Skip to content

fix(compose): archon-native 0.6.0 + drop broken archon from agents-stack + fix vector crash - #2218

Merged
POWERFULMOVES merged 1 commit into
mainfrom
fix/archon-native-060-followups
Jul 24, 2026
Merged

POWERFULMOVES merged 1 commit into
mainfrom
fix/archon-native-060-followups

Conversation

@POWERFULMOVES

@POWERFULMOVES POWERFULMOVES commented Jul 24, 2026 •

Copy link
Copy Markdown
Owner

Follow-ups from the Archon 0.6.0 sync + agents-stack bring-up (tracking: #2217).

1. up-archon-native rewritten for 0.6.0

0.6.0 is TS/SQLite-native, not Supabase. Dropped the SUPABASE_URL/env.shared/secrets-runtime-hydrate wiring; run Archon's own compose app service with PORT=3090 (the server self-allocates 3090 and ignores compose PORT); require the operator to seed Archon's env file; add archon-native-health/down targets. Fixed the stale :3737/:8051/:8181 comment. Verified live: healthy on :3090 (status:ok, version:0.6.0).

2. Drop archon from up-agents-stack

The in-compose archon is the pre-0.6.0 Python wrapper (imports server.main) that the TS rewrite broke → crash-loop. Removed from the stack so up-agents-stack comes up clean; Archon runs standalone via up-archon-native. First-class re-integration tracked in #2217.

3. supabase-vector crash fix

The supabase env files set HTTP_PROXY='' (empty); vector 0.28.1 fails to build its logflare proxy connector from an empty string (Failed to build Proxy connector: empty string) → 78-restart loop. Added pass-through (no =) HTTP_PROXY/HTTPS_PROXY/NO_PROXY so they resolve to ABSENT from the host (verified via docker compose config: "" → null), which vector tolerates. Overlay regenerated via compose-split.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added standalone Archon 0.6.0 startup and shutdown commands with configurable port support.
    • Added an Archon health-check command to verify service availability.
    • Updated agent-stack startup to run Archon separately from the remaining services.
    • Added dedicated configuration support for the Kimi coding API.
  • Bug Fixes

    • Prevented empty proxy settings from causing Vector service crash loops.
    • Improved separation of Kimi coding and Moonshot API credentials.

…agents-stack + fix vector crash

Three bring-up follow-ups from the Archon 0.6.0 sync (refs #2217):

1. up-archon-native rewritten for 0.6.0 (TS/SQLite-native, NOT Supabase): drop the
   SUPABASE_URL/env.shared/secrets-hydrate wiring; run Archon's own compose 'app'
   service with PORT=3090 (server self-allocates 3090, ignores compose PORT);
   require the operator to seed Archon's own env file first; add health/down
   targets. Fixes the stale 'server+mcp+frontend :3737/:8051/:8181' comment.

2. Remove 'archon' from up-agents-stack: the in-compose archon service is the
   pre-0.6.0 Python wrapper (imports server.main) that the TS rewrite broke and
   crash-loops. Archon 0.6.0 now runs standalone via up-archon-native. First-class
   main-compose re-integration is tracked in #2217.

3. supabase-vector crash fix: the supabase env files set HTTP_PROXY='' (empty), and
   vector 0.28.1 fails to build its logflare proxy connector from an empty string
   ('Failed to build Proxy connector: empty string') -> restart loop. Add
   pass-through (no '=') HTTP_PROXY/HTTPS_PROXY/NO_PROXY to the vector env so they
   resolve to ABSENT from the host (verified via 'docker compose config': empty
   '' -> null), which vector tolerates. Overlay regenerated (compose-split).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions github-actions Bot added the compose Compose files / service Dockerfiles label Jul 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Docker Hardening Validation

Hardening Validation Report

Validated: Fri Jul 24 23:31:10 UTC 2026

Services Checked

PMOVES.AI Docker Hardening Validation

[INFO] Checking: pmoves/docker-compose.hardened.yml

[INFO] Validating: hi-rag-gateway-v2
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: extract-worker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: langextract
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: presign
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: render-webhook
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: retrieval-eval
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pdf-ingest
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: jellyfin-bridge
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: invidious-companion-proxy
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: ffmpeg-whisper
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-video
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-audio
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-v2-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: deepresearch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supaserch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher-discord
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: mesh-agent
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-req
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-res
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: comfy-watcher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: grayjay-plugin-host
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: agent-zero
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: p7-room-orchestrator
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: archon
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: channel-monitor
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pmoves-yt
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: notebook-sync
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supabase_service_role_key
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: supabase_jwt_secret
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: p7_control_token
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

======================================
Summary: 112 passed, 43 warnings, 0 errors

@coderabbitai

coderabbitai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Changes

Runtime orchestration and environment configuration

Layer / File(s) Summary
Standalone Archon lifecycle
pmoves/Makefile
Replaces the Supabase-wired Archon flow with native compose startup, shutdown, required .env validation, port configuration, and /api/health checks.
Agents stack integration
pmoves/Makefile
Stops starting the in-compose archon service from up-agents-stack.
Compose environment routing
pmoves/docker-compose.yml, pmoves/docker-compose.core.yml
Passes proxy variables as absent values for Vector and adds dedicated KIMI_CODING_API routing for TensorZero.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Makefile
  participant ArchonCompose
  participant ArchonHealthAPI
  Makefile->>ArchonCompose: Start native Archon stack with PORT
  ArchonCompose->>ArchonHealthAPI: Publish service on host port
  Makefile->>ArchonHealthAPI: Probe /api/health
Loading

Possibly related issues

Possibly related PRs

Suggested labels: config

Suggested reviewers: hunnibear

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the changes but does not follow the required template: no Summary bullets, Testing block, or checklist items. Rewrite using the repository template with Summary bullets, a Testing section, the required checklists, and Reviewer Notes/Follow-up items as applicable.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed Title clearly reflects the main changes: Archon native bring-up, dropping the broken agents-stack service, and the Vector proxy fix.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/archon-native-060-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@POWERFULMOVES
POWERFULMOVES merged commit 8cd769e into main Jul 24, 2026
36 of 37 checks passed
@POWERFULMOVES
POWERFULMOVES deleted the fix/archon-native-060-followups branch July 24, 2026 23:32

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5d04b6b143

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pmoves/docker-compose.yml
Comment on lines +1102 to +1104
- HTTP_PROXY
- HTTPS_PROXY
- NO_PROXY

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Unset proxy variables instead of importing host values

When Docker Compose is invoked from a host that defines HTTP_PROXY or HTTPS_PROXY, these value-less entries do not make the variables absent: the Compose environment reference says a bare variable relies on the invoking environment to resolve its value and is removed only when unresolved. Consequently, supabase-vector inherits the host proxy and NO_PROXY; unless the latter includes supabase-analytics, internal Logflare traffic is sent through that proxy and log shipping remains broken. Unset these variables inside the container before executing Vector, or sanitize the Compose process environment.

Useful? React with 👍 / 👎.

Comment thread pmoves/Makefile

up-archon-native: secrets-runtime-hydrate ## Build+start native Archon (server+mcp+frontend) on local Supabase
@$(ARCHON_NATIVE_DC) up --build -d
.PHONY: up-archon-native down-archon-native archon-native-health

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the restart runbook when removing the config target

Removing archon-native-config leaves pmoves/docs/operations/SUPABASE_SAFE_RESTART_RUNBOOK.md:89 instructing operators to invoke that target, which now fails with “No rule to make target”; the same runbook also still identifies Archon as a Supabase-dependent service on ports 8181/8051/3737, contrary to this new SQLite-native port-3090 flow. Update the runbook alongside this interface change so key-rotation recovery remains executable.

AGENTS.md reference: AGENTS.md:L81-L84

Useful? React with 👍 / 👎.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pmoves/docker-compose.core.yml`:
- Around line 972-978: Document KIMI_CODING_API as the canonical credential for
Kimi coding at api.kimi.com/coding/v1, keeping it separate from MOONSHOT_API_KEY
and removing or updating legacy guidance that tells operators to reuse the
Moonshot key. Add KIMI_CODING_API to operator environment examples and
documentation, and add a Compose-rendering test that supplies distinct Moonshot
and Kimi coding values and verifies each is rendered to its corresponding
setting.

In `@pmoves/Makefile`:
- Around line 1464-1476: Enforce the native Archon contract in ARCHON_NATIVE_DC
and archon-native-health: validate the ../PMOVES-Archon checkout against a
deterministic version/commit pin and verify its docker-compose.yml before
startup, rather than relying on an arbitrary checkout or assumed port mapping.
Update archon-native-health to parse and validate the response status and
version fields, not merely accept HTTP 200; apply the health-check change at
pmoves/Makefile lines 1487-1488 and the checkout/Compose preflight at lines
1464-1476.
- Around line 1475-1476: Quote both ARCHON_NATIVE_DIR-derived arguments in the
ARCHON_NATIVE_DC definition: the value passed to --project-directory and the
docker-compose.yml path, so paths containing spaces remain single shell
arguments for up-archon-native and down-archon-native.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: b90da509-94b4-4937-acb9-2e55bc29ac7f

📥 Commits

Reviewing files that changed from the base of the PR and between 2b6160e and 5d04b6b.

📒 Files selected for processing (3)
  • pmoves/Makefile
  • pmoves/docker-compose.core.yml
  • pmoves/docker-compose.yml

Comment on lines +972 to +978
- MOONSHOT_API_KEY=${MOONSHOT_API_KEY:-local-disabled}
# Kimi Code SUBSCRIPTION key (canonical manifest/tier name, 2026-07-24).
# Read by models.chat_kimi_for_coding on api.kimi.com/coding/v1 — the
# subscription platform is ISOLATED from pay-per-token api.moonshot.ai,
# so this key must NOT be funneled into the legacy Moonshot location
# (it 401s there; verified live).
- KIMI_CODING_API=${KIMI_CODING_API:-local-disabled}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== candidate files =="
git ls-files | rg '(^|/)pmoves/(docs/ROADMAP\.md|docs/NEXT_STEPS\.md|docs/LOCAL_CI_CHECKS\.md|)docker-compose\.core\.yml|tensorzero\.toml|README|\.env|example|schema' | head -200

echo
echo "== referenced KIMI_CODING_API occurrences =="
rg -n "KIMI_CODING_API|Moonshot|moonshot|kimi|models\.chat_kimi_for_coding|local-disabled" pmoves -S || true

echo
echo "== relevant docker-compose section =="
sed -n '930,1005p' pmoves/docker-compose.core.yml

echo
echo "== tensorzero relevant section =="
sed -n '1,180p' pmoves/tensorzero.toml

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 48845


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== env.example sections with APIs =="
for f in pmoves/.env.example pmoves/.env.hybrid.example pmoves/.env.local.example pmoves/.env.supa.local.example pmoves/.env.supa.remote.example pm_moves/.env.example pmoves/env.spark-sidecar.example pmoves/env.shared.example; do
  [ -f "$f" ] || continue
  echo "--- $f ---"
  rg -n -C 2 "^#? *(MOONSHOT_API_KEY|KIMI_API_KEY|KIMI_CODING_API) |local-disabled|Moonshot|KIMI|kimi" "$f" || true
done

echo
echo "== tensorzero model/function config =="
sed -n '180,255p' pmoves/tensorzero/config/tensorzero.toml
sed -n '890,965p' pmoves/tensorzero/config/tensorzero.toml
sed -n '1135,1155p' pmoves/tensorzero/config/tensorzero.toml

echo
echo "== existing compose tests referencing local-disabled or provider keys =="
git ls-files 'pmoves/tests/*' 'tests/*' | xargs rg -n "local-disabled|MOONSHOT_API_KEY|KIMI_CODING_API|KIMI_API_KEY|docker-compose|compose" || true

echo
echo "== secrets manifests for KIMI_CODING_API entries =="
sed -n '1,60p' pmoves/chit/secrets_manifest_v2.yaml
sed -n '920,950p' pmoves/chit/secrets_manifest_v2.yaml

echo
echo "== provider_catalog and profile references =="
sed -n '120,156p' pmoves/config/provider_catalog.yaml
sed -n '25,40p' pmoves/config/profiles/hermes/elder-melchor.yaml
sed -n '130,165p' pmoves/config/profiles/laptop-4090.yaml

echo
echo "== env shared around Moonshot/Kimi =="
sed -n '420,455p' pmoves/env.shared.example

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 50379


Document KIMI_CODING_API as the canonical Kimi coding API key.

KIMI_CODING_API is now the explicit key for api.kimi.com/coding/v1 and is separate from MOONSHOT_API_KEY; the legacy sidecar note still points operators to copy MOONSHOT_API_KEY for Kimi mode. Add KIMI_CODING_API to the operator env examples/docs and include a Compose-rendering test with distinct Moonshot and Kimi coding values.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pmoves/docker-compose.core.yml` around lines 972 - 978, Document
KIMI_CODING_API as the canonical credential for Kimi coding at
api.kimi.com/coding/v1, keeping it separate from MOONSHOT_API_KEY and removing
or updating legacy guidance that tells operators to reuse the Moonshot key. Add
KIMI_CODING_API to operator environment examples and documentation, and add a
Compose-rendering test that supplies distinct Moonshot and Kimi coding values
and verifies each is rendered to its corresponding setting.

Source: Coding guidelines

Comment thread pmoves/Makefile
Comment on lines +1464 to 1476
# Native Archon 0.6.0: TS/SQLite-native, runs from its OWN compose + own env file.
# 0.6.0 upstream rewrote Python -> TypeScript and does NOT use Supabase — it uses
# SQLite by default (~/.archon), or its own Postgres via Archon's `--profile
# with-db`. The server self-allocates port 3090 and IGNORES the compose PORT (PORT
# is not injected into the container), so the published mapping must target 3090.
# Requires the operator to seed Archon's own env file from its example first (that
# file is secrets-domain and not machine-emitted by the PMOVES pipeline).
# See memory project_archon_060_native. Standalone for now; deeper main-compose
# integration is tracked as the "#5 Archon integration" follow-up.
ARCHON_NATIVE_DIR := $(CURDIR)/../PMOVES-Archon
# SUPABASE_URL is injected as a shell-env override scoped to THIS compose only
# (compose precedence: shell env > --env-file). It is deliberately absent from the
# global env.shared so it never clobbers the in-compose ${SUPABASE_URL:-http://supabase-kong:8000}
# default other services use (Codex #1984 P1). host.docker.internal reaches the
# host-published Kong gateway from Archon's standalone compose network.
ARCHON_NATIVE_SUPABASE_URL ?= http://host.docker.internal:8000
ARCHON_NATIVE_DC := SUPABASE_URL=$(ARCHON_NATIVE_SUPABASE_URL) docker compose --env-file $(CURDIR)/env.shared \
ARCHON_NATIVE_PORT ?= 3090
ARCHON_NATIVE_DC := PORT=$(ARCHON_NATIVE_PORT) docker compose \
--project-directory $(ARCHON_NATIVE_DIR) -f $(ARCHON_NATIVE_DIR)/docker-compose.yml

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== roadmap/next checks =="
for f in pmoves/docs/PMOVES.AI\ PLANS/ROADMAP.md pmoves/docs/NEXT_STEPS.md pmoves/docs/LOCAL_CI_CHECKS.md; do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    rg -n "Archon|native|sprint|next|LOCAL_CI|make" "$f" || true
  else
    echo "MISSING $f"
  fi
done

echo "== Makefile native archon section =="
sed -n '1448,1496p' pmoves/Makefile | cat -n

echo "== Locate Archon references =="
rg -n "PMOVES-Archon|archon-native|ARCHON_NATIVE|Archon 0\.6\.0|/api/health" pmoves || true

echo "== Search for version/validation in repo =="
rg -n "0\.6\.0|version.*ok|status.*ok|archon" . --iglob '!node_modules' --iglob '!dist' --iglob '!build' | head -200 || true

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 50380


🌐 Web query:

coleam00 Archon 0.6.0 health endpoint JSON response version status ok

💡 Result:

In the Archon project (coleam00/Archon), the health check endpoint is located at /api/health [1][2]. For modern versions of Archon, this endpoint returns a JSON object with a status of "ok" [3]. The schema for this response includes the following fields [2][4]: status: string (e.g., "ok") adapter: string concurrency: An object containing active, queuedTotal, and maxConcurrent counts [5][6] runningWorkflows: number version: string (optional) [2][7] is_docker: boolean [2][7] activePlatforms: An array of strings representing active adapters (optional) [2][4] The endpoint returns an HTTP 200 status code when the service is healthy [1]. Documentation and tests indicate that the /api/health endpoint is the primary method for verifying the service status [1][3]. Some legacy or simplified references may simply document expected output as {"status":"ok"} [8][3], but the full API implementation provides the more detailed object structure described above [2][4].

Citations:


🌐 Web query:

coleam00 Archon v0.6.0 docker-compose.yml PORT 3090

💡 Result:

In the Archon v0.6.0 deployment and local development environments, port 3090 is the default port for the backend API, but it is typically not the default port when running via Docker Compose [1][2]. 1. Local Development vs. Docker: When running Archon locally (e.g., via bun run dev), the backend server uses port 3090 by default [1][3]. However, when running via Docker Compose, the default port is 3000 [4][1][5]. The Docker Compose configuration utilizes the environment variable PORT, defaulting to 3000 if not specified: ports: - "${PORT:-3000}:${PORT:-3000}" [6][4][5] 2. How to use Port 3090 in Docker: If you specifically need to use port 3090 within the Docker Compose environment, you can override the default by setting the PORT environment variable in your.env file or directly in your environment. You can add the following to your.env file: PORT=3090 Once this is set, running docker compose up will map the container's service to port 3090 on your host machine [4][5]. 3. Important Considerations: - Consistency: If you are using a frontend (like the Vite UI), ensure that the frontend's API URL configuration also points to the port you have assigned to the backend to avoid connectivity issues [7][2]. - Documentation: Always verify your specific setup by checking the.env.example file included in your version of the repository, as configuration defaults can evolve between releases [1][2].

Citations:


Enforce the native Archon contract end to end.

At pmoves/Makefile:1464-1490, the native path relies on an unvalidated ../PMOVES-Archon checkout and assumes the PORT=3090 Compose mapping is the deployed service port. Add a deterministic version/commit pin or preflight validation against ../PMOVES-Archon/docker-compose.yml, and make archon-native-health parse the status/version fields instead of treating HTTP 200 as enough.

📍 Affects 1 file
  • pmoves/Makefile#L1464-L1476 (this comment)
  • pmoves/Makefile#L1487-L1488
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pmoves/Makefile` around lines 1464 - 1476, Enforce the native Archon contract
in ARCHON_NATIVE_DC and archon-native-health: validate the ../PMOVES-Archon
checkout against a deterministic version/commit pin and verify its
docker-compose.yml before startup, rather than relying on an arbitrary checkout
or assumed port mapping. Update archon-native-health to parse and validate the
response status and version fields, not merely accept HTTP 200; apply the
health-check change at pmoves/Makefile lines 1487-1488 and the checkout/Compose
preflight at lines 1464-1476.

Comment thread pmoves/Makefile
Comment on lines +1475 to 1476
ARCHON_NATIVE_DC := PORT=$(ARCHON_NATIVE_PORT) docker compose \
--project-directory $(ARCHON_NATIVE_DIR) -f $(ARCHON_NATIVE_DIR)/docker-compose.yml

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== locate files =="
git ls-files | rg '(^|/)Makefile$|ROADMAP\.md$|NEXT_STEPS\.md$|LOCAL_CI_CHECKS\.md$|\.env.*' | sed -n '1,120p'

echo
echo "== Makefile refs to ARCHON_NATIVE_DC / ARCHON_NATIVE_DIR =="
rg -n "ARCHON_NATIVE_(DC|DIR|PORT)|ARCHON_NATIVE_DC" -S --glob '!vendor/**' .

echo
echo "== pmoves/Makefile relevant lines =="
sed -n '1440,1500p' pmoves/Makefile

echo
echo "== shell word-splitting probe for Make variable expansion in rule commands =="
python3 - <<'PY'
import os
import shlex

paths = [
    "/tmp/check out/pmoves",
    "/tmp/check%20out/pmoves",
    "/tmp/check+out/pmoves",
]
for path in paths:
    cmd = f"PORT=8001 docker compose --project-directory {path} -f {path}/docker-compose.yml"
    print("path:", path)
    print("raw:", cmd)
    print("shlex:", shlex.split(cmd))
    print()
PY

echo
echo "== POSIX make rules are shell-escaped? check make docs availability =="
python3 - <<'PY'
from pathlib import Path
for fn in [Path(".phony-make-bounded"), Path("phony-make-bounded")]:
    print(fn, fn.exists())
PY

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 7712


🌐 Web query:

GNU make manual shell command word splitting quoted strings variable expansion

💡 Result:

In GNU make, the interaction between shell command execution, variable expansion, and word splitting follows specific rules: Shell Function Output Processing When you use the $(shell...) function, GNU make captures the output of the command and performs only one specific transformation: it converts each newline or carriage-return/newline pair into a single space [1][2][3]. It does not perform shell-style word splitting or interpret quoted strings within the captured output itself [1]. If there is a trailing newline, it is removed [1][2]. Variable Expansion and Word Splitting GNU make handles variables as flat strings [4]. When a variable is expanded within a recipe (the command lines of a rule), it is substituted into the command line exactly as it exists in its expanded form [5]. Crucially, after expansion, GNU make does not automatically "re-split" the resulting string into words based on whitespace before passing it to the shell, except in the context of how the shell itself processes the command line [4]. When the recipe is executed, make passes the entire command line string to the shell [5]. It is the shell—not make—that is responsible for interpreting the command line, performing word splitting, and handling quoted strings according to standard POSIX shell rules [5][6]. Key Differences in Context 1. Recipes: Lines in a recipe are passed to the shell. You can use backslashes () at the end of lines to continue a single command across multiple lines in the makefile [5]. Inside the recipe, you can use shell quoting (single or double quotes) to group words that contain spaces or special characters, and the shell will respect these quotes during its own parsing phase [6]. 2. $(shell...) function: The output of this function is treated as a string by make. If you intend to use the output of a $(shell...) command as a list of words for a make-level function (like filter or foreach), make will perform its own word splitting based on whitespace. This make-level word splitting occurs on the result after the newlines have been converted to spaces [1][2]. Summary of Behavior - GNU make itself does not parse shell-style quotes within variables or shell output; it treats them as literal characters [1]. - Shell-style word splitting and quote interpretation are performed by the subshell that executes the command line, not by make [5][6]. - When using the $(shell...) function, any structure or grouping (like quotes) in the command's output is lost because newlines are converted to spaces, turning the output into a flat, space-separated string [1][2].

Citations:


Quote the native Archon Compose paths.

When ARCHON_NATIVE_DIR expands into a path containing spaces, the shell splits docker compose --project-directory ... and docker-compose.yml arguments, breaking up-archon-native and down-archon-native.

Proposed fix
 ARCHON_NATIVE_DC := PORT=$(ARCHON_NATIVE_PORT) docker compose \
-	--project-directory $(ARCHON_NATIVE_DIR) -f $(ARCHON_NATIVE_DIR)/docker-compose.yml
+	--project-directory "$(ARCHON_NATIVE_DIR)" -f "$(ARCHON_NATIVE_DIR)/docker-compose.yml"
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
ARCHON_NATIVE_DC := PORT=$(ARCHON_NATIVE_PORT) docker compose \
--project-directory $(ARCHON_NATIVE_DIR) -f $(ARCHON_NATIVE_DIR)/docker-compose.yml
ARCHON_NATIVE_DC := PORT=$(ARCHON_NATIVE_PORT) docker compose \
--project-directory "$(ARCHON_NATIVE_DIR)" -f "$(ARCHON_NATIVE_DIR)/docker-compose.yml"
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pmoves/Makefile` around lines 1475 - 1476, Quote both
ARCHON_NATIVE_DIR-derived arguments in the ARCHON_NATIVE_DC definition: the
value passed to --project-directory and the docker-compose.yml path, so paths
containing spaces remain single shell arguments for up-archon-native and
down-archon-native.

POWERFULMOVES added a commit that referenced this pull request Jul 25, 2026
The docked archon service had two routes delivering a HOST-shaped
broker address (localhost) into the container: env.tier-agent after a
prod-bundle materialization overwrote node-local values, and a
duplicate ${NATS_URL} list entry whose project-env interpolation wins
as the last occurrence. In-container, localhost:4222 refuses and the
wrapper's startup NATS announce retry-loops the boot (observed live
2026-07-24 while restoring the 5090 docked instance; same class as the
nats-init localhost bug).

Pin the broker in-network (documented default creds convention) via a
fresh override name — the existing ARCHON_NATS_URL/NATS_URL names are
already host-shaped in the sourced layers and would flow through a
default — and drop the duplicate entry.

Context: the in-compose archon is the pre-0.6.0 python wrapper, pulled
from up-agents-stack by #2218 but still deployed docked on nodes (5090
runs it pinned to vendor e4c40759, healthy on 8091/3737 after this
fix). 0.6.0 re-integration: #2217.

Co-authored-by: Shaela Bello <slbello@uncg.edu>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

compose Compose files / service Dockerfiles

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant