44e2b5a897
test / integration-docker (pull_request) Successful in 13s
tracker-policy-pr / check-pr (pull_request) Successful in 14s
test / unit (pull_request) Successful in 42s
lint / lint (push) Failing after 54s
test / integration-firecracker (pull_request) Successful in 3m17s
test / coverage (pull_request) Successful in 17s
test / publish-infra (pull_request) Has been skipped
Give each service its own store package + manager, and cut the supervise module
along the control/data-plane boundary so nothing in the shared layer reaches up
into the orchestrator.
Stores, by owner:
- bot_bottle/store/ keeps only the shared base (DbStore, migrations) and the
concrete stores that aren't service-owned (audit_store, config_store).
- bot_bottle/orchestrator/store/ now houses the orchestrator-owned stores —
queue_store (supervise queue), secret_store, config_store — plus a new
orchestrator store_manager that migrates them (composing audit/config
downward from the base). The old shared store_manager is gone.
Supervise plane, by tier:
- bot_bottle/supervisor/ (NEUTRAL, importable by every tier including the
gateway): types.py (the Proposal/Response/AuditEntry wire types + the tool/
status/poll constants + the shared daemon constants moved out of
supervise.py) and plan.py (SupervisePlan, a pure DTO).
- bot_bottle/orchestrator/supervisor/ (orchestrator-only): queue.py (the
queue/audit I/O wrappers + render_diff + sha256_hex) and supervise.py (the
Supervise lifecycle that stages the DB via the store manager). Its __init__
re-exports the neutral vocabulary so orchestrator-side callers import from
one place.
The gateway now imports only bot_bottle.supervisor.types (never
bot_bottle.supervise), so the data plane holds no code dependency on the
orchestrator — it reaches the queue over the control-plane RPC. This removes
the circular import that moving queue_store under orchestrator introduced
(supervise -> orchestrator -> service -> supervise).
supervise_types.py -> supervisor/types.py; supervise.py deleted (split). Full
unit suite green (2251).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
70 lines
2.5 KiB
Python
70 lines
2.5 KiB
Python
"""Shared helpers for the consolidated launch sequence (PRD 0070).
|
|
|
|
Logic that was duplicated across the docker, macos_container, and
|
|
firecracker consolidated_launch modules — extracted so each backend
|
|
imports it rather than re-implementing it.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import dataclasses
|
|
|
|
from ..egress import EgressPlan
|
|
from ..git_gate import GitGatePlan
|
|
from ..orchestrator.client import OrchestratorClient, RegisteredBottle
|
|
from ..orchestrator.registration import registration_inputs
|
|
from ..orchestrator.store.secret_store import new_env_var_secret
|
|
from .docker.gateway_provision import GatewayTransport, deprovision_git_gate, provision_git_gate
|
|
|
|
|
|
def provision_bottle(
|
|
client: OrchestratorClient,
|
|
source_ip: str,
|
|
egress_plan: EgressPlan,
|
|
git_gate_plan: GitGatePlan,
|
|
transport: GatewayTransport,
|
|
*,
|
|
image_ref: str = "",
|
|
tokens: dict[str, str] | None = None,
|
|
env_var_secret: str | None = None,
|
|
) -> RegisteredBottle:
|
|
"""Register the bottle and provision its git-gate state. Rolls back the
|
|
registration if provisioning fails so no orphan is left.
|
|
|
|
Generates a fresh ENV_VAR_SECRET, passes it to the orchestrator so it can
|
|
encrypt the token values at rest, and stamps the secret onto the returned
|
|
``RegisteredBottle`` so callers can inject it into the agent container's
|
|
environment."""
|
|
inputs = registration_inputs(egress_plan)
|
|
env_var_secret = env_var_secret or new_env_var_secret()
|
|
reg = client.register_bottle(
|
|
source_ip, image_ref=image_ref, policy=inputs.policy,
|
|
metadata=inputs.metadata, tokens=tokens, env_var_secret=env_var_secret,
|
|
)
|
|
try:
|
|
provision_git_gate(transport, reg.bottle_id, git_gate_plan)
|
|
except Exception:
|
|
client.teardown_bottle(reg.bottle_id)
|
|
raise
|
|
return dataclasses.replace(reg, env_var_secret=env_var_secret)
|
|
|
|
|
|
def teardown_consolidated(
|
|
bottle_id: str,
|
|
transport: GatewayTransport,
|
|
*,
|
|
orchestrator_url: str,
|
|
timeout: float | None = None,
|
|
) -> None:
|
|
"""Deregister the bottle and remove its git-gate state. Both steps are
|
|
idempotent so this is safe from a cleanup trap."""
|
|
from ..orchestrator.store.config_store import DEFAULT_TEARDOWN_TIMEOUT_SECONDS
|
|
OrchestratorClient(
|
|
orchestrator_url,
|
|
timeout=timeout if timeout is not None else DEFAULT_TEARDOWN_TIMEOUT_SECONDS,
|
|
).teardown_bottle(bottle_id)
|
|
deprovision_git_gate(transport, bottle_id)
|
|
|
|
|
|
__all__ = ["provision_bottle", "teardown_consolidated"]
|