Skip to content

Ops scripts: backend container name, safe re-runs, probe Vinted again - #714

Merged
keysersoft merged 1 commit into
mainfrom
chore/ops-scripts-hygiene
Sep 25, 2026
Merged

keysersoft merged 1 commit into
mainfrom
chore/ops-scripts-hygiene

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

What

1. Container name in the ops scripts. The cloud backend has run as amcp-cloud-backend since the container split (docker-compose.cloud.yml). Every docker cp / docker exec / docker restart line in scripts/ops/ said amcp-cloud-app, and those commands no longer work. They now use amcp-cloud-backend. No other file in the repo (docs included) used the old name. Each restart step now warns that the restart takes the API down for ~30–60 s, and shows how to silence the host uptime probe first. The probe reads an expiry epoch from /var/lib/anythingmcp-probe/maintenance (deploy/cloud/uptime-probe.sh), the same file deploy-cloud.yml sets:

mkdir -p /var/lib/anythingmcp-probe && echo $(( $(date -u +%s) + 600 )) > /var/lib/anythingmcp-probe/maintenance
docker restart amcp-cloud-backend
rm -f /var/lib/anythingmcp-probe/maintenance

Behaviour is unchanged apart from the wording of the hints the scripts print.

2. Safe re-runs.

  • migrate-vinted-cloud.mjs never checked whether a connector was already migrated, so a dry run after --apply reported every connector as still to migrate. It now skips connectors already at the target and lists them as already current. A connector is at the target when all of these hold:

    • the base URL matches;
    • the auth type is LOGIN_TOKEN, with the adapter's authConfig (decrypted and compared);
    • config.adapterVersion matches;
    • every catalog tool is present, not deprecated, has useProxy off, and has the same description, parameters and endpoint mapping as the catalog;
    • no live tool is missing from the catalog.

    A second --apply writes nothing.

  • migrate-deutsche-bahn-cloud.mjs (prints SQL): the SQL now leaves out connectors already on this adapterVersion and MOTIS URL, and prints an already_current count. A second run matches no rows.

  • fix-etsy-api-key.mjs and fix-reddit-oauth.mjs were already safe to re-run. resync-catalog-connectors.mjs already reports already current.

  • migrate-amadeus-client-credentials.mjs is deleted because the Amadeus adapter was removed in Remove the Amadeus adapter: Amadeus retired its Self-Service API #713.

3. Weekly probe covers Vinted again. probe-keyless.mjs used to test only authType: NONE, so Vinted dropped out when it moved to LOGIN_TOKEN. "Keyless" now means the user supplies no credentials: no {{VAR}} in the authConfig, and no required env vars beyond those the operator provides. The rule reads the adapter JSON, so there is no Vinted-specific code.

  • The probe reproduces LOGIN_TOKEN the way login-token.service.ts / injectLoginTokenHeaders() do: cookie token (last non-empty Set-Cookie value) or body token (tokenJsonPath), then headerName / headerTemplate / extraHeaders.
  • A failed login is reported as login-failed, which counts as a failure under --check.
  • Other auth types with static credentials are listed as unsupported-auth, a warning, so they show up in the output instead of being skipped. Today Vinted is the only adapter in this category.

Verification

  • Local throwaway postgres:17-alpine, prisma migrate deploy, built backend. Seeded two old-style Vinted connectors: one with a baseline on www.vinted.fr, and one pre-baseline on www.vinted.de with an operator response mapping and a disabled tool. Also seeded one non-Vinted control connector.
    • Dry run: Would migrate 2 of 2 (0 already current).
    • --apply: Migrated 2 of 2, 9 tools in total.
    • Dry run: Would migrate 0 of 2 (2 already current).
    • --apply again: Migrated 0 of 2, still 9 tools. A DB snapshot including updated_at is identical before and after.
    • The original script on the same data still says Would migrate 2.
    • After setting useProxy back on for one tool of one connector, only that connector is migrated again.
  • Deutsche Bahn SQL applied twice against the same DB: 1 connector to migrate on the first run, then already_current 1, connectors_to_migrate 0, with updated_at unchanged.
  • Etsy and Reddit scripts: a second --apply patches 0 rows.
  • Probe: node scripts/probe-keyless.mjs --only=vinted --check gives ok 200 vinted_search_items (anonymous LOGIN_TOKEN), exit 0. A full --all run gives the same results as the old script, plus Vinted (16 probed instead of 15, no new failures). Two negative checks:
    • With a wrong cookie name the result is login-failed.
    • Without the token Vinted answers 403 (bot-blocked), which shows the token is what makes the call pass.

Not run against production.

- scripts/ops: the cloud backend runs as amcp-cloud-backend since the
  container split; every docker cp/exec/restart line now names it. Each
  restart step now silences the host uptime probe first with an expiring
  /var/lib/anythingmcp-probe/maintenance marker (as deploy-cloud.yml does),
  since the restart takes the API down for ~30-60 s.
- migrate-vinted-cloud.mjs: skip connectors already at the target (base
  URL, LOGIN_TOKEN with the adapter's authConfig, adapterVersion, tool set)
  and list them as "already current"; a second --apply writes nothing.
- migrate-deutsche-bahn-cloud.mjs: the generated SQL leaves out connectors
  already on this adapterVersion and MOTIS URL and reports them.
- Remove migrate-amadeus-client-credentials.mjs: the Amadeus adapter is
  gone (#713).
- probe-keyless.mjs: "keyless" now means no user-supplied credentials, not
  authType NONE. Adapters whose authConfig has no {{VAR}} are probed too,
  with LOGIN_TOKEN reproduced from the adapter JSON (cookie or body token),
  which brings Vinted's anonymous session back into the weekly run. Auth
  types the probe cannot reproduce are listed as unsupported-auth.
@keysersoft
keysersoft merged commit d0deafc into main Sep 25, 2026
14 checks passed
@keysersoft
keysersoft deleted the chore/ops-scripts-hygiene branch September 25, 2026 16:11
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 25, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant