Skip to content

feat(#4477): add caData, skipTLSVerify to OgxEntityProviderConfig - #4574

Open
fullsend-ai-coder[bot] wants to merge 7 commits into
mainfrom
agent/4477-ogx-tls-config
Open

feat(#4477): add caData, skipTLSVerify to OgxEntityProviderConfig#4574
fullsend-ai-coder[bot] wants to merge 7 commits into
mainfrom
agent/4477-ogx-tls-config

Conversation

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor

Add per-provider TLS connection settings to the OGX catalog entity provider so OgxModelEntityProvider can fetch /v1/models from OGX endpoints that use a private CA or self-signed certificates.

Changes:

  • types.ts: add optional caData and skipTLSVerify fields
  • module.ts: read both fields from both config paths
  • OgxModelEntityProvider.ts: use undici Agent dispatcher for TLS;
    skipTLSVerify takes precedence with warning logged
  • package.json: add undici dep, @backstage/config devDep
  • module.test.ts: new config parsing tests
  • OgxModelEntityProvider.test.ts: TLS test suite
  • app-config.yaml: commented TLS examples
  • changeset: minor bump for ogx-entity-provider

OgxAgentEntityProvider is unchanged (no outbound requests).


Closes #4477

Post-script verification

  • Branch is not main/master (agent/4477-ogx-tls-config)
  • Secret scan passed (gitleaks — 193b36a397eeaa92f836ff2085060f645ba81644..HEAD)
  • Pre-commit hooks passed (authoritative run on runner)
  • Tests ran inside sandbox

Add per-provider TLS connection settings to the OGX catalog entity
provider so OgxModelEntityProvider can fetch /v1/models from OGX
endpoints that use a private CA or self-signed certificates.

Changes:
- types.ts: add optional caData and skipTLSVerify fields
- module.ts: read both fields from both config paths
- OgxModelEntityProvider.ts: use undici Agent dispatcher for TLS;
  skipTLSVerify takes precedence with warning logged
- package.json: add undici dep, @backstage/config devDep
- module.test.ts: new config parsing tests
- OgxModelEntityProvider.test.ts: TLS test suite
- app-config.yaml: commented TLS examples
- changeset: minor bump for ogx-entity-provider

OgxAgentEntityProvider is unchanged (no outbound requests).

Closes #4477
@fullsend-ai-coder fullsend-ai-coder Bot added the ready-for-review Agent PR ready for human review label Sep 3, 2026
@rhdh-gh-app

rhdh-gh-app Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

This PR includes changes that affect public-facing API. Please ensure you are adding/updating documentation for new features or behavior.

Changed Packages

Package Name Package Path Changeset Bump Current Version
@red-hat-developer-hub/backstage-plugin-ogx-entity-provider workspaces/boost/plugins/ogx-entity-provider minor v0.4.0

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:38 PM UTC · Completed 7:51 PM UTC

Commit: 51201df · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Cost: $5.53

@codecov

codecov Bot commented Sep 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 62.39%. Comparing base (193b36a) to head (e02480b).
⚠️ Report is 3 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #4574      +/-   ##
==========================================
+ Coverage   62.36%   62.39%   +0.02%     
==========================================
  Files        2607     2607              
  Lines      104739   104772      +33     
  Branches    29433    29441       +8     
==========================================
+ Hits        65325    65374      +49     
+ Misses      37584    37568      -16     
  Partials     1830     1830              
Flag Coverage Δ *Carryforward flag
adoption-insights 84.77% <ø> (ø) Carriedforward from 14be65f
ai-integrations 78.80% <ø> (ø) Carriedforward from 14be65f
app-defaults 56.22% <ø> (ø) Carriedforward from 14be65f
augment 46.67% <ø> (ø) Carriedforward from 14be65f
boost 81.04% <100.00%> (+0.53%) ⬆️
bulk-import 73.12% <ø> (ø) Carriedforward from 14be65f
cost-management 13.35% <ø> (ø) Carriedforward from 14be65f
dcm 73.47% <ø> (ø) Carriedforward from 14be65f
e2e-adoption-insights 60.00% <ø> (ø) Carriedforward from 14be65f
e2e-extensions 62.32% <ø> (ø) Carriedforward from 14be65f
e2e-global-header 50.35% <ø> (ø) Carriedforward from 14be65f
e2e-homepage 61.11% <ø> (ø) Carriedforward from 14be65f
e2e-intelligent-assistant 47.04% <ø> (ø) Carriedforward from 14be65f
e2e-orchestrator 49.52% <ø> (ø) Carriedforward from 14be65f
e2e-orchestrator-plugin 49.51% <ø> (ø) Carriedforward from 14be65f
e2e-quickstart 55.21% <ø> (ø) Carriedforward from 14be65f
e2e-scorecard 50.21% <ø> (ø) Carriedforward from 14be65f
e2e-theme 16.36% <ø> (ø) Carriedforward from 14be65f
extensions 56.66% <ø> (ø) Carriedforward from 14be65f
global-floating-action-button 71.18% <ø> (ø) Carriedforward from 14be65f
global-header 68.09% <ø> (ø) Carriedforward from 14be65f
homepage 48.48% <ø> (ø) Carriedforward from 14be65f
install-dynamic-plugins 71.31% <ø> (ø) Carriedforward from 14be65f
intelligent-assistant 76.43% <ø> (ø) Carriedforward from 14be65f
konflux 91.98% <ø> (ø) Carriedforward from 14be65f
lightspeed 69.02% <ø> (ø) Carriedforward from 14be65f
mcp-integrations 84.14% <ø> (ø) Carriedforward from 14be65f
orchestrator 71.13% <ø> (ø) Carriedforward from 14be65f
quickstart 63.74% <ø> (ø) Carriedforward from 14be65f
sandbox 79.56% <ø> (ø) Carriedforward from 14be65f
scorecard 87.90% <ø> (ø) Carriedforward from 14be65f
theme 87.91% <ø> (ø) Carriedforward from 14be65f
translations 5.12% <ø> (ø) Carriedforward from 14be65f
x2a 77.10% <ø> (ø) Carriedforward from 14be65f

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 193b36a...e02480b. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026

Copy link
Copy Markdown

Review

Findings

Medium

  • [error-handling] workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts — When caData fails PEM validation in getTlsDispatcher(), the code logs an error but still creates an undici Agent with the invalid PEM string passed as ca. This diverges from the boost-connector-utils/src/ca-bundle.ts pattern where invalid PEM causes a fallback to undefined (system CA). The cached dispatcher then reuses this broken Agent on every refresh cycle, causing repeated cryptic TLS errors while the explanatory PEM-validation message is logged only once.
    Remediation: When isValidPem(caData) returns false, set this.cachedTlsDispatcher = null and return undefined, consistent with the ca-bundle.ts pattern.

  • [code-duplication] workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:269isValidPem() and PEM_HEADER/PEM_FOOTER constants duplicate logic from boost-connector-utils/src/ca-bundle.ts (the code comment acknowledges this). The source function has a different signature (Buffer vs string) and is private (@internal), so direct import is not possible without refactoring.
    Remediation: Either extract a shared string-based isValidPem into boost-connector-utils and import it, or expand the existing comment to explicitly state this is an intentional standalone copy for independent deployment isolation.

  • [missing-doc-update] workspaces/boost/plugins/ogx-entity-provider/src/module.ts — The JSDoc YAML configuration example (lines 45–58) is the only user-facing configuration reference for this module and does not include the new caData and skipTLSVerify options.
    Remediation: Add caData and skipTLSVerify (commented as optional) to the JSDoc YAML example.

Low

  • [TLS-verification-bypass] workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.tsskipTLSVerify disables TLS verification with a warning log. Consistent with Kubernetes/OpenShift ecosystem conventions.

  • [inconsistent-tls-coverage] workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxAgentEntityProvider.ts — Receives OgxEntityProviderConfig with TLS fields but does not use them. Not a current issue since it makes no HTTP calls.

  • [HTTP-client-inconsistency] workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:37 — Uses undici.Agent while boost-connector-utils uses node:https Agent. Technically necessary since global fetch() requires an undici dispatcher.

  • [export-scope] workspaces/boost/plugins/ogx-entity-provider/src/module.ts:117readOgxEntityProviderConfig exported for testing with @internal annotation. Not re-exported from index.ts, so the public API is unaffected.

  • [naming-convention] workspaces/boost/plugins/ogx-entity-provider/src/types.ts:115 — Flat TLS fields follow Kubernetes caData/insecureSkipTLSVerify conventions rather than the nested tls sub-object pattern in boost-connector-utils.

  • [incomplete-config-schema] workspaces/boost/plugins/ogx-entity-provider/config.d.ts — New file declares TLS-related and connection fields but pre-existing fields (modelRefreshIntervalSeconds, agentRefreshIntervalSeconds, defaultAgent, maxAgentTurns, agents) remain undeclared.

  • [test-fixture] workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.test.ts — Test "preserve Authorization header" uses caData: 'PEM-CERT' (invalid PEM), silently exercising the error path. Would break if the error-handling remediation above is applied.

  • [JSDoc-style] workspaces/boost/plugins/ogx-entity-provider/src/module.ts:116@internal Exported for testing only. diverges from existing @internal annotations in this package which use the tag alone.

  • [missing-readme] workspaces/boost/plugins/ogx-entity-provider — No README.md (pre-existing; several sibling packages also lack one).


Labels: PR adds new TLS configuration feature to the OGX entity provider in the boost workspace.

Previous run

Review — comment

Adds per-provider TLS connection settings (caData, skipTLSVerify) to OgxModelEntityProvider so it can fetch /v1/models from OGX endpoints behind a private CA or self-signed certificates. The implementation correctly extends the config type, reads from both config paths, uses an undici Agent dispatcher for TLS customization, and includes solid test coverage. No critical or high findings.

Four medium-severity findings are worth discussing but none individually block the change.


Findings

1. ⚠ Medium — Naming inconsistency: skipTLSVerify vs skipTlsVerify

File: workspaces/boost/plugins/ogx-entity-provider/src/types.ts:118

The new config field uses skipTLSVerify (uppercase TLS), but the existing kagenti provider in the same workspace's app-config.yaml (line 229) uses skipTlsVerify (camelCase). Once this ships as a minor release, the config key becomes a public contract. Users configuring both providers in the same app-config.yaml will encounter inconsistent casing for the same concept.

Remediation: Consider renaming to skipTlsVerify for consistency with the existing workspace convention, or document the intentional difference.

2. ⚠ Medium — Agent created per-call, never closed

File: workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:134

createTlsDispatcher() creates a new undici.Agent on every fetchModels() call (every ~60s). While the agents will be GC'd after keep-alive timeouts, best practice is to create the Agent once and reuse it across polling cycles — this is what connection pools are designed for.

Remediation: Create the Agent once in the constructor (or lazily on first use) and store as a private field.

3. ⚠ Medium — Warning logged on every refresh cycle

File: workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:163

When skipTLSVerify is true, the TLS-disabled warning fires on every 60-second refresh cycle, producing persistent log noise that desensitizes operators.

Remediation: Log the warning once at construction time or on first use. A boolean flag (e.g., this.tlsWarningLogged) can gate subsequent calls. This would also be solved naturally if the Agent is created once in the constructor.

4. ⚠ Medium — JSDoc config example not updated

File: workspaces/boost/plugins/ogx-entity-provider/src/module.ts:46

The inline YAML configuration example in the catalogModuleOgxEntityProvider docblock is the primary user-facing config reference. It does not include the new caData and skipTLSVerify options.

Remediation: Add commented lines:

# caData: ${OGX_CA_DATA}  # optional PEM-encoded CA certificate
# skipTLSVerify: false     # optional, development only

5. 💡 Low — app-config.yaml missing TLS examples

File: workspaces/boost/app-config.yaml

The dev app-config.yaml documents the ogx config block but has no commented examples for the new TLS fields. Adding them would improve discoverability.

6. 💡 Low — caData silently ignored when skipTLSVerify is set

File: workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:162

When both fields are set, skipTLSVerify takes precedence and caData is silently discarded. The behavior is correctly documented in the method JSDoc and tested, but an explicit log message would help operators debug misconfiguration.

Remediation: Log when caData is present but overridden: "caData is configured but will be ignored because skipTLSVerify is true."

7. 💡 Low — Invalid PEM gives cryptic error

File: workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:172

Malformed caData PEM content produces a cryptic OpenSSL error at TLS handshake time. The error IS caught (no crash), but doesn't point the operator to the config value as the cause. The workspace's boost-connector-utils has an isValidPem() function that demonstrates early validation.

8. 💡 Low — Parallel TLS pattern

File: workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.ts:157

The workspace's boost-connector-utils provides createHttpsAgent() and loadCaBundle() for TLS. This PR introduces a second pattern using undici.Agent. The divergence is technically justified — createHttpsAgent() returns a node:https Agent incompatible with fetch() — but creates two TLS patterns in the workspace. Consider extracting a shared undici-compatible dispatcher factory in a follow-up if more providers adopt fetch().

9. 💡 Low — No test for Agent reuse/cleanup

File: workspaces/boost/plugins/ogx-entity-provider/src/providers/OgxModelEntityProvider.test.ts

The tests mock the Agent constructor but never assert on cleanup or reuse across multiple polling cycles.

10. 💡 Low — Flat TLS keys vs nested convention

File: workspaces/boost/plugins/ogx-entity-provider/src/types.ts:119

TLS config uses flat keys (caData, skipTLSVerify) while boost-connector-utils uses a nested tls block. Defensible for two fields, but worth aligning if workspace-wide config consistency is a goal.


Summary: Clean, well-tested implementation that delivers the feature as specified. The four medium findings are all addressable with small changes — the naming inconsistency (finding 1) is the most impactful since it affects the public config surface. Findings 2 and 3 would both be resolved by creating the Agent once in the constructor.

Previous run (2)

Review

Verdict: comment — medium-severity findings worth noting but none that should block

This PR adds per-provider TLS connection settings (caData and skipTLSVerify) to OgxEntityProviderConfig so OgxModelEntityProvider can reach OGX endpoints behind a private CA or self-signed certificates. The implementation is well-structured: config is read from both supported paths, the undici Agent dispatcher integrates correctly with Node's built-in fetch, precedence logic is sound, and the test suite is thorough with good coverage across all TLS code paths.

All changes trace to the linked issue #4477. No scope creep detected. The minor changeset bump is appropriate for new user-visible configuration. Existing tests are unmodified in their assertions.

Findings

Medium

1. Resource leak — undici Agent created per fetch cycle · OgxModelEntityProvider.ts
createTlsDispatcher() is called inside fetchModels(), which runs every ~60 seconds. Each invocation creates a new undici.Agent with its own connection pool, and the Agent is never closed. Over sustained operation, this accumulates orphaned Agents holding sockets and event-loop refs until GC non-deterministically reclaims them.

Suggestion: Create the Agent once (lazily or in the constructor) and store it as a class field. The config is immutable after construction, so reuse is safe. Alternatively, call agent.close() in a finally block after fetch completes.


2. Repeated warning log on every refresh · OgxModelEntityProvider.ts
When skipTLSVerify is true, the warning is emitted every refresh cycle (~1,440 identical lines/day), which can obscure genuinely actionable warnings in production log aggregation.

Suggestion: Log the warning once — either in the constructor when skipTLSVerify is detected, or guard with a private warnedSkipTLS = false flag.


3. Missing config.d.ts — sensitive fields lack @visibility annotations · ogx-entity-provider/
The ogx-entity-provider plugin has no Backstage config schema file. Without @visibility annotations, apiKey (pre-existing) and the new caData field have no visibility restrictions and may be served to the frontend via Backstage's /api/config endpoint. Other plugins in this workspace (boost-backend, boost-backend-module-kagenti) correctly declare config.d.ts with @visibility secret on sensitive fields.

Suggestion: Create a config.d.ts and annotate apiKey with @visibility secret and caData with @visibility backend (or secret). Register it in package.json under configSchema. This is a pre-existing gap for apiKey that this PR extends.


4. No PEM validation for caData · OgxModelEntityProvider.ts
caData is passed directly to the undici Agent's connect.ca option without validation. The existing boost-connector-utils/src/ca-bundle.ts implements isValidPem() that checks for proper PEM BEGIN/END markers. An invalid caData value (truncated PEM, empty string from misconfigured env var) will cause opaque TLS handshake failures.

Suggestion: Validate caData before passing it to the Agent — at minimum check for PEM markers and log a clear error if validation fails. Consider reusing or adapting the isValidPem() logic from boost-connector-utils.


5. Naming inconsistency: skipTLSVerify vs skipTlsVerify · types.ts
The field name skipTLSVerify (uppercase TLS) conflicts with the existing kagenti.skipTlsVerify (lowercase) in the same workspace's app-config.yaml. Users editing the same config file will encounter two different casings of the same concept. This originates from the issue specification (#4477), not from the PR author.

Suggestion: Align naming across the boost workspace — either rename to skipTlsVerify here (matching kagenti) or update kagenti in a follow-up. Document the chosen convention.

Low

6. Silent config override when both fields set · OgxModelEntityProvider.ts
When both caData and skipTLSVerify: true are set, caData is silently discarded. The existing ca-bundle.ts logs a warning when conflicting CA options are set. A similar warning here would make the override behavior explicit.

7. Stale JSDoc config example · module.ts:46-58
The @public JSDoc config example on catalogModuleOgxEntityProvider documents baseUrl, apiKey, refresh intervals, and agents, but omits the new caData and skipTLSVerify keys. This is the primary config reference visible to adopters.

8. Internal method naming casing · OgxModelEntityProvider.ts
createTlsDispatcher (lowercase tls) alongside the skipTLSVerify property (uppercase TLS) is an internal casing inconsistency.

9. Pre-existing config path asymmetry · module.ts
The fallback config path (boost.providers.ogx) omits modelRefreshIntervalSeconds, agentRefreshIntervalSeconds, and serverVersion — unlike the primary path. Not introduced by this PR, but worth tracking.

10. Example config gap · examples/app-config.connectors.yaml
The reference config for AI catalog connectors documents TLS for RHOAI and OCI connectors but has no OGX entity provider section.


Labels: PR adds TLS configuration to the OGX entity provider in the boost workspace

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added requires-manual-review Review requires human judgment workspace/boost Boost workspace (Backstage AI plugin) labels Sep 3, 2026
Comment thread workspaces/boost/app-config.yaml Outdated
Comment thread workspaces/boost/app-config.yaml Outdated
Comment thread workspaces/boost/app-config.yaml Outdated
Comment thread workspaces/boost/app-config.yaml Outdated
Comment thread workspaces/boost/app-config.yaml Outdated
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026

Copy link
Copy Markdown

🤖 Review · ⚠️ Cancelled · Started 8:12 PM UTC · Ended 8:12 PM UTC

Commit: 1d2bdb4 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 8:13 PM UTC · Ended 8:30 PM UTC

Commit: 879903d · View workflow run →

@gabemontero

Copy link
Copy Markdown
Contributor

/fs-fix address all the medium findings from #4574 (comment) ... with the first finding, keep a global cache for the created Agent

@fullsend-ai-coder

fullsend-ai-coder Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Fix · ❌ Terminated · Started 8:21 PM UTC · Ended 8:39 PM UTC

Commit: 14be65f · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot removed the requires-manual-review Review requires human judgment label Sep 3, 2026
@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 3, 2026
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:13 PM UTC · Completed 8:30 PM UTC

Commit: 879903d · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Cost: $6.03

- Cache undici Agent as class field to prevent resource leak from
  creating a new Agent with its own connection pool on every refresh
- Warning for skipTLSVerify now fires only once (on first dispatcher
  creation) instead of every ~60s refresh cycle
- Add PEM validation for caData — logs clear error when certificate
  markers are missing instead of failing with opaque TLS handshake errors
- Create config.d.ts with @visibility annotations for apiKey (secret)
  and caData (backend) to prevent exposure via /api/config endpoint
- Add tests for Agent caching, single-warning, and PEM validation

Addresses review feedback on #4574
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 8:21 PM UTC · Completed 8:39 PM UTC

Commit: 14be65f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Cost: $2.78

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 8:40 PM UTC · Ended 8:59 PM UTC

Commit: e02480b · View workflow run →

@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

@@ -212,3 +269,19 @@ export class OgxModelEntityProvider implements EntityProvider {
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] code-duplication

isValidPem() function and PEM_HEADER/PEM_FOOTER constants duplicate logic from boost-connector-utils/src/ca-bundle.ts. The source function has a different signature (Buffer vs string) and is private, so direct import is not possible without refactoring.

Suggested fix: Either extract a shared string-based isValidPem into boost-connector-utils, or expand the comment to document this as an intentional standalone copy for independent deployment isolation.

@@ -35,6 +35,8 @@ import {
normalizeAIAssetVersion,
} from '@red-hat-developer-hub/backstage-plugin-boost-entity-provider-sdk';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] HTTP-client-inconsistency

Uses undici.Agent while boost-connector-utils uses node:https Agent. Technically necessary since global fetch() requires an undici dispatcher.


/**
* Read OGX entity provider configuration from app-config.yaml.
*

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] export-scope

readOgxEntityProviderConfig exported for testing with @internal annotation. Not re-exported from index.ts, so the public API is unaffected.

maxAgentTurns?: number;
/** Static agent configurations from YAML/admin config. */
agents?: OgxAgentConfig[];
/** PEM-encoded CA certificate or certificate bundle used to verify OGX. */

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] naming-convention

Flat TLS fields follow Kubernetes caData/insecureSkipTLSVerify conventions rather than the nested tls sub-object pattern in boost-connector-utils.

@@ -114,8 +114,10 @@ export const catalogModuleOgxEntityProvider = createBackendModule({

/**
* Read OGX entity provider configuration from app-config.yaml.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] JSDoc-style

@internal Exported for testing only. diverges from existing @internal annotations in this package which use the tag alone.

@fullsend-ai-review fullsend-ai-review Bot added requires-manual-review Review requires human judgment enhancement New feature or request and removed requires-manual-review Review requires human judgment labels Sep 3, 2026
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:40 PM UTC · Completed 8:59 PM UTC

Commit: e02480b · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Cost: $6.71

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request ready-for-review Agent PR ready for human review requires-manual-review Review requires human judgment workspace/boost Boost workspace (Backstage AI plugin)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(boost): add caData, skipTLSVerify to OgxEntityProviderConfig

1 participant