Repository navigation
perf(cloud): create New Machine in process - #18700
Open
austinywang wants to merge 48 commits into
Open
austinywang wants to merge 48 commits into
austinywang wants to merge 48 commits into
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
|
Summary
New Machine now creates supported Cloud machines through the authenticated VM client in the app process. The create response carries a snapshot-v2, trusted-carrier attach receipt (route, token field, session, daemon build, and readiness), so the app admits the machine directly, reuses the existing private-network and userspace WireGuard lifecycle, and skips the
cmux vm newsubprocess, full fleet refresh, and redundant attach request. CLI-created machines and unsupported New Machine arguments keep the existing CLI path.The flow keeps one
app-<operation UUID>idempotency key for each logical create, preserves the reserved workspace identity, and continues to use the coordinator's cancellation tombstones, stale-completion fences, cleanup, retry-after-open/attach failure, and account-scope checks. A missing or invalid receipt falls back to the existing provider discovery/attach path. No system VPN or new WireGuard stack was added.Impact map and measurements
The current branch was compared with merged PRs #16787 and #17339, and with historical #13368 and #13030. The active #18672/#16665 activation behavior remains the owner of hub-absent and hub-warming retries; this change does not gate activation or create on a new hub implementation.
Existing provider warm-up, parallel private-network resolution, snapshot-v2 image/attach behavior, and the userspace WireGuard hub/dialer remain in place. The changed path is the app-side handoff after provider create: the receipt populates the registry and marks the trusted carrier, then the existing link method consumes that route once.
Historical control-plane evidence (PR #13368, Freestyle dev backend, n=10) gives the useful before/after bound:
That benchmark reported p90 rather than p95 and described cold startup as about 13 s versus 6–7 s warm before the combined work. PR #17339 measured provider allocation at 1.7–2.7 s and the optimized network-resolution stage at 276–350 ms; that provider allocation remains the material lower bound here. The current request targets the remaining app-side overhead and avoids another attach request, so warm runs should stay near the provider-bound roughly 2 s baseline while cold runs are bounded by provider allocation and hub readiness.
A new live cold/warm p50/p95 run was not safe to execute in this checkout: the authenticated Cloud account currently reports its 40/40 vCPU/memory pool as occupied, and repository policy forbids reloading the user's running cmux to run a tagged dogfood flow. The exact p95 is therefore explicitly left as a hosted/dogfood follow-up rather than inferred from p90/max data.
Testing
Current head:
a84f99ab50d73d6bc2f79d37bc50635dd356b1c4.git diff --checkpassed.7e8efc180d9executed 309 Cloud package tests and failed exactly the two new default-session assertions. The repair usescloudwhile retaining explicit receipt sessions. Hosted verification of the stale-discovery regression is pending.78161443025234210159af29built and published tagpr-18700-cloud-create-v1(artifact digest68e7f09860e3e415bd1ec22f52d8ff43354242ce0c0c791fa6b8c09806ec9228), and the tagged app is launched for dogfood. Live cold/warm p50/p95 measurements remain a separate follow-up.Changelog
Changed: New Machine uses the in-process authenticated create receipt to reach Cloud terminals without redundant app-side subprocess, catalog refresh, or attach work.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Note
Medium Risk
Touches VM create/link/session handoff and workspace lifecycle; mistakes could mis-dial daemons or duplicate workspaces, but fallbacks to CLI/attach and broad test coverage mitigate scope.
Overview
New Machine for supported
vm new/vm openinvocations now runs in-process viaInProcessMachineCreateLauncherandVMClient.create, with stableapp-<operation UUID>idempotency keys passed throughMachineCreateCoordinator. Unsupported arguments still use the CLI launcher.The control plane POST
/api/vmresponse can include anattachsnapshot-v2 receipt (route, session, token, daemon build) plus separate resource fields. The Mac decodes this intoVMSummary.createAttach, registers the machine from the receipt, and consumes the full endpoint on first link—avoiding a fleet refresh and redundant attach round trip when possible. Native links andvm-tui-connectforward the receipt’s daemon session (defaultcloud) instead of hard-codedcmux.Workspace creation keeps the reserved loading pane: manual input is admitted before graph discovery, retries reuse the same reservation (including after window moves), upstream diagnostics are sanitized in the UI, and focus/reveal logic respects admission vs later navigation.
Reviewed by Cursor Bugbot for commit 3b2503c. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
New Machine for supported Cloud create/open flows now runs in the app process via
InProcessMachineCreateLauncherandVMClient.createinstead of shelling out tocmux vm new. Unsupported flows keep the existing CLI path.The create response carries a snapshot-v2 trusted-carrier attach receipt (route, token, session, daemon build, readiness), so the app registers the provider directly and skips the subprocess, full fleet refresh, and redundant attach request.
app-<operation UUID>idempotency key per logical create, so retries reuse the same reserved workspace pane.vm-tui-connectforward the backend session instead of locally reconstructed defaults. Without a receipt, links use the Cloud daemon session default.Written for commit 3b2503c. Summary will update on new commits.
Summary by CodeRabbit