Commit Graph
12 Commits
Author SHA1 Message Date
can1357 2623bc3be5 refactor: standardized repro_record output and restricted local stage port binding
- Changed repro_record to return only "recorded" after saving a transcript instead of including its workspace path.
- Removed the requirement to reference a transcript path from the repro prompt wording.
- Updated docker-compose to map the stage service to 127.0.0.1:6543 and aligned the repro_record test to assert the exact new return value.
2026-05-15 23:25:10 +02:00
can1357 c0757e9ebc config(config): added question auto-close environment defaults to docker-compose
- Added three question auto-close related environment variables to the docker-compose service configuration.
- Configured their defaults to enable auto-close with a 4-hour threshold and 60-second scan interval.
2026-05-15 09:43:12 +02:00
can1357 606a082c7c docs: documented operator-first bot behavior and bun run checks in README
- Rewrote `README.md` with a concise operator-first walkthrough of bot behavior and setup flow.
- Replaced large architecture and security narratives with a compact summary of proxy trust boundaries and run modes.
- Updated CLI and operational examples in `README.md` to match current `bun run`-based workflows and checks.
2026-05-15 05:17:40 +02:00
can1357 d7067af878 feat(cross-cutting): added Bun/Vite dashboard with /static integration
- Added a Bun/Vite dashboard frontend with App views for status, issues, events, logs, triggers, and working queue.
- Added dashboard backend support by mounting `/static`, serving package assets, and injecting replay config into `index.html`.
- Added client API/state modules for polling, retry, cancel, browse filtering, and config validation in the SPA.
- Replaced `justfile` task orchestration with bun scripts, updating README/AGENTS and command docs.
- Added Docker, Bun config, and ignorefiles to build web assets, copy them into runtime static data, and prune artifacts.
- Added webhook ping helper plus dashboard test fixtures for bootstrap HTML and replay-token substitution.
2026-05-15 04:58:28 +02:00
can1357 ef9962a920 build(build): configured build pipeline to use pi-artifacts images for Pi packaging
- Removed `bin/stage-pi.sh` and migrated build orchestration to the new `pi-artifacts` workflow.
- Added `PI_ARTIFACTS_IMAGE`/`PI_IMAGE` handling and rewired `just build` and `rebuild` around `pi-artifacts`.
- Replaced Dockerfile builder stages with a `pi-artifacts` stage and copied node/wheel artifacts from it.
- Updated compose and documentation to pass artifact image args and explain runtime invalidation/rebuild guidance.
2026-05-15 04:39:42 +02:00
can1357 4e876899e9 feat: added hard-timeout worker enforcement with per-slot tmpdir cleanup
- Added `ROBOMP_TASK_TIMEOUT_HARD_GRACE_SECONDS` and `Settings.task_timeout_hard_grace_seconds` with a 60s default.
- Updated triage/replay to await terminal completion, default `--wait-timeout` from timeout+grace, and return timed_out JSON.
- Added hard-timeout worker handling with per-slot TMPDIRs and RPC stop on expiry to avoid stuck runs.
- Added SlotPool `slot_uids` exposure and queue/sandbox cleanup to reap configured or stale slot processes before release.
- Added tests for new timeout parsing, manual triage waits, queue slot reaping, sandbox process cleanup, and worker hard-timeout behavior.
2026-05-15 03:45:49 +02:00
can1357 8e52599b8c feat: implemented robomp sandbox retry-slot metadata sharing
- Added bare_mention_reply() persona text and used it for bare mentions with trace metadata logging.
- Added a `robomp_data` named volume in compose and migrated /data mounts from host `./data` paths.
- Added slot-permission helpers in sandbox setup to share git metadata across retries on Linux roots.
- Added tests validating metadata group-permissions and workspace refresh idempotence for retry slot reuse.
2026-05-15 02:53:35 +02:00
can1357 aa3c7f89c8 chore(deployment): organized compose mounts for per-slot isolation
- Relocated compose mounts to /srv/agent-home-stage and copied staged ~/.agent/.omp config into /srv/agent-home at startup.
- Configured omp-* slot users in entrypoint.sh with dedicated group IDs for per-slot runtime isolation.
- Initialized /srv/agent-home with root-owned perms and tightened /data/robomp.sqlite ownership/mode handling.
2026-05-15 02:33:11 +02:00
can1357 bd9862af9e chore(container): organized role-based startup bypass and /srv/agent-home mounts
- Aligned agent volume mounts to `/srv/agent-home/.agent` and `/srv/agent-home/.omp/agent` paths.
- Added role-aware startup logic so proxy containers bypass `PI_ROOT` validation and run the target command.
- Created `omp` worker users and startup ownership/permissions for `/data` and `/srv/agent-home` directories.
- Hardened existing sqlite artifacts by setting `root:root` ownership and `0600` mode when present.
2026-05-15 02:32:10 +02:00
can1357 bbe6959b49 feat(deployment): added gh-proxy compose service and role checks
- Added ROBOMP_GH_PROXY_HMAC_KEY/URL wiring so orchestrator calls gh-proxy over signed API paths.
- Added a gh-proxy service and internal robomp_internal network in compose, isolating token-bearing calls.
- Changed robomp container startup to explicit env allowlisting and to fail when GITHUB_TOKEN is present.
- Added proxy-role detection in entrypoint.sh to skip PI_ROOT checks when running robomp.proxy.
- Added docs and operator workflow updates documenting the two-container trust boundary and recovery flow.
2026-05-15 01:56:57 +02:00
can1357 88f5369d74 config: configured container mounts for AGENTS context and rule files
- Mounted the host's AGENTS.md context file into /root/.agent/AGENTS.md with read-only access.
- Mounted the host's .agent/rules directory into /root/.agent/rules for in-container rule discovery.
2026-05-15 00:19:34 +02:00
can1357 0d55878be0 Initial commit 2026-05-14 23:50:50 +02:00