Compare commits

..
14 Commits
Author SHA1 Message Date
Daniel SamsonandClaude Opus 4.6 abbe47b1b9 Support Claude Code Max via OAuth token
Publish Image / publish (push) Successful in 21s
Pass CLAUDE_CODE_OAUTH_TOKEN to workspaces so they use the Max
subscription instead of pay-per-use API credits. Falls back to
ANTHROPIC_API_KEY if OAuth token not set.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:52:01 +01:00
Daniel SamsonandClaude Opus 4.6 9bca465565 Skip build for lightweight stages (analyse, architect, release, maintenance)
These stages only read code and post comments — no need for npm install,
frontend build, Playwright, or migrations. Saves several minutes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:47:48 +01:00
Daniel SamsonandClaude Opus 4.6 d220623a9f Always fire callback via trap, even on script failure
Uses ERR/EXIT trap to ensure the orchestrator is notified when the
startup script fails (e.g. clone error, missing command file). Prevents
orphaned workspaces that never get cleaned up.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:42:18 +01:00
Daniel SamsonandClaude Opus 4.6 e801d96410 Ephemeral workspaces: remove PVC, use emptyDir
Workspaces are now fully immutable like GH Actions runners — no
persistent volume, no init container, no stale state between runs.
Fresh emptyDir on every workspace creation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:27:30 +01:00
Daniel SamsonandClaude Opus 4.6 869d82998b Fresh clone on every automated task, generic repo setup
Always rm -rf ~/project before cloning to avoid stale state from
previous workspace runs on the same PVC. Made setup steps generic
(detect frontend, playwright, migrations) instead of babble-specific.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:25:17 +01:00
Daniel SamsonandClaude Opus 4.6 aa986a470e Remove log viewer app, output goes to agent logs directly
Publish Image / publish (push) Successful in 15s
The startup script already writes to stdout which the Coder agent
captures. No need for a separate HTTP log server or coder_app button.
Logs are visible via the Coder web terminal or agent log viewer.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:18:00 +01:00
Daniel SamsonandClaude Opus 4.6 520fc8f81e Custom workspace image + fix slash command invocation
Publish Workspace Image / publish (push) Successful in 3m51s
- Add coder/workspace.Dockerfile with Node.js 22, wrangler, claude-code,
  and Playwright deps pre-installed. Eliminates ~3 min of installs on
  every workspace startup.
- Add CI workflow to build and push to registry.samson.media/coder-workspace
- Fix slash command: -p mode doesn't support /commands, so read the .md
  file directly, strip frontmatter, substitute $ARGUMENTS, pass as prompt
- Switch workspace image from codercom/enterprise-base to custom image

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:15:17 +01:00
Daniel SamsonandClaude Opus 4.6 d46e3ca247 Fix slash command invocation: /analyse not /project:analyse
The project: prefix is not valid Claude Code syntax. Slash commands
in .claude/commands/ are invoked as /$TASK_TYPE directly.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:09:08 +01:00
Daniel SamsonandClaude Opus 4.6 ec0b012586 Reconcile queue state on startup, remove age-based staleness check
Publish Image / publish (push) Successful in 20s
On boot, query Coder for running workspaces and re-adopt them into the
active queue. This prevents 409 conflicts after restarts and ensures
callbacks still work for in-flight tasks.

On 409: only delete stopped/failed workspaces. Running workspaces are
adopted — never killed based on age.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:01:56 +01:00
Daniel SamsonandClaude Opus 4.6 36c80458e0 Safe 409 handling: check workspace age/status before deleting
Publish Image / publish (push) Successful in 20s
Instead of blindly deleting on 409 conflict, now checks:
- Stopped/failed → safe to delete and recreate
- Running but >30 min old → stale, delete and recreate
- Running and <30 min old → adopt existing workspace (mid-task)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 13:59:59 +01:00
Daniel SamsonandClaude Opus 4.6 06cf4d1b9e Handle stale workspaces: 409 conflict auto-cleanup + verbose logging
Publish Image / publish (push) Successful in 20s
When the orchestrator restarts, it loses in-memory queue state. If a
stale workspace still exists, createWorkspace now auto-deletes it and
retries instead of failing with 409. Also adds --verbose to Claude Code
invocation for better task log debugging.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 13:58:08 +01:00
Daniel SamsonandClaude Opus 4.6 4f1d306fdf Fix ImagePullBackOff: use multi-arch base image tag
The tag `ubuntu-arm64` doesn't exist on Docker Hub. Switch to `latest`
which includes arm64 in its multi-arch manifest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 13:44:44 +01:00
Daniel SamsonandClaude Opus 4.6 7145fb536a Add workspace lifecycle management via task-complete callback
Publish Image / publish (push) Successful in 20s
- Workspaces curl POST /webhook/task-complete/{name} when done
- Orchestrator deletes the workspace via Coder API on callback
- Active workspaces count toward concurrency limit
- GET /queue now shows active workspaces with elapsed time
- Coder template gains callback_url parameter
- TTL becomes a safety net, not the primary shutdown mechanism

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 13:37:08 +01:00
Daniel SamsonandClaude Opus 4.6 f23fb4e2e0 Add task queue with dedup and concurrency control
Publish Image / publish (push) Successful in 54s
- Tasks keyed by {taskType}-{repo}-{issue} for deduplication
- Duplicate requests (pending or running) are dropped
- Configurable concurrency via QUEUE_CONCURRENCY env (default 2)
- Workspace names now {taskType}-{repo}-{issue} for observability
- GET /queue endpoint shows pending/running tasks
- All handlers route through the queue instead of calling Coder directly

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 13:30:27 +01:00
14 changed files with 571 additions and 232 deletions
+27
View File
@@ -0,0 +1,27 @@
name: Publish Workspace Image
on:
push:
paths:
- 'coder/workspace.Dockerfile'
branches:
- main
concurrency:
group: publish-workspace
cancel-in-progress: false
jobs:
publish:
runs-on: self-hosted
steps:
- uses: actions/checkout@v4
- name: Log in to registry
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.samson.media -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
- name: Build and push
run: |
IMAGE=registry.samson.media/coder-workspace
docker build -f coder/workspace.Dockerfile -t "$IMAGE:latest" .
docker push "$IMAGE:latest"
+98 -121
View File
@@ -76,27 +76,6 @@ data "coder_parameter" "memory" {
}
}
data "coder_parameter" "disk_size" {
name = "disk_size"
display_name = "Disk Size (GB)"
description = "Persistent home directory size"
type = "number"
default = "10"
mutable = false
option {
name = "5 GB"
value = "5"
}
option {
name = "10 GB"
value = "10"
}
option {
name = "20 GB"
value = "20"
}
}
# ─── Automation Parameters ───────────────────────────────────────────────────
@@ -208,6 +187,24 @@ data "coder_parameter" "anthropic_api_key" {
mutable = false
}
data "coder_parameter" "callback_url" {
name = "callback_url"
display_name = "Task Complete Callback URL"
description = "URL to POST when task finishes (set by orchestrator)"
type = "string"
default = ""
mutable = false
}
data "coder_parameter" "claude_oauth_token" {
name = "claude_oauth_token"
display_name = "Claude OAuth Token"
description = "OAuth token for Claude Code Max subscription"
type = "string"
default = ""
mutable = false
}
data "coder_parameter" "deploy_env" {
name = "deploy_env"
display_name = "Deploy Environment"
@@ -366,33 +363,6 @@ resource "kubernetes_resource_quota_v1" "workspace" {
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
"limits.memory" = "${data.coder_parameter.memory.value}Mi"
"requests.storage" = "${data.coder_parameter.disk_size.value}Gi"
"persistentvolumeclaims" = "1"
}
}
}
# =============================================================================
# Storage
# =============================================================================
resource "kubernetes_persistent_volume_claim_v1" "home" {
metadata {
name = "home"
namespace = kubernetes_namespace_v1.workspace.metadata[0].name
labels = local.labels
}
wait_until_bound = false
spec {
access_modes = ["ReadWriteOnce"]
storage_class_name = "longhorn-backup"
resources {
requests = {
storage = "${data.coder_parameter.disk_size.value}Gi"
}
}
}
}
@@ -433,8 +403,28 @@ resource "coder_agent" "main" {
web_terminal = true
}
metadata {
display_name = "Task Status"
key = "task_status"
script = <<-EOS
if [ -f ~/task-output.log ]; then
if grep -q "Task completed" ~/task-output.log 2>/dev/null; then
echo "✅ Complete"
else
echo "⏳ Running ($(wc -l < ~/task-output.log) lines)"
fi
elif [ -n "$TASK_TYPE" ]; then
echo "⏳ Starting..."
else
echo "Interactive"
fi
EOS
interval = 10
}
env = {
ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value
CLAUDE_CODE_OAUTH_TOKEN = data.coder_parameter.claude_oauth_token.value
GITHUB_TOKEN = data.coder_external_auth.github.access_token
GITEA_TOKEN = data.coder_parameter.gitea_token.value
GITEA_ORG = data.coder_parameter.gitea_org.value
@@ -443,34 +433,24 @@ resource "coder_agent" "main" {
ISSUE_NUMBER = data.coder_parameter.issue_number.value
REPO_CLONE_URL = data.coder_parameter.repo_clone_url.value
DEPLOY_ENV = data.coder_parameter.deploy_env.value
CALLBACK_URL = data.coder_parameter.callback_url.value
}
startup_script = <<-EOT
#!/bin/bash
# Always notify the orchestrator when done, even on failure
notify_complete() {
if [ -n "$CALLBACK_URL" ]; then
curl -s -X POST -H "Content-Type: application/json" \
-d "{\"status\":\"$1\"}" \
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
fi
}
trap 'notify_complete "failed"' ERR EXIT
set -e
# --- Install Node.js 22 ---
if ! command -v node &> /dev/null; then
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
fi
# --- Install global tools ---
if ! command -v wrangler &> /dev/null; then
sudo npm install -g wrangler @anthropic-ai/claude-code
fi
# --- Install Playwright system dependencies ---
if ! dpkg -s libgbm1 &> /dev/null; then
sudo apt-get update
sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
libcups2t64 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2t64 libatspi2.0-0 \
|| sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
libcups2 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2 libatspi2.0-0
fi
# --- Configure git ---
git config --global user.name "${data.coder_workspace_owner.me.full_name}"
git config --global user.email "${data.coder_workspace_owner.me.email}"
@@ -483,27 +463,39 @@ resource "coder_agent" "main" {
fi
# --- Clone repository ---
if [ -n "$REPO_CLONE_URL" ] && [ ! -d ~/project ]; then
if [ -n "$REPO_CLONE_URL" ]; then
git clone "$REPO_CLONE_URL" ~/project
cd ~/project
# Switch to develop branch if it exists
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
# Install backend deps
npm ci --legacy-peer-deps
# Lightweight stages only need the code, not a full build
LIGHT_STAGES="analyse architect release maintenance"
if echo "$LIGHT_STAGES" | grep -qw "$TASK_TYPE"; then
echo "Lightweight stage ($TASK_TYPE) — skipping build"
else
# Install deps if package.json exists
if [ -f package.json ]; then
npm ci --legacy-peer-deps || npm ci
fi
# Install frontend deps
# Install frontend deps if present
if [ -f frontend/package.json ]; then
cd frontend && npm ci && cd ..
npm run build:frontend 2>/dev/null || true
fi
# Build frontend (required — vitest fails without frontend/dist)
npm run build:frontend
# Install Playwright Chromium
# Install Playwright if needed
if grep -q "playwright" package.json 2>/dev/null; then
npx playwright install chromium
fi
# Apply local migrations
npm run db:migrate:local
# Apply local migrations if script exists
if npm run --silent db:migrate:local 2>/dev/null; then
echo "Local migrations applied"
fi
fi
fi
# --- Automated task execution ---
@@ -515,11 +507,21 @@ resource "coder_agent" "main" {
ARGS="$DEPLOY_ENV"
fi
# Run Claude Code in non-interactive mode
claude --print --dangerously-skip-permissions "/project:$TASK_TYPE $ARGS" 2>&1 | tee ~/task-output.log
echo "Task completed. Output saved to ~/task-output.log"
# Read the slash command .md file, strip YAML frontmatter, substitute $ARGUMENTS
CMD_FILE=".claude/commands/$TASK_TYPE.md"
if [ ! -f "$CMD_FILE" ]; then
echo "ERROR: Command file not found: $CMD_FILE"
exit 1
fi
PROMPT=$(sed '1{/^---$/!q}; 1,/^---$/d' "$CMD_FILE" | sed "s/\\\$ARGUMENTS/$ARGS/g")
# Run Claude Code in non-interactive mode with tool access
claude -p --dangerously-skip-permissions --verbose "$PROMPT"
fi
# Success — override the trap
trap - ERR EXIT
notify_complete "complete"
EOT
}
@@ -568,42 +570,9 @@ resource "kubernetes_deployment_v1" "workspace" {
name = kubernetes_secret_v1.registry.metadata[0].name
}
init_container {
name = "fix-permissions"
image = "busybox:latest"
command = ["sh", "-c", <<-EOC
if [ ! -d /home/coder/project ]; then
mkdir -p /home/coder/project
fi
chown -R 1000:1000 /home/coder
EOC
]
volume_mount {
name = "home"
mount_path = "/home/coder"
}
resources {
requests = {
cpu = "5m"
memory = "8Mi"
}
limits = {
cpu = "50m"
memory = "32Mi"
}
}
security_context {
run_as_user = 0
}
}
container {
name = "coder-agent"
image = "codercom/enterprise-base:ubuntu-arm64"
image = "registry.samson.media/coder-workspace:latest"
command = ["sh", "-c", coder_agent.main.init_script]
@@ -617,6 +586,11 @@ resource "kubernetes_deployment_v1" "workspace" {
value = data.coder_parameter.anthropic_api_key.value
}
env {
name = "CLAUDE_CODE_OAUTH_TOKEN"
value = data.coder_parameter.claude_oauth_token.value
}
env {
name = "GITHUB_TOKEN"
value = data.coder_external_auth.github.access_token
@@ -657,6 +631,11 @@ resource "kubernetes_deployment_v1" "workspace" {
value = data.coder_parameter.deploy_env.value
}
env {
name = "CALLBACK_URL"
value = data.coder_parameter.callback_url.value
}
resources {
requests = {
cpu = "${tonumber(data.coder_parameter.cpu.value) * 500}m"
@@ -681,9 +660,7 @@ resource "kubernetes_deployment_v1" "workspace" {
volume {
name = "home"
persistent_volume_claim {
claim_name = kubernetes_persistent_volume_claim_v1.home.metadata[0].name
}
empty_dir {}
}
}
}
+23
View File
@@ -0,0 +1,23 @@
FROM codercom/enterprise-base:latest
USER root
# Node.js 22
RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \
&& apt-get install -y nodejs \
&& rm -rf /var/lib/apt/lists/*
# Global npm tools
RUN npm install -g wrangler @anthropic-ai/claude-code
# Playwright system dependencies (both Ubuntu 24.04 and 22.04 package names)
RUN apt-get update && apt-get install -y --no-install-recommends \
libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libatspi2.0-0 \
jq netcat-openbsd \
&& (apt-get install -y libcups2t64 libasound2t64 2>/dev/null \
|| apt-get install -y libcups2 libasound2 2>/dev/null) \
&& rm -rf /var/lib/apt/lists/*
USER coder
+8 -2
View File
@@ -11,14 +11,18 @@ export interface Config {
giteaDevToken: string;
/** Gitea API token for the review bot account */
giteaReviewToken: string;
/** Anthropic API key passed to Claude Code in workspaces */
/** Anthropic API key passed to Claude Code in workspaces (fallback) */
anthropicApiKey: string;
/** Claude Code OAuth token for Max subscription (preferred) */
claudeOauthToken: string;
/** Username of the dev bot (to filter out self-replies) */
botDevUsername: string;
/** Username of the review bot (to filter out self-replies) */
botReviewUsername: string;
/** Gitea base URL (e.g. https://gitea.samson.media) */
giteaUrl: string;
/** Base URL for task-complete callbacks (e.g. https://sdlc.samson.media) */
callbackUrl: string;
/** Optional webhook secret for verifying Gitea signatures */
webhookSecret?: string;
}
@@ -39,10 +43,12 @@ export function loadConfig(): Config {
coderTemplateId: required("CODER_TEMPLATE_ID"),
giteaDevToken: required("GITEA_DEV_TOKEN"),
giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
anthropicApiKey: required("ANTHROPIC_API_KEY"),
anthropicApiKey: process.env.ANTHROPIC_API_KEY || "",
claudeOauthToken: process.env.CLAUDE_OAUTH_TOKEN || "",
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
callbackUrl: required("CALLBACK_URL"),
webhookSecret: process.env.WEBHOOK_SECRET,
};
}
+5 -8
View File
@@ -1,14 +1,14 @@
import type { Context } from "hono";
import type { IssueCommentEvent, TaskRequest } from "../types.js";
import type { CoderClient } from "../services/coder.js";
import type { TaskQueue } from "../queue.js";
import type { Config } from "../config.js";
/**
* Issue comment created → re-trigger analyst if still in analysis.
* Issue comment created or edited → re-trigger analyst if still in analysis.
*
* Replaces: issue-comment-reply.json
*/
export function issueComment(config: Config, coder: CoderClient) {
export function issueComment(config: Config, queue: TaskQueue) {
return async (c: Context) => {
const event = await c.req.json<IssueCommentEvent>();
@@ -43,11 +43,8 @@ export function issueComment(config: Config, coder: CoderClient) {
giteaToken: config.giteaDevToken,
};
console.log(`[issue-comment] #${task.issueNumber} → re-trigger analyst`);
const queued = queue.enqueue(task);
const workspace = await coder.createWorkspace(task);
console.log(`[issue-comment] workspace created: ${workspace.name}`);
return c.json({ ok: true, workspace: workspace.name });
return c.json({ ok: true, queued });
};
}
+7 -15
View File
@@ -1,7 +1,6 @@
import type { Context } from "hono";
import type { IssueEvent, TaskRequest } from "../types.js";
import type { CoderClient } from "../services/coder.js";
import type { GiteaClient } from "../services/gitea.js";
import type { TaskQueue } from "../queue.js";
import type { Config } from "../config.js";
const LABEL_TO_TASK: Record<string, string> = {
@@ -19,7 +18,7 @@ const REVIEW_TASKS = new Set(["test"]);
*
* Replaces: issue-stage-transition.json
*/
export function issueLabel(config: Config, coder: CoderClient, gitea: GiteaClient) {
export function issueLabel(config: Config, queue: TaskQueue) {
return async (c: Context) => {
const event = await c.req.json<IssueEvent>();
@@ -55,18 +54,11 @@ export function issueLabel(config: Config, coder: CoderClient, gitea: GiteaClien
giteaToken,
};
console.log(`[issue-label] #${task.issueNumber} → ${taskType}`);
const queued = queue.enqueue(task, {
useReviewAccount: false,
body: `🤖 SDLC stage transition: **${taskType}** — workspace queued.`,
});
const workspace = await coder.createWorkspace(task);
console.log(`[issue-label] workspace created: ${workspace.name}`);
await gitea.commentOnIssue(
org,
repo,
event.issue.number,
`🤖 SDLC stage transition: **${taskType}** — workspace created.`,
);
return c.json({ ok: true, workspace: workspace.name });
return c.json({ ok: true, queued });
};
}
+7 -15
View File
@@ -1,7 +1,6 @@
import type { Context } from "hono";
import type { IssueEvent, TaskRequest } from "../types.js";
import type { CoderClient } from "../services/coder.js";
import type { GiteaClient } from "../services/gitea.js";
import type { TaskQueue } from "../queue.js";
import type { Config } from "../config.js";
/**
@@ -9,7 +8,7 @@ import type { Config } from "../config.js";
*
* Replaces: gitea-issue-triage.json
*/
export function issueTriage(config: Config, coder: CoderClient, gitea: GiteaClient) {
export function issueTriage(config: Config, queue: TaskQueue) {
return async (c: Context) => {
const event = await c.req.json<IssueEvent>();
@@ -32,18 +31,11 @@ export function issueTriage(config: Config, coder: CoderClient, gitea: GiteaClie
giteaToken: config.giteaDevToken,
};
console.log(`[issue-triage] #${task.issueNumber} → ${taskType}`);
const queued = queue.enqueue(task, {
useReviewAccount: false,
body: `🤖 Issue received. Starting **${taskType}** stage.`,
});
const workspace = await coder.createWorkspace(task);
console.log(`[issue-triage] workspace created: ${workspace.name}`);
await gitea.commentOnIssue(
org,
repo,
event.issue.number,
`🤖 Issue received. Starting **${taskType}** stage.`,
);
return c.json({ ok: true, workspace: workspace.name });
return c.json({ ok: true, queued });
};
}
+4 -18
View File
@@ -1,4 +1,4 @@
import type { CoderClient } from "../services/coder.js";
import type { TaskQueue } from "../queue.js";
import type { Config } from "../config.js";
import type { TaskRequest } from "../types.js";
@@ -9,15 +9,11 @@ export interface MaintenanceRepo {
}
/**
* Weekly maintenance cron → create a maintenance workspace.
* Weekly maintenance cron → enqueue a maintenance workspace per repo.
*
* Replaces: scheduled-maintenance.json
*/
export function runMaintenance(
config: Config,
coder: CoderClient,
repos: MaintenanceRepo[],
) {
export function runMaintenance(config: Config, queue: TaskQueue, repos: MaintenanceRepo[]) {
return async () => {
for (const entry of repos) {
const task: TaskRequest = {
@@ -29,17 +25,7 @@ export function runMaintenance(
giteaToken: config.giteaDevToken,
};
try {
const workspace = await coder.createWorkspace(task);
console.log(
`[maintenance] ${entry.org}/${entry.repo} → workspace: ${workspace.name}`,
);
} catch (err) {
console.error(
`[maintenance] failed for ${entry.org}/${entry.repo}:`,
err,
);
}
queue.enqueue(task);
}
};
}
+4 -7
View File
@@ -1,6 +1,6 @@
import type { Context } from "hono";
import type { PullRequestEvent, TaskRequest } from "../types.js";
import type { CoderClient } from "../services/coder.js";
import type { TaskQueue } from "../queue.js";
import type { GiteaClient } from "../services/gitea.js";
import type { Config } from "../config.js";
@@ -10,7 +10,7 @@ import type { Config } from "../config.js";
*
* Replaces: pr-review-trigger.json
*/
export function prReview(config: Config, coder: CoderClient, gitea: GiteaClient) {
export function prReview(config: Config, queue: TaskQueue, gitea: GiteaClient) {
return async (c: Context) => {
const event = await c.req.json<PullRequestEvent>();
@@ -40,11 +40,8 @@ export function prReview(config: Config, coder: CoderClient, gitea: GiteaClient)
giteaToken: config.giteaReviewToken,
};
console.log(`[pr-review] PR #${prNumber} → review-code`);
const queued = queue.enqueue(task);
const workspace = await coder.createWorkspace(task);
console.log(`[pr-review] workspace created: ${workspace.name}`);
return c.json({ ok: true, workspace: workspace.name });
return c.json({ ok: true, queued });
};
}
+7 -15
View File
@@ -1,7 +1,6 @@
import type { Context } from "hono";
import type { PullRequestReviewEvent, TaskRequest } from "../types.js";
import type { CoderClient } from "../services/coder.js";
import type { GiteaClient } from "../services/gitea.js";
import type { TaskQueue } from "../queue.js";
import type { Config } from "../config.js";
/**
@@ -9,7 +8,7 @@ import type { Config } from "../config.js";
*
* Replaces: pr-review-rework.json
*/
export function prRework(config: Config, coder: CoderClient, gitea: GiteaClient) {
export function prRework(config: Config, queue: TaskQueue) {
return async (c: Context) => {
const event = await c.req.json<PullRequestReviewEvent>();
@@ -43,18 +42,11 @@ export function prRework(config: Config, coder: CoderClient, gitea: GiteaClient)
giteaToken,
};
console.log(`[pr-rework] PR #${prNumber} ${reviewState} → ${taskType}`);
const queued = queue.enqueue(task, {
useReviewAccount: false,
body: `🤖 Review outcome: **${taskType}** — workspace queued.`,
});
const workspace = await coder.createWorkspace(task);
console.log(`[pr-rework] workspace created: ${workspace.name}`);
await gitea.commentOnIssue(
org,
repo,
prNumber,
`🤖 Review outcome: starting **${taskType}** stage.`,
);
return c.json({ ok: true, workspace: workspace.name });
return c.json({ ok: true, queued });
};
}
+7 -15
View File
@@ -1,7 +1,6 @@
import type { Context } from "hono";
import type { IssueEvent, TaskRequest } from "../types.js";
import type { CoderClient } from "../services/coder.js";
import type { GiteaClient } from "../services/gitea.js";
import type { TaskQueue } from "../queue.js";
import type { Config } from "../config.js";
/**
@@ -10,7 +9,7 @@ import type { Config } from "../config.js";
*
* Replaces: release-process.json
*/
export function release(config: Config, coder: CoderClient, gitea: GiteaClient) {
export function release(config: Config, queue: TaskQueue) {
return async (c: Context) => {
const event = await c.req.json<IssueEvent>();
@@ -52,18 +51,11 @@ export function release(config: Config, coder: CoderClient, gitea: GiteaClient)
giteaToken: config.giteaDevToken,
};
console.log(`[release] #${task.issueNumber} → release`);
const queued = queue.enqueue(task, {
useReviewAccount: false,
body: `🤖 Release process started.`,
});
const workspace = await coder.createWorkspace(task);
console.log(`[release] workspace created: ${workspace.name}`);
await gitea.commentOnIssue(
org,
repo,
event.issue.number,
`🤖 Release process started.`,
);
return c.json({ ok: true, workspace: workspace.name });
return c.json({ ok: true, queued });
};
}
+30 -9
View File
@@ -6,6 +6,7 @@ import cron from "node-cron";
import { loadConfig } from "./config.js";
import { CoderClient } from "./services/coder.js";
import { GiteaClient } from "./services/gitea.js";
import { TaskQueue } from "./queue.js";
import { issueTriage } from "./handlers/issue-triage.js";
import { issueLabel } from "./handlers/issue-label.js";
@@ -23,26 +24,41 @@ const config = loadConfig();
const coderClient = new CoderClient(config);
const giteaClient = new GiteaClient(config);
const concurrency = parseInt(process.env.QUEUE_CONCURRENCY || "2", 10);
const queue = new TaskQueue(coderClient, giteaClient, concurrency);
const app = new Hono();
app.use("*", logger());
// ---------------------------------------------------------------------------
// Health check
// Health check + queue status
// ---------------------------------------------------------------------------
app.get("/health", (c) => c.json({ status: "ok" }));
app.get("/queue", (c) => c.json(queue.status()));
// ---------------------------------------------------------------------------
// Webhook endpoints — same paths as the n8n webhooks so Gitea config
// can stay unchanged (just point to new host).
// ---------------------------------------------------------------------------
app.post("/webhook/gitea-issue-triage", issueTriage(config, coderClient, giteaClient));
app.post("/webhook/gitea-issue-label", issueLabel(config, coderClient, giteaClient));
app.post("/webhook/gitea-issue-comment", issueComment(config, coderClient));
app.post("/webhook/gitea-pr-review", prReview(config, coderClient, giteaClient));
app.post("/webhook/gitea-pr-review-rework", prRework(config, coderClient, giteaClient));
app.post("/webhook/gitea-release", release(config, coderClient, giteaClient));
app.post("/webhook/gitea-issue-triage", issueTriage(config, queue));
app.post("/webhook/gitea-issue-label", issueLabel(config, queue));
app.post("/webhook/gitea-issue-comment", issueComment(config, queue));
app.post("/webhook/gitea-pr-review", prReview(config, queue, giteaClient));
app.post("/webhook/gitea-pr-review-rework", prRework(config, queue));
app.post("/webhook/gitea-release", release(config, queue));
// ---------------------------------------------------------------------------
// Task-complete callback — workspaces call this when done
// ---------------------------------------------------------------------------
app.post("/webhook/task-complete/:name", async (c) => {
const name = c.req.param("name");
console.log(`[callback] task-complete received for: ${name}`);
const found = await queue.taskComplete(name);
return c.json({ ok: true, found });
});
// ---------------------------------------------------------------------------
// Scheduled maintenance cron (Monday 9:00 AM)
@@ -50,7 +66,7 @@ app.post("/webhook/gitea-release", release(config, coderClient, giteaClient));
const maintenanceRepos = parseMaintenanceRepos();
if (maintenanceRepos.length > 0) {
const maintenanceFn = runMaintenance(config, coderClient, maintenanceRepos);
const maintenanceFn = runMaintenance(config, queue, maintenanceRepos);
cron.schedule("0 9 * * 1", () => {
console.log("[cron] running weekly maintenance");
@@ -68,8 +84,13 @@ if (maintenanceRepos.length > 0) {
// Start
// ---------------------------------------------------------------------------
// Reconcile queue state with Coder before accepting traffic
queue.reconcile().catch((err) =>
console.error("[startup] reconcile failed:", err),
);
serve({ fetch: app.fetch, port: config.port }, (info) => {
console.log(`SDLC Orchestrator listening on :${info.port}`);
console.log(`SDLC Orchestrator listening on :${info.port} (concurrency: ${concurrency})`);
});
// ---------------------------------------------------------------------------
+207
View File
@@ -0,0 +1,207 @@
import type { TaskRequest } from "./types.js";
import type { CoderClient } from "./services/coder.js";
import type { GiteaClient } from "./services/gitea.js";
interface QueuedTask {
task: TaskRequest;
comment?: { useReviewAccount: boolean; body: string };
}
interface ActiveWorkspace {
workspaceId: string;
workspaceName: string;
startedAt: Date;
}
/**
* Task queue with deduplication, concurrency control, and workspace lifecycle.
*
* - Tasks are keyed by `{taskType}-{repo}-{issue}` for dedup
* - If a task with the same key is pending, running, or has an active workspace, new requests are dropped
* - Concurrency is configurable (defaults to 2)
* - Tracks active workspaces and stops them on task-complete callback
*/
export class TaskQueue {
private pending = new Map<string, QueuedTask>();
private running = new Set<string>();
private active = new Map<string, ActiveWorkspace>();
private concurrency: number;
private coder: CoderClient;
private gitea: GiteaClient;
constructor(coder: CoderClient, gitea: GiteaClient, concurrency = 2) {
this.coder = coder;
this.gitea = gitea;
this.concurrency = concurrency;
}
/**
* Reconcile in-memory state with Coder on startup.
* Re-adopts any running workspaces so callbacks and dedup work correctly.
*/
async reconcile(): Promise<void> {
const workspaces = await this.coder.listWorkspaces();
const runningStatuses = ["starting", "running", "started"];
for (const ws of workspaces) {
if (!runningStatuses.includes(ws.latestBuildStatus)) continue;
// Only adopt workspaces that match our naming pattern: {taskType}-{repo}-{issue}
const parts = ws.name.match(/^(.+?)-(.+?)-(\d+)$/);
if (!parts) continue;
this.active.set(ws.name, {
workspaceId: ws.id,
workspaceName: ws.name,
startedAt: new Date(), // approximate — we don't know the real start time
});
console.log(`[queue] reconciled: adopted workspace "${ws.name}" (status: ${ws.latestBuildStatus})`);
}
if (this.active.size > 0) {
console.log(`[queue] reconcile complete: ${this.active.size} active workspace(s) adopted`);
}
}
/** Build a dedup key for a task. */
static key(task: TaskRequest): string {
return `${task.taskType}-${task.giteaRepo}-${task.issueNumber}`;
}
/** Build the workspace name (matches the dedup key). */
static workspaceName(task: TaskRequest): string {
return `${task.taskType}-${task.giteaRepo}-${task.issueNumber}`;
}
/**
* Enqueue a task. Returns true if queued, false if deduplicated (dropped).
*/
enqueue(
task: TaskRequest,
comment?: { useReviewAccount: boolean; body: string },
): boolean {
const key = TaskQueue.key(task);
if (this.active.has(key)) {
console.log(`[queue] dropped (active workspace): ${key}`);
return false;
}
if (this.running.has(key)) {
console.log(`[queue] dropped (running): ${key}`);
return false;
}
if (this.pending.has(key)) {
console.log(`[queue] dropped (pending): ${key}`);
return false;
}
this.pending.set(key, { task, comment });
console.log(
`[queue] enqueued: ${key} (pending: ${this.pending.size}, running: ${this.running.size}/${this.concurrency}, active: ${this.active.size})`,
);
this.drain();
return true;
}
/**
* Handle task-complete callback from a workspace.
* Stops the workspace via Coder API and removes it from active tracking.
*/
async taskComplete(workspaceName: string): Promise<boolean> {
const entry = this.active.get(workspaceName);
if (!entry) {
console.log(`[queue] task-complete for unknown workspace: ${workspaceName}`);
return false;
}
const elapsed = Math.round(
(Date.now() - entry.startedAt.getTime()) / 1000,
);
console.log(
`[queue] task complete: ${workspaceName} (ran for ${elapsed}s) — stopping workspace`,
);
this.active.delete(workspaceName);
try {
await this.coder.deleteWorkspace(entry.workspaceId);
console.log(`[queue] workspace deleted: ${workspaceName}`);
} catch (err) {
console.error(`[queue] failed to delete workspace ${workspaceName}:`, err);
}
// Drain in case pending tasks were waiting for capacity
this.drain();
return true;
}
/** Process queued tasks up to the concurrency limit. */
private drain(): void {
const totalInFlight = this.running.size + this.active.size;
while (totalInFlight + this.pending.size > 0 && this.running.size + this.active.size < this.concurrency && this.pending.size > 0) {
const [key, entry] = this.pending.entries().next().value!;
this.pending.delete(key);
this.running.add(key);
this.process(key, entry);
}
}
private async process(key: string, entry: QueuedTask): Promise<void> {
const { task, comment } = entry;
try {
console.log(`[queue] processing: ${key}`);
const workspace = await this.coder.createWorkspace(task);
console.log(`[queue] workspace created: ${workspace.name} (id: ${workspace.id})`);
// Move from running → active (workspace is now alive, waiting for callback)
this.active.set(key, {
workspaceId: workspace.id,
workspaceName: workspace.name,
startedAt: new Date(),
});
if (comment) {
await this.gitea.commentOnIssue(
task.giteaOrg,
task.giteaRepo,
task.issueNumber,
comment.body,
comment.useReviewAccount,
);
}
} catch (err) {
console.error(`[queue] failed: ${key}`, err);
} finally {
this.running.delete(key);
// Don't drain here — active workspaces count toward concurrency
}
}
/** Current queue status for health/debug endpoints. */
status(): {
pending: string[];
running: string[];
active: Record<string, { workspaceId: string; elapsed: number }>;
concurrency: number;
} {
const activeMap: Record<string, { workspaceId: string; elapsed: number }> = {};
for (const [key, entry] of this.active) {
activeMap[key] = {
workspaceId: entry.workspaceId,
elapsed: Math.round((Date.now() - entry.startedAt.getTime()) / 1000),
};
}
return {
pending: [...this.pending.keys()],
running: [...this.running.keys()],
active: activeMap,
concurrency: this.concurrency,
};
}
}
+135 -5
View File
@@ -1,25 +1,26 @@
import type { Config } from "../config.js";
import type { TaskRequest } from "../types.js";
import { TaskQueue } from "../queue.js";
export class CoderClient {
private baseUrl: string;
private token: string;
private templateId: string;
private anthropicApiKey: string;
private claudeOauthToken: string;
private callbackUrl: string;
constructor(config: Config) {
this.baseUrl = config.coderUrl.replace(/\/$/, "");
this.token = config.coderToken;
this.templateId = config.coderTemplateId;
this.anthropicApiKey = config.anthropicApiKey;
this.claudeOauthToken = config.claudeOauthToken;
this.callbackUrl = config.callbackUrl;
}
async createWorkspace(task: TaskRequest): Promise<{ id: string; name: string }> {
const timestamp = new Date()
.toISOString()
.replace(/[-:T]/g, "")
.slice(8, 14); // HHmmss
const name = `${task.taskType}-${task.issueNumber}-${timestamp}`;
const name = TaskQueue.workspaceName(task);
const body = {
name,
@@ -32,6 +33,8 @@ export class CoderClient {
{ name: "gitea_org", value: task.giteaOrg },
{ name: "gitea_repo", value: task.giteaRepo },
{ name: "anthropic_api_key", value: this.anthropicApiKey },
{ name: "claude_oauth_token", value: this.claudeOauthToken },
{ name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` },
...(task.deployEnv
? [{ name: "deploy_env", value: task.deployEnv }]
: []),
@@ -50,6 +53,32 @@ export class CoderClient {
},
);
// Handle 409 conflict — workspace with this name already exists.
// This can happen if the orchestrator restarted and lost in-memory state.
if (res.status === 409) {
const existing = await this.findWorkspaceByName(name);
if (!existing) {
throw new Error(`Coder 409 but workspace "${name}" not found — possible race condition`);
}
const stoppedStatuses = ["stopped", "failed", "canceled", "deleted"];
if (stoppedStatuses.includes(existing.latestBuildStatus)) {
// Workspace is done — safe to replace
console.log(
`[coder] workspace "${name}" exists but ${existing.latestBuildStatus} — deleting and retrying`,
);
await this.deleteWorkspace(existing.id);
await new Promise((resolve) => setTimeout(resolve, 5000));
return this.createWorkspace(task);
}
// Workspace is still running — adopt it, don't kill it
console.log(
`[coder] workspace "${name}" is still ${existing.latestBuildStatus} — adopting existing workspace`,
);
return { id: existing.id, name: existing.name };
}
if (!res.ok) {
const text = await res.text();
throw new Error(`Coder API error ${res.status}: ${text}`);
@@ -58,4 +87,105 @@ export class CoderClient {
const data = (await res.json()) as { id: string; name: string };
return { id: data.id, name: data.name };
}
async stopWorkspace(workspaceId: string): Promise<void> {
const res = await fetch(
`${this.baseUrl}/api/v2/workspaces/${workspaceId}/builds`,
{
method: "POST",
headers: {
"Content-Type": "application/json",
"Coder-Session-Token": this.token,
},
body: JSON.stringify({ transition: "stop" }),
},
);
if (!res.ok) {
const text = await res.text();
throw new Error(`Coder stop error ${res.status}: ${text}`);
}
}
async deleteWorkspace(workspaceId: string): Promise<void> {
const res = await fetch(
`${this.baseUrl}/api/v2/workspaces/${workspaceId}`,
{
method: "DELETE",
headers: {
"Coder-Session-Token": this.token,
},
},
);
if (!res.ok) {
const text = await res.text();
throw new Error(`Coder delete error ${res.status}: ${text}`);
}
}
/**
* List all workspaces owned by the authenticated user.
* Used at startup to reconcile in-memory state with Coder.
*/
async listWorkspaces(): Promise<
Array<{ id: string; name: string; latestBuildStatus: string }>
> {
const res = await fetch(
`${this.baseUrl}/api/v2/workspaces?q=owner:me`,
{
headers: { "Coder-Session-Token": this.token },
},
);
if (!res.ok) return [];
const data = (await res.json()) as {
workspaces: Array<{
id: string;
name: string;
latest_build: { status: string };
}>;
};
return (data.workspaces ?? []).map((w) => ({
id: w.id,
name: w.name,
latestBuildStatus: w.latest_build?.status ?? "unknown",
}));
}
async findWorkspaceByName(name: string): Promise<{
id: string;
name: string;
createdAt: string;
latestBuildStatus: string;
} | null> {
const res = await fetch(
`${this.baseUrl}/api/v2/workspaces?q=name:${encodeURIComponent(name)}`,
{
headers: {
"Coder-Session-Token": this.token,
},
},
);
if (!res.ok) return null;
const data = (await res.json()) as {
workspaces: Array<{
id: string;
name: string;
created_at: string;
latest_build: { status: string };
}>;
};
const match = data.workspaces?.find((w) => w.name === name);
if (!match) return null;
return {
id: match.id,
name: match.name,
createdAt: match.created_at,
latestBuildStatus: match.latest_build?.status ?? "unknown",
};
}
}