itential/itential-builder
AI agent skills for the Itential Platform — deliver infrastructure automation from spec through acceptance testing and as-built documentation. Covers requirements, feasibility, design, build, QA/acceptance testing, FlowAgent, IAG, and MOP.
Changelog
Versions correspond to the plugin manifest version (plugin.json) and the GitHub
release tag — what every tool's update installs.
Unreleased
2.1.0
-
Added a Gateway4 → Gateway5 migration delivery: a new spec (
spec-gateway4-to-gateway5-migration) that takes thegateway4-to-gateway5readiness report as input, and a conversion guide covering the inventory move to Inventory Manager with broker actions, services imported through Gateway Manager, the task-by-task rewire, and parity tests — proven on a live Gateway4 and Gateway5 against a real device -
Added
convert_gateway4.py(bundled with builder-agent and iag): reads Gateway4 read-only, or its exported JSON, and generates the Gateway5services.yaml(decorators built from each script's Gateway4 schema or its ownargparseflags), the service repository layout with playbooks reading their devices from the Inventory Manager nodes passed torunService, Inventory Manager nodes with broker attributes (including enable mode fromansible_become, which config pushes need) and secret references, and a report of what still needs review -
Added broker-action inventories to
itential-inventory:createBrokerActions, theitential_*attribute convention, and how Gateway4 inventory variables map to it -
Added builder-agent guidance for Enable Query edge cases: array indexes (
#/items/0shown as.items[0]), keys containing/,~or.(dotted keys need.["a.b"]), and what a path that doesn't exist does (error transition; onevaluation, the failure transition) -
Added
helpers/enable_query.pyto generate and check Enable Query decorators (check/fix/apply_decorators); it also flags$varreferences placed inside a static object, which are sent as literal text -
Changed the config-push examples in the asset library from
AGManager.itential_cli(Gateway4) toGatewayManager.sendConfig: "Push Configuration" (itential-platform-configuration-management.json), "Push Configuration to Device - IAG" (vendor-arista-eos.json) and the three VXLAN Fabric Services LCM action workflows. Each takesinventoryNameandclusterIdand checks success per device. In the push workflows arunCodetask replaces the "Process Push Configuration Data" transformation and returns the config, inventory target and messages in one result (pushData, replacing theconfigurationToPushoutput). Both push workflows were run against a live Arista EOS device, when the push lands and when it can't -
Changed builder-agent and iag to recommend
sendConfigfor config push, andrunCodeinstead of JST transformations for reshaping data;itential_cliis called out as Gateway4, for existing workflows only, with two ways to move the tasks that read its output -
Fixed
scripts/use_case_init.pywriting an.auth.jsonwithoutplatform_url/auth_method, which made solution-arch-agent'spull-platform-data.pycrash; it now also startsuse-case-memory.mdfrom the template -
Fixed solution-arch-agent's platform pull recording only the first page of workflows (100) and devices (1,000) — it now fetches all of them, so reuse searches see every workflow
-
Fixed skills disagreeing on where a use case lives:
{use-case}isuse-cases/<use-case-name>/everywhere -
Fixed
exploretreating theenvironments/*.envtemplates as real credentials, andgateway4-to-gateway5naming the username/password modelogininstead ofpassword -
Fixed the
iagAnsible examples: JSON playbook output is set withstdout_callbackinansible.cfg—ANSIBLE_STDOUT_CALLBACKinruntime.envis ignored by Gateway5. Added gateway gotchas found on a live Gateway5: importing services through Gateway Manager, waiting for the new service id after aforceimport, getting Ansible onto the gateway viarequirements.txt, and howrunServicehands Inventory Manager nodes to a service on stdin -
Fixed transformation tasks in
itential-platform-configuration-management.jsonandvendor-arista-eos.jsonthat pointed at transformations outside their project, so 8 workflows imported as drafts that couldn't start; all 8 now start. Command Template Runner_v2's missing "Command Template Response Processor" and its four "Standard Output" transformations are nowrunCodetasks writing onestandardOutputresult (success,reason,errorMessage), replacing the separatesuccess/reasonoutputs; it needs aclusterIdinput. Also fixed the LCM workflows' success check, which only looked at Gateway4'sicode— that reports success even when the device rejects the configuration -
Fixed builder-agent's Enable Query guidance: it only showed the plain-field decorator, so workflows with a
#/pathbut a missing or wrong decorator ran correctly yet showed no query in Studio, and opening then saving them silently dropped the query. It now gives the verifiedpointerfor every field shape — top-level fields, whole object fields,runCodedataandtransformationvariableMapkeys,mergeitems,childJobvariables andchildJobloopdata_array -
Fixed builder-agent telling builders to put
queryinside anevaluationoperand, which never applied; the query goes on each evaluation item (query/rightQuery) -
Fixed builder-agent saying a
mergeitem reading achildJoboutput must usevalue; on 6.5.2valueresolves to null with no error andvariableis correct -
Fixed the push-config workflows' error-view decorator: its
displayPathused.results.0.outputwhere Studio writes.results[0].output, so Studio showed the query wrong and could strip it on save.enable_query.py checknow passes on every file in the asset library -
Removed the repo-wide
customizations/folder: each skill's owncustom/org,custom/teamandcustom/devfolders are the one place for an organization's rules, and they travel with every install. Move any rules fromcustomizations/into the matching skills'custom/folders -
Removed
scripts/use-skill; install the plugin or load a clone withclaude --plugin-dir .instead
2.0.0
- Added native installs for Codex CLI, GitHub Copilot (CLI and VS Code) and Cursor alongside Claude Code, each reading the same
skills/folder — no per-tool copies in the repo. Working from a clone, load it as a plugin (e.g.claude --plugin-dir .); skills are invoked with the plugin prefix (/itential-builder:spec-agent) - Added per-skill
custom/org,custom/teamandcustom/devfolders for an organization's own rules, kept separate from Itential's content so updates never overwrite them - Changed every skill to be self-contained: the templates, spec library and reference files it uses are bundled into its own
assets/folder - Removed the automatic version-bump and mirror-regeneration workflows; versions are bumped by hand when releasing, and the release tag always matches the plugin version
1.6.5
- Added the full six-stage delivery lifecycle skills:
spec-agent,solution-arch-agent,builder-agent,qa-agent, plusflowagent-to-specandproject-to-specfor productionizing an existing FlowAgent or reverse-engineering an undocumented project (#16, #78, #79) - Added platform-domain skills:
itential-json-forms,gateway4-to-gateway5migration readiness assessment, and org/team/dev customization layers so a foundational skill can be overridden without editing it directly (#43, #81, #94) - Added auto-versioning CI: branch-name-based PR labeling, Release Drafter changelog drafting, and a dumb always-patch version-bump workflow that opens its own PR on every merge (#97, #103, #105)
- Added cross-tool Agent Skills compatibility —
.agents/skillssymlinks and a Codex-native plugin manifest so Copilot, Codex CLI, and Cursor can use this repo's skills alongside Claude Code (#109) - Added dozens of helper JSON templates and real, importable vendor/platform asset exports (ops manager, LCM, config management, data manipulation, vendor integrations), replacing hand-crafted example snippets (#7, #12, #28, #76)
- Fixed numerous
builder-agentplatform gotchas found via live builds:incomingRefscaching,ViewHTML/manual-task quirks, workflow delete/rename, project membership patching after create/import, childJob variable behavior on P6.4.0, and canvas-layout/task-ID verification (#33, #34, #64, #67, #70, #74, #102, #106) - Fixed
PATCH /projectssilently ignoring theaccessControlbody — use themembersarray instead (#64) - Fixed Golden Config guidance to prohibit wiring any Configuration Manager remediation task, since Golden Config only detects and reports drift, never applies fixes to a device (#69)
- Fixed two commits that had been pushed directly to
main, bypassing branch protection, by reverting them (#77) - Fixed
version-bump.yml: moved off a direct push tomain(rejected by branch protection) to opening its own PR, then simplified to an unconditional patch bump with no label-based categorization (#103, #105) - Changed the JSON Forms skill name (
app-json_forms→itential-json-forms) and standardized Gateway 4 → Gateway 5 terminology repo-wide (#80, #86)