Compare commits
12
Commits
7145fb536a
..
v1.0.6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
abbe47b1b9 | ||
|
|
9bca465565 | ||
|
|
d220623a9f | ||
|
|
e801d96410 | ||
|
|
869d82998b | ||
|
|
aa986a470e | ||
|
|
520fc8f81e | ||
|
|
d46e3ca247 | ||
|
|
ec0b012586 | ||
|
|
36c80458e0 | ||
|
|
06cf4d1b9e | ||
|
|
4f1d306fdf |
@@ -0,0 +1,27 @@
|
||||
name: Publish Workspace Image
|
||||
|
||||
on:
|
||||
push:
|
||||
paths:
|
||||
- 'coder/workspace.Dockerfile'
|
||||
branches:
|
||||
- main
|
||||
|
||||
concurrency:
|
||||
group: publish-workspace
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
runs-on: self-hosted
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Log in to registry
|
||||
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.samson.media -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
|
||||
- name: Build and push
|
||||
run: |
|
||||
IMAGE=registry.samson.media/coder-workspace
|
||||
docker build -f coder/workspace.Dockerfile -t "$IMAGE:latest" .
|
||||
docker push "$IMAGE:latest"
|
||||
+82
-127
@@ -76,27 +76,6 @@ data "coder_parameter" "memory" {
|
||||
}
|
||||
}
|
||||
|
||||
data "coder_parameter" "disk_size" {
|
||||
name = "disk_size"
|
||||
display_name = "Disk Size (GB)"
|
||||
description = "Persistent home directory size"
|
||||
type = "number"
|
||||
default = "10"
|
||||
mutable = false
|
||||
|
||||
option {
|
||||
name = "5 GB"
|
||||
value = "5"
|
||||
}
|
||||
option {
|
||||
name = "10 GB"
|
||||
value = "10"
|
||||
}
|
||||
option {
|
||||
name = "20 GB"
|
||||
value = "20"
|
||||
}
|
||||
}
|
||||
|
||||
# ─── Automation Parameters ───────────────────────────────────────────────────
|
||||
|
||||
@@ -217,6 +196,15 @@ data "coder_parameter" "callback_url" {
|
||||
mutable = false
|
||||
}
|
||||
|
||||
data "coder_parameter" "claude_oauth_token" {
|
||||
name = "claude_oauth_token"
|
||||
display_name = "Claude OAuth Token"
|
||||
description = "OAuth token for Claude Code Max subscription"
|
||||
type = "string"
|
||||
default = ""
|
||||
mutable = false
|
||||
}
|
||||
|
||||
data "coder_parameter" "deploy_env" {
|
||||
name = "deploy_env"
|
||||
display_name = "Deploy Environment"
|
||||
@@ -375,33 +363,6 @@ resource "kubernetes_resource_quota_v1" "workspace" {
|
||||
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
|
||||
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
|
||||
"limits.memory" = "${data.coder_parameter.memory.value}Mi"
|
||||
"requests.storage" = "${data.coder_parameter.disk_size.value}Gi"
|
||||
"persistentvolumeclaims" = "1"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# =============================================================================
|
||||
# Storage
|
||||
# =============================================================================
|
||||
|
||||
resource "kubernetes_persistent_volume_claim_v1" "home" {
|
||||
metadata {
|
||||
name = "home"
|
||||
namespace = kubernetes_namespace_v1.workspace.metadata[0].name
|
||||
labels = local.labels
|
||||
}
|
||||
|
||||
wait_until_bound = false
|
||||
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
storage_class_name = "longhorn-backup"
|
||||
|
||||
resources {
|
||||
requests = {
|
||||
storage = "${data.coder_parameter.disk_size.value}Gi"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -442,8 +403,28 @@ resource "coder_agent" "main" {
|
||||
web_terminal = true
|
||||
}
|
||||
|
||||
metadata {
|
||||
display_name = "Task Status"
|
||||
key = "task_status"
|
||||
script = <<-EOS
|
||||
if [ -f ~/task-output.log ]; then
|
||||
if grep -q "Task completed" ~/task-output.log 2>/dev/null; then
|
||||
echo "✅ Complete"
|
||||
else
|
||||
echo "⏳ Running ($(wc -l < ~/task-output.log) lines)"
|
||||
fi
|
||||
elif [ -n "$TASK_TYPE" ]; then
|
||||
echo "⏳ Starting..."
|
||||
else
|
||||
echo "Interactive"
|
||||
fi
|
||||
EOS
|
||||
interval = 10
|
||||
}
|
||||
|
||||
env = {
|
||||
ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value
|
||||
CLAUDE_CODE_OAUTH_TOKEN = data.coder_parameter.claude_oauth_token.value
|
||||
GITHUB_TOKEN = data.coder_external_auth.github.access_token
|
||||
GITEA_TOKEN = data.coder_parameter.gitea_token.value
|
||||
GITEA_ORG = data.coder_parameter.gitea_org.value
|
||||
@@ -457,30 +438,19 @@ resource "coder_agent" "main" {
|
||||
|
||||
startup_script = <<-EOT
|
||||
#!/bin/bash
|
||||
|
||||
# Always notify the orchestrator when done, even on failure
|
||||
notify_complete() {
|
||||
if [ -n "$CALLBACK_URL" ]; then
|
||||
curl -s -X POST -H "Content-Type: application/json" \
|
||||
-d "{\"status\":\"$1\"}" \
|
||||
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
|
||||
fi
|
||||
}
|
||||
trap 'notify_complete "failed"' ERR EXIT
|
||||
|
||||
set -e
|
||||
|
||||
# --- Install Node.js 22 ---
|
||||
if ! command -v node &> /dev/null; then
|
||||
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
|
||||
sudo apt-get install -y nodejs
|
||||
fi
|
||||
|
||||
# --- Install global tools ---
|
||||
if ! command -v wrangler &> /dev/null; then
|
||||
sudo npm install -g wrangler @anthropic-ai/claude-code
|
||||
fi
|
||||
|
||||
# --- Install Playwright system dependencies ---
|
||||
if ! dpkg -s libgbm1 &> /dev/null; then
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
||||
libcups2t64 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
|
||||
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2t64 libatspi2.0-0 \
|
||||
|| sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
||||
libcups2 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
|
||||
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2 libatspi2.0-0
|
||||
fi
|
||||
|
||||
# --- Configure git ---
|
||||
git config --global user.name "${data.coder_workspace_owner.me.full_name}"
|
||||
git config --global user.email "${data.coder_workspace_owner.me.email}"
|
||||
@@ -493,27 +463,39 @@ resource "coder_agent" "main" {
|
||||
fi
|
||||
|
||||
# --- Clone repository ---
|
||||
if [ -n "$REPO_CLONE_URL" ] && [ ! -d ~/project ]; then
|
||||
if [ -n "$REPO_CLONE_URL" ]; then
|
||||
git clone "$REPO_CLONE_URL" ~/project
|
||||
cd ~/project
|
||||
|
||||
# Switch to develop branch if it exists
|
||||
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
|
||||
|
||||
# Install backend deps
|
||||
npm ci --legacy-peer-deps
|
||||
# Lightweight stages only need the code, not a full build
|
||||
LIGHT_STAGES="analyse architect release maintenance"
|
||||
if echo "$LIGHT_STAGES" | grep -qw "$TASK_TYPE"; then
|
||||
echo "Lightweight stage ($TASK_TYPE) — skipping build"
|
||||
else
|
||||
# Install deps if package.json exists
|
||||
if [ -f package.json ]; then
|
||||
npm ci --legacy-peer-deps || npm ci
|
||||
fi
|
||||
|
||||
# Install frontend deps
|
||||
# Install frontend deps if present
|
||||
if [ -f frontend/package.json ]; then
|
||||
cd frontend && npm ci && cd ..
|
||||
npm run build:frontend 2>/dev/null || true
|
||||
fi
|
||||
|
||||
# Build frontend (required — vitest fails without frontend/dist)
|
||||
npm run build:frontend
|
||||
|
||||
# Install Playwright Chromium
|
||||
# Install Playwright if needed
|
||||
if grep -q "playwright" package.json 2>/dev/null; then
|
||||
npx playwright install chromium
|
||||
fi
|
||||
|
||||
# Apply local migrations
|
||||
npm run db:migrate:local
|
||||
# Apply local migrations if script exists
|
||||
if npm run --silent db:migrate:local 2>/dev/null; then
|
||||
echo "Local migrations applied"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
# --- Automated task execution ---
|
||||
@@ -525,18 +507,21 @@ resource "coder_agent" "main" {
|
||||
ARGS="$DEPLOY_ENV"
|
||||
fi
|
||||
|
||||
# Run Claude Code in non-interactive mode
|
||||
claude --print --dangerously-skip-permissions "/project:$TASK_TYPE $ARGS" 2>&1 | tee ~/task-output.log
|
||||
|
||||
echo "Task completed. Output saved to ~/task-output.log"
|
||||
|
||||
# Notify orchestrator that the task is done
|
||||
if [ -n "$CALLBACK_URL" ]; then
|
||||
curl -s -X POST -H "Content-Type: application/json" \
|
||||
-d '{"status":"complete"}' \
|
||||
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
|
||||
# Read the slash command .md file, strip YAML frontmatter, substitute $ARGUMENTS
|
||||
CMD_FILE=".claude/commands/$TASK_TYPE.md"
|
||||
if [ ! -f "$CMD_FILE" ]; then
|
||||
echo "ERROR: Command file not found: $CMD_FILE"
|
||||
exit 1
|
||||
fi
|
||||
PROMPT=$(sed '1{/^---$/!q}; 1,/^---$/d' "$CMD_FILE" | sed "s/\\\$ARGUMENTS/$ARGS/g")
|
||||
|
||||
# Run Claude Code in non-interactive mode with tool access
|
||||
claude -p --dangerously-skip-permissions --verbose "$PROMPT"
|
||||
fi
|
||||
|
||||
# Success — override the trap
|
||||
trap - ERR EXIT
|
||||
notify_complete "complete"
|
||||
EOT
|
||||
}
|
||||
|
||||
@@ -585,42 +570,9 @@ resource "kubernetes_deployment_v1" "workspace" {
|
||||
name = kubernetes_secret_v1.registry.metadata[0].name
|
||||
}
|
||||
|
||||
init_container {
|
||||
name = "fix-permissions"
|
||||
image = "busybox:latest"
|
||||
|
||||
command = ["sh", "-c", <<-EOC
|
||||
if [ ! -d /home/coder/project ]; then
|
||||
mkdir -p /home/coder/project
|
||||
fi
|
||||
chown -R 1000:1000 /home/coder
|
||||
EOC
|
||||
]
|
||||
|
||||
volume_mount {
|
||||
name = "home"
|
||||
mount_path = "/home/coder"
|
||||
}
|
||||
|
||||
resources {
|
||||
requests = {
|
||||
cpu = "5m"
|
||||
memory = "8Mi"
|
||||
}
|
||||
limits = {
|
||||
cpu = "50m"
|
||||
memory = "32Mi"
|
||||
}
|
||||
}
|
||||
|
||||
security_context {
|
||||
run_as_user = 0
|
||||
}
|
||||
}
|
||||
|
||||
container {
|
||||
name = "coder-agent"
|
||||
image = "codercom/enterprise-base:ubuntu-arm64"
|
||||
image = "registry.samson.media/coder-workspace:latest"
|
||||
|
||||
command = ["sh", "-c", coder_agent.main.init_script]
|
||||
|
||||
@@ -634,6 +586,11 @@ resource "kubernetes_deployment_v1" "workspace" {
|
||||
value = data.coder_parameter.anthropic_api_key.value
|
||||
}
|
||||
|
||||
env {
|
||||
name = "CLAUDE_CODE_OAUTH_TOKEN"
|
||||
value = data.coder_parameter.claude_oauth_token.value
|
||||
}
|
||||
|
||||
env {
|
||||
name = "GITHUB_TOKEN"
|
||||
value = data.coder_external_auth.github.access_token
|
||||
@@ -703,9 +660,7 @@ resource "kubernetes_deployment_v1" "workspace" {
|
||||
|
||||
volume {
|
||||
name = "home"
|
||||
persistent_volume_claim {
|
||||
claim_name = kubernetes_persistent_volume_claim_v1.home.metadata[0].name
|
||||
}
|
||||
empty_dir {}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
FROM codercom/enterprise-base:latest
|
||||
|
||||
USER root
|
||||
|
||||
# Node.js 22
|
||||
RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \
|
||||
&& apt-get install -y nodejs \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Global npm tools
|
||||
RUN npm install -g wrangler @anthropic-ai/claude-code
|
||||
|
||||
# Playwright system dependencies (both Ubuntu 24.04 and 22.04 package names)
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
||||
libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
|
||||
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libatspi2.0-0 \
|
||||
jq netcat-openbsd \
|
||||
&& (apt-get install -y libcups2t64 libasound2t64 2>/dev/null \
|
||||
|| apt-get install -y libcups2 libasound2 2>/dev/null) \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
USER coder
|
||||
+5
-2
@@ -11,8 +11,10 @@ export interface Config {
|
||||
giteaDevToken: string;
|
||||
/** Gitea API token for the review bot account */
|
||||
giteaReviewToken: string;
|
||||
/** Anthropic API key passed to Claude Code in workspaces */
|
||||
/** Anthropic API key passed to Claude Code in workspaces (fallback) */
|
||||
anthropicApiKey: string;
|
||||
/** Claude Code OAuth token for Max subscription (preferred) */
|
||||
claudeOauthToken: string;
|
||||
/** Username of the dev bot (to filter out self-replies) */
|
||||
botDevUsername: string;
|
||||
/** Username of the review bot (to filter out self-replies) */
|
||||
@@ -41,7 +43,8 @@ export function loadConfig(): Config {
|
||||
coderTemplateId: required("CODER_TEMPLATE_ID"),
|
||||
giteaDevToken: required("GITEA_DEV_TOKEN"),
|
||||
giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
|
||||
anthropicApiKey: required("ANTHROPIC_API_KEY"),
|
||||
anthropicApiKey: process.env.ANTHROPIC_API_KEY || "",
|
||||
claudeOauthToken: process.env.CLAUDE_OAUTH_TOKEN || "",
|
||||
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
|
||||
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
|
||||
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
|
||||
|
||||
@@ -84,6 +84,11 @@ if (maintenanceRepos.length > 0) {
|
||||
// Start
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
// Reconcile queue state with Coder before accepting traffic
|
||||
queue.reconcile().catch((err) =>
|
||||
console.error("[startup] reconcile failed:", err),
|
||||
);
|
||||
|
||||
serve({ fetch: app.fetch, port: config.port }, (info) => {
|
||||
console.log(`SDLC Orchestrator listening on :${info.port} (concurrency: ${concurrency})`);
|
||||
});
|
||||
|
||||
@@ -35,6 +35,34 @@ export class TaskQueue {
|
||||
this.concurrency = concurrency;
|
||||
}
|
||||
|
||||
/**
|
||||
* Reconcile in-memory state with Coder on startup.
|
||||
* Re-adopts any running workspaces so callbacks and dedup work correctly.
|
||||
*/
|
||||
async reconcile(): Promise<void> {
|
||||
const workspaces = await this.coder.listWorkspaces();
|
||||
const runningStatuses = ["starting", "running", "started"];
|
||||
|
||||
for (const ws of workspaces) {
|
||||
if (!runningStatuses.includes(ws.latestBuildStatus)) continue;
|
||||
|
||||
// Only adopt workspaces that match our naming pattern: {taskType}-{repo}-{issue}
|
||||
const parts = ws.name.match(/^(.+?)-(.+?)-(\d+)$/);
|
||||
if (!parts) continue;
|
||||
|
||||
this.active.set(ws.name, {
|
||||
workspaceId: ws.id,
|
||||
workspaceName: ws.name,
|
||||
startedAt: new Date(), // approximate — we don't know the real start time
|
||||
});
|
||||
console.log(`[queue] reconciled: adopted workspace "${ws.name}" (status: ${ws.latestBuildStatus})`);
|
||||
}
|
||||
|
||||
if (this.active.size > 0) {
|
||||
console.log(`[queue] reconcile complete: ${this.active.size} active workspace(s) adopted`);
|
||||
}
|
||||
}
|
||||
|
||||
/** Build a dedup key for a task. */
|
||||
static key(task: TaskRequest): string {
|
||||
return `${task.taskType}-${task.giteaRepo}-${task.issueNumber}`;
|
||||
|
||||
+80
-3
@@ -7,6 +7,7 @@ export class CoderClient {
|
||||
private token: string;
|
||||
private templateId: string;
|
||||
private anthropicApiKey: string;
|
||||
private claudeOauthToken: string;
|
||||
private callbackUrl: string;
|
||||
|
||||
constructor(config: Config) {
|
||||
@@ -14,6 +15,7 @@ export class CoderClient {
|
||||
this.token = config.coderToken;
|
||||
this.templateId = config.coderTemplateId;
|
||||
this.anthropicApiKey = config.anthropicApiKey;
|
||||
this.claudeOauthToken = config.claudeOauthToken;
|
||||
this.callbackUrl = config.callbackUrl;
|
||||
}
|
||||
|
||||
@@ -31,6 +33,7 @@ export class CoderClient {
|
||||
{ name: "gitea_org", value: task.giteaOrg },
|
||||
{ name: "gitea_repo", value: task.giteaRepo },
|
||||
{ name: "anthropic_api_key", value: this.anthropicApiKey },
|
||||
{ name: "claude_oauth_token", value: this.claudeOauthToken },
|
||||
{ name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` },
|
||||
...(task.deployEnv
|
||||
? [{ name: "deploy_env", value: task.deployEnv }]
|
||||
@@ -50,6 +53,32 @@ export class CoderClient {
|
||||
},
|
||||
);
|
||||
|
||||
// Handle 409 conflict — workspace with this name already exists.
|
||||
// This can happen if the orchestrator restarted and lost in-memory state.
|
||||
if (res.status === 409) {
|
||||
const existing = await this.findWorkspaceByName(name);
|
||||
if (!existing) {
|
||||
throw new Error(`Coder 409 but workspace "${name}" not found — possible race condition`);
|
||||
}
|
||||
|
||||
const stoppedStatuses = ["stopped", "failed", "canceled", "deleted"];
|
||||
if (stoppedStatuses.includes(existing.latestBuildStatus)) {
|
||||
// Workspace is done — safe to replace
|
||||
console.log(
|
||||
`[coder] workspace "${name}" exists but ${existing.latestBuildStatus} — deleting and retrying`,
|
||||
);
|
||||
await this.deleteWorkspace(existing.id);
|
||||
await new Promise((resolve) => setTimeout(resolve, 5000));
|
||||
return this.createWorkspace(task);
|
||||
}
|
||||
|
||||
// Workspace is still running — adopt it, don't kill it
|
||||
console.log(
|
||||
`[coder] workspace "${name}" is still ${existing.latestBuildStatus} — adopting existing workspace`,
|
||||
);
|
||||
return { id: existing.id, name: existing.name };
|
||||
}
|
||||
|
||||
if (!res.ok) {
|
||||
const text = await res.text();
|
||||
throw new Error(`Coder API error ${res.status}: ${text}`);
|
||||
@@ -95,7 +124,42 @@ export class CoderClient {
|
||||
}
|
||||
}
|
||||
|
||||
async findWorkspaceByName(name: string): Promise<{ id: string } | null> {
|
||||
/**
|
||||
* List all workspaces owned by the authenticated user.
|
||||
* Used at startup to reconcile in-memory state with Coder.
|
||||
*/
|
||||
async listWorkspaces(): Promise<
|
||||
Array<{ id: string; name: string; latestBuildStatus: string }>
|
||||
> {
|
||||
const res = await fetch(
|
||||
`${this.baseUrl}/api/v2/workspaces?q=owner:me`,
|
||||
{
|
||||
headers: { "Coder-Session-Token": this.token },
|
||||
},
|
||||
);
|
||||
|
||||
if (!res.ok) return [];
|
||||
|
||||
const data = (await res.json()) as {
|
||||
workspaces: Array<{
|
||||
id: string;
|
||||
name: string;
|
||||
latest_build: { status: string };
|
||||
}>;
|
||||
};
|
||||
return (data.workspaces ?? []).map((w) => ({
|
||||
id: w.id,
|
||||
name: w.name,
|
||||
latestBuildStatus: w.latest_build?.status ?? "unknown",
|
||||
}));
|
||||
}
|
||||
|
||||
async findWorkspaceByName(name: string): Promise<{
|
||||
id: string;
|
||||
name: string;
|
||||
createdAt: string;
|
||||
latestBuildStatus: string;
|
||||
} | null> {
|
||||
const res = await fetch(
|
||||
`${this.baseUrl}/api/v2/workspaces?q=name:${encodeURIComponent(name)}`,
|
||||
{
|
||||
@@ -107,8 +171,21 @@ export class CoderClient {
|
||||
|
||||
if (!res.ok) return null;
|
||||
|
||||
const data = (await res.json()) as { workspaces: Array<{ id: string; name: string }> };
|
||||
const data = (await res.json()) as {
|
||||
workspaces: Array<{
|
||||
id: string;
|
||||
name: string;
|
||||
created_at: string;
|
||||
latest_build: { status: string };
|
||||
}>;
|
||||
};
|
||||
const match = data.workspaces?.find((w) => w.name === name);
|
||||
return match ? { id: match.id } : null;
|
||||
if (!match) return null;
|
||||
return {
|
||||
id: match.id,
|
||||
name: match.name,
|
||||
createdAt: match.created_at,
|
||||
latestBuildStatus: match.latest_build?.status ?? "unknown",
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user