mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 13:53:15 +00:00
* feat(infra): build + pin the baked open-swe-base-arm64 AMI (T12 AMI / item 3)
Packer-build the custom base image and repoint AppService off the AL2023
placeholder onto it.
deploy/ami/open-swe-base.pkr.hcl — fix two bugs that blocked the first real
`packer build` (the config had only ever been `packer validate`'d at T8):
- the file provisioner failed uploading the templates dir ('scp: …: Is a
directory') — a trailing-slash contents-upload needs the dest dir to exist;
added a 'mkdir -p /tmp/open-swe-templates' shell provisioner + dropped the
dest trailing slash.
- the shell provisioner's custom execute_command omitted {{ .Vars }}, so the
environment_vars never reached provision.sh (which runs under set -u and
aborted on CLOUDWATCH_AGENT_DEB_URL). Added {{ .Vars }}.
infra:
- ami-cache.ts: BAKED_OPEN_SWE_AMI_ID = ami-0545363bb147229ff (built 2026-06-26
from open-swe-base-arm64-20260626-201929) + bakedOpenSweArm64() pinning it by
exact id via MachineImage.genericLinux (offline, deterministic). Dropped the
now-dead AL2023 cachedInContext helper + context key; kept the EBS/replacement
discipline docs.
- app-service.ts: machineImage → bakedOpenSweArm64().
- open-swe-stack.ts: output BakedAmiId (was the AL2023 PinnedAmiId guard).
- cdk.context.json → {} (AMI is a static id pin; no context lookups remain).
- README: Baked AMI + EBS-replacement-discipline section.
tsc + cdk synth(dev+prod) + jest(16) clean; template ImageId = the baked AMI.
NOTE: held — do NOT merge until the open-swe-dev secret values are populated
(put-config.sh). The infra CD is live, so merging this to dev auto-deploys
OpenSweDevStack; without secrets the box boots but fetch-config fail-fasts →
unhealthy ALB target on the shared prod ALB. Merge once secrets are set (T14).
* fix(ami): ASCII-only AMI description + re-pin to ami-00080084502093021
Third packer bug: ami_description had an em-dash (non-ASCII); AWS rejects
non-ASCII in the AMI Description attribute, so packer registered then
DEREGISTERED the first AMI (ami-0545…) on the ModifyImageAttribute error.
Replaced with an ASCII '-'. Rebuilt clean → ami-00080084502093021 (available).
Re-pinned BAKED_OPEN_SWE_AMI_ID.
* fix(deploy): GitHub App + Slack required for prod only, not dev
Per the migration decision: do NOT create/duplicate a separate dev GitHub App or
Slack app — only prod owns the single shared app. So fetch-config.sh no longer
hard-requires the GitHub App quintet (ID/PRIVATE_KEY/INSTALLATION_ID/CLIENT_ID/
CLIENT_SECRET) + Slack/webhook secrets for dev; they move into the prod-only
block alongside the existing GITHUB_WEBHOOK_SECRET/SLACK_SIGNING_SECRET.
Dev now boots with just DASHBOARD_JWT_SECRET + TOKEN_ENCRYPTION_KEY + the active
provider key(s) + the langsmith sandbox keys. Dev is a deployment-validation env
(boot/health/boundary) with no GitHub/Slack/webhook integration; prod parity is
unchanged (prod still requires everything).
* feat: stand up dev properly — S3 assets bucket + artifact CD + on-box uv sync (T7+T19)
Make the dev/prod box deployable end-to-end: a real artifact pipeline and a
re-runnable on-box deploy, so OpenSweDevStack can come up genuinely healthy.
Infra (T7):
- assets-bucket.ts: open-swe-<env>-assets S3 bucket — BLOCK_ALL public access,
SSE-S3, enforceSSL (deny non-TLS), versioned, lifecycle (expire noncurrent +
abort MPU), RETAIN. Wired into OpenSweStack + CfnOutput.
- app-service.ts: open-swe-<env>-deploy SSM document that runs the baked
/opt/open-swe/bin/deploy.sh (tag-scoped roll-the-box). machineImage is the
baked open-swe-base-arm64 AMI (folds in the held #16).
IAM (app deploy role — cross-review gated):
- github-deploy-roles.ts: app role gains s3:PutObject/DeleteObject scoped to
open-swe-<env>-assets/releases/* (CI uploads releases). Drops the generic
AWS-RunShellScript grant now that the dedicated open-swe-<env>-deploy document
is the only SendCommand path — closes the T4 BLOCK#3 arbitrary-shell timebox.
Boot/deploy (T19):
- deploy/ami/deploy.sh: single, re-runnable app-deploy procedure — pull
app.tar.gz/spa.tar.gz from S3, `uv sync --frozen --no-dev` (native ARM64 venv
at the real path, py3.12 pre-baked), restart open-swe.service + reload nginx.
- user-data.sh: nginx starts BEFORE the app deploy (static /healthz -> the ALB
target is healthy even before the first release); deploy.sh is base64-rendered
by CDK into user-data (a normal reviewable repo file, not a heredoc) and the
first-boot deploy is NON-FATAL (no release yet -> wait for the first SSM deploy).
CI (T7+T19):
- build-artifacts.yml (+ .github/scripts): build the SPA with bun (vite ->
ui/.output/public -> spa.tar.gz), package the Python source via git archive
(app.tar.gz, no ui/ no .venv), upload to releases/<sha>/ + releases/latest/ via
the githubdeploy-open-swe-app-<env> OIDC role, then fire open-swe-<env>-deploy.
push dev -> dev (auto); push main -> prod (env "prod" approval gate).
Local: ruff/shellcheck clean, tsc clean, jest 16/16, cdk synth offline OK,
deploy.sh base64 round-trips exact.
* harden(sec-review): tar extraction, deploy gating, least-privilege, secret guard
Address the /sh-security-review fan-out + proof-or-kill verifier pass. Only one
confirmed-high surfaced and it is PRE-EXISTING and out-of-diff (OSWE-IAC-AUDIT-01,
the account-wide CDK cfn-exec residual already documented in config.ts; recorded in
.security-review/suppressions.json with justification + flagged for the per-env
bootstrap-qualifier follow-up). The rest were verifier-downgraded to unverified;
these are the cheap defense-in-depth fixes worth taking regardless:
- deploy.sh: extract tarballs with --no-same-owner --no-same-permissions (root
never honors an archive's uid/mode → no setuid/foreign-owned file can land); and
treat "no release in S3 yet" as a benign exit 0, distinct from a real deploy
failure (set -e stays loud once a release exists).
- publish-and-deploy.sh: gate on the AGGREGATE SSM Command.Status (+ TargetCount),
not CommandInvocations[0], so a partial failure across the brief 2-instance
replacement window can't be reported as success.
- instance-role.ts: scope the box's s3:GetObject to releases/* (mirrors the app
role's write scope) instead of the whole bucket.
- package-artifacts.sh: fail-closed secret-shaped-file guard on app.tar.gz
(defense in depth over .gitignore; scoped to data extensions so *_credentials.py
source is not a false positive — verified against the real tree).
Deferred as documented follow-ups (verifier: unverified, supply-chain-gated to the
CI OIDC writer; bucket is BLOCK_ALL + enforceSSL + versioned): SHA-pinned immutable
releases/<sha>/ pulls + signed checksum (vs mutable latest/), single-tarball release
to remove the torn-read window, and app-aware ALB health (vs static nginx /healthz).
shellcheck/tsc/jest(16) clean; both stacks synth offline.
* fix(infra): ASCII-only EC2 SecurityGroup descriptions + synth-time guard
The instance-SG GroupDescription + ingress/egress rule descriptions carried an
em-dash / arrow (—, →). `tsc` and `cdk synth` accept them, but the EC2 API rejects
non-ASCII in GroupDescription ("Character sets beyond ASCII are not supported"),
so OpenSweDevStack's first deploy failed at the SG and rolled back. (Pre-existing
from #14; same class as the AMI-description ASCII bug.)
- app-service.ts: replace —/→ with ASCII (- / ->) in the SG GroupDescription, the
ingress/egress rule descriptions, and the Route53 comment.
- test/ascii-aws-fields.test.ts: synth-time guard asserting EC2 SecurityGroup
GroupDescription + rule descriptions are pure ASCII, so this fails the build
instead of a deploy next time.
jest 18/18; tsc clean.
* fix(infra): SG rule descriptions use ASCII-charset-safe text (no `>`)
The first ASCII fix replaced the arrow with `->`, but EC2 SecurityGroup *rule*
descriptions allow a stricter set than ASCII — `a-zA-Z0-9. _-:/()#,@[]+=&;{}!$*`,
which EXCLUDES `<`/`>`. So OpenSweDevStack's second deploy still failed at the
ingress rule. Use "to" instead of "->", and tighten the guard test from "ASCII
only" to the exact EC2 allowed charset so it catches `>` (and `<`) too.
jest 18/18; tsc clean.
* fix(infra): minify embedded deploy.sh so user-data fits EC2's 25.6 KB limit
The base64 deploy.sh embedded in user-data pushed the encoded boot script to
27184 bytes, over EC2's 25600-byte cap, so OpenSweDevStack's instance failed with
"Encoded User data is limited to 25600 bytes". Strip full-line comments + blank
lines from deploy.sh before base64-embedding it (repo file keeps comments; only
the on-box copy is minified; the script is opaque base64 so user-data heredocs are
unaffected) -> rendered user-data drops to 16424 bytes (9 KB margin). Add a
synth-time guard test asserting EC2 user-data stays under 25600 bytes encoded.
jest 19/19; minified deploy.sh passes bash -n + shellcheck.
102 lines
5 KiB
Bash
Executable file
102 lines
5 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Open SWE app deploy — RE-RUNNABLE (first boot + every subsequent release).
|
|
#
|
|
# Pulls the current release from S3 (open-swe-<env>-assets), builds the venv
|
|
# natively on the box, and restarts the service. This is the SINGLE source of the
|
|
# app-deploy procedure; it runs in two places:
|
|
#
|
|
# 1. first boot — user-data.sh decodes this script to /opt/open-swe/bin and
|
|
# calls it ONCE (non-fatal: if no release is published yet,
|
|
# nginx is already up and the box waits for the first deploy).
|
|
# 2. every release — the `open-swe-<env>-deploy` SSM document (CI fires it after
|
|
# uploading app.tar.gz / spa.tar.gz) runs this same script.
|
|
#
|
|
# It deploys CODE + STATIC ASSETS only. Secrets/config are NOT fetched here: the
|
|
# systemd unit's ExecStartPre=fetch-config.sh materializes the tmpfs .env on every
|
|
# (re)start, fail-fast — so `systemctl restart` below is what reloads config too.
|
|
#
|
|
# Contract:
|
|
# app.tar.gz = the Python source tree (pyproject.toml + uv.lock + agent/ +
|
|
# deploy/ + langgraph.json + README.md, NO ui/, NO .venv). The venv
|
|
# is built HERE with `uv sync` so it is native ARM64 and lives at
|
|
# the real runtime path (no cross-built / non-relocatable venv).
|
|
# spa.tar.gz = the built dashboard SPA (vite output: _shell.html + assets),
|
|
# extracted to the nginx web root.
|
|
set -euo pipefail
|
|
exec > >(tee -a /var/log/open-swe/deploy.log) 2>&1
|
|
echo "==> open-swe deploy start $(date -u +%FT%TZ)"
|
|
|
|
# Non-secret pointers written by user-data.sh (env, region, bucket, artifact prefix).
|
|
# shellcheck disable=SC1091
|
|
. /etc/open-swe/boot.env
|
|
export AWS_DEFAULT_REGION="${AWS_REGION:?boot.env missing AWS_REGION}"
|
|
: "${ASSETS_BUCKET:?boot.env missing ASSETS_BUCKET}"
|
|
: "${ARTIFACT_PREFIX:?boot.env missing ARTIFACT_PREFIX}"
|
|
|
|
# Fixed layout — must match provision.sh + user-data.sh + the templates.
|
|
SERVICE_USER="openswe"
|
|
APP_DIR="/opt/open-swe/app"
|
|
WWW_ROOT="/var/www/open-swe"
|
|
ENV_FILE="/run/open-swe/.env"
|
|
UV_BIN="/usr/local/bin/uv"
|
|
UV_PYTHON_INSTALL_DIR="/opt/uv/python" # where provision.sh pre-installed py3.12
|
|
SERVICE_HOME="/opt/open-swe"
|
|
|
|
# Benign-vs-failure distinction: on a brand-new env no release is published yet.
|
|
# Treat "app.tar.gz absent in S3" as a benign no-op (exit 0) so first boot is not a
|
|
# scary failure; ONCE a release exists, any later step failing is loud (set -e).
|
|
if ! aws s3 ls "s3://${ASSETS_BUCKET}/${ARTIFACT_PREFIX}/app.tar.gz" >/dev/null 2>&1; then
|
|
echo "==> no release published at s3://${ASSETS_BUCKET}/${ARTIFACT_PREFIX}/ yet — nothing to deploy"
|
|
exit 0
|
|
fi
|
|
|
|
echo "==> pull release from s3://${ASSETS_BUCKET}/${ARTIFACT_PREFIX}/"
|
|
tmp="$(mktemp -d)"
|
|
trap 'rm -rf "$tmp"' EXIT
|
|
aws s3 cp "s3://${ASSETS_BUCKET}/${ARTIFACT_PREFIX}/app.tar.gz" "${tmp}/app.tar.gz"
|
|
aws s3 cp "s3://${ASSETS_BUCKET}/${ARTIFACT_PREFIX}/spa.tar.gz" "${tmp}/spa.tar.gz"
|
|
|
|
# Replace app source + SPA atomically-ish: clear the dirs (drops files removed in
|
|
# this release) then extract. The venv is rebuilt below, so wiping .venv too is
|
|
# fine — uv's cache (in the service home) makes the rebuild fast.
|
|
#
|
|
# Hardening: deploy.sh runs as root, so extract with --no-same-owner
|
|
# --no-same-permissions — files take root:root + umask perms (NOT the archive's
|
|
# uid/mode), so a tarball cannot land a setuid/setgid binary or a foreign-owned
|
|
# file; the chown -R below then hands the tree to the service user. (GNU tar also
|
|
# refuses `..`-escaping members by default.) Defense-in-depth: the only writer of
|
|
# this bucket is the CI OIDC app role, but the box never trusts the archive's
|
|
# ownership/mode regardless.
|
|
echo "==> install app source -> ${APP_DIR}"
|
|
install -d -o "$SERVICE_USER" -g "$SERVICE_USER" -m 0755 "$APP_DIR" "$WWW_ROOT"
|
|
find "$APP_DIR" -mindepth 1 -delete
|
|
find "$WWW_ROOT" -mindepth 1 -delete
|
|
tar --no-same-owner --no-same-permissions -xzf "${tmp}/app.tar.gz" -C "$APP_DIR"
|
|
tar --no-same-owner --no-same-permissions -xzf "${tmp}/spa.tar.gz" -C "$WWW_ROOT"
|
|
# langgraph reads ./.env from WorkingDirectory; point it at the tmpfs file the
|
|
# systemd ExecStartPre materializes.
|
|
ln -sfn "$ENV_FILE" "${APP_DIR}/.env"
|
|
chown -R "$SERVICE_USER":"$SERVICE_USER" "$APP_DIR" "$WWW_ROOT"
|
|
|
|
echo "==> build venv natively (uv sync --frozen --no-dev)"
|
|
# Run as the service user so the venv + uv cache are owned by it. Pin the
|
|
# pre-baked interpreter dir so uv never reaches out to download Python at deploy.
|
|
cd "$APP_DIR"
|
|
sudo -u "$SERVICE_USER" env \
|
|
HOME="$SERVICE_HOME" \
|
|
UV_PYTHON_INSTALL_DIR="$UV_PYTHON_INSTALL_DIR" \
|
|
UV_CACHE_DIR="${SERVICE_HOME}/.cache/uv" \
|
|
"$UV_BIN" sync --frozen --no-dev
|
|
|
|
echo "==> restart open-swe.service + reload nginx"
|
|
# ExecStartPre=fetch-config.sh fails-fast if secrets/config are missing, so a
|
|
# restart here surfaces a bad config as a failed unit (non-zero exit below).
|
|
systemctl restart open-swe.service
|
|
nginx -t && systemctl reload nginx
|
|
|
|
if systemctl is-active --quiet open-swe.service; then
|
|
echo "==> open-swe deploy OK $(date -u +%FT%TZ)"
|
|
else
|
|
echo "!! open-swe.service is not active after deploy (check fetch-config/secrets)"
|
|
exit 1
|
|
fi
|