Compare commits

..
8 Commits
Author SHA1 Message Date
Daniel SamsonandClaude Opus 4.6 abbe47b1b9 Support Claude Code Max via OAuth token
Publish Image / publish (push) Successful in 21s
Pass CLAUDE_CODE_OAUTH_TOKEN to workspaces so they use the Max
subscription instead of pay-per-use API credits. Falls back to
ANTHROPIC_API_KEY if OAuth token not set.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:52:01 +01:00
Daniel SamsonandClaude Opus 4.6 9bca465565 Skip build for lightweight stages (analyse, architect, release, maintenance)
These stages only read code and post comments — no need for npm install,
frontend build, Playwright, or migrations. Saves several minutes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:47:48 +01:00
Daniel SamsonandClaude Opus 4.6 d220623a9f Always fire callback via trap, even on script failure
Uses ERR/EXIT trap to ensure the orchestrator is notified when the
startup script fails (e.g. clone error, missing command file). Prevents
orphaned workspaces that never get cleaned up.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:42:18 +01:00
Daniel SamsonandClaude Opus 4.6 e801d96410 Ephemeral workspaces: remove PVC, use emptyDir
Workspaces are now fully immutable like GH Actions runners — no
persistent volume, no init container, no stale state between runs.
Fresh emptyDir on every workspace creation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:27:30 +01:00
Daniel SamsonandClaude Opus 4.6 869d82998b Fresh clone on every automated task, generic repo setup
Always rm -rf ~/project before cloning to avoid stale state from
previous workspace runs on the same PVC. Made setup steps generic
(detect frontend, playwright, migrations) instead of babble-specific.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:25:17 +01:00
Daniel SamsonandClaude Opus 4.6 aa986a470e Remove log viewer app, output goes to agent logs directly
Publish Image / publish (push) Successful in 15s
The startup script already writes to stdout which the Coder agent
captures. No need for a separate HTTP log server or coder_app button.
Logs are visible via the Coder web terminal or agent log viewer.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:18:00 +01:00
Daniel SamsonandClaude Opus 4.6 520fc8f81e Custom workspace image + fix slash command invocation
Publish Workspace Image / publish (push) Successful in 3m51s
- Add coder/workspace.Dockerfile with Node.js 22, wrangler, claude-code,
  and Playwright deps pre-installed. Eliminates ~3 min of installs on
  every workspace startup.
- Add CI workflow to build and push to registry.samson.media/coder-workspace
- Fix slash command: -p mode doesn't support /commands, so read the .md
  file directly, strip frontmatter, substitute $ARGUMENTS, pass as prompt
- Switch workspace image from codercom/enterprise-base to custom image

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:15:17 +01:00
Daniel SamsonandClaude Opus 4.6 d46e3ca247 Fix slash command invocation: /analyse not /project:analyse
The project: prefix is not valid Claude Code syntax. Slash commands
in .claude/commands/ are invoked as /$TASK_TYPE directly.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 14:09:08 +01:00
5 changed files with 125 additions and 185 deletions
+27
View File
@@ -0,0 +1,27 @@
name: Publish Workspace Image
on:
push:
paths:
- 'coder/workspace.Dockerfile'
branches:
- main
concurrency:
group: publish-workspace
cancel-in-progress: false
jobs:
publish:
runs-on: self-hosted
steps:
- uses: actions/checkout@v4
- name: Log in to registry
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.samson.media -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
- name: Build and push
run: |
IMAGE=registry.samson.media/coder-workspace
docker build -f coder/workspace.Dockerfile -t "$IMAGE:latest" .
docker push "$IMAGE:latest"
+67 -183
View File
@@ -76,27 +76,6 @@ data "coder_parameter" "memory" {
} }
} }
data "coder_parameter" "disk_size" {
name = "disk_size"
display_name = "Disk Size (GB)"
description = "Persistent home directory size"
type = "number"
default = "10"
mutable = false
option {
name = "5 GB"
value = "5"
}
option {
name = "10 GB"
value = "10"
}
option {
name = "20 GB"
value = "20"
}
}
# ─── Automation Parameters ─────────────────────────────────────────────────── # ─── Automation Parameters ───────────────────────────────────────────────────
@@ -217,6 +196,15 @@ data "coder_parameter" "callback_url" {
mutable = false mutable = false
} }
data "coder_parameter" "claude_oauth_token" {
name = "claude_oauth_token"
display_name = "Claude OAuth Token"
description = "OAuth token for Claude Code Max subscription"
type = "string"
default = ""
mutable = false
}
data "coder_parameter" "deploy_env" { data "coder_parameter" "deploy_env" {
name = "deploy_env" name = "deploy_env"
display_name = "Deploy Environment" display_name = "Deploy Environment"
@@ -375,33 +363,6 @@ resource "kubernetes_resource_quota_v1" "workspace" {
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m" "limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi" "requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
"limits.memory" = "${data.coder_parameter.memory.value}Mi" "limits.memory" = "${data.coder_parameter.memory.value}Mi"
"requests.storage" = "${data.coder_parameter.disk_size.value}Gi"
"persistentvolumeclaims" = "1"
}
}
}
# =============================================================================
# Storage
# =============================================================================
resource "kubernetes_persistent_volume_claim_v1" "home" {
metadata {
name = "home"
namespace = kubernetes_namespace_v1.workspace.metadata[0].name
labels = local.labels
}
wait_until_bound = false
spec {
access_modes = ["ReadWriteOnce"]
storage_class_name = "longhorn-backup"
resources {
requests = {
storage = "${data.coder_parameter.disk_size.value}Gi"
}
} }
} }
} }
@@ -462,7 +423,8 @@ resource "coder_agent" "main" {
} }
env = { env = {
ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value
CLAUDE_CODE_OAUTH_TOKEN = data.coder_parameter.claude_oauth_token.value
GITHUB_TOKEN = data.coder_external_auth.github.access_token GITHUB_TOKEN = data.coder_external_auth.github.access_token
GITEA_TOKEN = data.coder_parameter.gitea_token.value GITEA_TOKEN = data.coder_parameter.gitea_token.value
GITEA_ORG = data.coder_parameter.gitea_org.value GITEA_ORG = data.coder_parameter.gitea_org.value
@@ -476,30 +438,19 @@ resource "coder_agent" "main" {
startup_script = <<-EOT startup_script = <<-EOT
#!/bin/bash #!/bin/bash
# Always notify the orchestrator when done, even on failure
notify_complete() {
if [ -n "$CALLBACK_URL" ]; then
curl -s -X POST -H "Content-Type: application/json" \
-d "{\"status\":\"$1\"}" \
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
fi
}
trap 'notify_complete "failed"' ERR EXIT
set -e set -e
# --- Install Node.js 22 ---
if ! command -v node &> /dev/null; then
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
fi
# --- Install global tools ---
if ! command -v wrangler &> /dev/null; then
sudo npm install -g wrangler @anthropic-ai/claude-code
fi
# --- Install Playwright system dependencies ---
if ! dpkg -s libgbm1 &> /dev/null; then
sudo apt-get update
sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
libcups2t64 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2t64 libatspi2.0-0 \
|| sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
libcups2 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2 libatspi2.0-0
fi
# --- Configure git --- # --- Configure git ---
git config --global user.name "${data.coder_workspace_owner.me.full_name}" git config --global user.name "${data.coder_workspace_owner.me.full_name}"
git config --global user.email "${data.coder_workspace_owner.me.email}" git config --global user.email "${data.coder_workspace_owner.me.email}"
@@ -512,62 +463,39 @@ resource "coder_agent" "main" {
fi fi
# --- Clone repository --- # --- Clone repository ---
if [ -n "$REPO_CLONE_URL" ] && [ ! -d ~/project ]; then if [ -n "$REPO_CLONE_URL" ]; then
git clone "$REPO_CLONE_URL" ~/project git clone "$REPO_CLONE_URL" ~/project
cd ~/project cd ~/project
# Switch to develop branch if it exists # Switch to develop branch if it exists
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
# Install backend deps # Lightweight stages only need the code, not a full build
npm ci --legacy-peer-deps LIGHT_STAGES="analyse architect release maintenance"
if echo "$LIGHT_STAGES" | grep -qw "$TASK_TYPE"; then
# Install frontend deps echo "Lightweight stage ($TASK_TYPE) — skipping build"
cd frontend && npm ci && cd ..
# Build frontend (required — vitest fails without frontend/dist)
npm run build:frontend
# Install Playwright Chromium
npx playwright install chromium
# Apply local migrations
npm run db:migrate:local
fi
# --- Start log viewer on port 13338 ---
if [ -n "$TASK_TYPE" ]; then
touch ~/task-output.log
cat > ~/log-server.sh << 'LOGEOF'
#!/bin/bash
while true; do
{
echo "HTTP/1.1 200 OK"
echo "Content-Type: text/html; charset=utf-8"
echo "Connection: close"
echo ""
echo "<html><head><title>Task Log</title>"
echo "<meta http-equiv='refresh' content='5'>"
echo "<style>body{background:#1e1e1e;color:#d4d4d4;font-family:monospace;font-size:13px;padding:16px;white-space:pre-wrap;}"
echo "h2{color:#569cd6;margin:0 0 8px}.meta{color:#6a9955;margin-bottom:16px;display:block}</style></head><body>"
echo "<h2>$TASK_TYPE #$ISSUE_NUMBER — $(hostname)</h2>"
if [ -f ~/task-output.log ]; then
LINES=$(wc -l < ~/task-output.log)
if grep -q "Task completed" ~/task-output.log 2>/dev/null; then
echo "<span class='meta'>Status: ✅ Complete ($LINES lines)</span>"
else else
echo "<span class='meta'>Status: ⏳ Running ($LINES lines) — auto-refreshing every 5s</span>" # Install deps if package.json exists
if [ -f package.json ]; then
npm ci --legacy-peer-deps || npm ci
fi
# Install frontend deps if present
if [ -f frontend/package.json ]; then
cd frontend && npm ci && cd ..
npm run build:frontend 2>/dev/null || true
fi
# Install Playwright if needed
if grep -q "playwright" package.json 2>/dev/null; then
npx playwright install chromium
fi
# Apply local migrations if script exists
if npm run --silent db:migrate:local 2>/dev/null; then
echo "Local migrations applied"
fi
fi fi
sed 's/&/\&amp;/g; s/</\&lt;/g; s/>/\&gt;/g' ~/task-output.log
else
echo "Waiting for task to start..."
fi
echo "</body></html>"
} | nc -l -p 13338 -q 1 2>/dev/null || true
done
LOGEOF
chmod +x ~/log-server.sh
nohup bash ~/log-server.sh &>/dev/null &
fi fi
# --- Automated task execution --- # --- Automated task execution ---
@@ -579,38 +507,24 @@ LOGEOF
ARGS="$DEPLOY_ENV" ARGS="$DEPLOY_ENV"
fi fi
# Run Claude Code in non-interactive mode with tool access # Read the slash command .md file, strip YAML frontmatter, substitute $ARGUMENTS
claude -p --dangerously-skip-permissions --verbose "/project:$TASK_TYPE $ARGS" 2>&1 | tee ~/task-output.log CMD_FILE=".claude/commands/$TASK_TYPE.md"
EXIT_CODE=$? if [ ! -f "$CMD_FILE" ]; then
echo "Claude exited with code: $EXIT_CODE" | tee -a ~/task-output.log echo "ERROR: Command file not found: $CMD_FILE"
exit 1
echo "Task completed. Output saved to ~/task-output.log"
# Notify orchestrator that the task is done
if [ -n "$CALLBACK_URL" ]; then
curl -s -X POST -H "Content-Type: application/json" \
-d '{"status":"complete"}' \
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
fi fi
PROMPT=$(sed '1{/^---$/!q}; 1,/^---$/d' "$CMD_FILE" | sed "s/\\\$ARGUMENTS/$ARGS/g")
# Run Claude Code in non-interactive mode with tool access
claude -p --dangerously-skip-permissions --verbose "$PROMPT"
fi fi
# Success — override the trap
trap - ERR EXIT
notify_complete "complete"
EOT EOT
} }
resource "coder_app" "task_log" {
agent_id = coder_agent.main.id
slug = "task-log"
display_name = "Task Log"
icon = "/icon/document.svg"
url = "http://localhost:13338"
share = "owner"
healthcheck {
url = "http://localhost:13338"
interval = 10
threshold = 3
}
}
# ============================================================================= # =============================================================================
# Main Workspace Deployment # Main Workspace Deployment
# ============================================================================= # =============================================================================
@@ -656,42 +570,9 @@ resource "kubernetes_deployment_v1" "workspace" {
name = kubernetes_secret_v1.registry.metadata[0].name name = kubernetes_secret_v1.registry.metadata[0].name
} }
init_container {
name = "fix-permissions"
image = "busybox:latest"
command = ["sh", "-c", <<-EOC
if [ ! -d /home/coder/project ]; then
mkdir -p /home/coder/project
fi
chown -R 1000:1000 /home/coder
EOC
]
volume_mount {
name = "home"
mount_path = "/home/coder"
}
resources {
requests = {
cpu = "5m"
memory = "8Mi"
}
limits = {
cpu = "50m"
memory = "32Mi"
}
}
security_context {
run_as_user = 0
}
}
container { container {
name = "coder-agent" name = "coder-agent"
image = "codercom/enterprise-base:latest" image = "registry.samson.media/coder-workspace:latest"
command = ["sh", "-c", coder_agent.main.init_script] command = ["sh", "-c", coder_agent.main.init_script]
@@ -705,6 +586,11 @@ resource "kubernetes_deployment_v1" "workspace" {
value = data.coder_parameter.anthropic_api_key.value value = data.coder_parameter.anthropic_api_key.value
} }
env {
name = "CLAUDE_CODE_OAUTH_TOKEN"
value = data.coder_parameter.claude_oauth_token.value
}
env { env {
name = "GITHUB_TOKEN" name = "GITHUB_TOKEN"
value = data.coder_external_auth.github.access_token value = data.coder_external_auth.github.access_token
@@ -774,9 +660,7 @@ resource "kubernetes_deployment_v1" "workspace" {
volume { volume {
name = "home" name = "home"
persistent_volume_claim { empty_dir {}
claim_name = kubernetes_persistent_volume_claim_v1.home.metadata[0].name
}
} }
} }
} }
+23
View File
@@ -0,0 +1,23 @@
FROM codercom/enterprise-base:latest
USER root
# Node.js 22
RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \
&& apt-get install -y nodejs \
&& rm -rf /var/lib/apt/lists/*
# Global npm tools
RUN npm install -g wrangler @anthropic-ai/claude-code
# Playwright system dependencies (both Ubuntu 24.04 and 22.04 package names)
RUN apt-get update && apt-get install -y --no-install-recommends \
libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libatspi2.0-0 \
jq netcat-openbsd \
&& (apt-get install -y libcups2t64 libasound2t64 2>/dev/null \
|| apt-get install -y libcups2 libasound2 2>/dev/null) \
&& rm -rf /var/lib/apt/lists/*
USER coder
+5 -2
View File
@@ -11,8 +11,10 @@ export interface Config {
giteaDevToken: string; giteaDevToken: string;
/** Gitea API token for the review bot account */ /** Gitea API token for the review bot account */
giteaReviewToken: string; giteaReviewToken: string;
/** Anthropic API key passed to Claude Code in workspaces */ /** Anthropic API key passed to Claude Code in workspaces (fallback) */
anthropicApiKey: string; anthropicApiKey: string;
/** Claude Code OAuth token for Max subscription (preferred) */
claudeOauthToken: string;
/** Username of the dev bot (to filter out self-replies) */ /** Username of the dev bot (to filter out self-replies) */
botDevUsername: string; botDevUsername: string;
/** Username of the review bot (to filter out self-replies) */ /** Username of the review bot (to filter out self-replies) */
@@ -41,7 +43,8 @@ export function loadConfig(): Config {
coderTemplateId: required("CODER_TEMPLATE_ID"), coderTemplateId: required("CODER_TEMPLATE_ID"),
giteaDevToken: required("GITEA_DEV_TOKEN"), giteaDevToken: required("GITEA_DEV_TOKEN"),
giteaReviewToken: required("GITEA_REVIEW_TOKEN"), giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
anthropicApiKey: required("ANTHROPIC_API_KEY"), anthropicApiKey: process.env.ANTHROPIC_API_KEY || "",
claudeOauthToken: process.env.CLAUDE_OAUTH_TOKEN || "",
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev", botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review", botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media", giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
+3
View File
@@ -7,6 +7,7 @@ export class CoderClient {
private token: string; private token: string;
private templateId: string; private templateId: string;
private anthropicApiKey: string; private anthropicApiKey: string;
private claudeOauthToken: string;
private callbackUrl: string; private callbackUrl: string;
constructor(config: Config) { constructor(config: Config) {
@@ -14,6 +15,7 @@ export class CoderClient {
this.token = config.coderToken; this.token = config.coderToken;
this.templateId = config.coderTemplateId; this.templateId = config.coderTemplateId;
this.anthropicApiKey = config.anthropicApiKey; this.anthropicApiKey = config.anthropicApiKey;
this.claudeOauthToken = config.claudeOauthToken;
this.callbackUrl = config.callbackUrl; this.callbackUrl = config.callbackUrl;
} }
@@ -31,6 +33,7 @@ export class CoderClient {
{ name: "gitea_org", value: task.giteaOrg }, { name: "gitea_org", value: task.giteaOrg },
{ name: "gitea_repo", value: task.giteaRepo }, { name: "gitea_repo", value: task.giteaRepo },
{ name: "anthropic_api_key", value: this.anthropicApiKey }, { name: "anthropic_api_key", value: this.anthropicApiKey },
{ name: "claude_oauth_token", value: this.claudeOauthToken },
{ name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` }, { name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` },
...(task.deployEnv ...(task.deployEnv
? [{ name: "deploy_env", value: task.deployEnv }] ? [{ name: "deploy_env", value: task.deployEnv }]