chore(ci): install the sandbox agent from the release tarball - #106658
Conversation
🦔 PostHog Review reviewed this pull requestFound 0 must fix, 1 should fix, 1 consider. Published 2 findings (view the review). |
🤖 CI report🚨 Trunk lane — universal laneThis PR is assigned to the universal lane. It cannot merge in parallel with other PRs, so it can take longer to merge. Ask dev-ex if you think this is wrong. |
|
[High risk] Changes how the sandbox base image installs the agent package. The PR is not yet safe to merge because a transient tarball download failure can fail the image build before npm serves the release. Reviews (2) · Last reviewed commit: "chore(ci): install the sandbox agent fro..." |
|
PostHog Review alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏 |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: PostHog/posthog/.coderabbit.yaml Review profile: QUIET Plan: Enterprise Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe release workflow packs the agent package, calculates its SHA-256 checksum, and attaches both files to an existing or new GitHub release. The sandbox workflow checks for the pinned version in the release tarball and npm. The sandbox image verifies and installs the tarball when configured and available, or installs the pinned npm package otherwise. The version update workflow writes the checksum and version to the Dockerfile. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The identified tarball integrity and release-workflow failure paths do not block this change. The sandbox image uses a verified tarball when pinned and npm otherwise. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ❌ 1❌ Failed checks (1 warning)
Full details: Description checkExplanation The Problem and Changes sections explain the reason for the PR and its main behavior changes. The description omits the required testing section and release-status selection. It also includes only an after-flow diagram, although the template requires separate before-and-after diagrams for workflow changes. Resolution Add a “How did you test this code?” section with the automated tests actually run, expected results, and any checks not performed. Select exactly one Release status option. Add separate before-and-after Mermaid flowcharts for the workflow changes. Complete the Agent context section if an agent authored or co-authored the PR.
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
Review profile: QUIET
Plan: Enterprise
Run ID: e188a400-8ee2-42bc-9411-3e53a90b0b34
📒 Files selected for processing (4)
.github/workflows/cd-sandbox-base-image.yml.github/workflows/desktop-agent-release.yml.github/workflows/update-sandbox-agent-version.ymlproducts/tasks/backend/sandbox/images/Dockerfile.sandbox-base
Included review availability: Your plan provides up to 12 included reviews per hour; 8 remain after this review.
455aeb3 to
4ee2d81
Compare
4ee2d81 to
4592a5f
Compare
PR overviewAll previously flagged issues have been addressed. No open security concerns remain on this pull request. Security reviewNo open security issues remain on this pull request. Fixed/addressed: 1 · PR risk: 0/10 |
4592a5f to
8b2f77d
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
Review profile: QUIET
Plan: Enterprise
Run ID: bd09ac52-dce9-41a7-94a7-19180d76dd82
📒 Files selected for processing (3)
.github/workflows/desktop-agent-release.yml.github/workflows/update-sandbox-agent-version.ymlproducts/tasks/backend/sandbox/images/Dockerfile.sandbox-base
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 8 remain after this review.
8b2f77d to
230b383
Compare
|
😎 Stack merged successfully - details. |
230b383 to
76bb6a8
Compare
76bb6a8 to
f2feb6b
Compare
Problem
Even with the npm wait moved off the PR path (#106657), a sandbox image cannot install a freshly released
@posthog/agentuntil the npm registry serves it, 6 to 16 minutes afterpnpm publishreturns (packument timestamps over eight releases: 379 to 984 s after publish). That wait is the largest single stage left in the bump.Changes
pnpm publish, so a packing failure fails the run before npm holds the version. A new job,attach-tarball, creates a GitHub release on theagent-v<version>tag withposthog-agent-<version>.tgzand its.sha256attached, and fails when an asset already on the release differs from the one it built. The pin bump dispatches after that job, whether or not it succeeded, and carries the digest only when it did.AGENT_TARBALL_SHA256; a scheduled or manual bump with no digest installs from npm.npm install --prefix /scriptson that manifest, and a plain version spec with a matching installed package leaves the agent alone, as today; a URL spec would refetch it.contents: read; only the new job getscontents: write.flowchart LR P[release: pnpm publish] --> K[release: pnpm pack] K --> A[attach-tarball<br/>gh release create agent-vX] A --> D[bump-sandbox-agent-pin] D --> W[image: wait_for_agent] A -.asset, seconds.-> W N[(npm registry<br/>6 to 16 min)] -.fallback.-> W W --> B[image: base build<br/>npm install tarball or registry] classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff; classDef phRed fill:#f54e00,stroke:#f54e00,color:#fff; classDef phGray fill:#e5e7eb,stroke:#c7ccd1,color:#000; class P,K,A,D,W,B phBlue; class N phRed;