Skip to content

feat(deploy): 將 governance-service 納入 deploy 啟動 - #215

Merged
monkey1sai merged 3 commits into
mainfrom
docs/governance-service-deploy-spec
Jun 16, 2026
Merged

monkey1sai merged 3 commits into
mainfrom
docs/governance-service-deploy-spec

Conversation

@monkey1sai

Copy link
Copy Markdown
Owner

Summary

  • 在 deploy.ps1 -Build 啟動 host-native governance-service,使用 uvicorn 監聽 127.0.0.1:49102。
  • 將 HOST_GOVERNANCE_API_BASE 傳入 Docker coordinator,並在治理 port 變更時刷新 web plane。
  • 補 stop-all、dry-run audit、static deploy checks、Superpowers spec/plan 與 spec-to-done 狀態。

Validation

  • powershell -NoProfile -ExecutionPolicy Bypass -File scripts\tests\test-deploy-governance-static.ps1
  • powershell -NoProfile -ExecutionPolicy Bypass -File scripts\tests\test-deploy-dryrun.ps1
  • 先前完整驗證:deploy.ps1 -Build -SkipKit -SkipConversion -StrictPostVerify passed
  • 先前 browser evidence:npm run test:e2e -- --project=chromium e2e/a1-m1-closeout.spec.ts passed

Deploy Path Verification

Item Result
deploy path scripts/deploy.ps1 -Build starts governance-service unless -SkipGovernance
governance health http://127.0.0.1:49102/health returned 200 in smoke run
coordinator proxy http://127.0.0.1:8004/api/governance/files/tree returned 200 in smoke run
opt-out -SkipGovernance documented in dry-run audit
custom port -GovernancePort refreshes Docker coordinator env

Frontend Verification

Item Result
Frontend URL http://127.0.0.1:5173 during prior A1/M1 E2E
Buttons tested A1/M1 closeout flow and rerun controls via Playwright
Test fixture used existing A1/M1 E2E fixture
Expected visible result five-step stepper and failure component drawer remained operable
E2E command npm run test:e2e -- --project=chromium e2e/a1-m1-closeout.spec.ts
Screenshot evidence path artifacts/e2e/a1-m1-closeout-flow.png; artifacts/e2e/a1-m1-closeout-rerun.png
Known limitations GitNexus detect_changes returned No changes detected despite dirty linked worktree; treated as unavailable for this worktree

Add host-native uvicorn startup for governance-service in deploy.ps1 -Build, wire HOST_GOVERNANCE_API_BASE into the Docker coordinator, and document the spec-to-done plan/evidence state.

Validation: test-deploy-governance-static.ps1 and test-deploy-dryrun.ps1 pass.
Copilot AI review requested due to automatic review settings June 16, 2026 05:11
@coderabbitai

coderabbitai Bot commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@monkey1sai, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 32 minutes and 52 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 8d651706-91a3-4e0c-ad66-7395c8fca311

📥 Commits

Reviewing files that changed from the base of the PR and between 706d700 and 205a38c.

📒 Files selected for processing (14)
  • artifacts/spec-to-done/governance-service-deploy-state.md
  • artifacts/spec-to-done/governance-service-deploy/plan.md
  • artifacts/spec-to-done/governance-service-deploy/tasks.md
  • docs/superpowers/plans/2026-06-16-governance-service-deploy.md
  • docs/superpowers/specs/2026-06-16-governance-service-deploy-design.md
  • openspec/changes/governance-service-deploy/design.md
  • openspec/changes/governance-service-deploy/proposal.md
  • openspec/changes/governance-service-deploy/specs/one-click-deploy-hybrid/spec.md
  • openspec/changes/governance-service-deploy/tasks.md
  • scripts/deploy.ps1
  • scripts/lib/host-native-launcher.ps1
  • scripts/stop-all.ps1
  • scripts/tests/test-deploy-dryrun.ps1
  • scripts/tests/test-deploy-governance-static.ps1
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/governance-service-deploy-spec

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status blocked
Risk high
PR 215
Head docs/governance-service-deploy-spec / f273af6b464aef551c7e44416af26b85d6dce1b6
Base main / 706d7009f62eb447ba8deba2e256b5de2bb57203

Blockers

  • [high] Behavior, workflow, code, or repo-boundary changes require an OpenSpec change id or documented exception.

Warnings

  • [medium] GitNexus detect changes did not pass: warning.

Validation Commands

  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-pr-review-agent.ps1

Checks

  • passed script-level PR review agent tests (scripts)

Human Review Notes

  • Optional AI adapter is not required by policy and was skipped.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR integrates the governance-service into the canonical deploy.ps1 -Build hybrid deploy workflow so that the A1/M1 closeout UI can be operated from a single deploy command without requiring a second terminal. The governance service runs as a host-native Python/uvicorn process on 127.0.0.1:49102, with the Docker coordinator connecting to it via host.docker.internal.

Changes:

  • Adds Start-HostNativeGovernance to the host-native launcher, wires governance lifecycle into deploy Phase 4a (with new -SkipGovernance / -GovernancePort parameters, runtime signature management, port audit integration, Docker env injection, and Phase 5 health verification), and updates stop-all.ps1 to manage the service.
  • Extends existing dry-run and static deploy tests to cover governance audit fields, skip state, and custom port scenarios, and adds a new static contract test for governance integration.
  • Adds comprehensive spec design, implementation plan, and spec-to-done state/task tracking documentation.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
scripts/lib/host-native-launcher.ps1 Adds Start-HostNativeGovernance function following existing launcher patterns (Python312 resolution, import sanity check, env var setup, delegation to Start-HostNativeService)
scripts/deploy.ps1 Adds -SkipGovernance/-GovernancePort params, governance runtime signature, port audit integration, Phase 4a governance lifecycle, Docker HOST_GOVERNANCE_API_BASE injection, Phase 5 governance/proxy probes, web-plane refresh trigger, and audit fields; renumbers existing phases 4a→4b, 4b→4c, 4c→4d
scripts/stop-all.ps1 Adds governance-service with port 49102 to expected services list
scripts/tests/test-deploy-governance-static.ps1 New static contract test verifying governance integration points across deploy, launcher, and stop-all scripts
scripts/tests/test-deploy-dryrun.ps1 Extends dry-run audit tests to verify governance port, skip state, Docker base URL, and custom port recording
docs/superpowers/specs/2026-06-16-governance-service-deploy-design.md Design spec covering architecture, deploy behavior, launcher, compose/env, stop-all, testing, and risks
docs/superpowers/plans/2026-06-16-governance-service-deploy.md Step-by-step implementation plan with 9 tasks covering all changed files
artifacts/spec-to-done/governance-service-deploy/tasks.md Spec-to-done task checklist tracking implementation progress
artifacts/spec-to-done/governance-service-deploy/plan.md Spec-to-done execution plan with gate summaries
artifacts/spec-to-done/governance-service-deploy-state.md Spec-to-done phase state tracking (P0–P7)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +32 to +36
$audit = Get-Content -LiteralPath $auditJson -Raw | ConvertFrom-Json
Assert-Equal 49102 $audit.runtime.governancePort 'default governance port is 49102'
Assert-Equal $false $audit.runtime.governanceSkipped 'default governance is not skipped'
Assert-Equal 'http://host.docker.internal:49102' $audit.runtime.governanceApiBaseForDocker 'default Docker governance base URL'
Write-TestPass 'governance dry-run audit defaults'
Comment on lines +1 to +2
Set-StrictMode -Version Latest
$ErrorActionPreference = 'Stop'

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f273af6b46

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/deploy.ps1
Comment on lines +605 to +612
$resolvedGovernancePort = Resolve-DeployIntValue `
-Name 'GOV_PORT' `
-EnvFile $resolvedEnvFile `
-Default 49102 `
-ExplicitValue $GovernancePort `
-HasExplicitValue:($PSBoundParameters.ContainsKey('GovernancePort')) `
-Min 1 `
-Max 65535

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject governance ports that collide with runtime ports

When -GovernancePort/GOV_PORT is set to an already-reserved runtime port such as 49100 (Kit signaling), 49101 (conversion), or the default spectator range starting at 49110, the preflight still reports the port as free because it only checks current listeners and then governance binds it first in Phase 4a. The later Kit/conversion start then fails or loses that listener, so this needs an explicit collision check against the resolved Kit, conversion, and spectator ports before starting services.

Useful? React with 👍 / 👎.

Comment on lines +225 to +228
Remove-Item Env:PYTHONNOUSERSITE -ErrorAction SilentlyContinue
& $pythonExe -c "import ifcopenshell, fastapi, uvicorn" *> $null
if ($LASTEXITCODE -ne 0) {
throw "governance-service Python cannot import ifcopenshell, fastapi, and uvicorn: $pythonExe"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Install or check governance-only Python dependencies

In the fallback path where C:\Program Files\Python312\python.exe is absent and the deploy-created repo .venv is used, Phase 2 only installs bim-streaming-server\requirements.txt; that file does not include openpyxl, but governance-service/app.py imports rule_engine.excel_export at startup, which imports openpyxl. This sanity check can pass and then uvicorn app:app exits immediately, making the new default governance startup fail on hosts that rely on the repo venv; include the governance requirements in the deploy install/probe path or at least check the modules the app imports.

Useful? React with 👍 / 👎.

Add active OpenSpec evidence for the deploy.ps1 governance-service startup behavior so PR review governance can validate the workflow change.

Validation: npx openspec validate governance-service-deploy --strict; local pr-review-agent reports warning with no blockers.
@github-actions

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status warning
Risk medium
PR 215
Head docs/governance-service-deploy-spec / 89548eb4099f3aa419ac5d0b964cadb1a60313cc
Base main / 706d7009f62eb447ba8deba2e256b5de2bb57203

Blockers

  • None

Warnings

  • [medium] GitNexus detect changes did not pass: warning.

Validation Commands

  • openspec validate governance-service-deploy
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-pr-review-agent.ps1

Checks

  • passed openspec validate governance-service-deploy (openspec)
  • passed script-level PR review agent tests (scripts)

Human Review Notes

  • OpenSpec changes detected: governance-service-deploy
  • Optional AI adapter is not required by policy and was skipped.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 89548eb409

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/deploy.ps1
}
}
$extraHostNativePorts = @($resolvedSpectatorSignalPorts)
if (-not $SkipGovernance) { $extraHostNativePorts += $resolvedGovernancePort }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject governance ports that collide with web-plane ports

When -GovernancePort/GOV_PORT is set to 8004 or 5173, preflight can still pass if those web-plane ports are initially free because the governance port is only added to the host-native availability list. Phase 4a then binds the port before Phase 4d runs Docker Compose, so the coordinator/viewer cannot publish its host port and the deploy fails or leaves the UI unreachable; reject governance ports that equal the resolved coordinator/viewer host ports before starting services.

Useful? React with 👍 / 👎.

Mark the OpenSpec review task and spec-to-done PR gate as complete after CodeRabbit and pr-review-agent passed.

Validation: npx openspec validate governance-service-deploy --strict.
@github-actions

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status warning
Risk medium
PR 215
Head docs/governance-service-deploy-spec / 205a38c4c1fbaff0a64255983141ec1210db3601
Base main / 706d7009f62eb447ba8deba2e256b5de2bb57203

Blockers

  • None

Warnings

  • [medium] GitNexus detect changes did not pass: warning.

Validation Commands

  • openspec validate governance-service-deploy
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-pr-review-agent.ps1

Checks

  • passed openspec validate governance-service-deploy (openspec)
  • passed script-level PR review agent tests (scripts)

Human Review Notes

  • OpenSpec changes detected: governance-service-deploy
  • Optional AI adapter is not required by policy and was skipped.

@monkey1sai
monkey1sai merged commit 81a2bdd into main Jun 16, 2026
2 checks passed
@monkey1sai
monkey1sai deleted the docs/governance-service-deploy-spec branch June 16, 2026 05:47
monkey1sai added a commit that referenced this pull request Jun 18, 2026
#229)

把 13 個產品碼已 merge 進 main 的 active change 歸檔為不可變快照,
並將其 spec delta 併入 canonical specs。對齊 #197 收斂規約。

歸檔(archive/<merge-date>-<id>,git 偵測為 R100 純改名、零內容漂移):
  a1-m1-closeout(#213) a2-version-diff-selector(#207) conv-coverage-report(#218/#220)
  conv-prioritize-retry(#221) conv-watch-toggle(#225) conversion-artifact-id-sanitize(#206)
  governance-service-deploy(#215) minio-fileserver-source(#204) minio-watch-auto-intake(#210)
  raise-claude-md-line-budget(#199) sessions-terminate(#226) stop-all-single-pid-cleanup(#217)
  test-deploy-rebuild-workflow(#198)

canonical 併入:
- 9 個新 capability(純 ADDED → 新建 spec):a1-m1-closeout、a2-version-diff-selector、
  conv-coverage-report、conv-prioritize-retry、conversion-control、conversion-artifact-id-sanitize、
  minio-fileserver-source、minio-watch-auto-intake、test-deploy-rebuild-workflow。
- review-session-request-lifecycle:append sessions-terminate 的 ADDED requirement
  「Operator 結束 session controlled action」(5 scenario),既有 7 requirement 不動。
- one-click-deploy-hybrid:併入 governance-service-deploy 與 stop-all-single-pid-cleanup
  兩 delta,採「合併不取代」保全既有更豐富內容。依 deploy.ps1 現況權威
  (4a=governance/4b=conversion/4c=Kit/4d=docker)調和 Phase 4 編號,並修正
  canonical 其他兩處陳舊的舊 3 段編號(Mode C 入口 scenario、退出碼 stage 清單補 4d)。
- agent-doc-context-budget:raise-claude-md-line-budget 的 130 行預算已於 #199 併入,
  本次為 archive-only。

驗證:
- 結構檢查無殘留 ## ADDED/MODIFIED header、每 requirement 皆有 scenario、
  43 archive 檔全 R100、git diff --cached --check 無 whitespace。
- 雙 agent 對抗驗證:完整性 PASS(無規範遺失);一致性初判 FAIL 抓到 2 處
  Phase 4 編號矛盾,已修正後複驗。
- 本機 openspec CLI 不可用(結構驗證代替);openspec validate --strict 由 CI pr-review-agent 執行。


Claude-Session: https://claude.ai/code/session_01JEyNWhEmb3x8oinY3B2v9V

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants