Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
abbe47b1b9 | ||
|
|
9bca465565 | ||
|
|
d220623a9f | ||
|
|
e801d96410 | ||
|
|
869d82998b |
+58
-110
@@ -76,27 +76,6 @@ data "coder_parameter" "memory" {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
data "coder_parameter" "disk_size" {
|
|
||||||
name = "disk_size"
|
|
||||||
display_name = "Disk Size (GB)"
|
|
||||||
description = "Persistent home directory size"
|
|
||||||
type = "number"
|
|
||||||
default = "10"
|
|
||||||
mutable = false
|
|
||||||
|
|
||||||
option {
|
|
||||||
name = "5 GB"
|
|
||||||
value = "5"
|
|
||||||
}
|
|
||||||
option {
|
|
||||||
name = "10 GB"
|
|
||||||
value = "10"
|
|
||||||
}
|
|
||||||
option {
|
|
||||||
name = "20 GB"
|
|
||||||
value = "20"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# ─── Automation Parameters ───────────────────────────────────────────────────
|
# ─── Automation Parameters ───────────────────────────────────────────────────
|
||||||
|
|
||||||
@@ -217,6 +196,15 @@ data "coder_parameter" "callback_url" {
|
|||||||
mutable = false
|
mutable = false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
data "coder_parameter" "claude_oauth_token" {
|
||||||
|
name = "claude_oauth_token"
|
||||||
|
display_name = "Claude OAuth Token"
|
||||||
|
description = "OAuth token for Claude Code Max subscription"
|
||||||
|
type = "string"
|
||||||
|
default = ""
|
||||||
|
mutable = false
|
||||||
|
}
|
||||||
|
|
||||||
data "coder_parameter" "deploy_env" {
|
data "coder_parameter" "deploy_env" {
|
||||||
name = "deploy_env"
|
name = "deploy_env"
|
||||||
display_name = "Deploy Environment"
|
display_name = "Deploy Environment"
|
||||||
@@ -375,33 +363,6 @@ resource "kubernetes_resource_quota_v1" "workspace" {
|
|||||||
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
|
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
|
||||||
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
|
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
|
||||||
"limits.memory" = "${data.coder_parameter.memory.value}Mi"
|
"limits.memory" = "${data.coder_parameter.memory.value}Mi"
|
||||||
"requests.storage" = "${data.coder_parameter.disk_size.value}Gi"
|
|
||||||
"persistentvolumeclaims" = "1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# =============================================================================
|
|
||||||
# Storage
|
|
||||||
# =============================================================================
|
|
||||||
|
|
||||||
resource "kubernetes_persistent_volume_claim_v1" "home" {
|
|
||||||
metadata {
|
|
||||||
name = "home"
|
|
||||||
namespace = kubernetes_namespace_v1.workspace.metadata[0].name
|
|
||||||
labels = local.labels
|
|
||||||
}
|
|
||||||
|
|
||||||
wait_until_bound = false
|
|
||||||
|
|
||||||
spec {
|
|
||||||
access_modes = ["ReadWriteOnce"]
|
|
||||||
storage_class_name = "longhorn-backup"
|
|
||||||
|
|
||||||
resources {
|
|
||||||
requests = {
|
|
||||||
storage = "${data.coder_parameter.disk_size.value}Gi"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -462,7 +423,8 @@ resource "coder_agent" "main" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
env = {
|
env = {
|
||||||
ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value
|
ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value
|
||||||
|
CLAUDE_CODE_OAUTH_TOKEN = data.coder_parameter.claude_oauth_token.value
|
||||||
GITHUB_TOKEN = data.coder_external_auth.github.access_token
|
GITHUB_TOKEN = data.coder_external_auth.github.access_token
|
||||||
GITEA_TOKEN = data.coder_parameter.gitea_token.value
|
GITEA_TOKEN = data.coder_parameter.gitea_token.value
|
||||||
GITEA_ORG = data.coder_parameter.gitea_org.value
|
GITEA_ORG = data.coder_parameter.gitea_org.value
|
||||||
@@ -476,6 +438,17 @@ resource "coder_agent" "main" {
|
|||||||
|
|
||||||
startup_script = <<-EOT
|
startup_script = <<-EOT
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
|
# Always notify the orchestrator when done, even on failure
|
||||||
|
notify_complete() {
|
||||||
|
if [ -n "$CALLBACK_URL" ]; then
|
||||||
|
curl -s -X POST -H "Content-Type: application/json" \
|
||||||
|
-d "{\"status\":\"$1\"}" \
|
||||||
|
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
trap 'notify_complete "failed"' ERR EXIT
|
||||||
|
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
# --- Configure git ---
|
# --- Configure git ---
|
||||||
@@ -490,27 +463,39 @@ resource "coder_agent" "main" {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# --- Clone repository ---
|
# --- Clone repository ---
|
||||||
if [ -n "$REPO_CLONE_URL" ] && [ ! -d ~/project ]; then
|
if [ -n "$REPO_CLONE_URL" ]; then
|
||||||
git clone "$REPO_CLONE_URL" ~/project
|
git clone "$REPO_CLONE_URL" ~/project
|
||||||
cd ~/project
|
cd ~/project
|
||||||
|
|
||||||
# Switch to develop branch if it exists
|
# Switch to develop branch if it exists
|
||||||
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
|
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
|
||||||
|
|
||||||
# Install backend deps
|
# Lightweight stages only need the code, not a full build
|
||||||
npm ci --legacy-peer-deps
|
LIGHT_STAGES="analyse architect release maintenance"
|
||||||
|
if echo "$LIGHT_STAGES" | grep -qw "$TASK_TYPE"; then
|
||||||
|
echo "Lightweight stage ($TASK_TYPE) — skipping build"
|
||||||
|
else
|
||||||
|
# Install deps if package.json exists
|
||||||
|
if [ -f package.json ]; then
|
||||||
|
npm ci --legacy-peer-deps || npm ci
|
||||||
|
fi
|
||||||
|
|
||||||
# Install frontend deps
|
# Install frontend deps if present
|
||||||
cd frontend && npm ci && cd ..
|
if [ -f frontend/package.json ]; then
|
||||||
|
cd frontend && npm ci && cd ..
|
||||||
|
npm run build:frontend 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
# Build frontend (required — vitest fails without frontend/dist)
|
# Install Playwright if needed
|
||||||
npm run build:frontend
|
if grep -q "playwright" package.json 2>/dev/null; then
|
||||||
|
npx playwright install chromium
|
||||||
|
fi
|
||||||
|
|
||||||
# Install Playwright Chromium
|
# Apply local migrations if script exists
|
||||||
npx playwright install chromium
|
if npm run --silent db:migrate:local 2>/dev/null; then
|
||||||
|
echo "Local migrations applied"
|
||||||
# Apply local migrations
|
fi
|
||||||
npm run db:migrate:local
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# --- Automated task execution ---
|
# --- Automated task execution ---
|
||||||
@@ -525,25 +510,18 @@ resource "coder_agent" "main" {
|
|||||||
# Read the slash command .md file, strip YAML frontmatter, substitute $ARGUMENTS
|
# Read the slash command .md file, strip YAML frontmatter, substitute $ARGUMENTS
|
||||||
CMD_FILE=".claude/commands/$TASK_TYPE.md"
|
CMD_FILE=".claude/commands/$TASK_TYPE.md"
|
||||||
if [ ! -f "$CMD_FILE" ]; then
|
if [ ! -f "$CMD_FILE" ]; then
|
||||||
echo "ERROR: Command file not found: $CMD_FILE" | tee ~/task-output.log
|
echo "ERROR: Command file not found: $CMD_FILE"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
PROMPT=$(sed '1{/^---$/!q}; 1,/^---$/d' "$CMD_FILE" | sed "s/\\\$ARGUMENTS/$ARGS/g")
|
PROMPT=$(sed '1{/^---$/!q}; 1,/^---$/d' "$CMD_FILE" | sed "s/\\\$ARGUMENTS/$ARGS/g")
|
||||||
|
|
||||||
# Run Claude Code in non-interactive mode with tool access
|
# Run Claude Code in non-interactive mode with tool access
|
||||||
claude -p --dangerously-skip-permissions --verbose "$PROMPT" 2>&1 | tee ~/task-output.log
|
claude -p --dangerously-skip-permissions --verbose "$PROMPT"
|
||||||
EXIT_CODE=$?
|
|
||||||
echo "Claude exited with code: $EXIT_CODE" | tee -a ~/task-output.log
|
|
||||||
|
|
||||||
echo "Task completed. Output saved to ~/task-output.log"
|
|
||||||
|
|
||||||
# Notify orchestrator that the task is done
|
|
||||||
if [ -n "$CALLBACK_URL" ]; then
|
|
||||||
curl -s -X POST -H "Content-Type: application/json" \
|
|
||||||
-d '{"status":"complete"}' \
|
|
||||||
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Success — override the trap
|
||||||
|
trap - ERR EXIT
|
||||||
|
notify_complete "complete"
|
||||||
EOT
|
EOT
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -592,39 +570,6 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
name = kubernetes_secret_v1.registry.metadata[0].name
|
name = kubernetes_secret_v1.registry.metadata[0].name
|
||||||
}
|
}
|
||||||
|
|
||||||
init_container {
|
|
||||||
name = "fix-permissions"
|
|
||||||
image = "busybox:latest"
|
|
||||||
|
|
||||||
command = ["sh", "-c", <<-EOC
|
|
||||||
if [ ! -d /home/coder/project ]; then
|
|
||||||
mkdir -p /home/coder/project
|
|
||||||
fi
|
|
||||||
chown -R 1000:1000 /home/coder
|
|
||||||
EOC
|
|
||||||
]
|
|
||||||
|
|
||||||
volume_mount {
|
|
||||||
name = "home"
|
|
||||||
mount_path = "/home/coder"
|
|
||||||
}
|
|
||||||
|
|
||||||
resources {
|
|
||||||
requests = {
|
|
||||||
cpu = "5m"
|
|
||||||
memory = "8Mi"
|
|
||||||
}
|
|
||||||
limits = {
|
|
||||||
cpu = "50m"
|
|
||||||
memory = "32Mi"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
security_context {
|
|
||||||
run_as_user = 0
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
container {
|
container {
|
||||||
name = "coder-agent"
|
name = "coder-agent"
|
||||||
image = "registry.samson.media/coder-workspace:latest"
|
image = "registry.samson.media/coder-workspace:latest"
|
||||||
@@ -641,6 +586,11 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
value = data.coder_parameter.anthropic_api_key.value
|
value = data.coder_parameter.anthropic_api_key.value
|
||||||
}
|
}
|
||||||
|
|
||||||
|
env {
|
||||||
|
name = "CLAUDE_CODE_OAUTH_TOKEN"
|
||||||
|
value = data.coder_parameter.claude_oauth_token.value
|
||||||
|
}
|
||||||
|
|
||||||
env {
|
env {
|
||||||
name = "GITHUB_TOKEN"
|
name = "GITHUB_TOKEN"
|
||||||
value = data.coder_external_auth.github.access_token
|
value = data.coder_external_auth.github.access_token
|
||||||
@@ -710,9 +660,7 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
|
|
||||||
volume {
|
volume {
|
||||||
name = "home"
|
name = "home"
|
||||||
persistent_volume_claim {
|
empty_dir {}
|
||||||
claim_name = kubernetes_persistent_volume_claim_v1.home.metadata[0].name
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+5
-2
@@ -11,8 +11,10 @@ export interface Config {
|
|||||||
giteaDevToken: string;
|
giteaDevToken: string;
|
||||||
/** Gitea API token for the review bot account */
|
/** Gitea API token for the review bot account */
|
||||||
giteaReviewToken: string;
|
giteaReviewToken: string;
|
||||||
/** Anthropic API key passed to Claude Code in workspaces */
|
/** Anthropic API key passed to Claude Code in workspaces (fallback) */
|
||||||
anthropicApiKey: string;
|
anthropicApiKey: string;
|
||||||
|
/** Claude Code OAuth token for Max subscription (preferred) */
|
||||||
|
claudeOauthToken: string;
|
||||||
/** Username of the dev bot (to filter out self-replies) */
|
/** Username of the dev bot (to filter out self-replies) */
|
||||||
botDevUsername: string;
|
botDevUsername: string;
|
||||||
/** Username of the review bot (to filter out self-replies) */
|
/** Username of the review bot (to filter out self-replies) */
|
||||||
@@ -41,7 +43,8 @@ export function loadConfig(): Config {
|
|||||||
coderTemplateId: required("CODER_TEMPLATE_ID"),
|
coderTemplateId: required("CODER_TEMPLATE_ID"),
|
||||||
giteaDevToken: required("GITEA_DEV_TOKEN"),
|
giteaDevToken: required("GITEA_DEV_TOKEN"),
|
||||||
giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
|
giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
|
||||||
anthropicApiKey: required("ANTHROPIC_API_KEY"),
|
anthropicApiKey: process.env.ANTHROPIC_API_KEY || "",
|
||||||
|
claudeOauthToken: process.env.CLAUDE_OAUTH_TOKEN || "",
|
||||||
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
|
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
|
||||||
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
|
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
|
||||||
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
|
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ export class CoderClient {
|
|||||||
private token: string;
|
private token: string;
|
||||||
private templateId: string;
|
private templateId: string;
|
||||||
private anthropicApiKey: string;
|
private anthropicApiKey: string;
|
||||||
|
private claudeOauthToken: string;
|
||||||
private callbackUrl: string;
|
private callbackUrl: string;
|
||||||
|
|
||||||
constructor(config: Config) {
|
constructor(config: Config) {
|
||||||
@@ -14,6 +15,7 @@ export class CoderClient {
|
|||||||
this.token = config.coderToken;
|
this.token = config.coderToken;
|
||||||
this.templateId = config.coderTemplateId;
|
this.templateId = config.coderTemplateId;
|
||||||
this.anthropicApiKey = config.anthropicApiKey;
|
this.anthropicApiKey = config.anthropicApiKey;
|
||||||
|
this.claudeOauthToken = config.claudeOauthToken;
|
||||||
this.callbackUrl = config.callbackUrl;
|
this.callbackUrl = config.callbackUrl;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -31,6 +33,7 @@ export class CoderClient {
|
|||||||
{ name: "gitea_org", value: task.giteaOrg },
|
{ name: "gitea_org", value: task.giteaOrg },
|
||||||
{ name: "gitea_repo", value: task.giteaRepo },
|
{ name: "gitea_repo", value: task.giteaRepo },
|
||||||
{ name: "anthropic_api_key", value: this.anthropicApiKey },
|
{ name: "anthropic_api_key", value: this.anthropicApiKey },
|
||||||
|
{ name: "claude_oauth_token", value: this.claudeOauthToken },
|
||||||
{ name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` },
|
{ name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` },
|
||||||
...(task.deployEnv
|
...(task.deployEnv
|
||||||
? [{ name: "deploy_env", value: task.deployEnv }]
|
? [{ name: "deploy_env", value: task.deployEnv }]
|
||||||
|
|||||||
Reference in New Issue
Block a user