fix(zulip-health): retire the dead kagentz Zulip adapter leg #78

Merged
abiba-bot merged 4 commits from fix/zulip-kagentz-adapter-20260912 into master 2026-09-12 14:34:09 +00:00
Owner

What and why

The kagentz Zulip adapter code (/a0/usr/kagentz-zulip/) no longer exists in the agent-zero container, so scripts/zulip-monitor.sh ran an adapter-process check on every pass that could only ever fail, issued a restart for something that cannot start, and posted a false 🔴 kagentz-adapter-down alert (and restart) every 15 minutes. Captain's ruling: Zulip communication with Agent Zero is not a priority.

Changes

  • scripts/zulip-monitor.sh — remove the adapter-process check, the adapter restart, the A2A-agent restart, and the hardcoded kagentz ZULIP_API_KEY/A2A_TOKEN literals from the deleted command. The Agent Zero A2A probe stays, moved to the :80/a2a/ HTTP-status form; it never restarts a platform. Signal handling is now honest: 000 → 🔴 down, 200/401 → ✅ alive (auth-gated), any other code → 🟡 running-but-unexpected. The probe capture was also fixed so a failed connection cannot append a duplicate 000 (000000) and hide the down case, and the same unsafe || echo "000" capture was corrected on the Zulip server and Abiba legs.
  • zulip-health.prose.md — reconciled with the shipped behaviour (v3.3.0): adapter leg documented as retired, C2/C3 removed, the Platform C Actions table no longer authorizes adapter or A2A restarts, and a note tells future agents not to re-add it.
  • tests/test_mumuni_monitor_removal.py — the regression test no longer asserts the removed adapter line; it pins the retained A2A leg and can simulate a connection failure so the 000 path is actually exercised.
  • contract-registry.yaml — zulip-health version 3.2.0 → 3.3.0.
  • zulip-mention-reliability.prose.md — points at the current Platform C state.

Validation

no-mistakes pipeline run 01M2AZ6Y3WA14CWTHJJNWVVBS5 — outcome passed (review, test, document, lint, push). Live run of the updated monitor: Server 200, Abiba Connected, Tanko active 401, kagentz A2A alive (HTTP 401), Result All healthy, exit 0.

Known exposure (declined in this change, tracked separately)

The removed restart command contained a kagentz-bot Zulip API key and an A2A token. Removing them from the code does not remove them from git history, and they may still be live. Credential rotation/revocation is a security-sensitive captain decision and is deliberately NOT attempted here (no rotation, no revocation, no history rewrite, no scanner suppression). It is tracked as a separate security follow-up. The unrelated hardcoded abiba-bot key already in the file is left exactly as-is.

## What and why The kagentz Zulip adapter code (`/a0/usr/kagentz-zulip/`) no longer exists in the agent-zero container, so `scripts/zulip-monitor.sh` ran an adapter-process check on every pass that could only ever fail, issued a restart for something that cannot start, and posted a false 🔴 kagentz-adapter-down alert (and restart) every 15 minutes. Captain's ruling: Zulip communication with Agent Zero is not a priority. ## Changes - **`scripts/zulip-monitor.sh`** — remove the adapter-process check, the adapter restart, the A2A-agent restart, and the hardcoded kagentz `ZULIP_API_KEY`/`A2A_TOKEN` literals from the deleted command. The Agent Zero A2A probe stays, moved to the `:80/a2a/` HTTP-status form; it never restarts a platform. Signal handling is now honest: `000` → 🔴 down, `200`/`401` → ✅ alive (auth-gated), any other code → 🟡 running-but-unexpected. The probe capture was also fixed so a failed connection cannot append a duplicate `000` (`000000`) and hide the down case, and the same unsafe `|| echo "000"` capture was corrected on the Zulip server and Abiba legs. - **`zulip-health.prose.md`** — reconciled with the shipped behaviour (v3.3.0): adapter leg documented as retired, C2/C3 removed, the Platform C Actions table no longer authorizes adapter or A2A restarts, and a note tells future agents not to re-add it. - **`tests/test_mumuni_monitor_removal.py`** — the regression test no longer asserts the removed adapter line; it pins the retained A2A leg and can simulate a connection failure so the `000` path is actually exercised. - **`contract-registry.yaml`** — zulip-health version 3.2.0 → 3.3.0. - **`zulip-mention-reliability.prose.md`** — points at the current Platform C state. ## Validation no-mistakes pipeline run `01M2AZ6Y3WA14CWTHJJNWVVBS5` — outcome **passed** (review, test, document, lint, push). Live run of the updated monitor: `Server 200`, `Abiba Connected`, `Tanko active 401`, `kagentz A2A alive (HTTP 401)`, `Result All healthy`, exit 0. ## Known exposure (declined in this change, tracked separately) The removed restart command contained a kagentz-bot Zulip API key and an A2A token. Removing them from the code does not remove them from git history, and they may still be live. **Credential rotation/revocation is a security-sensitive captain decision and is deliberately NOT attempted here** (no rotation, no revocation, no history rewrite, no scanner suppression). It is tracked as a separate security follow-up. The unrelated hardcoded `abiba-bot` key already in the file is left exactly as-is.
abiba-bot added 4 commits 2026-09-12 14:31:58 +00:00
- Remove adapter process check and restart logic
- Keep A2A probe (port 80, HTTP code check)
- The adapter code at /a0/usr/kagentz-zulip/ no longer exists
- Captain's ruling: Zulip communication with agent zero is not priority
no-mistakes(document): Reconcile Zulip docs with retired kagentz adapter leg
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 14s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
22d2c3acac
abiba-bot merged commit e3752af162 into master 2026-09-12 14:34:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SyslogSolution/prose-contracts#78