deploy: bind Agent Runtime updates to recorded resource identity
@asrujana-44 is already working on this.
Since Sep 14, 2026.
Assessment
This issue has not been assessed yet.
Description
Summary
Agent Runtime updates are selected by display_name on the v1.3.1 source baseline. A display name is not a unique resource identity, so an update can target an arbitrary same-name Reasoning Engine.
Baseline: 5a306f8956cb1eeae69f9709de0e4d61b44e11e7 (v1.3.1).
Reproduction
- Deploy an
agent_runtimeproject and keep its generateddeployment_metadata.json. - Create a second Reasoning Engine in the same project/location with the same display name.
- Run
agents-cli deployagain. - Separately, remove the metadata file and repeat with 0, 1, and 2 same-name resources.
Actual behavior
The baseline lists by display name and uses the first match. With duplicate names, selection depends on list order and a mutation may be sent to the wrong resource.
Expected behavior
- If
deployment_metadata.json.remote_agent_runtime_idexists, fetch exactly that resource by ID. - Before mutation, validate its project number, location, deployment target, resource name, and actual display name.
- Reject stale or inconsistent metadata.
- Only without usable metadata: create for 0 matches, update for exactly 1 match, and reject 2+ matches before any create/update API call.
- Revalidate after acquiring the local deployment-operation claim so a concurrently changed target cannot be mutated.
Minimal fix
Resolve the target in one shared selector that prefers the recorded resource ID and fails closed on every mismatch. Treat display-name lookup only as the metadata-free fallback and require it to be unambiguous. Atomically update metadata only after a successful mutation.
Reference implementation and regressions: fork Batch 4 branch.
Verification evidence
- Targeted identity/lifecycle suite: 35 tests passed under a fresh reviewer; full local suite: 92 passed.
- Multiple same-name case asserted zero calls to create/update/identity-create.
- Disposable isolated GCP project acceptance:
- create returned one recorded resource ID;
- update retained the same resource ID;
- after temporarily removing metadata and creating a second same-name resource, the CLI rejected before mutation;
- cleanup found 0 Reasoning Engines and 0 unfinished operations;
- project lifecycle was confirmed as
DELETE_REQUESTED.
ruff check src tests,ty check src, build, and Python 3.11/3.13 installed-wheel smoke tests passed.
- Dominant language
- Python
- Stars
- 6k
- Forks
- 670
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from google/agents-cli
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
google/agents-cli#86 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
google/agents-cli#85 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
google/agents-cli#84 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 72/100
google/agents-cli#83 · 2 comments · 1 reaction ·
-
google/agents-cli#79 · 2 comments · 1 assignee ·
All issues in google/agents-cli
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
anthropics/skills#1811 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
speaches-ai/speaches#678 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
datalayer/mcp-compose#42 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
conda-forge/spacy-feedstock#177 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
UKGovernmentBEIS/inspect_evals#2523 ·