fix(console): pin Beta channel to a versioned release, default ACP deploys to it - #153
Merged
Merged
Conversation
…ploys to it resolve_vendor_image_tags's "Beta" resolved to the rolling pre-beta-<vendor> moving tag, and the wizard's Image tag select had no link to the ACP checkbox at all — picking the implicit default (Stable) with ACP on silently sent whatever Stable currently resolves to. Stable is pinned to 0.9.0 right now (no 0.10.0 GA has cut yet), which predates ACP being wired as a first-class adapter (openab#1418, first in 0.10.0-beta.2) — so that combination reproduces the exact "no adapter configured" crash currently hitting Nike. Beta now resolves to the newest beta-named release (<version>-beta.N) confirmed to have a matching GHCR image, same verify-don't-infer pattern Stable already used, instead of a tag with no version number to reason about. The console defaults the Image tag select to Beta the moment ACP is checked, and re-applies that on every ACP toggle.
…blocking it studio#152 blocked Add-instance on a k8s fleet to stop it from silently deploying an ECS service (deploy.ts's compose step assumed ECS whenever it wasn't in "new-fleet" mode, since the k8s identity step is skipped for add-instance). That traded a silent wrong-provider deploy for a dead end: there was no way to add an instance to an existing k8s fleet at all. DeployMode's add-instance variant now carries the target fleet's existing runtime/context/namespace/expected_principal (main.ts already has this on hand from FleetConfigEntry — the fleet the operator drilled into). A new currentK8sTarget() helper in deploy.ts is the single place that decides whether a submit targets k8s and with what context/namespace/service account: new-fleet reads it live off the identity step's fields (the only mode with that step), add-instance reads it off the fleet's existing binding. No new identity step needed for add-instance — a k8s fleet's placement was fixed at creation, this wizard never re-asks for it. deploy_provision_agent/provision_agent_k8s already rebuild the manifest fresh on every call regardless of whether the fleet is new, so this is a pure console-side wiring fix — no backend change needed.
This was referenced Sep 13, 2026
brettchien
added a commit
that referenced
this pull request
Sep 13, 2026
…157) deploy_events (ECS control-plane events, archived via EventBridge) has no k8s equivalent and explicitly refuses k8s-runtime fleets — there's no archival system to read because the k8s API serves pod logs directly. Adds a k8s_logs tool built on the kube client k8s_client_for() already wires (list_k8s_contexts/list_namespaces/fleet_config's k8s dispatch): - studio-cp: extract find_k8s_pods() (deployment lookup + live pod list) out of observe_k8s_deployment so both it and the new fetch_k8s_pod_logs() share the same selector logic. fetch_k8s_pod_logs() disambiguates by instance_id (the same pod uid deploy_get/get_agent_states already surface) when more than one pod matches — the shape hit debugging seaturtle's image swap, where a crashed pod sat next to its replacement mid-rollout — and supports `previous` (kubectl logs -p) to read a CrashLoopBackOff pod's last terminated container, since its current log is empty post-restart. - oab-mcp: new k8s_logs tool, dispatched the same way deploy_get/deploy_list require `fleet` for k8s (no bare-cluster k8s path exists for those either). Test plan: - cargo check -p studio-cp, -p oab-mcp: clean - cargo test -p studio-cp/-p oab-mcp --lib: hits the same aws-sdk-ec2 test-cfg OOM on this box PR #153 already documented and deferred to CI (unrelated to this change — cargo check compiles the same code cleanly) 🤖 Generated with Claude Code
brettchien
added a commit
that referenced
this pull request
Sep 13, 2026
) studio#153 already guards the New Fleet wizard's Image-tag <select> against picking Stable (currently 0.9.0, predates openab#1418's /acp gateway support) with ACP enabled — but that guard lives entirely client-side in console/src/deploy.ts. A caller that bypasses the wizard (an MCP client calling deploy_provision_agent directly) sails right through it and reproduces the exact "no adapter configured" crash — which is exactly how this session's "seaturtle" test agent broke, using deploy_provision_agent directly with no chat_platform and the (then-current) default image. Adds check_acp_image_compat(), enforced in both provision_agent (ECS) and provision_agent_k8s — the one place every caller funnels through regardless of front end. Refuses acp_enabled=true + no chat_platform onto an image tag whose parsed version predates 0.10.0-beta.2. Only recognizes openab's own <version>[-beta.N]-<vendor> tag shape; a custom image the caller supplied directly passes through unchecked (can't verify, don't block — same stance resolve_vendor_image_tags already takes). Test plan: - cargo check -p studio-cp: clean - 9 new unit tests for parse_openab_version/check_acp_image_compat (pure, no AWS/k8s I/O) — cargo test -p studio-cp hits the same aws-sdk-ec2 test-cfg OOM on this box PR #153 already documented and deferred to CI 🤖 Generated with Claude Code
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
resolve_vendor_image_tags's "Beta" now resolves to the newest beta-named release (<version>-beta.N) confirmed to have a matching GHCR image, instead of the rollingpre-beta-<vendor>moving tag — matches the same verify-don't-infer pattern Stable already used, and gives callers/humans an actual version number to reason about.0.9.0right now (no0.10.0GA has cut yet), which predates ACP being wired as a first-class adapter (openab#1418, first in0.10.0-beta.2) — reproducing the exact "no adapter configured" crash currently hittingNikeinopenab-studio. The console now defaults the Image tag select to Beta the moment ACP is checked (and re-applies on every toggle).DeployMode'sadd-instancevariant now carries the target fleet's existingruntime/context/namespace/expected_principal(already available onFleetConfigEntry), and a newcurrentK8sTarget()helper indeploy.tsis the single place deciding whether a submit targets k8s, for bothnew-fleet(reads the identity step's live fields) andadd-instance(reads the fleet's existing binding — a k8s fleet's placement is fixed at creation, so this wizard never re-asks). No backend change needed —deploy_provision_agent/provision_agent_k8salready rebuild the manifest fresh on every call.Context
Diagnosed live in the
oab-studio/openab-studiok8s namespaces incident thread —Nike's CrashLoop is0.9.0-claude+ ACP enabled, and Brett hit the "Add instance isn't supported yet" dead end trying to redeploy it through the console. Confirmed viagh api repos/openabdev/openab/releasesthatopenab-0.9.0(2026-07-20) is genuinely the newest non-beta release;0.10.0-beta.1/2/3are all that's shipped since — not a resolution-logic bug, the gap was purely the missing ACP↔image-version guard plus the blocked add-instance path.Test plan
cargo check -p oabctl— compiles cleancargo test -p oabctl vendor_images— new unit tests forstable_release_versions/beta_release_versionscover the beta/stable split against a real release-list snapshot (prerelease: falseon a beta-named tag included, matching the known-unreliable-flag case) — local run hit an OOM on this box building the fullaws-sdk-ec2test-cfg dep tree unrelated to this change; deferring to CInpx tsc --noEmit— cleannpx vitest run— 107/107 passing (no existing test file coversdeploy.tsitself — it's DOM/Tauri-invoke coupled, consistent with its existing test coverage)🤖 Generated with Claude Code