Files
heygen-com__hyperframes/scripts/set-version.ts
James Russo 4da567df22 feat(gcp-cloud-run): Google Cloud Run + Workflows distributed render adapter (#1253)
* feat(gcp-cloud-run): add Google Cloud Run + Workflows distributed render adapter

Adds @hyperframes/gcp-cloud-run, the GCP counterpart to @hyperframes/aws-lambda
(issue #932). The OSS distributed primitives (plan, renderChunk x N, assemble)
are unchanged; this package is the storage/compute/orchestration glue.

Package: Cloud Run handler (one image, three actions), runs under bun; GCS
transport; in-image chrome-headless-shell resolver; client SDK
(renderToCloudRun, getRenderProgress, deploySite, computeRenderCost); Dockerfile;
Cloud Workflows definition; Terraform module; CLI cloudrun
deploy|sites|render|render-batch|progress|destroy with --output-resolution and
--strict-variables; 62 unit tests + docs + live smoke script.

Shared extraction (removes ~640 lines of adapter duplication): move the
cloud-agnostic config validator + content-hash into producer/distributed; both
adapters import them. Validated end-to-end on GCP at 37.4 dB PSNR vs baseline.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(cli): resolve @hyperframes/gcp-cloud-run in the CLI build + root build

The CLI bundle (esbuild) couldn't resolve `@hyperframes/gcp-cloud-run/sdk`,
failing Build/Typecheck/CLI-smoke (and the perf/windows/regression jobs that
build first). Mirror the aws-lambda handling: mark the gcp adapter + its /sdk
subpath external in tsup.config.ts with a source alias, and add gcp-cloud-run
to the root `build` filter so its dist exists for publish + runtime.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(ci): copy gcp-cloud-run manifest in Dockerfile.test for frozen install

The regression test image runs `bun install --frozen-lockfile` after copying
each workspace package.json individually. The CLI now depends on
@hyperframes/gcp-cloud-run (workspace:*), so the frozen install fails to
resolve it unless its manifest is present. Add the COPY line.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(cli): add machine-sizing flags to `cloudrun deploy`

Closes the parity gap with `lambda deploy` (which exposes --memory etc.).
`cloudrun deploy` now threads --cpu, --memory, --max-instances, and --timeout
into the Terraform apply; omitted flags keep the module defaults
(4 vCPU / 16Gi / 100 instances / 3600s). For finer control, apply the module
directly.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(gcp-cloud-run): address PR review (security, waste, limits, alerts)

- server.ts: bucket-allowlist guard no longer fails open silently. Unset env
  logs a one-time WARNING; "*" is an explicit opt-out; otherwise it enforces.
- server.ts: stop double-shipping audio.aac. It already rides in the plan
  tarball every consumer downloads, so drop the redundant standalone upload
  (plan) + re-download/overwrite (assemble); assemble reads it from the untar,
  falling back to a supplied AudioGcsUri for compat.
- server.ts: chunk extension via path.extname() instead of slice(lastIndexOf).
- workflow.yaml: clamp parallel concurrency_limit to math.min(chunkCount, 20)
  — Cloud Workflows hard-caps concurrent iterations at 20.
- Dockerfile: pin bun (bun-v1.3.9) so an interop change can't silently break
  the image rebuild.
- terraform: add min_instances var (default 0); add a workflow-failure alert
  (finished_execution_count status=FAILED) alongside the request-count one.
- costAccounting: document that displayCost excludes GCS storage/egress.

Verified against the actual APIs: @google-cloud/workflows@4.4.0
ICreateExecutionRequest has no executionId (so the idempotency-token suggestion
isn't available in this client); Workflows concurrency cap is 20; failure
metric is workflows.googleapis.com/finished_execution_count (status label).
174 adapter tests pass, fallow/oxlint/oxfmt/terraform clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(gcp-cloud-run): address round-2 review — error code + CFR forwarding

- workflow.yaml: rename the zero-chunk failure code PLAN_TOO_LARGE →
  PLAN_PRODUCED_ZERO_CHUNKS. The old code implied a size-ceiling breach (the
  opposite cause), misleading anyone triaging the alert.
- workflow.yaml: forward Config.cfr to the assemble step
  (`Cfr: ${("cfr" in config) and config.cfr}`). It was read by the handler
  but never sent, so exact-CFR was silently off for every Cloud Run render.
  Uses the same `in`-operator guard already proven in the retryable predicate.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(release): include gcp-cloud-run in set-version PACKAGES list

set-version.ts (driven by release:prepare) bumps an explicit package list to
the shared version on each release. gcp-cloud-run was wired into the build +
publish.yml but missing here, so a release would leave it at a stale version
and publish.yml would push the wrong version. Add it so the new package
version-bumps + publishes in lockstep with the others.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 14:43:38 -07:00

270 lines
9.5 KiB
TypeScript

#!/usr/bin/env tsx
/**
* Set the version across all publishable packages and plugins in the monorepo,
* then create a git commit and tag.
*
* Usage:
* bun run set-version 0.1.1 # stable release → npm "latest" tag
* bun run set-version 0.1.1-alpha.1 # pre-release → npm "alpha" tag
* bun run set-version 0.1.1 --no-tag # bump only (no commit or tag)
* bun run set-version 0.1.1 --skip-changelog-check # emergency stable release
*
* All packages and plugins share a single version number (fixed versioning).
* Pre-release suffixes (-alpha, -beta, -rc, etc.) are detected by the
* publish workflow and published to the corresponding npm dist-tag.
*/
import { existsSync, readFileSync, writeFileSync } from "fs";
import { join } from "path";
import { execFileSync } from "child_process";
import { pathToFileURL } from "url";
import { CLI_SEMVER_PATTERN } from "./cli-options.ts";
const PACKAGES = [
"packages/core",
"packages/engine",
"packages/player",
"packages/producer",
"packages/shader-transitions",
"packages/studio",
"packages/cli",
"packages/aws-lambda",
"packages/gcp-cloud-run",
];
const PLUGINS = [".claude-plugin", ".codex-plugin", ".cursor-plugin"];
const ROOT = join(import.meta.dirname, "..");
export const CHANGELOG_REVIEW_TODO = "<!-- TODO: write a 1-2 sentence release summary here. -->";
type ReleaseOptions = {
version: string;
skipTag: boolean;
skipChangelogCheck: boolean;
};
function main() {
const options = parseReleaseOptions(process.argv.slice(2));
if (releaseRequiresChangelog(options)) {
assertReviewedChangelog(options.version);
}
updatePackageVersions(options.version);
updatePluginVersions(options.version);
console.log(
`\nSet ${PACKAGES.length} packages and ${PLUGINS.length} plugin manifests to v${options.version}`,
);
if (options.skipTag) {
console.log(`\nSkipped commit and tag (--no-tag). Remember to commit and tag manually.`);
return;
}
createReleaseCommitAndTag(options.version);
printReleaseNextSteps(options.version);
}
export function parseReleaseOptions(args: string[]): ReleaseOptions {
const version = args.find((a) => !a.startsWith("--"));
const skipTag = args.includes("--no-tag");
const skipChangelogCheck = args.includes("--skip-changelog-check");
if (!version) {
console.error("Usage: bun run set-version <version> [--no-tag] [--skip-changelog-check]");
console.error("Example: bun run set-version 0.1.1");
process.exit(1);
}
if (!CLI_SEMVER_PATTERN.test(version)) {
console.error(`Invalid semver: ${version}`);
process.exit(1);
}
return { version, skipTag, skipChangelogCheck };
}
function updatePackageVersions(version: string) {
for (const pkg of PACKAGES) {
const pkgPath = join(ROOT, pkg, "package.json");
const content = JSON.parse(readFileSync(pkgPath, "utf-8"));
const oldVersion = content.version;
content.version = version;
writeFileSync(pkgPath, JSON.stringify(content, null, 2) + "\n");
console.log(` ${content.name}: ${oldVersion} -> ${version}`);
}
}
function updatePluginVersions(version: string) {
// Update each plugin.json. Replace just the version string rather than
// round-tripping through JSON.parse/stringify: oxfmt keeps these manifests'
// short arrays inline, but JSON.stringify expands them, which would fail the
// pre-commit format check on the release commit this script creates.
for (const plugin of PLUGINS) {
const pluginPath = join(ROOT, plugin, "plugin.json");
const text = readFileSync(pluginPath, "utf-8");
const oldVersion = text.match(/"version"\s*:\s*"([^"]*)"/)?.[1] ?? "unknown";
writeFileSync(pluginPath, text.replace(/("version"\s*:\s*)"[^"]*"/, `$1"${version}"`));
console.log(` ${plugin}: ${oldVersion} -> ${version}`);
}
}
function createReleaseCommitAndTag(version: string) {
const allowedPaths = releaseAllowedPaths(version);
assertNoUnexpectedChanges(collectChangedPaths(), allowedPaths);
// Pass git arguments as an array (execFileSync, no shell) so the interpolated
// version and paths can never be interpreted as shell commands.
const pathsToAdd = allowedPaths.filter((path) => existsSync(join(ROOT, path)));
execFileSync("git", ["add", ...pathsToAdd], { cwd: ROOT, stdio: "inherit" });
execFileSync("git", ["commit", "-m", `chore: release v${version}`], {
cwd: ROOT,
stdio: "inherit",
});
execFileSync("git", ["tag", `v${version}`], { cwd: ROOT, stdio: "inherit" });
console.log(`\nCreated commit and tag v${version}`);
}
export function releaseRequiresChangelog(options: ReleaseOptions) {
return !options.skipTag && !options.skipChangelogCheck && !isPrerelease(options.version);
}
export function isPrerelease(version: string) {
return version.includes("-");
}
function assertReviewedChangelog(version: string) {
const missing = missingChangelogArtifacts(version);
const unreviewed = unreviewedChangelogArtifacts(version);
if (missing.length > 0 || unreviewed.length > 0) {
console.error("\nChangelog review required:");
missing.forEach((artifact) => console.error(` ${artifact}`));
unreviewed.forEach((artifact) =>
console.error(` ${artifact} still contains the generated TODO summary`),
);
console.error(`\nRun: bun run release:prepare ${version}`);
console.error(
"Review and rewrite the generated release notes, then rerun release:prepare. Use --skip-changelog-check only for emergency releases.",
);
process.exit(1);
}
}
export function missingChangelogArtifacts(version: string) {
return changelogArtifacts(version).filter((artifact) => !artifactExists(artifact));
}
export function changelogArtifacts(version: string) {
return [join("releases", `v${version}.md`), `docs/changelog.mdx#HyperFrames v${version}`];
}
export function unreviewedChangelogArtifacts(version: string) {
return changelogArtifacts(version).filter(
(artifact) => artifactExists(artifact) && artifactHasGeneratedTodo(artifact),
);
}
function artifactExists(artifact: string) {
const [path, marker] = artifact.split("#");
const absolutePath = join(ROOT, path);
if (!existsSync(absolutePath)) {
return false;
}
return marker ? readFileSync(absolutePath, "utf-8").includes(`label="${marker}"`) : true;
}
function artifactHasGeneratedTodo(artifact: string) {
const [path, marker] = artifact.split("#");
const content = readFileSync(join(ROOT, path), "utf-8");
if (!marker) {
return hasGeneratedChangelogTodo(content);
}
return docsChangelogEntryHasGeneratedTodo(content, marker);
}
export function hasGeneratedChangelogTodo(content: string) {
return content.includes(CHANGELOG_REVIEW_TODO);
}
export function docsChangelogEntryHasGeneratedTodo(content: string, marker: string) {
const labelIndex = content.indexOf(`label="${marker}"`);
if (labelIndex === -1) {
return false;
}
const entryStart = content.lastIndexOf("<Update", labelIndex);
const entryEnd = content.indexOf("</Update>", labelIndex);
const entry = content.slice(
entryStart === -1 ? labelIndex : entryStart,
entryEnd === -1 ? undefined : entryEnd + "</Update>".length,
);
return hasGeneratedChangelogTodo(entry);
}
export function releaseAllowedPaths(version: string) {
return [
...PACKAGES.map((pkg) => join(pkg, "package.json")),
...PLUGINS.map((plugin) => join(plugin, "plugin.json")),
"docs/changelog.mdx",
join("releases", `v${version}.md`),
];
}
// Collect every uncommitted path (modified-tracked + untracked) as clean,
// repo-relative paths. We deliberately use `diff --name-only` and `ls-files`
// with `-z` rather than parsing `git status --porcelain`: the porcelain
// "XY <path>" prefix width shifts with stage state, and a fixed-width slice
// of it once mis-read a legitimate release file (`.claude-plugin/plugin.json`)
// as an unexpected change, falsely blocking a release. These two commands
// emit bare NUL-separated paths with no status column to misparse.
function collectChangedPaths(): string[] {
const tracked = execFileSync("git", ["diff", "--name-only", "-z", "HEAD"], {
cwd: ROOT,
encoding: "utf-8",
});
const untracked = execFileSync("git", ["ls-files", "--others", "--exclude-standard", "-z"], {
cwd: ROOT,
encoding: "utf-8",
});
return [...splitNulList(tracked), ...splitNulList(untracked)];
}
export function splitNulList(output: string): string[] {
return output.split("\0").filter(Boolean);
}
export function findUnexpectedChanges(changedPaths: string[], allowedPaths: string[]): string[] {
const allowed = new Set(allowedPaths);
return changedPaths.filter((path) => !allowed.has(path));
}
function assertNoUnexpectedChanges(changedPaths: string[], allowedPaths: string[]) {
const unexpected = findUnexpectedChanges(changedPaths, allowedPaths);
if (unexpected.length > 0) {
console.error("\nUnexpected uncommitted changes:");
unexpected.forEach((path) => console.error(` ${path}`));
console.error("Commit or stash these before releasing.");
process.exit(1);
}
}
function printReleaseNextSteps(version: string) {
if (isPrerelease(version)) {
const distTag = version.replace(/^.*-([a-zA-Z]+).*$/, "$1");
console.log(`\nThis is a pre-release — npm dist-tag will be "${distTag}" (not "latest").`);
console.log(`Consumers install with: npm install @hyperframes/core@${distTag}`);
console.log(`\nRun 'git push origin v${version}' to trigger the publish workflow.`);
} else {
console.log(`Run 'git push origin main --tags' to trigger the publish workflow.`);
}
}
if (process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href) {
main();
}