CL-6458: seed the template library on first read, not at boot behind an operator bench - #185
Merged
Merged
Conversation
The bench library's template shelf never seeded in a real environment: the boot seed waited for an operator bench that dev onboarding never creates, and gave up after a bounded retry window. These tests state what the shelf should do instead — converge per tenant on the first library read, retry rather than latch on failure, and never leave the new-workbench picker offering a kind the library cannot serve.
… an operator bench The shelf never seeded in a real environment. The boot seed signed in as the operator admin, looked for a bench named ORG_SLUG among that account's memberships, and only then wrote the shipped manifests — a precondition dev onboarding never satisfies, wrapped in a retry that gave up after a bounded window. The result was a library that stayed empty until the next restart, and a new-workbench picker whose "Code review" row 404d at create time. The bench lookup was only ever standing in for a scope to own the rows. Template rows are tenant-scoped artifacts, so the tenant being read is the honest owner, and every bench needs its own — one operator bench could never have served the rest. Seeding now happens on the library read itself: one reconciliation pass per tenant per process, shared by concurrent first reads, not remembered when it fails, so the next read retries. Reconciliation is unchanged (CL-6400's content-hash markers), so re-running stays safe. A read whose seed could not run answers 503, never a 404 that reads as "no such template". The picker offers only the kinds this bench's library can serve and shows the rest as not set up, so a kind is never offered and then dead-ended at create time. The boot seed also published the @corbits/* tool tarballs for that one bench; every tenant already gets them from seedTenant, which each provisioning path runs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Creating the code-review workbench 404d for every bench:
GET /library/templates/code-reviewfound nothing because the shelf never seeded.What the operator-bench precondition was actually for
The boot seed signed in as the operator admin, looked for a bench named
ORG_SLUGamong that account's memberships, and only then wrote the shipped manifests. The lookup was only ever standing in for a scope to own the artifact rows —seedTemplateLibraryneeds a{tenantId, principalId}.Two things were wrong with that:
template library seed: not ready yet (operator bench "workbench" does not exist yet ...), forever.On top of that the retry gave up after a bounded window, so a bench onboarded after boot silently never seeded until the next restart.
The new trigger
The library read itself.
createTemplateLibrarySeederreconciles the shelf of the tenant being read, onGET /library/templatesandGET /library/templates/:id— one pass per tenant per process, shared by concurrent first reads, and not remembered when it fails, so the next read retries instead of the shelf staying empty. No window to miss, no bench to wait for, any boot order.Reconciliation semantics are unchanged: CL-6400/#162's content-hash markers still decide revise / keep / retire / restore, so re-running stays safe and a member's edits still win.
No dead-end picker
Also removed
The boot seed published the
@corbits/*tool tarballs for that one bench. Every tenant already gets them fromseedTenant, which each provisioning path (workbench seed, onboarding provision, credential setup) runs — so this was redundant, not load-bearing.apps/hub/src/template-library-seed.tsis gone.The evals harness no longer pre-seeds its scratch tenant either:
Target.installTemplate's library read is now what converges the shelf, so a passing install is itself the convergence proof.Red → green
Red first (
packages/artifacts-hub/src/template-library.test.ts,apps/web/test/new-workbench-picker.test.tsx):Scoped green:
bun run typecheck(all packages), eslint + prettier on the touched tree,packages/artifacts-hub55 pass,apps/hub137 pass,apps/web749 pass.Fixes CL-6458