Skip to content

feat(runner): report the runtime tier and egress posture per session - #1148

Merged
trunk-io[bot] merged 1 commit into
compass-service-owner/rig-3512-egress-runner-profilefrom
compass-service-owner/rig-3512-egress-posture-wire
Sep 13, 2026
Merged

feat(runner): report the runtime tier and egress posture per session#1148
trunk-io[bot] merged 1 commit into
compass-service-owner/rig-3512-egress-runner-profilefrom
compass-service-owner/rig-3512-egress-posture-wire

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 10 PRs:

  1. main
  2. feat(runtime): add the host-process WorkloadRuntime backend (RIG-3512) #1120
  3. feat(runner): derive the agent uid from the Runner's euid on the host backend (RIG-3512) #1125
  4. feat(runner): deliver the agent socket and config by path on the host backend (RIG-3512) #1135
  5. feat(runtime): distinguish a configured egress policy from an unset one #1142
  6. feat(runtime): refuse an egress policy the host tier cannot enforce #1143
  7. feat(runner): carry no egress policy on a backend that cannot enforce one #1145
  8. "feat(runner): report the runtime tier and egress posture per session" (this PR)
  9. feat(cli): show the runtime tier and egress posture per session #1153
  10. feat(ui): mark each agent's runtime tier and egress posture #1154
  11. feat(runner): declare the runtime tier and egress posture at enrollment #1156

A green launch said nothing about which boundary an agent actually got, and the
host tier has none. AgentSessionStatus now carries both the tier and the egress
posture, stamped by the Runner because it is the component that resolved the
backend.

Posture is carried separately rather than derived from the tier: enforcement is
a property of the backend, so a client inferring one from the other would render
a stale answer the moment that changes. Both fields are backward-compatible
appends, and an unrecognized value maps to UNSPECIFIED rather than a plausible
default — on a security surface, saying nothing beats guessing.

Tier identity rides a capability probe rather than widening the frozen
WorkloadRuntime interface, matching the existing egress markers.

@linear-code

linear-code Bot commented Sep 12, 2026

Copy link
Copy Markdown

RIG-3512

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-service-owner-rig-35-3bn7.compass-eng-docs.pages.dev

Deployed from compass-service-owner/rig-3512-egress-posture-wire at b6f3d69.

A green launch said nothing about which boundary an agent actually got, and the
host tier has none. AgentSessionStatus now carries both the tier and the egress
posture, stamped by the Runner because it is the component that resolved the
backend.

Posture is carried separately rather than derived from the tier: enforcement is
a property of the backend, so a client inferring one from the other would render
a stale answer the moment that changes. Both fields are backward-compatible
appends, and an unrecognized value maps to UNSPECIFIED rather than a plausible
default — on a security surface, saying nothing beats guessing.

Tier identity rides a capability probe rather than widening the frozen
WorkloadRuntime interface, matching the existing egress markers.
@rigel-mintaka
rigel-mintaka force-pushed the compass-service-owner/rig-3512-egress-posture-wire branch from 68a27c8 to b6f3d69 Compare September 12, 2026 19:37
@trunk-io
trunk-io Bot merged commit 4d0347b into main Sep 13, 2026
16 of 26 checks passed
@trunk-io
trunk-io Bot deleted the compass-service-owner/rig-3512-egress-posture-wire branch September 13, 2026 00:29
@trunk-io

trunk-io Bot commented Sep 13, 2026

Copy link
Copy Markdown

This pull request was merged into main as part of stacked PR 1156.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants