Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CodeyBox.slnx
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@
<Project Path="src/CodeyBox.Audit.Presets/CodeyBox.Audit.Presets.csproj" />
<Project Path="src/CodeyBox.Audit.Shell/CodeyBox.Audit.Shell.csproj" />
<Project Path="src/CodeyBox.Audit/CodeyBox.Audit.csproj" />
<Project Path="src/CodeyBox.Composition/CodeyBox.Composition.csproj" />
<Project Path="src/CodeyBox.Core/CodeyBox.Core.csproj" />
<Project Path="src/CodeyBox.Deployment/CodeyBox.Deployment.csproj" />
<Project Path="src/CodeyBox.Executor/CodeyBox.Executor.csproj" />
Expand Down
7 changes: 7 additions & 0 deletions docs/reference/api.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,13 @@ quota meter). Give each executor host its own token environment variable and
matching `ExecutorHostId`, and put that token (not the operator key) in the
executor's `ApiKeyEnvVar` on that host.

The majordomo MCP endpoint (`/mcp/majordomo`) is another host-scoped surface:
it accepts only the named API client configured by
`CodeyBox:Majordomo:ClientName` (default `majordomo`). Every other credential —
the operator key included — is refused, so the majordomo's calls are
attributable to its own principal and the token can be revoked without
rotating the operator key.

### GitHub App delivery credentials

For team installations, configure the GitHub upstream with a GitHub App
Expand Down
22 changes: 22 additions & 0 deletions docs/reference/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -1226,6 +1226,28 @@ Read-only parser settings for agent stream analytics.
| `MaxLineBytes` | `67108864` | Maximum JSONL event size accepted by the parser. Defaults to 64 MiB so large tool-result events fit under the default stream file cap. |
| `MaxJsonDepth` | `64` | Maximum JSON nesting depth accepted by the parser. |

## `Majordomo`

The majordomo's MCP endpoint (`POST /mcp/majordomo`, stateless streamable
HTTP) publishes exactly the majordomo tool vocabulary. These values are
hot-reloadable; the executor reads the current options on every call.

```json
"Majordomo": {
"Mode": "proposed",
"MaxMutatedItemsPerTurn": 8,
"ClientName": "majordomo",
"TurnWindowSeconds": 120
}
```

| Key | Default | Description |
|-----|---------|-------------|
| `Mode` | `proposed` | `autonomous` executes mutations immediately; `proposed` returns an operator-reviewable proposal with the validated change set instead of mutating. |
| `MaxMutatedItemsPerTurn` | `8` | Per-call and cumulative per-turn cap on mutated work items (hard ceiling 100). |
| `ClientName` | `majordomo` | The `CodeyBox:ApiClients` entry whose token is the majordomo credential. Only that client may reach the endpoint — the operator key and other named clients are refused — so majordomo calls are attributable and the credential is revocable independently. |
| `TurnWindowSeconds` | `120` | Rolling window over which mutations from one identity accumulate toward the per-turn cap. 1–3600. |

## `Projects`

See [docs/concepts/projects.md](../concepts/projects.md).
Expand Down
9 changes: 9 additions & 0 deletions src/CodeyBox.Api/ApiKeyAuth.cs
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,15 @@ public static void Configure(WebApplicationBuilder builder)
configuration,
environment,
RequiredConfigurationValidator.ApiClientsEntryMessage);
// The auth-disabled sentinel name is reserved: a configured
// client carrying it would be treated as the loopback
// operator by every host-scoped gate that asks
// IsAuthenticationDisabled.
if (string.Equals(client.Name, AuthenticationDisabledClientName, StringComparison.Ordinal))
throw RequiredConfigurationValidator.CreateAggregateException(
configuration,
environment,
$"CodeyBox:ApiClients entry name '{AuthenticationDisabledClientName}' is reserved.");
var token = Environment.GetEnvironmentVariable(client.TokenEnvVar);
if (string.IsNullOrWhiteSpace(token) || token.Length < 32)
throw RequiredConfigurationValidator.CreateAggregateException(
Expand Down
3 changes: 3 additions & 0 deletions src/CodeyBox.Api/CodeyBox.Api.csproj
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
<Project Sdk="Microsoft.NET.Sdk.Web">

<ItemGroup>
<ProjectReference Include="..\CodeyBox.Composition\CodeyBox.Composition.csproj" />
<ProjectReference Include="..\CodeyBox.Core\CodeyBox.Core.csproj" />
<ProjectReference Include="..\CodeyBox.Majordomo\CodeyBox.Majordomo.csproj" />
<ProjectReference Include="..\CodeyBox.Deployment\CodeyBox.Deployment.csproj" />
<ProjectReference Include="..\CodeyBox.AdminSeed\CodeyBox.AdminSeed.csproj" />
<ProjectReference Include="..\CodeyBox.Orchestrator\CodeyBox.Orchestrator.csproj" />
Expand Down Expand Up @@ -82,6 +84,7 @@
</ItemGroup>

<ItemGroup>
<PackageReference Include="ModelContextProtocol.AspNetCore" Version="2.2.0" />
<PackageReference Include="Serilog.AspNetCore" Version="8.0.3" />
<PackageReference Include="Serilog.Extensions.Hosting" Version="8.0.0" />
<PackageReference Include="Serilog.Sinks.File" Version="6.0.0" />
Expand Down
Loading
Loading