Skip to content

Commit 3e753fd

Browse files
authored
Catch the changelog and docs up to what shipped (#125)
* Catch the changelog and docs up to what shipped The Unreleased notes already tracked most of the recent work, since each change carried its own line in. This fills the gaps and fixes what went stale. Two merged changes had no line. The address guard's alternate-encoding refusal: it turned away the metadata and private addresses as usually written but not the same ones spelled as an IPv6-mapped or NAT64 form, an integer, or with a trailing dot, and it now canonicalises before it checks and refuses the container credential endpoints even with the private-host opt-in on. And the supervisor refusing to adopt a container it did not create, so a shared Docker host cannot hand it a stranger's container with the computer token. Docs that drifted: the README and the Cloud Run note still said one replica, which the deployment doc's own Replicas section now contradicts, so both point at the real remaining constraint instead, which is the shared browser. And AUDIT_RETENTION_DAYS and COMPUTER_SANDBOX were configurable and documented in the changelog and the README but missing from the configuration table. The knowledge back-out left one more orphan the removal missed: agents/invocation.ts routed a built-in agent to the knowledge agent that is gone, and nothing live constructs it. Deleted with its test. The changelog line that said the local index's connector "is going away" is now "has been removed", because it has been. README stays a build doc; none of this adds history to it. * Reconcile with the table drops that landed after #126 and #127 dropped the document index and the old connector tables, so the changelog line that said the index was "read by nothing" now understates it: the tables are gone. Say dropped, and add the one Upgrading note that matters, which is that those migrations destroy that data and cannot be rolled back. architecture.md still listed connector state among what the database holds; #127 removed it, so the line goes too. The README's database line never named those tables, so it needs nothing. #123 is CI and build hardening, not a deployment behavior, so it earns no changelog line.
1 parent 2bd2add commit 3e753fd

7 files changed

Lines changed: 26 additions & 55 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,11 @@ digit. The same rule container and volume names have always followed. A deployme
3030
`AUDIT_RETENTION_DAYS` is new and unset, which keeps the audit trail forever, as before. Set it to a
3131
whole number of days to have old rows removed.
3232

33+
The local document index and the old connector tables are dropped by migration. `documents`,
34+
`chunks`, `document_acls` and the four connector-bookkeeping tables are removed and their rows go
35+
with them; this cannot be rolled back. A deployment that had been syncing into the local index loses
36+
that copy, which is the point: answering now goes through a live system's own search.
37+
3338
**An MCP server pointed at a credential that no longer exists loses the pointer.** `mcp_servers`
3439
now names its credential with a real foreign key, where the column was `text` against a `uuid`
3540
primary key with nothing checking it — so a deployment is allowed to be holding a pointer to a vault
@@ -69,7 +74,7 @@ Sessions survive and nobody signs in again.
6974
that system's own search as the person asking, so the vendor decides what they may see and there is
7075
no second copy of anybody's documents here to keep in step, to secure, or to leave behind when
7176
somebody is removed. The local index that was being filled — `documents`, `chunks` and
72-
`document_acls` — is read by nothing, and the connector that filled it is going away. Retrieval over
77+
`document_acls` — and the connector that filled it have both been dropped. Retrieval over
7378
a copy of a customer's corpus is not a thing OpenBot does.
7479

7580
### Added
@@ -184,6 +189,19 @@ Sessions survive and nobody signs in again.
184189
is unavailable never blocks a sign-in.
185190

186191
### Fixed
192+
- **A Bot could reach the deployment's own network by writing the address a different way.** The
193+
guard refused `169.254.169.254` and the private ranges as usually written, but not the same
194+
addresses spelled as an IPv6-mapped or NAT64 form, an integer, or with a trailing dot, so a Bot
195+
talked into fetching one still reached cloud metadata or an internal host. The address is
196+
canonicalised before it is checked now, the mapped form of `0.0.0.0` (which reaches every local
197+
port) is refused, and the container credential endpoints a hosted deployment must never expose —
198+
ECS and Fargate's `169.254.170.2`, Alibaba's `100.100.100.200` — are refused even when the
199+
private-host opt-in is on. The same guard backs agent registration, so it is closed there too.
200+
- **The supervisor could adopt a container it did not create.** When starting a Bot's computer hit a
201+
name already taken, it started whatever held the name and handed it the deployment's computer
202+
token, so on a Docker host shared with anything else it could drive a stranger's container as a
203+
Bot's. It now refuses a container that does not carry its own namespace label, read from the
204+
container rather than inferred, so a second deployment on the same host is never adopted.
187205
- **Removing somebody left the credentials they had granted this deployment sitting in the vault.**
188206
Removing them from the People screen ended their sessions and stopped the next sign-in, and left the
189207
refresh token behind, unrevoked. They could not use it — the account comes from a session they no

‎README.md‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -108,8 +108,7 @@ docker run -p 3001:3001 --env-file .env \
108108
```
109109

110110
Leave `EMBEDDED_POSTGRES` off and set `DATABASE_URL` to point at a database you already run.
111-
[docs/deployment.md](docs/deployment.md) has the minimum sizes, the platform notes, and why this runs
112-
as one replica for now.
111+
[docs/deployment.md](docs/deployment.md) has the minimum sizes, the platform notes, and how it behaves behind more than one replica.
113112

114113
## Try it
115114

‎docs/architecture.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ Regenerate it with `bun run diagram` after changing anything it shows.
1919
| `agent-bot` | 4200 | Proof-of-concept AG-UI Bot. |
2020
| `agent-langgraph` | 4201 | LangGraph AG-UI Bot. |
2121
| `supervisor` | 4500 host / 4300 container | Creates, stops, resets, and lists per-Bot computer containers. |
22-
| PostgreSQL with pgvector | 5432 | Product data, audit rows, credentials, policy, grants, channels, components, and connector state. |
22+
| PostgreSQL with pgvector | 5432 | Product data, audit rows, credentials, policy, grants, channels, and components. |
2323
| CopilotKit Intelligence | external | Durable threads, memory, and realtime gateway. |
2424

2525
`scripts/start.sh` starts PostgreSQL, `agent-computer`, `agent-bot`, `agent-langgraph`, and the supervisor through Docker Compose, then starts `server` and `app` on the host.

‎docs/configuration.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,7 @@ at `agent-langgraph` on a laptop.
5454
| `AGENT_STALL_TIMEOUT_MS` | unset (off) | How long a Bot's stream may produce nothing before the turn is ended for it. |
5555
| `AGENT_TOOL_TOKEN` | unset | The secret a framework Bot presents when it calls a granted tool back through this server. |
5656
| `APP_DIST_DIR` | unset | Where the built app is, when this process serves it. Set inside the container image; unset in development, where Vite serves the app. |
57+
| `AUDIT_RETENTION_DAYS` | unset | Whole number of days to keep audit rows; older ones are removed. Unset keeps the trail forever. |
5758

5859
**`AGENT_STALL_TIMEOUT_MS`** watches for the failure a Bot has that nothing else in the trail can
5960
show: a stream that stops producing anything. Every other audit row is something that happened, and
@@ -169,6 +170,7 @@ where `<provider>` is `google`, `microsoft` or `okta`.
169170
| `AGENT_COMPUTER_ALLOW_PRIVATE_HOSTS` | Local-only private-host browsing when `true`. Cloud metadata addresses are still refused. |
170171
| `AGENT_COMPUTER_POLICY` | JSON action policy: `{"mode":"enforce","deny":[...],"allow":[...]}`. |
171172
| `COMPUTER_RUNTIME` | Set to `runsc` to run supervised computers under gVisor. |
173+
| `COMPUTER_SANDBOX` | Set to `on` to enable Chromium's own sandbox where the host permits user namespaces. Which way it went is printed at start-up. |
172174

173175
`agent-computer` also reads:
174176

‎docs/deployment.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,9 @@ supervisor is still not in this image, so every replica shares the one browser i
111111

112112
## Platform notes
113113

114-
**Google Cloud Run.** Set memory to at least 2 GB and max instances to 1. Cloud Run runs every
114+
**Google Cloud Run.** Set memory to at least 2 GB. More than one instance is fine (see Replicas
115+
above); each instance has its own browser, so a Bot's logins stay on whichever instance served them.
116+
Cloud Run runs every
115117
container under gVisor, which Chromium is sensitive to; test a navigation before trusting it.
116118
`gcloud run compose up` will also deploy the whole compose file if you want a throwaway database
117119
alongside.

‎server/src/agents/invocation.ts‎

Lines changed: 0 additions & 20 deletions
This file was deleted.

‎server/tests/agent-invocation.test.ts‎

Lines changed: 0 additions & 30 deletions
This file was deleted.

0 commit comments

Comments
 (0)