Compare commits
@@ -0,0 +1,27 @@
|
|||||||
|
name: Publish Workspace Image
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
paths:
|
||||||
|
- 'coder/workspace.Dockerfile'
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: publish-workspace
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
publish:
|
||||||
|
runs-on: self-hosted
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Log in to registry
|
||||||
|
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.samson.media -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||||
|
|
||||||
|
- name: Build and push
|
||||||
|
run: |
|
||||||
|
IMAGE=registry.samson.media/coder-workspace
|
||||||
|
docker build -f coder/workspace.Dockerfile -t "$IMAGE:latest" .
|
||||||
|
docker push "$IMAGE:latest"
|
||||||
@@ -1,39 +1,184 @@
|
|||||||
# SDLC Orchestrator
|
# SDLC Orchestrator
|
||||||
|
|
||||||
Lightweight webhook-driven orchestrator that replaces n8n for the Gitea + Coder + Claude Code SDLC pipeline.
|
Lightweight webhook-driven orchestrator for the Gitea + Coder + Claude Code SDLC pipeline. Receives Gitea webhooks, creates ephemeral Coder workspaces running Claude Code, and cleans up when done.
|
||||||
|
|
||||||
Receives Gitea webhooks, routes them to the correct SDLC stage, creates Coder workspaces, and posts status comments back on issues/PRs.
|
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
|
|
||||||
```
|
```
|
||||||
Gitea Webhooks → SDLC Orchestrator → Coder API (creates workspace)
|
Gitea Webhook → Orchestrator → Coder API (create workspace)
|
||||||
→ Gitea API (posts comments)
|
→ Gitea API (post status comment)
|
||||||
|
|
||||||
|
Workspace runs Claude Code → reads issue → does work → posts results to Gitea
|
||||||
|
→ POST /webhook/task-complete/:name (callback)
|
||||||
|
|
||||||
|
Orchestrator receives callback → deletes workspace via Coder API
|
||||||
```
|
```
|
||||||
|
|
||||||
~500 lines of TypeScript. No database, no UI, no state — just a webhook router.
|
## Adding a New Project
|
||||||
|
|
||||||
## Webhook Endpoints
|
To add a new Gitea repo to the SDLC pipeline:
|
||||||
|
|
||||||
| Endpoint | Gitea Event | Action |
|
### 1. Add Claude Code slash commands to the repo
|
||||||
|----------|-------------|--------|
|
|
||||||
| `POST /webhook/gitea-issue-triage` | Issue opened | Route to `analyse` or `fix-bug` |
|
|
||||||
| `POST /webhook/gitea-issue-label` | Issue labeled | Stage transition (architect/develop/test/devops) |
|
|
||||||
| `POST /webhook/gitea-issue-comment` | Comment created | Re-trigger analyst if still in analysis |
|
|
||||||
| `POST /webhook/gitea-pr-review` | PR opened/synced | Trigger code review |
|
|
||||||
| `POST /webhook/gitea-pr-review-rework` | Review submitted | Route to `rework-pr` or `test` |
|
|
||||||
| `POST /webhook/gitea-release` | Release issue | Tag RC or production release |
|
|
||||||
| `GET /health` | — | Health check |
|
|
||||||
|
|
||||||
Plus a cron job (Monday 9 AM) for weekly maintenance.
|
Create `.claude/commands/` in the repo with command files for each SDLC stage:
|
||||||
|
|
||||||
## Setup
|
```
|
||||||
|
.claude/commands/
|
||||||
|
├── analyse.md # Business analyst — requirements & acceptance criteria
|
||||||
|
├── architect.md # Systems architect — design doc & spec
|
||||||
|
├── develop.md # Developer — implement & create PR
|
||||||
|
├── review-code.md # Reviewer — approve or request changes
|
||||||
|
├── test.md # QA — test report & additional tests
|
||||||
|
├── fix-bug.md # Bug fix — skip analyse/architect
|
||||||
|
├── rework-pr.md # Address review feedback
|
||||||
|
├── release.md # Tag RC or production release
|
||||||
|
├── devops.md # Migration & deployment
|
||||||
|
└── maintenance.md # Weekly maintenance tasks
|
||||||
|
```
|
||||||
|
|
||||||
|
Each file uses this format:
|
||||||
|
|
||||||
|
```markdown
|
||||||
|
---
|
||||||
|
description: What this command does
|
||||||
|
allowed-tools: Read, Bash, Glob, Grep
|
||||||
|
---
|
||||||
|
|
||||||
|
You are a **Role Name**. Your job is to...
|
||||||
|
|
||||||
|
## Process
|
||||||
|
|
||||||
|
1. **Read the issue**:
|
||||||
|
```bash
|
||||||
|
curl -s "https://gitea.samson.media/api/v1/repos/${GITEA_ORG}/${GITEA_REPO}/issues/$ARGUMENTS" \
|
||||||
|
-H "Authorization: token ${GITEA_TOKEN}" | jq '{title, body, labels: [.labels[].name]}'
|
||||||
|
```
|
||||||
|
|
||||||
|
2. **Do your work...**
|
||||||
|
|
||||||
|
3. **Post a comment**:
|
||||||
|
```bash
|
||||||
|
curl -X POST "https://gitea.samson.media/api/v1/repos/${GITEA_ORG}/${GITEA_REPO}/issues/$ARGUMENTS/comments" \
|
||||||
|
-H "Authorization: token ${GITEA_TOKEN}" \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
-d '{"body": "..."}'
|
||||||
|
```
|
||||||
|
```
|
||||||
|
|
||||||
|
`$ARGUMENTS` is replaced with the issue/PR number at runtime.
|
||||||
|
|
||||||
|
### 2. Add bot users as collaborators
|
||||||
|
|
||||||
|
Add both `claude-dev` and `claude-review` as **direct collaborators** with **Write** access on the repo. Org membership alone is not sufficient.
|
||||||
|
|
||||||
|
### 3. Configure Gitea webhooks
|
||||||
|
|
||||||
|
In the repo's **Settings → Webhooks**, create these webhooks:
|
||||||
|
|
||||||
|
| # | URL | Events |
|
||||||
|
|---|-----|--------|
|
||||||
|
| 1 | `https://sdlc.samson.media/webhook/gitea-issue-triage` | Issues: `opened` |
|
||||||
|
| 2 | `https://sdlc.samson.media/webhook/gitea-issue-label` | Issues: `labeled` |
|
||||||
|
| 3 | `https://sdlc.samson.media/webhook/gitea-issue-comment` | Issue Comment: `created`, `edited` |
|
||||||
|
| 4 | `https://sdlc.samson.media/webhook/gitea-pr-review` | Pull Request: `opened`, `synchronized` |
|
||||||
|
| 5 | `https://sdlc.samson.media/webhook/gitea-pr-review-rework` | Pull Request Review: `submitted` |
|
||||||
|
| 6 | `https://sdlc.samson.media/webhook/gitea-release` | Issues: `opened`, `labeled` |
|
||||||
|
|
||||||
|
All webhooks use:
|
||||||
|
- Content type: `application/json`
|
||||||
|
- Method: `POST`
|
||||||
|
|
||||||
|
### 4. (Optional) Add to maintenance cron
|
||||||
|
|
||||||
|
To include the repo in weekly maintenance, add it to the `MAINTENANCE_REPOS` env var:
|
||||||
|
|
||||||
|
```
|
||||||
|
MAINTENANCE_REPOS=org1/repo1=https://gitea.samson.media/org1/repo1.git,org2/repo2=https://gitea.samson.media/org2/repo2.git
|
||||||
|
```
|
||||||
|
|
||||||
|
### 5. Test it
|
||||||
|
|
||||||
|
Create an issue in the repo. The orchestrator will:
|
||||||
|
1. Receive the `issues/opened` webhook
|
||||||
|
2. Create a Coder workspace running `/analyse`
|
||||||
|
3. Claude reads the issue, posts clarifying questions as a comment
|
||||||
|
4. Workspace is deleted automatically when done
|
||||||
|
|
||||||
|
## SDLC Flow
|
||||||
|
|
||||||
|
| Stage | Trigger | Task Type | Bot Account |
|
||||||
|
|-------|---------|-----------|-------------|
|
||||||
|
| Analyse | Issue opened / comment | `analyse` | claude-dev |
|
||||||
|
| Architect | Label: `ready-for-architecture` | `architect` | claude-dev |
|
||||||
|
| Develop | Label: `ready-for-development` | `develop` | claude-dev |
|
||||||
|
| Review | PR opened/updated | `review-code` | claude-review |
|
||||||
|
| Rework | Review: changes requested | `rework-pr` | claude-dev |
|
||||||
|
| Test | Review: approved | `test` | claude-review |
|
||||||
|
| Deploy | Label: `ready-for-deployment` | `devops` | claude-dev |
|
||||||
|
| Fix Bug | Issue opened with `bug` label | `fix-bug` | claude-dev |
|
||||||
|
|
||||||
|
## Infrastructure Setup
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
- Node.js 22+
|
- k3s cluster with Traefik ingress and cert-manager
|
||||||
- Coder running with the `cloudflare-worker` template (see `coder/`)
|
- Coder instance (e.g. `coder.samson.media`)
|
||||||
- Gitea with two bot accounts: `claude-dev` and `claude-review`
|
- Gitea instance (e.g. `gitea.samson.media`)
|
||||||
|
- Docker registry (e.g. `registry.samson.media`)
|
||||||
|
- Claude Code Max subscription (for OAuth token)
|
||||||
|
|
||||||
|
### Deploy the Orchestrator
|
||||||
|
|
||||||
|
1. **Build the workspace image** (pre-installed Node.js, Claude Code, Playwright deps):
|
||||||
|
```bash
|
||||||
|
docker build -f coder/workspace.Dockerfile -t registry.samson.media/coder-workspace:latest .
|
||||||
|
docker push registry.samson.media/coder-workspace:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
2. **Push the Coder template**:
|
||||||
|
```bash
|
||||||
|
coder templates push cloudflare-worker --directory coder/cloudflare-worker --yes
|
||||||
|
```
|
||||||
|
Note the template ID from the Coder dashboard.
|
||||||
|
|
||||||
|
3. **Create Gitea bot accounts**:
|
||||||
|
- `claude-dev` — used for most stages (analyse, develop, etc.)
|
||||||
|
- `claude-review` — used for review and test stages
|
||||||
|
- Generate API tokens for each
|
||||||
|
|
||||||
|
4. **Generate Claude Code OAuth token** (uses Max subscription instead of API credits):
|
||||||
|
```bash
|
||||||
|
claude setup-token
|
||||||
|
```
|
||||||
|
This opens a browser for auth and outputs a long-lived token (`sk-ant-oat01-...`).
|
||||||
|
|
||||||
|
5. **Create k8s secrets**:
|
||||||
|
```bash
|
||||||
|
kubectl create namespace sdlc-orchestrator
|
||||||
|
kubectl create secret generic orchestrator-secrets -n sdlc-orchestrator \
|
||||||
|
--from-literal=CODER_URL=https://coder.samson.media \
|
||||||
|
--from-literal=CODER_TOKEN=<coder-session-token> \
|
||||||
|
--from-literal=CODER_TEMPLATE_ID=<template-id> \
|
||||||
|
--from-literal=GITEA_DEV_TOKEN=<claude-dev-token> \
|
||||||
|
--from-literal=GITEA_REVIEW_TOKEN=<claude-review-token> \
|
||||||
|
--from-literal=CLAUDE_OAUTH_TOKEN=<oauth-token-from-step-4> \
|
||||||
|
--from-literal=CALLBACK_URL=https://sdlc.samson.media \
|
||||||
|
--from-literal=GITEA_URL=https://gitea.samson.media \
|
||||||
|
--from-literal=BOT_DEV_USERNAME=claude-dev \
|
||||||
|
--from-literal=BOT_REVIEW_USERNAME=claude-review
|
||||||
|
```
|
||||||
|
|
||||||
|
6. **Deploy**:
|
||||||
|
```bash
|
||||||
|
# Tag to trigger CI build
|
||||||
|
git tag -a v1.0.0 -m "Initial release"
|
||||||
|
git push origin main --tags
|
||||||
|
|
||||||
|
# Or deploy manually
|
||||||
|
docker build -t registry.samson.media/sdlc-orchestrator:latest .
|
||||||
|
docker push registry.samson.media/sdlc-orchestrator:latest
|
||||||
|
kubectl apply -f k8s/deployment.yaml
|
||||||
|
```
|
||||||
|
|
||||||
### Environment Variables
|
### Environment Variables
|
||||||
|
|
||||||
@@ -43,58 +188,58 @@ Plus a cron job (Monday 9 AM) for weekly maintenance.
|
|||||||
| `CODER_URL` | Yes | Coder API base URL |
|
| `CODER_URL` | Yes | Coder API base URL |
|
||||||
| `CODER_TOKEN` | Yes | Coder session token |
|
| `CODER_TOKEN` | Yes | Coder session token |
|
||||||
| `CODER_TEMPLATE_ID` | Yes | Coder workspace template ID |
|
| `CODER_TEMPLATE_ID` | Yes | Coder workspace template ID |
|
||||||
| `GITEA_DEV_TOKEN` | Yes | Gitea API token for `claude-dev` |
|
| `GITEA_DEV_TOKEN` | Yes | Gitea API token for claude-dev |
|
||||||
| `GITEA_REVIEW_TOKEN` | Yes | Gitea API token for `claude-review` |
|
| `GITEA_REVIEW_TOKEN` | Yes | Gitea API token for claude-review |
|
||||||
| `ANTHROPIC_API_KEY` | Yes | Anthropic API key for Claude Code |
|
| `CLAUDE_OAUTH_TOKEN` | Yes | Claude Code Max OAuth token |
|
||||||
|
| `CALLBACK_URL` | Yes | Public URL of this service (e.g. `https://sdlc.samson.media`) |
|
||||||
| `GITEA_URL` | No | Gitea base URL (default: `https://gitea.samson.media`) |
|
| `GITEA_URL` | No | Gitea base URL (default: `https://gitea.samson.media`) |
|
||||||
| `BOT_DEV_USERNAME` | No | Dev bot username (default: `claude-dev`) |
|
| `BOT_DEV_USERNAME` | No | Dev bot username (default: `claude-dev`) |
|
||||||
| `BOT_REVIEW_USERNAME` | No | Review bot username (default: `claude-review`) |
|
| `BOT_REVIEW_USERNAME` | No | Review bot username (default: `claude-review`) |
|
||||||
|
| `QUEUE_CONCURRENCY` | No | Max concurrent workspaces (default: 2) |
|
||||||
| `MAINTENANCE_REPOS` | No | Comma-separated `org/repo=clone_url` for weekly maintenance |
|
| `MAINTENANCE_REPOS` | No | Comma-separated `org/repo=clone_url` for weekly maintenance |
|
||||||
|
|
||||||
### Local Development
|
> **Important**: Do NOT set `ANTHROPIC_API_KEY` in the workspace — it takes priority over the OAuth token and will use pay-per-use credits instead of your Max subscription.
