Skip to content

Add Kiro to databricks aitools install - #6908

Merged
rugpanov merged 4 commits into
mainfrom
aitools-add-kiro
Oct 2, 2026
Merged

rugpanov merged 4 commits into
mainfrom
aitools-add-kiro

Conversation

@rugpanov

@rugpanov rugpanov commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Recreated from #6436 as a branch in databricks/cli (not a fork) so the JFrog/OIDC-gated CI jobs (task test, task test-exp-aitools, validate-generated) actually run — fork PRs can't obtain the OIDC token. Original author's commits are preserved. Supersedes #6436.

Summary

Adds Kiro to the agent registry so databricks aitools install treats it like any other skills-only agent. Follows the same shape as Goose (#6214), Gemini CLI (#6204) and Pi (#6199).

Why

Kiro reads agent skills from ~/.kiro/skills (user-level) and <workspace>/.kiro/skills (workspace-level), each skill a directory containing SKILL.md — exactly the layout this repo already emits. Today Kiro users have to fall back to databricks aitools install --path ~/.kiro/skills, which works but records no state, so aitools update and aitools uninstall never see those skills and aitools list reports every one of them as not installed.

Verification

Tested on macOS with Kiro 1.0.182.

Kiro's loader (NodeProgressiveContextSource) rejects a skill when frontmatter is missing, when name or description is empty, when name is outside 1–64 characters, when description exceeds 1024, or when name does not equal the directory name. Everything this repo emits satisfies that.

With 29 stable skills installed into ~/.kiro/skills, Kiro accepted all 29. The only rejections in that directory were two deliberately malformed probe skills added to confirm the loader was really scanning, plus two unrelated pre-existing skills whose frontmatter name disagrees with their directory:

skill.frontmatter.missing   zz-probe-no-frontmatter      (deliberate probe)
skill.fields.missing        zz-probe-no-description      (deliberate probe)
skill.name.mismatch         analyze-mlflow-trace         (pre-existing, unrelated)
skill.name.mismatch         analyze-mlflow-chat-session  (pre-existing, unrelated)

Worth knowing for anyone testing this: Kiro resolves skills lazily when a chat session starts, not when the IDE launches. Installing and then looking at an already-open Kiro shows nothing until a new session begins.

Notes on the registry entry

  • SkillsSubdir is left empty because Kiro's directory is literally skills, so the default applies.
  • SupportsProjectScope: true — Kiro's own picker text documents both scopes.
  • Binary: "kiro" is set, but Kiro is IDE-first so the binary is frequently absent from PATH. Detection then falls back to ConfigDir and reports files-only, which is the correct state for a skills-only agent (Plugin nil).

Telemetry

Also adds AitoolsAgentTypeKiro and the matching agentType case, so Kiro installs are not logged as TYPE_UNSPECIFIED and TestAgentTypeCoversRegistry stays green.

The Universe half is already merged, so nothing is owed on the proto side. That guard's failure message notes the enum lives in enum.proto (Universe) as well as aitools_install.go (CLI). KIRO = 10 was added to AitoolsAgentType.Type and merged to master on 2026-09-01 (universe 2524420), with Protobuf-Linter-Pr and OpenAPICompatibility-Pr both green — the latter being the machine check that the additive enum value is backward compatible. The two changes are order-independent: the enum addition is additive, and the CLI only emits "KIRO" once this PR merges. So this is the complete change and needs a review rather than any follow-up work.

Tests

go test ./cmd/aitools/... ./libs/aitools/... ./libs/telemetry/...

ok  github.com/databricks/cli/cmd/aitools              4.159s
ok  github.com/databricks/cli/libs/aitools/agents      1.529s
ok  github.com/databricks/cli/libs/aitools/installer   2.648s
ok  github.com/databricks/cli/libs/telemetry           6.616s
ok  github.com/databricks/cli/libs/telemetry/protos    2.023s

Test coverage added alongside the existing Goose cases: registry paths and project detection in libs/aitools/agents/registry_test.go, the skills-only assertion in agents_test.go, the project-scope declaration in libs/aitools/installer/installer_test.go, the agent-choices assertion in cmd/aitools/install_test.go, and the project-scope update path in cmd/aitools/update_test.go — which needed a .kiro project skills dir in the fixture alongside the existing .pi, .gemini and .goose ones.

libs/aitools/agents/detect_test.go is deliberately not extended: Goose and Gemini CLI have custom config-dir resolution to cover there (XDG_CONFIG_HOME, GOOSE_PATH_ROOT), while Kiro uses a plain ~/.kiro with no env override and registry_test.go already pins both of its paths.

Changelog

.nextchanges/cli/aitools-kiro.md, matching the fragment the Goose and Gemini CLI PRs each shipped.

Co-authored-by: Antony Prasad Thevaraj 280810845+antonyprasad-db@users.noreply.github.com

This pull request and its description were written by Isaac.

antonyprasad-db and others added 2 commits October 1, 2026 23:19
Kiro reads agent skills from ~/.kiro/skills (user-level) and
<workspace>/.kiro/skills (workspace-level), each skill a directory holding a
SKILL.md. Its loader requires frontmatter name and description, rejects a name
longer than 64 characters or a description longer than 1024, and requires the
name to match its directory. That is already what this repo emits, so Kiro
needs only a registry entry.

Verified on macOS with Kiro 1.0.182: all 29 stable skills written to
~/.kiro/skills are accepted by Kiro's loader. The only rejections in that
directory were two deliberately malformed probes and two unrelated
pre-existing skills whose frontmatter name does not match their directory.

Kiro is IDE-first, so the `kiro` binary is frequently absent from PATH.
Detection then falls back to ConfigDir and reports files-only, which is the
correct state for a skills-only agent (Plugin nil).

Also adds the telemetry enum and agentType case so Kiro installs are not
logged as TYPE_UNSPECIFIED, keeping TestAgentTypeCoversRegistry green. Note
the matching AitoolsAgentType value is still needed in enum.proto on the
Universe side; only the CLI half is in this change.

Follows the same shape as Goose (#6214), Gemini CLI (#6204) and Pi (#6199).
The Goose (#6214) and Gemini CLI (#6204) precedents each ship a
.nextchanges fragment plus a Kiro-equivalent assertion in
cmd/aitools/install_test.go and cmd/aitools/update_test.go. This branch
was missing all three.

The update test also needed its fixture extended, not just an assertion:
it creates .pi, .gemini and .goose project skill dirs, so
DetectProjectInstalled correctly reported no Kiro until .kiro was created
alongside them. The production path was never at fault.

libs/aitools/agents/detect_test.go is deliberately left alone. Goose and
Gemini CLI have custom config-dir resolution worth covering there
(XDG_CONFIG_HOME, GOOSE_PATH_ROOT); Kiro uses a plain ~/.kiro with no env
override, and registry_test.go already pins both its global and project
skills paths.

Co-authored-by: Isaac <no-reply@databricks.com>
@antonyprasad-db

Copy link
Copy Markdown
Contributor

Verified the recreate against #6436 — diff is byte-identical (9 files, +26/−2) and both commits keep the original author, thanks for doing it cleanly. test-exp-aitools green on both OSes confirms the move was worth it. Isaac review at 5863ce63: 0 findings.

Two things before I stamp:

  1. preview is failing — the changelog fragment still links Add Kiro to databricks aitools install #6436, but tools/validate_nextchanges.py requires the PR that adds the fragment (Add Kiro to databricks aitools install #6908). It accepts a comma-separated list, so this satisfies it and keeps the original PR visible in the release notes:
* `databricks aitools install` now supports Kiro, installing Databricks agent skills into its skills directory. ([#6436](https://github.com/databricks/cli/pull/6436), [#6908](https://github.com/databricks/cli/pull/6908))
  1. Could you add this as the last line of the PR description? Squash-merge takes the commit author from the PR opener, so without the trailer the commit on main loses the original authorship. Same thing Configure Docker authentication for Artifact Registry #6700 and Tag genie ask requests with databricks_cli source and disable viz #6056 did when they re-homed fork PRs:
Co-authored-by: Antony Prasad Thevaraj <280810845+antonyprasad-db@users.noreply.github.com>

Happy to approve as soon as preview is green.

@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: 3cf337b

Run: 36983159417

Env 🔄​flaky ✅​pass 🙈​skip Time
✅​ aws linux 276 15 5:40
✅​ aws windows 278 13 7:16
🔄​ azure linux 2 273 15 5:40
✅​ azure windows 277 13 7:36
✅​ gcp linux 276 15 5:31
✅​ gcp windows 278 13 7:58
Test Name azure linux
🔄​ TestFsRmNonEmptyDirectory 🔄​f
🔄​ TestFsRmNonEmptyDirectory/uc-volumes 🔄​f
Top 6 slowest tests (at least 2 minutes):
duration env testname
7:55 gcp windows TestAccept
7:33 azure windows TestAccept
7:14 aws windows TestAccept
4:07 aws linux TestAccept
4:04 azure linux TestAccept
3:57 gcp linux TestAccept

@antonyprasad-db

Copy link
Copy Markdown
Contributor

Heads up on the Integration Tests red — it's infra, not this change. The aws-cli-is / windows-server-latest cell died during environment setup: curl: (35) schannel ... CRYPT_E_REVOCATION_OFFLINE — the certificate-revocation server was unreachable — and Setup Python, Setup uv and Configure uv and pip were all skipped after it. No test ever ran: zero === RUN lines in the job log. Should clear on a re-run, and your changelog-fragment push will re-trigger it anyway.

rugpanov and others added 2 commits October 2, 2026 08:27
The nextchanges validator requires the fragment's trailing PR link to
reference the PR that ships it. This branch supersedes the fork PR #6436.

Co-authored-by: Isaac <no-reply@databricks.com>

@antonyprasad-db antonyprasad-db left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at 3cf337b5. Net diff is identical to the version I reviewed apart from the changelog fragment link, the main merge brought in nothing of its own, and all 27 checks are green. Thanks for re-homing it and for keeping the authorship intact.

@rugpanov
rugpanov added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit c232883 Oct 2, 2026
32 checks passed
@rugpanov
rugpanov deleted the aitools-add-kiro branch October 2, 2026 12:58
@eng-dev-ecosystem-bot

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: c232883

Run: 37009992502

Env ❌​FAIL 🔄​flaky ✅​pass 🙈​skip Time
❌​ aws linux 2 3 1432 1118 147:39
❌​ aws windows 3 1359 1143 160:30
❌​ azure linux 3 1283 1170 125:02
❌​ azure windows 3 1208 1195 142:56
❌​ gcp linux 6 1269 1174 140:37
❌​ gcp windows 6 1194 1199 155:11
8 interesting tests: 6 FAIL, 2 flaky
Test Name aws linux aws windows azure linux azure windows gcp linux gcp windows
❌​ TestAccept 🔄​f ❌​F ❌​F ❌​F ❌​F ❌​F
❌​ TestAccept/bundle/debug/fetch-repository-info ✅​p ✅​p ✅​p ✅​p ❌​F ❌​F
❌​ TestAccept/bundle/debug/fetch-repository-info/DMS= ✅​p ✅​p ✅​p ✅​p ❌​F ❌​F
❌​ TestAccept/bundle/debug/fetch-repository-info/DMS=true ✅​p ✅​p ✅​p ✅​p ❌​F ❌​F
❌​ TestAccept/bundle/dms/provenance ❌​F ❌​F ❌​F ❌​F ❌​F ❌​F
❌​ TestAccept/bundle/dms/provenance/DMS=true ❌​F ❌​F ❌​F ❌​F ❌​F ❌​F
🔄​ TestAccept/bundle/resources/postgres_synced_tables/recreate 🔄​f ✅​p 🙈​s 🙈​s 🙈​s 🙈​s
🔄​ TestAccept/bundle/resources/postgres_synced_tables/recreate/DMS=true 🔄​f ✅​p
Top 50 slowest tests (at least 2 minutes):
duration env testname
18:22 azure windows TestAccept/bundle/resources/clusters/deploy/data_security_mode/DMS=
15:39 azure linux TestAccept/bundle/invariant/no_drift/DMS=true/INPUT_CONFIG=cluster_apply_policy_default_values.yml.tmpl/READPLAN=
12:13 gcp windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
11:08 azure windows TestAccept/bundle/resources/clusters/deploy/simple/DMS=
10:58 gcp linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=
10:58 gcp windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=
10:37 gcp linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
10:03 azure linux TestAccept/bundle/invariant/no_drift/DMS=true/INPUT_CONFIG=cluster_libraries.yml.tmpl/READPLAN=
8:35 azure windows TestAccept/bundle/resources/clusters/deploy/data_security_mode/DMS=true
8:30 aws windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=
8:29 aws linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
8:22 aws linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=
8:07 aws windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
8:03 aws windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
7:31 azure windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
7:26 gcp linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=true
7:22 aws linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
7:20 aws linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
7:20 gcp windows TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=true
7:10 gcp windows TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=
7:00 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
6:59 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
6:59 gcp linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=
6:56 gcp linux TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=
6:53 azure linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
6:49 azure windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=
6:45 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
6:45 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
6:45 azure linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=
6:45 aws linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=true
6:44 gcp linux TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=true
6:42 aws linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=
6:37 azure linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=true
6:26 azure linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=
6:23 aws linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=
6:08 azure windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
6:04 aws windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
5:41 azure windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
5:41 azure windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
5:37 azure linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
5:24 aws linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
5:10 aws linux TestAccept/bundle/deploy/spark-jar-task/DMS=
5:09 azure linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
5:09 aws linux TestAccept/bundle/deploy/spark-jar-task/DMS=true
5:07 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
5:01 aws windows TestAccept/bundle/deploy/spark-jar-task/DMS=true
4:46 gcp linux TestAccept/bundle/deploy/spark-jar-task/DMS=
4:46 gcp linux TestAccept/bundle/resources/apps/inline_config/DMS=
4:42 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=
4:40 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true

