Add an authoritative "Final, verified topology" section (1a) and
reconcile the phased plan with the executed end-state, superseding the
spike-era values throughout.
Captures: two LangGraph Cloud deployments (dev/prod, one LangSmith
workspace) with their final URL hashes; one Vercel project open-swe-prod
with production + custom dev environments and per-env LANGGRAPH_BACKEND_URL;
the Nitro routeRules proxy mechanism (PR #76, superseding the vercel.json
rewrite and PR #75's build-vercel-output.mjs); two dev/prod-isolated
GitHub Apps; per-deployment user stores; the Bedrock IAM users; and the
seven hard-won operational gotchas.
Refs: #65#74#76
Document the live execution of MIGRATION.md §10.1 (Bedrock auth via static
keys): the customer-managed least-privilege policy open-swe-bedrock-invoke
and the open-swe-dev-bedrock / open-swe-prod-bedrock IAM users. Captures the
static-key deviation rationale (managed LangGraph Cloud cannot assume a role)
and that both mandatory gates (GPT-4.1 IAM cross-review, /sh-security-review)
passed with no critical/high.
* fix(dashboard): managed-cloud OAuth hardening + admin user-mapping endpoint
Prepare the dashboard backend for the managed LangGraph Cloud + Vercel
runtime, where the API is HTTPS and cross-site from the UI.
- OAuth redirect_uri (#2): coerce a schemeless DASHBOARD_API_BASE_URL to
https:// in _api_base_url() so GitHub stops rejecting login with
"redirect_uri not associated with this application". _cookie_security()
now treats a schemeless (managed) value as Secure; SameSite=None too,
consistent with the coerced scheme.
- OAuth state cookie (#3): document that osw_oauth_state is host-only by
design (a Domain cookie is unsafe across *.vercel.app, a public suffix),
so login must always start on the stable alias to avoid "oauth state
mismatch". Operational contract; no behavioral change.
- Admin user mappings (#4): add POST /admin/user-mappings so an admin can
set the github_login -> work_email link from the dashboard instead of a
raw Store write. New "admin" MappingSource provenance value.
* fix(webapp): refresh user-mapping cache on GitHub webhook paths
On managed LangGraph Cloud the backend runs multiple replicas, so the
per-process GitHub<->work-email mapping cache can be stale on the replica
handling a webhook (a mapping created on another replica is invisible
until refresh). process_github_pr_comment and process_github_issue now
refresh the cache from the durable Store before resolving the author's
email, matching the existing Slack mention path (process_slack_mention).
* perf(webapp): defer deepagents import to speed custom-app cold start
The custom FastAPI app (agent.webapp:app, the langgraph.json http.app)
pulled deepagents -> langchain_anthropic -> anthropic into its import
graph via dashboard.routes, only to build skill/chat seed files. Defer
those create_file_data imports into the functions that use them. Removes
deepagents/langchain_anthropic/anthropic from app import entirely and
roughly halves module-import wall time (~0.6-0.8s -> ~0.35s warm; larger
cold-start saving since native anthropic init is skipped). Behavior
identical. (reviewer_diff already imports deepagents under TYPE_CHECKING.)
* feat(ui): set work_email user mappings from the admin dashboard
Add an "Add / update" form to the admin User mappings section and the
adminUpsertUserMapping API client method, wiring the new
POST /admin/user-mappings endpoint. Admins can now create or update a
github_login -> work_email mapping directly instead of waiting for the
user to self-connect Slack.
* docs: document managed LangGraph Cloud + Vercel deployment
- INSTALLATION §10: add the managed production env triad (LANGGRAPH_URL,
DASHBOARD_BASE_URL + DASHBOARD_API_BASE_URL with https://, empty
VITE_DASHBOARD_API_BASE_URL for same-origin), the stable-alias login
and vercel.json stable-deployment-URL requirements, multi-replica cache
note, plus redirect_uri-scheme and oauth-state-mismatch troubleshooting.
Refresh the langgraph.json snippet to all six graphs.
- README: reframe deployment around the managed migration; link the plan.
- deploy/MIGRATION.md: import the self-hosted -> managed migration plan.