mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
fix(ci): remove npm propagation from cloud readiness (#13456)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work.
> - Paperclip Cloud needs a verified image and matching database
migrator before it can deploy a merge.
> - New npm package versions can take minutes to become downloadable
after the package build finishes.
> - The direct producer now publishes signed archives and a complete
dependency lockfile for each master commit.
> - This pull request makes readiness verify those artifacts and removes
the duplicate automatic npm migrator run.
> - Deployment still requires all source checks, exact image identity,
migration compatibility, and pinned dependencies.
## Linked Issues or Issue Description
Refs: #13455, #13454, #13192
**What existing behavior does this improve?**
The time from a master merge to the `Cloud deployable v1` signal.
**Current behavior**
Readiness polls npm metadata for the new DB and shared versions. An
automatic dispatcher also starts a separate npm-only migrator workflow.
A measured source built its packages at 06:22:41 UTC on 2026-09-15, but
both npm archives were not downloadable until 06:31:56 UTC.
**Proposed behavior**
Wait for the successful exact-source direct producer, verify its signed
manifest and all pinned downloads, and publish readiness only after the
existing source and image jobs pass. Keep manual npm migrators and
branch previews available.
**Reason and benefit**
Remove new-version npm propagation from merge-to-deployable time. The
gain depends on whether image building or source verification finishes
later; it is not a fixed subtraction from every run.
## What Changed
- Require a successful producer from the canonical repository, exact
commit, master ref, expected workflow, and approved event.
- Verify the manifest's GitHub attestation with the hosted GitHub CLI.
Enforce the exact source SHA, master workflow identity, and hosted
runner.
- Download and validate both archives and the complete dependency
lockfile after publication succeeds. Reject invalid signatures,
inaccessible objects, corrupt bytes, and source mismatches.
- Remove automatic npm-only migrator dispatch. Retain manual release and
branch-preview publication.
- Document the cloud feature-switch prerequisite and coordinated
rollback.
## Verification
- `node --test .github/scripts/tests/*.test.mjs`: 405 pass.
- Focused readiness, routing, preview, and artifact tests: 249 pass.
- Workflow lint and `git diff --check`: pass.
- `pnpm test:release-registry`: 139 pass after installing this
worktree's dependencies.
- All latest-head GitHub CI checks passed. Greptile is 5/5 with no
unresolved comments.
- Application source is unchanged. Common-source local typecheck and
build passed. The full local application suite has the documented macOS
read-only-directory rename limitation from #13454 (13 failures in two
unchanged suites); Linux CI is the final application gate.
- Live readiness verification of master
da77a0c28c passed in 6.52 seconds,
including the real GitHub CLI signature policy and all artifact
downloads.
- Cloud consumer resolution with the certificate encoding fix passed in
5.45 seconds with zero npm metadata requests or npm processes. The
consumer is deployed and enabled in staging and production; their live
resolution APIs passed in 2.34 and 2.38 seconds. Both report the
expected fixed harness commit. A fresh tenant deployment follows this
cutover merge.
## Risks
- `Cloud deployable v1` no longer promises npm preview availability.
Enable the cloud direct-artifact consumer in staging and production
before merging this change.
- Artifact storage and GitHub attestations become required services for
new direct releases. Missing or invalid evidence fails explicitly.
- Restore the old npm dispatcher and readiness gate together before
disabling the consumer switch. Retain artifacts referenced by existing
releases.
- This change does not expand AWS runner access. The producer and
readiness bookkeeping use GitHub-hosted runners. Existing PR allowlists
and source verification gates remain enforced.
## Model Used
OpenAI GPT-6 through Codex, with reasoning, repository tools, and code
execution. The exact serving model ID and context window are not exposed
by this environment.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused checks; full
application host limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
1 parent
9ed55f6931
commit
4cc387f907
9 files changed
+211
-122
No files matched your search
@@ -9,11 +9,12 @@ The `Cloud readiness` workflow starts for every master push. Its versioned
|
||||
image, including Sentry resolution and orphan reaping, then publishes the
|
||||
full-SHA cloud tag. Cloud readiness owns the master trigger so there is one
|
||||
cloud build per push. Release tags and manual Docker runs retain their callers.
|
||||
- The full-SHA image and both exact-source npm packages are visible. The
|
||||
packages are `@paperclipai/shared` and `@paperclipai/db` at
|
||||
`0.0.0-preview.g<FULL_SHA>`, published through the migrator-only release lane.
|
||||
Registry metadata must match the full commit, and the database package must
|
||||
pin the matching shared package.
|
||||
- The full-SHA image is visible and the exact-source `Cloud migrator artifacts`
|
||||
workflow has succeeded. Readiness verifies the manifest's GitHub attestation
|
||||
against the full SHA, canonical master workflow, and GitHub-hosted runner,
|
||||
then downloads and validates both package archives and the prepared dependency
|
||||
lockfile. The database package pins the matching shared package. New-version
|
||||
npm metadata and tarball propagation are outside this path.
|
||||
|
||||
The Cloud workflow builds the image with `USER_UID=1001` and `USER_GID=1001`,
|
||||
matching the managed runtime. This avoids a startup user remap, which can walk
|
||||
@@ -56,16 +57,19 @@ before that bot's PR merges. Verification must install and test that commit
|
||||
without waiting for another merge. The generated lockfile stays in the job's
|
||||
workspace; these checks do not commit it back to the repository.
|
||||
|
||||
The artifact wait runs for up to 30 minutes and reports what is missing. Only
|
||||
an HTTP 404 means publication is pending; authorization errors, upstream outages,
|
||||
and identity mismatches fail the job. A failed, cancelled, or skipped prerequisite
|
||||
The artifact wait runs for up to 30 minutes and reports what is missing. A
|
||||
missing image or an exact-source publisher with no successful run yet means publication
|
||||
is pending. An earlier successful push or manual run remains valid after a failed
|
||||
retry because publication is immutable. If all matching runs failed, readiness
|
||||
fails. An invalid signature, inaccessible or corrupt
|
||||
bundle, authorization error, or identity mismatch fails the job. A failed, cancelled, or skipped prerequisite
|
||||
cannot produce a successful readiness job. Retry the failed publication or build,
|
||||
then rerun the failed readiness workflow jobs to check the same commit again.
|
||||
|
||||
## Consumer contract
|
||||
|
||||
`Cloud deployable v1` is a source-and-artifact readiness signal. A deployment
|
||||
consumer must still resolve and pin the image digest and npm integrity/lockfile,
|
||||
consumer must still resolve and pin the image digest and migrator integrity/lockfile,
|
||||
validate migration contents and compatibility, and apply its target health gates.
|
||||
The check creates no release record and deploys no instance. A full-SHA tag by
|
||||
itself, or a successful migrator dispatch, is not this readiness signal.
|
||||
@@ -78,9 +82,16 @@ Do not trust a similarly named check from another workflow or a manual branch ru
|
||||
Order candidates by master ancestry, not job completion time: an older commit
|
||||
finishing late must not roll a fleet backward. Fail closed on API errors.
|
||||
|
||||
Existing npm canary discovery is unchanged by this producer workflow. Consumers
|
||||
can adopt the versioned signal separately after the workflow has landed and
|
||||
successfully verified a real master commit.
|
||||
Cloud consumers must enable `CLOUD_HARNESS_DIRECT_MIGRATOR_ARTIFACTS` before
|
||||
this gate is adopted: readiness no longer promises preview npm availability.
|
||||
The automatic npm-only migrator dispatcher has been removed. Manual
|
||||
`release.yml` runs with `channel=cloud-migrator`, branch previews, and stable
|
||||
releases retain their npm publisher for legacy consumers and rollback.
|
||||
|
||||
For rollback, restore the npm dispatcher and gate together before disabling the
|
||||
cloud direct-artifact switch. Already-created releases retain their immutable
|
||||
archive URLs and lockfiles; keep those objects available. The master producer
|
||||
can be retried independently without republishing or overwriting a valid bundle.
|
||||
|
||||
## Timing and rollout
|
||||
|
||||
@@ -151,9 +162,10 @@ its trusted-publisher identity.
|
||||
|
||||
Before enabling the switch, deploy the separate Fleet and restrict its GitHub
|
||||
runner group to repository ID `1170821064` and these workflows at
|
||||
`refs/heads/master`: `cloud-readiness.yml`, `cloud-artifacts.yml`,
|
||||
`refs/heads/master`: `cloud-readiness.yml`,
|
||||
`release-verify.yml`, `runner-chaos-evals.yml`, and `release.yml`. Do not authorize
|
||||
PR-controlled workflow versions. PR placement retains its independent pinned
|
||||
PR-controlled workflow versions. The direct migrator producer always uses
|
||||
GitHub-hosted runners and needs no AWS runner-group authorization. PR placement retains its independent pinned
|
||||
workflow and six-account author/actor allowlist.
|
||||
|
||||
Disable the switch and rerun the whole workflow to restore GitHub-hosted
|
||||
|
||||
@@ -170,10 +170,12 @@ The deploy policies are checked in under `.github/cloud-migrator-deploy/`:
|
||||
|
||||
There is no lifecycle expiry on this prefix. Keep referenced artifacts for
|
||||
rollback; deleting them can prevent a fresh migrator install for an old release.
|
||||
This producer rollout is additive. npm preview publication and the current
|
||||
cloud readiness gate remain active until the cloud consumer supports the new
|
||||
manifest. A later cutover must preserve source verification, image identity,
|
||||
migration compatibility, and the cloud runner's integrity checks.
|
||||
Cloud readiness consumes the signed direct bundle after its exact-source
|
||||
publisher succeeds. It retains source verification, image identity, and the
|
||||
cloud runner's integrity and migration compatibility checks. The cloud direct
|
||||
artifact switch must be enabled before adopting this gate. Automatic npm-only
|
||||
migrator dispatch is removed; explicit npm previews and manual migrator runs
|
||||
remain available. See `doc/cloud-build-readiness.md` for coordinated rollback.
|
||||
|
||||
Local verification:
|
||||
|
||||
|
||||
Reference in new issue
Block a user