Repository navigation
cloud: static model-plane env baked into the snapshot; create writes nothing into the guest - #11813
Merged
Merged
Conversation
…nothing into the guest The guest env (base URLs, placeholder keys) is now the same bytes for every machine: agents dial one alias host, coderouter.cmux.internal, and the machine's TLS edge rule terminates that name at the edge, forwards to this deployment's API host (destinationHost), and adds the route token header. The bake writes /etc/cmux/model-plane.env and agent-config.sh falls back to it when no boot env and no per-home file exist. The per-machine file write at create and restore is gone, and so is CMUX_VM_ID in the guest (nothing read it; the edge already stamps the machine id on every request). Spiked on Freestyle first: a rule for the alias with destination host cmux.com:443 answers exactly like the direct host from inside a machine.
…ll materializes from it
…ix sizes, both kinds
|
Warning Review limit reachedNext included review available in 4 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (17)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
|
All contributors have signed the CLA ✍️ ✅ |
rustybret
pushed a commit
to rustybret/bmux
that referenced
this pull request
Sep 3, 2026
4e30be8 cloud: compact access screen with the app icon (manaflow-ai#11819) 2558039 fix(cmux-tui): restore rustfmt import order (manaflow-ai#11808) f4e3d4f Keep client identity cache responsive during file lock waits (manaflow-ai#11795) 69dfcd1 fix(cmux-tui): make workspace clippy green and lint in every hosted lane (manaflow-ai#11796) 0f19be0 cloud: static model-plane env baked into the snapshot; create writes nothing into the guest (manaflow-ai#11813) c03ec18 cloud: add authenticated public VM domains (manaflow-ai#11692) e4325ab fix(cmux-tui): validate relay CLI values # Conflicts: # .github/workflows/cmux-tui.yml
lawrencecchen
added a commit
that referenced
this pull request
Sep 3, 2026
…nothing into the guest (#11813) * cloud: static model-plane env baked into the snapshot; create writes nothing into the guest The guest env (base URLs, placeholder keys) is now the same bytes for every machine: agents dial one alias host, coderouter.cmux.internal, and the machine's TLS edge rule terminates that name at the edge, forwards to this deployment's API host (destinationHost), and adds the route token header. The bake writes /etc/cmux/model-plane.env and agent-config.sh falls back to it when no boot env and no per-home file exist. The per-machine file write at create and restore is gone, and so is CMUX_VM_ID in the guest (nothing read it; the edge already stamps the machine id on every request). Spiked on Freestyle first: a rule for the alias with destination host cmux.com:443 answers exactly like the direct host from inside a machine. * docs: the model plane is an alias the edge routes; the guest env is baked * bake: write the static model-plane env last; verify the configs a shell materializes from it * verify: import the alias domain * cloud: promote the 20260903d ladder (static model-plane env baked), six sizes, both kinds
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The last Freestyle call on the create path that was not the create itself: the per-machine model-plane env file write (
vm.fs.writeTextFile, 33 to 83 ms, plus a second one on restore). Gone.What "model-plane env" is. The environment variables the coding agents inside a machine read to reach models:
OPENAI_BASE_URL,ANTHROPIC_BASE_URL,CMUX_CODEROUTER_URL, and placeholder API keys. They point at coderouter through the machine's TLS edge rule, which injects the real route token. Until now the file also carriedCMUX_VM_IDand the deployment's real API host, so it was per machine and per environment and had to be written at create.Why it can be static. The guest now dials one alias host,
coderouter.cmux.internal. The machine's edge rule (written inline byvms.create, as before) terminates that name at the platform edge and forwards to this deployment's API host (destinationHost, new onVmEdgeRule) with the token headers. Spiked on Freestyle before writing code: from inside a machine, the alias and the direct host return byte-identical status for the same route, so Host is handled. Prod, staging, and previews differ only in the rule's destination.CMUX_VM_IDhad no consumer in the guest (only the self-check grepped it) and the edge already stampsx-cmux-vm-idon every request.What changed.
services/coderouter/vmGuestEnv.ts(dependency-free) owns the alias, the env, and the file renderer. The bake writes/etc/cmux/model-plane.envas its last layer andagent-config.shfalls back to it when no boot env and no per-home file exist. The verifier asserts the baked file and that a shell with no boot env derives codex and pi configs pointing at the alias with no token.CreateOptions.envs,writeModelPlaneEnv, and the driver's renderer are deleted. Ladderfreestyle-cmux-devbox-20260903d(six sizes, both kinds) baked from this branch is the default;20260903cstays for rollback.Create is now
vms.create(firewall, VPC, TLS rule inline) and nothing else on Freestyle, plus the grow-only resize for a size-less image. Expected in production:provider_createabout 300 ms, nofs/writespan.Summary by cubic
The per-machine model-plane env write at create and restore is gone; the env is now identical for every machine and baked into the devbox snapshot, so create writes nothing into the guest.
coderouter.cmux.internal); the machine's TLS edge rule forwards it to the deployment's API host via the newdestinationHostfield and adds the route token headers.CreateOptions.envsand the driver'swriteModelPlaneEnvare deleted, and the guest no longer getsCMUX_VM_ID(nothing read it; the edge already stamps the machine id on every request)./etc/cmux/model-plane.env;agent-config.shfalls back to it when no boot env and no per-home file exist.freestyle-cmux-devbox-20260903d(six sizes, both kinds);20260903cstays listed for rollback.Written for commit fcdeb9b. Summary will update on new commits.