Repository navigation
feat(cloud-agent-next): activate containers billing admission and terminal enforcement - #6575
Conversation
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryFull re-review after the branch was rebased (the previously reviewed SHA was not an ancestor of HEAD) found no new changed-code defects across the 12 changed files; the containers billing admission and terminal-enforcement activation are consistent with the legacy Cloudflare path, and the advertised-default vs. picker-availability gap remains the intentional, stack-tracked deferral to part 5 (#6576). Files Reviewed (12 files)
Previous Review Summaries (3 snapshots, latest commit 16848a7)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 16848a7)Status: No Issues Found | Recommendation: Merge Executive SummaryIncremental re-review of Files Reviewed (1 file)
Previous review (commit 9e773ad)Status: 1 Issue Found | Recommendation: Address before merge Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (13 files)
Fix these issues in Kilo Cloud Previous review (commit 28105b1)Status: 1 Issue Found | Recommendation: Address before merge Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (13 files)
Notes on the rest of the change (no comments raised): the containers adapter's admission flow mirrors the legacy Cloudflare branch, the resolved instance is passed consistently to both billing RPCs and Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
28105b1 to
9e773ad
Compare
Inside `provider === 'vercel'`, providerSupportsEnforcedBilling is statically false, so the `!providerSupportsEnforcedBilling(provider)` conjunct could never change the result and read as if Vercel could become eligible under enforcement. Behaviour is unchanged: the enforcement check alone decides. Addresses PR #6575 review. The advertised-default vs picker-availability gap is closed by the next stack chunk, which opens the containers picker.
9e773ad to
16848a7
Compare
…minal enforcement Adapter admission mirrors the legacy Cloudflare branch with the resolved instance and maps real credit/stopping rejections to billing_blocked. validateTerminalAccess dispatches cloudflare-containers through the containers billing runtime while the legacy terminal path stays frozen. A shared provider-eligibility leaf drives the enforcement-aware default so an enforced owner never lands on Vercel; non-enforced precedence is unchanged and the picker exclusion remains for chunk 5.
Inside `provider === 'vercel'`, providerSupportsEnforcedBilling is statically false, so the `!providerSupportsEnforcedBilling(provider)` conjunct could never change the result and read as if Vercel could become eligible under enforcement. Behaviour is unchanged: the enforcement check alone decides. Addresses PR #6575 review. The advertised-default vs picker-availability gap is closed by the next stack chunk, which opens the containers picker.
… the canonical allocation The flat allocation entry points (getPhysicalRecord/claimCreate/confirmInstance) were removed by the canonical sandbox state core; seed through the canonical fixtures instead.
16848a7 to
6edbc32
Compare
Release checklist (operations, not code)
Register the SKU rows via admin (
apps/web/src/app/admin/cloud-billing-skus/) before any live exposure. Missing rows make Default a dead end for enforced owners.cloud-agent-containers-standard-3-2026-09secondtruecloud-agent-containers-standard-4-2026-09secondtruecloud-agent-containers-standard-3-2026-09confirmed (id,unit = 'second',accepts_new_usage = true, positive rate)cloud-agent-containers-standard-4-2026-09confirmed (id,unit = 'second',accepts_new_usage = true, positive rate)SKUs are admin-managed; no seed inserts exist, so no code change can substitute. This same checklist also covers part 5.
Summary
Activate enforced containers billing end to end.
cloudflare-providerbranch: enforced owners get real admission and a realinsufficient_credits/stoppingrejection maps tobilling_blocked; non-enforced owners get best-effortconfigureBilling. The resolved default instance is passed to both billing RPCs and tolaunchWrapper.validateTerminalAccessdispatchescloudflare-containersthrough the containers billing runtime (status fromSANDBOX_CONTAINERS.getByName(this.sandboxId)); the legacycloudflarepath is unchanged and every other provider keepsbilling_policy_unavailable. Containers validation preserves the full legacy surface: payer, actor (incl.onBehalfOf), workspace/session attribution,DEADLINE_MS.stopAttempt, and the post-observation re-read before lease renewal.sandbox-provider-eligibility.tsownsproviderSupportsEnforcedBilling(cloudflare / cloudflare-containers: true; vercel: false). When enforcement is on,selectDefaultSandboxProviderskips enforcement-incapable providers so an enforced dual-enrolled owner no longer hits Vercel's deterministic rejection. Non-enforced precedence is unchanged.Picker exclusion for containers remains until part 5.
Verification
pnpm --filter cloud-agent-next exec vitest run src/sandbox-control/cloudflare-containers-provider.test.ts src/sandbox-control/terminal-billing.test.ts src/sandbox-id.test.ts— 282/282 passpnpm --filter cloud-agent-next typecheck— passpnpm --filter cloud-agent-next test:integration— passStack
Part 4 of 5. Previous: #6574. Holds the ops release checklist for this PR and part 5.