Repository navigation
cmux VM: staging on vm-staging.cmux.dev from feat-cmux-next, cross-tenant smoke, jsonb param fix - #18282
Conversation
…enant smoke Staging deploys and smokes on push to feat-cmux-next (and main), plus a deploy-staging dispatch action that runs check first. Staging answers on workers.dev until its hostname is chosen. smoke.ts takes an optional second tenant key and requires 404 for every call that tenant makes on the first tenant's VM, and no leak in its list.
A create that failed answered 503 with nothing in the Worker logs. Failed queries now log their operation and SQLSTATE, failed provider calls their operation and HTTP status; never ids, parameters, bodies or messages.
postgres.js serializes a parameter the server types as jsonb with JSON.stringify. The stores pass JSON strings, so labels were stored as a jsonb string and every create on staging failed resources_labels_check (SQLSTATE 23514, now visible in the Worker log). Casting $n::text::jsonb makes the parameter text, which the driver passes as is.
Workers custom domains in the cmux.dev zone (CMUX-VM-API amendment 2). Staging leaves workers.dev; production attaches its domain on its first deploy. The OpenAPI servers name the new hosts.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The provider account is shared, so resources this service creates are now named cmux-vm-<environment> <tenant> <cmux id> (VMs, snapshots, fork snapshots, networks, tunnels). The environment comes from ENVIRONMENT at the composition root and is required by every upstream client.
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37586437879 at a16b9e0 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37586751376 at 5107871 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
Landed on feat-cmux-next by safe-push as a merge: bdb097c (this PR plus the environment name prefix), then e3c0c61 (custom domains attached through the Workers domains API, because wrangler routes needed a zone permission the token lacks). Push-triggered staging deploy and smoke on e3c0c61: https://github.com/manaflow-ai/cmux/actions/runs/37586997717 (all passed on https://vm-staging.cmux.dev, including the tenant B 404 checks). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37586913855 at e4da892 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37586965300 at 8b1c329 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37587042315 at 6a753c9 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37587935376 at a53b04b failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37588003146 at b472aa1 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37587147561 at 9ec0d03 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37588244794 at 8eee20c failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37586861355 at 8d69556 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
Deploys the cmux VM staging Worker from feat-cmux-next and proves tenant isolation live.
.github/workflows/cmux-vm.yml: staging deploy and smoke run on push tofeat-cmux-next(andmain), plus adeploy-stagingdispatch action that runscheckfirst.wrangler.jsonc: staging is the Workers custom domainvm-staging.cmux.dev(workers.dev off). Production gets the routevm.cmux.dev, which attaches on its first deploy. The OpenAPI servers use the new hosts (CMUX-VM-API amendment 2).scripts/smoke.ts: withCMUX_VM_SMOKE_API_KEY_B, a second tenant must get 404 on GET, exec, pause, stop, fork and delete of the first tenant's VM, and must not see it in its list.resources_labels_check(SQLSTATE 23514). The JSON parameters now cast$n::text::jsonb. PGlite in the tests does not show this behavior.Spec note: decisions.md line 1008 says staging Workers have no Freestyle secret. The chief decided (2026-10-07) to give staging the cmux-next dev Freestyle key, on the shared account, with deletes only by exact id. The chief will amend decisions.md.
Evidence: run https://github.com/manaflow-ai/cmux/actions/runs/37583690978 at 7dabdcf. It contains feat-cmux-next 4d8998d. check, deploy-staging and smoke-staging all passed on https://vm-staging.cmux.dev. The smoke VM was deleted by its exact id.
Not done: the SDK
DEFAULT_BASE_URLand the Rust client/CLI default still namevm.cmux.com. Those files are generated, so the S4 owner regenerates them.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Deploys the cmux VM staging Worker from
feat-cmux-nexttovm-staging.cmux.devand proves tenant isolation live with a cross-tenant smoke run. Also fixes a jsonb parameter bug that failed every create with 503 on real Postgres.Staging deploy
feat-cmux-nextormain, plus adeploy-stagingdispatch action that runscheckfirst.vm-staging.cmux.dev; production attachesvm.cmux.devon its first deploy.cmux-vm-<environment> <tenant> <cmux id>so resources on the shared provider account are attributable to this service.Bug fix
resources_labels_check(SQLSTATE 23514). JSON parameters now cast$n::text::jsonb.Written for commit bdb097c. Summary will update on new commits.
Note
Medium Risk
Changes staging deploy triggers, custom domains, and a data-layer jsonb binding fix that unblocks creates on real Postgres; cross-tenant smoke increases confidence in isolation but touches CI secrets and live staging.
Overview
Staging deploy and live tenant isolation. CI now deploys and smokes the cmux VM staging Worker on push to
feat-cmux-nextormain, adds a manualdeploy-stagingworkflow dispatch (runscheckfirst), and wires staging to the custom domainvm-staging.cmux.dev(workers_devoff; production routevm.cmux.devis declared for first prod deploy).Cross-tenant smoke. When
CMUX_VM_SMOKE_API_KEY_Bis set,scripts/smoke.tsasserts a second tenant gets 404 on every read/mutation against the first tenant's VM and never sees it in list.Postgres jsonb fix. JSON bind parameters now cast as
$n::text::jsonbacross stores so real Postgres/Hyperdrive does not double-encode labels and failresources_labels_check(staging was 503 on every create).Upstream naming and ops logging. Provider display names use
cmux-vm-<environment> <tenant> <id>vianaming.ts. Failed DB queries log operation + SQLSTATE; failed upstream calls log operation + HTTP status, without ids or secrets.Reviewed by Cursor Bugbot for commit bdb097c. Bugbot is set up for automated code reviews on this repo. Configure here.