|
||||||
|
|
||||||
```bash
|
## Webhook Endpoints
|
||||||
npm install
|
|
||||||
cp k8s/secret.yaml.example .env # Edit with real values (use KEY=value format)
|
|
||||||
npm run dev
|
|
||||||
```
|
|
||||||
|
|
||||||
### Deploy to k3s
|
| Endpoint | Purpose |
|
||||||
|
|----------|---------|
|
||||||
|
| `GET /health` | Health check |
|
||||||
|
| `GET /queue` | Queue status (pending, running, active workspaces) |
|
||||||
|
| `POST /webhook/gitea-issue-triage` | Route new issues to analyse or fix-bug |
|
||||||
|
| `POST /webhook/gitea-issue-label` | Stage transitions via labels |
|
||||||
|
| `POST /webhook/gitea-issue-comment` | Re-trigger analyst on new/edited comments |
|
||||||
|
| `POST /webhook/gitea-pr-review` | Trigger code review on PR open/update |
|
||||||
|
| `POST /webhook/gitea-pr-review-rework` | Route review outcomes to rework or test |
|
||||||
|
| `POST /webhook/gitea-release` | Handle release workflow |
|
||||||
|
| `POST /webhook/task-complete/:name` | Callback from workspaces when done |
|
||||||
|
|
||||||
```bash
|
## How Workspaces Work
|
||||||
# Build and push image
|
|
||||||
docker build -t registry.samson.media/sdlc-orchestrator:latest .
|
|
||||||
docker push registry.samson.media/sdlc-orchestrator:latest
|
|
||||||
|
|
||||||
# Create secrets
|
Workspaces are **ephemeral** (emptyDir, no persistent storage):
|
||||||
cp k8s/secret.yaml.example k8s/secret.yaml
|
|
||||||
# Edit k8s/secret.yaml with real values
|
|
||||||
kubectl apply -f k8s/secret.yaml
|
|
||||||
|
|
||||||
# Deploy
|
1. Orchestrator creates workspace via Coder API with parameters (issue number, task type, tokens, callback URL)
|
||||||
kubectl apply -f k8s/deployment.yaml
|
2. Startup script clones the repo and checks out `develop`
|
||||||
```
|
3. For heavy stages (develop, test, review, rework, fix-bug, devops): installs deps, builds frontend, installs Playwright
|
||||||
|
4. For lightweight stages (analyse, architect, release, maintenance): skips build
|
||||||
|
5. Reads `.claude/commands/<task_type>.md`, strips YAML frontmatter, substitutes `$ARGUMENTS` with issue number
|
||||||
|
6. Runs `claude -p --dangerously-skip-permissions --verbose "<prompt>"`
|
||||||
|
7. On completion (success or failure via ERR/EXIT trap): POSTs to callback URL
|
||||||
|
8. Orchestrator receives callback, deletes workspace via Coder API
|
||||||
|
|
||||||
### Configure Gitea Webhooks
|
## Resilience
|
||||||
|
|
||||||
For each project, add these webhooks in **Settings → Webhooks**:
|
- **Deduplication**: Tasks keyed by `{taskType}-{repo}-{issue}`. Duplicate webhooks are dropped.
|
||||||
|
- **Startup reconciliation**: On boot, queries Coder for running workspaces and re-adopts them into the queue.
|
||||||
|
- **409 handling**: If workspace already exists — adopts if running, deletes and retries if stopped/failed.
|
||||||
|
- **Callback trap**: Startup script uses `trap` to always fire the callback, even on clone failure or other errors.
|
||||||
|
- **TTL safety net**: Coder template has 1-hour auto-stop as a backstop for missed callbacks.
|
||||||
|
|
||||||
| Event | URL |
|
## CI/CD
|
||||||
|-------|-----|
|
|
||||||
| Issues (opened) | `https://sdlc.samson.media/webhook/gitea-issue-triage` |
|
|
||||||
| Issues (labeled) | `https://sdlc.samson.media/webhook/gitea-issue-label` |
|
|
||||||
| Issue Comments (created) | `https://sdlc.samson.media/webhook/gitea-issue-comment` |
|
|
||||||
| Pull Request (opened, synchronized) | `https://sdlc.samson.media/webhook/gitea-pr-review` |
|
|
||||||
| Pull Request Review (submitted) | `https://sdlc.samson.media/webhook/gitea-pr-review-rework` |
|
|
||||||
| Issues (opened, labeled) — releases | `https://sdlc.samson.media/webhook/gitea-release` |
|
|
||||||
|
|
||||||
## Coder Template
|
| Workflow | Trigger | Output |
|
||||||
|
|----------|---------|--------|
|
||||||
|
| `publish.yml` | `v*` tags | `registry.samson.media/sdlc-orchestrator:<version>` + `:latest` |
|
||||||
|
| `publish-workspace.yml` | Changes to `coder/workspace.Dockerfile` on main | `registry.samson.media/coder-workspace:latest` |
|
||||||
|
|
||||||
The `coder/` directory contains the Terraform template for ephemeral Kubernetes workspaces. See `coder/README.md`.
|
Fleet GitOps (in `samson-media/devops` repo) watches `registry.samson.media/sdlc-orchestrator:latest` for deployment.
|
||||||
|
|
||||||
## Migrating from n8n
|
|
||||||
|
|
||||||
1. Deploy this service to k3s
|
|
||||||
2. Update Gitea webhooks to point to `sdlc.samson.media` instead of `n8n.samson.media`
|
|
||||||
3. Verify with a test issue
|
|
||||||
4. Decommission n8n
|
|
||||||
|
|||||||
+95
-124
@@ -76,27 +76,6 @@ data "coder_parameter" "memory" {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
data "coder_parameter" "disk_size" {
|
|
||||||
name = "disk_size"
|
|
||||||
display_name = "Disk Size (GB)"
|
|
||||||
description = "Persistent home directory size"
|
|
||||||
type = "number"
|
|
||||||
default = "10"
|
|
||||||
mutable = false
|
|
||||||
|
|
||||||
option {
|
|
||||||
name = "5 GB"
|
|
||||||
value = "5"
|
|
||||||
}
|
|
||||||
option {
|
|
||||||
name = "10 GB"
|
|
||||||
value = "10"
|
|
||||||
}
|
|
||||||
option {
|
|
||||||
name = "20 GB"
|
|
||||||
value = "20"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# ─── Automation Parameters ───────────────────────────────────────────────────
|
# ─── Automation Parameters ───────────────────────────────────────────────────
|
||||||
|
|
||||||
@@ -208,6 +187,24 @@ data "coder_parameter" "anthropic_api_key" {
|
|||||||
mutable = false
|
mutable = false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
data "coder_parameter" "callback_url" {
|
||||||
|
name = "callback_url"
|
||||||
|
display_name = "Task Complete Callback URL"
|
||||||
|
description = "URL to POST when task finishes (set by orchestrator)"
|
||||||
|
type = "string"
|
||||||
|
default = ""
|
||||||
|
mutable = false
|
||||||
|
}
|
||||||
|
|
||||||
|
data "coder_parameter" "claude_oauth_token" {
|
||||||
|
name = "claude_oauth_token"
|
||||||
|
display_name = "Claude OAuth Token"
|
||||||
|
description = "OAuth token for Claude Code Max subscription"
|
||||||
|
type = "string"
|
||||||
|
default = ""
|
||||||
|
mutable = false
|
||||||
|
}
|
||||||
|
|
||||||
data "coder_parameter" "deploy_env" {
|
data "coder_parameter" "deploy_env" {
|
||||||
name = "deploy_env"
|
name = "deploy_env"
|
||||||
display_name = "Deploy Environment"
|
display_name = "Deploy Environment"
|
||||||
@@ -366,33 +363,6 @@ resource "kubernetes_resource_quota_v1" "workspace" {
|
|||||||
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
|
"limits.cpu" = "${tonumber(data.coder_parameter.cpu.value) * 1000}m"
|
||||||
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
|
"requests.memory" = "${tonumber(data.coder_parameter.memory.value) / 2}Mi"
|
||||||
"limits.memory" = "${data.coder_parameter.memory.value}Mi"
|
"limits.memory" = "${data.coder_parameter.memory.value}Mi"
|
||||||
"requests.storage" = "${data.coder_parameter.disk_size.value}Gi"
|
|
||||||
"persistentvolumeclaims" = "1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# =============================================================================
|
|
||||||
# Storage
|
|
||||||
# =============================================================================
|
|
||||||
|
|
||||||
resource "kubernetes_persistent_volume_claim_v1" "home" {
|
|
||||||
metadata {
|
|
||||||
name = "home"
|
|
||||||
namespace = kubernetes_namespace_v1.workspace.metadata[0].name
|
|
||||||
labels = local.labels
|
|
||||||
}
|
|
||||||
|
|
||||||
wait_until_bound = false
|
|
||||||
|
|
||||||
spec {
|
|
||||||
access_modes = ["ReadWriteOnce"]
|
|
||||||
storage_class_name = "longhorn-backup"
|
|
||||||
|
|
||||||
resources {
|
|
||||||
requests = {
|
|
||||||
storage = "${data.coder_parameter.disk_size.value}Gi"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -433,8 +403,27 @@ resource "coder_agent" "main" {
|
|||||||
web_terminal = true
|
web_terminal = true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
metadata {
|
||||||
|
display_name = "Task Status"
|
||||||
|
key = "task_status"
|
||||||
|
script = <<-EOS
|
||||||
|
if [ -f ~/task-output.log ]; then
|
||||||
|
if grep -q "Task completed" ~/task-output.log 2>/dev/null; then
|
||||||
|
echo "✅ Complete"
|
||||||
|
else
|
||||||
|
echo "⏳ Running ($(wc -l < ~/task-output.log) lines)"
|
||||||
|
fi
|
||||||
|
elif [ -n "$TASK_TYPE" ]; then
|
||||||
|
echo "⏳ Starting..."
|
||||||
|
else
|
||||||
|
echo "Interactive"
|
||||||
|
fi
|
||||||
|
EOS
|
||||||
|
interval = 10
|
||||||
|
}
|
||||||
|
|
||||||
env = {
|
env = {
|
||||||
ANTHROPIC_API_KEY = data.coder_parameter.anthropic_api_key.value
|
CLAUDE_CODE_OAUTH_TOKEN = data.coder_parameter.claude_oauth_token.value
|
||||||
GITHUB_TOKEN = data.coder_external_auth.github.access_token
|
GITHUB_TOKEN = data.coder_external_auth.github.access_token
|
||||||
GITEA_TOKEN = data.coder_parameter.gitea_token.value
|
GITEA_TOKEN = data.coder_parameter.gitea_token.value
|
||||||
GITEA_ORG = data.coder_parameter.gitea_org.value
|
GITEA_ORG = data.coder_parameter.gitea_org.value
|
||||||
@@ -443,34 +432,24 @@ resource "coder_agent" "main" {
|
|||||||
ISSUE_NUMBER = data.coder_parameter.issue_number.value
|
ISSUE_NUMBER = data.coder_parameter.issue_number.value
|
||||||
REPO_CLONE_URL = data.coder_parameter.repo_clone_url.value
|
REPO_CLONE_URL = data.coder_parameter.repo_clone_url.value
|
||||||
DEPLOY_ENV = data.coder_parameter.deploy_env.value
|
DEPLOY_ENV = data.coder_parameter.deploy_env.value
|
||||||
|
CALLBACK_URL = data.coder_parameter.callback_url.value
|
||||||
}
|
}
|
||||||
|
|
||||||
startup_script = <<-EOT
|
startup_script = <<-EOT
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
|
# Always notify the orchestrator when done, even on failure
|
||||||
|
notify_complete() {
|
||||||
|
if [ -n "$CALLBACK_URL" ]; then
|
||||||
|
curl -s -X POST -H "Content-Type: application/json" \
|
||||||
|
-d "{\"status\":\"$1\"}" \
|
||||||
|
"$CALLBACK_URL" || echo "Callback failed (non-fatal)"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
trap 'notify_complete "failed"' ERR EXIT
|
||||||
|
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
# --- Install Node.js 22 ---
|
|
||||||
if ! command -v node &> /dev/null; then
|
|
||||||
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
|
|
||||||
sudo apt-get install -y nodejs
|
|
||||||
fi
|
|
||||||
|
|
||||||
# --- Install global tools ---
|
|
||||||
if ! command -v wrangler &> /dev/null; then
|
|
||||||
sudo npm install -g wrangler @anthropic-ai/claude-code
|
|
||||||
fi
|
|
||||||
|
|
||||||
# --- Install Playwright system dependencies ---
|
|
||||||
if ! dpkg -s libgbm1 &> /dev/null; then
|
|
||||||
sudo apt-get update
|
|
||||||
sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
|
||||||
libcups2t64 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
|
|
||||||
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2t64 libatspi2.0-0 \
|
|
||||||
|| sudo apt-get install -y libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
|
||||||
libcups2 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
|
|
||||||
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2 libatspi2.0-0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# --- Configure git ---
|
# --- Configure git ---
|
||||||
git config --global user.name "${data.coder_workspace_owner.me.full_name}"
|
git config --global user.name "${data.coder_workspace_owner.me.full_name}"
|
||||||
git config --global user.email "${data.coder_workspace_owner.me.email}"
|
git config --global user.email "${data.coder_workspace_owner.me.email}"
|
||||||
@@ -483,27 +462,39 @@ resource "coder_agent" "main" {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# --- Clone repository ---
|
# --- Clone repository ---
|
||||||
if [ -n "$REPO_CLONE_URL" ] && [ ! -d ~/project ]; then
|
if [ -n "$REPO_CLONE_URL" ]; then
|
||||||
git clone "$REPO_CLONE_URL" ~/project
|
git clone "$REPO_CLONE_URL" ~/project
|
||||||
cd ~/project
|
cd ~/project
|
||||||
|
|
||||||
# Switch to develop branch if it exists
|
# Switch to develop branch if it exists
|
||||||
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
|
git fetch origin develop 2>/dev/null && git checkout develop 2>/dev/null || true
|
||||||
|
|
||||||
# Install backend deps
|
# Lightweight stages only need the code, not a full build
|
||||||
npm ci --legacy-peer-deps
|
LIGHT_STAGES="analyse architect release maintenance"
|
||||||
|
if echo "$LIGHT_STAGES" | grep -qw "$TASK_TYPE"; then
|
||||||
|
echo "Lightweight stage ($TASK_TYPE) — skipping build"
|
||||||
|
else
|
||||||
|
# Install deps if package.json exists
|
||||||
|
if [ -f package.json ]; then
|
||||||
|
npm ci --legacy-peer-deps || npm ci
|
||||||
|
fi
|
||||||
|
|
||||||
# Install frontend deps
|
# Install frontend deps if present
|
||||||
|
if [ -f frontend/package.json ]; then
|
||||||
cd frontend && npm ci && cd ..
|
cd frontend && npm ci && cd ..
|
||||||
|
npm run build:frontend 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
# Build frontend (required — vitest fails without frontend/dist)
|
# Install Playwright if needed
|
||||||
npm run build:frontend
|
if grep -q "playwright" package.json 2>/dev/null; then
|
||||||
|
|
||||||
# Install Playwright Chromium
|
|
||||||
npx playwright install chromium
|
npx playwright install chromium
|
||||||
|
fi
|
||||||
|
|
||||||
# Apply local migrations
|
# Apply local migrations if script exists
|
||||||
npm run db:migrate:local
|
if npm run --silent db:migrate:local 2>/dev/null; then
|
||||||
|
echo "Local migrations applied"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# --- Automated task execution ---
|
# --- Automated task execution ---
|
||||||
@@ -515,11 +506,21 @@ resource "coder_agent" "main" {
|
|||||||
ARGS="$DEPLOY_ENV"
|
ARGS="$DEPLOY_ENV"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Run Claude Code in non-interactive mode
|
# Read the slash command .md file, strip YAML frontmatter, substitute $ARGUMENTS
|
||||||
claude --print --dangerously-skip-permissions "/project:$TASK_TYPE $ARGS" 2>&1 | tee ~/task-output.log
|
CMD_FILE=".claude/commands/$TASK_TYPE.md"
|
||||||
|
if [ ! -f "$CMD_FILE" ]; then
|
||||||
echo "Task completed. Output saved to ~/task-output.log"
|
echo "ERROR: Command file not found: $CMD_FILE"
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
PROMPT=$(sed '1{/^---$/!q}; 1,/^---$/d' "$CMD_FILE" | sed "s/\\\$ARGUMENTS/$ARGS/g")
|
||||||
|
|
||||||
|
# Run Claude Code in non-interactive mode with tool access
|
||||||
|
claude -p --dangerously-skip-permissions --verbose "$PROMPT"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Success — override the trap
|
||||||
|
trap - ERR EXIT
|
||||||
|
notify_complete "complete"
|
||||||
EOT
|
EOT
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -568,42 +569,9 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
name = kubernetes_secret_v1.registry.metadata[0].name
|
name = kubernetes_secret_v1.registry.metadata[0].name
|
||||||
}
|
}
|
||||||
|
|
||||||
init_container {
|
|
||||||
name = "fix-permissions"
|
|
||||||
image = "busybox:latest"
|
|
||||||
|
|
||||||
command = ["sh", "-c", <<-EOC
|
|
||||||
if [ ! -d /home/coder/project ]; then
|
|
||||||
mkdir -p /home/coder/project
|
|
||||||
fi
|
|
||||||
chown -R 1000:1000 /home/coder
|
|
||||||
EOC
|
|
||||||
]
|
|
||||||
|
|
||||||
volume_mount {
|
|
||||||
name = "home"
|
|
||||||
mount_path = "/home/coder"
|
|
||||||
}
|
|
||||||
|
|
||||||
resources {
|
|
||||||
requests = {
|
|
||||||
cpu = "5m"
|
|
||||||
memory = "8Mi"
|
|
||||||
}
|
|
||||||
limits = {
|
|
||||||
cpu = "50m"
|
|
||||||
memory = "32Mi"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
security_context {
|
|
||||||
run_as_user = 0
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
container {
|
container {
|
||||||
name = "coder-agent"
|
name = "coder-agent"
|
||||||
image = "codercom/enterprise-base:ubuntu-arm64"
|
image = "registry.samson.media/coder-workspace:latest"
|
||||||
|
|
||||||
command = ["sh", "-c", coder_agent.main.init_script]
|
command = ["sh", "-c", coder_agent.main.init_script]
|
||||||
|
|
||||||
@@ -613,8 +581,8 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
env {
|
env {
|
||||||
name = "ANTHROPIC_API_KEY"
|
name = "CLAUDE_CODE_OAUTH_TOKEN"
|
||||||
value = data.coder_parameter.anthropic_api_key.value
|
value = data.coder_parameter.claude_oauth_token.value
|
||||||
}
|
}
|
||||||
|
|
||||||
env {
|
env {
|
||||||
@@ -657,6 +625,11 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
value = data.coder_parameter.deploy_env.value
|
value = data.coder_parameter.deploy_env.value
|
||||||
}
|
}
|
||||||
|
|
||||||
|
env {
|
||||||
|
name = "CALLBACK_URL"
|
||||||
|
value = data.coder_parameter.callback_url.value
|
||||||
|
}
|
||||||
|
|
||||||
resources {
|
resources {
|
||||||
requests = {
|
requests = {
|
||||||
cpu = "${tonumber(data.coder_parameter.cpu.value) * 500}m"
|
cpu = "${tonumber(data.coder_parameter.cpu.value) * 500}m"
|
||||||
@@ -681,9 +654,7 @@ resource "kubernetes_deployment_v1" "workspace" {
|
|||||||
|
|
||||||
volume {
|
volume {
|
||||||
name = "home"
|
name = "home"
|
||||||
persistent_volume_claim {
|
empty_dir {}
|
||||||
claim_name = kubernetes_persistent_volume_claim_v1.home.metadata[0].name
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
FROM codercom/enterprise-base:latest
|
||||||
|
|
||||||
|
USER root
|
||||||
|
|
||||||
|
# Node.js 22
|
||||||
|
RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \
|
||||||
|
&& apt-get install -y nodejs \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Global npm tools
|
||||||
|
RUN npm install -g wrangler @anthropic-ai/claude-code
|
||||||
|
|
||||||
|
# Playwright system dependencies (both Ubuntu 24.04 and 22.04 package names)
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||||
|
libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
||||||
|
libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 \
|
||||||
|
libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libatspi2.0-0 \
|
||||||
|
jq netcat-openbsd \
|
||||||
|
&& (apt-get install -y libcups2t64 libasound2t64 2>/dev/null \
|
||||||
|
|| apt-get install -y libcups2 libasound2 2>/dev/null) \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
USER coder
|
||||||
+8
-2
@@ -11,14 +11,18 @@ export interface Config {
|
|||||||
giteaDevToken: string;
|
giteaDevToken: string;
|
||||||
/** Gitea API token for the review bot account */
|
/** Gitea API token for the review bot account */
|
||||||
giteaReviewToken: string;
|
giteaReviewToken: string;
|
||||||
/** Anthropic API key passed to Claude Code in workspaces */
|
/** Anthropic API key passed to Claude Code in workspaces (fallback) */
|
||||||
anthropicApiKey: string;
|
anthropicApiKey: string;
|
||||||
|
/** Claude Code OAuth token for Max subscription (preferred) */
|
||||||
|
claudeOauthToken: string;
|
||||||
/** Username of the dev bot (to filter out self-replies) */
|
/** Username of the dev bot (to filter out self-replies) */
|
||||||
botDevUsername: string;
|
botDevUsername: string;
|
||||||
/** Username of the review bot (to filter out self-replies) */
|
/** Username of the review bot (to filter out self-replies) */
|
||||||
botReviewUsername: string;
|
botReviewUsername: string;
|
||||||
/** Gitea base URL (e.g. https://gitea.samson.media) */
|
/** Gitea base URL (e.g. https://gitea.samson.media) */
|
||||||
giteaUrl: string;
|
giteaUrl: string;
|
||||||
|
/** Base URL for task-complete callbacks (e.g. https://sdlc.samson.media) */
|
||||||
|
callbackUrl: string;
|
||||||
/** Optional webhook secret for verifying Gitea signatures */
|
/** Optional webhook secret for verifying Gitea signatures */
|
||||||
webhookSecret?: string;
|
webhookSecret?: string;
|
||||||
}
|
}
|
||||||
@@ -39,10 +43,12 @@ export function loadConfig(): Config {
|
|||||||
coderTemplateId: required("CODER_TEMPLATE_ID"),
|
coderTemplateId: required("CODER_TEMPLATE_ID"),
|
||||||
giteaDevToken: required("GITEA_DEV_TOKEN"),
|
giteaDevToken: required("GITEA_DEV_TOKEN"),
|
||||||
giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
|
giteaReviewToken: required("GITEA_REVIEW_TOKEN"),
|
||||||
anthropicApiKey: required("ANTHROPIC_API_KEY"),
|
anthropicApiKey: process.env.ANTHROPIC_API_KEY || "",
|
||||||
|
claudeOauthToken: process.env.CLAUDE_OAUTH_TOKEN || "",
|
||||||
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
|
botDevUsername: process.env.BOT_DEV_USERNAME || "claude-dev",
|
||||||
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
|
botReviewUsername: process.env.BOT_REVIEW_USERNAME || "claude-review",
|
||||||
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
|
giteaUrl: process.env.GITEA_URL || "https://gitea.samson.media",
|
||||||
|
callbackUrl: required("CALLBACK_URL"),
|
||||||
webhookSecret: process.env.WEBHOOK_SECRET,
|
webhookSecret: process.env.WEBHOOK_SECRET,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -49,6 +49,17 @@ app.post("/webhook/gitea-pr-review", prReview(config, queue, giteaClient));
|
|||||||
app.post("/webhook/gitea-pr-review-rework", prRework(config, queue));
|
app.post("/webhook/gitea-pr-review-rework", prRework(config, queue));
|
||||||
app.post("/webhook/gitea-release", release(config, queue));
|
app.post("/webhook/gitea-release", release(config, queue));
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Task-complete callback — workspaces call this when done
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
app.post("/webhook/task-complete/:name", async (c) => {
|
||||||
|
const name = c.req.param("name");
|
||||||
|
console.log(`[callback] task-complete received for: ${name}`);
|
||||||
|
const found = await queue.taskComplete(name);
|
||||||
|
return c.json({ ok: true, found });
|
||||||
|
});
|
||||||
|
|
||||||
// ---------------------------------------------------------------------------
|
// ---------------------------------------------------------------------------
|
||||||
// Scheduled maintenance cron (Monday 9:00 AM)
|
// Scheduled maintenance cron (Monday 9:00 AM)
|
||||||
// ---------------------------------------------------------------------------
|
// ---------------------------------------------------------------------------
|
||||||
@@ -73,6 +84,11 @@ if (maintenanceRepos.length > 0) {
|
|||||||
// Start
|
// Start
|
||||||
// ---------------------------------------------------------------------------
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
// Reconcile queue state with Coder before accepting traffic
|
||||||
|
queue.reconcile().catch((err) =>
|
||||||
|
console.error("[startup] reconcile failed:", err),
|
||||||
|
);
|
||||||
|
|
||||||
serve({ fetch: app.fetch, port: config.port }, (info) => {
|
serve({ fetch: app.fetch, port: config.port }, (info) => {
|
||||||
console.log(`SDLC Orchestrator listening on :${info.port} (concurrency: ${concurrency})`);
|
console.log(`SDLC Orchestrator listening on :${info.port} (concurrency: ${concurrency})`);
|
||||||
});
|
});
|
||||||
|
|||||||
+107
-7
@@ -7,16 +7,24 @@ interface QueuedTask {
|
|||||||
comment?: { useReviewAccount: boolean; body: string };
|
comment?: { useReviewAccount: boolean; body: string };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface ActiveWorkspace {
|
||||||
|
workspaceId: string;
|
||||||
|
workspaceName: string;
|
||||||
|
startedAt: Date;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Task queue with deduplication and concurrency control.
|
* Task queue with deduplication, concurrency control, and workspace lifecycle.
|
||||||
*
|
*
|
||||||
* - Tasks are keyed by `{taskType}-{repo}-{issue}` for dedup
|
* - Tasks are keyed by `{taskType}-{repo}-{issue}` for dedup
|
||||||
* - If a task with the same key is already pending or running, new requests are dropped
|
* - If a task with the same key is pending, running, or has an active workspace, new requests are dropped
|
||||||
* - Concurrency is configurable (defaults to 2)
|
* - Concurrency is configurable (defaults to 2)
|
||||||
|
* - Tracks active workspaces and stops them on task-complete callback
|
||||||
*/
|
*/
|
||||||
export class TaskQueue {
|
export class TaskQueue {
|
||||||
private pending = new Map<string, QueuedTask>();
|
private pending = new Map<string, QueuedTask>();
|
||||||
private running = new Set<string>();
|
private running = new Set<string>();
|
||||||
|
private active = new Map<string, ActiveWorkspace>();
|
||||||
private concurrency: number;
|
private concurrency: number;
|
||||||
private coder: CoderClient;
|
private coder: CoderClient;
|
||||||
private gitea: GiteaClient;
|
private gitea: GiteaClient;
|
||||||
@@ -27,6 +35,34 @@ export class TaskQueue {
|
|||||||
this.concurrency = concurrency;
|
this.concurrency = concurrency;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reconcile in-memory state with Coder on startup.
|
||||||
|
* Re-adopts any running workspaces so callbacks and dedup work correctly.
|
||||||
|
*/
|
||||||
|
async reconcile(): Promise<void> {
|
||||||
|
const workspaces = await this.coder.listWorkspaces();
|
||||||
|
const runningStatuses = ["starting", "running", "started"];
|
||||||
|
|
||||||
|
for (const ws of workspaces) {
|
||||||
|
if (!runningStatuses.includes(ws.latestBuildStatus)) continue;
|
||||||
|
|
||||||
|
// Only adopt workspaces that match our naming pattern: {taskType}-{repo}-{issue}
|
||||||
|
const parts = ws.name.match(/^(.+?)-(.+?)-(\d+)$/);
|
||||||
|
if (!parts) continue;
|
||||||
|
|
||||||
|
this.active.set(ws.name, {
|
||||||
|
workspaceId: ws.id,
|
||||||
|
workspaceName: ws.name,
|
||||||
|
startedAt: new Date(), // approximate — we don't know the real start time
|
||||||
|
});
|
||||||
|
console.log(`[queue] reconciled: adopted workspace "${ws.name}" (status: ${ws.latestBuildStatus})`);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (this.active.size > 0) {
|
||||||
|
console.log(`[queue] reconcile complete: ${this.active.size} active workspace(s) adopted`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/** Build a dedup key for a task. */
|
/** Build a dedup key for a task. */
|
||||||
static key(task: TaskRequest): string {
|
static key(task: TaskRequest): string {
|
||||||
return `${task.taskType}-${task.giteaRepo}-${task.issueNumber}`;
|
return `${task.taskType}-${task.giteaRepo}-${task.issueNumber}`;
|
||||||
@@ -46,6 +82,11 @@ export class TaskQueue {
|
|||||||
): boolean {
|
): boolean {
|
||||||
const key = TaskQueue.key(task);
|
const key = TaskQueue.key(task);
|
||||||
|
|
||||||
|
if (this.active.has(key)) {
|
||||||
|
console.log(`[queue] dropped (active workspace): ${key}`);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
if (this.running.has(key)) {
|
if (this.running.has(key)) {
|
||||||
console.log(`[queue] dropped (running): ${key}`);
|
console.log(`[queue] dropped (running): ${key}`);
|
||||||
return false;
|
return false;
|
||||||
@@ -58,16 +99,54 @@ export class TaskQueue {
|
|||||||
|
|
||||||
this.pending.set(key, { task, comment });
|
this.pending.set(key, { task, comment });
|
||||||
console.log(
|
console.log(
|
||||||
`[queue] enqueued: ${key} (pending: ${this.pending.size}, running: ${this.running.size}/${this.concurrency})`,
|
`[queue] enqueued: ${key} (pending: ${this.pending.size}, running: ${this.running.size}/${this.concurrency}, active: ${this.active.size})`,
|
||||||
);
|
);
|
||||||
|
|
||||||
this.drain();
|
this.drain();
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Handle task-complete callback from a workspace.
|
||||||
|
* Stops the workspace via Coder API and removes it from active tracking.
|
||||||
|
*/
|
||||||
|
async taskComplete(workspaceName: string): Promise<boolean> {
|
||||||
|
const entry = this.active.get(workspaceName);
|
||||||
|
if (!entry) {
|
||||||
|
console.log(`[queue] task-complete for unknown workspace: ${workspaceName}`);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
const elapsed = Math.round(
|
||||||
|
(Date.now() - entry.startedAt.getTime()) / 1000,
|
||||||
|
);
|
||||||
|
console.log(
|
||||||
|
`[queue] task complete: ${workspaceName} (ran for ${elapsed}s) — stopping workspace`,
|
||||||
|
);
|
||||||
|
|
||||||
|
this.active.delete(workspaceName);
|
||||||
|
|
||||||
|
try {
|
||||||
|
await this.coder.stopWorkspace(entry.workspaceId);
|
||||||
|
console.log(`[queue] workspace stopped: ${workspaceName} — waiting for shutdown`);
|
||||||
|
// Wait for the workspace to fully stop before deleting
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 10_000));
|
||||||
|
await this.coder.deleteWorkspace(entry.workspaceId);
|
||||||
|
console.log(`[queue] workspace deleted: ${workspaceName}`);
|
||||||
|
} catch (err) {
|
||||||
|
console.error(`[queue] failed to clean up workspace ${workspaceName}:`, err);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Drain in case pending tasks were waiting for capacity
|
||||||
|
this.drain();
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
/** Process queued tasks up to the concurrency limit. */
|
/** Process queued tasks up to the concurrency limit. */
|
||||||
private drain(): void {
|
private drain(): void {
|
||||||
while (this.running.size < this.concurrency && this.pending.size > 0) {
|
const totalInFlight = this.running.size + this.active.size;
|
||||||
|
while (totalInFlight + this.pending.size > 0 && this.running.size + this.active.size < this.concurrency && this.pending.size > 0) {
|
||||||
const [key, entry] = this.pending.entries().next().value!;
|
const [key, entry] = this.pending.entries().next().value!;
|
||||||
this.pending.delete(key);
|
this.pending.delete(key);
|
||||||
this.running.add(key);
|
this.running.add(key);
|
||||||
@@ -81,7 +160,14 @@ export class TaskQueue {
|
|||||||
try {
|
try {
|
||||||
console.log(`[queue] processing: ${key}`);
|
console.log(`[queue] processing: ${key}`);
|
||||||
const workspace = await this.coder.createWorkspace(task);
|
const workspace = await this.coder.createWorkspace(task);
|
||||||
console.log(`[queue] workspace created: ${workspace.name}`);
|
console.log(`[queue] workspace created: ${workspace.name} (id: ${workspace.id})`);
|
||||||
|
|
||||||
|
// Move from running → active (workspace is now alive, waiting for callback)
|
||||||
|
this.active.set(key, {
|
||||||
|
workspaceId: workspace.id,
|
||||||
|
workspaceName: workspace.name,
|
||||||
|
startedAt: new Date(),
|
||||||
|
});
|
||||||
|
|
||||||
if (comment) {
|
if (comment) {
|
||||||
await this.gitea.commentOnIssue(
|
await this.gitea.commentOnIssue(
|
||||||
@@ -96,15 +182,29 @@ export class TaskQueue {
|
|||||||
console.error(`[queue] failed: ${key}`, err);
|
console.error(`[queue] failed: ${key}`, err);
|
||||||
} finally {
|
} finally {
|
||||||
this.running.delete(key);
|
this.running.delete(key);
|
||||||
this.drain();
|
// Don't drain here — active workspaces count toward concurrency
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Current queue status for health/debug endpoints. */
|
/** Current queue status for health/debug endpoints. */
|
||||||
status(): { pending: string[]; running: string[]; concurrency: number } {
|
status(): {
|
||||||
|
pending: string[];
|
||||||
|
running: string[];
|
||||||
|
active: Record<string, { workspaceId: string; elapsed: number }>;
|
||||||
|
concurrency: number;
|
||||||
|
} {
|
||||||
|
const activeMap: Record<string, { workspaceId: string; elapsed: number }> = {};
|
||||||
|
for (const [key, entry] of this.active) {
|
||||||
|
activeMap[key] = {
|
||||||
|
workspaceId: entry.workspaceId,
|
||||||
|
elapsed: Math.round((Date.now() - entry.startedAt.getTime()) / 1000),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
pending: [...this.pending.keys()],
|
pending: [...this.pending.keys()],
|
||||||
running: [...this.running.keys()],
|
running: [...this.running.keys()],
|
||||||
|
active: activeMap,
|
||||||
concurrency: this.concurrency,
|
concurrency: this.concurrency,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,12 +7,16 @@ export class CoderClient {
|
|||||||
private token: string;
|
private token: string;
|
||||||
private templateId: string;
|
private templateId: string;
|
||||||
private anthropicApiKey: string;
|
private anthropicApiKey: string;
|
||||||
|
private claudeOauthToken: string;
|
||||||
|
private callbackUrl: string;
|
||||||
|
|
||||||
constructor(config: Config) {
|
constructor(config: Config) {
|
||||||
this.baseUrl = config.coderUrl.replace(/\/$/, "");
|
this.baseUrl = config.coderUrl.replace(/\/$/, "");
|
||||||
this.token = config.coderToken;
|
this.token = config.coderToken;
|
||||||
this.templateId = config.coderTemplateId;
|
this.templateId = config.coderTemplateId;
|
||||||
this.anthropicApiKey = config.anthropicApiKey;
|
this.anthropicApiKey = config.anthropicApiKey;
|
||||||
|
this.claudeOauthToken = config.claudeOauthToken;
|
||||||
|
this.callbackUrl = config.callbackUrl;
|
||||||
}
|
}
|
||||||
|
|
||||||
async createWorkspace(task: TaskRequest): Promise<{ id: string; name: string }> {
|
async createWorkspace(task: TaskRequest): Promise<{ id: string; name: string }> {
|
||||||
@@ -29,6 +33,8 @@ export class CoderClient {
|
|||||||
{ name: "gitea_org", value: task.giteaOrg },
|
{ name: "gitea_org", value: task.giteaOrg },
|
||||||
{ name: "gitea_repo", value: task.giteaRepo },
|
{ name: "gitea_repo", value: task.giteaRepo },
|
||||||
{ name: "anthropic_api_key", value: this.anthropicApiKey },
|
{ name: "anthropic_api_key", value: this.anthropicApiKey },
|
||||||
|
{ name: "claude_oauth_token", value: this.claudeOauthToken },
|
||||||
|
{ name: "callback_url", value: `${this.callbackUrl}/webhook/task-complete/${name}` },
|
||||||
...(task.deployEnv
|
...(task.deployEnv
|
||||||
? [{ name: "deploy_env", value: task.deployEnv }]
|
? [{ name: "deploy_env", value: task.deployEnv }]
|
||||||
: []),
|
: []),
|
||||||
@@ -47,6 +53,32 @@ export class CoderClient {
|
|||||||
},
|
},
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Handle 409 conflict — workspace with this name already exists.
|
||||||
|
// This can happen if the orchestrator restarted and lost in-memory state.
|
||||||
|
if (res.status === 409) {
|
||||||
|
const existing = await this.findWorkspaceByName(name);
|
||||||
|
if (!existing) {
|
||||||
|
throw new Error(`Coder 409 but workspace "${name}" not found — possible race condition`);
|
||||||
|
}
|
||||||
|
|
||||||
|
const stoppedStatuses = ["stopped", "failed", "canceled", "deleted"];
|
||||||
|
if (stoppedStatuses.includes(existing.latestBuildStatus)) {
|
||||||
|
// Workspace is done — safe to replace
|
||||||
|
console.log(
|
||||||
|
`[coder] workspace "${name}" exists but ${existing.latestBuildStatus} — deleting and retrying`,
|
||||||
|
);
|
||||||
|
await this.deleteWorkspace(existing.id);
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 5000));
|
||||||
|
return this.createWorkspace(task);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Workspace is still running — adopt it, don't kill it
|
||||||
|
console.log(
|
||||||
|
`[coder] workspace "${name}" is still ${existing.latestBuildStatus} — adopting existing workspace`,
|
||||||
|
);
|
||||||
|
return { id: existing.id, name: existing.name };
|
||||||
|
}
|
||||||
|
|
||||||
if (!res.ok) {
|
if (!res.ok) {
|
||||||
const text = await res.text();
|
const text = await res.text();
|
||||||
throw new Error(`Coder API error ${res.status}: ${text}`);
|
throw new Error(`Coder API error ${res.status}: ${text}`);
|
||||||
@@ -55,4 +87,105 @@ export class CoderClient {
|
|||||||
const data = (await res.json()) as { id: string; name: string };
|
const data = (await res.json()) as { id: string; name: string };
|
||||||
return { id: data.id, name: data.name };
|
return { id: data.id, name: data.name };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async stopWorkspace(workspaceId: string): Promise<void> {
|
||||||
|
const res = await fetch(
|
||||||
|
`${this.baseUrl}/api/v2/workspaces/${workspaceId}/builds`,
|
||||||
|
{
|
||||||
|
method: "POST",
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
"Coder-Session-Token": this.token,
|
||||||
|
},
|
||||||
|
body: JSON.stringify({ transition: "stop" }),
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!res.ok) {
|
||||||
|
const text = await res.text();
|
||||||
|
throw new Error(`Coder stop error ${res.status}: ${text}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async deleteWorkspace(workspaceId: string): Promise<void> {
|
||||||
|
const res = await fetch(
|
||||||
|
`${this.baseUrl}/api/v2/workspaces/${workspaceId}`,
|
||||||
|
{
|
||||||
|
method: "DELETE",
|
||||||
|
headers: {
|
||||||
|
"Coder-Session-Token": this.token,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!res.ok) {
|
||||||
|
const text = await res.text();
|
||||||
|
throw new Error(`Coder delete error ${res.status}: ${text}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* List all workspaces owned by the authenticated user.
|
||||||
|
* Used at startup to reconcile in-memory state with Coder.
|
||||||
|
*/
|
||||||
|
async listWorkspaces(): Promise<
|
||||||
|
Array<{ id: string; name: string; latestBuildStatus: string }>
|
||||||
|
> {
|
||||||
|
const res = await fetch(
|
||||||
|
`${this.baseUrl}/api/v2/workspaces?q=owner:me`,
|
||||||
|
{
|
||||||
|
headers: { "Coder-Session-Token": this.token },
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!res.ok) return [];
|
||||||
|
|
||||||
|
const data = (await res.json()) as {
|
||||||
|
workspaces: Array<{
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
latest_build: { status: string };
|
||||||
|
}>;
|
||||||
|
};
|
||||||
|
return (data.workspaces ?? []).map((w) => ({
|
||||||
|
id: w.id,
|
||||||
|
name: w.name,
|
||||||
|
latestBuildStatus: w.latest_build?.status ?? "unknown",
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
async findWorkspaceByName(name: string): Promise<{
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
createdAt: string;
|
||||||
|
latestBuildStatus: string;
|
||||||
|
} | null> {
|
||||||
|
const res = await fetch(
|
||||||
|
`${this.baseUrl}/api/v2/workspaces?q=name:${encodeURIComponent(name)}`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
"Coder-Session-Token": this.token,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!res.ok) return null;
|
||||||
|
|
||||||
|
const data = (await res.json()) as {
|
||||||
|
workspaces: Array<{
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
created_at: string;
|
||||||
|
latest_build: { status: string };
|
||||||
|
}>;
|
||||||
|
};
|
||||||
|
const match = data.workspaces?.find((w) => w.name === name);
|
||||||
|
if (!match) return null;
|
||||||
|
return {
|
||||||
|
id: match.id,
|
||||||
|
name: match.name,
|
||||||
|
createdAt: match.created_at,
|
||||||
|
latestBuildStatus: match.latest_build?.status ?? "unknown",
|
||||||
|
};
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user