Skip to content

Instantly share code, notes, and snippets.

@fleeto
Created September 26, 2026 14:50
Show Gist options
  • Select an option

  • Save fleeto/8ee86acc35ab9c1451780a56dbf4def4 to your computer and use it in GitHub Desktop.

Select an option

Save fleeto/8ee86acc35ab9c1451780a56dbf4def4 to your computer and use it in GitHub Desktop.
AX + Kimi end-to-end experiment assets (manifests and runner sources)

AX + Kimi E2E experiment assets

These files support the walkthrough in the AX/Kimi article. The two ax-code-demo*.yaml files are the manifests; the remaining files build and run the Kimi task image and guest uploader.

Clone this gist, then follow the article's setup steps to copy each file into the AX checkout under experiments/kimi-inspection/{manifests,image,guest-upload}. Do not put API credentials in these files; the article injects a temporary key at runtime.

apiVersion: ate.dev/v1alpha1
kind: WorkerPool
metadata:
name: ax-code-demo-workers
namespace: default
labels:
workload: ax-code-demo
spec:
replicas: 6
workerImage: ko://github.com/agent-substrate/substrate/cmd/ateom-gvisor
template:
nodeSelector:
ate.dev/substrate-version: "67253354"
resources:
requests:
cpu: 250m
memory: 2Gi
limits:
cpu: "1"
memory: 2Gi
apiVersion: ax.io/v1alpha1
kind: Workspace
metadata:
name: reverse-demo
atespace: default
spec:
git:
- name: origin
repo: https://github.com/fleeto/example.git
branch: ax-demo/seed-bug
dir: .
---
apiVersion: ax.io/v1alpha1
kind: Task
metadata:
name: fix-reverse
atespace: default
spec:
image: "REPLACE_WITH_RUNNER_IMAGE_DIGEST"
command: ["python3", "/opt/run-coding-agent.py"]
env:
- name: DEMO_WORKSPACE
value: /workspace/reverse-demo
resources:
requests:
cpu: "500m"
memory: "1Gi"
limits:
cpu: "1"
memory: "2Gi"
workspaces:
- name: reverse-demo
path: /workspace/reverse-demo
debug: true

你在 AX Task 的 gVisor 沙箱中修复 Go 示例仓库里的 Unicode 字符串反转错误。

先在仓库根目录创建并切换到新分支 ax-demo/kimi-fix。进入 hello 目录运行 go test ./...,确认中文字符串测试失败。检查实现和现有测试,修复 Unicode 反转问题;不要修改测试期望来掩盖错误。再次运行 go test ./...,只有全部通过后才创建 Git commit,提交信息使用 fix: reverse Unicode strings。提交前配置本地 Git 作者为 AX Demo Agent、ax-demo@example.invalid。不要推送分支。

不要读取 /run/kimi.key、环境变量中的凭据或工作区以外的文件;不要访问除 Kimi 模型调用外的网络,也不要尝试提权。只修改修复所需的源代码和回归测试。不要把密钥写进文件、命令输出或报告。

结束前确认当前分支为 ax-demo/kimi-fix,commit 已创建,工作区干净;报告基线测试、修复后测试、分支名和 commit hash。

FROM node:24-bookworm-slim
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates git golang-go python3 procps \
&& rm -rf /var/lib/apt/lists/*
RUN npm install --global @moonshot-ai/kimi-code@2.0.2 \
&& npm cache clean --force
COPY ax-task-runner /usr/local/bin/ax-task-runner
COPY run-coding-agent.py /opt/run-coding-agent.py
COPY coding-task-prompt.md /opt/coding-task-prompt.md
COPY kimi-config.toml /run/kimi-code/config.toml
RUN mkdir -p /opt/empty-skills
ENTRYPOINT ["/usr/local/bin/ax-task-runner"]
// Upload a small file over an existing local Kubernetes port-forward.
package main
import (
"context"
"fmt"
env "github.com/agent-substrate/env/proto/ateenv/v1alpha"
"google.golang.org/grpc"
"google.golang.org/grpc/credentials/insecure"
"google.golang.org/grpc/metadata"
"io"
"os"
"time"
)
func main() {
if len(os.Args) != 4 {
fmt.Fprintln(os.Stderr, "usage: guest-upload localhost:port atespace/actor destination")
os.Exit(2)
}
if err := run(); err != nil {
fmt.Fprintln(os.Stderr, err)
os.Exit(1)
}
}
func run() error {
data, err := io.ReadAll(io.LimitReader(os.Stdin, 2*1024*1024+1))
if err != nil {
return err
}
if len(data) > 2*1024*1024 {
return fmt.Errorf("file exceeds 2 MiB")
}
c, err := grpc.NewClient(os.Args[1], grpc.WithTransportCredentials(insecure.NewCredentials()))
if err != nil {
return err
}
defer c.Close()
ctx, cancel := context.WithTimeout(context.Background(), 30*time.Second)
defer cancel()
ctx = metadata.AppendToOutgoingContext(ctx, "ate-target-actor", os.Args[2])
stream, err := env.NewFileSystemServiceClient(c).WriteFile(ctx)
if err != nil {
return err
}
if err = stream.Send(&env.WriteFileRequest{Path: os.Args[3], Mode: 0600, Chunk: data}); err != nil {
return err
}
_, err = stream.CloseAndRecv()
return err
}
default_model = "inspection"
[providers.inspection]
type = "kimi"
base_url = "https://api.kimi.com/coding/v1"
api_key_env = "KIMI_API_KEY"
[models.inspection]
provider = "inspection"
model = "kimi-for-coding"
max_context_size = 262144
import json
import os
import pathlib
import subprocess
import time
workspace = pathlib.Path(os.environ.get("DEMO_WORKSPACE", "/workspace/reverse-demo"))
ready_file = pathlib.Path("/run/coding.ready")
key_file = pathlib.Path("/run/kimi.key")
started = time.time()
while not ready_file.exists():
if time.time() - started > 900:
raise SystemExit("credential bootstrap timed out")
time.sleep(1)
key = key_file.read_text().strip()
if not key:
raise SystemExit("Kimi API key is empty")
env = os.environ.copy()
env.update(KIMI_API_KEY=key, KIMI_CODE_HOME="/run/kimi-code")
prompt = pathlib.Path("/opt/coding-task-prompt.md").read_text()
started = time.time()
try:
result = subprocess.run(
[
"kimi",
"--skills-dir",
"/opt/empty-skills",
"--prompt",
prompt,
"--output-format",
"stream-json",
],
cwd=workspace,
env=env,
capture_output=True,
text=True,
timeout=900,
check=False,
)
(workspace / "kimi.jsonl").write_text(result.stdout.replace(key, "[REDACTED]"))
(workspace / "kimi.stderr.log").write_text(result.stderr.replace(key, "[REDACTED]"))
status = {"exit_code": result.returncode, "seconds": round(time.time() - started, 2)}
except subprocess.TimeoutExpired:
status = {"exit_code": 124, "seconds": round(time.time() - started, 2), "error": "Agent timed out"}
(workspace / "completion.json").write_text(json.dumps(status))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment