aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

agent: Fail-fast preflight verify step before run_agent

Open
#563 0 comments 0 reactions 0 assignees View on GitHub
agent-runtime enhancement validation-loop
Dominant language
TypeScript
Stars
143
Forks
46
Avg merge
3d 9h
Merged PRs (30d)
20

Description

## Component

Agent (Python runtime)

## Describe the feature

Support an explicit **`verify_build` or `verify_lint` step before the first `run_agent`** that **fails the task without invoking the LLM** when the repo is already broken.

```yaml
steps:
- { kind: clone_repo, name: setup }
- { kind: verify_build, name: preflight, gate: strict, on_failure: fail }
- { kind: run_agent, name: implement }
- { kind: verify_build, name: build, gate: regression_only }
- { kind: ensure_pr, name: open_pr, strategy: create }
```

## Use case

**What exists today (not sufficient):**

- `clone_repo` / `setup_repo` already runs `mise run build` and `mise run lint` deterministically and records `build_before` / `lint_before` in `RepoSetup`.
- If the initial build fails, the task **still proceeds to `run_agent`** — failure is noted in setup notes and prompts tell the agent to run build, but there is no workflow-level fail-fast gate.
- Post-agent `verify_build` runs only after the agent consumes tokens.

**Gap:** Operators need a declarative, deterministic preflight gate — not prompt guidance — to skip LLM execution when the tree is already red.

Orchestrator pre-flight ([ARCHITECTURE.md](https://github.com/aws-samples/sample-autonomous-cloud-coding-agents/blob/main/docs/design/ARCHITECTURE.md)) covers GitHub reachability; this covers **repo health after clone**.

## Proposed solution

1. **Validator** — If a `verify_*` step appears before `run_agent`, `gate` must be `strict` or `regression_only` (not `informational`); record baseline in `workflow_state.json` for post-agent `regression_only` compare.
2. **Runner** — Step order already supported; add test proving preflight failure never invokes `run_agent`.
3. **Cost** — `clone_repo` already runs build; consider skipping duplicate full build in clone when a preflight `verify_build` immediately follows, or document opt-in on workflows only.
4. **Docs** — WORKFLOWS.md preflight pattern + cost trade-off.
5. **Opt-in** — Enable on `coding/new-task-v1` only after cold-start cost measurement.

## Other information

- Forbidden when `requires_repo: false` (existing validator rule).
- Related: #457 (post-agent fix loops — complementary).

## Acknowledgements

- [ ] I may be able to implement this feature
- [ ] This might be a breaking change

Contributor guide

Open the contributing guide

Research direction

Read docs/design/ARCHITECTURE.md and WORKFLOWS.md, then trace the verify_* validator and runner entry points around clone_repo and run_agent. Add coverage for a failing preflight that never invokes run_agent, records workflow_state.json baselines, and document the preflight pattern and build-cost trade-off.

Written by the indexing model from the issue text.

Assessment

Tech stack
python, typescript
Domain
backend, documentation, tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.