Skip to content

fix(cli): flows deploy --repo can target GitLab - #609

Merged
khaliqgant merged 3 commits into
mainfrom
relayflow/flows-software-garden-ba6edbd8
Oct 4, 2026
Merged

khaliqgant merged 3 commits into
mainfrom
relayflow/flows-software-garden-ba6edbd8

Conversation

@agent-relay-code

@agent-relay-code agent-relay-code Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #607.

flows deploy --repo gitlab:group/sub/project and GitLab.com HTTP(S) URLs now send { owner: "group/sub", name: "project", host: "gitlab" }, so Cloud selects GitLab instead of treating the target as GitHub.

Behavior

  • Bare owner/name and GitHub URLs keep their existing wire shape, with no host key. Explicit github: / gitlab: prefixes are case-insensitive. Bare gitlab/myrepo and github/docs remain GitHub repositories; bare a/b/c remains refused.
  • GitLab coordinates are checked exactly as Cloud's isValidFlowRepositoryCoordinates (AgentWorkforce/cloud packages/web/lib/flows/flow-repository.ts) checks them: the owner is the namespace path, at most 255 characters and 20 segments (the root group counts; the project name does not); every owner segment and the project name match /^[A-Za-z0-9][A-Za-z0-9_.-]{0,99}$/ and do not end in ., .git or .atom. A trailing .git on the input is stripped as a URL suffix first, as Cloud's gitlabProjectCoordinates does.
  • Conflicting prefix/URL hosts, unsupported hosts (self-hosted GitLab, SSH URLs) and malformed paths fail before any HTTP.
  • Creation checks the target host's integration. GitLab sources default project to a GitLab target; an unscoped GitHub source against a GitLab target requires an explicit repository. Explicit scopes are preserved. The existing GitLab --flow update path is unchanged and has regression coverage.
  • Deploy/list text shows GitLab targets as gitlab:owner/name; JSON repository objects include host: "gitlab". Usage text and docs/CLOUD.md document the forms, scoping and limits.

Files

packages/sdk/src/{cloud-deploy.ts, cli/cloud-deploy.ts, cloud-versions.ts, flow-requirements.ts, cli-commands.ts, cli.ts, index.ts}, packages/sdk/tests/{cloud-deploy.test.ts, relay-cli-surface.test.ts}, docs/CLOUD.md. No evidence transcripts are committed.

Verification

The Cloud-parity cases (GitLab coordinates match Cloud in tests/cloud-deploy.test.ts) were written first against the previous head and failed 10 of 19 (21 segments, 256-char owner, _-led segments, and each forbidden suffix on owner and name were accepted). After the change:

cd packages/sdk
npx vitest run tests/cloud-deploy.test.ts tests/relay-cli-surface.test.ts tests/flow-requirements.test.ts
 Test Files  3 passed (3)
      Tests  218 passed (218)

The wire shape is unit-pinned against mocked Cloud; no live Cloud deployment was performed.


Note

Medium Risk
Changes hosted deploy wire format, integration preflight, and trigger scoping for GitLab targets; mistakes could mis-route listeners or block valid cross-host trigger combos, though behavior is heavily unit-tested against Cloud rules.

Overview
flows deploy --repo can target GitLab as well as GitHub: gitlab:group/sub/project, github:/gitlab: prefixes, and github.com / gitlab.com HTTP(S) URLs parse into a wire shape with host: "gitlab" when appropriate, while bare owner/name stays GitHub-only (no host key).

Validation for GitLab namespace paths mirrors Cloud (isValidFlowRepositoryCoordinates): segment rules, 20 namespace segments, 255-character owner cap, and rejection of bad suffixes (., .git, .atom) before any deploy HTTP call.

Deploy behavior updates integration requirements and trigger scoping: the deploy target requires GitHub or GitLab depending on host; same-host --on sources default repository/project to the target; a GitLab target with an unscoped GitHub trigger is refused unless github:repository=… is explicit. Deploy/list output shows gitlab:owner/name; --flow version updates on existing GitLab listeners do not re-require GitLab as a new deploy-target integration.

CLI help, docs/CLOUD.md, exports, and tests (including Cloud-parity coordinate cases) are updated accordingly.

Reviewed by Cursor Bugbot for commit 02170be. Bugbot is set up for automated code reviews on this repo. Configure here.

Relayflow and others added 2 commits October 4, 2026 06:58
…dence

The module comment still listed only the GitHub App installation and the
Slack/Linear/Jira/Shortcut connections as possible ingresses, which is now
wrong: a GitLab connection is one too.

Replace evidence/gitlab-deploy/ with captures that reproduce. The committed
full-suite.txt was a transcript from before check.sh pinned bun to 1.4.0 and
ended "41 failed | 172 failed" with no README, so a reviewer opening the
evidence for a passing change saw 172 failures. It is now the SDK suite
section of the current run, alongside:

  - typecheck.txt                    tsc source + tests, exit=0
  - targeted.txt                     the three touched files, 201/201
  - mutation-host-propagation.txt    revert the `host` spread -> 12 failures,
                                     restore -> 100 pass; sha256 recorded
                                     either side of the restore
  - environment.txt                  the probes behind all 31 suite failures
  - README.md                        what each file is, and what is NOT
                                     covered (no live Cloud deploy)

The 31 remaining full-suite failures are environmental and unrelated: 24 need
a usable bubblewrap (apparmor_restrict_unprivileged_userns=1, and the sysctl
CI relaxes is refused by the sysbox FUSE /proc/sys), 7 need a checkout with no
CommonJS ancestor package.json. No test was skipped, weakened or edited.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9c2edaf2-ce26-40cf-b14b-3991aee92918

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@agent-relay-code

Copy link
Copy Markdown
Contributor Author

Relayflow: the adversarial review did not pass. This branch is not approved: the flow stopped here and did not mark it ready to merge.

Review of PR #609

Reviewed head: 1345c39875172c3a9af88d3ad7a7a6eff10034f1.
PR: #609

Disposition: not clean. Two unresolved review concerns follow. No demonstrated
functional regression was found in the supported short GitLab paths or existing
GitHub forms. This review leaves implementation and workflow files unchanged.

R1 — P2: Cloud namespace-limit parity remains unverified

Location: packages/sdk/src/cloud-deploy.ts:49-52 and
packages/sdk/tests/cloud-deploy.test.ts:100-108.

The request explicitly requires namespace-depth validation matching Cloud.
The implementation hard-codes 21 namespace segments and its tests assert that
same choice. The PR body and reviewed-plan.md explicitly acknowledge that
Cloud's validator was unavailable and that this is a limit inferred from
GitLab subgroup documentation. Those tests verify internal consistency, not
the requested API contract.

A stricter Cloud bound would let invalid targets reach the API; a more permissive
bound would make the CLI reject projects Cloud supports. These are possible
consequences, not a demonstrated mismatch. Do not mark the requirement complete
until Cloud's actual validator is cited and its boundary (including whether the
root group counts) is pinned by accepted/rejected regression cases. Check the
segment-length rule against that validator at the same time.

I attempted to inspect cloud#3801; access failed:

gh api repos/AgentWorkforce/cloud/pulls/3801 --jq '{state,merge_commit_sha}'
gh: Not Found (HTTP 404)
{"message":"Not Found","documentation_url":"https://docs.github.com/rest/pulls/pulls#get-a-pull-request","status":"404"}

Exit status: 1.

R2 — P2: mutation evidence does not record reproducible restore commands

Location: evidence/gitlab-deploy/mutation-host-propagation.txt:37-40;
claim: evidence/gitlab-deploy/README.md:22-26.

The committed report calls its procedure mutation verification “in the strict
sense”, but its restore evidence contains:

$ git diff --quiet packages/sdk/src/cloud-deploy.ts (vs the pre-mutation file)
identical to pre-mutation copy

The command as printed is not executable shell syntax, and git diff --quiet
does not emit that success sentence or restore a file. The mutation/restore
commands and hash-producing commands are absent. The before/after test output
is excerpted rather than a complete capture. The identical printed digests
do not repair the missing procedural record.

This does not establish that the mutation was never performed; it establishes
that the committed artifact does not meet AGENTS.md's requirement for literal
commands and captured output. Replace it with a captured sequence showing the
specific edit, failure, byte-for-byte restore comparison and passing rerun,
or narrow/remove the strict mutation-verification claim. I did not perform a
new mutation run and do not claim one.

Review coverage

Read the PR diff, its test additions, deploy parsing/serialization, connection
requirements, deployment-list formatting, listener-version update path, help
text and documentation. In particular:

  • GitHub keeps the wire shape without a host key.
  • GitLab prefixes/URLs preserve nested owners and attach host: 'gitlab'.
  • Cross-host trigger handling preserves explicit scopes; unscoped GitHub
    sources on GitLab targets are refused.
  • The existing GitLab listener update path remains unchanged in behavior.
  • Prefix/URL disagreement, empty segments, unsupported hosts, and the
    implementation's chosen depth boundary have regression cases.

Read all available PR conversation comments, inline comments and submitted
reviews. The only conversation comment was CodeRabbit's skipped-review
notification; it is not a code-review approval. No inline comments or submitted
reviews were present. These are paginated API reads; the conversation evidence
below prints only the opening after the full comment was read.

gh api --paginate repos/AgentWorkforce/flows/issues/609/comments --jq '.[] | {id, author: .user.login, opening: (.body | split("\n") | .[0:8])}'
{"author":"coderabbitai[bot]","id":5977881070,"opening":["\u003c!-- This is an auto-generated comment: summarize by coderabbit.ai --\u003e","\u003c!-- This is an auto-generated comment: skip review by coderabbit.ai --\u003e","","\u003e [!IMPORTANT]","\u003e ## Review skipped","\u003e ","\u003e Bot user detected.","\u003e "]}

Exit status: 0.

gh api --paginate repos/AgentWorkforce/flows/pulls/609/comments
[]

Exit status: 0.

gh api --paginate repos/AgentWorkforce/flows/pulls/609/reviews
[]

Exit status: 0.

Verification performed for this review

Working directory for the following test/typecheck commands:
packages/sdk.

npx vitest run tests/cloud-deploy.test.ts tests/relay-cli-surface.test.ts tests/flow-requirements.test.ts

 RUN  v2.1.9 /home/daytona/.relayflow-v2-supervisor/durable/repository/packages/sdk

 ✓ tests/relay-cli-surface.test.ts (87 tests) 39ms
 ✓ tests/flow-requirements.test.ts (14 tests) 1232ms
   ✓ flows check prints REQUIRES > names the helper, the harness and the mcp server of an authored flow 835ms
 ✓ tests/cloud-deploy.test.ts (100 tests) 2821ms

 Test Files  3 passed (3)
      Tests  201 passed (201)
   Start at  07:56:29
   Duration  5.62s (transform 2.16s, setup 54ms, collect 7.49s, tests 4.09s, environment 0ms, prepare 176ms)

Exit status: 0.

npm run typecheck && npm run typecheck:tests

> @relayflows/sdk@2.0.39 typecheck
> tsc --noEmit && tsc -p tsconfig.type-tests.json


> @relayflows/sdk@2.0.39 typecheck:tests
> tsc -p tsconfig.tests.json

Exit status: 0.

The full SDK suite was not rerun in this review. The committed
evidence/gitlab-deploy/full-suite.txt records failures, and the PR attributes
them to environment restrictions. This review does not independently certify
that attribution or a clean full-suite run. No live Cloud deployment was made.

The diff whitespace check also reports whitespace in committed test transcripts.
This is a lower-priority artifact-formatting observation, not a runtime defect.
Command run from the repository root:

git diff --check c88c3d0 HEAD
evidence/gitlab-deploy/full-suite.txt:1091: trailing whitespace.
+    893| 
evidence/gitlab-deploy/full-suite.txt:1102: trailing whitespace.
+    959| 
evidence/gitlab-deploy/full-suite.txt:1114: trailing whitespace.
+    1195| 
evidence/gitlab-deploy/full-suite.txt:1122: trailing whitespace.
+- Expected: 
evidence/gitlab-deploy/full-suite.txt:1130: trailing whitespace.
++ Received: 
evidence/gitlab-deploy/full-suite.txt:1196: new blank line at EOF.
evidence/gitlab-deploy/targeted.txt:15: new blank line at EOF.

Exit status: 2.

review.clean was not created because R1 and R2 remain unresolved.

parseRepository now mirrors isValidFlowRepositoryCoordinates from
AgentWorkforce/cloud packages/web/lib/flows/flow-repository.ts: at most 20
owner (namespace) segments, a 255-character owner, segments and project name
led by a letter or digit, and no trailing ., .git or .atom. Boundary cases are
pinned on both sides. The evidence/gitlab-deploy transcripts were working
artifacts and are removed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@khaliqgant

Copy link
Copy Markdown
Member

For the review's R1: Cloud's rule (AgentWorkforce/cloud packages/web/lib/flows/flow-repository.ts, isValidFlowRepositoryCoordinates, host gitlab) is owner ≤ 255 chars and ≤ 20 /-segments (root group counts; the project name is separate), each segment and the name matching ^[A-Za-z0-9][A-Za-z0-9_.-]{0,99}$ and not ending in ., .git or .atom. So 21 is a real mismatch. Fleet agent flows-609-finish-sf (sf-frame, channel flows-609-finish) is fixing R1 with boundary regressions and R2 (evidence files, claims); it will not merge.

@khaliqgant khaliqgant changed the title flows deploy cannot target a GitLab repository: --repo always means GitHub fix(cli): flows deploy --repo can target GitLab Oct 4, 2026
@khaliqgant

Copy link
Copy Markdown
Member

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 02170be. Configure here.

@khaliqgant

Copy link
Copy Markdown
Member

Addressed the adversarial review (reviewed head 1345c39) in 02170be:

  • R1: parseRepository now mirrors Cloud's isValidFlowRepositoryCoordinates (packages/web/lib/flows/flow-repository.ts, host gitlab), which is cited in a code comment. The owner is at most 20 segments (the root group counts; the project name does not) and at most 255 characters. Each owner segment and the project name must match /^[A-Za-z0-9][A-Za-z0-9_.-]{0,99}$/ and may not end in ., .git or .atom. The GitLab coordinates match Cloud tests pin each boundary from both sides: 20 vs 21 segments, a 255 vs 256-character owner, 100 vs 101-character segments, the leading character (digit accepted; _, . and - refused), and each forbidden suffix on both an owner segment and the name. On 1345c39, 10 of these 19 cases failed. All pass now (218/218 in the three affected suites).
  • R2: evidence/gitlab-deploy/ is removed. reviewed-plan.md was never committed on this branch. The PR body now describes the final tree and no longer makes the mutation-verification claim.

CI is green and Cursor Bugbot passed on 02170be.

@khaliqgant
khaliqgant marked this pull request as ready for review October 4, 2026 08:50
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T08:52:52.863608Z 02170be Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@khaliqgant
khaliqgant merged commit 7fec0b1 into main Oct 4, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

flows deploy cannot target a GitLab repository: --repo always means GitHub

1 participant