Repository navigation
docs(spike): Fly verification spike for Published Apps Phase 0 - #2424
2witstudios wants to merge 1 commit into
Conversation
deploy_token exists and is strictly app-scoped (403 on any other app, on org list, and on app create) — safe as a per-published-app credential, but it returns no token id and can self-renew, so record mints and treat app destruction as the revocation path. fly-replay reaches a zero-IP target and auto-starts it (~1.4s wake floor), but ONLY within one 6PN network: per-app `network` isolation — decision D2 — makes the proxy refuse with "cross-network replays are not allowed". D2 and the Phase 3 routing design cannot both stand. A replay to an app with no serving machine is a bare 502 with an empty body after ~7.5-7.9s; `timeout=` on the replay header cuts that to ~80ms, so the router must set it and render its own error page. The machine events endpoint keeps only the most recent 20 events (5 stop/start cycles), not a time window — mirroring at write time is mandatory, and `source: "proxy"` vs `"user"` is what distinguishes a proxy wake from our own start call for awake-second metering. All spike resources destroyed and the minted org token revoked.
|
Warning Review limit reached
Next review available in: 3 minutes Limit details: You’ve used all 3 included reviews currently available under your plan. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5c993b24a6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - have the **router** render the user-facing error/parked page itself (detect the failure and serve HTML) | ||
| rather than letting the bare 502 through — Fly gives the client nothing to render. |
There was a problem hiding this comment.
Handle failures before returning the fly-replay response
When the target is missing or has no serving Machine, the router cannot detect and replace the resulting 502 after it emits fly-replay: Fly Proxy performs the replay and generates the empty 502 without returning control to the router application. A Phase 3 implementation following this requirement will therefore still expose the blank error unless it performs a preflight before replaying or introduces another proxy layer/fallback mechanism.
Useful? React with 👍 / 👎.
| 3. **Phase 4 must mirror machine events synchronously**, and must treat `source: "proxy"` starts as billable | ||
| wakes — the 20-event window cannot be polled after the fact. |
There was a problem hiding this comment.
Capture proxy wakes through an observable event source
When Fly Proxy auto-starts a stopped Machine, PageSpace performs no write at which it can synchronously mirror the source: "proxy" event. Since this document also establishes that the API retains only 20 events, implementing this prescription can silently miss wake/stop pairs and corrupt awake-time billing during bursts; Phase 4 needs a push/log ingestion source, a router-owned wake ledger, or another explicitly observable mechanism rather than synchronous write-time mirroring.
Useful? React with 👍 / 👎.
Empirical verification of three ambiguously-documented Fly behaviors the Published Apps epic depends on (epic page thjql2b2eu2oaty6jouqbmb2, Phase 0 requirement).
Verdicts:
POST /v1/apps/{app}/deploy_token: CONFIRMED — live, strictly app-scoped (403 on siblings/org), no token id returned (record mints ourselves)timeout=is set on the replay headersource: "proxy"marks billable proxy wakesAll
pgs-spike-*apps destroyed and org token revoked (verified in doc). Docs-only change.🤖 Generated with Claude Code
https://claude.ai/code/session_018BJCFvfRz9JrBYFbBHzQeJ