Skip to content

policy commands refuse the documented graph-plus-cluster bundle layout #761

Description

@ragnorc

omnigraph policy validate|test|explain --cluster <dir> --graph <id> refuses the
cluster layout the documentation prescribes.

select_cluster_policy (crates/omnigraph-cli/src/helpers.rs) matches every bundle
whose applies_to contains graph.<id> or cluster, then refuses when more
than one matches:

graph `knowledge` in cluster `./company-brain` matches 2 policy bundles ([graph, server]);
the cluster model expects one bundle per graph scope

Both docs/user/operations/policy.md and skills/omnigraph/references/server-policy.md
document exactly that layout: one bundle bound to a graph id, a second bound to
cluster (which is what grants graph_list, and now config_manage). So the
policy commands are unusable on a normal cluster.

Two related defects in the same selector:

  • A cluster bundle is always compiled as a graph bundle
    (PolicyEngine::load_graph_from_source), so its graph_list / config_manage
    rules are rejected by the kind check. A cluster whose only bundle is the
    cluster one therefore fails policy validate outright.
  • policy explain --action graph-list evaluates against the graph bundle rather
    than the bundle the server actually asks.

The server does not have this problem: crates/omnigraph-server/src/settings.rs
routes bindings to slots (one bundle per graph, one cluster bundle) and asks the
bundle that owns each request. The CLI had drifted from that model.

Expected: the policy commands select a bundle per request the way serving does —
graph actions from the --graph bundle, graph_list / config_manage from the
cluster bundle, with no fallback between scopes.

Existing CLI coverage only ever applied a single bundle, so nothing caught this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions