[management] Name private capabilities, not an embedded proxy, in the refusal

The requirement is a cluster with private capabilities, which is what the
proxy reports and what the dashboard renders as supports_private. Framing
the refusal around an embedded proxy named one way of getting there as if
it were the requirement, and told an API user to fix the wrong thing. The
message, the comments and the test fixtures now speak of private
capabilities throughout.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sa3DsBDP3VciAi4PPG17L6
This commit is contained in:
mlsmaycon
2026-09-13 10:38:15 +00:00
co-authored by Claude Fable 5.1
parent 2ee84e475a
commit e5dc66b65b
6 changed files with 50 additions and 53 deletions
@@ -89,7 +89,7 @@ func TestAgentNetwork_UpdateSettings_PreservesImmutableAndTogglesCollection(t *t
// Bootstrap is an explicit settings create; providers have no settings
// side effects anymore.
seedEmbeddedProxyCluster(t, am.Store, clusterAddr)
seedPrivateProxyCluster(t, am.Store, clusterAddr)
before, err := mgr.CreateSettings(ctx, adminUserID, agenttypes.DefaultSettings(accountID), clusterAddr, "")
require.NoError(t, err, "CreateSettings must bootstrap the row")
require.Equal(t, clusterAddr, before.ProxyAddress, "proxy address pinned at bootstrap")