Skip to content

feat(cli): every put names its images <id>__<role>, as a bundle does - #70

Merged
earakely-scale merged 2 commits into
mainfrom
edgararakelyan/put-image-ids
Oct 6, 2026
Merged

earakely-scale merged 2 commits into
mainfrom
edgararakelyan/put-image-ids

Conversation

@earakely-scale

@earakely-scale earakely-scale commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Every put command now names the images it writes <id>__<role>, the way a bundle names the same image, so a put with an @local --id works.

Why

The put commands named their images with a prefix in front of the env's or agent's id. A derived id has to keep its base's namespace, so a prefix in front of an @local id is refused (id 'mcp-server-@local/…' contains an @local id but isn't one). The refusal came after the docker build had run. Bundles already name implied images with derive_id, so the same image had two names depending on how it was written.

What changes

put before after
env mcp-server put --id crm mcp-server-crm crm__env_image
env website put --id shop website-backend-shop, website-frontend-shop shop__backend_image, shop__frontend_image
a2a-agent put --id solver a2a-agent-solver solver__agent_image
env gateway put --id default gateway-default default__env_image
env service-db put --id default-db service-db-…, db-web-…, db-mcp-default-db default-db__db_image, __db_web_image, __db_mcp_image
env website-browser put --id website-browser website-browser-website-browser website-browser__env_image
  • GitHub builds. MCPServerEnv.put_from_github and WebsiteEnv.put_from_github use the same ids.
  • Bootstrap. A run's infra bootstrap uses the same ids, since it calls the same put functions.
  • Local tags. Each local build is tagged with the id's image repository (image_repository), so an @local id builds under a valid reference. The infra builds keep their fixed tags.
  • Role names. They're the ones the bundle resolver derives: env_image for an env's image key, agent_image for an agent's, and the key itself for a website's backend_image / frontend_image.

Compatibility

  • Stored envs and agents keep resolving. They name their images by {id, version}, and a deploy uses the image's stored image_name. Nothing re-derives an image id from an env id.
  • A put of an existing env starts a new image lineage. Its image is written as v1 under the new id, with its own image repository. Putting a brand-new env already created a repository, so this needs no new permission.
  • Nothing in this repo matches on the old prefixes. The only a2a-agent-* match left is the agent-container fallback in sandbox_utils, which matches container names, not image ids.

Tests

  • The put tests now expect the new ids and tags: build platform, the GitHub token forwarding, and the infra puts' config defaults.
  • New: a2a-agent put, env mcp-server put and env website put with an @local --id, through the real artifact store and namespace routing, with docker stubbed. Each builds under local/… tags and writes its images under ids derived from the @local id, all in the @local namespace's store.
  • Unit tier: 5,859 passed.

Release

Hot path: images built through the GitHub build paths get the new names once consumers pin this release. It needs the bump-version label and the usual production smoke after the release.

🤖 Generated with Claude Code

RetriggerConfidence Score: 5/5

The PR appears safe to merge, though the local put test still skips image publication.

Fix All in CursorFindings

  1. P2 Local put test skips publication ▶
Fix with agent prompt
### Issue 1
tst/unit/store/local_id_acceptance_test.py:285-286
The new `@local` put test replaces `DockerImageArtifact.put` with `put_tar`, so it skips the image store and registry path this change relies on. It checks build tags and artifact IDs, but not the saved image reference or the registered env or agent. Add checks for those results so a routing or publication mistake cannot pass unnoticed.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

Put commands now name images by combining the owner id with the image’s role, matching bundle resolution. Local builds also use valid image tags for @local ids, and infra bootstrap uses the same role-based naming.

  • Put commands save images under ids built from the owner and role.
  • Infra bootstrap saves images under ids built from each env and image role.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Put command] --> B[Derive image IDs]
  B --> C[Check owner and image IDs]
  C --> D[Build images]
  D --> E[Save image artifacts]
  E --> F[Register env or agent]
Loading

Reviews (2) · Last reviewed commit: "fix(cli): check a put's ids before it bu..."

