Skip to content

Unify deployment sandbox configuration and node specifications - #95

Merged
SaladDay merged 31 commits into
mainfrom
codex/hosted-deployment-spec
Sep 25, 2026
Merged

SaladDay merged 31 commits into
mainfrom
codex/hosted-deployment-spec

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Managed sandbox settings currently differ between Core setup and node files. This change gives each deployment one database-owned Provider, enforced resource specification and immutable Runtime release. Nodes inherit and verify that selection before enrollment and reconnect; unsupported limits and mismatched resources or Runtime reject explicitly. The installer keeps Core/Web/PostgreSQL with zero nodes by default and preserves identity/configuration on retries.

Provider, specification and Runtime changes share maintenance, generation and retained-resource guards. Candidate validation precedes commit; failed changes retain the active configuration. An explicit administrator Session archive now requests cancellation and sandbox/snapshot cleanup while preserving public Session history and persisted Files/Artifacts. Unpersisted workspace content is discarded and the original Session cannot resume. Cleanup remains pending until the existing lifecycle confirms release; unknown creates and retained snapshots continue blocking a switch. The management client, proxy allowlist and operator/API documentation cover this flow. Public /v1 and caller-managed Runtime contracts are unchanged.

Validation:

  • Real Docker resources on two nodes, an exact E2B template build, and microsandbox CPU/memory/disks; earlier real Kimi execution, Files/Artifacts, cancellation, restart continuation and microsandbox snapshot/restore qualification retained.
  • Real active Kimi/Codex archive cancelled the Turn and released Docker compute. Existing Docker/E2B/microsandbox Sessions retained history, Artifact content hashes and persisted File bytes after archive and Core restart. E2B native lookup returned 404; microsandbox's exact snapshot identity/path was removed.
  • Docker reached zero owned resources, changed CPU specification from 3 to 2, and advanced generation. All archived Sessions rejected fresh input after maintenance resumed. Cross-Project requests, Project keys and stale generations rejected correctly.
  • Transaction rollback, lifecycle ordering, lease loss, HTTP Worker wiring, shared client and proxy checks passed. Public OpenAPI remains byte-identical; management OpenAPI and SQLC were regenerated.
  • Complete make check passed on final candidate 869d5f1, including the PostgreSQL suite and all 147 browser cases (installed Playwright Chromium). A fresh independent GPT-6 Astra high review of the full 7322982..869d5f1 diff found no concrete blockers.

Limits: Docker ordinary volumes and E2B do not offer the requested per-sandbox hard disk quotas; unsupported fields reject. Installation qualification used recorded candidate artifacts, not a published release. Original PR95 test databases required explicit alignment of their unmerged migration number after main introduced migration 68; business data was preserved. Microsandbox retains a separate unrelated retained allocation, which was not manually released; only Docker demonstrated a fully drained configuration switch.

@SaladDay
SaladDay marked this pull request as ready for review September 25, 2026 07:50
@SaladDay
SaladDay merged commit 8e53e38 into main Sep 25, 2026
3 checks passed
SaladDay added a commit that referenced this pull request Sep 25, 2026
* Drain deployments saved before sandbox specifications

A Web-selected Docker or microsandbox deployment saved before #95 keeps the
empty specification default after migration. Current Core could neither load
its provider nor authenticate its retained nodes, so its sandboxes could not be
archived or cleaned up, and the specification could never be replaced.

Load such a deployment for draining only: retained nodes that never recorded a
specification digest or generation reconnect, fresh hosted sandboxes are
refused, and node configuration and enrollment stay closed. The existing
maintenance, archive and PUT sequence then records a specification and retires
those nodes. E2B deployments from that period remain out of scope.

* Refuse enrollment tokens while a deployment has no specification

Address blind-review follow-ups: an unspecified deployment cannot issue a node
enrollment token that would always fail, the drain rule applies only to
Web-managed selections, and the contract notes that GET omits the missing
specification.
@SaladDay
SaladDay deleted the codex/hosted-deployment-spec branch October 10, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant