fix: remove EnvironmentFile from paperclip service - #1344
Conversation
|
You do not have enough credits to review this pull request. Please purchase more credits to continue. |
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 21 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Mesa DescriptionTL;DRFixed a crash-looping What changed?
Description generated by Mesa. Update settings |
| "HOME=${homeDir}" | ||
| "PATH=${homeDir}/.local/bin:${homeDir}/.bun/bin:${homeDir}/.nix-profile/bin:${homeDir}/.local/share/pnpm:${homeDir}/.local/share/fnm/current/bin:${homeDir}/.npm-global/bin:/usr/local/bin:/usr/bin:/bin" | ||
| ]; | ||
| EnvironmentFile = "${instanceDir}/.env"; |
There was a problem hiding this comment.
Pull request overview
Removes a systemd user service EnvironmentFile reference in the Paperclip Home Manager module to stop the service from crash-looping when the expected .env file is missing on the kyber host.
Changes:
- Remove
EnvironmentFile = "${instanceDir}/.env";from the Paperclip user service definition.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| Environment = [ | ||
| "HOME=${homeDir}" | ||
| "PATH=${homeDir}/.local/bin:${homeDir}/.bun/bin:${homeDir}/.nix-profile/bin:${homeDir}/.local/share/pnpm:${homeDir}/.local/share/fnm/current/bin:${homeDir}/.npm-global/bin:/usr/local/bin:/usr/bin:/bin" | ||
| ]; | ||
| EnvironmentFile = "${instanceDir}/.env"; | ||
| WorkingDirectory = "${homeDir}/.paperclip"; |
There was a problem hiding this comment.
instanceDir is now unused after removing EnvironmentFile. Consider removing the instanceDir let-binding (or using it elsewhere) to avoid suggesting there is still instance-specific state being referenced by this module.
| WorkingDirectory = "${homeDir}/.paperclip"; | ||
| StandardOutput = "append:/tmp/paperclip/paperclip.log"; | ||
| StandardError = "append:/tmp/paperclip/paperclip.log"; |
There was a problem hiding this comment.
The service logs to /tmp/paperclip/paperclip.log, but /tmp is typically cleared on reboot and the Home Manager activation hook won’t run at user-service start. This can cause the unit to fail if the directory is missing. Prefer creating the directory in the unit itself (e.g., RuntimeDirectory/StateDirectory + %t for the path, or an ExecStartPre mkdir) so it’s always present with correct ownership/permissions.
* feat: add paperclip service (#1342) * feat: add paperclip service - Systemd service on kyber: runs `paperclipai run` via bun, depends on docker-postgres - Config via builtins.toJSON: external postgres on kyber, embedded on macOS - Setup script creates paperclip database on docker-postgres - Makefile target: `make systemctl-paperclip` * fix: add shellcheck disable and shell test coverage for paperclip * fix: correct shellcheck disable directive syntax * refactor: use config.template.json pattern for paperclip * refactor: rename setup.sh to hydrate.sh for paperclip * test: add auto-switch hook tests and update coverage spec * fix: remove EnvironmentFile from paperclip service (#1344) * fix: paperclip authenticated mode and required config fields (#1345) * fix: remove EnvironmentFile from paperclip service * fix: use authenticated mode on kyber, add required meta/logging fields * fix: add allowedHostnames for paperclip.shunkakinoki.com * fix: format config template json * fix: use trust auth for docker-postgres (#1346) POSTGRES_HOST_AUTH_METHOD=trust removes password auth for all connections. The password kept going out of sync after crash recovery, causing paperclip and other services to fail with 'password authentication failed'. Safe since postgres is only reachable from the host. * fix: use k8s postgres via DATABASE_URL, remove docker-postgres dep, add authenticated mode (#1347) * fix: use bun runtime for paperclip (pino-http node crash), k8s postgres via DATABASE_URL (#1348) * fix: use nix-profile bun path for paperclip service (#1350) * fix: add caret prefix to paperclipai dependency (#1349) * fix: use extra-substituters to avoid untrusted user warnings (#1351) * fix: run paperclip from cloned repo via pnpm dev:once (#1352) * fix: run paperclip from cloned repo via pnpm dev:once The global bun install flattens pino@10 + pino-http@10.5 together, but pino-http needs pino@9. The repo lockfile resolves this correctly with nested dependencies. Running from the repo avoids the crash. * fix: use bun run server/src/index.ts instead of pnpm dev:once * fix: pin pino@9.14.0 override, run paperclipai from dotfiles node_modules The bun flat hoisting was resolving pino@10 which is incompatible with pino-http@10.5. Pinning pino to 9.14.0 via overrides matches the paperclip repo's lockfile resolution and fixes the crash. * fix: use global bun paperclipai with pino override (#1353) * fix: use global ~/.bun/bin/paperclipai with pino override Propagate overrides from dotfiles package.json to ~/.bun/install/global/ so the global binary resolves pino@9.14.0 correctly. * test: add tests for npm-globals dependency overrides * fix: resolve GitHub Actions failures and code review issues - Fix non-portable \s regex to [[:space:]] in auto-switch.sh (shfmt compat) - Add jq dependency check alongside cswap - Use printf instead of echo for safer output - Fix claude-swap version from >=1.1.5 (non-existent) to >=0.7.1 - Add auto-switch.sh to Nix deployment config (default.nix) - Sort covered_scripts list alphabetically in coverage_spec.sh https://claude.ai/code/session_012GyQBesQGF1asTfKebWyLM --------- Co-authored-by: Claude <noreply@anthropic.com>
Summary
EnvironmentFilepointing to non-existent~/.paperclip/instances/default/.envlocal_trustedmode — auth is handled at the Cloudflare tunnel / nginx ingress levelProblem
Service was crash-looping with
Failed to load environment files: No such file or directorySummary by cubic
Removed
EnvironmentFilefrom the paperclip service to stop crash loops caused by a missing.env. This aligns withlocal_trustedmode where auth is handled at the edge.EnvironmentFilereference to${instanceDir}/.envto prevent “Failed to load environment files” and restart loops.local_trusted; Cloudflare tunnel/nginx ingress handle auth.Written for commit 4e4ca0a. Summary will update on new commits.