mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-10 09:19:42 +02:00
chore: version packages
This commit is contained in:
@@ -1,37 +0,0 @@
|
|||||||
---
|
|
||||||
'aicodeman': minor
|
|
||||||
---
|
|
||||||
|
|
||||||
Restore in-app self-update for the Docker Compose deployment.
|
|
||||||
|
|
||||||
App Settings → Updates now works in the container, using the same updater,
|
|
||||||
status file and progress UI as a bare-host install. The Compose file mounts the
|
|
||||||
checkout it builds from at `/opt/codeman`, so an update's `git checkout` and
|
|
||||||
rebuild land on the host and survive container recreation, and the restart is
|
|
||||||
the server exiting — `restart: unless-stopped` relaunches it on the new build.
|
|
||||||
|
|
||||||
An in-place container update applies application code only, since a restarted
|
|
||||||
container reuses its existing image and configuration. The updater therefore
|
|
||||||
refuses a release that changes `docker/server.Dockerfile` or
|
|
||||||
`docker/docker-compose.yaml`, or that adds keys to `docker/.env.example` the
|
|
||||||
user's `.env` has no value for, naming what changed and pointing at
|
|
||||||
`docker/Start-Codeman.sh` on the host. It also refuses when the container's
|
|
||||||
restart policy would not bring it back. The missing-key check matters most:
|
|
||||||
Compose resolves an unset `${VAR}` to the empty string and starts anyway, so a
|
|
||||||
new required setting would otherwise arrive as a silently blank variable.
|
|
||||||
|
|
||||||
Supporting changes:
|
|
||||||
|
|
||||||
- The runtime image keeps devDependencies and gains `python3`/`make`/`g++`, so
|
|
||||||
`npm install` and `npm run build` can run inside the container. This makes the
|
|
||||||
image larger; that is the cost of updating in place.
|
|
||||||
- Build artefacts live in `codeman-node-modules` and `codeman-dist` named
|
|
||||||
volumes so container-compiled native modules never land in the host checkout.
|
|
||||||
- The four global agent CLIs are pinned, so a release needing newer CLI
|
|
||||||
behaviour becomes a Dockerfile change the environment gate can detect.
|
|
||||||
- `docker/Start-Codeman.sh` records the Dockerfile and compose fingerprints the
|
|
||||||
container was created from, which is the baseline the gate compares against.
|
|
||||||
- New CI guard: `test/docker-compose-env-parity.test.ts` fails when a compose
|
|
||||||
variable has no `.env.example` entry, or the reverse.
|
|
||||||
|
|
||||||
Documented in `docs/docker-self-update.md`.
|
|
||||||
@@ -1,5 +1,20 @@
|
|||||||
# aicodeman
|
# aicodeman
|
||||||
|
|
||||||
|
## 1.24.7
|
||||||
|
|
||||||
|
### Patch Changes
|
||||||
|
|
||||||
|
- The web-tab proxy refuses link-local and cloud-metadata targets. Its Test probe, the proxy itself and the WebSocket relay accepted any http(s) host, so a saved dashboard URL could reach `169.254.169.254` (in decimal, hex, IPv6-mapped or DNS-name form) through a capability and no cookie. Loopback and RFC1918 addresses stay allowed on purpose, since a localhost Grafana is the feature; only link-local and the fixed cloud-metadata addresses are refused, at the schema, at every connect site, and through a DNS lookup hook that judges the resolved addresses, which is what closes DNS rebinding. Adds `undici` so the proxy runs its fetch through its own agent.
|
||||||
|
|
||||||
|
Proxy capabilities are revoked on logout. `revokeOwner()` had shipped with no caller, so a leaked proxy URL stayed valid for as long as anything kept polling it. `POST /api/logout`, the admin forced logout and user deletion now revoke the capabilities they should, and proxied responses carry `Referrer-Policy: same-origin` with the upstream's own policy dropped, so a dashboard on a loose referrer policy cannot hand the capability to a third-party host it links to.
|
||||||
|
|
||||||
|
The Docker Compose deployment updates itself from App Settings again (#373, @opticon454). The checkout Compose builds from is bind-mounted at `/opt/codeman`, so an update's `git checkout` and rebuild land on the host and survive container recreation; build artefacts live in named volumes so container-compiled native modules never enter the host checkout; the image keeps devDependencies and a build toolchain; and the restart is the server exiting under `restart: unless-stopped`. An in-place update applies code only, so the updater refuses a release that changes `server.Dockerfile` or `docker-compose.yaml`, or that adds keys to `.env.example` the user's `.env` has no value for (Compose interpolates an unset variable to the empty string and starts anyway), and points at `docker/Start-Codeman.sh` on the host instead. The four global agent CLIs in the image are pinned. A follow-up makes the final step fail safe: the server exits only when the Compose file declares `CODEMAN_RESTART_BY_EXIT=1` or the daemon confirms an auto-restart policy, and otherwise the build is staged for a manual restart, so a container nothing would restart is never taken down. Details in `docs/docker-self-update.md`.
|
||||||
|
|
||||||
|
The test suite strips `CODEMAN_INSTANCE`, `CODEMAN_DATA_DIR` and `CODEMAN_TMUX_SOCKET` before any application module loads (#371, @opticon454), with a two-half test whose static half reads `test/setup.ts` so a dropped line fails everywhere. This replaces the throwaway data dir #356 had set for the same variable.
|
||||||
|
|
||||||
|
### Thanks
|
||||||
|
- @opticon454 for the Compose self-update (#373) and the test isolation fix (#371).
|
||||||
|
|
||||||
## 1.24.6
|
## 1.24.6
|
||||||
|
|
||||||
### Patch Changes
|
### Patch Changes
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ When user says "COM":
|
|||||||
|
|
||||||
CI runs `npm run check:lockfile` on every push/PR, so lockfile drift fails the build even if the `version-packages` script is bypassed.
|
CI runs `npm run check:lockfile` on every push/PR, so lockfile drift fails the build even if the `version-packages` script is bypassed.
|
||||||
|
|
||||||
**Version**: 1.24.6 (must match `package.json`)
|
**Version**: 1.24.7 (must match `package.json`)
|
||||||
|
|
||||||
## Project Overview
|
## Project Overview
|
||||||
|
|
||||||
|
|||||||
Generated
+2
-2
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "aicodeman",
|
"name": "aicodeman",
|
||||||
"version": "1.24.6",
|
"version": "1.24.7",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "aicodeman",
|
"name": "aicodeman",
|
||||||
"version": "1.24.6",
|
"version": "1.24.7",
|
||||||
"hasInstallScript": true,
|
"hasInstallScript": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"workspaces": [
|
"workspaces": [
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "aicodeman",
|
"name": "aicodeman",
|
||||||
"version": "1.24.6",
|
"version": "1.24.7",
|
||||||
"description": "Mission control for AI coding agents - run 20 autonomous agents with real-time monitoring and session persistence",
|
"description": "Mission control for AI coding agents - run 20 autonomous agents with real-time monitoring and session persistence",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"main": "dist/index.js",
|
"main": "dist/index.js",
|
||||||
|
|||||||
Reference in New Issue
Block a user