Skip to content

feat(docker): review isolated fleet packaging and policy sync - #11

Draft
ZiaLothbrook wants to merge 1 commit into
TechNickAI:nick/upgrade-v3.8.51-rebase-20260922from
DeepGem-Interactive:feat/fleet-review
Draft

ZiaLothbrook wants to merge 1 commit into
TechNickAI:nick/upgrade-v3.8.51-rebase-20260922from
DeepGem-Interactive:feat/fleet-review

Conversation

@ZiaLothbrook

Copy link
Copy Markdown

Summary

Add an opt-in fleet Docker and policy-sync toolkit for collaboration and review. Everything lives under scripts/docker/fleet-review/, with three focused test files and a usage guide. All 18 files are additions; existing application code, root dependencies, Docker defaults, and workflows are unchanged.

The builder fetches public upstream source at a verified full SHA (TechNickAI/OmniRoute@486509c71b9890914d78cf2c83a22f967fbb635e) into a temporary directory outside the checkout. Registry namespace and image provenance are configurable. Builds load locally and do not publish. Compose binds the API to 127.0.0.1:21128, keeps Redis private, and generates fresh instance secrets separately from the image.

Policy sync uses the existing management API for explicit connection pools per key, restricted combos, rate limits, protected identities, and capability overrides. It provides validation, dry-run, and guarded apply with inventory readback. The example has synthetic identities, no provider connections, and all keys disabled.

This is a draft for review, based on the agreed September 22 v3.8.51 branch. Nothing has been merged or deployed. No real provider accounts were connected. Private requirements, account maps, credentials, databases, backups, deployment details, and private repository history are excluded.

Related Issues

No linked issue; collaboration review.

Validation

  • Change type: build-deploy / standalone management tooling.
  • Reconciled with nick/upgrade-v3.8.51-rebase-20260922 at 486509c71b9890914d78cf2c83a22f967fbb635e.
  • node --test tests/unit/fleet-*.test.mjs: 27 passed.
  • Disposable native ARM64 Docker smoke against an existing image built from the exact upstream pin: 8 groups passed — fresh boot; non-root/authentication; native SQLite; endpoint-key separation from management; persistence across container replacement; empty-policy dry-run; explicit pool grants/rate limits/route denials and idempotent sync; protected-identity shutdown. Synthetic records have no provider credentials; no provider inference calls were made. This validates the exported harness against the pinned runtime, not a newly published image from this PR.
  • Compose configuration: loopback ports, mandatory authentication, private Redis network, and expected volume names.
  • npm run check:build-scope, npm run check:lockfile, and npm run check:pack-policy.
  • Nested dependency lockfile validation; npm audit --prefix scripts/docker/fleet-review --omit=dev: 0 vulnerabilities.
  • Changed-test ESLint, Prettier, documentation frontmatter/links, deprecated-version and fabricated-docs checks.
  • Husky identity, staged lint/format, docs-sync, any-budget, tracked-artifacts, and commit-message gates. Automatic lint-staged stash was disabled to honor the repository's no-stash rule; hooks were not bypassed.
  • Diff/privacy review: only the 18 intended additions; sensitive-file ignore rules checked; no private account or host information.
  • Full repository lint/docs are not green on the selected base; details below. Broad application suites and coverage were not rerun for this additive draft.

Existing baseline findings left untouched: open-sse/executors/base.ts has seven unused-binding lint errors; ESLint also reports stale suppressions. check:docs-all fails on the existing 178-versus-181 migration counts in README, AGENTS, and llm.txt. Environment-doc validation reports existing DEEP_HEALTH_CHECK_ENABLED and CLAUDE_CC_ENTRYPOINT gaps; after installing the optional toolkit dependencies, its recursive scanner also sees the YAML library's LOG_STREAM/LOG_TOKENS diagnostics. None of those upstream files are changed here.

Tests Added Or Updated

  • tests/unit/fleet-build.test.mjs: exact source pin, detached checkout, build-label/secret isolation, external scratch paths.
  • tests/unit/fleet-init.test.mjs: independent private secrets, no overwrite, symlink refusal.
  • tests/unit/fleet-policy.test.mjs: pool boundaries, protected identities, route restrictions, validation, idempotency, inventory races, and failure shutdown.

Coverage Notes

No production files in src/, open-sse/, electron/, or bin/ changed. No coverage claim or baseline update is made.

Reviewer Notes

Start with docs/guides/FLEET_DOCKER.md and the synthetic policy example. Review the explicit key allowlists and the disable/update/readback/activate sequence in fleet-policy.mjs.

Apply is an operator maintenance action that requires drained clients and management authority. It updates managed fleet: keys and sets the extra-usage block on all Claude connections, including unbound ones. Emergency activation remains blocked pending quota-only fallback and per-use alert integration. Budget/no-training declarations do not provide provider-side enforcement. Runtime secrets, real policy, sync state, and backups must remain private; backups and sync state belong outside the checkout.

The fork has Actions disabled and this PR adds no workflow. Review does not require access to anyone else's image registry, accounts, or running router; a reviewer can build the pinned public source locally.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant