Skip to content

feat(cloud): optional Akeru Cloud account with a linked environment socket - #364

Open
leoisadev1 wants to merge 22 commits into
mainfrom
akeru-cloud/foundation
Open

leoisadev1 wants to merge 22 commits into
mainfrom
akeru-cloud/foundation

Conversation

@leoisadev1

@leoisadev1 leoisadev1 commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Summary

Akeru had no way to offer hosted services, such as one-click Slack setup or cloud sandboxes, because Slack and other platforms need a public HTTPS endpoint and Akeru environments are local. This adds an optional Akeru Cloud account. An environment links to it once with a device code, then keeps one outbound socket that the cloud uses to relay requests. Without a linked account, the app works exactly as before.

flowchart LR
  Browser -->|Clerk sign-in, approve code| Worker[apps/cloud Worker]
  Slack -->|HTTPS events| Worker
  Worker <-->|one outbound socket| Hub[EnvironmentHub Durable Object]
  Hub <--> Env[Environment server]
  Env --> Secrets[(ServerSecretStore: link token)]
Loading
  • packages/contracts/src/cloud.ts: versioned socket protocol, device link, forwarded requests.
  • apps/cloud: Cloudflare Worker with Clerk accounts, device link, the EnvironmentHub socket and the hosted Slack relay. apps/cloud/infra deploys it with Alchemy, which pins its own Effect version.
  • Server: link, unlink and status, plus the outbound connection. A 401 or 410 handshake marks the link revoked and stops reconnecting.
  • Settings → Akeru Cloud on web, desktop and mobile, with palette commands. Docs for users and maintainers.

Message content and Slack tokens stay on the environment. The cloud stores account and environment metadata only.

Evidence

After
Settings, not connected
Settings, waiting for approval with a device code
Settings, not connected, mobile web width
  • Live: on an isolated dev server, Connect requested a device code from the staging cloud ("YH5C-LR97") and showed it. Cancel returned to Not connected.
  • Tests: vp test run apps/cloud passes 51 tests in 6 files. Focused server, contracts, web and client-runtime suites pass 261 tests in 26 files. Typecheck passes for cloud, cloud/web, cloud/infra, server, web, mobile, contracts and client-runtime.
  • Review: an independent review found two problems carried over from the original branch, both fixed with regression tests. A socket upgrade could slip past a revocation (a876e6226), and mobile Connect and Disconnect failed silently (7cf888bc6).

Not tested: the Linked state, because approving needs a real Clerk sign-in. Native mobile rendering. A live hosted Slack event through the relay.

Merge Danger

Door: one-way. A push to main that touches apps/cloud/** or packages/contracts/** runs cloud-deploy.yml and redeploys the production Worker at cloud.akeru-bot.com. Production is already live from this branch: the Cloudflare for SaaS hostname, Vercel DNS records, Clerk production instance (email sign-in), and every required cloud-production secret are in place, so the merge only redeploys the same code. Staging stays on its workers.dev address and only allows Leo's account.

Blast radius: environments that link a cloud account, plus the Settings page. Unlinked environments never open the socket.

Created with Claude Opus 5.5 in Claude Code.

leoisadev1 and others added 9 commits October 5, 2026 21:48
Port the cloud wire contracts and owner-only link RPCs onto the current contract modules. Keep the cloud origin configurable only by the environment.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Port device approval, account management, the EnvironmentHub socket, and hosted Slack relay. Keep Alchemy on its own compatible Effect version and wire workspace tests and stage deployments.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Port origin-pinned credentials, device approval, reconnection, revocation, unlink, and the hosted relay seam into the split server layers and RPC handlers. The typed Node transport reads refused upgrade statuses directly.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
The existing navigator augmentation resolves to an empty parameter list, and StaticParamList enters circular SDK inference. Declare the global route map from each screen’s parameter contract instead, without changing runtime navigation.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Port account linking, connection status, cancellation, and disconnect to web, desktop, and mobile Settings. Adapt palette commands and settings deep links to the current navigation and share the status presentation and RPC atoms.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Document linking, privacy, the relay boundary, and deployment stages. Add the minor release changeset for Settings on web, desktop, and mobile.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Keep protocol assertions typed when reading request IDs from the outbound message union.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Serialize upgrades, hello, and revocation through the Durable Object gate. Persist a revoked marker across restarts and recheck the environment and account in D1 before welcoming a socket.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Report non-interruption command failures with an alert for cloud actions. Extend the pending minor changeset and cover failed connection, failed disconnection, and interruption.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
@vercel

vercel Bot commented Oct 6, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
akeru-bot-landing Building Building Preview Oct 6, 2026 2:08am UTC

Request Review

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Oct 6, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 6 potential issues.

Devin Review

Comment thread apps/cloud/src/modules/link/index.ts Outdated
Comment thread apps/cloud/src/modules/channels/oauth.ts Outdated
Comment thread apps/web/src/components/CommandPalette.tsx
Comment thread docs/internals/cloud.md Outdated
Comment thread apps/server/src/cloud/HostedChannelRelay.ts
@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Critical risk] Adds a new hosted cloud service with authentication, database, and deployment infrastructure.

The PR appears safe to merge based on the changes since the previous review and the resolved prior threads.

Summary

The PR adds optional Akeru Cloud account linking, an outbound environment socket, hosted Slack routing, and settings interfaces. Since the previous review, it changes the cloud sign-in component to keep sign-up on the cloud page. No new actionable issue was established.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Client[Settings] -->|Device link| Worker[Akeru Cloud Worker]
  Worker <-->|Environment socket| Server[Environment server]
  Slack -->|Hosted events| Worker
  Worker -->|Relay| Server
Loading

Reviews (9) · Last reviewed commit: "fix(cloud): sign-up stays on Akeru Cloud..."

Comment thread apps/cloud/src/modules/environments/hub.ts
Comment thread apps/cloud/src/modules/environments/revoke.ts Outdated
Comment thread apps/server/src/cloud/CloudConnection.ts
Comment thread apps/cloud/src/modules/link/index.ts
Comment thread apps/mobile/src/settings-stack.tsx
Comment thread apps/cloud/src/modules/link/index.ts Outdated
Comment thread apps/server/src/cloud/CloudAccount.ts
Comment thread apps/cloud/src/modules/environments/hub.ts Outdated
Comment thread apps/mobile/src/features/settings/SettingsAkeruCloudRouteScreen.tsx
Comment thread .github/workflows/cloud-deploy.yml Outdated
leoisadev1 and others added 6 commits October 5, 2026 22:22
Give the Chinese palette fixture a valid environment and cover both cloud action titles. Include optional Akeru Cloud linking in the deliberate thirteen-page navigation cap.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Derive repeatable credentials from the secret device code, retain approved codes through expiry, and make environment creation idempotent. Limit anonymous outstanding codes with a conditional D1 insert.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Cache encrypted OAuth completion results through delivery retries and serialize callbacks. Make revocation atomic and idempotent, recheck account access for socket commands, and require a welcomed socket for delivery. Disabled routes no longer consume the active quota.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Keep credentials on failed disconnects and save a token-free revocation record if deletion fails. Align palette Settings with the command environment, handle mobile app links without an environment, and report verification-page failures. Extract the server test harness along its fixture boundary.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Describe direct handshake status handling, recoverable link and OAuth flows, and confirmed disconnects. State that no hosted bots or production relay consumer ship yet.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Use the resolved v6 checkout and v1 setup-vp commit IDs in the secret-bearing deployment job.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Comment thread apps/cloud/src/modules/link/index.ts Outdated
Comment thread apps/cloud/src/modules/channels/routes.ts
leoisadev1 and others added 2 commits October 5, 2026 22:58
Generate independent link credentials, encrypt their short-lived handoff, and clear it when the environment confirms receipt. Admit starts per caller and limit socket messages before D1 access while caching heartbeat checks.

Implemented with GPT-6.1 Sol through the Codex harness.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Keep confirmed cloud disconnection and add a separate owner-only local Forget RPC and Settings actions on web, desktop, and mobile. Warn that the cloud may still list the environment until revoked there. Update the existing minor changeset and cloud documentation.

Implemented with GPT-6.1 Sol through the Codex harness.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
Comment thread apps/cloud/src/modules/link/index.ts Outdated
Comment thread apps/cloud/src/modules/link/index.ts Outdated
Comment thread apps/cloud/src/modules/link/index.ts Outdated
leoisadev1 and others added 2 commits October 5, 2026 23:21
Persist heartbeat timestamps in socket attachments, check link admission before cleanup, and count only pending codes toward caller quotas. Keep encrypted credential delivery until the code expires or hello confirms receipt. Retain disabled routes for thirty days and cap account route responses.

Seven regression checks fail on the prior implementation; fifty focused tests, scoped lint, and the cloud typecheck pass.

Implemented with GPT-6.1 Sol through the Codex harness.

Co-Authored-By: GPT-6.1 Sol <noreply@openai.com>
The production Worker attaches cloud.akeru-bot.com as a Cloudflare custom
domain, and the app's default cloud address follows it. Staging keeps its
workers.dev address; its Clerk instance now allows only the maintainer's
account, which the docs record. Production deploys need the akeru-bot.com
zone on the Cloudflare account.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Comment thread apps/cloud/infra/alchemy.run.ts Outdated
leoisadev1 and others added 3 commits October 6, 2026 09:23
… (AKR-145)

akeru-bot.com's DNS and landing page stay on Vercel. cloud.akeru-bot.com
becomes a custom hostname on the leodev.cv zone, Vercel DNS points it at that
zone's fallback origin, and a Worker route sends it to the production Worker.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-145)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…bot.com

The sign-in box linked to Clerk's hosted sign-up page, which finishes on the
production instance's home, the bare akeru-bot.com. Sign-up now runs inline in
the same box and returns to the page that asked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch was successfully deployed

1 active (outdated) deployment
Preview — 70680dbb Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant