Files
mrcharles 8ce279276f feat: initial agent identity provisioning automation [#442]
Playwright-based tool for enrolling AI agent identities in Cloudron,
generating API keys via SSO (Gitea/Discourse/Redmine), and storing
all credentials in Bitwarden per-agent collections.

- provision-agent.py: main Playwright automation (Cloudron enroll,
  SSO login, API key generation, verification)
- bw-helper.py: Bitwarden CLI wrapper (password gen, item CRUD,
  TOTP, session management)
- Dockerfile: Playwright v1.52.0 + bw CLI + Python deps
- agents.yaml.example: manifest template for Q3/Q4 agents
- TSYSGroupAIOS framework adopted (hooks, rules engine, Makefile)

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-13 08:59:14 -05:00

1.2 KiB

Agent Identity Provisioning

Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage.

Overview

Each AI agent (VP TechOps, VP SecOps, etc.) gets:

  1. A dedicated Cloudron user (identity root — SSO provisions everywhere)
  2. TOTP 2FA enrolled and stored in Bitwarden
  3. API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden)
  4. All credentials owned by the agent, sourced via bw-run.sh (no ~/.creds/ files)

See ~/Q3/agent-identity-bootstrap.md for the full architecture.

Usage

# 1. Create the manifest from the example
cp agents.yaml.example agents.yaml
# Edit: add Cloudron invite links for each agent

# 2. Set BW credentials
export BW_CLIENTID="..."
export BW_CLIENTSECRET="..."

# 3. Build and run
docker compose up --build

# Or run a single agent
docker compose run --rm provision --agent vp-techops

Manifest format

See agents.yaml.example. Each agent defines:

  • Cloudron invite link
  • Display name
  • Priority (Q3 vs Q4)
  • System scopes (Redmine projects, Gitea orgs, Discourse categories)