The put commands named their images with a prefix: mcp-server-<id>, website-backend-<id> and
website-frontend-<id>, a2a-agent-<id>, gateway-<id>, service-db-, db-web- and db-mcp-<id>, and
website-browser-<id>. Since derived ids keep their base's namespace, a prefix in front of an
@Local id isn't one, so a put with an @Local --id was refused, after its docker build had run.

Every put now derives its image ids with derive_id, using the roles a bundle uses for the same
image: env_image, backend_image / frontend_image, agent_image, and db_image / db_web_image /
db_mcp_image for the service-db. The GitHub builds the hub calls do the same. Each local build
is tagged with the id's image repository, so an @Local id builds under a valid reference.

Stored envs and agents keep resolving, since they name their images by id and version. A put
of an existing env starts its image's versions again under the new id.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@earakely-scale

Copy link
Copy Markdown
Collaborator Author

Verification on 40d684c

Real puts and runs on macOS arm64 with Docker, from fresh state roots, on the local stores and the local sandbox provider.

check result
env mcp-server put / env website put, bare ids images slack__env_image, shop__backend_image, shop__frontend_image, tagged locally under those names
agent-env run on a bundle deploying both the infra bootstrap writes default__env_image, default-db__db_image / __db_web_image / __db_mcp_image and website-browser__env_image; both deploys pass
env mcp-server put --id @local/~/…/envs/crm builds under local/…-env-image-<hash>, writes @local/~/…/envs/crm__env_image; a bundle task deploying the env passes
a2a-agent put, bare and @local echo__agent_image and @local/~/…/agents/echo__agent_image; a bundle deploys and prompts both, and each replies as expected
envs put by v0.9.1270 under the old ids still deploy; a re-put writes env v2 on slack__env_image v1, leaves mcp-server-slack v1 in place, and deploys
the same @local put on v0.9.1270 fails at docker build: invalid tag "mcp-server-@local/…": invalid reference format

No sandbox folder or container was left after any run.

Not run locally: the GitHub build path (it needs a remote VM; its ids are covered by the unit test) and a registry other than the local one.

@earakely-scale
earakely-scale marked this pull request as ready for review October 6, 2026 17:50
@earakely-scale
earakely-scale requested a review from a team as a code owner October 6, 2026 17:50
Comment thread src/agent_env/cli/a2a_agent/put.py
Comment on lines +285 to +286
monkeypatch.setattr(DockerImageArtifact, "put", classmethod(lambda cls, id, *, description, image_name, **kwargs: (
cls.put_tar(id, description=description, image_name=image_name, tar_gz_s3_url=tarball))))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Local put test skips publication

The new @local put test replaces DockerImageArtifact.put with put_tar, so it skips the image store and registry path this change relies on. It checks build tags and artifact IDs, but not the saved image reference or the registered env or agent. Add checks for those results so a routing or publication mistake cannot pass unnoticed.

Knowledge Base Used: Container images and composition

Prompt To Fix With AI
This is a comment left during a code review.
Path: tst/unit/store/local_id_acceptance_test.py
Line: 285-286

Comment:
**Local put test skips publication**

The new `@local` put test replaces `DockerImageArtifact.put` with `put_tar`, so it skips the image store and registry path this change relies on. It checks build tags and artifact IDs, but not the saved image reference or the registered env or agent. Add checks for those results so a routing or publication mistake cannot pass unnoticed.

**Knowledge Base Used:** [Container images and composition](https://app.greptile.com/scale-ai/-/custom-context/knowledge-base/scaleapi/agentenv-framework/-/docs/container-images-and-composition.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added in c08585c: the test now checks each saved image name and that the registered env or agent names the derived images. The real push to the local registry is covered by an end-to-end run, in the verification comment: the @Local mcp-server and a2a-agent puts write localhost:5000/local/… images, and a bundle deploys both.

…put registers

An @Local id as long as one may be leaves no room for the image's suffix, and the
image id was refused only once the image had been built. The building puts now
check the env's or agent's id and each image id against the store they're written
to before they build.

The @Local put test now also checks the saved image names and the env or agent the
put registers over its images.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@earakely-scale
earakely-scale merged commit 7d1eeea into main Oct 6, 2026
13 checks passed
@earakely-scale
earakely-scale deleted the edgararakelyan/put-image-ids branch October 6, 2026 20:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant