Skip to content

feat(audit): add durable agent loop tracing - #142

Closed
geminixiang wants to merge 2 commits into
mainfrom
feat/agent-audit-trace
Closed

geminixiang wants to merge 2 commits into
mainfrom
feat/agent-audit-trace

Conversation

@geminixiang

Copy link
Copy Markdown
Owner

Summary

Adds a deployment-owned, metadata-only agent-loop audit subsystem and a dedicated Admin Audit view.

  • creates the top-level runId at runtime admission and correlates Sentry, runner, harness, tools, logical model requests, compaction, retry, budgets, Session Dream, and child subagents
  • stores immutable typed events plus run/tool/model projections in <state-dir>/audit/audit.sqlite
  • keeps SQLite off the agent hot path with a bounded non-throwing queue and one worker-thread writer
  • adds WAL/busy handling, exclusive schema migration, owner-only file modes, run-coherent 90-day retention, health/degraded counters, and bounded shutdown
  • adds Admin filters for conversation, run ID, tool, status, and time, with keyset run pagination and a backward-pageable complete run timeline
  • deliberately stores no prompts, completions, thinking, tool arguments/results, provider payloads/headers, images, file bodies, terminal output, or free-form error messages

Architecture rationale and Codex rollout-trace research are captured in:

  • docs/adr/0006-durable-agent-audit-and-diagnostic-traces.md
  • docs/research/mikan-agent-audit-trace-architecture.md

How I tested

  • npm run lint
  • npm run fmt:check
  • npm run knip
  • npm run build
  • npm test — 121 files / 1770 tests
  • Manual verification

Manual verification:

  • built-distribution worker smoke test against dist/audit/worker.js
  • 20 consecutive dual-store concurrent first-boot/WAL startup checks
  • architecture TOML/reference/Markdown-link validation
  • Admin inline JavaScript syntax compilation in tests
  • byte-for-byte verification that the unrelated untracked research file was excluded

Notes for reviewers

  • This is the run-centered Phase 1 described in the research: indexed run search plus pageable per-run events. Cross-run event search is intentionally deferred.
  • Codex-like raw diagnostic capture is intentionally not included. It needs separate opt-in enablement, retention, authorization, and evidence policy.
  • node:sqlite still emits Node's experimental-feature warning on the supported Node releases; no new dependency was added.
  • Audit write/serialization/worker failures never change the agent outcome. Loss is surfaced through Audit health and drop/degraded counters.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Deploying mikan with  Cloudflare Pages  Cloudflare Pages

Latest commit: 748166b
Status: ✅  Deploy successful!
Preview URL: https://e5b2c96e.mikan-1wv.pages.dev
Branch Preview URL: https://feat-agent-audit-trace.mikan-1wv.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant