Skip to content

Re-land #16397: initialize Cloud VM account pools (migration applied first) - #16572

Merged
lawrencecchen merged 1 commit into
mainfrom
reland-16397-pool-init
Oct 2, 2026
Merged

lawrencecchen merged 1 commit into
mainfrom
reland-16397-pool-init

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Re-lands #16397 (austinywang), which #16405 reverted after a production outage: every Cloud VM create failed with model_plane_unavailable from 2026-10-01 08:44 to 15:47 UTC (30 of 30), because migration 20261001000000_coderouter_vm_pool_initialization was never applied.

The code and migration are unchanged from #16397. The difference is ordering:

  1. Apply the migration to PlanetScale staging, then main (production), with bun run cloud-vm:migrate -- <target>. Verified read-only first: it is the only pending migration on both branches, and the runner selects pending migrations by name, so its earlier folder timestamp does not cause a skip.
  2. Merge this PR only after coderouter_pool_initializations exists in production.

Verification: bun scripts/db-migrate.mjs twice on a fresh Postgres 16 (the CI path), then every coderouter-*db-behavior suite: 73 pass, 0 fail, including #16397's own regression test. bun test tests/coderouter-*: 553 pass, 0 fail. Typecheck clean.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Re-lands Cloud VM account pool initialization, which the previous revert removed after a production outage: Cloud VM creates failed with model_plane_unavailable because the migration had not been applied. This re-land is identical but merges only after the migration is applied to staging and production.

  • Adds coderouter_pool_initializations to mark pools that already received their initial snapshot of the team's shared accounts.
  • The first VM token request after deploy marks the default pool as initialized and inserts its grants.
  • Subsequent token refreshes skip the snapshot, preserving operator removals instead of recreating them.

Written for commit 45c9eec. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Newly initialized default CodeRouter pools now include accounts visible to the team, so VMs can route requests through those accounts without requiring separate pool grants.
    • Team-visible legacy Codex accounts selected for a VM’s pool can now be routed through that VM. Private Codex accounts remain hidden, and removing a pool grant removes the shared account from the VM’s listing.

Reverts #16405. #16397 was reverted because its migration
20261001000000_coderouter_vm_pool_initialization was never applied to
staging or production, so every Cloud VM create failed. This re-land
merges only after that migration is applied to staging and production.

Co-Authored-By: austinywang <austinywang@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6cbecf06-ceae-49b0-b0c8-f1df907087b1

📥 Commits

Reviewing files that changed from the base of the PR and between 7d57a03 and 45c9eec.

📒 Files selected for processing (4)
  • web/db/migrations/20261001000000_coderouter_vm_pool_initialization/migration.sql
  • web/db/schema.ts
  • web/services/coderouter/repository.ts
  • web/tests/coderouter-vm-scope-db-behavior.test.ts
 _______________________________________________________
< Perhaps loot boxes can help us cover the OpenAI bill. >
 -------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 4 files

You’re at about 91% of the monthly reviewed-line limit. You may want to disable incremental reviews to conserve quota. Reviews will continue until that limit is exceeded. If you need help avoiding interruptions, please contact contact@cubic.dev.

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="web/services/coderouter/repository.ts">

<violation number="1" location="web/services/coderouter/repository.ts:475">
P1: These grant queries reread `vm.coderouter_pool_id` after the marker statement, so a concurrent same-team pool reassignment can mark the default pool initialized but grant every shared account to the VM’s new custom pool. Use the pool ID returned by the marker for both inserts, or lock and revalidate the VM’s pool.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic


await tx.execute(sql`
insert into coderouter_pool_accounts (team_id, pool_id, account_id, granted_by_user_id)
select vm.owner_team_id, vm.coderouter_pool_id, account.id, account.created_by

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: These grant queries reread vm.coderouter_pool_id after the marker statement, so a concurrent same-team pool reassignment can mark the default pool initialized but grant every shared account to the VM’s new custom pool. Use the pool ID returned by the marker for both inserts, or lock and revalidate the VM’s pool.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At web/services/coderouter/repository.ts, line 475:

<comment>These grant queries reread `vm.coderouter_pool_id` after the marker statement, so a concurrent same-team pool reassignment can mark the default pool initialized but grant every shared account to the VM’s new custom pool. Use the pool ID returned by the marker for both inserts, or lock and revalidate the VM’s pool.</comment>

<file context>
@@ -449,6 +450,47 @@ export async function issueVmAuthorizationToken(
+
+    await tx.execute(sql`
+      insert into coderouter_pool_accounts (team_id, pool_id, account_id, granted_by_user_id)
+      select vm.owner_team_id, vm.coderouter_pool_id, account.id, account.created_by
+      from cloud_vms vm
+      join coderouter_accounts account on account.team_id = vm.owner_team_id
</file context>

@lawrencecchen
lawrencecchen merged commit 3ec9918 into main Oct 2, 2026
70 of 72 checks passed
@lawrencecchen
lawrencecchen deleted the reland-16397-pool-init branch October 2, 2026 00:41
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Merge receipt for 45c9eec33f: every check was green at merge (18 verified; 19 skipped by policy). Full suite runs on main after merge.

rustybret pushed a commit to rustybret/bmux that referenced this pull request Oct 2, 2026
0bfd027 test(cloud): fix the Cloud header and moved-panel focus tests that never ran (manaflow-ai#16539)
c5c4345 localization: accept numbered placeholders in any order (manaflow-ai#16376)
456edeb fix(settings): replace custom sidebar mockups with real previews (manaflow-ai#16569)
98dc3ab Prototype: cmux Cloud as a remote MCP server (manaflow-ai#16568)
6c22525 test(remote): isolate tmux stale-surface fixture (manaflow-ai#16566)
3ec9918 Re-land "fix(coderouter): initialize Cloud VM account pools (manaflow-ai#16397)" (manaflow-ai#16572)
2b895a5 Fix browser paste routing with terminal text box beta (manaflow-ai#6380) (manaflow-ai#16560)
2bd3455 localization: check Swift defaultValue literals against their catalog en value (manaflow-ai#16396)
c43086e test(cli): expect --mark-read to mark every listed inbox message (manaflow-ai#16537)
fcda4f0 test(feed): wait for zero-wait Codex permission acceptance before checking attention (manaflow-ai#16536)
7d57a03 fix(remote): evict stale persistent SSH bridge leases (manaflow-ai#16558)
d630cb8 docs: add protected-folder diagnostics for tmux sessions (manaflow-ai#12219)
7dceaac test: create cwd fixtures that new terminals now resolve on disk (manaflow-ai#16538)
28cc575 docs: cover surface resume binding CLI contract (manaflow-ai#16473)
5c7dca1 Fix idle zsh PR probes triggering chpwd hooks (manaflow-ai#16553)

# Conflicts:
#	.github/workflows/ci-guards.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant