From 6244b44c6eeb76a0589c92a541612f71668218b7 Mon Sep 17 00:00:00 2001 From: Codex Date: Sat, 13 Jun 2026 17:30:48 +0300 Subject: [PATCH] Add dynamic AI Workspace run profiles --- docs/AI_WORKSPACE_CONFIG_CONTRACT.md | 54 ++ docs/DEPLOYMENT_LOCAL.md | 34 ++ infra/.env.example | 7 +- .../check-ai-workspace-config-contract.sh | 146 ++++++ .../check-ai-workspace-release-gates.sh | 123 +++++ infra/scripts/check-ai-workspace-topology.sh | 194 +++++++ infra/scripts/init-dev-env.sh | 8 +- infra/synology/.env.synology.example | 3 + infra/synology/README.md | 10 + infra/synology/apply-current-runtime.sh | 4 + infra/synology/backup-current.sh | 76 ++- .../synology/check-ai-workspace-apply-plan.sh | 190 +++++++ infra/synology/deploy-current.sh | 31 +- infra/synology/prepare-ai-workspace-env.sh | 98 ++++ infra/synology/verify-current-runtime.sh | 4 + services/ai-workspace-assistant/README.md | 43 ++ .../ai-workspace-assistant/TEST_MATRIX.md | 178 +++++++ services/ai-workspace-assistant/package.json | 3 +- .../src/scripts/smoke-run-profile.mjs | 347 +++++++++++++ .../ai-workspace-assistant/src/server.mjs | 483 ++++++++++++++++++ .../src/templates/install-windows.ps1 | 195 ++++++- 21 files changed, 2179 insertions(+), 52 deletions(-) create mode 100644 docs/AI_WORKSPACE_CONFIG_CONTRACT.md create mode 100755 infra/scripts/check-ai-workspace-config-contract.sh create mode 100755 infra/scripts/check-ai-workspace-release-gates.sh create mode 100755 infra/scripts/check-ai-workspace-topology.sh create mode 100755 infra/synology/check-ai-workspace-apply-plan.sh create mode 100755 infra/synology/prepare-ai-workspace-env.sh create mode 100644 services/ai-workspace-assistant/TEST_MATRIX.md create mode 100644 services/ai-workspace-assistant/src/scripts/smoke-run-profile.mjs diff --git a/docs/AI_WORKSPACE_CONFIG_CONTRACT.md b/docs/AI_WORKSPACE_CONFIG_CONTRACT.md new file mode 100644 index 0000000..002feef --- /dev/null +++ b/docs/AI_WORKSPACE_CONFIG_CONTRACT.md @@ -0,0 +1,54 @@ +# AI Workspace Config Contract + +This contract keeps topology differences in env/config instead of product-code branches. + +## URL Classes + +- Worker-facing URL: returned to or used by the Codex worker. It must be reachable from the machine that executes Codex. +- Backend-internal URL: used by app backends, Platform Assistant, Hub, Gateway, and service-to-service calls. +- Browser URL: used by user-facing UI. +- Downstream app URL: used by an adapter service to mutate/read its owned app backend. + +Do not mix these classes. A URL reachable from the Mac browser is not automatically reachable from a remote Codex worker. + +## Current Profiles + +`local/hybrid-prod-bridge`: + +- Tasker UI: `http://task.local.nodedc` +- Platform Assistant: `http://127.0.0.1:18082` +- Local Hub process: `http://127.0.0.1:18081` +- Default worker-facing Hub: `wss://ai-hub.nodedc.ru/api/ai-workspace/hub` +- Ops entitlement adapter: `http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements` when deliberately enabled +- Ops Gateway downstream Tasker: `http://task.local.nodedc` +- This profile is valid for contract smoke and local Ops vertical smoke, not proof of live local Codex worker e2e. + +`synology/prod-public`: + +- Browser Launcher: `https://hub.nodedc.ru` +- Browser Ops: `https://ops.nodedc.ru` +- Worker-facing Hub: `wss://ai-hub.nodedc.ru/api/ai-workspace/hub` +- Platform Assistant internal: `http://ai-workspace-assistant:18082` +- Platform to Ops entitlement: `http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements` +- Ops Gateway worker-facing MCP: `https://ops-agents.nodedc.ru/mcp` +- Ops Gateway downstream Tasker: `http://172.22.0.222:18090` +- This is the preferred controlled runtime e2e target. + +`tailscale/tunnel-local-e2e`: + +- Allowed only as an explicit profile. +- All worker-facing URLs must be reachable from the executing Codex worker through Tailscale or a named tunnel. +- No product code should auto-fallback from localhost to Tailscale to public domains. + +## Required Rule + +New apps must join AI Workspace through app manifests/config/adapters: + +- app id and surface id; +- context schema; +- entitlement adapter URL/token; +- MCP/tool pack URL and worker-facing public URL; +- smoke test contract; +- owner repo/service. + +Do not add app-specific address logic to the agent installer, Engine, Ops, or Platform Assistant runtime flow. diff --git a/docs/DEPLOYMENT_LOCAL.md b/docs/DEPLOYMENT_LOCAL.md index 5d6ba5f..60d7712 100644 --- a/docs/DEPLOYMENT_LOCAL.md +++ b/docs/DEPLOYMENT_LOCAL.md @@ -44,6 +44,40 @@ Source fork: /Users/dcconstructions/Downloads/mnt/data/dc_taskmanager/NODEDC_TASKMANAGER/plane-src ``` +## AI Workspace Topology + +Локальная доступность UI не равна честному AI Workspace e2e. Перед интерпретацией результата запускайте: + +```bash +cd /Users/dcconstructions/Downloads/mnt/NODEDC/platform +infra/scripts/check-ai-workspace-topology.sh +``` + +Скрипт ничего не прокидывает и не меняет. Он только классифицирует текущий режим: + +- `contract-only`: можно доверять только контрактным smoke-тестам без runtime e2e. +- `local-ops-vertical`: локальный Ops Gateway и локальный Tasker проверяются вертикально, без live Codex worker. +- `local-ui-only`: локальный UI доступен, но AI write path не доказан. +- `hybrid-prod-bridge`: часть контура локальная, а Hub/worker/MCP смотрят в публичный или другой контур. Такой результат нельзя считать local e2e. +- `true-local-e2e`: Engine, AI Workspace Assistant, Hub, Ops Gateway, Tasker и worker находятся в одной локальной топологии. +- `tunnel-local-e2e`: то же самое через явно выбранный tunnel/Tailscale-профиль. + +Не надо пытаться неявно “дотянуть” Mac-local окружение до Synology. Если нужен Tailscale, это отдельный явный профиль: Hub public URL, Gateway public URL и Engine/Tasker downstream должны быть заданы так, чтобы именно выполняющий Codex worker мог их достичь. До этого UI-диалоги через удаленного агента считаются `hybrid-prod-bridge`, а не доказательством локальной записи. + +Перед controlled Synology apply запускайте общий predeploy gate: + +```bash +infra/scripts/check-ai-workspace-release-gates.sh +``` + +Он не деплоит, не перезапускает контейнеры и не меняет `.env`. Скрипт только выполняет meaningful проверки до runtime e2e: topology classification, Platform contract smoke, Ops Gateway static/build/smoke, Engine static check и diff hygiene. + +Адресная модель описана в `docs/AI_WORKSPACE_CONFIG_CONTRACT.md`. При изменении env examples, compose или AI Workspace URL запускайте: + +```bash +infra/scripts/check-ai-workspace-config-contract.sh +``` + ## Target local flow Первый local infra milestone: diff --git a/infra/.env.example b/infra/.env.example index af88641..75c50fb 100644 --- a/infra/.env.example +++ b/infra/.env.example @@ -59,9 +59,14 @@ AI_WORKSPACE_PG_USER=nodedc_ai_workspace AI_WORKSPACE_PG_PASS=change-me-generate-with-infra-scripts-init-dev-env AI_WORKSPACE_ASSISTANT_TOKEN=change-me-generate-with-infra-scripts-init-dev-env NODEDC_AI_WORKSPACE_ASSISTANT_URL=http://ai-workspace-assistant:18082 +AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements +AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN=replace-with-ops-agent-gateway-internal-token +AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED=false # AI Workspace Hub for downloaded Codex workers. -# Default local development uses the deployed relay. Override these only for offline Hub development. +# Default local development uses the deployed relay and is a hybrid-prod-bridge topology: +# local UI/services can be tested, but live Codex worker write-path e2e is not proven. +# For true local/tunnel e2e, change both Hub URLs and Ops Gateway public URL deliberately. AI_WORKSPACE_HUB_TOKEN=change-me-generate-with-infra-scripts-init-dev-env AI_WORKSPACE_HUB_HOST_BIND=127.0.0.1:18081 AI_WORKSPACE_HUB_PUBLIC_URL=wss://ai-hub.nodedc.ru/api/ai-workspace/hub diff --git a/infra/scripts/check-ai-workspace-config-contract.sh b/infra/scripts/check-ai-workspace-config-contract.sh new file mode 100755 index 0000000..8dc3908 --- /dev/null +++ b/infra/scripts/check-ai-workspace-config-contract.sh @@ -0,0 +1,146 @@ +#!/usr/bin/env sh +set -eu + +SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd) +PLATFORM_ROOT=$(CDPATH= cd -- "$SCRIPT_DIR/../.." && pwd) +OPS_GATEWAY_REPO="${OPS_GATEWAY_REPO:-$PLATFORM_ROOT/../../data/NODEDC_TASKMANAGER_CODEXAPI}" +ENGINE_REPO="${ENGINE_REPO:-$PLATFORM_ROOT/../NODEDC_ENGINE_INFRA}" +PLATFORM_ENV="${PLATFORM_ENV:-$PLATFORM_ROOT/infra/.env}" + +passed=0 +failed=0 +warnings=0 + +section() { + printf '\n== %s ==\n' "$1" +} + +pass() { + passed=$((passed + 1)) + printf 'PASS %s\n' "$1" +} + +fail() { + failed=$((failed + 1)) + printf 'FAIL %s\n' "$1" >&2 +} + +warn() { + warnings=$((warnings + 1)) + printf 'WARN %s\n' "$1" >&2 +} + +require_file() { + file="$1" + label="$2" + if [ -f "$file" ]; then + pass "$label" + else + fail "$label (missing file: $file)" + fi +} + +require_contains() { + file="$1" + needle="$2" + label="$3" + if [ ! -f "$file" ]; then + fail "$label (missing file: $file)" + return 0 + fi + if grep -Fq "$needle" "$file"; then + pass "$label" + else + fail "$label (missing: $needle)" + fi +} + +read_env() { + file="$1" + key="$2" + if [ ! -f "$file" ]; then + return 0 + fi + awk -F= -v key="$key" ' + $0 ~ "^[[:space:]]*#" { next } + $1 == key { + value = substr($0, index($0, "=") + 1) + gsub(/^[[:space:]]+|[[:space:]]+$/, "", value) + gsub(/^"|"$/, "", value) + print value + exit + } + ' "$file" +} + +require_env_value() { + file="$1" + key="$2" + expected="$3" + label="$4" + actual=$(read_env "$file" "$key" || true) + if [ "$actual" = "$expected" ]; then + pass "$label" + else + fail "$label (expected $key=$expected, got ${actual:-})" + fi +} + +section "Required files" +require_file "$PLATFORM_ROOT/infra/.env.example" "Platform local env example exists" +require_file "$PLATFORM_ROOT/infra/synology/.env.synology.example" "Platform Synology env example exists" +require_file "$PLATFORM_ROOT/infra/docker-compose.dev.yml" "Platform local compose exists" +require_file "$PLATFORM_ROOT/infra/synology/docker-compose.platform-http.yml" "Platform Synology compose exists" +require_file "$OPS_GATEWAY_REPO/.env.example" "Ops Gateway local env example exists" +require_file "$OPS_GATEWAY_REPO/.env.synology.example" "Ops Gateway Synology env example exists" +require_file "$OPS_GATEWAY_REPO/docker-compose.local.yml" "Ops Gateway local compose exists" +require_file "$OPS_GATEWAY_REPO/docker-compose.synology.yml" "Ops Gateway Synology compose exists" +require_file "$ENGINE_REPO/docker-compose.yml" "Engine compose exists" + +section "Platform local contract" +require_env_value "$PLATFORM_ROOT/infra/.env.example" "AI_WORKSPACE_OPS_ENTITLEMENT_URL" "http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements" "Local Platform example points Ops entitlement to local Gateway" +require_env_value "$PLATFORM_ROOT/infra/.env.example" "AI_WORKSPACE_HUB_PUBLIC_URL" "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" "Local Platform example keeps deployed Hub as hybrid worker relay by default" +require_env_value "$PLATFORM_ROOT/infra/.env.example" "AI_WORKSPACE_HUB_INTERNAL_URL" "https://ai-hub.nodedc.ru" "Local Platform example has explicit Hub internal URL" +require_contains "$PLATFORM_ROOT/infra/scripts/init-dev-env.sh" "AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements" "Local env generator emits local Ops entitlement URL" +require_contains "$PLATFORM_ROOT/infra/scripts/init-dev-env.sh" "AI_WORKSPACE_HUB_INTERNAL_URL=https://ai-hub.nodedc.ru" "Local env generator emits explicit Hub internal URL" + +section "Platform Synology contract" +require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "NODEDC_AI_WORKSPACE_ASSISTANT_URL" "http://ai-workspace-assistant:18082" "Synology Platform exposes Assistant to app services on compose network" +require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "AI_WORKSPACE_OPS_ENTITLEMENT_URL" "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" "Synology Platform points Ops entitlement to Synology Gateway" +require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "AI_WORKSPACE_HUB_PUBLIC_URL" "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" "Synology Platform worker-facing Hub URL is public relay" +require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "AI_WORKSPACE_HUB_INTERNAL_URL" "https://ai-hub.nodedc.ru" "Synology Platform backend Hub URL is explicit" +require_contains "$PLATFORM_ROOT/infra/synology/verify-current-runtime.sh" 'AI_WORKSPACE_OPS_ENTITLEMENT_URL" = "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements"' "Synology verify checks Ops entitlement URL" + +section "Ops Gateway contract" +require_env_value "$OPS_GATEWAY_REPO/.env.example" "NODEDC_AGENT_GATEWAY_PUBLIC_URL" "https://ops-agents.nodedc.ru" "Ops Gateway local example keeps worker-facing MCP URL explicit" +require_env_value "$OPS_GATEWAY_REPO/.env.example" "NODEDC_TASKER_INTERNAL_URL" "http://task.local.nodedc" "Ops Gateway local example points downstream to local Tasker" +require_env_value "$OPS_GATEWAY_REPO/.env.synology.example" "NODEDC_AGENT_GATEWAY_PUBLIC_URL" "https://ops-agents.nodedc.ru" "Ops Gateway Synology public MCP URL is public relay" +require_env_value "$OPS_GATEWAY_REPO/.env.synology.example" "NODEDC_TASKER_INTERNAL_URL" "http://172.22.0.222:18090" "Ops Gateway Synology downstream points to Synology Tasker" +require_contains "$OPS_GATEWAY_REPO/docker-compose.synology.yml" '${HOST_BIND:-172.22.0.222}:${HOST_PORT:-18190}:${PORT:-4100}' "Ops Gateway Synology compose binds expected internal port" +require_contains "$OPS_GATEWAY_REPO/README.md" "The response uses the AI Workspace adapter contract" "Ops Gateway README documents AI Workspace adapter contract" + +section "Engine contract" +require_contains "$ENGINE_REPO/docker-compose.yml" 'NODEDC_AI_WORKSPACE_ASSISTANT_URL: ${NODEDC_AI_WORKSPACE_ASSISTANT_URL:-http://ai-workspace-assistant:18082}' "Engine compose accepts configurable Assistant URL" +require_contains "$ENGINE_REPO/docker-compose.yml" 'NDC_AI_WORKSPACE_HUB_URL: ${NDC_AI_WORKSPACE_HUB_URL:-wss://ai-hub.nodedc.ru/api/ai-workspace/hub}' "Engine compose accepts configurable worker-facing Hub URL" +require_contains "$ENGINE_REPO/docker-compose.yml" 'NDC_AI_WORKSPACE_HUB_HTTP_URL: ${NDC_AI_WORKSPACE_HUB_HTTP_URL:-https://ai-hub.nodedc.ru}' "Engine compose accepts configurable Hub HTTP URL" +require_contains "$ENGINE_REPO/nodedc-source/server/aiWorkspace/assistantRegistryClient.js" "'X-NODEDC-User-Role': role" "Engine forwards user role to Assistant" +require_contains "$ENGINE_REPO/nodedc-source/server/aiWorkspace/assistantRegistryClient.js" "'X-NODEDC-User-Groups': groups.join(',')" "Engine forwards user groups to Assistant" + +section "Current local env warnings" +if [ -f "$PLATFORM_ENV" ]; then + local_ops_entitlement=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_OPS_ENTITLEMENT_URL || true) + if [ -z "$local_ops_entitlement" ]; then + warn "Current Platform env has no AI_WORKSPACE_OPS_ENTITLEMENT_URL; current Mac remains hybrid/contract-only until env is deliberately updated." + else + pass "Current Platform env has AI_WORKSPACE_OPS_ENTITLEMENT_URL" + fi +else + warn "Current Platform env not found: $PLATFORM_ENV" +fi + +section "Summary" +printf 'passed=%s failed=%s warnings=%s\n' "$passed" "$failed" "$warnings" + +if [ "$failed" -ne 0 ]; then + exit 1 +fi diff --git a/infra/scripts/check-ai-workspace-release-gates.sh b/infra/scripts/check-ai-workspace-release-gates.sh new file mode 100755 index 0000000..02f8166 --- /dev/null +++ b/infra/scripts/check-ai-workspace-release-gates.sh @@ -0,0 +1,123 @@ +#!/usr/bin/env sh +set -eu + +SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd) +PLATFORM_ROOT=$(CDPATH= cd -- "$SCRIPT_DIR/../.." && pwd) +AI_ASSISTANT_DIR="$PLATFORM_ROOT/services/ai-workspace-assistant" + +OPS_GATEWAY_REPO="${OPS_GATEWAY_REPO:-$PLATFORM_ROOT/../../data/NODEDC_TASKMANAGER_CODEXAPI}" +ENGINE_REPO="${ENGINE_REPO:-$PLATFORM_ROOT/../NODEDC_ENGINE_INFRA}" + +RUN_GATEWAY_SMOKE="${RUN_GATEWAY_SMOKE:-1}" +GATEWAY_DATABASE_URL="${GATEWAY_DATABASE_URL:-postgres://nodedc_agent_gateway:replace-with-local-postgres-password@localhost:54100/nodedc_agent_gateway}" +GATEWAY_INTERNAL_TOKEN="${GATEWAY_INTERNAL_TOKEN:-replace-with-gateway-internal-token}" +GATEWAY_RUN_TOKEN_TTL_SECONDS="${GATEWAY_RUN_TOKEN_TTL_SECONDS:-43200}" + +passed=0 +failed=0 +skipped=0 + +section() { + printf '\n== %s ==\n' "$1" +} + +pass() { + passed=$((passed + 1)) + printf 'PASS %s\n' "$1" +} + +fail() { + failed=$((failed + 1)) + printf 'FAIL %s\n' "$1" >&2 +} + +skip() { + skipped=$((skipped + 1)) + printf 'SKIP %s\n' "$1" +} + +run_in() { + dir="$1" + label="$2" + command="$3" + + if [ ! -d "$dir" ]; then + fail "$label (missing directory: $dir)" + return 0 + fi + + printf '\n$ %s\n' "$label" + set +e + (cd "$dir" && sh -lc "$command") + status=$? + set -e + + if [ "$status" -eq 0 ]; then + pass "$label" + else + fail "$label (exit $status)" + fi +} + +section "AI Workspace topology classification" +run_in "$PLATFORM_ROOT" \ + "Classify current topology" \ + "infra/scripts/check-ai-workspace-topology.sh" + +section "Platform static and contract gates" +run_in "$PLATFORM_ROOT" \ + "Platform shell syntax" \ + "sh -n infra/scripts/init-dev-env.sh infra/scripts/check-ai-workspace-topology.sh infra/scripts/check-ai-workspace-config-contract.sh infra/scripts/check-ai-workspace-release-gates.sh infra/synology/check-ai-workspace-apply-plan.sh infra/synology/prepare-ai-workspace-env.sh infra/synology/deploy-current.sh infra/synology/verify-current-runtime.sh infra/synology/apply-current-runtime.sh infra/synology/backup-current.sh" +run_in "$PLATFORM_ROOT" \ + "AI Workspace config contract" \ + "infra/scripts/check-ai-workspace-config-contract.sh" +run_in "$AI_ASSISTANT_DIR" \ + "AI Workspace Assistant server syntax" \ + "node --check src/server.mjs" +run_in "$AI_ASSISTANT_DIR" \ + "AI Workspace run profile smoke" \ + "npm run smoke:run-profile" +run_in "$PLATFORM_ROOT" \ + "Platform diff hygiene" \ + "git diff --check" + +section "Ops Gateway static and vertical gates" +if [ -d "$OPS_GATEWAY_REPO" ]; then + run_in "$OPS_GATEWAY_REPO" \ + "Ops Gateway TypeScript check" \ + "npm run check" + run_in "$OPS_GATEWAY_REPO" \ + "Ops Gateway build" \ + "npm run build" + if [ "$RUN_GATEWAY_SMOKE" = "1" ]; then + run_in "$OPS_GATEWAY_REPO" \ + "Ops Gateway smoke" \ + "DATABASE_URL='$GATEWAY_DATABASE_URL' NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN='$GATEWAY_INTERNAL_TOKEN' NODEDC_AI_WORKSPACE_RUN_TOKEN_TTL_SECONDS='$GATEWAY_RUN_TOKEN_TTL_SECONDS' npm run smoke:gateway" + else + skip "Ops Gateway smoke (RUN_GATEWAY_SMOKE=$RUN_GATEWAY_SMOKE)" + fi + run_in "$OPS_GATEWAY_REPO" \ + "Ops Gateway diff hygiene" \ + "git diff --check" +else + fail "Ops Gateway repo not found: $OPS_GATEWAY_REPO" +fi + +section "Engine static gates" +if [ -d "$ENGINE_REPO" ]; then + run_in "$ENGINE_REPO" \ + "Engine AI Workspace client syntax" \ + "node --check nodedc-source/server/aiWorkspace/assistantRegistryClient.js" + run_in "$ENGINE_REPO" \ + "Engine diff hygiene" \ + "git diff --check" +else + fail "Engine repo not found: $ENGINE_REPO" +fi + +section "Summary" +printf 'passed=%s failed=%s skipped=%s\n' "$passed" "$failed" "$skipped" + +if [ "$failed" -ne 0 ]; then + exit 1 +fi diff --git a/infra/scripts/check-ai-workspace-topology.sh b/infra/scripts/check-ai-workspace-topology.sh new file mode 100755 index 0000000..6494c59 --- /dev/null +++ b/infra/scripts/check-ai-workspace-topology.sh @@ -0,0 +1,194 @@ +#!/usr/bin/env sh +set -eu + +SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd) +INFRA_DIR=$(CDPATH= cd -- "$SCRIPT_DIR/.." && pwd) +PLATFORM_ENV="${PLATFORM_ENV:-$INFRA_DIR/.env}" + +ASSISTANT_URL="${ASSISTANT_URL:-http://127.0.0.1:18082}" +HUB_URL="${HUB_URL:-http://127.0.0.1:18081}" +GATEWAY_URL="${GATEWAY_URL:-http://127.0.0.1:4100}" +TASK_URL="${TASK_URL:-http://task.local.nodedc/}" +ENGINE_URL="${ENGINE_URL:-http://127.0.0.1:5300/}" + +read_env() { + file="$1" + key="$2" + if [ ! -f "$file" ]; then + return 0 + fi + awk -F= -v key="$key" ' + $0 ~ "^[[:space:]]*#" { next } + $1 == key { + value = substr($0, index($0, "=") + 1) + gsub(/^[[:space:]]+|[[:space:]]+$/, "", value) + gsub(/^"|"$/, "", value) + print value + exit + } + ' "$file" +} + +http_status() { + url="$1" + curl -k -sS -o /dev/null -w "%{http_code}" --max-time 3 "$url" 2>/dev/null || true +} + +http_body() { + url="$1" + curl -k -sS --max-time 3 "$url" 2>/dev/null || true +} + +ok_status() { + code="$1" + case "$code" in + 2*|3*) printf true ;; + *) printf false ;; + esac +} + +json_number() { + key="$1" + sed -n "s/.*\"$key\"[[:space:]]*:[[:space:]]*\\([0-9][0-9]*\\).*/\\1/p" | head -n 1 +} + +url_kind() { + value="$1" + case "$value" in + "") + printf missing + ;; + *127.0.0.1*|*localhost*|*host.docker.internal*|*".local.nodedc"*|*ai-workspace-hub*|*agent-gateway*) + printf local + ;; + *100.[6-9][0-9].*|*100.1[01][0-9].*|*100.12[0-7].*|*.ts.net*) + printf tailscale + ;; + *172.22.0.222*|*".nas.nodedc"*) + printf synology-lan + ;; + *ai-hub.nodedc.ru*|*ops-agents.nodedc.ru*|*hub.nodedc.ru*|*ops.nodedc.ru*) + printf prod-public + ;; + http://172.*|http://192.168.*|http://10.*) + printf lan + ;; + *) + printf custom + ;; + esac +} + +bool_and() { + left="$1" + right="$2" + if [ "$left" = true ] && [ "$right" = true ]; then + printf true + else + printf false + fi +} + +assistant_code=$(http_status "$ASSISTANT_URL/healthz") +hub_body=$(http_body "$HUB_URL/healthz") +hub_code=000 +if [ -n "$hub_body" ]; then + hub_code=$(http_status "$HUB_URL/healthz") +fi +gateway_code=$(http_status "$GATEWAY_URL/readyz") +task_code=$(http_status "$TASK_URL") +engine_code=$(http_status "$ENGINE_URL") + +assistant_ok=$(ok_status "$assistant_code") +hub_ok=$(ok_status "$hub_code") +gateway_ok=$(ok_status "$gateway_code") +task_ok=$(ok_status "$task_code") +engine_ok=$(ok_status "$engine_code") + +agents_online=$(printf "%s" "$hub_body" | json_number agentsOnline) +case "$agents_online" in + ""|*[!0-9]*) agents_online=0 ;; +esac + +hub_public=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_HUB_PUBLIC_URL || true) +hub_internal=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_HUB_INTERNAL_URL || true) +ops_entitlement=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_OPS_ENTITLEMENT_URL || true) + +hub_public_kind=$(url_kind "$hub_public") +hub_internal_kind=$(url_kind "$hub_internal") +ops_entitlement_kind=$(url_kind "$ops_entitlement") + +local_services_ok=$(bool_and "$(bool_and "$assistant_ok" "$hub_ok")" "$(bool_and "$gateway_ok" "$task_ok")") +worker_on_local_hub=false +if [ "$agents_online" -gt 0 ]; then + worker_on_local_hub=true +fi + +hub_runtime_kind=custom +case "$hub_public_kind:$hub_internal_kind" in + local:local|local:missing|missing:local) hub_runtime_kind=local ;; + tailscale:local|tailscale:tailscale|tailscale:missing) hub_runtime_kind=tailscale ;; + prod-public:prod-public|prod-public:missing|missing:prod-public) hub_runtime_kind=prod-public ;; + *) hub_runtime_kind=mixed ;; +esac + +classification=contract-only +if [ "$local_services_ok" = true ]; then + if [ "$engine_ok" = true ] \ + && [ "$worker_on_local_hub" = true ] \ + && [ "$ops_entitlement_kind" = local ] \ + && [ "$hub_runtime_kind" = local ]; then + classification=true-local-e2e + elif [ "$engine_ok" = true ] \ + && [ "$worker_on_local_hub" = true ] \ + && { [ "$ops_entitlement_kind" = tailscale ] || [ "$hub_runtime_kind" = tailscale ]; }; then + classification=tunnel-local-e2e + elif [ "$hub_runtime_kind" = prod-public ] || [ "$worker_on_local_hub" = false ]; then + classification=hybrid-prod-bridge + else + classification=local-ops-vertical + fi +elif [ "$gateway_ok" = true ] && [ "$task_ok" = true ]; then + classification=local-ops-vertical +elif [ "$task_ok" = true ] || [ "$engine_ok" = true ]; then + classification=local-ui-only +fi + +cat < +AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED=false +``` + ## Локальные домены для первичной проверки На Mac для первичной проверки добавить в `/etc/hosts`: @@ -137,6 +145,8 @@ GATEWAY_REPO=/Users/dcconstructions/Downloads/mnt/data/NODEDC_TASKMANAGER_CODEXA Скрипт не запускает Docker сам: на NAS `sudo` интерактивный, поэтому команды применения печатаются в конце. +По умолчанию sync source-копий на SMB/NAS не сохраняет owner/group/perms/times. Для Docker build важен контент, а macOS/Synology metadata может падать на `utimensat Operation timed out`. Если metadata действительно нужно сохранить для отдельного ручного случая, запускать с `RSYNC_PRESERVE_METADATA=1`. + Что синхронизируется: - Platform compose/Caddy. diff --git a/infra/synology/apply-current-runtime.sh b/infra/synology/apply-current-runtime.sh index 677a33e..69f00a8 100755 --- a/infra/synology/apply-current-runtime.sh +++ b/infra/synology/apply-current-runtime.sh @@ -57,6 +57,10 @@ echo "== ai workspace assistant hub target check ==" "${DOCKER_BIN}" exec nodedc-platform-ai-workspace-assistant-1 sh -lc \ 'test "$AI_WORKSPACE_HUB_PUBLIC_URL" = "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" && test -z "$AI_WORKSPACE_HUB_FALLBACK_URLS" && echo ai-workspace-prod-hub-target-ok' +echo "== ai workspace assistant Ops entitlement adapter check ==" +"${DOCKER_BIN}" exec nodedc-platform-ai-workspace-assistant-1 sh -lc \ + 'test "$AI_WORKSPACE_OPS_ENTITLEMENT_URL" = "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" && test -n "$AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN" && echo ai-workspace-ops-entitlement-env-ok' + echo "== clear authentik global brand css ==" DOCKER_BIN="${DOCKER_BIN}" bash "${PLATFORM_DIR}/clear-authentik-brand-css.sh" diff --git a/infra/synology/backup-current.sh b/infra/synology/backup-current.sh index 7829888..7bb274e 100755 --- a/infra/synology/backup-current.sh +++ b/infra/synology/backup-current.sh @@ -46,6 +46,7 @@ rsync_dir "${NAS_ROOT}/authentik/custom-templates/" "${BACKUP_DIR}/files/authent rsync_dir "${NAS_ROOT}/platform/authentik/" "${BACKUP_DIR}/files/platform/authentik/" rsync_dir "${NAS_ROOT}/platform/notification-core/" "${BACKUP_DIR}/files/platform/notification-core/" rsync_dir "${NAS_ROOT}/platform/ai-workspace-hub/" "${BACKUP_DIR}/files/platform/ai-workspace-hub/" +rsync_dir "${NAS_ROOT}/platform/ai-workspace-assistant/" "${BACKUP_DIR}/files/platform/ai-workspace-assistant/" rsync_file "${NAS_ROOT}/platform/.env.synology" "${BACKUP_DIR}/files/platform/" rsync_file "${NAS_ROOT}/platform/.env.synology.example" "${BACKUP_DIR}/files/platform/" @@ -73,6 +74,7 @@ Contains: - Platform runtime config: platform/.env.synology, compose, Caddyfile - Notification Core source/config: platform/notification-core, platform compose/env - AI Workspace Hub source/config: platform/ai-workspace-hub, platform compose/env +- AI Workspace Assistant source/config: platform/ai-workspace-assistant, platform compose/env - Tasker runtime config: tasker/plane-app/.env.synology, compose, Synology override - Ops Agents Gateway runtime config: ops-agents/.env, compose @@ -101,8 +103,24 @@ sudo "${DOCKER_BIN}" compose \\ --env-file "${ENV_FILE}" \\ -f "${COMPOSE_FILE}" \\ exec -T postgresql-authentik \\ - sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\ - < "\${BACKUP_DIR}/authentik-postgres.dump" + rm -f /tmp/authentik-postgres.dump + +sudo "${DOCKER_BIN}" compose \\ + --env-file "${ENV_FILE}" \\ + -f "${COMPOSE_FILE}" \\ + cp "\${BACKUP_DIR}/authentik-postgres.dump" postgresql-authentik:/tmp/authentik-postgres.dump + +sudo "${DOCKER_BIN}" compose \\ + --env-file "${ENV_FILE}" \\ + -f "${COMPOSE_FILE}" \\ + exec -T postgresql-authentik \\ + pg_restore --list /tmp/authentik-postgres.dump >/dev/null + +sudo "${DOCKER_BIN}" compose \\ + --env-file "${ENV_FILE}" \\ + -f "${COMPOSE_FILE}" \\ + exec -T postgresql-authentik \\ + rm -f /tmp/authentik-postgres.dump if command -v sha256sum >/dev/null 2>&1; then (cd "\${BACKUP_DIR}" && sha256sum authentik-postgres.dump > SHA256SUMS) @@ -132,8 +150,24 @@ sudo "${DOCKER_BIN}" compose \\ --env-file "${ENV_FILE}" \\ -f "${COMPOSE_FILE}" \\ exec -T notification-postgres \\ - sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\ - < "\${BACKUP_DIR}/notification-postgres.dump" + rm -f /tmp/notification-postgres.dump + +sudo "${DOCKER_BIN}" compose \\ + --env-file "${ENV_FILE}" \\ + -f "${COMPOSE_FILE}" \\ + cp "\${BACKUP_DIR}/notification-postgres.dump" notification-postgres:/tmp/notification-postgres.dump + +sudo "${DOCKER_BIN}" compose \\ + --env-file "${ENV_FILE}" \\ + -f "${COMPOSE_FILE}" \\ + exec -T notification-postgres \\ + pg_restore --list /tmp/notification-postgres.dump >/dev/null + +sudo "${DOCKER_BIN}" compose \\ + --env-file "${ENV_FILE}" \\ + -f "${COMPOSE_FILE}" \\ + exec -T notification-postgres \\ + rm -f /tmp/notification-postgres.dump echo "notification-db-dump-ok: \${BACKUP_DIR}/notification-postgres.dump" EOF @@ -158,8 +192,18 @@ sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\ sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\ exec -T plane-db \\ - sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\ - < "\${BACKUP_DIR}/tasker-postgres.dump" + rm -f /tmp/tasker-postgres.dump + +sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\ + cp "\${BACKUP_DIR}/tasker-postgres.dump" plane-db:/tmp/tasker-postgres.dump + +sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\ + exec -T plane-db \\ + pg_restore --list /tmp/tasker-postgres.dump >/dev/null + +sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\ + exec -T plane-db \\ + rm -f /tmp/tasker-postgres.dump echo "tasker-db-dump-ok: \${BACKUP_DIR}/tasker-postgres.dump" EOF @@ -183,8 +227,24 @@ sudo "${DOCKER_BIN}" compose \\ --env-file .env \\ -f docker-compose.synology.yml \\ exec -T postgres \\ - sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\ - < "\${BACKUP_DIR}/ops-agents-postgres.dump" + rm -f /tmp/ops-agents-postgres.dump + +sudo "${DOCKER_BIN}" compose \\ + --env-file .env \\ + -f docker-compose.synology.yml \\ + cp "\${BACKUP_DIR}/ops-agents-postgres.dump" postgres:/tmp/ops-agents-postgres.dump + +sudo "${DOCKER_BIN}" compose \\ + --env-file .env \\ + -f docker-compose.synology.yml \\ + exec -T postgres \\ + pg_restore --list /tmp/ops-agents-postgres.dump >/dev/null + +sudo "${DOCKER_BIN}" compose \\ + --env-file .env \\ + -f docker-compose.synology.yml \\ + exec -T postgres \\ + rm -f /tmp/ops-agents-postgres.dump echo "ops-agents-db-dump-ok: \${BACKUP_DIR}/ops-agents-postgres.dump" EOF diff --git a/infra/synology/check-ai-workspace-apply-plan.sh b/infra/synology/check-ai-workspace-apply-plan.sh new file mode 100755 index 0000000..c2768bc --- /dev/null +++ b/infra/synology/check-ai-workspace-apply-plan.sh @@ -0,0 +1,190 @@ +#!/usr/bin/env bash +set -euo pipefail + +SCRIPT_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)" +PLATFORM_REPO="$(cd -- "${SCRIPT_DIR}/../.." && pwd)" +NAS_ROOT="${NAS_ROOT:-/Volumes/docker/nodedc-platform}" +GATEWAY_REPO="${GATEWAY_REPO:-${PLATFORM_REPO}/../../data/NODEDC_TASKMANAGER_CODEXAPI}" +ENGINE_REPO="${ENGINE_REPO:-${PLATFORM_REPO}/../NODEDC_ENGINE_INFRA}" + +NAS_PLATFORM_ENV="${NAS_PLATFORM_ENV:-${NAS_ROOT}/platform/.env.synology}" +NAS_GATEWAY_ENV="${NAS_GATEWAY_ENV:-${NAS_ROOT}/ops-agents/.env}" + +passed=0 +failed=0 +warnings=0 + +section() { + printf '\n== %s ==\n' "$1" +} + +pass() { + passed=$((passed + 1)) + printf 'PASS %s\n' "$1" +} + +fail() { + failed=$((failed + 1)) + printf 'FAIL %s\n' "$1" >&2 +} + +warn() { + warnings=$((warnings + 1)) + printf 'WARN %s\n' "$1" >&2 +} + +read_env() { + local file="$1" + local key="$2" + [[ -f "${file}" ]] || return 0 + awk -F= -v key="${key}" ' + $0 ~ "^[[:space:]]*#" { next } + $1 == key { + value = substr($0, index($0, "=") + 1) + gsub(/^[[:space:]]+|[[:space:]]+$/, "", value) + gsub(/^"|"$/, "", value) + print value + exit + } + ' "${file}" +} + +require_path() { + local path="$1" + local label="$2" + if [[ -e "${path}" ]]; then + pass "${label}" + else + fail "${label} (missing: ${path})" + fi +} + +require_file_contains() { + local file="$1" + local needle="$2" + local label="$3" + if [[ ! -f "${file}" ]]; then + fail "${label} (missing file: ${file})" + return + fi + if grep -Fq "${needle}" "${file}"; then + pass "${label}" + else + fail "${label} (missing: ${needle})" + fi +} + +require_env_value() { + local file="$1" + local key="$2" + local expected="$3" + local label="$4" + local actual + actual="$(read_env "${file}" "${key}" || true)" + if [[ "${actual}" == "${expected}" ]]; then + pass "${label}" + else + fail "${label} (expected ${key}=${expected}, got ${actual:-})" + fi +} + +require_env_nonempty() { + local file="$1" + local key="$2" + local label="$3" + local actual + actual="$(read_env "${file}" "${key}" || true)" + if [[ -n "${actual}" && "${actual}" != replace-with-* && "${actual}" != change-me-* ]]; then + pass "${label}" + else + fail "${label} (${key} missing or placeholder)" + fi +} + +section "Local prerequisites" +require_path "${NAS_ROOT}" "NAS mount exists" +require_path "${GATEWAY_REPO}" "Ops Gateway repo exists" +require_path "${ENGINE_REPO}" "Engine repo exists" +require_path "${PLATFORM_REPO}/infra/scripts/check-ai-workspace-release-gates.sh" "Predeploy gate runner exists" +require_path "${PLATFORM_REPO}/infra/scripts/check-ai-workspace-config-contract.sh" "Config contract checker exists" +require_path "${PLATFORM_REPO}/infra/synology/backup-current.sh" "Synology backup script exists" +require_path "${PLATFORM_REPO}/infra/synology/apply-current-runtime.sh" "Synology apply script exists" +require_path "${PLATFORM_REPO}/infra/synology/verify-current-runtime.sh" "Synology verify script exists" + +section "Source and migration audit" +require_path "${PLATFORM_REPO}/services/ai-workspace-assistant/src/server.mjs" "AI Workspace Assistant source present" +require_path "${PLATFORM_REPO}/services/ai-workspace-assistant/src/templates/install-windows.ps1" "Worker installer template present" +require_path "${GATEWAY_REPO}/migrations/004_run_grants.sql" "Ops Gateway token-scoped run grants migration present" +require_file_contains "${GATEWAY_REPO}/docker-entrypoint.sh" "npm run migrate:dist" "Ops Gateway image applies migrations on startup" +require_file_contains "${PLATFORM_REPO}/infra/synology/backup-current.sh" "ai-workspace-assistant" "Backup includes AI Workspace Assistant source" +require_file_contains "${PLATFORM_REPO}/infra/synology/deploy-current.sh" "RSYNC_METADATA_ARGS" "Deploy sync avoids fragile NAS metadata by default" +require_file_contains "${PLATFORM_REPO}/infra/synology/apply-current-runtime.sh" "ai-workspace-ops-entitlement-env-ok" "Apply verifies Ops entitlement env" +require_file_contains "${PLATFORM_REPO}/infra/synology/verify-current-runtime.sh" "ai-workspace-ops-entitlement-env-ok" "Verify checks Ops entitlement env" + +section "NAS env readiness" +if [[ -f "${NAS_PLATFORM_ENV}" ]]; then + pass "NAS Platform env exists" + require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_PUBLIC_URL" "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" "NAS Platform worker-facing Hub URL" + require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_INTERNAL_URL" "https://ai-hub.nodedc.ru" "NAS Platform internal Hub URL" + require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_FALLBACK_URLS" "" "NAS Platform Hub fallback URLs disabled" + require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_OPS_ENTITLEMENT_URL" "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" "NAS Platform Ops entitlement URL" + require_env_nonempty "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN" "NAS Platform Ops entitlement token configured" + require_env_nonempty "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_ASSISTANT_TOKEN" "NAS Platform Assistant token configured" + require_env_nonempty "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_TOKEN" "NAS Platform Hub token configured" +else + fail "NAS Platform env missing: ${NAS_PLATFORM_ENV}" +fi + +if [[ -f "${NAS_GATEWAY_ENV}" ]]; then + pass "NAS Ops Gateway env exists" + require_env_value "${NAS_GATEWAY_ENV}" "NODEDC_AGENT_GATEWAY_PUBLIC_URL" "https://ops-agents.nodedc.ru" "NAS Gateway worker-facing MCP URL" + require_env_value "${NAS_GATEWAY_ENV}" "NODEDC_TASKER_INTERNAL_URL" "http://172.22.0.222:18090" "NAS Gateway downstream Tasker URL" + require_env_value "${NAS_GATEWAY_ENV}" "NODEDC_AI_WORKSPACE_RUN_TOKEN_TTL_SECONDS" "43200" "NAS Gateway AI Workspace run token TTL" + require_env_nonempty "${NAS_GATEWAY_ENV}" "NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN" "NAS Gateway internal token configured" + require_env_nonempty "${NAS_GATEWAY_ENV}" "NODEDC_INTERNAL_ACCESS_TOKEN" "NAS Gateway Tasker internal token configured" + require_env_nonempty "${NAS_GATEWAY_ENV}" "POSTGRES_PASSWORD" "NAS Gateway Postgres password configured" +else + fail "NAS Ops Gateway env missing: ${NAS_GATEWAY_ENV}" +fi + +section "Controlled apply order" +cat </run-authentik-db-dump-on-synology.sh + bash /volume1/docker/nodedc-platform/backups//run-notification-db-dump-on-synology.sh + bash /volume1/docker/nodedc-platform/backups//run-ops-agents-db-dump-on-synology.sh + # Tasker DB dump only if Tasker backend/schema changes are included: + bash /volume1/docker/nodedc-platform/backups//run-tasker-db-dump-on-synology.sh + +4. Sync source to NAS mount: + cd ${PLATFORM_REPO} + NAS_ROOT=${NAS_ROOT} GATEWAY_REPO=${GATEWAY_REPO} infra/synology/deploy-current.sh + +5. Apply Ops Gateway first on Synology: + cd /volume1/docker/nodedc-platform/ops-agents + sudo /usr/local/bin/docker compose --env-file .env -f docker-compose.synology.yml up -d --build --force-recreate + curl -fsS http://172.22.0.222:18190/readyz + +6. Apply Platform AI Workspace services on Synology: + cd /volume1/docker/nodedc-platform/platform + sudo bash apply-current-runtime.sh + +7. Verify runtime: + cd /volume1/docker/nodedc-platform/platform + sudo bash verify-current-runtime.sh +EOF + +section "Summary" +printf 'passed=%s failed=%s warnings=%s\n' "${passed}" "${failed}" "${warnings}" + +if [[ "${failed}" -ne 0 ]]; then + exit 1 +fi diff --git a/infra/synology/deploy-current.sh b/infra/synology/deploy-current.sh index a422902..2b1ca97 100755 --- a/infra/synology/deploy-current.sh +++ b/infra/synology/deploy-current.sh @@ -11,6 +11,11 @@ TASKER_CHANGED_BASE="${TASKER_CHANGED_BASE:-}" GATEWAY_REPO="${GATEWAY_REPO:-}" SYNC_AUTHENTIK_TEMPLATES="${SYNC_AUTHENTIK_TEMPLATES:-0}" +RSYNC_METADATA_ARGS=() +if [[ "${RSYNC_PRESERVE_METADATA:-0}" != "1" ]]; then + RSYNC_METADATA_ARGS=(--no-times --no-perms --no-owner --no-group) +fi + if [[ ! -d "${NAS_ROOT}" ]]; then echo "NAS_ROOT not found: ${NAS_ROOT}" >&2 echo "Set NAS_ROOT=/path/to/nodedc-platform when the Synology share is mounted elsewhere." >&2 @@ -19,15 +24,15 @@ fi mkdir -p "${NAS_ROOT}/platform" -rsync -av \ +rsync -av "${RSYNC_METADATA_ARGS[@]}" \ "${PLATFORM_REPO}/infra/synology/docker-compose.platform-http.yml" \ "${NAS_ROOT}/platform/docker-compose.platform-http.yml" -rsync -av \ +rsync -av "${RSYNC_METADATA_ARGS[@]}" \ "${PLATFORM_REPO}/infra/synology/Caddyfile.http" \ "${NAS_ROOT}/platform/Caddyfile.http" -rsync -av \ +rsync -av "${RSYNC_METADATA_ARGS[@]}" \ "${PLATFORM_REPO}/infra/synology/deploy-current.sh" \ "${PLATFORM_REPO}/infra/synology/backup-current.sh" \ "${PLATFORM_REPO}/infra/synology/apply-current-runtime.sh" \ @@ -36,7 +41,7 @@ rsync -av \ "${NAS_ROOT}/platform/" mkdir -p "${NAS_ROOT}/platform/notification-core" -rsync -av --delete \ +rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \ --exclude='node_modules/' \ --exclude='.env' \ --exclude='.env.*' \ @@ -44,7 +49,7 @@ rsync -av --delete \ "${NAS_ROOT}/platform/notification-core/" mkdir -p "${NAS_ROOT}/platform/ai-workspace-hub" -rsync -av --delete \ +rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \ --exclude='node_modules/' \ --exclude='.env' \ --exclude='.env.*' \ @@ -52,7 +57,7 @@ rsync -av --delete \ "${NAS_ROOT}/platform/ai-workspace-hub/" mkdir -p "${NAS_ROOT}/platform/ai-workspace-assistant" -rsync -av --delete \ +rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \ --exclude='node_modules/' \ --exclude='.env' \ --exclude='.env.*' \ @@ -61,7 +66,7 @@ rsync -av --delete \ if [[ "${SYNC_AUTHENTIK_TEMPLATES}" == "1" ]]; then mkdir -p "${NAS_ROOT}/authentik/custom-templates" - rsync -av --delete \ + rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \ "${PLATFORM_REPO}/infra/authentik/custom-templates/" \ "${NAS_ROOT}/authentik/custom-templates/" else @@ -75,7 +80,7 @@ if [[ -n "${LAUNCHER_REPO}" ]]; then fi mkdir -p "${NAS_ROOT}/launcher/source" - rsync -av --delete \ + rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \ --exclude='.git/' \ --exclude='node_modules/' \ --exclude='dist/' \ @@ -95,7 +100,7 @@ if [[ -n "${TASKER_REPO}" ]]; then mkdir -p "${NAS_ROOT}/tasker/plane-src" "${NAS_ROOT}/tasker/plane-app" - rsync -av \ + rsync -av "${RSYNC_METADATA_ARGS[@]}" \ "${TASKER_REPO}/plane-app/docker-compose.yaml" \ "${NAS_ROOT}/tasker/plane-app/docker-compose.yaml" @@ -121,14 +126,14 @@ if [[ -n "${TASKER_REPO}" ]]; then if [[ -f "${source_path}" ]]; then mkdir -p "$(dirname -- "${target_path}")" - rsync -av "${source_path}" "${target_path}" + rsync -av "${RSYNC_METADATA_ARGS[@]}" "${source_path}" "${target_path}" else echo "skip deleted Tasker file in changed sync: ${changed_file}" fi done elif [[ "${TASKER_SYNC_SOURCE}" == "1" ]]; then echo "TASKER_SYNC_SOURCE=1: syncing full Tasker source without delete" - rsync -av \ + rsync -av "${RSYNC_METADATA_ARGS[@]}" \ --exclude='.git/' \ --exclude='node_modules/' \ --exclude='.pnpm-store/' \ @@ -153,7 +158,7 @@ if [[ -n "${TASKER_REPO}" ]]; then fi if [[ -f "${TASKER_REPO}/plane-app/docker-compose.synology.override.yml" ]]; then - rsync -av \ + rsync -av "${RSYNC_METADATA_ARGS[@]}" \ "${TASKER_REPO}/plane-app/docker-compose.synology.override.yml" \ "${NAS_ROOT}/tasker/plane-app/docker-compose.synology.override.yml" else @@ -170,7 +175,7 @@ if [[ -n "${GATEWAY_REPO}" ]]; then fi mkdir -p "${NAS_ROOT}/ops-agents" - rsync -av --delete \ + rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \ --exclude='.git/' \ --exclude='node_modules/' \ --exclude='dist/' \ diff --git a/infra/synology/prepare-ai-workspace-env.sh b/infra/synology/prepare-ai-workspace-env.sh new file mode 100755 index 0000000..9f44b16 --- /dev/null +++ b/infra/synology/prepare-ai-workspace-env.sh @@ -0,0 +1,98 @@ +#!/usr/bin/env bash +set -euo pipefail + +NAS_ROOT="${NAS_ROOT:-/Volumes/docker/nodedc-platform}" +PLATFORM_ENV="${PLATFORM_ENV:-${NAS_ROOT}/platform/.env.synology}" +GATEWAY_ENV="${GATEWAY_ENV:-${NAS_ROOT}/ops-agents/.env}" +BACKUP_ROOT="${BACKUP_ROOT:-${NAS_ROOT}/backups/env-prep}" +TIMESTAMP="${TIMESTAMP:-$(date +%Y%m%d-%H%M%S)}" +BACKUP_DIR="${BACKUP_DIR:-${BACKUP_ROOT}/${TIMESTAMP}}" + +mkdir -p "${BACKUP_DIR}" + +read_env() { + local file="$1" + local key="$2" + [[ -f "${file}" ]] || return 0 + awk -F= -v key="${key}" ' + $0 ~ "^[[:space:]]*#" { next } + $1 == key { + value = substr($0, index($0, "=") + 1) + gsub(/^[[:space:]]+|[[:space:]]+$/, "", value) + gsub(/^"|"$/, "", value) + print value + exit + } + ' "${file}" +} + +backup_file() { + local file="$1" + local label="$2" + if [[ ! -f "${file}" ]]; then + echo "missing ${label}: ${file}" >&2 + exit 1 + fi + local backup_path="${BACKUP_DIR}/$(basename "${file}").${label}.bak" + if ! COPYFILE_DISABLE=1 cp -X "${file}" "${backup_path}" 2>/dev/null; then + cat "${file}" > "${backup_path}" + fi + chmod 600 "${backup_path}" +} + +set_env_value() { + local file="$1" + local key="$2" + local value="$3" + local tmp + tmp="$(mktemp)" + if grep -qE "^${key}=" "${file}"; then + awk -v key="${key}" -v value="${value}" ' + BEGIN { replaced = 0 } + $0 ~ "^[[:space:]]*#" { print; next } + index($0, key "=") == 1 { + print key "=" value + replaced = 1 + next + } + { print } + END { + if (!replaced) { + print key "=" value + } + } + ' "${file}" > "${tmp}" + else + cat "${file}" > "${tmp}" + printf '\n%s=%s\n' "${key}" "${value}" >> "${tmp}" + fi + cat "${tmp}" > "${file}" + rm -f "${tmp}" + chmod 600 "${file}" +} + +gateway_internal_token="$(read_env "${GATEWAY_ENV}" NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN || true)" +if [[ -z "${gateway_internal_token}" || "${gateway_internal_token}" == replace-with-* || "${gateway_internal_token}" == change-me-* ]]; then + echo "Gateway NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN is missing or placeholder in ${GATEWAY_ENV}" >&2 + exit 1 +fi + +backup_file "${PLATFORM_ENV}" platform +backup_file "${GATEWAY_ENV}" ops-agents + +set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_HUB_PUBLIC_URL "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" +set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_HUB_INTERNAL_URL "https://ai-hub.nodedc.ru" +set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_HUB_FALLBACK_URLS "" +set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_OPS_ENTITLEMENT_URL "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" +set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN "${gateway_internal_token}" +set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED "false" + +set_env_value "${GATEWAY_ENV}" NODEDC_AI_WORKSPACE_RUN_TOKEN_TTL_SECONDS "43200" + +cat < server.serverName), + requiredMcpServerNames: mcpServers.filter((server) => server.required).map((server) => server.serverName), + }, + diagnostics: { + schemaVersion: "ai-workspace.run-profile.diagnostics.v1", + dynamicProfile: true, + sourceSurface: "engine", + modeId: "ops", + entitlementAdapters: { + source: "adapters+settings", + adapters: [{ appId: "ops", status: "ok", required: true }], + }, + mcpServerNames: mcpServers.map((server) => server.serverName), + }, +}; +runProfile.diagnostics.profileHash = runProfileHash(runProfile); +const publicProfile = redactRunProfile(runProfile); + +assert.deepEqual(Object.keys(appGrants), ["ops"]); +assert.equal(appGrants.ops.source, "entitlement-adapter"); +assert.equal(appGrants.ops.appId, "ops"); +assert.deepEqual(appGrantSummary.ops.scopes, ["workspace:read", "project:read", "issue:read"]); +assert.equal(appGrantSummary.ops.hasMcpServers, true); +assert.deepEqual(appGrantSummary.ops.mcpServerNames, ["nodedc_ops_agent"]); + +assert.equal(mcpServers.length, 1); +assert.equal(mcpServers[0].appId, "ops"); +assert.equal(mcpServers[0].serverName, "nodedc_ops_agent"); +assert.equal(mcpServers[0].required, true); +assert.equal(mcpServers[0].httpHeaders.Authorization, `Bearer ${SECRET_TOKEN}`); +assert.equal(mcpServers[0].httpHeaders.Accept, "application/json"); + +assert.equal(publicProfile.toolProfile.mcpServers.length, 1); +assert.equal(publicProfile.toolProfile.mcpServers[0].serverName, "nodedc_ops_agent"); +assert.equal(publicProfile.toolProfile.mcpServers[0].httpHeaders.Authorization, ""); +assert.equal(publicProfile.toolProfile.mcpServers[0].httpHeaders.Accept, ""); +assert.equal(publicProfile.toolProfile.mcpServers[0].headers, undefined); +assert.equal(JSON.stringify(publicProfile).includes(SECRET_TOKEN), false); +assert.match(runProfile.diagnostics.profileHash, /^[a-f0-9]{16}$/); + +console.log(JSON.stringify({ + ok: true, + checks: [ + "adapter_grant_normalized", + "token_scoped_ops_mcp_in_run_profile", + "public_run_profile_redacts_mcp_headers", + "stable_public_profile_hash", + ], + mcpServerNames: runProfile.toolProfile.mcpServerNames, + profileHash: runProfile.diagnostics.profileHash, +}, null, 2)); + +function normalizeEntitlementAdapterAppGrants(payload, currentAdapter) { + const source = isPlainObject(payload?.appGrants) + ? payload.appGrants + : Array.isArray(payload?.appGrants) + ? payload.appGrants + : payload?.grant || payload?.appGrant || payload?.entitlement || payload?.entitlements || payload?.grants || payload; + const out = {}; + if (Array.isArray(source)) { + for (const item of source) { + const grant = normalizeEntitlementAdapterGrant(item, currentAdapter); + if (grant?.appId) out[grant.appId] = grant; + } + return out; + } + if (!isPlainObject(source)) return out; + if (source.mcpServers || source.scopes || source.appId || source.app_id || source.surface) { + const grant = normalizeEntitlementAdapterGrant(source, currentAdapter); + if (grant?.appId) out[grant.appId] = grant; + return out; + } + for (const [key, value] of Object.entries(source)) { + const grant = normalizeEntitlementAdapterGrant(value, { ...currentAdapter, appId: normalizeKey(key) || currentAdapter.appId }); + if (grant?.appId) out[grant.appId] = grant; + } + return out; +} + +function normalizeEntitlementAdapterGrant(value, currentAdapter) { + if (!isPlainObject(value)) return null; + const appId = normalizeKey(value.appId || value.app_id || currentAdapter.appId); + if (!appId) return null; + return { + ...value, + appId, + appTitle: optionalString(value.appTitle || value.app_title || value.title || currentAdapter.title), + surface: optionalString(value.surface) || appId, + source: "entitlement-adapter", + adapterId: currentAdapter.id, + }; +} + +function runProfileMcpServersFromAppGrants(settings, appGrantsInput = {}) { + const servers = []; + const metadata = isPlainObject(settings?.metadata) ? settings.metadata : {}; + collectInstallerMcpServers(servers, metadata.mcpServers, {}); + const grants = isPlainObject(appGrantsInput) ? appGrantsInput : {}; + for (const [appId, grant] of Object.entries(grants)) { + if (!isPlainObject(grant)) continue; + collectInstallerMcpServers(servers, grant.mcpServers, { + appId: optionalString(grant.appId) || normalizeKey(appId), + appTitle: optionalString(grant.appTitle || grant.title), + }); + } + + const byServerName = new Map(); + for (const server of servers.map(sanitizeInstallerMcpServer).filter(Boolean)) { + if (server.enabled === false) continue; + byServerName.set(server.serverName, server); + } + return Array.from(byServerName.values()); +} + +function summarizeRunAppGrants(metadata) { + const grants = isPlainObject(metadata?.appGrants) ? metadata.appGrants : {}; + const out = {}; + for (const [key, value] of Object.entries(grants)) { + if (!isPlainObject(value)) continue; + const appId = optionalString(value.appId) || normalizeKey(key); + if (!appId) continue; + const mcpServers = Array.isArray(value.mcpServers) + ? value.mcpServers + : isPlainObject(value.mcpServers) + ? Object.values(value.mcpServers) + : []; + out[appId] = { + appId, + appTitle: optionalString(value.appTitle || value.title), + surface: optionalString(value.surface) || appId, + updatedAt: optionalString(value.updatedAt || value.updated_at), + context: redactForPublicDiagnostics(isPlainObject(value.context) ? value.context : {}), + scopes: uniqueStrings(Array.isArray(value.scopes) ? value.scopes : []), + hasMcpServers: mcpServers.length > 0, + mcpServerNames: mcpServers + .map((server) => safeMcpServerName(server?.serverName || server?.server_name || server?.name)) + .filter(Boolean), + }; + } + return out; +} + +function collectInstallerMcpServers(target, value, defaults = {}) { + const items = Array.isArray(value) + ? value + : isPlainObject(value) + ? Object.values(value) + : []; + for (const item of items) { + if (!isPlainObject(item)) continue; + target.push({ ...defaults, ...item }); + } +} + +function sanitizeInstallerMcpServer(raw) { + if (!isPlainObject(raw)) return null; + const serverName = safeMcpServerName(raw.serverName || raw.server_name || raw.name); + const url = optionalString(raw.url); + if (!serverName || !url) return null; + const httpHeaders = sanitizeInstallerMcpHeaders(raw.httpHeaders || raw.http_headers || raw.headers); + return { + appId: normalizeKey(raw.appId || raw.app_id) || "global", + appTitle: optionalString(raw.appTitle || raw.app_title || raw.title), + serverName, + url, + enabled: raw.enabled !== false, + required: raw.required === true, + startupTimeoutSec: sanitizeInteger(raw.startupTimeoutSec || raw.startup_timeout_sec, 20, 1, 600), + toolTimeoutSec: sanitizeInteger(raw.toolTimeoutSec || raw.tool_timeout_sec, 60, 1, 3600), + httpHeaders, + }; +} + +function sanitizeInstallerMcpHeaders(value) { + if (!isPlainObject(value)) return {}; + const headers = {}; + for (const [key, rawValue] of Object.entries(value)) { + const headerName = optionalString(key); + const headerValue = optionalString(rawValue); + if (!headerName || !headerValue || headerName.length > 120 || headerValue.length > 4000) continue; + headers[headerName] = headerValue; + } + return headers; +} + +function runProfileHash(runProfile) { + const publicProfile = redactRunProfile(runProfile); + const stableProfile = { + ...publicProfile, + runId: undefined, + createdAt: undefined, + diagnostics: { + ...(isPlainObject(publicProfile?.diagnostics) ? publicProfile.diagnostics : {}), + profileHash: undefined, + }, + }; + return createHash("sha256").update(JSON.stringify(stableProfile)).digest("hex").slice(0, 16); +} + +function redactRunProfile(runProfile) { + if (!isPlainObject(runProfile)) return null; + return { + ...runProfile, + targetContexts: redactForPublicDiagnostics(runProfile.targetContexts), + appGrants: redactForPublicDiagnostics(runProfile.appGrants), + toolProfile: { + ...(isPlainObject(runProfile.toolProfile) ? runProfile.toolProfile : {}), + mcpServers: Array.isArray(runProfile.toolProfile?.mcpServers) + ? runProfile.toolProfile.mcpServers.map(redactMcpServer) + : [], + }, + }; +} + +function redactMcpServer(server) { + if (!isPlainObject(server)) return {}; + const headers = isPlainObject(server.httpHeaders) ? server.httpHeaders : {}; + return { + ...server, + httpHeaders: Object.fromEntries(Object.keys(headers).map((key) => [key, ""])), + headers: undefined, + }; +} + +function redactForPublicDiagnostics(value, depth = 0) { + if (depth > 6) return "[max-depth]"; + if (Array.isArray(value)) return value.map((item) => redactForPublicDiagnostics(item, depth + 1)); + if (!isPlainObject(value)) return value; + const out = {}; + for (const [key, item] of Object.entries(value)) { + const normalizedKey = normalizeKey(key); + if ( + normalizedKey.includes("token") + || normalizedKey.includes("secret") + || normalizedKey.includes("password") + || normalizedKey === "authorization" + || normalizedKey === "cookie" + || normalizedKey === "setcookie" + ) { + out[key] = ""; + } else { + out[key] = redactForPublicDiagnostics(item, depth + 1); + } + } + return out; +} + +function safeMcpServerName(value) { + const text = optionalString(value); + if (!text) return ""; + return text.replace(/[^A-Za-z0-9_-]+/g, "_").replace(/^_+|_+$/g, "").slice(0, 80); +} + +function sanitizeInteger(value, fallback, min, max) { + const number = Number(value || fallback); + if (!Number.isFinite(number)) return fallback; + return Math.min(Math.max(Math.trunc(number), min), max); +} + +function uniqueStrings(values) { + return Array.from(new Set((Array.isArray(values) ? values : []).map(optionalString).filter(Boolean))); +} + +function normalizeKey(value) { + return optionalString(value).toLowerCase().replace(/[^a-z0-9_-]+/g, "_").replace(/^_+|_+$/g, ""); +} + +function optionalString(value) { + if (value === null || value === undefined) return ""; + const text = String(value).trim(); + return text.length ? text : ""; +} + +function isPlainObject(value) { + return Boolean(value) && typeof value === "object" && !Array.isArray(value); +} diff --git a/services/ai-workspace-assistant/src/server.mjs b/services/ai-workspace-assistant/src/server.mjs index 65c13ff..81c64f2 100644 --- a/services/ai-workspace-assistant/src/server.mjs +++ b/services/ai-workspace-assistant/src/server.mjs @@ -326,6 +326,8 @@ app.post("/api/ai-workspace/assistant/v1/threads/:threadId/dispatch", requireInt accessMode: "ops-write", }; } + const runProfile = await buildRunProfile({ owner, thread, executor, ownerSettings, bridgePayload }); + bridgePayload.runProfile = runProfile; let bridge = null; try { bridge = await dispatchExecutorMessage(executor, bridgePayload); @@ -379,6 +381,7 @@ app.post("/api/ai-workspace/assistant/v1/threads/:threadId/dispatch", requireInt executor, message, assistantMessage: null, + runProfile: redactRunProfile(runProfile), bridge, }); })); @@ -1018,6 +1021,7 @@ async function createBridgeRun({ owner, thread, executor, bridge, payload }) { const requestId = optionalString(bridge?.requestId); if (!requestId || bridge?.accepted !== true || bridge?.mode !== "hub") return null; const context = isPlainObject(payload?.context) ? payload.context : {}; + const runProfile = isPlainObject(payload?.runProfile) ? payload.runProfile : null; const metadata = { modeId: optionalString(context.modeId), modeTitle: optionalString(context.modeTitle), @@ -1025,6 +1029,7 @@ async function createBridgeRun({ owner, thread, executor, bridge, payload }) { threadTitle: optionalString(payload?.threadTitle) || thread.title, executorName: executor.name, executorType: executor.type, + runProfile: runProfile ? redactRunProfile(runProfile) : null, }; const result = await pool.query( `insert into ai_workspace_runs ( @@ -1426,6 +1431,367 @@ function buildBridgeMessagePayload({ thread, message, history, executor, command }; } +async function buildRunProfile({ owner, thread, executor, ownerSettings, bridgePayload }) { + const context = isPlainObject(bridgePayload?.context) ? bridgePayload.context : {}; + const sourceSurface = optionalString(context.sourceSurface) + || optionalString(context.surface) + || thread.originSurface + || "global"; + const targetContexts = isPlainObject(context.contexts) ? context.contexts : {}; + const enabledToolPacks = mergeToolPacks( + ownerSettings?.enabledToolPacks, + thread.enabledToolPacks, + bridgePayload?.enabledToolPacks + ); + const grantResolution = await resolveRunAppGrants({ owner, context, ownerSettings }); + const appGrants = summarizeRunAppGrants({ appGrants: grantResolution.appGrants }); + const mcpServers = runProfileMcpServersFromAppGrants(ownerSettings, grantResolution.appGrants); + const mcpServerNames = mcpServers.map((server) => server.serverName).filter(Boolean); + const requiredMcpServerNames = mcpServers + .filter((server) => server.required === true) + .map((server) => server.serverName) + .filter(Boolean); + const diagnostics = { + schemaVersion: "ai-workspace.run-profile.diagnostics.v1", + dynamicProfile: true, + contextReady: context.contextReady !== false, + accessMode: optionalString(context.accessMode) || "chat", + sourceSurface, + modeId: optionalString(context.modeId) || "ops", + targetSurfaces: Object.keys(targetContexts).map(normalizeKey).filter(Boolean).sort(), + enabledToolPacks, + appGrantIds: Object.keys(appGrants).sort(), + entitlementAdapters: grantResolution.diagnostics, + mcpServerNames, + requiredMcpServerNames, + missingContext: Array.isArray(context.missingContext) + ? context.missingContext.map(optionalString).filter(Boolean) + : [], + }; + const runProfile = { + schemaVersion: "ai-workspace.run-profile.v1", + runId: randomUUID(), + createdAt: new Date().toISOString(), + owner: publicOwner(owner), + executor: { + id: executor.id, + type: executor.type, + connectionMode: executor.connectionMode, + }, + sourceSurface, + modeId: optionalString(context.modeId) || "ops", + modeTitle: optionalString(context.modeTitle) || "", + targetContexts: redactForPublicDiagnostics(targetContexts), + enabledToolPacks, + appGrants, + toolProfile: { + schemaVersion: "ai-workspace.tool-profile.v1", + enabledToolPacks, + mcpServers, + mcpServerNames, + requiredMcpServerNames, + }, + policyPrompt: buildRunProfilePolicyPrompt({ context, diagnostics }), + diagnostics, + }; + runProfile.diagnostics.profileHash = runProfileHash(runProfile); + return runProfile; +} + +async function resolveRunAppGrants({ owner, context, ownerSettings }) { + const metadata = isPlainObject(ownerSettings?.metadata) ? ownerSettings.metadata : {}; + const staticAppGrants = isPlainObject(metadata.appGrants) ? metadata.appGrants : {}; + const appGrants = { ...staticAppGrants }; + const adapterDiagnostics = []; + const adapters = Array.isArray(config.entitlementAdapters) ? config.entitlementAdapters : []; + if (!adapters.length) { + return { + appGrants, + diagnostics: { + source: "settings", + adapters: [], + }, + }; + } + + for (const adapter of adapters) { + const result = await fetchRunEntitlementAdapter({ adapter, owner, context, ownerSettings }).catch((error) => ({ + ok: false, + error: errorMessage(error), + })); + if (!result.ok) { + adapterDiagnostics.push({ + appId: adapter.appId, + status: "error", + required: adapter.required === true, + error: sanitizeBridgeErrorText(result.error || "entitlement_adapter_failed"), + }); + if (adapter.required === true) { + const error = new Error(`entitlement_adapter_failed:${adapter.appId}`); + error.status = 502; + throw error; + } + continue; + } + const adapterAppGrants = normalizeEntitlementAdapterAppGrants(result.payload, adapter); + for (const [appId, grant] of Object.entries(adapterAppGrants)) { + if (!isPlainObject(grant)) continue; + const existing = isPlainObject(appGrants[appId]) ? appGrants[appId] : {}; + appGrants[appId] = { + ...existing, + ...grant, + appId, + mcpServers: Object.hasOwn(grant, "mcpServers") ? grant.mcpServers : existing.mcpServers, + }; + } + adapterDiagnostics.push({ + appId: adapter.appId, + status: "ok", + required: adapter.required === true, + grantIds: Object.keys(adapterAppGrants).sort(), + mcpServerNames: Object.values(adapterAppGrants) + .flatMap((grant) => { + const servers = Array.isArray(grant?.mcpServers) + ? grant.mcpServers + : isPlainObject(grant?.mcpServers) + ? Object.values(grant.mcpServers) + : []; + return servers.map((server) => safeMcpServerName(server?.serverName || server?.server_name || server?.name)); + }) + .filter(Boolean), + }); + } + + return { + appGrants, + diagnostics: { + source: adapterDiagnostics.some((item) => item.status === "ok") ? "adapters+settings" : "settings", + adapters: adapterDiagnostics, + }, + }; +} + +async function fetchRunEntitlementAdapter({ adapter, owner, context, ownerSettings }) { + const controller = new AbortController(); + const timeout = setTimeout(() => controller.abort(), adapter.timeoutMs); + const body = JSON.stringify({ + schemaVersion: "ai-workspace.entitlement-request.v1", + appId: adapter.appId, + owner: publicOwner(owner), + activeContext: redactForPublicDiagnostics(isPlainObject(ownerSettings?.activeContext) ? ownerSettings.activeContext : {}), + runContext: redactForPublicDiagnostics(context), + requestedAt: new Date().toISOString(), + }); + try { + const response = await fetch(adapter.url, { + method: "POST", + headers: { + Accept: "application/json", + "Content-Type": "application/json", + ...(adapter.authorization ? { Authorization: adapter.authorization } : {}), + ...adapter.headers, + }, + body, + signal: controller.signal, + }); + const text = await response.text(); + let payload = {}; + try { + payload = text ? JSON.parse(text) : {}; + } catch { + payload = { ok: false, error: "invalid_json_response" }; + } + if (!response.ok || payload?.ok === false) { + throw new Error(optionalString(payload?.error || payload?.message) || `http_${response.status}`); + } + return { ok: true, payload }; + } catch (error) { + if (error?.name === "AbortError") throw new Error("entitlement_adapter_timeout"); + throw error; + } finally { + clearTimeout(timeout); + } +} + +function normalizeEntitlementAdapterAppGrants(payload, adapter) { + const source = isPlainObject(payload?.appGrants) + ? payload.appGrants + : Array.isArray(payload?.appGrants) + ? payload.appGrants + : payload?.grant || payload?.appGrant || payload?.entitlement || payload?.entitlements || payload?.grants || payload; + const out = {}; + if (Array.isArray(source)) { + for (const item of source) { + const grant = normalizeEntitlementAdapterGrant(item, adapter); + if (grant?.appId) out[grant.appId] = grant; + } + return out; + } + if (!isPlainObject(source)) return out; + if (source.mcpServers || source.scopes || source.appId || source.app_id || source.surface) { + const grant = normalizeEntitlementAdapterGrant(source, adapter); + if (grant?.appId) out[grant.appId] = grant; + return out; + } + for (const [key, value] of Object.entries(source)) { + const grant = normalizeEntitlementAdapterGrant(value, { ...adapter, appId: normalizeKey(key) || adapter.appId }); + if (grant?.appId) out[grant.appId] = grant; + } + return out; +} + +function normalizeEntitlementAdapterGrant(value, adapter) { + if (!isPlainObject(value)) return null; + const appId = normalizeKey(value.appId || value.app_id || adapter.appId); + if (!appId) return null; + return { + ...value, + appId, + appTitle: optionalString(value.appTitle || value.app_title || value.title || adapter.title), + surface: optionalString(value.surface) || appId, + source: "entitlement-adapter", + adapterId: adapter.id, + }; +} + +function runProfileMcpServersFromSettings(settings) { + const metadata = isPlainObject(settings?.metadata) ? settings.metadata : {}; + const appGrants = isPlainObject(metadata.appGrants) ? metadata.appGrants : {}; + return runProfileMcpServersFromAppGrants(settings, appGrants); +} + +function runProfileMcpServersFromAppGrants(settings, appGrantsInput = {}) { + const servers = []; + const metadata = isPlainObject(settings?.metadata) ? settings.metadata : {}; + collectInstallerMcpServers(servers, metadata.mcpServers, {}); + const appGrants = isPlainObject(appGrantsInput) ? appGrantsInput : {}; + for (const [appId, grant] of Object.entries(appGrants)) { + if (!isPlainObject(grant)) continue; + collectInstallerMcpServers(servers, grant.mcpServers, { + appId: optionalString(grant.appId) || normalizeKey(appId), + appTitle: optionalString(grant.appTitle || grant.title), + }); + } + + const byServerName = new Map(); + for (const server of servers.map(sanitizeInstallerMcpServer).filter(Boolean)) { + if (server.enabled === false) continue; + byServerName.set(server.serverName, server); + } + return Array.from(byServerName.values()); +} + +function summarizeRunAppGrants(metadata) { + const appGrants = isPlainObject(metadata?.appGrants) ? metadata.appGrants : {}; + const out = {}; + for (const [key, value] of Object.entries(appGrants)) { + if (!isPlainObject(value)) continue; + const appId = optionalString(value.appId) || normalizeKey(key); + if (!appId) continue; + const mcpServers = Array.isArray(value.mcpServers) + ? value.mcpServers + : isPlainObject(value.mcpServers) + ? Object.values(value.mcpServers) + : []; + out[appId] = { + appId, + appTitle: optionalString(value.appTitle || value.title), + surface: optionalString(value.surface) || appId, + updatedAt: optionalString(value.updatedAt || value.updated_at), + context: redactForPublicDiagnostics(isPlainObject(value.context) ? value.context : {}), + scopes: uniqueStrings(Array.isArray(value.scopes) ? value.scopes : []), + hasMcpServers: mcpServers.length > 0, + mcpServerNames: mcpServers + .map((server) => safeMcpServerName(server?.serverName || server?.server_name || server?.name)) + .filter(Boolean), + }; + } + return out; +} + +function buildRunProfilePolicyPrompt({ context, diagnostics }) { + const lines = [ + "AI Workspace dynamic run profile:", + `- source surface: ${diagnostics.sourceSurface}`, + `- mode: ${diagnostics.modeId}`, + `- access mode: ${diagnostics.accessMode}`, + `- context ready: ${diagnostics.contextReady ? "yes" : "no"}`, + `- entitlement source: ${diagnostics.entitlementAdapters?.source || "settings"}`, + `- enabled tool packs: ${diagnostics.enabledToolPacks.length ? diagnostics.enabledToolPacks.join(", ") : "none"}`, + `- MCP servers available in this run: ${diagnostics.mcpServerNames.length ? diagnostics.mcpServerNames.join(", ") : "none"}`, + "- MCP tokens and headers are runtime secrets and must never be printed in public answers.", + ]; + const opsContext = isPlainObject(context?.contexts?.ops) ? context.contexts.ops : {}; + if (opsContext.opsWorkspaceSlug || opsContext.opsProjectId) { + lines.push( + `- Ops target workspace: ${opsContext.opsWorkspaceSlug || opsContext.opsWorkspaceId || "unknown"}`, + `- Ops target project: ${opsContext.opsProjectId || "unknown"}` + ); + } + const engineContext = isPlainObject(context?.contexts?.engine) ? context.contexts.engine : {}; + if (engineContext.workflowId || engineContext.agentNodeId) { + lines.push( + `- Engine target workflow: ${engineContext.workflowId || "unknown"}`, + `- Engine target agent node: ${engineContext.agentNodeId || "unknown"}` + ); + } + return lines.join("\n"); +} + +function runProfileHash(runProfile) { + const publicProfile = redactRunProfile(runProfile); + const stableProfile = { + ...publicProfile, + runId: undefined, + createdAt: undefined, + diagnostics: { + ...(isPlainObject(publicProfile?.diagnostics) ? publicProfile.diagnostics : {}), + profileHash: undefined, + }, + }; + return createHash("sha256").update(JSON.stringify(stableProfile)).digest("hex").slice(0, 16); +} + +function redactRunProfile(runProfile) { + if (!isPlainObject(runProfile)) return null; + return { + ...runProfile, + targetContexts: redactForPublicDiagnostics(runProfile.targetContexts), + appGrants: redactForPublicDiagnostics(runProfile.appGrants), + toolProfile: { + ...(isPlainObject(runProfile.toolProfile) ? runProfile.toolProfile : {}), + mcpServers: Array.isArray(runProfile.toolProfile?.mcpServers) + ? runProfile.toolProfile.mcpServers.map(redactMcpServer) + : [], + }, + }; +} + +function redactMcpServer(server) { + if (!isPlainObject(server)) return {}; + const headers = isPlainObject(server.httpHeaders) ? server.httpHeaders : {}; + return { + ...server, + httpHeaders: Object.fromEntries(Object.keys(headers).map((key) => [key, ""])), + headers: undefined, + }; +} + +function redactForPublicDiagnostics(value, depth = 0) { + if (depth > 6) return "[max-depth]"; + if (Array.isArray(value)) return value.map((item) => redactForPublicDiagnostics(item, depth + 1)); + if (!isPlainObject(value)) return value; + const out = {}; + for (const [key, item] of Object.entries(value)) { + if (/token|secret|password|authorization|cookie|api[_-]?key/i.test(key)) { + out[key] = ""; + continue; + } + out[key] = redactForPublicDiagnostics(item, depth + 1); + } + return out; +} + function mergeSurfaceContexts(...contexts) { const out = {}; for (const context of contexts) { @@ -2188,6 +2554,13 @@ function sanitizeDispatchCommand(payload) { function getRequestOwner(req) { const userId = optionalString(req.headers["x-nodedc-user-id"] || req.query.userId); const email = normalizeEmail(req.headers["x-nodedc-user-email"] || req.query.email); + const role = normalizeKey(req.headers["x-nodedc-user-role"] || req.query.role); + const groups = uniqueStrings( + String(req.headers["x-nodedc-user-groups"] || req.query.groups || "") + .split(/[\n,;]+/) + .map((item) => item.trim()) + .filter(Boolean) + ); if (!userId && !email) { throw badRequest("ai_workspace_owner_required"); } @@ -2195,6 +2568,8 @@ function getRequestOwner(req) { key: email ? `email:${email}` : `user:${userId}`, userId, email, + role: role || "", + groups, }; } @@ -2203,6 +2578,8 @@ function publicOwner(owner) { ownerKey: owner.key, userId: owner.userId, email: owner.email, + role: owner.role || "", + groups: Array.isArray(owner.groups) ? owner.groups : [], }; } @@ -2568,6 +2945,111 @@ function isDeployedPublicHubUrl(value) { } } +function parseEntitlementAdapters() { + const adapters = []; + collectEntitlementAdapters(adapters, parseJsonEnv( + process.env.AI_WORKSPACE_ENTITLEMENT_ADAPTERS_JSON || + process.env.NDC_AI_WORKSPACE_ENTITLEMENT_ADAPTERS_JSON || + "" + )); + collectEntitlementAdapter(adapters, "ops", { + url: process.env.AI_WORKSPACE_OPS_ENTITLEMENT_URL || process.env.NDC_AI_WORKSPACE_OPS_ENTITLEMENT_URL, + token: process.env.AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN || process.env.NDC_AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN, + required: process.env.AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED || process.env.NDC_AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED, + }); + collectEntitlementAdapter(adapters, "engine", { + url: process.env.AI_WORKSPACE_ENGINE_ENTITLEMENT_URL || process.env.NDC_AI_WORKSPACE_ENGINE_ENTITLEMENT_URL, + token: process.env.AI_WORKSPACE_ENGINE_ENTITLEMENT_TOKEN || process.env.NDC_AI_WORKSPACE_ENGINE_ENTITLEMENT_TOKEN, + required: process.env.AI_WORKSPACE_ENGINE_ENTITLEMENT_REQUIRED || process.env.NDC_AI_WORKSPACE_ENGINE_ENTITLEMENT_REQUIRED, + }); + + const byAppId = new Map(); + for (const adapter of adapters) { + byAppId.set(adapter.appId, adapter); + } + return Array.from(byAppId.values()); +} + +function parseJsonEnv(value) { + const text = optionalString(value); + if (!text) return null; + try { + return JSON.parse(text); + } catch { + return null; + } +} + +function collectEntitlementAdapters(target, value) { + if (Array.isArray(value)) { + for (const item of value) collectEntitlementAdapter(target, "", item); + return; + } + if (!isPlainObject(value)) return; + for (const [appId, adapter] of Object.entries(value)) { + collectEntitlementAdapter(target, appId, adapter); + } +} + +function collectEntitlementAdapter(target, defaultAppId, value) { + const adapter = sanitizeEntitlementAdapter(value, defaultAppId); + if (adapter) target.push(adapter); +} + +function sanitizeEntitlementAdapter(value, defaultAppId = "") { + if (!isPlainObject(value)) return null; + const appId = normalizeKey(value.appId || value.app_id || defaultAppId); + const url = cleanHttpEndpoint(value.url || value.endpoint); + if (!appId || !url) return null; + const tokenEnv = optionalString(value.tokenEnv || value.token_env); + const rawToken = optionalString(value.token || value.bearerToken || value.bearer_token) + || (tokenEnv ? optionalString(process.env[tokenEnv]) : null) + || optionalString(process.env.NODEDC_INTERNAL_ACCESS_TOKEN) + || optionalString(process.env.NODEDC_PLATFORM_SERVICE_TOKEN) + || ""; + const authorization = optionalString(value.authorization || value.Authorization) + || (rawToken + ? rawToken.match(/^Bearer\s+/i) ? rawToken : `Bearer ${rawToken}` + : ""); + return { + id: optionalString(value.id) || appId, + appId, + title: optionalString(value.title || value.appTitle || value.app_title), + url, + authorization, + headers: sanitizeAdapterHeaders(value.headers), + required: value.required === true || isTruthy(value.required), + timeoutMs: sanitizeInteger(value.timeoutMs || value.timeout_ms, 5000, 500, 30000), + }; +} + +function sanitizeAdapterHeaders(value) { + if (!isPlainObject(value)) return {}; + const headers = {}; + for (const [key, rawValue] of Object.entries(value)) { + const headerName = optionalString(key); + const headerValue = optionalString(rawValue); + if (!headerName || !headerValue || /[\r\n\0]/.test(headerName) || /[\r\n\0]/.test(headerValue)) continue; + if (/^authorization$/i.test(headerName)) continue; + headers[headerName] = headerValue; + } + return headers; +} + +function cleanHttpEndpoint(value) { + const text = optionalString(value); + if (!text) return ""; + try { + const url = new URL(text); + if (url.protocol !== "http:" && url.protocol !== "https:") return ""; + url.username = ""; + url.password = ""; + return url.toString().replace(/\/+$/, ""); + } catch { + return ""; + } +} + function readConfig() { const databaseUrl = process.env.DATABASE_URL || @@ -2610,6 +3092,7 @@ function readConfig() { process.env.NODEDC_INTERNAL_ACCESS_TOKEN, process.env.NODEDC_PLATFORM_SERVICE_TOKEN, ]), + entitlementAdapters: parseEntitlementAdapters(), }; } diff --git a/services/ai-workspace-assistant/src/templates/install-windows.ps1 b/services/ai-workspace-assistant/src/templates/install-windows.ps1 index 485507c..0ccd8a6 100644 --- a/services/ai-workspace-assistant/src/templates/install-windows.ps1 +++ b/services/ai-workspace-assistant/src/templates/install-windows.ps1 @@ -765,6 +765,7 @@ const FINAL_MESSAGE_PHASES = new Set(['final', 'final_answer', 'answer']) const BRIDGE_FILE = fileURLToPath(import.meta.url) const BRIDGE_DIR = path.dirname(BRIDGE_FILE) const NDC_AGENT_CODEX_HOME = path.resolve(process.env.AI_BRIDGE_NDC_AGENT_CODEX_HOME || path.join(BRIDGE_DIR, 'codex-home-ndc-agent-core')) +const RUN_CODEX_HOME_ROOT = path.resolve(process.env.AI_BRIDGE_RUN_CODEX_HOME_ROOT || path.join(BRIDGE_DIR, 'codex-home-runs')) const DEFAULT_NDC_AGENT_MCP_API_BASE = 'http://127.0.0.1:3001/api/ndc-agent-mcp' const HUB_URL = String(process.env.AI_BRIDGE_HUB_URL || '').trim() const HUB_URLS = parseHubUrls(process.env.AI_BRIDGE_HUB_URLS || '', HUB_URL) @@ -1047,6 +1048,8 @@ async function readConversations() { function buildPrompt(payload) { const context = payload?.context && typeof payload.context === 'object' ? payload.context : {} + const runProfile = payload?.runProfile && typeof payload.runProfile === 'object' ? payload.runProfile : {} + const runProfilePolicyPrompt = String(runProfile.policyPrompt || '').trim() const userMessage = String(payload?.message || '').trim() const history = payload?.resume ? [] : normalizeHistory(payload?.history || []) const isNdcAgentCore = String(context.modeId || '').trim() === 'ndc-agent-core' @@ -1142,6 +1145,10 @@ function buildPrompt(payload) { 'System context guard:', guardInstruction, ] : [], + ...runProfilePolicyPrompt ? [ + '', + runProfilePolicyPrompt, + ] : [], '', ...history.length ? [ 'Recent conversation from AI Workspace:', @@ -1455,8 +1462,12 @@ function buildResumeArgs(sessionId) { return [...base, 'resume', clean, '-'] } +function isPlainObject(value) { + return Boolean(value && typeof value === 'object' && !Array.isArray(value)) +} + function isNdcAgentCorePayload(payload) { - const context = payload?.context && typeof payload.context === 'object' ? payload.context : {} + const context = isPlainObject(payload?.context) ? payload.context : {} return String(context.modeId || '').trim() === 'ndc-agent-core' } @@ -1564,6 +1575,124 @@ function tomlString(value) { return JSON.stringify(String(value || '')) } +function tomlKey(value) { + const key = String(value || '').trim() + if (/^[A-Za-z0-9_-]+$/.test(key)) return key + return JSON.stringify(key) +} + +function cleanMcpServerName(value) { + const text = String(value || '').trim().replace(/[^A-Za-z0-9_-]+/g, '_').replace(/^_+|_+$/g, '') + return text.slice(0, 80) +} + +function cleanRunDirectoryName(value) { + const text = String(value || '').trim().replace(/[^A-Za-z0-9._-]+/g, '_').replace(/^_+|_+$/g, '') + return (text || `run-${Date.now()}`).slice(0, 120) +} + +function positiveInteger(value, fallback, min = 1, max = 600) { + const parsed = Number(value) + if (!Number.isFinite(parsed)) return fallback + return Math.max(min, Math.min(max, Math.trunc(parsed))) +} + +function runProfileFromPayload(payload) { + return isPlainObject(payload?.runProfile) ? payload.runProfile : {} +} + +function runProfileMcpServers(payload) { + const runProfile = runProfileFromPayload(payload) + const toolProfile = isPlainObject(runProfile.toolProfile) ? runProfile.toolProfile : {} + const rawServers = Array.isArray(toolProfile.mcpServers) ? toolProfile.mcpServers : [] + const byName = new Map() + for (const raw of rawServers) { + const server = sanitizeRunMcpServer(raw) + if (!server) continue + byName.set(server.serverName, server) + } + return Array.from(byName.values()) +} + +function sanitizeRunMcpServer(raw) { + if (!isPlainObject(raw) || raw.enabled === false) return null + const serverName = cleanMcpServerName(raw.serverName || raw.server_name || raw.name) + const url = String(raw.url || '').trim() + if (!serverName || !isHttpUrl(url)) return null + return { + serverName, + url, + required: raw.required === true, + startupTimeoutSec: positiveInteger(raw.startupTimeoutSec || raw.startup_timeout_sec, 20, 1, 120), + toolTimeoutSec: positiveInteger(raw.toolTimeoutSec || raw.tool_timeout_sec, 60, 1, 600), + httpHeaders: sanitizeRunMcpHeaders(raw.httpHeaders || raw.http_headers || raw.headers), + } +} + +function sanitizeRunMcpHeaders(value) { + if (!isPlainObject(value)) return {} + const out = {} + for (const [key, item] of Object.entries(value)) { + const headerName = String(key || '').trim() + const headerValue = String(item ?? '').trim() + if (!headerName || !headerValue) continue + if (/[\r\n\0]/.test(headerName) || /[\r\n\0]/.test(headerValue)) continue + out[headerName] = headerValue + } + return out +} + +function runtimeCodexConfig() { + return [ + 'approval_policy = "never"', + 'sandbox_mode = "danger-full-access"', + ].join('\n') +} + +function dynamicMcpServerConfig(server) { + const lines = [ + `[mcp_servers.${tomlKey(server.serverName)}]`, + `url = ${tomlString(server.url)}`, + 'enabled = true', + `required = ${server.required ? 'true' : 'false'}`, + `startup_timeout_sec = ${positiveInteger(server.startupTimeoutSec, 20, 1, 120)}`, + `tool_timeout_sec = ${positiveInteger(server.toolTimeoutSec, 60, 1, 600)}`, + ] + const headers = isPlainObject(server.httpHeaders) ? server.httpHeaders : {} + const headerEntries = Object.entries(headers) + if (headerEntries.length) { + lines.push('', `[mcp_servers.${tomlKey(server.serverName)}.http_headers]`) + for (const [key, value] of headerEntries) { + lines.push(`${tomlKey(key)} = ${tomlString(value)}`) + } + } + return lines.join('\n') +} + +function dynamicMcpConfig(servers) { + return (Array.isArray(servers) ? servers : []) + .map(dynamicMcpServerConfig) + .filter(Boolean) + .join('\n\n') +} + +function ndcAgentMcpServerConfig(mcpContext, cwd) { + const ndcConfig = [ + '[mcp_servers.ndc_agent_core]', + `command = ${tomlString('node')}`, + `args = [${tomlString(NDC_AGENT_MCP_SERVER)}]`, + 'startup_timeout_sec = 20', + 'tool_timeout_sec = 120', + ].join('\n') + return `${ndcConfig}\n${ndcAgentMcpEnvConfig(mcpContext, cwd)}` +} + +function dynamicCodexHomePath(payload, needsNdcAgentCore) { + const runProfile = runProfileFromPayload(payload) + const runId = cleanRunDirectoryName(runProfile.runId || payload?.requestId || payload?.threadId || '') + return path.join(RUN_CODEX_HOME_ROOT, needsNdcAgentCore ? `ndc-${runId}` : runId) +} + function stripTomlSection(raw, sectionName) { const section = String(sectionName || '').trim() if (!section) return String(raw || '') @@ -1717,43 +1846,43 @@ function ndcAgentMcpEnvConfig(mcpContext, cwd) { ].join('\n') } -async function prepareNdcAgentCodexHome(mcpContext = {}, cwd = CODEX_CWD) { - await fs.mkdir(NDC_AGENT_CODEX_HOME, { recursive: true }) - await copyIfExists(path.join(CODEX_HOME, 'auth.json'), path.join(NDC_AGENT_CODEX_HOME, 'auth.json')) - const opsMcpConfig = await readOptionalOpsMcpConfig() - const runtimeConfig = [ - 'approval_policy = "never"', - 'sandbox_mode = "danger-full-access"', - ].join('\n') - const ndcConfig = [ - '[mcp_servers.ndc_agent_core]', - `command = ${tomlString('node')}`, - `args = [${tomlString(NDC_AGENT_MCP_SERVER)}]`, - 'startup_timeout_sec = 20', - 'tool_timeout_sec = 120', - ].join('\n') +async function prepareRunCodexHome({ payload = {}, cwd = CODEX_CWD, mcpContext = null, dynamicMcpServers = [] } = {}) { + const needsNdcAgentCore = isPlainObject(mcpContext) + const hasDynamicMcp = Array.isArray(dynamicMcpServers) && dynamicMcpServers.length > 0 + const codexHome = hasDynamicMcp + ? dynamicCodexHomePath(payload, needsNdcAgentCore) + : NDC_AGENT_CODEX_HOME + await fs.mkdir(codexHome, { recursive: true }) + await copyIfExists(path.join(CODEX_HOME, 'auth.json'), path.join(codexHome, 'auth.json')) + const legacyOpsMcpConfig = needsNdcAgentCore && !hasDynamicMcp ? await readOptionalOpsMcpConfig() : '' const config = [ - runtimeConfig, - `${ndcConfig}\n${ndcAgentMcpEnvConfig(mcpContext, cwd)}`, - opsMcpConfig, + runtimeCodexConfig(), + needsNdcAgentCore ? ndcAgentMcpServerConfig(mcpContext, cwd) : '', + hasDynamicMcp ? dynamicMcpConfig(dynamicMcpServers) : legacyOpsMcpConfig, ].filter(Boolean).join('\n\n') - await fs.writeFile(path.join(NDC_AGENT_CODEX_HOME, 'config.toml'), `${config}\n`, 'utf8') - return NDC_AGENT_CODEX_HOME + await fs.writeFile(path.join(codexHome, 'config.toml'), `${config}\n`, 'utf8') + return codexHome } async function codexInvocationForPayload(baseArgs, payload, cwd) { - if (!isNdcAgentCorePayload(payload)) return { args: baseArgs, env: {} } - const mcpContext = buildNdcAgentMcpContext(payload, cwd) - const codexHome = await prepareNdcAgentCodexHome(mcpContext, cwd) + const dynamicMcpServers = runProfileMcpServers(payload) + const needsNdcAgentCore = isNdcAgentCorePayload(payload) + if (!needsNdcAgentCore && !dynamicMcpServers.length) return { args: baseArgs, env: {}, dynamicMcpServerNames: [] } + const mcpContext = needsNdcAgentCore ? buildNdcAgentMcpContext(payload, cwd) : null + const codexHome = await prepareRunCodexHome({ payload, cwd, mcpContext, dynamicMcpServers }) return { args: baseArgs, env: { CODEX_HOME: codexHome, - NDC_AGENT_MCP_ROOT: CODEX_CWD, - NDC_AGENT_MCP_CONTEXT: JSON.stringify(mcpContext), - NDC_AGENT_MCP_API_BASE_URL: mcpContext.ndcAgentMcpApiBaseUrl, - AI_BRIDGE_PAIRING_CODE: PAIRING_CODE, + ...(needsNdcAgentCore ? { + NDC_AGENT_MCP_ROOT: CODEX_CWD, + NDC_AGENT_MCP_CONTEXT: JSON.stringify(mcpContext), + NDC_AGENT_MCP_API_BASE_URL: mcpContext.ndcAgentMcpApiBaseUrl, + AI_BRIDGE_PAIRING_CODE: PAIRING_CODE, + } : {}), }, + dynamicMcpServerNames: dynamicMcpServers.map((server) => server.serverName), + codexHome, } } @@ -2218,6 +2347,12 @@ async function runCodexForPayload(prompt, payload, onEvent = () => {}, cwd = COD }) } catch {} } + if (Array.isArray(invocation.dynamicMcpServerNames) && invocation.dynamicMcpServerNames.length) { + onEvent({ + kind: 'run_profile', + message: `Dynamic run profile MCP servers: ${invocation.dynamicMcpServerNames.join(', ')}`, + }) + } const control = { requestId: meta?.requestId, threadId: payload?.threadId, @@ -2453,6 +2588,10 @@ async function handleBridgeCommand(command, payload = {}, onEvent = () => {}, me codexAuthPath: runtime.authPath, codexBin: CODEX_BIN, codexArgs: CODEX_ARGS, + dynamicRunProfile: { + enabled: true, + codexHomeRoot: RUN_CODEX_HOME_ROOT, + }, cwd: CODEX_CWD, hubMode: hubState.mode, hubConnected: hubState.connected,