep_dead: Deletes agents with no live deployment and no recent heartbeat or audit log activity within a retention window (default 30 days).
    • sweep_malformed: Deletes agents whose deployment_hash does not match the expected pattern (e.g., raw agent tokens or empty strings).

Testing and validation:

  • Added a comprehensive new test suite (tests/agent_sweep.rs) that covers all major cases for agent row cleanup, including:
    • Deletion of agents with deleted or missing deployments and no activity.
    • Preservation of agents with recent audit log entries or live deployments.
    • Removal of rows with malformed deployment_hash values.
    • Ensuring audit log records are preserved after agent deletion.

Other improvements:

  • Added a new test to ensure that config_contract is included in the project body for each app, preserving policy information during sync operations. [1] [2]

These changes collectively improve the reliability, maintainability, and security of the agent management subsystem by ensuring that only valid, relevant agent records persist in the database.

Remove dead agent rows whose deployment is deleted/missing and that show
no sign of life within 30 days (last_heartbeat AND audit_log). Remove
rows with structurally invalid deployment_hash unconditionally — these
can never authenticate and often leak a raw token in plaintext.

The audit_log check protects agents that are alive but failing
authentication: last_heartbeat only advances on successful wait/report,
while audit_log captures auth_failure entries.

Migration 20260113000002 already converted audit_log.created_at to
timestamptz — no new migration needed.

Includes 9 integration tests covering the key cases from the sweep plan.
@vsilent
vsilent merged commit 6b7f4a8 into dev Sep 18, 2026
8 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants