Skip to content

Commit a0f48da

Browse files
committed
feat: publish auditable AgentTeams DevFlow system
0 parents  commit a0f48da

93 files changed

Lines changed: 9303 additions & 0 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.env.example‎

Lines changed: 107 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,107 @@
1+
# =============================================================================
2+
# DevFlow Environment Variables Template
3+
# =============================================================================
4+
# Copy this file to `.env` and fill in real values. The DevFlow runtime loads
5+
# `.env` automatically via python-dotenv. NEVER commit the real `.env` — it
6+
# should be in .gitignore.
7+
#
8+
# Every variable here is referenced by the YAML configs in config/ using the
9+
# ${VAR} expansion syntax. Adding a new secret? Add it here AND wire it into
10+
# the relevant config file.
11+
# =============================================================================
12+
13+
# -----------------------------------------------------------------------------
14+
# LLM Configuration
15+
# -----------------------------------------------------------------------------
16+
# API key for the LLM provider. Used by all glm-4 agents and as the fallback
17+
# for CoderAgent. Treat as a top-level secret — it is injected into the
18+
# credential gateway, never passed directly to agent prompts.
19+
LLM_API_KEY=
20+
21+
# Base URL of the OpenAI-compatible endpoint serving GLM-4 / Codex.
22+
# Examples:
23+
# - ZhipuAI: https://open.bigmodel.cn/api/paas/v4
24+
# - Local vLLM: http://127.0.0.1:8000/v1
25+
# - Azure OpenAI: https://<resource>.openai.azure.com
26+
LLM_BASE_URL=https://open.bigmodel.cn/api/paas/v4
27+
28+
# Default model name. Individual agents override this in config/agents.yaml
29+
# (e.g. CoderAgent uses "codex" with a "glm-4" fallback).
30+
LLM_MODEL=glm-4
31+
32+
# -----------------------------------------------------------------------------
33+
# GitHub Configuration
34+
# -----------------------------------------------------------------------------
35+
# Fine-grained personal access token with repository + workflow scopes.
36+
# Required scopes: Contents (RW), Issues (RW), Pull requests (RW),
37+
# Workflows (R), Metadata (R). Used by the github MCP server.
38+
GITHUB_PERSONAL_ACCESS_TOKEN=
39+
40+
# Target repository. Used by the github MCP server default context and by
41+
# the cicd MCP server to scope pipeline operations.
42+
GITHUB_REPO_OWNER=
43+
GITHUB_REPO_NAME=
44+
45+
# -----------------------------------------------------------------------------
46+
# Vector Store (RAG / Experience Store)
47+
# -----------------------------------------------------------------------------
48+
# Local path to the ChromaDB persistent directory. Used by LocatorAgent for
49+
# code root-cause retrieval and by the experience-distiller for pattern
50+
# storage and deduplication lookups.
51+
CHROMADB_PATH=.devflow/chromadb
52+
53+
# -----------------------------------------------------------------------------
54+
# Observability — OpenTelemetry
55+
# -----------------------------------------------------------------------------
56+
# OTLP exporter endpoint for traces. Point at a local collector in dev and a
57+
# remote collector (e.g. Tempo, Jaeger, or the OTel Collector) in prod.
58+
OTEL_EXPORTER_OTLP_ENDPOINT=http://127.0.0.1:4317
59+
60+
# Deployment environment tag attached to every trace/metric as a resource
61+
# attribute. Useful for filtering prod vs staging vs dev.
62+
# Default: development
63+
DEPLOYMENT_ENV=development
64+
65+
# -----------------------------------------------------------------------------
66+
# Audit Log
67+
# -----------------------------------------------------------------------------
68+
# Path to the append-only audit log (JSONL). See config/security.yaml for
69+
# retention and rotation policy.
70+
AUDIT_LOG_PATH=logs/audit.log
71+
72+
# Optional: structured application log file (defaults to logs/devflow.log).
73+
LOG_FILE_PATH=logs/devflow.log
74+
75+
# -----------------------------------------------------------------------------
76+
# MCP Servers
77+
# -----------------------------------------------------------------------------
78+
# Port for the github MCP server. Only needed if running github MCP over HTTP
79+
# instead of the default stdio transport (see config/mcp_servers.yaml).
80+
MCP_GITHUB_PORT=8765
81+
82+
# Port for the custom CI/CD MCP server. Binds to 127.0.0.1 only.
83+
MCP_CICD_PORT=8766
84+
85+
# CI/CD provider backing the cicd MCP server. Currently supported:
86+
# github_actions — uses GitHub Actions workflows
87+
# Default: github_actions
88+
CICD_PROVIDER=github_actions
89+
90+
# -----------------------------------------------------------------------------
91+
# Credential Gateway (Security)
92+
# -----------------------------------------------------------------------------
93+
# URL of the credential gateway / secret broker. In development this defaults
94+
# to an in-process gateway; in production point at Vault or equivalent.
95+
# Default: http://127.0.0.1:8200
96+
CREDENTIAL_GATEWAY_URL=http://127.0.0.1:8200
97+
98+
# -----------------------------------------------------------------------------
99+
# Rollback / Alerting (optional)
100+
# -----------------------------------------------------------------------------
101+
# Channel to notify when rollback retries are exhausted or a boundary
102+
# violation occurs. Leave empty to log-only. Example: a Slack webhook URL.
103+
ALERT_CHANNEL=
104+
105+
# Health check endpoint used to confirm a rollback succeeded.
106+
# Default: /health
107+
HEALTH_CHECK_ENDPOINT=/health

‎.github/workflows/ci.yml‎

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
name: quality-gate
2+
3+
on:
4+
push:
5+
branches: [main]
6+
pull_request:
7+
branches: [main]
8+
9+
permissions:
10+
contents: read
11+
12+
jobs:
13+
verify:
14+
runs-on: ubuntu-latest
15+
strategy:
16+
fail-fast: false
17+
matrix:
18+
python-version: ["3.10", "3.12"]
19+
steps:
20+
- uses: actions/checkout@v4
21+
- uses: actions/setup-python@v5
22+
with:
23+
python-version: ${{ matrix.python-version }}
24+
cache: pip
25+
- name: Install
26+
run: python -m pip install -e ".[dev]"
27+
- name: Validate configuration
28+
run: python -m devflow.cli validate
29+
- name: Lint
30+
run: ruff check .
31+
- name: Type check
32+
run: mypy src scripts tests
33+
- name: Test
34+
run: pytest -q
35+
- name: Evaluate Skills
36+
run: python scripts/evaluate_skills.py
37+
- name: Build AgentTeams package
38+
run: python scripts/build_agentteams_package.py
39+
- uses: actions/upload-artifact@v4
40+
with:
41+
name: devflow-worker-python-${{ matrix.python-version }}
42+
path: dist/devflow-worker.zip
43+
if-no-files-found: error
44+

‎.gitignore‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
.env
2+
.venv/
3+
.devflow/
4+
.pytest_cache/
5+
.mypy_cache/
6+
.ruff_cache/
7+
__pycache__/
8+
*.py[cod]
9+
*.egg-info/
10+
build/
11+
dist/
12+
htmlcov/
13+
.coverage
14+
logs/
15+

‎CHANGELOG.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Changelog
2+
3+
All notable changes follow semantic versioning.
4+
5+
## 1.0.0 - 2026-07-24
6+
7+
- Added a six-agent AgentTeams software-delivery design.
8+
- Added six self-contained Skill v2 packages with executable quality gates.
9+
- Added typed, digest-checked inter-agent hand-offs.
10+
- Added isolated regression testing, security approval policy, audit design,
11+
and terminal experience distillation.
12+
- Added a credential-free deterministic demonstration and AgentTeams worker
13+
package builder.
14+

‎CONTRIBUTING.md‎

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
# Contributing to DevFlow
2+
3+
Contributions should preserve DevFlow's evidence-first and least-privilege
4+
design. Open an issue before changing an artifact schema, approval rule, or
5+
Agent boundary.
6+
7+
## Development check
8+
9+
Use Python 3.10 through 3.12 and run:
10+
11+
```powershell
12+
python -m pip install -e ".[dev]"
13+
ruff check .
14+
mypy src scripts tests
15+
pytest -q
16+
python scripts/evaluate_skills.py
17+
python -m devflow.cli demo
18+
```
19+
20+
## Skill changes
21+
22+
- Keep `SKILL.md` focused on the operational procedure.
23+
- Put detailed contracts and examples one level below `references/`.
24+
- Update the semantic contract version when behavior changes.
25+
- Add deterministic success, failure, and boundary tests.
26+
- Do not weaken a security or human-approval gate to make an evaluation pass.
27+
- Regenerate `agents/openai.yaml` when discovery metadata changes.
28+
29+
Pull requests must explain the user-visible effect, risk, verification
30+
evidence, compatibility impact, and rollback path.
31+

‎LICENSE‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
Apache License
2+
Version 2.0, January 2004
3+
http://www.apache.org/licenses/
4+
5+
Copyright 2026 DevFlow contributors
6+
7+
Licensed under the Apache License, Version 2.0 (the "License");
8+
you may not use this file except in compliance with the License.
9+
You may obtain a copy of the License at
10+
11+
http://www.apache.org/licenses/LICENSE-2.0
12+
13+
Unless required by applicable law or agreed to in writing, software
14+
distributed under the License is distributed on an "AS IS" BASIS,
15+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16+
See the License for the specific language governing permissions and
17+
limitations under the License.
18+

‎README.md‎

Lines changed: 127 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,127 @@
1+
# DevFlow
2+
3+
DevFlow is an auditable multi-agent system for resolving software issues from
4+
intake to a reviewed pull request. It is built for the **Agent Infra** track of
5+
the Global Open-source AI Challenge and maps its domain agents onto the
6+
[AgentTeams](https://github.com/agentscope-ai/AgentTeams) Manager–Team–Worker
7+
runtime.
8+
9+
The project is intentionally a controlled workflow rather than an unrestricted
10+
agent swarm:
11+
12+
```text
13+
Issue → Triage → Locate → Code → Test → Review → Approval / PR
14+
↑ │ │
15+
└────────┴───────┘ feedback loop
16+
```
17+
18+
Every stage has a structured input/output contract, explicit failure behavior,
19+
security boundaries, and an event trail. T4/T5 changes stop for recorded human
20+
approval.
21+
22+
## What works now
23+
24+
- Six domain agents: Team Leader, Triage, Locator, Coder, Tester, Reviewer.
25+
- Typed event bus and lifecycle events for local execution.
26+
- AST-aware code indexing and an experience store backed by ChromaDB.
27+
- OpenAI-compatible LLM client with Pydantic response validation.
28+
- MCP boundaries for GitHub and isolated CI/CD tools.
29+
- Structured logs, OpenTelemetry spans, and in-memory metrics.
30+
- Credential-free offline demo that applies a real candidate patch in a
31+
temporary repository, executes a real regression test, reviews the result,
32+
and writes a JSON evidence report.
33+
- AgentTeams `Team` manifest and six self-contained Skill v2 packages with
34+
typed contracts, deterministic validators, UI metadata, examples, and
35+
release/rollback policy.
36+
- Integrity-checked `HandoffEnvelope` collaboration with versioned artifacts,
37+
idempotency keys, and SHA-256.
38+
39+
## Quick start
40+
41+
Python 3.10–3.12 is recommended.
42+
43+
```powershell
44+
py -3.10 -m venv .venv
45+
.\.venv\Scripts\python -m pip install -e ".[dev]"
46+
.\.venv\Scripts\devflow validate
47+
.\.venv\Scripts\devflow demo
48+
.\.venv\Scripts\python -m pytest
49+
```
50+
51+
The demo does not need an API key or GitHub token. It:
52+
53+
1. classifies the bundled calculator issue;
54+
2. retrieves and identifies the faulty function;
55+
3. produces a structured one-line patch;
56+
4. copies the fixture repository to a temporary sandbox;
57+
5. proves that the baseline fails and the candidate passes;
58+
6. performs the review/approval gate;
59+
7. distills and stores a provenance-linked reusable experience;
60+
8. stores the full event and result evidence under `.devflow/runs/`.
61+
62+
Production mode uses variables from `.env.example`. Copy it to `.env` and
63+
provide only the credentials required by the integrations you enable.
64+
Install the persistent ChromaDB-backed RAG implementation with
65+
`python -m pip install -e ".[rag]"`; the credential-free demo does not require
66+
that heavier optional dependency.
67+
68+
## AgentTeams deployment
69+
70+
DevFlow targets AgentTeams `agentteams.io/v1beta1`.
71+
72+
```powershell
73+
.\.venv\Scripts\python scripts\build_agentteams_package.py
74+
```
75+
76+
Copy `dist/devflow-worker.zip` into the AgentTeams Manager/controller at
77+
`/tmp/devflow-worker.zip`, then apply:
78+
79+
```bash
80+
agentteams-apply.sh -f agentteams/team.yaml
81+
```
82+
83+
The manifest creates one Team Leader and five workers. AgentTeams supplies the
84+
Matrix room topology, task delegation, heartbeat/state reconciliation, shared
85+
storage, and credential isolation. DevFlow supplies the software-engineering
86+
roles, reusable Skills, schemas, gates, and evidence.
87+
88+
## Project layout
89+
90+
```text
91+
agentteams/ AgentTeams v1beta1 Team manifest and package template
92+
config/ agent, skill, security, MCP, observability configuration
93+
docs/ research notes and competition scorecard
94+
examples/ deterministic regression scenario
95+
skills/ distributable SKILL.md specifications
96+
src/devflow/ runtime, agents, models, RAG, CLI
97+
tests/ unit and end-to-end tests
98+
```
99+
100+
## Verification
101+
102+
```powershell
103+
.\.venv\Scripts\python -m ruff check src tests examples
104+
.\.venv\Scripts\python -m mypy src
105+
.\.venv\Scripts\python -m pytest --cov=devflow --cov-report=term-missing
106+
.\.venv\Scripts\python scripts\evaluate_skills.py
107+
.\.venv\Scripts\devflow demo
108+
```
109+
110+
See [the research basis](docs/RESEARCH.md), [competition scorecard](docs/SCORECARD.md),
111+
[Skill engineering standard](docs/SKILL_ENGINEERING.md), and
112+
[AgentTeams mapping](docs/AGENTTEAMS.md) for design rationale and remaining work.
113+
114+
## Security
115+
116+
- Workers receive gateway-scoped consumer credentials, not raw provider keys.
117+
- Generated paths must remain repository-relative.
118+
- Secret-shaped output and dangerous execution patterns are blocked.
119+
- Test execution occurs in a temporary copy in the offline demo.
120+
- CI failure and high/critical findings block promotion.
121+
- T4/T5 issues always require a human approval event.
122+
123+
Never commit `.env`, runtime evidence containing private code, or real tokens.
124+
125+
## License
126+
127+
Apache-2.0. See [LICENSE](LICENSE).

‎SECURITY.md‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# Security policy
2+
3+
Do not open a public issue containing a vulnerability, credential, private
4+
repository content, or personal data. Report sensitive findings privately to
5+
the repository owner through GitHub's private vulnerability reporting feature.
6+
7+
DevFlow treats issues, source code, retrieved text, tool output, and model
8+
responses as untrusted input. Expected invariants include:
9+
10+
- credentials never enter prompts, logs, commits, or evidence artifacts;
11+
- repository writes remain branch-scoped and repository-relative;
12+
- candidate execution occurs only in isolation;
13+
- red CI and high/critical findings block promotion;
14+
- T4 and T5 changes require recorded human approval;
15+
- inter-agent artifacts are versioned and integrity checked.
16+
17+
Include affected version, reproduction steps, impact, and a proposed
18+
containment measure. Do not include real secrets in a proof of concept.
19+

0 commit comments

Comments
 (0)