Add a github-app connection whose tokens gete issues itself - #83
Merged
Merged
Conversation
Some agents need to read the same repositories whoever calls them, and a per-user token forwarded by Gemini Enterprise cannot give them that. A GitHub App installation token can, but until now the only way to use one was a python tool holding its own credential, outside the connection's host check and the openapi block's operations, params, and does_not. The new connection kind keeps every one of those guards: the token is issued from the App's private key inside gete's client, narrowed on every issue to the repositories and permissions gete.yaml declares, and sent only to the connection's hosts. Nobody approves anything, so register creates no authorization and the agent offers no reauthorization tool; a missing key or a refused issue reaches the user as text. The key is delivered like secret_env, so an agent cannot swap it for its own. MCP blocks are refused for now: ADK reads MCP headers synchronously, while issuing a token is a request of its own. 🤖 Generated with Claude Code
…bots An app connection acts as the App for whoever calls the agent, the same trust model as a shared credential, but gete graph drew it like a connection carrying the caller's authorization. It is now marked (bot). The private key could issue a token with the installation's whole grant, above the ceiling gete.yaml declares. Left in GETE_APP_KEY_*, any tool reading its settings, and any process it starts, would find it. The agent build now takes it out of the environment before the agent's own modules are imported. This is not a sandbox against code in the same process, which the README now says. A bare app_id in YAML is read as a number, and the schema refused it although the loader already turned it into a string; both forms are accepted now. 🤖 Generated with Claude Code
Collaborator
Author
|
Pushed ddbd9f5 with three follow-ups:
|
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
github-app, a catalog connection whose tokens gete issues itself from a GitHub App's private key, instead of receiving a user's token from Gemini Enterprise. Agents use it from ordinaryopenapiblocks (and python tools throughConnectionClient), sooperations,params,does_not, and the host check apply exactly as they do today.What gete does for such a connection
iatbackdated 60s, valid for under 10 minutes) and finds the installation from the first permitted repository the App is installed on (GET /repos/{owner}/{repo}/installation).POST /app/installations/{id}/access_tokenswithrepositoriesandpermissions) and reuses it in-process until 5 minutes beforeexpires_at. A 401 from the service drops the cached token so the next request gets a fresh one.registerskips the connection,--reset-authorizationdoes not accept it, and no reauthorization tool is offered. A missing key or a refused issue is reported to the user as text (status code only; response bodies and key contents never appear).secret_env.private_key_secretis wired into the Terraform module call asGETE_APP_KEY_<CONNECTION>, which the agent may not set itself;validate --check-secretschecks it. The App ID and the ceiling travel in the resolved declaration.Schema and validation
oauthorapp.appopen (like{base_url});validaterefuses an agent holding it untilapp_id,private_key_secret,repositories, andpermissionsare set.permissionsis required so a token never carries the installation's whole grant.repositoriesmust share one owner, since a token comes from one installation.mcpblocks on an app connection are refused. MCP is left for a follow-up: ADK reads MCP headers synchronously, while issuing a token is a request of its own.Other changes
gete connections github-appdescribes the App, key secret, delivery variable, and ceiling instead of OAuth client details.gete runno longer asks forGETE_TOKEN_*for app connections; the issuer reads the PEM fromGETE_APP_KEY_*.cryptographyis declared as a direct dependency (already installed through ADK) since gete now signs the JWT itself.Test plan
uv run pytest(934 passed)uv run mypyuv run ruff check/uv run ruff format --check