Skip to content

feat(cloud-agent-next): open Cloudflare containers selection under enforced billing - #6576

Merged
eshurakov merged 1 commit into
eshurakov/containers-billing-c4-activationfrom
eshurakov/containers-billing-c5-picker
Sep 23, 2026
Merged

eshurakov merged 1 commit into
eshurakov/containers-billing-c4-activationfrom
eshurakov/containers-billing-c5-picker

Conversation

@eshurakov

@eshurakov eshurakov commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Ops follow-up (not a merge blocker). Same SKU checklist as #6575: register the two container SKU rows before any live exposure. Confirmed 2026-09-22: no live users of this path yet.

Summary

Final wiring: open explicit Cloudflare containers selection for enrolled owners under enforced organization billing.

  • Removes the containers exclusion in sandbox-selection.ts (the enforcement check for containers is dropped)
  • The Vercel exclusion now uses the shared providerSupportsEnforcedBilling predicate from part 4, keeping its message
  • For an enrolled + enforced owner: both containers allocations appear in options, defaultDestination equals cloudflare-containers-standard-4, and isSandboxAllocationAvailable(capabilities, 'cloudflare-containers-standard-4') is true

Verification

  • pnpm --filter cloud-agent-next exec vitest run src/sandbox-selection.test.ts — 39/39 pass
  • pnpm --filter cloud-agent-next typecheck — pass
  • pnpm lint — pass
  • Whole-stack E2E in the integration workspace: enforced/non-enforced picker scenarios PASS; paid billing session (admission, activation, heartbeat charging, warn → stop → settle, fresh admission) PASS; terminal allow-while-measured PASS. Boundary notes: real Cloudflare container allocation not exercised (local workerd/Docker); billing_blocked terminal denial is unit-test-only (workspace gate masks it in practice).

Stack

Part 5 of 5. Previous: #6575.

1         extract metered billing lifecycle
2         containers billing identity from instance size
3         SandboxContainers adopts the billing lifecycle
4         activate containers billing admission + terminal enforcement
5 (this)  open Cloudflare containers selection under enforced billing

@kilo-code-bot

kilo-code-bot Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

This PR removes only the picker-level block that hid Cloudflare containers from owners under enforced compute billing, and the removal is consistent with the billing path: containers are enforcement-capable (providerSupportsEnforcedBilling), are already the default destination for enforced control-plane owners, and admission fails closed via ensureBillingAdmission/billingInput when billing attribution is missing. Verified against current HEAD 81c4f232.

Files Reviewed (2 files)
  • services/cloud-agent-next/src/sandbox-selection.ts
  • services/cloud-agent-next/src/sandbox-selection.test.ts
Previous Review Summaries (3 snapshots, latest commit df9153c)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit df9153c)

Status: No Issues Found | Recommendation: Merge

Executive Summary

This PR only removes the picker-level block that hid Cloudflare containers from owners under enforced compute billing; the removal is consistent with the billing admission path, which marks those containers as enforcement-capable and fails closed on insufficient credits, so no new correctness or billing-bypass issue was found. Verified against current HEAD df9153cc.

Files Reviewed (2 files)
  • services/cloud-agent-next/src/sandbox-selection.ts
  • services/cloud-agent-next/src/sandbox-selection.test.ts

Previous review (commit 15e02c9)

Status: No Issues Found | Recommendation: Merge

Executive Summary

This change removes the picker-level exclusion that blocked Cloudflare containers for owners under enforced compute billing, aligning the selection path with the shared providerSupportsEnforcedBilling predicate that already marks cloudflare-containers as enforcement-capable; the removal also resolves the prior inconsistency where defaultDestination could point at containers while options excluded them. Verified against current HEAD 15e02c929.

Files Reviewed (2 files)
  • services/cloud-agent-next/src/sandbox-selection.ts
  • services/cloud-agent-next/src/sandbox-selection.test.ts

Previous review (commit fe2f4d5)

Status: No Issues Found | Recommendation: Merge

Executive Summary

This change removes the picker-level exclusion that blocked Cloudflare containers for owners under enforced compute billing, aligning the selection path with the shared providerSupportsEnforcedBilling predicate that already marks cloudflare-containers as enforcement-capable; the removal also resolves the prior inconsistency where defaultDestination could point at containers while options excluded them. Verified against current HEAD.

Files Reviewed (2 files)
  • services/cloud-agent-next/src/sandbox-selection.ts
  • services/cloud-agent-next/src/sandbox-selection.test.ts

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch eshurakov/containers-billing-c4-activation

@eshurakov
eshurakov force-pushed the eshurakov/containers-billing-c5-picker branch from fe2f4d5 to 15e02c9 Compare September 22, 2026 19:07
@eshurakov
eshurakov force-pushed the eshurakov/containers-billing-c5-picker branch from 15e02c9 to df9153c Compare September 22, 2026 21:03
@eshurakov
eshurakov added this pull request to stack #6635 September 23, 2026 09:24
@eshurakov
eshurakov merged commit 4ee97d6 into main Sep 23, 2026
26 checks passed
@eshurakov
eshurakov deleted the eshurakov/containers-billing-c5-picker branch September 23, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants