feat(kimi): Kimi K3 provider on the official kimi-code CLI (#713)

* feat(kimi): Kimi K3 provider on the official kimi-code CLI (Wave 1)

ModelProvider.KIMI routes through KimiCliProvider driving Moonshot's kimi
CLI on a Kimi subscription (OAuth device-code, no metered key). One-shot
delivery roles only (V1), interactive ban wired in both guard lists.

Auth: one shared RW auth mount; containers symlink credentials/ and
oauth/ (the CLI's cross-process refresh-lock dir) into a container-local
KIMI_CODE_HOME so every container and the host redeem the SAME rotating
refresh chain - live-verified that per-copy chains cross-invalidate after
the reuse-grace window. No orchestrator refresh daemon; an expires_at
preflight exits 78.

Config renderer mirrors the login-managed provider/model blocks
field-for-field (live-captured; the model value is the CLI-side name,
never the raw API id), plus per-role deny rules and the bash-guard as a
PreToolUse hook via a wrapper script (an env key on a hooks entry makes
the CLI silently drop ALL hooks - live-verified). Usage capture sums
wire.jsonl usage.record 4-bucket events; sniff classifies rate-limit/auth
from structured error text only, mapped to the shared 75/78 park
contract. Image installs the CLI latest-at-build (no version pin, by
policy) with the resolved version stamped as provenance, binary split to
/usr/local away from mutable state.

Migrations 090 (enum) + 091 (provider seed); catalog, pricing, routing
mode, and orchestrator park/usage wiring mirror the codex integration.

* feat(kimi): surface sweep + fleet-wide pin drop (Wave 2)

Compose x3 gain the agent-kimi-image service and the orchestrator's
read-write ~/.kimi-code mount + kimi-usage dir; .env.example documents
the Kimi block. Panel mirrors ModelProvider.KIMI and adds the kimi
routing mode (catalog filter, mode button, mix-picker group, badge) with
tests; provider routes gain the kimi remediation entry. CLAUDE.md and
docs/map document the runtime. Per the no-pins policy, agent-grok/
gemini/codex Dockerfiles drop their version pins for latest-at-build
with resolved-version provenance stamps (grok resolves 0.2.112 vs the
old 0.2.56 pin - verified by real builds of all four images).

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-07-29 01:48:55 +02:00
committed by GitHub
co-authored by Renn F
parent eb470dfb33
commit 6374bbbed0
43 changed files with 3907 additions and 110 deletions
+9 -7
View File
@@ -17,15 +17,16 @@ FROM roboco-agent-base
USER root
# Install the official Gemini CLI. Pinned — untrusted model output runs under
# it, so bump the version deliberately, never float (spike verified 0.52.0 at
# github.com/google-gemini/gemini-cli @ 9681621c). npm installs to the global
# node_modules the base image's Node 22 already resolves onto PATH.
ARG GEMINI_CLI_VERSION=0.52.0
RUN npm install -g "@google/gemini-cli@${GEMINI_CLI_VERSION}" \
# Install the official Gemini CLI. NO version pin (2026-07-28 policy:
# latest-at-build, always adapt — fleet-wide across grok/gemini/codex/kimi).
# npm installs to the global node_modules the base image's Node 22 already
# resolves onto PATH; the resolved version is stamped to /etc/gemini-cli-version
# for per-image provenance (a record, not a pin).
RUN npm install -g @google/gemini-cli \
&& npm cache clean --force \
&& rm -rf /root/.npm /tmp/* \
&& gemini --version
&& command -v gemini \
&& gemini --version | tee /etc/gemini-cli-version
# Entrypoint: copy the staged OAuth credential into a writable ~/.gemini,
# render settings.json + policy TOML, then run gemini headless (overrides the
@@ -39,6 +40,7 @@ USER agent
LABEL role="gemini-cli-runtime"
LABEL description="Gemini (Google) agent runtime — Gemini Build via the official gemini CLI"
LABEL gemini.cli.pinned="false"
# advanced.autoConfigureMemory=false (rendered into settings.json) pins Node's
# heap sizing away from auto-detection against a shared host; this bounds it