deco-sdk-tagging Bot added a commit that referenced this pull request Oct 7, 2026
## Release v1.20.0

### Notable Changes

 * Remove the Terraform deployment engine. `bundle.engine: terraform` and `DATABRICKS_BUNDLE_ENGINE=terraform` now error, and a failed migration of existing Terraform state is reported as an error instead of falling back to Terraform. To keep deploying with Terraform, use Databricks CLI v1.19.x. ([#6888](#6888), [#6889](#6889))

### CLI

 * `databricks aitools install` now supports Kiro, installing Databricks agent skills into its skills directory. ([#6908](#6908))
 * Fixed `databricks api` corrupting integers larger than 2^53 (such as job and pipeline ids) — request bodies and responses now preserve them exactly. ([#6884](#6884))
 * Added `--auth-mode` and `--set <plugin>.<resourceKey>.authMode=obo|sp|both` to `databricks apps init` so AppKit resources can be accessed on behalf of the user, by the service principal, or both. The default stays service principal. ([#6886](#6886))
 * `databricks apps init` now requires a value for every field a service principal resource binding references, prompting for missing values in an interactive terminal and otherwise failing with the `--set` key to use, instead of creating a project with unset variables. ([#6903](#6903))
 * Add `databricks apps init --package-manager <npm|pnpm>` to select the package manager for Node.js templates. Infer the default quietly from template lockfiles and AppKit version, check prerequisites before creating files, and preserve template formatting and pnpm version pins. ([#6902](#6902))
 * Select npm or pnpm from `packageManager` declarations and lockfiles for `apps validate` and project validation during `apps deploy`. ([#6892](#6892))
 * Fix `auth docker host` reporting the credential helper as configured when its executable is missing from `PATH`. ([#6880](#6880))
 * Warn when the CLI binary was built more than 6 months ago and recommend updating. ([#6898](#6898))

### AI Runtime

 * Add an experimental rank-partitioned container images to AI Runtime jobs. ([#6841](#6841))
 * Support snapshot fields directly under `code_source` without requiring `type` or a nested `snapshot` block. ([#6927](#6927))
 * Map AIR priority and Unity Catalog image fields when converting run configurations to bundles. ([#6905](#6905))
 * Add workspace backend validation to `air run --dry-run`. ([#6934](#6934))

### Bundles

 * Warn that `bundle.terraform` is deprecated and has no effect since the Terraform deployment engine was removed. ([#6940](#6940))
 * Direct engine now detects and applies an explicitly configured zero-value boolean or float (e.g. `gcp_attributes.use_preemptible_executors: false`, `azure_attributes.spot_bid_max_price: 0`) added to a resource first deployed without the field, matching the existing handling of an explicit integer zero. ([#6882](#6882))
 * Fix `bundle deployment migrate` failing with "no such file or directory" when the Terraform state has no resources or the configuration no longer declares any of them. ([#6958](#6958))
 * `bundle run` and `pipelines run` now send the per-update `development` parameter for pipelines in development mode targets. Setting `development` on a pipeline is deprecated and now emits a warning; use `mode: development` instead. ([#6863](#6863))
 * Remove the hidden `bundle debug terraform` command. ([#6933](#6933))
 * Add support for `run_as.group_name` at the bundle and target levels for jobs and pipelines. ([#6676](#6676))
 * Fix recreating a secret scope that was deleted outside of the bundle with the direct deployment engine. ([#6970](#6970))
 * Accept title-case booleans (`True`/`False`, as rendered by Azure Pipelines) for boolean variables, and accept the same boolean strings (`yes`/`no`, `on`/`off`, ...) in Python bundles as in YAML. ([#6942](#6942))

### Dependency Updates

 * Bump `github.com/databricks/databricks-sdk-go` from v0.182.0 to v0.185.0. ([#6928](#6928))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants