Builds on the v0.8.2 runtime. Four workstreams, all behind the §15 MCP door:
- Group rooms (Phase 1): migration 0026; N-way threads repo with a DM/room
count-guard; chat.send {room} + room.create/invite/leave tools; RoomMessage
-> room.message SSE; /api/claw-chat/rooms* APIs; Observer room badge.
- Per-claw door identity: door caller_agent resolves the X-ZeroClaw-Agent
header (set by the fork) to the specific claw, falling back to roster[0].
- Gated delegation bridge (Phase 3): clawmates__delegate door tool drives a
sibling via the existing /ws/chat ZeroClawDriveExecutor (not A2A); self-deny,
per-workspace hourly budget, audit trail, untrusted-banner result. Native
in-daemon delegation stays off (it would bypass the door).
- A2A tenant ingress (Phase 2): migration 0027 (workspace_a2a + a2a_tokens);
runtime_provision enable_a2a_server/publish_claw; routes/a2a.rs tenant-aware
proxy (per-workspace tokens, injected internal bearer, daemon stays internal,
cards URL-rewritten to the cm-api edge); a2a.invoked taxonomy.
Tests: cm-db room repos, cm-runtime chat tools, door units. sqlx cache updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
32 lines
1.4 KiB
SQL
32 lines
1.4 KiB
SQL
-- Phase 2: A2A tenant-aware ingress.
|
|
-- We expose ZeroClaw's spec-conforming Agent2Agent server, but ONLY via cm-api's
|
|
-- edge: the raw daemon (:42617) stays internal. These tables hold per-workspace
|
|
-- opt-in + the external bearer tokens cm-api checks before proxying a task to the
|
|
-- daemon (injecting the internal ZEROCLAW_TOKEN itself).
|
|
|
|
CREATE TABLE workspace_a2a (
|
|
workspace_id UUID PRIMARY KEY REFERENCES workspaces (id) ON DELETE CASCADE,
|
|
enabled BOOLEAN NOT NULL DEFAULT false,
|
|
-- The edge base URL advertised in discovery cards (points at cm-api, never
|
|
-- the daemon), e.g. https://api.clawmates.work/api/a2a/<workspace>.
|
|
public_base_url TEXT,
|
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
|
updated_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
|
);
|
|
|
|
CREATE TABLE a2a_tokens (
|
|
id UUID PRIMARY KEY,
|
|
workspace_id UUID NOT NULL REFERENCES workspaces (id) ON DELETE CASCADE,
|
|
-- NULL = any published alias in the workspace; else this token may only
|
|
-- invoke the named claw alias.
|
|
alias TEXT,
|
|
token UUID NOT NULL UNIQUE,
|
|
exposed_skills TEXT[] NOT NULL DEFAULT '{}',
|
|
enabled BOOLEAN NOT NULL DEFAULT true,
|
|
label TEXT,
|
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
|
last_used_at TIMESTAMPTZ
|
|
);
|
|
|
|
CREATE INDEX a2a_tokens_workspace ON a2a_tokens (workspace_id);
|