Skip to content

chore(ci): smoke the sandbox agent inside the image build - #106654

Merged
trunk-io[bot] merged 2 commits into
chore/sandbox-derived-images-jobfrom
chore/sandbox-smoke-in-build
Sep 28, 2026
Merged

trunk-io[bot] merged 2 commits into
chore/sandbox-derived-images-jobfrom
chore/sandbox-smoke-in-build

Conversation

@tatoalo

@tatoalo tatoalo commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Every sandbox image build spends about a minute re-pulling the image it just pushed, to run two one-second checks (run 36044984574, step "Smoke the installed agent on both architectures": 66 s).

  • The step pulls the base image once per platform, about 27 s each.
  • The arm64 half runs under QEMU on an amd64 runner, 8 to 9 s for what takes 1 s natively.
  • Depot already builds each platform on a native machine, so the same checks as a RUN in the Dockerfile execute natively during the build.

Changes

  • The Dockerfile checks the installed @posthog/agent version against the pin and runs agent-server --help in the last layer of the image, after the skills and the shims, on both platforms, natively.
  • The workflow step that ran the image now only checks that the pushed manifest list carries linux/amd64 and linux/arm64, so a half-pushed image still fails the smoke check.
  • The QEMU setup step is gone; nothing in the job runs a container any more.
  • The check the bump waits on keeps its name and its output. A failing smoke now fails the build step, which the check step already requires to succeed.
before                              after
  depot build (amd64, arm64)          depot build (amd64, arm64)
  push                                  RUN version == pin, agent-server --help
  pull amd64, run checks   27 s + 1 s   push
  pull arm64, run checks   28 s + 9 s   imagetools inspect: both platforms listed   ~1 s

@tatoalo
tatoalo added this pull request to stack #106659 September 25, 2026 12:56
@tatoalo tatoalo added the reviewhog ($$$) Reviews pull requests before humans do label Sep 25, 2026
@posthog

posthog Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🦔 PostHog Review reviewed this pull request

Nothing worth raising this time. Enjoy the moment:

A panda relaxing and waving

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🤖 CI report

🚨 Trunk lane — universal lane

This PR is assigned to the universal lane. It cannot merge in parallel with other PRs, so it can take longer to merge. Ask dev-ex if you think this is wrong.

⚠️ Duplication (Python) — 16 new duplicated blocks (worst 213 tokens)

New Python code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

First copy Second copy Lines Tokens
products/experiments/backend/hogql_queries/breakdown_injector.py:252 products/experiments/backend/hogql_queries/breakdown_injector.py:336 31 213
posthog/api/test/test_signup.py:1046 posthog/api/test/test_signup.py:1091 21 165
products/experiments/backend/hogql_queries/experiment_funnel_query_builder.py:223 products/experiments/backend/hogql_queries/experiment_funnel_query_builder.py:341 29 161
products/experiments/backend/hogql_queries/utils.py:513 products/experiments/backend/hogql_queries/utils.py:608 37 161
products/experiments/backend/hogql_queries/breakdown_injector.py:131 products/experiments/backend/hogql_queries/breakdown_injector.py:382 15 125
products/experiments/backend/hogql_queries/breakdown_injector.py:213 products/experiments/backend/hogql_queries/breakdown_injector.py:298 15 121
products/experiments/backend/hogql_queries/breakdown_injector.py:88 products/experiments/backend/hogql_queries/experiment_breakdown_attribution_query_builder.py:271 12 120
products/experiments/backend/hogql_queries/breakdown_injector.py:152 products/experiments/backend/hogql_queries/experiment_breakdown_attribution_query_builder.py:297 13 120
products/experiments/backend/hogql_queries/breakdown_injector.py:227 products/experiments/backend/hogql_queries/breakdown_injector.py:312 13 120
products/experiments/backend/hogql_queries/breakdown_injector.py:89 products/experiments/backend/hogql_queries/breakdown_injector.py:205 11 109
products/experiments/backend/hogql_queries/breakdown_injector.py:239 products/experiments/backend/hogql_queries/breakdown_injector.py:325 14 101
products/experiments/backend/hogql_queries/experiment_funnels_query_runner.py:204 products/experiments/backend/hogql_queries/experiment_trends_query_runner.py:401 11 88
products/experiments/backend/hogql_queries/breakdown_injector.py:134 products/experiments/backend/hogql_queries/breakdown_injector.py:181 14 85
products/experiments/backend/hogql_queries/breakdown_injector.py:159 products/experiments/backend/hogql_queries/breakdown_injector.py:211 11 85
products/experiments/backend/hogql_queries/trends_statistics_v2_continuous.py:92 products/experiments/backend/hogql_queries/trends_statistics_v2_count.py:66 15 79
products/experiments/backend/hogql_queries/utils.py:322 products/experiments/backend/hogql_queries/utils.py:339 17 78
✅ Duplication (TypeScript) — clean

New TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Retrigger

[High risk] Moves agent validation from CI workflow into the container image build.

The PR appears safe to merge; no new actionable issue was established.

Reviews (2) · Last reviewed commit: "chore(ci): smoke the sandbox agent insid..."

Comment thread .github/workflows/cd-sandbox-base-image.yml
@posthog posthog Bot removed the reviewhog ($$$) Reviews pull requests before humans do label Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 01c967d7-7313-46f3-a832-85d4e0c2251d

📥 Commits

Reviewing files that changed from the base of the PR and between 34ad507 and 4e75682.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 828a57dd-ad14-495a-bf07-deeba1c45a33

📥 Commits

Reviewing files that changed from the base of the PR and between 62f3642 and 34ad507.

📒 Files selected for processing (2)
  • .github/scripts/test_sandbox_agent_release.py
  • .github/workflows/cd-sandbox-base-image.yml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The Dockerfile checks that the installed @posthog/agent version matches AGENT_VERSION and that agent-server --help runs successfully. The workflow removes QEMU setup and checks that the pushed image manifest includes both linux/amd64 and linux/arm64. The packaging smoke test checks for both platforms in the image manifest.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 34ad5

No concrete issue requiring a fix before merge was established.

Architecture Summary

Architecture risk: 🔵 Low · up to 34ad5

The change affects 1 system.

Changed systems: products

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — products (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in products/tasks/backend/sandbox/images/Dockerfile.sandbox-base: After checking the npm version, the build reads the installed @posthog/agent version, exits with an error if it differs from AGENT_VERSION, and runs agent-server --help.
  • observed — Modified behavior in .github/scripts/test_sandbox_agent_release.py: Replaces the per-platform digest and container smoke test with a check that docker buildx imagetools inspect output contains both required platform entries. The test passes for linux/amd64 plus linux/arm64 and fails when only linux/amd64 is reported.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: Removed the QEMU setup step from the base-image build job.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: Renamed the smoke step to check the pushed image’s architecture manifests. It now inspects the manifest list and fails if either linux/amd64 or linux/arm64 is absent. The previous per-architecture container runs and checks for the pinned agent version and startup command were removed.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description clearly explains the problem and implementation, but it omits required template sections for testing, release status, automatic notifications, and docs updates. Because the change modi… Add a completed “How did you test this code?” section with executed tests and limitations, select exactly one release-status option, complete the automatic notifications and docs-update sections, and include the required before-and-after Me…
Full details: Description check

Explanation

The description clearly explains the problem and implementation, but it omits required template sections for testing, release status, automatic notifications, and docs updates. Because the change modifies CI wiring, it also uses a text table instead of the required before-and-after Mermaid flowcharts. Agent context is missing if an agent authored or assisted with the PR.

Resolution

Add a completed “How did you test this code?” section with executed tests and limitations, select exactly one release-status option, complete the automatic notifications and docs-update sections, and include the required before-and-after Mermaid flowcharts for the CI change. Add the Agent context section if applicable.

✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@tatoalo
tatoalo force-pushed the chore/sandbox-smoke-in-build branch from 8bbeea7 to 62f3642 Compare September 25, 2026 13:36
@tatoalo
tatoalo marked this pull request as ready for review September 25, 2026 14:17
@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested a review from a team September 25, 2026 14:17
@pr-assigner-resolver-posthog

Copy link
Copy Markdown

👀 Auto-assigned reviewers

These soft owners were skipped because they only have minor changes here. Nothing blocks merge, so self-assign if you'd like a look:

  • @PostHog/team-posthog-desktop (products/tasks/product.yaml)
  • @PostHog/team-self-driving (products/tasks/product.yaml)

Soft owners come from each directory's owners.yaml and each product's product.yaml (resolved nearest-file-wins). The locator after each owner is the file that decided it. Generated files and lockfiles are ignored when deciding ownership.

@trunk-io

trunk-io Bot commented Sep 28, 2026

Copy link
Copy Markdown

Stacked PR 106658 failed testing in the merge queue. Please investigate the failure and re-submit the stack.

@tatoalo
tatoalo force-pushed the chore/sandbox-smoke-in-build branch from 34ad507 to 9d90965 Compare September 28, 2026 08:26
@tatoalo
tatoalo force-pushed the chore/sandbox-smoke-in-build branch from 9d90965 to 4e75682 Compare September 28, 2026 08:29
@trunk-io
trunk-io Bot merged commit e811d17 into master Sep 28, 2026
224 checks passed
@trunk-io
trunk-io Bot deleted the chore/sandbox-smoke-in-build branch September 28, 2026 09:03
@trunk-io

trunk-io Bot commented Sep 28, 2026

Copy link
Copy Markdown

This pull request was merged into master as part of stacked PR 106658.

@deployment-status-posthog

deployment-status-posthog Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploy status

Environment Status Deployed At Workflow
dev ✅ Deployed 2026-09-28 09:24 UTC Run
prod-us ✅ Deployed 2026-09-28 09:41 UTC Run
prod-eu ✅ Deployed 2026-09-28 09:42 UTC Run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants