All Classes and Interfaces

Class
Description
Serves Release's A2A Agent Card at the spec's well-known path (/.well-known/agent-card.json): identity, the JSON-RPC service endpoint, and the currently visible skills.
The governed implementation of A2aAgentGateway: every call passes the A2A feature toggle and the agent-allowlist check — on the caller-supplied URL and on the service endpoint the Agent Card names — before any byte leaves the host, and every outcome is logged with the agent, method and remote task id (never with credentials or payloads).
The one implementation of the A2A agent allowlist, shared by every component that sends a byte to a caller-influenced URL: the outbound gateway (agent calls) and the push-notification sender (webhook POSTs registered by external callers — the classic SSRF vector, closed by requiring webhook targets to sit on the same allowlist as the agents themselves).
Mints and validates the push-notification callbacks the gateway offers remote agents.
Receives a remote agent's push notification and wakes the waiting Release task — nothing more.
A handoff-contract violation: the caller omitted governance metadata a mutating skill requires (change reference, risk classification, …).
Release's A2A server endpoint: JSON-RPC 2.0 over HTTP, implementing the Phase-0 slice of A2A 1.0 — SendMessage (execute a skill synchronously, answer with a completed or failed task) and GetTask (read a recent task back).
The host's built-in A2A wire layer: Agent Card resolution plus the JSON-RPC 2.0 binding over HTTPS/HTTP, on the JDK HttpClient, speaking A2A 1.0.
Push-notification configs external callers registered for release-backed A2A tasks: one config per task (the release id), replaced on re-registration, dropped when the release reaches a terminal state or the map outgrows its bound.
One registered webhook.
The inbound counterpart of the callback servlet: when a release backing an A2A task changes state, POST the mapped task to the webhook its remote caller registered — so external agents stop polling GetTask the same way our tasks stopped polling them.
The Phase-1 heart of "Release as an A2A server": a release is an A2A task, live.
Stands up Release's A2A server surface, mirroring McpServerConfiguration's structure: the JSON-RPC endpoint servlet at <servlet-path>/a2a behind the feature-toggle filter, and the Agent Card at the spec's well-known path /.well-known/agent-card.json (which checks the toggle itself, as the well-known path sits outside the servlet base path).
Runtime gate: answers 404 while the "A2A agent-to-agent" feature setting is disabled, so the endpoint can be toggled from the UI without a restart.
The one place A2A payloads become JSON on the server side, delegating to the SDK's own mapper.
One skill Release advertises on its Agent Card and executes when an external A2A agent sends a message for it.
What a skill produced: either an immediate text artifact (the Phase-0 shape — the A2A task is complete the moment the skill returns), or a release the skill started, whose live state IS the A2A task from then on.
The live set of skills the A2A server serves: the host's built-in skills (seeded at construction, never removable) plus plugin-contributed ones that come and go with their bundles.
Bridges A2aSkillset extensions — whichever plugin contributed them, and however it authored the contribution — into the live A2aSkillRegistry, so contributed skills appear on the Agent Card and endpoint without restart and disappear with their bundle.
Recently answered A2A tasks, so a client that got a task from SendMessage can read it back with GetTask.
The first built-in A2A skill: a read-only release status summary, so an external agent can ask "where is this release?" and learn — in its own protocol's terms — whether a human is currently in the loop (an active gate or manual task).
Starts any Release template as a governed release on behalf of an external agent and tracks it as a live A2A task — the general-purpose counterpart of RequestDeploymentApprovalSkill's approval-specific contract.
The flagship governance skill: an external agent asks Release to run an approval workflow and only sees TASK_STATE_COMPLETED once policy — and any humans the workflow pulls in — approve.