Skip to content

feat(evaluators): add extensions/metadata for additional fields that we want to pass as context to execution of evaluator - #276

Merged
namrataghadi-galileo merged 10 commits into
mainfrom
feature/SAO-17620-pass-scorer-context-to-galileo-evaluators
Oct 1, 2026
Merged

namrataghadi-galileo merged 10 commits into
mainfrom
feature/SAO-17620-pass-scorer-context-to-galileo-evaluators

Conversation

@namrataghadi-galileo

@namrataghadi-galileo namrataghadi-galileo commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Pass the authenticated execution context through Agent Control to Galileo evaluators so scorer invocation can receive the Orbit-authorized organization, caller, project, and target information.

  • Preserve upstream authorization response extras as opaque Principal.extensions metadata.
  • Add an optional opaque extensions claim to newly minted runtime JWTs. Existing claims, expiration behavior, and tokens without extensions remain compatible.
  • Pass verified principal extensions through a provider-neutral evaluator hook. Existing evaluators continue using their current evaluation path.
  • In the Galileo evaluator only, translate the trusted extension envelope into Galileo's execution_context. For the current Orbit contract, caller_id is the authenticated user ID. A log_stream target's authenticated target ID becomes run_id.
  • Return a clear evaluator error when required authenticated fields are missing.

Scope

  • API/runtime contract: additive opaque extensions claim; no named Galileo fields are added to generic principal or JWT models.
  • Internal: carry verified extensions from auth exchange through runtime-token verification and engine evaluation.
  • Galileo: serialize the local execution context with scorer invocation requests.
  • Out of scope: scorer grants, scorer authorization/execution, API-key forwarding to Runners, record factory changes.

Trust and Compatibility

Execution metadata comes only from the verified runtime principal. Evaluator step payloads are not used to construct it, and user-supplied tenant identity is not trusted. No scorer grant is acquired or cached, and the application GALILEO_API_KEY is not sent to Runners. Legacy runtime tokens without extensions and evaluators that do not override the extension hook remain supported.

Testing and Coverage

  • Engine tests: 120 passed, including opaque extension pass-through and legacy evaluator fallback.
  • Built-in evaluator tests: 311 passed, including default extension-hook delegation.
  • Galileo tests: 156 passed, including context serialization, missing caller handling, and API-key non-forwarding.
  • Focused server auth tests: 6 passed, including malformed extension handling and signed-token round-trip.
  • make check passed in PR CI; Codecov patch check passed.
  • make lint and make typecheck passed locally.

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@namrataghadi-galileo

Copy link
Copy Markdown
Contributor Author

Tested in devstack:

(.venv) namratag@NAMRATAG-M-6QFJ ace-demo % TOKEN="$(jq -r '.token' /tmp/agent-control-auth.json)"      

python - "$TOKEN" <<'PY'
import base64
import json
import sys

payload = sys.argv[1].split(".")[1]
payload += "=" * (-len(payload) % 4)

claims = json.loads(base64.urlsafe_b64decode(payload))
print(json.dumps(claims, indent=2, sort_keys=True))
print("\nproject_id:", claims.get("extensions", {}).get("project_id"))
PY
{
  "actor_id": "4b0890ea-bc1d-47a0-9808-556f76a83835",
  "domain": "runtime",
  "exp": 1790819890,
  "extensions": {
    "project_id": "96da6d6d-a63f-40db-94c9-ccfcfa99c95c"
  },
  "iat": 1790819590,
  "iss": "agent-control/server",
  "jti": "77Bs7-hge_oVxRualkZytw",
  "namespace_key": "f3befdd7-6f82-4136-8a7d-529366231ce3",
  "scopes": [
    "runtime.use"
  ],
  "target_id": "eee67868-b583-4bda-b7ad-8bfd8ddb8348",
  "target_type": "log_stream"
}

project_id: 96da6d6d-a63f-40db-94c9-ccfcfa99c95c

@namrataghadi-galileo
namrataghadi-galileo merged commit 4e6b025 into main Oct 1, 2026
6 checks passed
@namrataghadi-galileo
namrataghadi-galileo deleted the feature/SAO-17620-pass-scorer-context-to-galileo-evaluators branch October 1, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants