Skip to content

[Feature] A2A gateway production wiring: main-process boot, RocksDB task store, auth, metrics, contextId #5405

Description

@qqeasonchen

Motivation

The A2A / Agent Gateway is feature-complete in components but not in wiring. A source audit of runtime/a2a + protocol-a2a (develop @ 66727b6) shows:

  1. Production wiring is missing. EventMeshA2ATransport (bridging onto UniIngressService / the real CloudEvents-over-MQ core) exists but nothing uses it: A2AGatewayServer is only started from standalone demos with an in-memory transport, and EventMeshApplication never boots the gateway. docker run apache/eventmesh gives no A2A endpoints at all.
  2. TaskStore has one backend. Only MetaBackedTaskStore (requires Nacos). Single-instance / docker deployments have no durable task store at all.
  3. [Bug] The a2a protocol layer is not working #5225 class confusion. Users post A2A JSON-RPC to the runtime traffic port (/eventmesh/publish) and get an opaque error. The traffic port should answer with actionable guidance pointing at the A2A gateway endpoints.
  4. Gateway has no auth. The Authorization header is passed to the security gate as an opaque principal ([Architecture Review][P1] Unified multi-tenant / security / quota entrypoint #5304) but never actually verified — the gateway is open when started.
  5. Zero A2A metrics. No counters for submitted/completed/failed/expired tasks or gateway latency; /admin/metrics and /metrics know nothing about the A2A plane.
  6. Task payloads are opaque strings. TaskRecord.input/output are raw strings; contextId (A2A conversation linkage) is not persisted, so related tasks cannot be correlated after the fact.

A follow-up audit of the eventmesh-agent module (the v2 streaming-agent process) found a parallel set of gaps:

  1. Port-migration leftover. AgentApplication defaults agent.runtime.url to http://localhost:8080; the traffic port moved to 10105. The agent cannot connect to a default-configured runtime at all.
  2. dist-agent packages a nonexistent bin/. The dist-agent gradle task copies eventmesh-agent/bin, but that directory was never created — the distribution has no launcher, while conf/agent.properties references ./bin/start-agent.sh.
  3. Unbounded conversation map. ConversationStore bounds each conversation's history (sliding window) but never evicts conversations — session count grows without limit (memory leak on a long-lived agent).
  4. No fail-fast on a missing LLM key. With llm.api.key empty the agent still registers and flips READY — every routed request then fails.
  5. Zombie agent on heartbeat loss. Heartbeat failures only log; after the runtime TTL evicts the registration the agent process keeps serving nothing.

Proposal

Single PR covering both planes (Testcontainers E2E stays in #5347):

A2A gateway (1-6): main-process boot (withA2aGateway + -Deventmesh.a2a.enabled=true, port 10108) on the real transport; RocksDBTaskStore local default; bearer-token auth; A2A metrics in /admin/metrics + /metrics; traffic-port guidance for #5225; contextId passthrough.

Agent process (7-11): default agent.runtime.url -> http://localhost:10105; new bin/start-agent.sh launcher (env -> -D mapping, mirrors the runtime's start.sh); ConversationStore gains a bounded conversation count (LRU eviction, agent.conversation.maxConversations); fail-fast when llm.api.key is empty (unless llm.api.key.optional=true); heartbeat consecutive-failure limit (agent.heartbeat.failLimit, default 6) exits the process so the supervisor can restart; module documentation docs/feature/agent.md.

Non-Goals

Testing

  • Unit tests: RocksDBTaskStore round-trip + epoch CAS; auth guard; contextId passthrough; guidance response; ConversationStore conversation-count eviction.
  • Integration: gateway-on-main-process smoke; agent control-plane config parsing.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions