Repository navigation
feat(entitlements): make UserMeter service authority - #1148
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
# Conflicts: # packages/worker/src/email/inbound.ts # packages/worker/src/email/outbound.ts # packages/worker/worker-configuration.d.ts Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
# Conflicts: # docs/contributing/architecture/data-storage.md # packages/worker/src/account/export.node.test.ts # packages/worker/src/account/export.ts Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
# Conflicts: # docs/contributing/architecture/data-storage.md Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
# Conflicts: # docs/contributing/architecture/data-storage.md Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
# Conflicts: # packages/worker/src/mcp/capabilities/admin/domain.ts # packages/worker/src/mcp/capabilities/registry.node.test.ts Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (2)
📝 WalkthroughWalkthroughUserMeter now provides authoritative running package-service counts and ChangesPackage-service authority cutover
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant ServiceStart
participant EntitlementService
participant UserMeter
ServiceStart->>EntitlementService: request current package_services usage
EntitlementService->>UserMeter: count running services
UserMeter-->>EntitlementService: return authoritative count
EntitlementService-->>ServiceStart: enforce entitlement limit
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 1909a01. Configure here.
| now: now.toISOString(), | ||
| }) | ||
| return count | ||
| } |
There was a problem hiding this comment.
Meter lags D1 on starts
Medium Severity
service_start now enforces package_services via countRunningPackageServices, which reads only the UserMeter DO. Lifecycle still awaits D1 upserts in projectServiceStateToD1 but schedules UserMeter updates through waitUntil, so a completed start can leave D1 fresh while the meter omits that service. Back-to-back starts can undercount running services and allow limits to be exceeded until the shadow write lands.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 1909a01. Configure here.
|
🔎 Preview deployed: https://kody-pr-1148.kody-a99.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/contributing/architecture/entitlements.md`:
- Around line 260-263: Update the lifecycle start path and its
upsertPackageServiceState handling so running-state projection is retried
synchronously and the service start fails if projection cannot succeed. Keep
projection best-effort only for transitions that cannot increase usage, ensuring
countRunningPackageServices never evaluates a newly runnable service without a
successful UserMeter update.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: f1ac7aad-c539-46ba-bb3b-906ba321a9e8
📒 Files selected for processing (10)
docs/contributing/architecture/entitlements.mdpackages/worker/src/admin/user-meter-parity.tspackages/worker/src/entitlements/entitlements.node.test.tspackages/worker/src/entitlements/package-service-states.workers.test.tspackages/worker/src/entitlements/package-services-user-meter.node.test.tspackages/worker/src/entitlements/service.tspackages/worker/src/entitlements/user-meter-do.tspackages/worker/src/mcp/capabilities/services/service-start.node.test.tspackages/worker/src/mcp/capabilities/services/service-start.tspackages/worker/src/test-support/user-meter.ts
| **Authority after the flip:** `countRunningPackageServices` reads directly from | ||
| the UserMeter DO — no D1 access on the enforcement path. New lifecycle | ||
| dual-writes (`upsertPackageServiceState`) populate the meter so enforcement is | ||
| immediately consistent. D1 `package_service_states` remains: |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift
Make running-state projection required before a service becomes runnable.
countRunningPackageServices reads UserMeter only. If upsertPackageServiceState fails, D1 can contain a fresh running row while UserMeter remains missing or stale. The next service_start can undercount usage and admit a service beyond the entitlement limit.
Parity detection and later rollback do not protect the failed enforcement decision. Retry the running-state projection synchronously and fail the start if it cannot succeed. Keep best-effort projection only for transitions that cannot increase usage.
Also applies to: 325-328
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/contributing/architecture/entitlements.md` around lines 260 - 263,
Update the lifecycle start path and its upsertPackageServiceState handling so
running-state projection is retried synchronously and the service start fails if
projection cannot succeed. Keep projection best-effort only for transitions that
cannot increase usage, ensuring countRunningPackageServices never evaluates a
newly runnable service without a successful UserMeter update.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>


Summary
package_servicesenforcement and usagepackage_service_statesas discovery/export/deletion inventory and rollback mirrorValidation
npm run validate— passed (1,893 tests)System recap
No table or column retirement in this PR.
Conductor report
aafa600c); required running-projection hardening merged/deployed in fix(services): await authoritative running projection #1149 at 01:45Z.1533313823166173364.Summary by CodeRabbit