Skip to content

docs(wish): pgserve-singleton-no-proxy (genie consumer wiring + self-healing update) - #1670

Merged
namastex888 merged 1 commit into
devfrom
wish/pgserve-singleton-no-proxy
May 6, 2026
Merged

namastex888 merged 1 commit into
devfrom
wish/pgserve-singleton-no-proxy

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Companion wish to automagik/pgserve#pgserve-singleton-no-proxy (the big one). Byte-identical SHARED-DESIGN.md.

Summary

Wire genie as clean consumer of pgserve 2.3 singleton. Add tier integration via pgserve verify invocation in connection setup. Make genie update self-healing: pm2 restart self with --update-env, run migrations, invoke genie doctor --fix tiered post-restart. Vendored-pgserve assertion as defensive guard. Compile-time requirements manifest.

Scope

7 execution groups, 3 waves, ~1-2 weeks appetite. See WISH.md.

Test plan

  • genie wish lint pgserve-singleton-no-proxy clean
  • No code changes — doc-only PR

Companion PRs

  • automagik/pgserve#pgserve-singleton-no-proxy
  • automagik/omni#pgserve-singleton-no-proxy

🤖 Generated with Claude Code

Wire genie as clean consumer of pgserve 2.3 singleton. Add tier
integration in db.ts (pgserve verify CLI invocation + HMAC-signed
cache token). Make genie update self-healing: pm2 restart self with
--update-env, run all migrations, invoke genie doctor --fix tiered
post-restart. Vendored-pgserve assertion as defensive guard against
regression. Compile-time requirements manifest.

Companion wishes (paired, byte-identical SHARED-DESIGN.md):
- automagik/pgserve#pgserve-singleton-no-proxy (the big one)
- automagik/omni#pgserve-singleton-no-proxy

7 execution groups, 3 waves, ~1-2 weeks appetite.
@coderabbitai

coderabbitai Bot commented May 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 2f93b613-14b8-4749-b9ce-7887cde0f6fc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch wish/pgserve-singleton-no-proxy

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connector

Copy link
Copy Markdown

💡 Codex Review

- HMAC-cache-token consumer: read `$XDG_STATE_HOME/pgserve/verified/<fp>.token` if present; only call `pgserve verify` on cache miss or mtime change.

P2 Badge Enforce cache-token expiry before skipping verify

The tier-integration scope currently says to run pgserve verify only on cache miss or binary mtime change, but the shared design defines a sliding token expiry window (1h idle / 7d max). If implementation follows this line literally, a token can remain valid indefinitely on long-lived hosts, so revoked or outdated attestations are never re-checked unless the binary changes. Please include expiry validation in the cache-hit path so trust decisions stay fresh.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces the pgserve-singleton-no-proxy design and the corresponding implementation wish for the genie consumer. The architectural shift involves removing the Bun proxy from the data plane in favor of native Postgres transports (Unix socket and TCP 5432) and transitioning pgserve to an on-demand CLI for control operations. Key features include cosign-based publisher attestation, a self-healing update contract for CLIs, tiered doctor --fix modes for automated maintenance, and cross-CLI dependency enforcement. I have no feedback to provide as there are no review comments.

@namastex888
namastex888 merged commit a47380a into dev May 6, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant