feat(deploy): 將 governance-service 納入 deploy 啟動 - #215
Conversation
Add host-native uvicorn startup for governance-service in deploy.ps1 -Build, wire HOST_GOVERNANCE_API_BASE into the Docker coordinator, and document the spec-to-done plan/evidence state. Validation: test-deploy-governance-static.ps1 and test-deploy-dryrun.ps1 pass.
|
Warning Review limit reached
More reviews will be available in 32 minutes and 52 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (14)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Review Agent Summary
Blockers
Warnings
Validation Commands
Checks
Human Review Notes
|
There was a problem hiding this comment.
Pull request overview
This PR integrates the governance-service into the canonical deploy.ps1 -Build hybrid deploy workflow so that the A1/M1 closeout UI can be operated from a single deploy command without requiring a second terminal. The governance service runs as a host-native Python/uvicorn process on 127.0.0.1:49102, with the Docker coordinator connecting to it via host.docker.internal.
Changes:
- Adds
Start-HostNativeGovernanceto the host-native launcher, wires governance lifecycle into deploy Phase 4a (with new-SkipGovernance/-GovernancePortparameters, runtime signature management, port audit integration, Docker env injection, and Phase 5 health verification), and updatesstop-all.ps1to manage the service. - Extends existing dry-run and static deploy tests to cover governance audit fields, skip state, and custom port scenarios, and adds a new static contract test for governance integration.
- Adds comprehensive spec design, implementation plan, and spec-to-done state/task tracking documentation.
Reviewed changes
Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
scripts/lib/host-native-launcher.ps1 |
Adds Start-HostNativeGovernance function following existing launcher patterns (Python312 resolution, import sanity check, env var setup, delegation to Start-HostNativeService) |
scripts/deploy.ps1 |
Adds -SkipGovernance/-GovernancePort params, governance runtime signature, port audit integration, Phase 4a governance lifecycle, Docker HOST_GOVERNANCE_API_BASE injection, Phase 5 governance/proxy probes, web-plane refresh trigger, and audit fields; renumbers existing phases 4a→4b, 4b→4c, 4c→4d |
scripts/stop-all.ps1 |
Adds governance-service with port 49102 to expected services list |
scripts/tests/test-deploy-governance-static.ps1 |
New static contract test verifying governance integration points across deploy, launcher, and stop-all scripts |
scripts/tests/test-deploy-dryrun.ps1 |
Extends dry-run audit tests to verify governance port, skip state, Docker base URL, and custom port recording |
docs/superpowers/specs/2026-06-16-governance-service-deploy-design.md |
Design spec covering architecture, deploy behavior, launcher, compose/env, stop-all, testing, and risks |
docs/superpowers/plans/2026-06-16-governance-service-deploy.md |
Step-by-step implementation plan with 9 tasks covering all changed files |
artifacts/spec-to-done/governance-service-deploy/tasks.md |
Spec-to-done task checklist tracking implementation progress |
artifacts/spec-to-done/governance-service-deploy/plan.md |
Spec-to-done execution plan with gate summaries |
artifacts/spec-to-done/governance-service-deploy-state.md |
Spec-to-done phase state tracking (P0–P7) |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| $audit = Get-Content -LiteralPath $auditJson -Raw | ConvertFrom-Json | ||
| Assert-Equal 49102 $audit.runtime.governancePort 'default governance port is 49102' | ||
| Assert-Equal $false $audit.runtime.governanceSkipped 'default governance is not skipped' | ||
| Assert-Equal 'http://host.docker.internal:49102' $audit.runtime.governanceApiBaseForDocker 'default Docker governance base URL' | ||
| Write-TestPass 'governance dry-run audit defaults' |
| Set-StrictMode -Version Latest | ||
| $ErrorActionPreference = 'Stop' |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f273af6b46
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| $resolvedGovernancePort = Resolve-DeployIntValue ` | ||
| -Name 'GOV_PORT' ` | ||
| -EnvFile $resolvedEnvFile ` | ||
| -Default 49102 ` | ||
| -ExplicitValue $GovernancePort ` | ||
| -HasExplicitValue:($PSBoundParameters.ContainsKey('GovernancePort')) ` | ||
| -Min 1 ` | ||
| -Max 65535 |
There was a problem hiding this comment.
Reject governance ports that collide with runtime ports
When -GovernancePort/GOV_PORT is set to an already-reserved runtime port such as 49100 (Kit signaling), 49101 (conversion), or the default spectator range starting at 49110, the preflight still reports the port as free because it only checks current listeners and then governance binds it first in Phase 4a. The later Kit/conversion start then fails or loses that listener, so this needs an explicit collision check against the resolved Kit, conversion, and spectator ports before starting services.
Useful? React with 👍 / 👎.
| Remove-Item Env:PYTHONNOUSERSITE -ErrorAction SilentlyContinue | ||
| & $pythonExe -c "import ifcopenshell, fastapi, uvicorn" *> $null | ||
| if ($LASTEXITCODE -ne 0) { | ||
| throw "governance-service Python cannot import ifcopenshell, fastapi, and uvicorn: $pythonExe" |
There was a problem hiding this comment.
Install or check governance-only Python dependencies
In the fallback path where C:\Program Files\Python312\python.exe is absent and the deploy-created repo .venv is used, Phase 2 only installs bim-streaming-server\requirements.txt; that file does not include openpyxl, but governance-service/app.py imports rule_engine.excel_export at startup, which imports openpyxl. This sanity check can pass and then uvicorn app:app exits immediately, making the new default governance startup fail on hosts that rely on the repo venv; include the governance requirements in the deploy install/probe path or at least check the modules the app imports.
Useful? React with 👍 / 👎.
Add active OpenSpec evidence for the deploy.ps1 governance-service startup behavior so PR review governance can validate the workflow change. Validation: npx openspec validate governance-service-deploy --strict; local pr-review-agent reports warning with no blockers.
PR Review Agent Summary
Blockers
Warnings
Validation Commands
Checks
Human Review Notes
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 89548eb409
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
| } | ||
| $extraHostNativePorts = @($resolvedSpectatorSignalPorts) | ||
| if (-not $SkipGovernance) { $extraHostNativePorts += $resolvedGovernancePort } |
There was a problem hiding this comment.
Reject governance ports that collide with web-plane ports
When -GovernancePort/GOV_PORT is set to 8004 or 5173, preflight can still pass if those web-plane ports are initially free because the governance port is only added to the host-native availability list. Phase 4a then binds the port before Phase 4d runs Docker Compose, so the coordinator/viewer cannot publish its host port and the deploy fails or leaves the UI unreachable; reject governance ports that equal the resolved coordinator/viewer host ports before starting services.
Useful? React with 👍 / 👎.
Mark the OpenSpec review task and spec-to-done PR gate as complete after CodeRabbit and pr-review-agent passed. Validation: npx openspec validate governance-service-deploy --strict.
PR Review Agent Summary
Blockers
Warnings
Validation Commands
Checks
Human Review Notes
|
#229) 把 13 個產品碼已 merge 進 main 的 active change 歸檔為不可變快照, 並將其 spec delta 併入 canonical specs。對齊 #197 收斂規約。 歸檔(archive/<merge-date>-<id>,git 偵測為 R100 純改名、零內容漂移): a1-m1-closeout(#213) a2-version-diff-selector(#207) conv-coverage-report(#218/#220) conv-prioritize-retry(#221) conv-watch-toggle(#225) conversion-artifact-id-sanitize(#206) governance-service-deploy(#215) minio-fileserver-source(#204) minio-watch-auto-intake(#210) raise-claude-md-line-budget(#199) sessions-terminate(#226) stop-all-single-pid-cleanup(#217) test-deploy-rebuild-workflow(#198) canonical 併入: - 9 個新 capability(純 ADDED → 新建 spec):a1-m1-closeout、a2-version-diff-selector、 conv-coverage-report、conv-prioritize-retry、conversion-control、conversion-artifact-id-sanitize、 minio-fileserver-source、minio-watch-auto-intake、test-deploy-rebuild-workflow。 - review-session-request-lifecycle:append sessions-terminate 的 ADDED requirement 「Operator 結束 session controlled action」(5 scenario),既有 7 requirement 不動。 - one-click-deploy-hybrid:併入 governance-service-deploy 與 stop-all-single-pid-cleanup 兩 delta,採「合併不取代」保全既有更豐富內容。依 deploy.ps1 現況權威 (4a=governance/4b=conversion/4c=Kit/4d=docker)調和 Phase 4 編號,並修正 canonical 其他兩處陳舊的舊 3 段編號(Mode C 入口 scenario、退出碼 stage 清單補 4d)。 - agent-doc-context-budget:raise-claude-md-line-budget 的 130 行預算已於 #199 併入, 本次為 archive-only。 驗證: - 結構檢查無殘留 ## ADDED/MODIFIED header、每 requirement 皆有 scenario、 43 archive 檔全 R100、git diff --cached --check 無 whitespace。 - 雙 agent 對抗驗證:完整性 PASS(無規範遺失);一致性初判 FAIL 抓到 2 處 Phase 4 編號矛盾,已修正後複驗。 - 本機 openspec CLI 不可用(結構驗證代替);openspec validate --strict 由 CI pr-review-agent 執行。 Claude-Session: https://claude.ai/code/session_01JEyNWhEmb3x8oinY3B2v9V Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Summary
Validation
Deploy Path Verification
Frontend Verification