Repository navigation
Unify deployment sandbox configuration and node specifications - #95
Merged
Merged
Conversation
SaladDay
marked this pull request as ready for review
September 25, 2026 07:50
This was referenced Sep 25, 2026
SaladDay
added a commit
that referenced
this pull request
Sep 25, 2026
* Drain deployments saved before sandbox specifications A Web-selected Docker or microsandbox deployment saved before #95 keeps the empty specification default after migration. Current Core could neither load its provider nor authenticate its retained nodes, so its sandboxes could not be archived or cleaned up, and the specification could never be replaced. Load such a deployment for draining only: retained nodes that never recorded a specification digest or generation reconnect, fresh hosted sandboxes are refused, and node configuration and enrollment stay closed. The existing maintenance, archive and PUT sequence then records a specification and retires those nodes. E2B deployments from that period remain out of scope. * Refuse enrollment tokens while a deployment has no specification Address blind-review follow-ups: an unspecified deployment cannot issue a node enrollment token that would always fail, the drain rule applies only to Web-managed selections, and the contract notes that GET omits the missing specification.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Managed sandbox settings currently differ between Core setup and node files. This change gives each deployment one database-owned Provider, enforced resource specification and immutable Runtime release. Nodes inherit and verify that selection before enrollment and reconnect; unsupported limits and mismatched resources or Runtime reject explicitly. The installer keeps Core/Web/PostgreSQL with zero nodes by default and preserves identity/configuration on retries.
Provider, specification and Runtime changes share maintenance, generation and retained-resource guards. Candidate validation precedes commit; failed changes retain the active configuration. An explicit administrator Session archive now requests cancellation and sandbox/snapshot cleanup while preserving public Session history and persisted Files/Artifacts. Unpersisted workspace content is discarded and the original Session cannot resume. Cleanup remains pending until the existing lifecycle confirms release; unknown creates and retained snapshots continue blocking a switch. The management client, proxy allowlist and operator/API documentation cover this flow. Public
/v1and caller-managed Runtime contracts are unchanged.Validation:
make checkpassed on final candidate869d5f1, including the PostgreSQL suite and all 147 browser cases (installed Playwright Chromium). A fresh independent GPT-6 Astra high review of the full7322982..869d5f1diff found no concrete blockers.Limits: Docker ordinary volumes and E2B do not offer the requested per-sandbox hard disk quotas; unsupported fields reject. Installation qualification used recorded candidate artifacts, not a published release. Original PR95 test databases required explicit alignment of their unmerged migration number after main introduced migration 68; business data was preserved. Microsandbox retains a separate unrelated retained allocation, which was not manually released; only Docker demonstrated a fully drained configuration switch.