Repository navigation
feat(docker): review isolated fleet packaging and policy sync - #11
Draft
ZiaLothbrook wants to merge 1 commit into
Draft
ZiaLothbrook wants to merge 1 commit into
ZiaLothbrook wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add an opt-in fleet Docker and policy-sync toolkit for collaboration and review. Everything lives under
scripts/docker/fleet-review/, with three focused test files and a usage guide. All 18 files are additions; existing application code, root dependencies, Docker defaults, and workflows are unchanged.The builder fetches public upstream source at a verified full SHA (
TechNickAI/OmniRoute@486509c71b9890914d78cf2c83a22f967fbb635e) into a temporary directory outside the checkout. Registry namespace and image provenance are configurable. Builds load locally and do not publish. Compose binds the API to127.0.0.1:21128, keeps Redis private, and generates fresh instance secrets separately from the image.Policy sync uses the existing management API for explicit connection pools per key, restricted combos, rate limits, protected identities, and capability overrides. It provides validation, dry-run, and guarded apply with inventory readback. The example has synthetic identities, no provider connections, and all keys disabled.
This is a draft for review, based on the agreed September 22 v3.8.51 branch. Nothing has been merged or deployed. No real provider accounts were connected. Private requirements, account maps, credentials, databases, backups, deployment details, and private repository history are excluded.
Related Issues
No linked issue; collaboration review.
Validation
nick/upgrade-v3.8.51-rebase-20260922at486509c71b9890914d78cf2c83a22f967fbb635e.node --test tests/unit/fleet-*.test.mjs: 27 passed.npm run check:build-scope,npm run check:lockfile, andnpm run check:pack-policy.npm audit --prefix scripts/docker/fleet-review --omit=dev: 0 vulnerabilities.Existing baseline findings left untouched:
open-sse/executors/base.tshas seven unused-binding lint errors; ESLint also reports stale suppressions.check:docs-allfails on the existing 178-versus-181 migration counts in README, AGENTS, and llm.txt. Environment-doc validation reports existingDEEP_HEALTH_CHECK_ENABLEDandCLAUDE_CC_ENTRYPOINTgaps; after installing the optional toolkit dependencies, its recursive scanner also sees the YAML library'sLOG_STREAM/LOG_TOKENSdiagnostics. None of those upstream files are changed here.Tests Added Or Updated
tests/unit/fleet-build.test.mjs: exact source pin, detached checkout, build-label/secret isolation, external scratch paths.tests/unit/fleet-init.test.mjs: independent private secrets, no overwrite, symlink refusal.tests/unit/fleet-policy.test.mjs: pool boundaries, protected identities, route restrictions, validation, idempotency, inventory races, and failure shutdown.Coverage Notes
No production files in
src/,open-sse/,electron/, orbin/changed. No coverage claim or baseline update is made.Reviewer Notes
Start with
docs/guides/FLEET_DOCKER.mdand the synthetic policy example. Review the explicit key allowlists and the disable/update/readback/activate sequence infleet-policy.mjs.Apply is an operator maintenance action that requires drained clients and management authority. It updates managed
fleet:keys and sets the extra-usage block on all Claude connections, including unbound ones. Emergency activation remains blocked pending quota-only fallback and per-use alert integration. Budget/no-training declarations do not provide provider-side enforcement. Runtime secrets, real policy, sync state, and backups must remain private; backups and sync state belong outside the checkout.The fork has Actions disabled and this PR adds no workflow. Review does not require access to anyone else's image registry, accounts, or running router; a reviewer can build the pinned public source locally.