Skip to content

Speed up container discovery and harden emulator listings - #2828

Merged
Andriy Knysh (aknysh) merged 7 commits into
mainfrom
osterman/debug-container-list-latency
Jul 30, 2026
Merged

Andriy Knysh (aknysh) merged 7 commits into
mainfrom
osterman/debug-container-list-latency

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Jul 29, 2026 •

Copy link
Copy Markdown
Member

what

  • Cache automatic Docker/Podman selection, eliminate duplicate probes, and show progress during uncached discovery.
  • Fetch container statuses in one bulk runtime query and recover from stale cached runtimes.
  • Return an empty emulator status list when invoked outside an Atmos stack project.

why

  • Repeated container commands avoid unnecessary runtime checks while still recovering when a runtime changes.
  • List commands now respond predictably when no stack manifests are present.

references

  • None.

Summary by CodeRabbit

  • New Features

    • Added support for deleting cached entries to keep container/runtime selection up to date.
    • Container listings now compute instance status using a single bulk query for improved responsiveness.
  • Bug Fixes

    • Container runtime auto-selection is more resilient: corrupted cache data triggers fresh discovery, and failed runtime operations invalidate cached selections.
    • Emulator listing now returns an empty result (no error) when no stacks/manifests are found.
    • Improved runtime environment propagation when supported, and more reliable auto-start recovery between Docker and Podman.

@atmos-pro

atmos-pro Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions github-actions Bot added the size/m Medium size PR label Jul 29, 2026
@github-actions

github-actions Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

  • website/pnpm-lock.yaml

@osterman Erik Osterman (Cloud Posse) (osterman) added the patch A minor, backward compatible change label Jul 29, 2026
@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 6fbe8216-cef3-4e3f-bd22-e3254f81ff8f

📥 Commits

Reviewing files that changed from the base of the PR and between dc7c62c and 00932de.

⛔ Files ignored due to path filters (1)
  • website/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • .github/workflows/dependency-review.yml
  • website/package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/dependency-review.yml

📝 Walkthrough

Walkthrough

Container runtime resolution now supports automatic-selection caching, invalidation, explicit recovery outcomes, and bulk status queries. File-cache deletion is idempotent. Emulator listing treats missing imports or stack manifests as empty successful results. Website dependency overrides and dependency-review exceptions are updated.

Changes

Container runtime resolution

Layer / File(s) Summary
Cached runtime discovery
pkg/cache/file_cache.go, pkg/cache/file_cache_test.go, pkg/component/container/runtime_discovery.go, pkg/component/container/runtime_discovery_test.go
Automatic Docker/Podman selection is cached with environment-sensitive keys, invalid entries are removed, and runtime operation failures invalidate cached selections.
Runtime resolution and bulk container status
pkg/component/container/executor.go, pkg/component/container/list.go, pkg/component/container/list_test.go, pkg/container/identity.go, pkg/container/identity_test.go
Container commands use resolved runtimes and forward environments, while listing performs one component-type query and retries cached-runtime failures after rediscovery.
Autostart recovery behavior
pkg/container/detector.go, pkg/container/detector_autostart_test.go
Automatic and explicit recovery paths return Docker or Podman only after successful availability checks and report unavailable-runtime errors otherwise.

Emulator empty-result handling

Layer / File(s) Summary
No-manifest status handling
pkg/component/emulator/executor.go, pkg/component/emulator/executor_test.go
Missing imports or stacks produce empty successful status results, while unrelated errors continue to propagate.

Website dependency overrides

Layer / File(s) Summary
Brace expansion override updates
website/package.json, .github/workflows/dependency-review.yml
Brace-expansion overrides are pinned to specific versions and the dependency-review allowlist includes an additional advisory with explanatory comments.

Estimated code review effort: 4 (Complex) | ~45 minutes

Suggested labels: patch

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 35.42% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: faster container discovery and more robust emulator listing behavior.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/debug-container-list-latency

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
pkg/component/emulator/executor_test.go (1)

476-522: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use a table-driven test for the sentinel cases.

The two new subtests share the same setup and assertions; table-drive them with the sentinel error as the test-case input. As per coding guidelines, Go tests should use table-driven tests for multiple scenarios.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/component/emulator/executor_test.go` around lines 476 - 522, Convert the
two sentinel-error subtests around emulatorStatuses into one table-driven test,
using each sentinel error (errUtils.ErrFailedToFindImport and
errUtils.ErrNoStacksFound) as the test-case input. Keep the shared stub setup,
describeEmulatorStacks seam, emulatorStatuses invocation, and
no-error/empty-status assertions unchanged for every case.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/component/container/runtime_discovery.go`:
- Around line 77-80: In the cached-runtime branch of runtime discovery, set
resolution.cached to true before assigning resolution.invalidate to
invalidatingRuntime. Ensure the captured invalidation method observes the cached
state so failures remove stale cache entries, while preserving the existing
runtime return flow.

---

Nitpick comments:
In `@pkg/component/emulator/executor_test.go`:
- Around line 476-522: Convert the two sentinel-error subtests around
emulatorStatuses into one table-driven test, using each sentinel error
(errUtils.ErrFailedToFindImport and errUtils.ErrNoStacksFound) as the test-case
input. Keep the shared stub setup, describeEmulatorStacks seam, emulatorStatuses
invocation, and no-error/empty-status assertions unchanged for every case.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 5887254f-320c-449d-9410-28067ecd15b9

📥 Commits

Reviewing files that changed from the base of the PR and between e4c680c and 86cc792.

📒 Files selected for processing (13)
  • pkg/cache/file_cache.go
  • pkg/cache/file_cache_test.go
  • pkg/component/container/executor.go
  • pkg/component/container/list.go
  • pkg/component/container/list_test.go
  • pkg/component/container/runtime_discovery.go
  • pkg/component/container/runtime_discovery_test.go
  • pkg/component/emulator/executor.go
  • pkg/component/emulator/executor_test.go
  • pkg/container/detector.go
  • pkg/container/detector_autostart_test.go
  • pkg/container/identity.go
  • pkg/container/identity_test.go

Comment thread pkg/component/container/runtime_discovery.go
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 29, 2026
@codecov

codecov Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 94.28571% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.90%. Comparing base (8c46159) to head (00932de).

Files with missing lines Patch % Lines
pkg/component/container/runtime_discovery.go 95.07% 7 Missing ⚠️
pkg/component/container/list.go 86.20% 3 Missing and 1 partial ⚠️
pkg/container/detector.go 93.75% 1 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2828      +/-   ##
==========================================
+ Coverage   81.89%   81.90%   +0.01%     
==========================================
  Files        1796     1797       +1     
  Lines      173711   173901     +190     
==========================================
+ Hits       142255   142428     +173     
- Misses      23674    23690      +16     
- Partials     7782     7783       +1     
Flag Coverage Δ
unittests 81.90% <94.28%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
pkg/cache/file_cache.go 87.50% <100.00%> (+0.88%) ⬆️
pkg/component/container/executor.go 80.66% <100.00%> (+1.10%) ⬆️
pkg/component/emulator/executor.go 88.25% <100.00%> (+0.15%) ⬆️
pkg/container/identity.go 100.00% <100.00%> (ø)
pkg/container/detector.go 86.47% <93.75%> (-2.77%) ⬇️
pkg/component/container/list.go 92.40% <86.20%> (-0.46%) ⬇️
pkg/component/container/runtime_discovery.go 95.07% <95.07%> (ø)

... and 8 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Covers the Delete() error branch in FileCache, the invalidatingRuntime
wrapper's delegate-and-invalidate-on-error behavior, the cached-runtime
decode switch, resolved.runtime's error/env-forwarding branches, and
DetectRuntimeWithPreferenceAndRecovery's new provider-selection switch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 30, 2026
Bumps the brace-expansion pnpm overrides from 1.1.13/2.0.3 to
1.1.17/2.1.3 (both within the existing major-version ranges, so not
blocked by dependabot.yml's major-bump ignore policy; pnpm resolved
1.1.18/2.1.4, the latest patch releases satisfying those ranges).
Verified by unpacking the tarballs that 1.1.18/2.1.4 contain the
CVE-2026-14257 fix (EXPANSION_MAX_LENGTH bounding) while keeping the
same `module.exports = expandTop` callable export shape that
minimatch@3.1.5/9.0.9 require() against — unlike the full 5.0.8 bump,
which changes that export shape and was reverted elsewhere for
breaking those consumers.

Fixes GHSA-mh99-v99m-4gvg / alert #261.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 30, 2026
The "Review Dependency Licenses" check still flags brace-expansion
1.1.18/2.1.4 (the backported patch versions from the prior commit)
because the advisory's vulnerable_version_range ("<=5.0.7") predates
the maintainer's backport of the same fix into the 1.x/2.x lines --
GitHub's advisory data hasn't caught up to it. Bumping further to the
"official" first-patched version 5.0.8 isn't an option: its CommonJS
export shape change breaks minimatch@3.1.5/9.0.9's require() usage
(already tried and reverted elsewhere in this repo's history).

Mirrors the existing GHSA-fxhp-mv3v-67qp temporary-allowlist pattern
in this same file, with the verification and removal condition
documented inline.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mergify

mergify Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

@mergify mergify Bot added the needs-cloudposse Needs Cloud Posse assistance label Jul 30, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/dependency-review.yml:
- Around line 72-74: Clarify the dependency-version wording in the workflow
comment near the brace-expansion verification: the website/package.json
overrides are semver ranges, so either change them to exact versions or state
that verification used the versions resolved in the lockfile rather than
“pinned” tarballs.
- Around line 68-80: Scope the GHSA-mh99-v99m-4gvg exception in the
dependency-review configuration to the verified brace-expansion versions
recorded in website/pnpm-lock.yaml, rather than allowing the advisory for every
resolved version. Preserve the existing GHSA-fxhp-mv3v-67qp exception and ensure
vulnerable versions such as <=5.0.7 cannot bypass review; remove the exception
instead if advisory metadata has been corrected.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 11bee48d-e31e-449a-8236-7255b114bee3

📥 Commits

Reviewing files that changed from the base of the PR and between 71ec1c9 and dc7c62c.

📒 Files selected for processing (1)
  • .github/workflows/dependency-review.yml

Comment thread .github/workflows/dependency-review.yml
Comment thread .github/workflows/dependency-review.yml Outdated
Addresses two CodeRabbit findings on the prior commit:

- website/package.json's pnpm overrides used ^1.1.17/^2.1.3 (semver
  ranges), but the workflow comment described them as "pinned" tarball
  versions. Changed to exact pins (1.1.18/2.1.4, the same versions
  already verified by unpacking their tarballs) so the wording is
  accurate and a future `pnpm install` can't silently drift to an
  unverified patch release within the range.

- allow-ghsas suppresses GHSA-mh99-v99m-4gvg for every resolved
  brace-expansion version, not just 1.1.18/2.1.4 -- the action has no
  package/version-scoped vulnerability exception (only
  allow-dependencies-licenses is purl-scoped, and that's license-only,
  confirmed against the action's README). Documented this limitation
  inline and noted the exact override pins are what keeps the
  exception scoped in practice.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@aknysh
Andriy Knysh (aknysh) merged commit 6a68bb4 into main Jul 30, 2026
85 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the osterman/debug-container-list-latency branch July 30, 2026 21:51
@atmos-pro

atmos-pro Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@mergify mergify Bot removed the needs-cloudposse Needs Cloud Posse assistance label Jul 30, 2026
@github-actions

Copy link
Copy Markdown

These changes were released in v1.225.0-rc.3.

This branch was successfully deployed

1 active deployment
preview — 00932de9 Deployed Jul 30, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch A minor, backward compatible change size/l Large size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants