Skip to content

chore(ci): install the sandbox agent from the release tarball - #106658

Merged
trunk-io[bot] merged 2 commits into
chore/sandbox-bump-open-earlyfrom
chore/sandbox-agent-tarball
Sep 28, 2026
Merged

trunk-io[bot] merged 2 commits into
chore/sandbox-bump-open-earlyfrom
chore/sandbox-agent-tarball

Conversation

@tatoalo

@tatoalo tatoalo commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Even with the npm wait moved off the PR path (#106657), a sandbox image cannot install a freshly released @posthog/agent until the npm registry serves it, 6 to 16 minutes after pnpm publish returns (packument timestamps over eight releases: 379 to 984 s after publish). That wait is the largest single stage left in the bump.

Changes

  • The release workflow packs the package and its sha256 before pnpm publish, so a packing failure fails the run before npm holds the version. A new job, attach-tarball, creates a GitHub release on the agent-v<version> tag with posthog-agent-<version>.tgz and its .sha256 attached, and fails when an asset already on the release differs from the one it built. The pin bump dispatches after that job, whether or not it succeeded, and carries the digest only when it did.
  • The bump PR pins the digest next to the version. The release run passes the digest it computed to the bump dispatch, and the bump workflow writes it to AGENT_TARBALL_SHA256; a scheduled or manual bump with no digest installs from npm.
  • The Dockerfile downloads the tarball only when a digest is pinned, fails the build on a mismatch, and falls back to the npm registry when the asset is absent, so a pin on a version older than this change still builds.
  • After the install the Dockerfile rewrites the dependency to the plain version. The Modal image build later runs npm install --prefix /scripts on that manifest, and a plain version spec with a matching installed package leaves the agent alone, as today; a URL spec would refetch it.
  • The image workflow's wait job polls the release asset when a digest is pinned, and npm always, and continues on whichever appears first.
  • The npm publish job keeps contents: read; only the new job gets contents: write.
flowchart LR
    P[release: pnpm publish] --> K[release: pnpm pack]
    K --> A[attach-tarball<br/>gh release create agent-vX]
    A --> D[bump-sandbox-agent-pin]
    D --> W[image: wait_for_agent]
    A -.asset, seconds.-> W
    N[(npm registry<br/>6 to 16 min)] -.fallback.-> W
    W --> B[image: base build<br/>npm install tarball or registry]
    classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff;
    classDef phRed fill:#f54e00,stroke:#f54e00,color:#fff;
    classDef phGray fill:#e5e7eb,stroke:#c7ccd1,color:#000;
    class P,K,A,D,W,B phBlue;
    class N phRed;
Loading

@tatoalo
tatoalo added this pull request to stack #106659 September 25, 2026 12:56
@tatoalo tatoalo added the reviewhog ($$$) Reviews pull requests before humans do label Sep 25, 2026
@posthog

posthog Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🦔 PostHog Review reviewed this pull request

Found 0 must fix, 1 should fix, 1 consider.

Published 2 findings (view the review).

@github-actions

Copy link
Copy Markdown
Contributor

🤖 CI report

🚨 Trunk lane — universal lane

This PR is assigned to the universal lane. It cannot merge in parallel with other PRs, so it can take longer to merge. Ask dev-ex if you think this is wrong.

@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Retrigger

[High risk] Changes how the sandbox base image installs the agent package.

The PR is not yet safe to merge because a transient tarball download failure can fail the image build before npm serves the release.

Reviews (2) · Last reviewed commit: "chore(ci): install the sandbox agent fro..."

Comment thread .github/workflows/desktop-agent-release.yml
@posthog

posthog Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

PostHog Review alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏

@posthog posthog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PostHog Review

Found 1 should fix, 1 consider.

Comment thread .github/workflows/desktop-agent-release.yml Outdated
Comment thread products/tasks/backend/sandbox/images/Dockerfile.sandbox-base
@posthog posthog Bot removed the reviewhog ($$$) Reviews pull requests before humans do label Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: d936b1a6-67d0-4946-9ce8-fef6c378ba62

📥 Commits

Reviewing files that changed from the base of the PR and between 8b2f77d and f2feb6b.

📒 Files selected for processing (2)
  • .github/workflows/desktop-agent-release.yml
  • products/tasks/backend/sandbox/images/Dockerfile.sandbox-base

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow packs the agent package, calculates its SHA-256 checksum, and attaches both files to an existing or new GitHub release. The sandbox workflow checks for the pinned version in the release tarball and npm. The sandbox image verifies and installs the tarball when configured and available, or installs the pinned npm package otherwise. The version update workflow writes the checksum and version to the Dockerfile.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to f2feb

The identified tarball integrity and release-workflow failure paths do not block this change. The sandbox image uses a verified tarball when pinned and npm otherwise.

Architecture Summary

Architecture risk: 🔵 Low · up to f2feb

The change affects 1 system.

Changed systems: products

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — products (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in products/tasks/backend/sandbox/images/Dockerfile.sandbox-base: Adds an optional tarball checksum and configurable URL. When the checksum is nonempty and the download succeeds, the build verifies the tarball before installing it; verification failure fails the build. Otherwise, it installs the pinned npm package. Both install paths use COMMIT_HASH as CACHE_BUST, and the dependency is set to AGENT_VERSION.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: Renames the job from waiting for npm to serve the pinned agent to waiting for the pinned agent to be published.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: The polling step now reads the tarball SHA and checks the pinned-version GitHub release tarball when that SHA is nonempty; a successful response ends polling before the npm check. If the GitHub check is skipped or unsuccessful, npm remains the fallback, and either source serving the pinned version succeeds. The loop retains 120 attempts and 10-second sleeps; the retry message now names both sources, and the timeout error refers to publication within 20 minutes.
  • observed — Modified behavior in .github/workflows/update-sandbox-agent-version.yml: Adds an optional tarball_sha256 workflow input for the release tarball digest; leaving it empty specifies npm installation.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The Problem and Changes sections explain the reason for the PR and its main behavior changes. The description omits the required testing section and release-status selection. It also includes only an … Add a “How did you test this code?” section with the automated tests actually run, expected results, and any checks not performed. Select exactly one Release status option. Add separate before-and-after Mermaid flowcharts for the workflow c…
Full details: Description check

Explanation

The Problem and Changes sections explain the reason for the PR and its main behavior changes. The description omits the required testing section and release-status selection. It also includes only an after-flow diagram, although the template requires separate before-and-after diagrams for workflow changes.

Resolution

Add a “How did you test this code?” section with the automated tests actually run, expected results, and any checks not performed. Select exactly one Release status option. Add separate before-and-after Mermaid flowcharts for the workflow changes. Complete the Agent context section if an agent authored or co-authored the PR.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: e188a400-8ee2-42bc-9411-3e53a90b0b34

📥 Commits

Reviewing files that changed from the base of the PR and between c167617 and 455aeb3.

📒 Files selected for processing (4)
  • .github/workflows/cd-sandbox-base-image.yml
  • .github/workflows/desktop-agent-release.yml
  • .github/workflows/update-sandbox-agent-version.yml
  • products/tasks/backend/sandbox/images/Dockerfile.sandbox-base

Included review availability: Your plan provides up to 12 included reviews per hour; 8 remain after this review.

Comment thread products/tasks/backend/sandbox/images/Dockerfile.sandbox-base Outdated
@tatoalo
tatoalo force-pushed the chore/sandbox-agent-tarball branch from 455aeb3 to 4ee2d81 Compare September 25, 2026 13:36
@tatoalo
tatoalo marked this pull request as ready for review September 25, 2026 14:17
@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested review from a team September 25, 2026 14:17
Comment thread .github/workflows/update-sandbox-agent-version.yml Outdated
Comment thread products/tasks/backend/sandbox/images/Dockerfile.sandbox-base Outdated
@tatoalo
tatoalo force-pushed the chore/sandbox-agent-tarball branch from 4ee2d81 to 4592a5f Compare September 25, 2026 14:46
Comment thread .github/workflows/desktop-agent-release.yml Outdated
@veria-ai

veria-ai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

PR overview

All previously flagged issues have been addressed. No open security concerns remain on this pull request.

Security review

No open security issues remain on this pull request.

Fixed/addressed: 1 · PR risk: 0/10

@tatoalo
tatoalo force-pushed the chore/sandbox-agent-tarball branch from 4592a5f to 8b2f77d Compare September 26, 2026 08:19

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: bd09ac52-dce9-41a7-94a7-19180d76dd82

📥 Commits

Reviewing files that changed from the base of the PR and between 4ee2d81 and 8b2f77d.

📒 Files selected for processing (3)
  • .github/workflows/desktop-agent-release.yml
  • .github/workflows/update-sandbox-agent-version.yml
  • products/tasks/backend/sandbox/images/Dockerfile.sandbox-base

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 8 remain after this review.

Comment thread .github/workflows/desktop-agent-release.yml
@tatoalo
tatoalo force-pushed the chore/sandbox-agent-tarball branch from 8b2f77d to 230b383 Compare September 26, 2026 08:32
@trunk-io

trunk-io Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

😎 Stack merged successfully - details.

@tatoalo
tatoalo force-pushed the chore/sandbox-agent-tarball branch from 230b383 to 76bb6a8 Compare September 28, 2026 08:26
@tatoalo
tatoalo force-pushed the chore/sandbox-agent-tarball branch from 76bb6a8 to f2feb6b Compare September 28, 2026 08:30
@trunk-io
trunk-io Bot merged commit eee9f0a into master Sep 28, 2026
226 checks passed
@trunk-io
trunk-io Bot deleted the chore/sandbox-agent-tarball branch September 28, 2026 09:03
@deployment-status-posthog

deployment-status-posthog Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploy status

Environment Status Deployed At Workflow
dev ✅ Deployed 2026-09-28 09:24 UTC Run
prod-us ✅ Deployed 2026-09-28 09:41 UTC Run
prod-eu ✅ Deployed 2026-09-28 09:42 UTC Run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants