Commit Graph

4085 Commits

Author SHA1 Message Date
Jordan Ritter 6b924a7a44 fix(showcase): use waitUntil:load for the D4 chat-roundtrip probe (networkidle never settles on persistent-SSE pages) 2026-06-07 13:53:07 -07:00
Jordan Ritter ebd5f53549 fix(showcase): guard browser-pool context acquisition against a disconnected shared browser (byoc) 2026-06-07 13:52:57 -07:00
github-actions[bot] b4b5f10d55 style: auto-fix formatting 2026-06-07 17:04:33 +00:00
Jordan Ritter f0edcd5d94 fix(showcase): convey timeout_ms to fleet worker and stop rendering unprobed ms-agent-harness-dotnet 2026-06-07 10:00:47 -07:00
Jordan Ritter 94f564a0f8 fix(showcase): align mastra to ai SDK v5 for the gen-a2ui secondary call 2026-06-07 10:00:40 -07:00
Jordan Ritter 6e34ea836e fix(showcase): pydantic-ai gen-ui forwards the real conversation to its secondary call 2026-06-07 10:00:40 -07:00
Jordan Ritter 4920128332 fix(showcase): forward x-aimock-context across the AG-UI SSE-pump boundary in ms-agent-dotnet 2026-06-07 10:00:35 -07:00
Jordan Ritter e1cf704e13 fix(showcase): propagate x-aimock-context to off-thread gen-ui secondary call across Python backends 2026-06-07 10:00:29 -07:00
Jordan Ritter 46e66d8d4b fix(showcase): add missing per-pill copilotkit routes for agno/langroid/llamaindex/spring-ai/strands 2026-06-07 10:00:24 -07:00
Jordan Ritter 79d61b68ee docs(shell-docs): add shared-state/prebuilt guides, sidebar wiring, css, model-selection, whats-new 2026-06-06 16:10:13 -07:00
Jordan Ritter aade9d0e86 docs(shell-docs): add troubleshooting, migration, and concepts guides 2026-06-06 16:10:09 -07:00
Jordan Ritter 1c33e99f49 docs(shell-docs): add reference hook pages and retire orphaned v2 useAgent 2026-06-06 16:10:04 -07:00
Jordan Ritter e529593650 docs(shell-docs): add MS Agent Framework + Mastra integration samples 2026-06-06 16:10:00 -07:00
Jordan Ritter 58887baeda docs(shell-docs): add backend runtime/runner/self-managed docs 2026-06-06 16:09:56 -07:00
github-actions[bot] c73afd1e3d style: auto-fix formatting 2026-06-06 19:26:25 +00:00
Jordan Ritter 469d79b029 diag(showcase): ungated x-diag-probe (thread+ctx) on outbound LLM calls to localize native-tool context loss 2026-06-06 12:24:44 -07:00
github-actions[bot] 1e5a9b77cd style: auto-fix formatting 2026-06-06 17:44:07 +00:00
Jordan Ritter bd77954ab5 feat(showcase): instrument per-framework x-aimock-context forwarding with gated CVDIAG breadcrumb
Add CVDIAG logging + x-diag-hops breadcrumb (route-<fw>/backend-<fw>) at each forwarding hop across LangGraph (py/ts/fastapi), google-adk, the self-contained Node + Python shims, spring-ai (Java) and ms-agent (.NET). Breadcrumb append is gated on diagnostic-header presence so non-diagnostic traffic stays byte-identical; surfaces previously-silent forwarding misses (empty configurable, missing httpx event-hooks target, swallowed hook-install errors).
2026-06-06 10:40:25 -07:00
Jordan Ritter 32d0afaba0 feat(showcase-harness): instrument D5/D6 drivers, orchestrator, pool & scheduler with CVDIAG
Mint a run_id per D5/D6 feature run, inject x-diag-run-id + seed x-diag-hops=harness alongside x-aimock-context, and do a post-run aimock-journal join (timeout-bounded) that records a cv-verdict row (tagged harness-d5/harness-d6) localizing whether the context header reached aimock. Add claim/worker_id/snapshot/pool-condition breadcrumbs and surface previously-swallowed catches.
2026-06-06 10:40:25 -07:00
Jordan Ritter acf9f6fe2c feat(showcase-harness): add CVDIAG diagnostic contract + durable diag_events sink
Shared single-line CVDIAG log format (redacted 12-char header prefix), x-diag-run-id/x-diag-hops correlation header constants, and a best-effort PocketBase diag_events sink (anonymously HTTP-readable) so the CV/x-aimock-context propagation chain can be traced mid-incident without Railway log access.
2026-06-06 10:40:24 -07:00
Jordan Ritter da03e1626a fix(showcase): reconcile harness-workers SSOT key with the Railway service name
The pool-fleet worker's Railway service is named `harness-workers` (PLURAL),
but the SSOT keyed it `showcase-harness-worker` (singular). The image-ref gate
matches SSOT keys to Railway service names verbatim, so the gate reported
`harness-workers` as an untracked Railway service AND the stale singular key
matched nothing. Rename the SSOT key (and every test/fixture reference) to the
exact Railway name `harness-workers`.

It stays the staging-only, domainless, probe-disabled worker that runs the
shared `showcase-harness` image: serviceId c2aa8a0b-…, staging instance
362c1e37-…, ciBuilt:false, gateIgnore:true, no build slot (so no dispatchName),
single `staging` env with no domain. Add a focused test pinning that shape.
Counts are unchanged (29 services / 26 CI_BUILT) — this is a rename, not an
addition; both harness workers already existed on main.

Verified LOCALLY against Railway: verify-railway-image-refs reports
`54 env-scoped instances verified (2 skipped)` — 0 violations, 0 missing, 0
untracked (harness-workers reconciled, harness-workers + harness-legacy the 2
gateIgnore'd skips). emit --check zero drift, Ruby parity green (borrowed
.up.railway.app host is parity-excluded), full scripts suite + typecheck green.
2026-06-06 07:51:00 -07:00
Jordan Ritter 9b76a2d2a4 refactor(showcase): unify railway-envs SSOT into per-env environments map (Option C)
Replace ServiceEntry's parallel prodInstanceId/stagingInstanceId/domains/probe/
repoNameOverride fields with a single environments: Record<string, {instanceId,
domain?, probe?, repoName?}> map plus a hoisted env-independent probeDriver.
EnvName becomes an open string backed by an ENV_ID_BY_NAME registry so
accessors resolve arbitrary env names; a single-env service (the staging-only
showcase-harness-worker) now simply omits the absent env instead of carrying a
placeholder ID/borrowed host.

Accessors instanceIdFor/domainFor/repoNameFor index environments[env]
(domainFor still throws on missing/scheme); add envsFor(name),
serviceEnvPairs(), and probeEnabled(name, env). Generalize the image-ref gate
(iterate each service's declared environments, resolve env-id via the
registry, sum/iterate missingByEnv over registry env names) and verify-deploy's
host->env reverse-map (envForTarget iterates environments).

Pure TS-internal: emit-railway-envs-json.ts projects the env-map back onto the
FROZEN legacy JSON shape (prodInstanceId/stagingInstanceId/domains/probe/
repoNameOverride) via a documented legacyJsonCompat shim for the two domainless
harness workers, so railway-envs.generated.json stays byte-identical and Ruby
(bin/railway) + workflow jq + the parity test are untouched. Verified: emit
--check zero drift, Ruby test_expected_domains_parity green, golden snapshot
toEqual proves byte-identical resolution for every real (service, env) pair,
full scripts vitest suite green, showcase scripts typecheck clean.
2026-06-06 07:48:14 -07:00
Jordan Ritter a8b5214b5f test(showcase): add railway-envs golden snapshot (behavior-preservation guard)
Serializes the fully-resolved {service -> env -> {instanceId, domain, probe,
driver, repoName}} projection for all 29 services x 2 envs via the public
accessors (instanceIdFor/domainFor/repoNameFor) + per-entry probe config,
frozen as a fixture. This is the behavior-preservation guard for the
forthcoming env-map (Option C) refactor: resolved values must stay
byte-identical before and after.
2026-06-06 07:32:10 -07:00
Jordan Ritter 5387e4de38 fix(showcase): add D6 entry to coverage dashboard legend 2026-06-06 02:30:36 -07:00
Jordan Ritter d408766cce fix(harness): balance fleet claim distribution to reduce settle-timeout contention 2026-06-06 02:30:36 -07:00
Jordan Ritter d6b0e895ae fix(harness): restore resource_snapshots in the fleet worker + per-replica attribution
Wire the resource-snapshot writer back into the fleet worker path with
per-replica attribution, add the worker_id column migration, and stamp
the legacy single-process path's worker_id as "" (empty string) to match
PocketBase storage and the surrounding codebase convention.
2026-06-06 02:30:32 -07:00
Jordan Ritter 5240ba813c fix(showcase): quarantine gen-ui-interrupt/interrupt-headless pills via not_supported_features
Move gen-ui-interrupt + interrupt-headless from features: to
not_supported_features: across affected integration manifests, and align
the generate-registry/generate-catalog scripts tests to the resulting
wired-feature counts (derive expected lengths from the parsed manifest
rather than hardcoding pre-quarantine numbers).
2026-06-06 02:30:26 -07:00
Jordan Ritter 182e3e2fd9 fix(showcase): add follow-up-turn aimock fixtures for multi-pill D6 sessions 2026-06-06 02:30:17 -07:00
Jordan Ritter 0cbc990e42 fix(showcase): forward x-aimock-context on all built-in-agent demo routes 2026-06-06 02:30:17 -07:00
Jordan Ritter 5c72d1addd fix(showcase): propagate x-aimock-context across AG-UI SDK pooled-thread hop in spring-ai 2026-06-06 02:30:13 -07:00
Jordan Ritter 5812739b5e feat(showcase): drive bin/showcase test d5/d6 through the fleet control-plane + add dev hot-reload mode
Make the showcase dev tool faithful to staging by construction. Two changes:

1. `showcase test --d5/--d6` now drives the fleet CONTROL-PLANE (producer ->
   probe_jobs queue -> worker -> result-aggregator) instead of the legacy
   in-process runLevel() driver. The new cli/control-plane-run.ts replicates
   the deep/full producer tick exactly as runControlPlane wires it
   (createE2eDeepServiceEnumerator / createServiceEnumerator over
   createJobProducer + createFleetQueueClient), enqueues one operator-triggered
   tick, and polls local PocketBase for the run's terminal cells. The running
   worker fleet claims + runs the driver + the aggregator writes the d5/d6
   status cells, so the dev tool exercises the IDENTICAL wiring + concurrency
   as staging. The old in-process path stays available behind `--direct`.

2. `showcase up --dev` adds a docker-compose.dev.yml overlay that bind-mounts
   each integration's source and overrides the run command with a stack-aware
   hot-reload entrypoint (shared/dev/dev-entrypoint.sh: uvicorn --reload for
   FastAPI agents, langgraph dev for graphs, next dev for the frontend). Edit a
   source file and the component reloads in place with no image rebuild. The
   built-image mode remains the faithful/staging-equivalent default.
2026-06-06 00:06:29 -07:00
Jordan Ritter 3948629576 docs(showcase): remove stale e2e_deep/d5-single-pill references after D5=D6-take-one 2026-06-05 21:54:42 -07:00
Jordan Ritter a6a28f276e fix(showcase): keep D5 CLI error-path key consistent with success path 2026-06-05 21:42:50 -07:00
Jordan Ritter f723bc27da docs(showcase): correct payload-mapper to three browser driver families
The e2e_deep kind was removed (D5 now runs the D6 driver), leaving three
browser driver families: e2e_d6, e2e_demos, e2e_smoke. Update the stale
"four browser driver families" docstring and its test comment.
2026-06-05 21:36:16 -07:00
Jordan Ritter db2bf3e2ce test(showcase): cover composed representativeOnly+rowPrefix:d5 D5 invocation
Asserts the real D5 invocation shape buildDeepInputs stamps (both knobs
together): only D5_REPRESENTATIVES featureTypes run AND every emitted key
(per-cell d5:<slug>/<ft> + aggregate d5:<slug>) uses the d5: prefix. The
existing tests cover the knobs in isolation only.
2026-06-05 21:36:09 -07:00
Jordan Ritter 27c5217d1c fix(showcase): forward notSupportedFeatures + use d5: error key in D5 CLI path
buildDeepInputs now forwards manifest.not_supported_features (matching D6's
buildFullInputs) so local CLI D5 runs don't false-red architecturally-
unsupported features. The D5 thrown-error terminal key changes from
d5-single-pill-e2e:<slug> to d5:<slug> (the driver's own emitAggregate key
shape) so a hard driver throw surfaces as a RED D5 cell, not a blank row.
Also corrects D5-scope docs: representativeOnly keeps the representative
featureTypes per D5_REPRESENTATIVES, not "one pill per category".
2026-06-05 21:36:02 -07:00
Jordan Ritter 04a7ee703a fix(showcase): repoint d6-capture-references import off deleted d5-single-pill 2026-06-05 21:35:47 -07:00
Jordan Ritter 703985ec39 refactor(showcase): drop the e2e_deep kind constant + stale D5-driver references
Removes E2E_DEEP_DRIVER_KIND and "e2e_deep" from the worker-internal
closed driver-kind set (D5 runs the e2e_d6 driver now), updates the
x-test-id-headers guard to assert on the surviving d6-all-pills driver
(d5-single-pill.ts was deleted), and repoints a stale doc comment.
2026-06-05 21:23:21 -07:00
Jordan Ritter 1829c3f580 feat(showcase): run D5 as "D6 take-one" via driver inputs, not a separate kind
Repoints the D5 probe at the unified D6 driver. The fleet D5
enumerator now stamps driverKind=e2e_d6 with representativeOnly + a
"d5" rowPrefix; the CLI's buildDeepInputs carries the same inputs;
config/probes/e2e-deep.yml declares kind=e2e_d6. Drops the e2e_deep
driver registration (orchestrator + worker registry + BROWSER_KINDS +
the worker-internal kind set), keeping the D5 producer schedule/cadence
intact. The worker now honors driverInputs.rowPrefix when filtering the
aggregate side-row out of captured cells so a "d5:<slug>" aggregate
doesn't leak into the D6 entry's "d6:<slug>" cell capture. This
eliminates the separate D5 launcher path whose own launcher instance +
cadence systematically dropped x-aimock-context against the shared fleet
pool (aimock strict 503 -> red).
2026-06-05 21:22:45 -07:00
Jordan Ritter 8db67ca064 feat(showcase): add representativeOnly + rowPrefix knobs to the D6 driver
Adds two input knobs to the d6-all-pills driver so it can run as "D5
take-one": `representativeOnly` filters the feature matrix to the
D5_REPRESENTATIVES set, and `rowPrefix` ("d5" | "d6", default "d6")
threads the dashboard key prefix through every emitted per-cell and
aggregate PB row. The representatives map is injectable for testing.
Everything else (route, headers, conversation, pooled launcher) is
unchanged. Red-green unit tests cover both knobs.
2026-06-05 21:21:03 -07:00
Jordan Ritter 723090e24e feat(showcase): mount /api/probes trigger endpoint on the fleet control-plane
The control-plane runs the 8 in-process HTTP probe families but the
on-demand trigger endpoint (POST /api/probes/:id/trigger) was only mounted
on the legacy boot() path, so operators had no way to fire a family
immediately and had to wait on the slow cron. Wire the same
registerProbesRoutes onto the control-plane's buildServer using its own
httpProbeRegistry/httpProbeConfigs/scheduler/httpRunWriter and
OPS_TRIGGER_TOKEN. Only the prefixed in-process probe ids (probe:<id>) are
triggerable; browser-only and unknown ids 404. Token handling mirrors
boot() (unset -> router omitted; set-but-empty -> fail-loud).
2026-06-05 16:44:43 -07:00
Jordan Ritter 3d940a3c74 feat(showcase): run e2e_smoke/e2e_demos/e2e_deep browser families on the fleet
Phase 2 of the harness pool-fleet migration — wire the three remaining BROWSER
probe families into the control-plane PRODUCER side so they actually run on the
fleet (the worker DriverRegistry for all four kinds already landed in #5283).

Unit A — three catalog-enumerator factories mirroring createD6ServiceEnumerator,
each delegating to the generic createServiceEnumerator with its own driverKind +
dashboard probeKey prefix and the shared D6_DISCOVERY_FILTER:
  - createE2eSmokeServiceEnumerator → e2e_smoke / d4:<slug>
  - createE2eDemosServiceEnumerator → e2e_demos / e2e-demos:<slug>
  - createE2eDeepServiceEnumerator  → e2e_deep  / d5-single-pill-e2e:<slug>

R-timeout (demos): the demos driver's 20-min outer cap is threaded in-process via
the legacy E2E_DEMOS_TIMEOUT_MS env, which the fleet worker never sets. The demos
enumerator now conveys the YAML timeout_ms per-job in driverInputs.timeout_ms
(new E2E_DEMOS_TIMEOUT_MS SSOT const mirroring e2e-demos.yml), and the demos
driver reads input.timeout_ms as a resolution source (env > input > deps >
default) so the 38-demo service no longer blows the 5-min default to all-red.

Unit B — runControlPlane now builds four producers and passes a multi-schedule
manifest (buildProducerSchedules) to createControlPlane, each family on its own
cron read literally from the config YAMLs (the deliberate offsets stagger the
families' Playwright fan-outs on the shared BrowserPool):
  - fleet-job-producer       40 * * * *          (d6, unchanged; honors FLEET_PRODUCER_CRON)
  - fleet-producer-e2e-smoke  */15 * * * *
  - fleet-producer-e2e-demos  10 * * * *
  - fleet-producer-e2e-deep   5,20,35,50 * * * *
The in-process HTTP probe runner and the d6 producer's REQ-B sweep leg are left
intact (additive). The worker registry is untouched.

R1 (verified, no change): both createPooledE2eSmokeLauncher and
createPooledE2eDeepLauncher thread contextOpts.extraHTTPHeaders, so smoke + deep
set their per-slug X-AIMock-Context themselves.
2026-06-05 16:11:08 -07:00
github-actions[bot] 12a6c18049 style: auto-fix formatting 2026-06-05 22:49:28 +00:00
github-actions[bot] a3ec4f5875 style: auto-fix formatting 2026-06-05 15:48:34 -07:00
Jordan Ritter eed8d8316f fix(showcase): control-plane probe sweep parity, kind drift-guard, and CR gap-fills
Address the CR gaps on the in-process HTTP-probe control-plane:

- Sweep orphaned `running` probe_runs at control-plane boot (boot()'s
  sweepStaleRuns never ran in fleet mode → leaked rows forever). Best-effort;
  a sweep failure does not abort boot.
- Add a fail-loud BROWSER_KINDS / HTTP-driver disjointness assert at boot plus
  a drift-lock test mirroring registerAllProbeDrivers, so a mis-added kind
  can't silently go dark.
- Assert the PR's headline guarantees that were unasserted: cron-from-YAML
  (exact values), /health loader-failure boot-survival + probes.reload.failed
  emit + rules=0 observability, hot-reload add/remove + watcher teardown, a
  discovery-backed family (qa) in the in-process schedule, and tightened
  /health rule/job counts to exact equality.
- Bump the includeKind skip log to info; make diffHttpProbeSchedules'
  unregister-failure post-state explicit (keep config observable); correct the
  /health "no longer masks" comment, the discovery-source comment
  (image_drift uses railway-services; version_drift uses pnpm-packages), the
  reload-failed surface comment (no bus subscriber on the control-plane), and
  drop transitional-rot tags.
2026-06-05 15:46:15 -07:00
Jordan Ritter 8caff3f704 feat(showcase): run HTTP-only probe families in-process on the fleet control-plane
The fleet control-plane previously ran only the d6 producer, leaving the 8
HTTP-only probe families (smoke, starter_smoke, image_drift, qa, aimock_wiring,
version_drift, pin_drift, redirect_decommission) dark on the fleet. Lift the
legacy boot() probe-loader machinery into runControlPlane so those families run
in-process:

- Add BROWSER_KINDS = {e2e_d6, e2e_smoke, e2e_demos, e2e_deep}; HTTP = every
  other kind. Add registerHttpProbeDrivers (HTTP-only driver set, no BrowserPool
  drivers).
- In runControlPlane, build an HTTP-only probeRegistry + discovery registry
  (railway-services cached + pnpm-packages, mirroring boot()), a probe-loader
  scoped to HTTP kinds, and the same diffProbeSchedules/buildProbeInvoker loop
  boot() uses — registering one probe:<id> scheduler entry per YAML config.
  Crons are driven from the YAML schedule. Browser e2e_* YAMLs route to the
  worker producer path and are NOT scheduled in-process.
- Add an includeKind predicate to createProbeLoader so a browser YAML on disk is
  SKIPPED (not rejected) against the HTTP-only registry — no spurious
  probes.reload.failed.
- /health: ruleCount now reflects the in-process HTTP probe count (was a
  hardcoded 0). The control-plane role still drops the rules>0 gate, but the
  real count means a silent probe-loader failure is visible on /health rather
  than masked. schedulerJobCount already counts the new probe entries.
- Tear down the HTTP-probe file watcher on stop() and on bind failure.
2026-06-05 15:46:15 -07:00
Jordan Ritter ca96837025 feat(harness/fleet): generalize enumerator + control-plane for N producer schedules (#5285)
## Summary

Producer-side foundation for fleet framework item 3b. Two
**behavior-preserving** generalizations that make the seam capable of
multiple browser families and multiple producer cadences, while keeping
the d6 case **byte-identical**. No wiring is flipped on yet (see Out of
Scope).

### 1. Parameterized service enumerator
`showcase/harness/src/fleet/control-plane/catalog-enumerator.ts`
- New generic `createServiceEnumerator(params)`
(catalog-enumerator.ts:215) takes the service-set `filter`, the
`driverKind`, and a `probeKeyPrefix` (string prefix → `<prefix>:<slug>`,
or a builder fn).
- `createD6ServiceEnumerator` (catalog-enumerator.ts:280) is
re-expressed as a thin call passing the d6 params: `D6_DRIVER_KIND`
(`e2e_d6`), prefix `"d6"` (→ `d6:<slug>`), and `D6_DISCOVERY_FILTER`. d6
output is unchanged — same services, same filter, same kind, same keys.

### 2. Control-plane accepts an array of producer schedules
`showcase/harness/src/fleet/control-plane/control-plane.ts`
- New `ProducerSchedule` type (`{ scheduleId, cron, producer }`) + a
`schedules?` dep on `ControlPlaneDeps`.
- `createControlPlane` normalizes to an array (control-plane.ts:~232);
omitting `schedules` degenerates to the single d6 schedule on
`FLEET_PRODUCER_SCHEDULE_ID` (`fleet-job-producer`) @ `40 * * * *` —
current behavior preserved exactly.
- `start()` / `stop()` iterate the array, registering/unregistering each
scheduler entry and starting/stopping each producer.

## Out of scope (deferred — gated on other in-flight PRs)
- **No `runControlPlane` wiring** to actually PASS multiple schedules —
that edit conflicts with in-flight **#5284** (which edits
`runControlPlane`) and is deferred. This PR only makes
`control-plane.ts` *capable* of N schedules + generalizes the enumerator
seam; the wiring lands later.
- No `e2e_smoke` / `e2e_demos` / `e2e_deep` enumerators or producers
(Phase 2).
- No changes to `worker-loop.ts` / `payload-mapper.ts` /
`probe-loader.ts` (other PRs own those).
- No driverKind constant / contract changes.

## Test plan
- [x] Red→green TDD: 3 new enumerator tests (generic
kind/keys/filter/fn-prefix) + 2 new control-plane tests (N entries
registered with distinct crons; stop tears all down) failed before impl,
pass after.
- [x] Equivalence: all pre-existing d6-enumerator + single-schedule
control-plane tests pass unchanged.
- [x] Full harness suite green: **2078 passed** (119 files).
- [x] `tsc -p tsconfig.build.json` clean (exit 0).
- [x] Only the 4 intended files changed; no lockfile drift.

Do not merge — producer-side foundation only; wiring follows after #5284
lands.
2026-06-05 15:44:07 -07:00
Jordan Ritter fcf1a33d73 fix(showcase): track interim harness-legacy service in railway-envs SSOT (unblock harness builds)
The showcase_build verify-image-refs gate (SSOT = showcase/scripts/railway-envs.ts)
was failing with "1 untracked Railway services" because the interim
harness-legacy staging service (the legacy all-probe harness kept live during
the pool-fleet migration) exists on Railway but had no SSOT entry. That
Railway->SSOT drift check skips the build, so nothing deploys.

Adds a harness-legacy SERVICES entry mirroring the showcase-harness-worker
precedent (PR #5280): ciBuilt:false (not built by showcase_build, runs a pinned
out-of-band digest) and gateIgnore:true (deliberately-untracked for the image-ref
gate). findUntrackedServices treats any SSOT entry as known, so this clears the
untracked failure; gateValidated:false keeps findMissingServices from flagging
it. Real serviceInstance IDs for both envs recorded from Railway GraphQL.
Regenerates railway-envs.generated.json and updates the service-count /
gate-ignored carve-out assertions (28->29 services).

Verified: live verify-railway-image-refs.ts now exits 0 ("54 env-scoped
instances verified, 2 skipped"); without the entry it exits 1 with the
harness-legacy untracked failure. Full scripts test suite green (1771 passed).
2026-06-05 15:37:26 -07:00
Jordan Ritter ef4413035d fix(harness/fleet): harden multi-schedule seam to fail-loud bar
The multi-schedule seam (createServiceEnumerator + the schedules[] capability
in control-plane) didn't meet the file's own best-effort/fail-loud bar. Harden
it now since Phase 2 builds on it (no production caller yet):

- stop(): guard each producer.stop() per-entry so one rejection no longer aborts
  teardown of later schedules (leaked cron handlers + running producers).
- start(): pre-validate every schedule's cron up-front before starting any
  producer, throwing an aggregated error naming the offending scheduleId — no
  more half-started plane with `started` latched true.
- normalization: throw on duplicate scheduleId (replace-semantics would silently
  collapse two producers onto one entry) and on an explicitly-empty schedules:[]
  (distinct from omitted, which keeps the d6 default).
- createServiceEnumerator: require a non-empty filter.namePrefix (an absent
  prefix would enumerate ALL services) and reject an empty probeKey from a
  function-form prefix, naming the slug.

Also: narrow the d6 "byte-identical" docstring (specs identical; the
catalog-enumerated log adds driverKind), pluralize the start()/stop() +
module-header producer comments, drop the Phase 2 marker, and extract the shared
ServiceSetFilter type.
2026-06-05 15:24:55 -07:00
github-actions[bot] ab4bb1cc65 style: auto-fix formatting 2026-06-05 22:16:41 +00:00