Skip to content

docs(spike): Fly verification spike for Published Apps Phase 0 - #2424

Closed
2witstudios wants to merge 1 commit into
masterfrom
pu/fly-spike
Closed

2witstudios wants to merge 1 commit into
masterfrom
pu/fly-spike

Conversation

@2witstudios

Copy link
Copy Markdown
Owner

Empirical verification of three ambiguously-documented Fly behaviors the Published Apps epic depends on (epic page thjql2b2eu2oaty6jouqbmb2, Phase 0 requirement).

Verdicts:

  • POST /v1/apps/{app}/deploy_token: CONFIRMED — live, strictly app-scoped (403 on siblings/org), no token id returned (record mints ourselves)
  • fly-replay to zero-IP target: CONFIRMED on a shared network; REFUTED across per-app networks ("cross-network replays are not allowed") — ADR D2's per-app-network clause is under revision
  • Proxy auto-start of stopped targets: CONFIRMED; wake ≈1.4s floor; no-target failure is a 7.5–7.9s empty 502 unless timeout= is set on the replay header
  • Machine events endpoint: only the last 20 events retained — write-time mirroring is mandatory for metering; source: "proxy" marks billable proxy wakes

All pgs-spike-* apps destroyed and org token revoked (verified in doc). Docs-only change.

🤖 Generated with Claude Code

https://claude.ai/code/session_018BJCFvfRz9JrBYFbBHzQeJ

deploy_token exists and is strictly app-scoped (403 on any other app,
on org list, and on app create) — safe as a per-published-app credential,
but it returns no token id and can self-renew, so record mints and treat
app destruction as the revocation path.

fly-replay reaches a zero-IP target and auto-starts it (~1.4s wake floor),
but ONLY within one 6PN network: per-app `network` isolation — decision D2 —
makes the proxy refuse with "cross-network replays are not allowed". D2 and
the Phase 3 routing design cannot both stand.

A replay to an app with no serving machine is a bare 502 with an empty body
after ~7.5-7.9s; `timeout=` on the replay header cuts that to ~80ms, so the
router must set it and render its own error page.

The machine events endpoint keeps only the most recent 20 events (5 stop/start
cycles), not a time window — mirroring at write time is mandatory, and
`source: "proxy"` vs `"user"` is what distinguishes a proxy wake from our own
start call for awake-second metering.

All spike resources destroyed and the minted org token revoked.
@coderabbitai

coderabbitai Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@2witstudios, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 3 minutes

Limit details: You’ve used all 3 included reviews currently available under your plan.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 21a4e7a3-e1bc-438f-bc8f-6d339fda0fe0

📥 Commits

Reviewing files that changed from the base of the PR and between 854ccdb and 5c993b2.

📒 Files selected for processing (1)
  • docs/spikes/2026-08-fly-published-apps-spike.md

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5c993b24a6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +292 to +293
- have the **router** render the user-facing error/parked page itself (detect the failure and serve HTML)
rather than letting the bare 502 through — Fly gives the client nothing to render.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Handle failures before returning the fly-replay response

When the target is missing or has no serving Machine, the router cannot detect and replace the resulting 502 after it emits fly-replay: Fly Proxy performs the replay and generates the empty 502 without returning control to the router application. A Phase 3 implementation following this requirement will therefore still expose the blank error unless it performs a preflight before replaying or introduces another proxy layer/fallback mechanism.

Useful? React with 👍 / 👎.

Comment on lines +426 to +427
3. **Phase 4 must mirror machine events synchronously**, and must treat `source: "proxy"` starts as billable
wakes — the 20-event window cannot be polled after the fact.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Capture proxy wakes through an observable event source

When Fly Proxy auto-starts a stopped Machine, PageSpace performs no write at which it can synchronously mirror the source: "proxy" event. Since this document also establishes that the API retains only 20 events, implementing this prescription can silently miss wake/stop pairs and corrupt awake-time billing during bursts; Phase 4 needs a push/log ingestion source, a router-owned wake ledger, or another explicitly observable mechanism rather than synchronous write-time mirroring.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant