Skip to content

feat(ci): promote Deep Agents Code managed image pointers - #11342

Closed
zac-wang-nv wants to merge 1 commit into
NVIDIA:mainfrom
zac-wang-nv:feat/publish-dcode-managed-image
Closed

zac-wang-nv wants to merge 1 commit into
NVIDIA:mainfrom
zac-wang-nv:feat/publish-dcode-managed-image

Conversation

@zac-wang-nv

@zac-wang-nv zac-wang-nv commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Publishes the complete Deep Agents Code managed image (ghcr.io/nvidia/nemoclaw/langchain-deepagents-code-sandbox) with :<revision> and :<release> consumer pointers, alongside openclaw-sandbox and hermes-sandbox (#11228/#11298), from the promote lane that already builds and stages it.

Resolves #11341.

Related Issue

#11341 — filed with the product-scope fields (ownership, validation plan, compatibility, security) this PR implements. Follows the same pattern as #11228 → #11298 for Hermes.

What already existed vs what changes

  • The six-candidate barrier already builds, validates, attests, stages, and anonymously pull-proves the Deep Agents Code cohort on both architectures; the durable cohort contract already records it.
  • Stock Deep Agents Code onboarding is already buildless by exact digest — the quickstart states stock onboarding "normally uses the release's exact managed-image digest."
  • SHIPPED_MANAGED_IMAGE_AGENTS in src/lib/onboard/managed-image/contract.ts already names langchain-deepagents-code a shipped agent (only pi is a candidate).
  • The only gap was the consumer pointers: all 370 registry tags are cohort-ghrun-* or buildcache — nothing a downstream nemo-deepagents onboard --from Dockerfile can FROM by name. This PR closes that, and with it the inconsistency that the workflow's pointer set was narrower than the source contract's shipped-agent list.

Changes

  • .github/workflows/managed-images.yaml: shipped_agents=(openclaw hermes) → (openclaw hermes langchain-deepagents-code) at both the staging (alias-recording) and pointer-promotion sites; the exact-reference repository pattern widened accordingly; comments point at Publish the complete Deep Agents Code managed image (ghcr.io/nvidia/nemoclaw/langchain-deepagents-code-sandbox) like openclaw-sandbox and hermes-sandbox #11341 and the source contract, and preserve the post-test(ci): refresh current main contracts #11332 registry-failure reconciliation note.
  • test/inference/managed/managed-image-publication-promotion.test.ts: proves the Deep Agents Code pointer moves only after all cohort aliases stage, and that a failed barrier moves no pointer for any agent.
  • test/inference/managed/managed-image-publication-workflow.test.ts: source-shape assertions follow the three-agent list.
  • docs/get-started/quickstart-langchain-deepagents-code.mdx: the custom-image path documents FROM ghcr.io/nvidia/nemoclaw/langchain-deepagents-code-sandbox@sha256:<digest> with digest pinning.

Type of Change

  • Code change with doc updates

Quality Gates

  • Tests added or updated for changed behavior
  • Docs updated for user-facing behavior changes
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding)
  • Sensitive-path review completed or maintainer-approved waiver recorded — requesting maintainer review, same rationale as feat(ci): promote Hermes managed image pointers alongside OpenClaw #11298: widens what is published (one more already-validated artifact gains consumer tags), not how — barrier ordering and fail-closed validations unchanged, applied per shipped agent before any pointer moves.
  • Non-success, skipped, or missing CI check accepted by maintainer:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: docs-updated
  • Evidence: stating plainly the subagent was not run; happy to run it if maintainers require the receipt.
  • Agent: Claude Code

Verification


Signed-off-by: Zac Wang zacw@nvidia.com

Summary by CodeRabbit

  • New Features

    • Added LangChain Deep Agents Code to the shipped managed sandbox images.
    • Deep Agents Code images now support cohort, release, revision, and digest-based references.
    • Promotion and validation workflows now include Deep Agents Code alongside OpenClaw and Hermes.
  • Documentation

    • Updated the quickstart guide with instructions for using the pinned Deep Agents Code sandbox image.
    • Documented the corresponding release and revision tags for custom Dockerfiles.

Extends the shipped-agent pointer set from (openclaw hermes) to include
langchain-deepagents-code at both managed-images.yaml sites, so the
promote lane records and moves :<revision> and :<release> consumer
pointers for the Deep Agents Code image it already builds, validates,
attests, and stages in the six-candidate cohort barrier (NVIDIA#11341).

Stock Deep Agents Code onboarding already consumes this image buildless
by exact digest, and SHIPPED_MANAGED_IMAGE_AGENTS already names the
agent shipped; only the consumer pointers were missing, so downstream
custom images (nemo-deepagents onboard --from) had nothing to FROM by
name. This aligns the workflow's pointer set with the source contract's
shipped-agent list.

The publication tests now prove the Deep Agents Code pointer moves only
after all cohort aliases stage and that a barrier failure moves no
pointer for any agent. The quickstart documents starting custom images
FROM the published image.

Signed-off-by: Zac Wang <zacw@nvidia.com>
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: ebb4b3ff-d144-46f9-8ced-f2e0c3ad97bf

📥 Commits

Reviewing files that changed from the base of the PR and between a89af34 and 532622e.

📒 Files selected for processing (4)
  • .github/workflows/managed-images.yaml
  • docs/get-started/quickstart-langchain-deepagents-code.mdx
  • test/inference/managed/managed-image-publication-promotion.test.ts
  • test/inference/managed/managed-image-publication-workflow.test.ts

Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

Deep Agents Code is added to the managed-image publication set. The workflow promotes its cohort, release, and revision pointers, validates its image repository, updates publication tests, and documents digest-pinned custom-image usage.

Changes

Managed-image publication

Layer / File(s) Summary
Publication workflow
.github/workflows/managed-images.yaml
The workflow includes langchain-deepagents-code in shipped-agent alias staging, durable pointer promotion, and exact cohort reference validation.
Publication validation and onboarding guidance
test/inference/managed/managed-image-publication-promotion.test.ts, test/inference/managed/managed-image-publication-workflow.test.ts, docs/get-started/quickstart-langchain-deepagents-code.mdx
Tests verify Deep Agents Code pointer promotion and ordering. The quickstart documents digest-pinned custom-image usage and release and revision tags.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 53262

This change publishes Deep Agents Code release and revision image pointers alongside the existing managed images, enabling digest-pinned custom image builds. The workflow and publication tests cover the added promotion path, with no remaining merge-blocking risk identified.

Sequence Diagram(s)

sequenceDiagram
  participant ManagedImagesWorkflow
  participant CohortValidation
  participant GHCRRegistry
  ManagedImagesWorkflow->>CohortValidation: validate Deep Agents Code exact cohort reference
  CohortValidation-->>ManagedImagesWorkflow: accept validated cohort
  ManagedImagesWorkflow->>GHCRRegistry: stage Deep Agents Code cohort aliases
  ManagedImagesWorkflow->>GHCRRegistry: promote Deep Agents Code release and revision pointers
Loading

Suggested reviewers: prekshivyas, cv

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the primary change: promoting Deep Agents Code managed-image pointers in CI.
Linked Issues check ✅ Passed The changes satisfy issue #11341 by adding Deep Agents Code to managed-image staging and pointer promotion, extending publication validation and fail-closed tests, and documenting digest-pinned custom…
Out of Scope Changes check ✅ Passed All changes are within the linked issue scope: workflow publication, matching tests, and documentation. No Dockerfile, runtime, or onboarding behavior changes are included.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@wscurran wscurran added area: ci CI workflows, checks, release automation, or GitHub Actions area: packaging Packages, images, registries, installers, or distribution feature PR adds or expands user-visible functionality integration: dcode LangChain Deep Code integration behavior labels Sep 10, 2026
ericksoa added a commit that referenced this pull request Sep 28, 2026
Publish Deep Agents Code release and revision image tags through the existing managed-image promotion workflow. Retain all cohort, digest, and durable-evidence checks.

Replay Zac Wang's contribution from #11342 on an NVIDIA-owned branch so the required reviewed SDK CI can run. The original four-file implementation is preserved. Add one focused release-alias regression and fixture support; production behavior is unchanged from the original contribution.

Validated commit: 61ca6bc. Forty focused tests, required CI, managed-image qualification, and self-hosted qualification passed.

Resolves #11341. Supersedes #11342.

Co-authored-by: Zac Wang <zacw@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@ericksoa

Copy link
Copy Markdown
Member

Thanks, Zac. Your change has landed through #12371, with your authorship and contribution preserved. The original fork could not receive the reviewed OpenShell SDK required by CI, so we replayed the original change, with one additional release-tag regression test on an NVIDIA-owned branch.

The replacement passed CI, the 40 focused publication tests, documentation validation, and managed-image qualification before merging. Closing this PR as delivered by #12371. Release tags will be published through the normal trusted release workflow.

@ericksoa ericksoa closed this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci CI workflows, checks, release automation, or GitHub Actions area: packaging Packages, images, registries, installers, or distribution feature PR adds or expands user-visible functionality integration: dcode LangChain Deep Code integration behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish the complete Deep Agents Code managed image (ghcr.io/nvidia/nemoclaw/langchain-deepagents-code-sandbox) like openclaw-sandbox and hermes-sandbox

3 participants