Skip to content

cloud: static model-plane env baked into the snapshot; create writes nothing into the guest - #11813

Merged
lawrencecchen merged 5 commits into
mainfrom
feat-static-model-plane
Sep 3, 2026
Merged

lawrencecchen merged 5 commits into
mainfrom
feat-static-model-plane

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

The last Freestyle call on the create path that was not the create itself: the per-machine model-plane env file write (vm.fs.writeTextFile, 33 to 83 ms, plus a second one on restore). Gone.

What "model-plane env" is. The environment variables the coding agents inside a machine read to reach models: OPENAI_BASE_URL, ANTHROPIC_BASE_URL, CMUX_CODEROUTER_URL, and placeholder API keys. They point at coderouter through the machine's TLS edge rule, which injects the real route token. Until now the file also carried CMUX_VM_ID and the deployment's real API host, so it was per machine and per environment and had to be written at create.

Why it can be static. The guest now dials one alias host, coderouter.cmux.internal. The machine's edge rule (written inline by vms.create, as before) terminates that name at the platform edge and forwards to this deployment's API host (destinationHost, new on VmEdgeRule) with the token headers. Spiked on Freestyle before writing code: from inside a machine, the alias and the direct host return byte-identical status for the same route, so Host is handled. Prod, staging, and previews differ only in the rule's destination. CMUX_VM_ID had no consumer in the guest (only the self-check grepped it) and the edge already stamps x-cmux-vm-id on every request.

What changed. services/coderouter/vmGuestEnv.ts (dependency-free) owns the alias, the env, and the file renderer. The bake writes /etc/cmux/model-plane.env as its last layer and agent-config.sh falls back to it when no boot env and no per-home file exist. The verifier asserts the baked file and that a shell with no boot env derives codex and pi configs pointing at the alias with no token. CreateOptions.envs, writeModelPlaneEnv, and the driver's renderer are deleted. Ladder freestyle-cmux-devbox-20260903d (six sizes, both kinds) baked from this branch is the default; 20260903c stays for rollback.

Create is now vms.create (firewall, VPC, TLS rule inline) and nothing else on Freestyle, plus the grow-only resize for a size-less image. Expected in production: provider_create about 300 ms, no fs/write span.


Summary by cubic

The per-machine model-plane env write at create and restore is gone; the env is now identical for every machine and baked into the devbox snapshot, so create writes nothing into the guest.

  • Agents dial one alias host (coderouter.cmux.internal); the machine's TLS edge rule forwards it to the deployment's API host via the new destinationHost field and adds the route token headers.
  • CreateOptions.envs and the driver's writeModelPlaneEnv are deleted, and the guest no longer gets CMUX_VM_ID (nothing read it; the edge already stamps the machine id on every request).
  • The bake writes /etc/cmux/model-plane.env; agent-config.sh falls back to it when no boot env and no per-home file exist.
  • The default image ladder is now freestyle-cmux-devbox-20260903d (six sizes, both kinds); 20260903c stays listed for rollback.

Written for commit fcdeb9b. Summary will update on new commits.

Review in cubic

…nothing into the guest

The guest env (base URLs, placeholder keys) is now the same bytes for every
machine: agents dial one alias host, coderouter.cmux.internal, and the
machine's TLS edge rule terminates that name at the edge, forwards to this
deployment's API host (destinationHost), and adds the route token header.
The bake writes /etc/cmux/model-plane.env and agent-config.sh falls back to
it when no boot env and no per-home file exist. The per-machine file write
at create and restore is gone, and so is CMUX_VM_ID in the guest (nothing
read it; the edge already stamps the machine id on every request).

Spiked on Freestyle first: a rule for the alias with destination host
cmux.com:443 answers exactly like the direct host from inside a machine.
@vercel

vercel Bot commented Sep 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cmux166 Building Building Preview Sep 3, 2026 6:22am UTC
cmux41 Building Building Preview Sep 3, 2026 6:22am UTC

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 4 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: e7ae050d-2aae-4861-a1e7-ea2490c8a743

📥 Commits

Reviewing files that changed from the base of the PR and between c03ec18 and fcdeb9b.

📒 Files selected for processing (17)
  • web/scripts/build-devbox-freestyle.ts
  • web/scripts/verify-devbox-image.ts
  • web/services/coderouter/routeTokenAuth.ts
  • web/services/coderouter/vmGuestEnv.ts
  • web/services/coderouter/vmModelPlane.ts
  • web/services/vms/README.md
  • web/services/vms/drivers/freestyle.ts
  • web/services/vms/drivers/types.ts
  • web/services/vms/images/devbox/agent-config.sh
  • web/services/vms/images/manifest.json
  • web/services/vms/workflows.ts
  • web/tests/coderouter-vm-model-plane.test.ts
  • web/tests/vm-devbox-image.test.ts
  • web/tests/vm-freestyle-provider.test.ts
  • web/tests/vm-guest-env.test.ts
  • web/tests/vm-image-resolver.test.ts
  • web/tests/vm-model-plane-workflow.test.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@lawrencecchen
lawrencecchen merged commit 0f19be0 into main Sep 3, 2026
10 of 12 checks passed
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 3, 2026
4e30be8 cloud: compact access screen with the app icon (manaflow-ai#11819)
2558039 fix(cmux-tui): restore rustfmt import order (manaflow-ai#11808)
f4e3d4f Keep client identity cache responsive during file lock waits (manaflow-ai#11795)
69dfcd1 fix(cmux-tui): make workspace clippy green and lint in every hosted lane (manaflow-ai#11796)
0f19be0 cloud: static model-plane env baked into the snapshot; create writes nothing into the guest (manaflow-ai#11813)
c03ec18 cloud: add authenticated public VM domains (manaflow-ai#11692)
e4325ab fix(cmux-tui): validate relay CLI values

# Conflicts:
#	.github/workflows/cmux-tui.yml
lawrencecchen added a commit that referenced this pull request Sep 3, 2026
…nothing into the guest (#11813)

* cloud: static model-plane env baked into the snapshot; create writes nothing into the guest

The guest env (base URLs, placeholder keys) is now the same bytes for every
machine: agents dial one alias host, coderouter.cmux.internal, and the
machine's TLS edge rule terminates that name at the edge, forwards to this
deployment's API host (destinationHost), and adds the route token header.
The bake writes /etc/cmux/model-plane.env and agent-config.sh falls back to
it when no boot env and no per-home file exist. The per-machine file write
at create and restore is gone, and so is CMUX_VM_ID in the guest (nothing
read it; the edge already stamps the machine id on every request).

Spiked on Freestyle first: a rule for the alias with destination host
cmux.com:443 answers exactly like the direct host from inside a machine.

* docs: the model plane is an alias the edge routes; the guest env is baked

* bake: write the static model-plane env last; verify the configs a shell materializes from it

* verify: import the alias domain

* cloud: promote the 20260903d ladder (static model-plane env baked), six sizes, both kinds

This branch was successfully deployed

2 active deployments
Preview – cmux166 — fcdeb9bd Deployed Sep 3, 2026 by vercel[bot]
Preview – cmux41 — fcdeb9bd Deployed Sep 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant