mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-09-30 01:53:45 +00:00
## Summary
Replaces the `[run.sandbox]` configuration surface with a named,
provider-explicit environment catalog. Runs now select an environment by
slug (`[run.environment] id = "..."`) rather than configuring a sandbox
inline. Fabro resolves the catalog through normal settings precedence,
applies sparse run-level overrides, and creates a concrete sandbox from
the resolved environment.
This is a clean break — no `[run.sandbox]` compatibility layer.
### Plan Summary
- **New config shape:** Top-level `[environments.<slug>]` catalog valid
in `settings.toml`, `.fabro/project.toml`, and `workflow.toml`. Runs
reference a slug via `[run.environment] id = "..."` with optional sparse
overrides under `[run.environment.*]`.
- **Unified environment fields:** `provider`, `image` (ref +
dockerfile), `resources` (cpu/memory/disk), `network` (mode + allow
CIDRs), `lifecycle` (preserve/stop_on_terminal/auto_stop), `labels`,
`volumes`, `env` — replacing the previous split between `[run.sandbox]`,
`[run.sandbox.docker]`, `[run.sandbox.daytona]`, and
`[run.sandbox.daytona.snapshot]`.
- **OpenAPI schema update:** `RunSandboxSettings`, `DockerSettings`,
`DaytonaSettings`, and `DaytonaNetworkLayer` replaced with
`RunEnvironmentSettings`, `EnvironmentSettings`, `EnvironmentProvider`,
`EnvironmentImageSettings`, `EnvironmentResourcesSettings`,
`EnvironmentNetworkSettings`, `EnvironmentLifecycleSettings`, and
`EnvironmentVolumeSettings`.
- **CLI flag rename:** `--sandbox <provider>` → `--environment <slug>`
on `run`, `create`, `preflight`, and `server start/restart`.
- **Provider capability model:** Hard errors for security properties a
provider cannot enforce (local with blocked/CIDR networking; docker with
CIDR allow-lists). Warnings for unsupported resource limits, volumes,
labels, auto-stop, and Docker Dockerfiles.
- **Docs and internal code updated** throughout: `.fabro/project.toml`,
workflow configs, all public docs, CLI args, manifest builders, and the
runner's GitHub credentials check.
### Provider mapping
| Environment field | Local | Docker | Daytona |
|---|---|---|---|
| `image.ref` | Ignored | Docker image | Snapshot name |
| `image.dockerfile` | Ignored | Warning; ignored | Snapshot Dockerfile
(requires `image.ref`) |
| `resources.cpu/memory/disk` | Warning; ignored | cpu_quota / memory
limit / warning | Snapshot sizing |
| `network.mode = block` | **Error** | `network_mode = none` | Daytona
block |
| `network.mode = cidr_allow_list` | **Error** | **Error** | Daytona
CIDR allow-list |
| `labels` | Warning; ignored | Warning; ignored | Daytona labels |
| `volumes` | Warning; ignored | Warning; ignored | Daytona volume
mounts |
| `lifecycle.auto_stop` | Warning; ignored | Warning; ignored | Daytona
auto-stop interval |
| `env` | Process env overlay | Container env | Sandbox env |
### Fabro Details
<details>
<summary>Ran 11 stages in 217m 39s for $129.86</summary>
| Stage | Duration | Cost | Retries |
|---|---|---|---|
| start | 0s | – | 0 |
| toolchain | 1s | – | 0 |
| preflight_compile | 4m 7s | – | 0 |
| preflight_lint | 4m 9s | – | 0 |
| fix_lints | 3m 46s | $1.06 | 0 |
| implement | 76m 6s | $57.39 | 0 |
| simplify_opus | 71m 50s | $38.17 | 0 |
| simplify_gpt | 8m 27s | $2.24 | 0 |
| verify | 6m 10s | – | 0 |
| fixup | 42m 1s | $31.00 | 0 |
| fmt | 3s | – | 0 |
| **Total** | **217m 39s** | **$129.86** | **0** |
</details>
<details>
<summary>Ran <code>ImplementPlan.fabro</code> (12 nodes and 15
edges)</summary>
```dot
digraph ImplementPlan {
graph [
goal="Implement and simplify",
model_stylesheet="
* { model: claude-opus-4-7; }
"
]
rankdir=LR
start [shape=Mdiamond, label="Start"]
exit [shape=Msquare, label="Exit"]
toolchain [label="Toolchain", shape=parallelogram, script="command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1", max_retries=0]
preflight_compile [label="Preflight Compile", shape=parallelogram, script="cargo check -q --workspace 2>&1", max_retries=0]
preflight_lint [label="Preflight Lint", shape=parallelogram, script="cargo +nightly-2026-04-14 clippy -q --workspace --all-targets -- -D warnings 2>&1", max_retries=0]
fix_lints [label="Fix Lints", prompt="The preflight lint step failed. Read the build output from context and fix all clippy lint warnings.", max_visits=3]
implement [label="Implement", prompt="Read the plan file referenced in the goal and implement every step. Make all the code changes described in the plan. Use red/green TDD.", model="gpt-55", reasoning_effort="xhigh"]
simplify_opus [label="Simplify (Opus)", prompt="@prompts/simplify.md"]
simplify_gpt [label="Simplify (GPT-55)", prompt="@prompts/simplify.md", model="gpt-55"]
verify [label="Verify", shape=parallelogram, script="cargo +nightly-2026-04-14 clippy -q --workspace --all-targets -- -D warnings 2>&1 && cargo nextest run --cargo-quiet --workspace --status-level fail 2>&1 && cargo dev docs refresh 2>&1 && cargo dev docs check 2>&1", goal_gate=true, retry_target="fixup"]
fixup [label="Fixup", prompt="The verify step failed. Read the build output from context and fix all clippy lint warnings, test failures, and generated docs errors.", max_visits=3]
fmt [label="Format", shape=parallelogram, script="cargo +nightly-2026-04-14 fmt --all 2>&1", max_retries=0]
start -> toolchain
toolchain -> preflight_compile [condition="outcome=succeeded"]
toolchain -> exit
preflight_compile -> preflight_lint [condition="outcome=succeeded"]
preflight_compile -> exit
preflight_lint -> implement [condition="outcome=succeeded"]
preflight_lint -> fix_lints
fix_lints -> preflight_lint
implement -> simplify_opus -> simplify_gpt -> verify
verify -> fmt [condition="outcome=succeeded"]
verify -> fixup
fixup -> verify
fmt -> exit
}
```
</details>
⚒️ Generated with [Fabro](https://fabro.sh)
---------
Co-authored-by: Fabro <noreply@fabro.sh>
Co-authored-by: Bryan Helmkamp <bryan@brynary.com>
Co-authored-by: Bryan Helmkamp <bhelmkamp@users.noreply.github.com>
243 lines
6.8 KiB
Rust
243 lines
6.8 KiB
Rust
use fabro_test::{fabro_json_snapshot, fabro_snapshot, test_context};
|
||
|
||
use super::support::{output_stdout, resolve_run, wait_for_status, write_gated_workflow};
|
||
use crate::support::unique_run_id;
|
||
|
||
const SHARED_DAEMON_TIMEOUT: std::time::Duration = std::time::Duration::from_secs(30);
|
||
|
||
#[test]
|
||
fn help() {
|
||
let context = test_context!();
|
||
let mut cmd = context.command();
|
||
cmd.args(["start", "--help"]);
|
||
fabro_snapshot!(context.filters(), cmd, @"
|
||
success: true
|
||
exit_code: 0
|
||
----- stdout -----
|
||
Start a created workflow run on the server
|
||
|
||
Usage: fabro start [OPTIONS] <RUN>
|
||
|
||
Arguments:
|
||
<RUN> Run ID prefix or workflow name
|
||
|
||
Options:
|
||
--json Output as JSON [env: FABRO_JSON=]
|
||
--server <SERVER> Fabro server target: http(s) URL or absolute Unix socket path [env: FABRO_SERVER=]
|
||
--debug Enable DEBUG-level logging (default is INFO) [env: FABRO_DEBUG=]
|
||
--no-upgrade-check Disable automatic upgrade check [env: FABRO_NO_UPGRADE_CHECK=true]
|
||
--quiet Suppress non-essential output [env: FABRO_QUIET=]
|
||
--verbose Enable verbose output [env: FABRO_VERBOSE=]
|
||
-h, --help Print help
|
||
----- stderr -----
|
||
");
|
||
}
|
||
|
||
#[test]
|
||
fn start_by_run_id_starts_created_run() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let run_id = unique_run_id();
|
||
let workflow = context.install_fixture("simple.fabro");
|
||
|
||
context
|
||
.command()
|
||
.args([
|
||
"create",
|
||
"--dry-run",
|
||
"--auto-approve",
|
||
"--run-id",
|
||
run_id.as_str(),
|
||
workflow.to_str().unwrap(),
|
||
])
|
||
.assert()
|
||
.success();
|
||
|
||
context
|
||
.command()
|
||
.args(["start", &run_id])
|
||
.assert()
|
||
.success();
|
||
context
|
||
.command()
|
||
.args(["wait", &run_id])
|
||
.timeout(SHARED_DAEMON_TIMEOUT)
|
||
.assert()
|
||
.success();
|
||
|
||
let output = context
|
||
.command()
|
||
.args(["wait", "--json", &run_id])
|
||
.output()
|
||
.expect("wait should execute");
|
||
assert!(output.status.success(), "wait should succeed");
|
||
let value: serde_json::Value = serde_json::from_slice(&output.stdout).expect("wait JSON");
|
||
fabro_json_snapshot!(
|
||
context,
|
||
serde_json::json!({
|
||
"status": value["status"],
|
||
}),
|
||
@r#"
|
||
{
|
||
"status": "succeeded"
|
||
}
|
||
"#
|
||
);
|
||
}
|
||
|
||
#[test]
|
||
fn start_by_run_id_starts_created_run_without_run_json_or_status_json() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let run_id = unique_run_id();
|
||
let workflow = context.install_fixture("simple.fabro");
|
||
|
||
context
|
||
.command()
|
||
.args([
|
||
"create",
|
||
"--dry-run",
|
||
"--auto-approve",
|
||
"--run-id",
|
||
run_id.as_str(),
|
||
workflow.to_str().unwrap(),
|
||
])
|
||
.assert()
|
||
.success();
|
||
|
||
context
|
||
.command()
|
||
.args(["start", &run_id])
|
||
.assert()
|
||
.success();
|
||
let output = context
|
||
.command()
|
||
.args(["wait", "--json", &run_id])
|
||
.timeout(SHARED_DAEMON_TIMEOUT)
|
||
.output()
|
||
.expect("wait should execute");
|
||
assert!(output.status.success(), "wait should succeed");
|
||
let value: serde_json::Value = serde_json::from_slice(&output.stdout).expect("wait JSON");
|
||
fabro_json_snapshot!(
|
||
context,
|
||
serde_json::json!({
|
||
"status": value["status"],
|
||
}),
|
||
@r#"
|
||
{
|
||
"status": "succeeded"
|
||
}
|
||
"#
|
||
);
|
||
}
|
||
|
||
#[test]
|
||
fn start_rejects_already_active_or_completed_run() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let gate = write_gated_workflow(&context.temp_dir.join("slow.fabro"), "slow", "Run slowly");
|
||
|
||
let mut create_cmd = context.command();
|
||
create_cmd.env("OPENAI_API_KEY", "test");
|
||
create_cmd.args([
|
||
"create",
|
||
"--provider",
|
||
"openai",
|
||
"--environment",
|
||
"local",
|
||
"slow.fabro",
|
||
]);
|
||
let create_output = create_cmd.output().expect("command should execute");
|
||
assert!(
|
||
create_output.status.success(),
|
||
"create failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&create_output.stdout),
|
||
String::from_utf8_lossy(&create_output.stderr)
|
||
);
|
||
let run_id = output_stdout(&create_output).trim().to_string();
|
||
let run = resolve_run(&context, &run_id);
|
||
|
||
let mut start_cmd = context.command();
|
||
start_cmd.env("OPENAI_API_KEY", "test");
|
||
start_cmd.args(["start", &run_id]);
|
||
start_cmd.assert().success();
|
||
|
||
wait_for_status(&run.run_dir, &["running"]);
|
||
|
||
let mut active_cmd = context.command();
|
||
active_cmd.args(["start", &run_id]);
|
||
fabro_snapshot!(context.filters(), active_cmd, @"
|
||
success: false
|
||
exit_code: 1
|
||
----- stdout -----
|
||
----- stderr -----
|
||
× an engine process is still running for this run — cannot start
|
||
");
|
||
|
||
gate.release();
|
||
wait_for_status(&run.run_dir, &["succeeded"]);
|
||
|
||
let mut completed_cmd = context.command();
|
||
completed_cmd.args(["start", &run_id]);
|
||
fabro_snapshot!(context.filters(), completed_cmd, @"
|
||
success: false
|
||
exit_code: 1
|
||
----- stdout -----
|
||
----- stderr -----
|
||
× cannot start run: status is succeeded(completed), expected submitted
|
||
");
|
||
}
|
||
|
||
#[test]
|
||
fn start_runs_under_server_ownership_without_launcher_record() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let gate = write_gated_workflow(
|
||
&context.temp_dir.join("owned-by-server.fabro"),
|
||
"owned-by-server",
|
||
"Run under daemon ownership",
|
||
);
|
||
|
||
let output = context
|
||
.command()
|
||
.args([
|
||
"create",
|
||
"--provider",
|
||
"openai",
|
||
"--environment",
|
||
"local",
|
||
"owned-by-server.fabro",
|
||
])
|
||
.env("OPENAI_API_KEY", "test")
|
||
.output()
|
||
.expect("create should execute");
|
||
assert!(
|
||
output.status.success(),
|
||
"create failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
|
||
let run_id = output_stdout(&output).trim().to_string();
|
||
let run = resolve_run(&context, &run_id);
|
||
|
||
context
|
||
.command()
|
||
.args(["start", &run_id])
|
||
.env("OPENAI_API_KEY", "test")
|
||
.assert()
|
||
.success();
|
||
|
||
wait_for_status(&run.run_dir, &["running"]);
|
||
assert!(
|
||
!context
|
||
.storage_dir
|
||
.join("launchers")
|
||
.join(format!("{run_id}.json"))
|
||
.exists(),
|
||
"server-owned execution should not create a launcher record"
|
||
);
|
||
|
||
gate.release();
|
||
wait_for_status(&run.run_dir, &["succeeded"]);
|
||
}
|