Skip to content

feat(cloud-agent-next): activate containers billing admission and terminal enforcement - #6575

Merged
eshurakov merged 3 commits into
eshurakov/containers-billing-c3-substratefrom
eshurakov/containers-billing-c4-activation
Sep 23, 2026
Merged

eshurakov merged 3 commits into
eshurakov/containers-billing-c3-substratefrom
eshurakov/containers-billing-c4-activation

Conversation

@eshurakov

@eshurakov eshurakov commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Ops follow-up (not a merge blocker). This PR is the runtime activation boundary: after it merges, Default already reaches real containers admission even while the picker group is hidden. Missing SKU rows fail admission non-retryably. Confirmed 2026-09-22: no live users of this path yet, so the rows can land after merge and before any real exposure.

Release checklist (operations, not code)

Register the SKU rows via admin (apps/web/src/app/admin/cloud-billing-skus/) before any live exposure. Missing rows make Default a dead end for enforced owners.

id unit accepts_new_usage rate_cents_per_unit
cloud-agent-containers-standard-3-2026-09 second true ops-set, > 0
cloud-agent-containers-standard-4-2026-09 second true ops-set, > 0
  • SKU cloud-agent-containers-standard-3-2026-09 confirmed (id, unit = 'second', accepts_new_usage = true, positive rate)
  • SKU cloud-agent-containers-standard-4-2026-09 confirmed (id, unit = 'second', accepts_new_usage = true, positive rate)

SKUs are admin-managed; no seed inserts exist, so no code change can substitute. This same checklist also covers part 5.

Summary

Activate enforced containers billing end to end.

  • Adapter admission mirrors the legacy cloudflare-provider branch: enforced owners get real admission and a real insufficient_credits/stopping rejection maps to billing_blocked; non-enforced owners get best-effort configureBilling. The resolved default instance is passed to both billing RPCs and to launchWrapper.
  • Terminal enforcement: validateTerminalAccess dispatches cloudflare-containers through the containers billing runtime (status from SANDBOX_CONTAINERS.getByName(this.sandboxId)); the legacy cloudflare path is unchanged and every other provider keeps billing_policy_unavailable. Containers validation preserves the full legacy surface: payer, actor (incl. onBehalfOf), workspace/session attribution, DEADLINE_MS.stopAttempt, and the post-observation re-read before lease renewal.
  • Enforcement-aware default: new leaf sandbox-provider-eligibility.ts owns providerSupportsEnforcedBilling (cloudflare / cloudflare-containers: true; vercel: false). When enforcement is on, selectDefaultSandboxProvider skips enforcement-incapable providers so an enforced dual-enrolled owner no longer hits Vercel's deterministic rejection. Non-enforced precedence is unchanged.

Picker exclusion for containers remains until part 5.

Verification

  • pnpm --filter cloud-agent-next exec vitest run src/sandbox-control/cloudflare-containers-provider.test.ts src/sandbox-control/terminal-billing.test.ts src/sandbox-id.test.ts — 282/282 pass
  • pnpm --filter cloud-agent-next typecheck — pass
  • pnpm --filter cloud-agent-next test:integration — pass

Stack

Part 4 of 5. Previous: #6574. Holds the ops release checklist for this PR and part 5.

1         extract metered billing lifecycle
2         containers billing identity from instance size
3         SandboxContainers adopts the billing lifecycle
4 (this)  activate containers billing admission + terminal enforcement
5         open Cloudflare containers selection under enforced billing

Comment thread services/cloud-agent-next/src/sandbox-selection.ts Outdated
@kilo-code-bot

kilo-code-bot Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

Full re-review after the branch was rebased (the previously reviewed SHA was not an ancestor of HEAD) found no new changed-code defects across the 12 changed files; the containers billing admission and terminal-enforcement activation are consistent with the legacy Cloudflare path, and the advertised-default vs. picker-availability gap remains the intentional, stack-tracked deferral to part 5 (#6576).

Files Reviewed (12 files)
  • services/cloud-agent-next/src/persistence/SandboxControl.ts
  • services/cloud-agent-next/src/sandbox-control/cloudflare-containers-provider.ts
  • services/cloud-agent-next/src/sandbox-control/cloudflare-containers-provider.test.ts
  • services/cloud-agent-next/src/sandbox-control/lifecycle.test.ts
  • services/cloud-agent-next/src/sandbox-control/terminal-billing.ts
  • services/cloud-agent-next/src/sandbox-control/terminal-billing.test.ts
  • services/cloud-agent-next/src/sandbox-id.ts
  • services/cloud-agent-next/src/sandbox-id.test.ts
  • services/cloud-agent-next/src/sandbox-provider-eligibility.ts
  • services/cloud-agent-next/src/sandbox-selection.test.ts
  • services/cloud-agent-next/src/session/session-registration.ts
  • services/cloud-agent-next/test/integration/sandbox-control.test.ts
Previous Review Summaries (3 snapshots, latest commit 16848a7)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 16848a7)

Status: No Issues Found | Recommendation: Merge

Executive Summary

Incremental re-review of 16848a746 found a single behavior-neutral change: the tautological providerSupportsEnforcedBilling guard was removed from the Vercel branch in sandbox-selection.ts, resolving the prior SUGGESTION. No new changed-code issues were introduced, and the advertised-default vs. picker-availability gap remains the intentional, stack-tracked deferral to part 5.

Files Reviewed (1 file)
  • services/cloud-agent-next/src/sandbox-selection.ts

Previous review (commit 9e773ad)

Status: 1 Issue Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 1
Issue Details (click to expand)

SUGGESTION

File Line Issue
services/cloud-agent-next/src/sandbox-selection.ts 30 Redundant providerSupportsEnforcedBilling guard in the Vercel branch; the new enforcement-aware default can advertise cloudflare-containers-standard-4 as defaultDestination while this module still reports containers as unavailable and assertSandboxAllocationAvailable rejects it.
Files Reviewed (13 files)
  • services/cloud-agent-next/src/persistence/SandboxControl.ts
  • services/cloud-agent-next/src/sandbox-control/cloudflare-containers-provider.ts
  • services/cloud-agent-next/src/sandbox-control/cloudflare-containers-provider.test.ts
  • services/cloud-agent-next/src/sandbox-control/lifecycle.test.ts
  • services/cloud-agent-next/src/sandbox-control/terminal-billing.ts
  • services/cloud-agent-next/src/sandbox-control/terminal-billing.test.ts
  • services/cloud-agent-next/src/sandbox-id.ts
  • services/cloud-agent-next/src/sandbox-id.test.ts
  • services/cloud-agent-next/src/sandbox-provider-eligibility.ts
  • services/cloud-agent-next/src/sandbox-selection.ts - 1 issue
  • services/cloud-agent-next/src/sandbox-selection.test.ts
  • services/cloud-agent-next/src/session/session-registration.ts
  • services/cloud-agent-next/test/integration/sandbox-control.test.ts

Fix these issues in Kilo Cloud

Previous review (commit 28105b1)

Status: 1 Issue Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 1
Issue Details (click to expand)

SUGGESTION

File Line Issue
services/cloud-agent-next/src/sandbox-selection.ts 30 Redundant providerSupportsEnforcedBilling guard in the Vercel branch; the new enforcement-aware default can advertise cloudflare-containers-standard-4 as defaultDestination while this same module still reports containers as unavailable and assertSandboxAllocationAvailable rejects it.
Files Reviewed (13 files)
  • services/cloud-agent-next/src/persistence/SandboxControl.ts
  • services/cloud-agent-next/src/sandbox-control/cloudflare-containers-provider.ts
  • services/cloud-agent-next/src/sandbox-control/cloudflare-containers-provider.test.ts
  • services/cloud-agent-next/src/sandbox-control/lifecycle.test.ts
  • services/cloud-agent-next/src/sandbox-control/terminal-billing.ts
  • services/cloud-agent-next/src/sandbox-control/terminal-billing.test.ts
  • services/cloud-agent-next/src/sandbox-id.ts
  • services/cloud-agent-next/src/sandbox-id.test.ts
  • services/cloud-agent-next/src/sandbox-provider-eligibility.ts
  • services/cloud-agent-next/src/sandbox-selection.ts - 1 issue
  • services/cloud-agent-next/src/sandbox-selection.test.ts
  • services/cloud-agent-next/src/session/session-registration.ts
  • services/cloud-agent-next/test/integration/sandbox-control.test.ts

Notes on the rest of the change (no comments raised): the containers adapter's admission flow mirrors the legacy Cloudflare branch, the resolved instance is passed consistently to both billing RPCs and launchWrapper, and validateContainersTerminalBillingRuntime preserves the legacy payer/actor/onBehalfOf/session attribution checks while binding to the logical session id and containers DO id, matching how ContainersBilling records instanceId/durable_object_id. No memory leaks, MCP catalog changes, markdown, or changed-line issues were found beyond the note above.

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch eshurakov/containers-billing-c3-substrate

@eshurakov
eshurakov force-pushed the eshurakov/containers-billing-c4-activation branch from 28105b1 to 9e773ad Compare September 22, 2026 19:07
eshurakov added a commit that referenced this pull request Sep 22, 2026
Inside `provider === 'vercel'`, providerSupportsEnforcedBilling is statically
false, so the `!providerSupportsEnforcedBilling(provider)` conjunct could never
change the result and read as if Vercel could become eligible under
enforcement. Behaviour is unchanged: the enforcement check alone decides.

Addresses PR #6575 review. The advertised-default vs picker-availability gap
is closed by the next stack chunk, which opens the containers picker.
@eshurakov
eshurakov force-pushed the eshurakov/containers-billing-c4-activation branch from 9e773ad to 16848a7 Compare September 22, 2026 21:03
…minal enforcement

Adapter admission mirrors the legacy Cloudflare branch with the resolved
instance and maps real credit/stopping rejections to billing_blocked.
validateTerminalAccess dispatches cloudflare-containers through the
containers billing runtime while the legacy terminal path stays frozen.
A shared provider-eligibility leaf drives the enforcement-aware default so
an enforced owner never lands on Vercel; non-enforced precedence is
unchanged and the picker exclusion remains for chunk 5.
Inside `provider === 'vercel'`, providerSupportsEnforcedBilling is statically
false, so the `!providerSupportsEnforcedBilling(provider)` conjunct could never
change the result and read as if Vercel could become eligible under
enforcement. Behaviour is unchanged: the enforcement check alone decides.

Addresses PR #6575 review. The advertised-default vs picker-availability gap
is closed by the next stack chunk, which opens the containers picker.
… the canonical allocation

The flat allocation entry points (getPhysicalRecord/claimCreate/confirmInstance)
were removed by the canonical sandbox state core; seed through the canonical
fixtures instead.
@eshurakov
eshurakov force-pushed the eshurakov/containers-billing-c4-activation branch from 16848a7 to 6edbc32 Compare September 23, 2026 08:35
@eshurakov
eshurakov added this pull request to stack #6635 September 23, 2026 09:24
@eshurakov
eshurakov merged commit b24d415 into main Sep 23, 2026
26 checks passed
@eshurakov
eshurakov deleted the eshurakov/containers-billing-c4-activation branch September 23, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants