mirror of
https://github.com/harivansh-afk/sandbox-agent.git
synced 2026-04-15 21:03:26 +00:00
* Move Foundry HTTP APIs out of /api/rivet
* Move Foundry HTTP APIs onto /v1
* Fix Foundry Rivet base path and frontend endpoint fallback
* Configure Foundry Rivet runner pool for /v1
* Remove Foundry Rivet runner override
* Serve Foundry Rivet routes directly from Bun
* Log Foundry RivetKit deployment friction
* Add actor display metadata
* Tighten actor schema constraints
* Reset actor persistence baseline
* Remove temporary actor key version prefix
Railway has no persistent volumes so stale actors are wiped on
each deploy. The v2 key rotation is no longer needed.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Cache app workspace actor handle across requests
Every request was calling getOrCreate on the Rivet engine API
to resolve the workspace actor, even though it's always the same
actor. Cache the handle and invalidate on error so retries
re-resolve. This eliminates redundant cross-region round-trips
to api.rivet.dev on every request.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add temporary debug logging to GitHub OAuth exchange
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Make squashed baseline migrations idempotent
Use CREATE TABLE IF NOT EXISTS and CREATE UNIQUE INDEX IF NOT
EXISTS so the squashed baseline can run against actors that
already have tables from the pre-squash migration sequence.
This fixes the "table already exists" error when org workspace
actors wake up with stale migration journals.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Revert "Make squashed baseline migrations idempotent"
This reverts commit 356c146035.
* Fix GitHub OAuth callback by removing retry wrapper
OAuth authorization codes are single-use. The appWorkspaceAction wrapper
retries failed calls up to 20 times, but if the code exchange succeeds
and a later step fails, every retry sends the already-consumed code,
producing "bad_verification_code" from GitHub.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add runner versioning to RivetKit registry
Uses Date.now() so each process start gets a unique version.
This ensures Rivet Cloud migrates actors to the new runner on
deploy instead of routing requests to stale runners.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add backend request and workspace logging
* Log callback request headers
* Make GitHub OAuth callback idempotent against duplicate requests
Clear oauthState before exchangeCode so duplicate callback requests
fail the state check instead of hitting GitHub with a consumed code.
Marked as HACK — root cause of duplicate HTTP requests is unknown.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add temporary header dump on GitHub OAuth callback
Log all request headers on the callback endpoint to diagnose
the source of duplicate requests (Railway proxy, Cloudflare, browser).
Remove once root cause is identified.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Defer slow GitHub org sync to workflow queue for fast OAuth callback
Split syncGithubSessionFromToken into a fast path (initGithubSession:
exchange code, get viewer, store token+identity) and a slow path
(syncGithubOrganizations: list orgs/installations, sync workspaces).
completeAppGithubAuth now returns the 302 redirect in ~2s instead of
~18s by enqueuing the org sync to the workspace workflow queue
(fire-and-forget). This eliminates the proxy timeout window that was
causing duplicate callback requests.
bootstrapAppGithubSession (dev-only) still calls the full synchronous
sync since proxy timeouts are not a concern and it needs the session
fully populated before returning.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* foundry: async app repo import on org select
* foundry: parallelize app snapshot org reads
* repo: push all current workspace changes
* foundry: update runner version and snapshot logging
* Refactor Foundry GitHub state and sandbox runtime
Refactors Foundry around organization/repository ownership and adds an organization-scoped GitHub state actor plus a user-scoped GitHub auth actor, removing the old project PR/branch sync actors and repo PR cache.
Updates sandbox provisioning to rely on sandbox-agent for in-sandbox work, hardens Daytona startup and image-build behavior, and surfaces runtime and task-startup errors more clearly in the UI.
Extends workbench and GitHub state handling to track merged PR state, adds runtime-issue tracking, refreshes client/test/config wiring, and documents the main live Foundry test flow plus actor coordination rules.
Also updates the remaining Sandbox Agent install-version references in docs/examples to the current pinned minor channel.
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
153 lines
4.3 KiB
Text
153 lines
4.3 KiB
Text
---
|
||
title: "Foundry Self-Hosting"
|
||
description: "Environment, credentials, and deployment setup for Sandbox Agent Foundry auth, GitHub, and billing."
|
||
---
|
||
|
||
This guide documents the deployment contract for the Foundry product surface: app auth, GitHub onboarding, repository import, and billing.
|
||
|
||
It also covers the local-development bootstrap that uses `.env.development` only when `NODE_ENV=development`.
|
||
|
||
## Local Development
|
||
|
||
For backend local development, the Foundry backend now supports a development-only dotenv bootstrap:
|
||
|
||
- It loads `.env.development.local` and `.env.development`
|
||
- It does this **only** when `NODE_ENV=development`
|
||
- It does **not** load dotenv files in production
|
||
|
||
The example file lives at [`/.env.development.example`](https://github.com/rivet-dev/sandbox-agent/blob/main/.env.development.example).
|
||
|
||
To use it locally:
|
||
|
||
```bash
|
||
cp .env.development.example .env.development
|
||
```
|
||
|
||
Run the backend with:
|
||
|
||
```bash
|
||
just foundry-backend-start
|
||
```
|
||
|
||
That recipe sets `NODE_ENV=development`, which enables the dotenv loader.
|
||
|
||
### Local Defaults
|
||
|
||
These values can be safely defaulted for local development:
|
||
|
||
- `APP_URL=http://localhost:4173`
|
||
- `BETTER_AUTH_URL=http://localhost:7741`
|
||
- `BETTER_AUTH_SECRET=sandbox-agent-foundry-development-only-change-me`
|
||
- `GITHUB_REDIRECT_URI=http://localhost:7741/v1/auth/github/callback`
|
||
|
||
These should be treated as development-only values.
|
||
|
||
## Production Environment
|
||
|
||
For production or self-hosting, set these as real environment variables in your deployment platform. Do not rely on dotenv file loading.
|
||
|
||
### App/Auth
|
||
|
||
| Variable | Required | Notes |
|
||
|---|---:|---|
|
||
| `APP_URL` | Yes | Public frontend origin |
|
||
| `BETTER_AUTH_URL` | Yes | Public auth base URL |
|
||
| `BETTER_AUTH_SECRET` | Yes | Strong random secret for auth/session signing |
|
||
|
||
### GitHub OAuth
|
||
|
||
| Variable | Required | Notes |
|
||
|---|---:|---|
|
||
| `GITHUB_CLIENT_ID` | Yes | GitHub OAuth app client id |
|
||
| `GITHUB_CLIENT_SECRET` | Yes | GitHub OAuth app client secret |
|
||
| `GITHUB_REDIRECT_URI` | Yes | GitHub OAuth callback URL |
|
||
|
||
Use GitHub OAuth for:
|
||
|
||
- user sign-in
|
||
- user identity
|
||
- org selection
|
||
- access to the signed-in user’s GitHub context
|
||
|
||
## GitHub App
|
||
|
||
If your Foundry deployment uses GitHub App-backed organization install and repo import, also configure:
|
||
|
||
| Variable | Required | Notes |
|
||
|---|---:|---|
|
||
| `GITHUB_APP_ID` | Yes | GitHub App id |
|
||
| `GITHUB_APP_CLIENT_ID` | Yes | GitHub App client id |
|
||
| `GITHUB_APP_CLIENT_SECRET` | Yes | GitHub App client secret |
|
||
| `GITHUB_APP_PRIVATE_KEY` | Yes | PEM private key for installation auth |
|
||
|
||
For `.env.development` and `.env.development.local`, store `GITHUB_APP_PRIVATE_KEY` as a quoted single-line value with `\n` escapes instead of raw multi-line PEM text.
|
||
|
||
Recommended GitHub App permissions:
|
||
|
||
- Repository `Metadata: Read`
|
||
- Repository `Contents: Read & Write`
|
||
- Repository `Pull requests: Read & Write`
|
||
- Repository `Checks: Read`
|
||
- Repository `Commit statuses: Read`
|
||
|
||
Set the webhook URL to `https://<your-backend-host>/v1/webhooks/github` and generate a webhook secret. Store the secret as `GITHUB_WEBHOOK_SECRET`.
|
||
|
||
Recommended webhook subscriptions:
|
||
|
||
- `installation`
|
||
- `installation_repositories`
|
||
- `pull_request`
|
||
- `pull_request_review`
|
||
- `pull_request_review_comment`
|
||
- `push`
|
||
- `create`
|
||
- `delete`
|
||
- `check_suite`
|
||
- `check_run`
|
||
- `status`
|
||
|
||
Use the GitHub App for:
|
||
|
||
- installation/reconnect state
|
||
- org repo import
|
||
- repository sync
|
||
- PR creation and updates
|
||
|
||
Use GitHub OAuth for:
|
||
|
||
- who the user is
|
||
- which orgs they can choose
|
||
|
||
## Stripe
|
||
|
||
For live billing, configure:
|
||
|
||
| Variable | Required | Notes |
|
||
|---|---:|---|
|
||
| `STRIPE_SECRET_KEY` | Yes | Server-side Stripe secret key |
|
||
| `STRIPE_PUBLISHABLE_KEY` | Yes | Client-side Stripe publishable key |
|
||
| `STRIPE_WEBHOOK_SECRET` | Yes | Signing secret for billing webhooks |
|
||
| `STRIPE_PRICE_TEAM` | Yes | Stripe price id for the Team plan checkout session |
|
||
|
||
Stripe should own:
|
||
|
||
- hosted checkout
|
||
- billing portal
|
||
- subscription status
|
||
- invoice history
|
||
- webhook-driven state sync
|
||
|
||
## Mock Invariant
|
||
|
||
Foundry’s mock client path should continue to work end to end even when the real auth/GitHub/Stripe path exists.
|
||
|
||
That includes:
|
||
|
||
- sign-in
|
||
- org selection/import
|
||
- settings
|
||
- billing UI
|
||
- workspace/task/session flow
|
||
- seat accrual
|
||
|
||
Use mock mode for deterministic UI review and local product development. Use the real env-backed path for integration and self-hosting.
|