Flag reference: agentengine agent validate, agentengine build.
Audience: CLI users running agentengine agent validate or agentengine build. For ECP build-start hook placement, secret metadata lookup, and GitHub/archive file loading, see operator documentation at docs/executor/artifact-registry-validation.md in the agentic-platform monorepo (not shipped in the client-libraries mirror).
The Agentic CLI runs the same declared-index artifact registry checks as ECP build-start validation, locally and before archive upload. Shared logic lives in client-libraries/agent-config/agentconfig/ (ValidateArtifactRegistry, LoadProjectFilesFromDir).
Commands
Command | Hard validation | Secret warnings |
|---|---|---|
| When | When logged in (best-effort); |
| Same, before | Always when client is available; non-blocking |
| Same | Uploads declared secrets from the environment first — see below |
Both commands read tooling files from the same directory as ``agent.yaml`` (not the monorepo root unless the manifest lives there).
What is validated
Always (schema — agentconfig.Validate)
artifact_repositoriesentry shape:name,type,secret,scope,auth,npm_scope
When artifact_repositories is non-empty (cross-file)
Declared
name(or npmnpm_scope) must exist in project tooling.Matching tooling entry must have an HTTPS registry URL.
URLs in tooling and loaded lockfiles are scanned for SSRF-unsafe hosts.
Opt-in model (not errors)
No
artifact_repositoriesblock → no cross-file fetch.Private HTTPS URLs in
uv.lock/package-lock.jsonthat are not declared → pass without platform creds.SSRF-unsafe URLs in tooling or loaded lockfiles still fail with
INVALID_REGISTRY_URLwhenartifact_repositoriesis non-empty.
Secret warnings (online)
Mirrors ECP AP-3980 scope rules using ListSecrets / ListWorkspaceSecrets. In the CLI these are warnings unless agentengine agent validate --strict (exit 1). ECP build-start treats a missing secret as a hard failure (MISSING_BUILD_SECRET before CodeBuild).
Code | CLI validate | ECP build start | Meaning |
|---|---|---|---|
| Warning; | Hard fail | No ASM secret at declared scope |
| Warning; | Hard fail | Secret exists at the other scope |
| Warning; | N/A (CLI needs | Workspace-scoped entry but no workspace context |
| Warning; | Hard fail (non-retryable); retried when transient | Online secret list could not be verified |
Cross-file hard errors
These fail agentengine agent validate, agentengine build (before upload), and ECP build-start cross-check when artifact_repositories is non-empty:
Code | Meaning | What to do |
|---|---|---|
| Declared | Align |
| Name matched but tooling has no HTTPS URL | Add |
| Non-HTTPS URL, embedded credentials, or blocked host | Use |
Undeclared private HTTPS URLs in lockfiles pass without platform creds (opt-in model). SSRF-unsafe URLs in tooling or loaded lockfiles still fail with INVALID_REGISTRY_URL when artifact_repositories is non-empty. Setup walkthroughs, CI token refresh, webhook pre-seed, and migration from vendored wheels/ are in agent-yaml.md.
Examples
Valid declared index (Python)
agent.yaml:
language: python required_secrets: artifact_repositories: - name: corps-pypi type: pypi secret: ARTIFACT_REPO_CORPS_PYPI_TOKEN
pyproject.toml must contain a matching [[tool.uv.index]] name and HTTPS url.
agentengine agent validate # ✓ ./agent.yaml valid (egress rules: 0, atlas clusters: 0, artifact repositories: 1)
Unknown declared name
agentengine agent validate # ✗ ./agent.yaml: artifact registry: UNKNOWN_INDEX_NAME: declared name "missing-index" not found in project tooling # exit 1
Undeclared lockfile URL (passes)
An agent with private packages in uv.lock but no artifact_repositories block exits 0 — customer-managed auth only.
Strict mode
agentengine agent validate --strict # Any artifact-registry secret warning (or secret-list failure) becomes exit 1.
Uploading declared secrets before a build (AP-3986)
agentengine build --upload-build-secrets is an opt-in convenience for short-lived registry tokens. It reads each artifact_repositories[].secret from the environment variable of the same name and PUT s it at the declared scope before the build is created. It never reads an environment variable that agent.yaml does not declare.
export ARTIFACT_REPO_CORPS_PYPI_TOKEN="$(aws codeartifact get-authorization-token \ --domain my-domain --query authorizationToken --output text)" agentengine build --upload-build-secrets # ✓ uploaded project secret ARTIFACT_REPO_CORPS_PYPI_TOKEN (version 3)
Without the flag, set credentials once with agentengine secret set <NAME>; the flag exists for tokens that expire between builds.
Behavior | Detail |
|---|---|
Scope | Per entry, from |
Ordering | Runs before build creation — ECP resolves declared secrets to ASM ARNs inside build-start and fails the build if one is absent |
Deduplication | Same secret at the same scope and project is uploaded once, including across |
Missing / empty env var | Fails before that agent’s upload or build, listing every offending name at once. With |
Reserved or invalid name | Rejected locally ( |
Authorization | Project scope needs |
Validation | A workspace’s |
| Uploaded per workspace; a failure fails only that workspace |
Secret values never appear in stdout, logs, or error text — a failing upload is scrubbed via the same path as agentengine secret set.
Local testing
# Shared agentconfig library go test ./client-libraries/agent-config/agentconfig/... -run 'LoadProjectFilesFromDir|ArtifactRegistry' # CLI unit tests go test ./client-libraries/agentengine-cli/internal/cmd/... -run 'ArtifactRegistry|RunValidate_Artifact' # Build pre-check go test ./client-libraries/agentengine-cli/internal/cmd/... -run 'RunBuild_InvalidArtifactRegistry'
Manual smoke test
Create a temp agent dir with
agent.yaml,pyproject.toml, and optionaluv.lock.Run
go run ./client-libraries/agentengine-cli/cmd/agentengine agent validatefrom that directory (or pass the manifest path).Add a bad
artifact_repositoriesentry and confirm exit 1 before any build upload.Log in and run
agentengine agent validateto see secret warnings; repeat with--strict.
Related docs
ECP build-start validation:
docs/executor/artifact-registry-validation.mdin the agentic-platform monorepo (operator documentation; not shipped in the client-libraries mirror)artifact_repositoriesfield reference and setup: client-libraries/docs/agent-yaml.md