Repository navigation
build(repo): add the one-command local stack - #38
Closed
systemfsoftware-maker wants to merge 14 commits into
Closed
systemfsoftware-maker wants to merge 14 commits into
systemfsoftware-maker wants to merge 14 commits into
Conversation
systemfsoftware-maker
added this pull request to stack #34
October 5, 2026 19:48
systemfsoftware-maker
force-pushed
the
lake1/local-stack
branch
from
October 5, 2026 20:29
ee67743 to
e7592da
Compare
systemfsoftware-maker
force-pushed
the
lake1/local-stack
branch
from
October 5, 2026 21:07
e7592da to
cc69021
Compare
ryanleecode
force-pushed
the
lake1/local-stack
branch
from
October 5, 2026 22:38
ed4b2cf to
3f59428
Compare
systemfsoftware-maker
force-pushed
the
lake1/local-stack
branch
from
October 6, 2026 01:32
3f59428 to
c12182c
Compare
systemfsoftware-maker
force-pushed
the
lake1/shared-configs
branch
from
October 6, 2026 01:32
e3948bc to
cd81ee6
Compare
check:ci no longer runs stryker. The release gate on push to main plans one shard per workspace package that declares a mutation script, refuses an empty set, and runs each shard at break 100 on the fleet with its incremental report cached. The checker drops prioritizePerformanceOverAccuracy, which stryker-js 15 removes. Operator approval: Kiro, 2026-10-05 (GATE1)
The plan and per-package mutation jobs move from the self-hosted fleet, which admits only private repositories, to ubuntu-latest. Mutation stays one parallel job per package. Operator approval: Kiro, 2026-10-05 (GATE1)
ryanleecode
force-pushed
the
lake1/local-stack
branch
from
October 6, 2026 01:46
c12182c to
cff2ab6
Compare
Collaborator
Author
|
Fix |
systemfsoftware-maker
force-pushed
the
lake1/local-stack
branch
from
October 6, 2026 08:38
4ce06fb to
fb53998
Compare
A package with a mutation script whose mutate globs match nothing reports zero mutants and passes a break-100 threshold vacuously (review finding #9). Each package now declares its globs once, as stryker.mutate in package.json; its Stryker config reads them and the release gate's shard planner expands them. The planner fails red at plan time naming the package, its directory and its globs when they match no file, including a package with no declared globs. Its Deno tests are ordinary tests: a turbo root task, test:scripts, runs them through the dev shell's deno, and both pnpm test and check:ci run it, so a local check:ci covers the planner exactly as CI does
Every catalog entry is an exact version: effect 4.0.1, the systemfsoftware toolchain on its Effect 4 stable majors (recommended preset 4.0.0, stryker-js 15.0.1, vitest 2.0.0, gherkin-spec 7.0.1) and current tooling. minimumReleaseAge 1440 is explicit, so the policy is strict; the exclude list holds the effect name patterns and one exact entry per resolved systemfsoftware package. oxlint-tsgolint stays 7.0.2001, the exact peer the presets require. turbo 2.11 writes an agent guidance block into AGENTS.md unless agentGuidance is false, so turbo.json opts out. Grader package majors move here because they require Effect 4 stable (CONST-W3 declared)
oxlint.shared.ts, vitest.shared.ts and stryker.shared.ts hold the house settings; each package config extends them and declares only its own mutate set and aliases. Both lint overrides are gone: preset 4.0.0 already accepts Gherkin step bodies and build-config imports. The root lint file is named oxlint.shared.ts so lint-staged's nearest-config walk never treats the repository root as a package. Turbo inputs track the shared files. Operator approval: Kiro, 2026-10-05 (GATE1)
…root Root tsconfig.base.json extends the bundler/dom preset and allows exactly effect/http through the effect language service. effect 4.0.1 ships HTTP only as unstable and global-fetch-in-effect bans the fetch alternative. Operator approval: Kiro, 2026-10-05 (GATE1)
tsconfig.base.json now allows exactly effect/http and effect/observability. effect 4.0.1 ships its OTLP exporter only as unstable, and the Effect-native exporter keeps raw OpenTelemetry SDK wiring out of the Worker. Operator approval: Kiro, 2026-10-05 (GATE1)
pnpm dev starts the OpenTelemetry collector, Tempo and Grafana under process-compose with readiness probes. The binaries come from the locked flake through a local-stack package, and bin/local-stack runs it from the repo root the way bin/dprint runs dprint. Grafana provisions Tempo as its default data source; stack state lives in the ignored local-stack/data
process-compose sends SIGKILL after a shutdown timeout only when one is declared; without it a process that ignores SIGTERM keeps local-stack down waiting forever. Tempo's live store does that after it has taken spans (shutdown completing loop). Every process now declares a 10 second timeout, after which its process group is killed; Tempo replays its WAL on the next start
Tempo 3's live store, backend scheduler and block builder default to /var/tempo. Only root can create that, so on a GitHub-hosted runner the live store failed with "mkdir /var/tempo: permission denied", the distributor that depends on it failed too, and Tempo stopped before it was ready. Local runs as root had hidden it. All four paths now sit under local-stack/data/tempo
`pnpm dev` (bin/local-stack) exits 1 with "TUI startup error: terminal entry not found" whenever stdout is not a TTY and TERM is unset: an agent, a CI job, `ssh host pnpm dev`. process-compose's TUI wants a terminal it does not have. local-stack now sets PC_DISABLE_TUI when stdout is not a TTY, so the same command renders plain logs and every process starts. bin/check-local-stack proves it, and pnpm check:ci runs it as check:ci-run on Linux. It starts the stack the way an agent does — stdout not a TTY, TERM unset — inside an unprivileged network namespace, waits for every readiness probe, stops the stack and checks every port is free. Operator approval: Kiro, 2026-10-06 (QA Q1)
Grafana's built-in preinstall list (grafana-pyroscope-app, grafana-exploretraces-app) downloads unpinned zips from grafana.com on every fresh data dir; nothing pins that code and it runs outside the sandbox. Nothing here needs those apps: the Tempo data source is provisioned from a file and core Explore renders traces from it. preinstall_disabled keeps the stack offline. bin/check-local-stack now asserts Grafana never reaches for a plugin while the stack runs with outbound networking denied, and kills a half-started stack so a failed assertion cannot leak processes. Operator approval: Kiro, 2026-10-06 (QA Q3)
check:ci runs bin/check-local-stack on Linux, but hosted Linux CI runs check:ci split into legs and only macOS runs it whole, where the check is skipped. The new leg runs it on every PR
systemfsoftware-maker
force-pushed
the
lake1/local-stack
branch
from
October 6, 2026 08:49
fb53998 to
4f8ea78
Compare
systemfsoftware-maker
force-pushed
the
lake1/shared-configs
branch
from
October 6, 2026 08:49
95620d7 to
9a8cee1
Compare
The leg's first hosted run failed before the stack started: "no unprivileged network namespace (unshare -rn or bwrap --unshare-net)". ubuntu-24.04 runners restrict unprivileged user namespaces through AppArmor (actions/runner-images#10443), and the image maintainers declined to lift it (actions/runner-images#11489). The leg now sets kernel.apparmor_restrict_unprivileged_userns=0 before its gate, so the check can start the stack with the network denied
systemfsoftware-maker
removed this pull request from stack #34
October 6, 2026 16:04
systemfsoftware-maker
added this pull request to stack #54
October 6, 2026 19:52
systemfsoftware-maker
force-pushed
the
lake1/shared-configs
branch
from
October 6, 2026 21:56
9a8cee1 to
68974f4
Compare
Collaborator
Author
|
Dropped by the 2026-10-06 starter spec: pnpm dev runs alchemy dev, no local trace stack. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lake 1, U6 — stacked on #37.
pnpm dev(./bin/local-stack up) starts the local stack under process-compose with readiness probes and no cloud credentials (R63, without thesiteservice that U7 adds):otelcol-contrib0.155.0), OTLP on:4318HTTP and:4317gRPC:13133/local-stack/data/tempo:3200/ready:3000/api/healthnix/local-stack.nixis awriteShellApplicationoverprocess-composeand the three services.bin/local-stackcopies thebin/dprintwrapper and addscdto the repo root, since every path inprocess-compose.yamlis root-relative.cfg:overrides. Relative paths ingrafana.iniresolve against Grafana's homepath in the Nix store; the first run showedcan't read datasource provisioning files ... /nix/store/...-grafana-13.1.6/share/grafana/local-stack/grafana/datasources.local-stack/data/is gitignored.QA
Screenshot: Grafana Explore showing the trace
local-stack-qa: qa.roundtrip(taken with headless Chromium; the image is kept with the session evidence, not uploaded, since the GitHub CLI cannot attach images to PR bodies).Fix commits after opening
ed4b2cfbuild:local-stack downhung with Tempo stuck inTerminating. Once Tempo has taken spans, its live store loops inshutdown completing loopon SIGTERM, and process-compose escalates to SIGKILL only whenshutdown.timeout_secondsis declared. Every process now declares 10 s. Reproduced first (stack up, spans sent,downstill waiting after 5 min); after the fix, 20 OTLP spans thendown→ exit 0 in 10 s with Tempo killed. Tempo replays its WAL on the next start.Review fixes (Kiro rulings, Lake 1 bottom review)
pnpm devwith no terminal (ea247d9, CI leg4f8ea78).nix/local-stack.nixsetsPC_DISABLE_TUI=1when stdout is not a TTY.bin/check-local-stack(pnpm check:ci-run) does the following:./bin/local-stack upwith stdout redirected andTERMunset.project is-ready, then checks every readiness probe (13133, 3200/ready, 3000/api/health).down, then waits until all eight ports are free.check:ciruns it on Linux. Hosted Linux CI splitscheck:ciinto legs, so it also has its ownlocal-stackleg.pnpm dev exited before the stack was ready … FTL TUI startup error error="terminal entry not found: term not set", exit 1. Green: exit 0.c2767fa).local-stack/grafana.inisets[plugins] preinstall_disabled = true.unshare -rn, withbwrap --unshare-netas fallback). It proves the namespace is offline (curl: Could not resolve host: grafana.com) and fails if any log shows a plugin install.[plugins]block removed:Grafana reached for a plugin with the network denied: Installing plugin, exit 1. Green: exit 0.