Conversation
time - Add `finished_at` column to deployments table - Implement status-based timestamping for deployment completion - Update runtime reconciliation to skip non-existent containers - Fix Ko-fi popup mounting in dashboard sidebar - Update docker-compose configuration for local builds
customization - Add `project_type`, `buildCommand`, and `startCommand` fields to projects. - Implement dynamic `railpack.json` generation for better build/runtime compatibility. - Add `ProjectSettingsTab` to the dashboard for managing build settings. - Update Caddy reverse proxy to correctly pass the Host header to upstream containers.
project deployments - Update database schema to store compose-specific metadata - Enhance Caddy dynamic ingress to route traffic to specific services - Extend project/domain APIs to support service target configuration - Refactor documentation landing page and UI components
management - Migrate databases to a standalone resource model with project-optional attachment - Implement database lifecycle management: start, stop, restart, and retry - Add public access controls with CIDR allowlisting - Introduce Redis and MongoDB support - Add granular storage monitoring and credential management - Replace legacy project-scoped database tab with global dashboard view
time - Add `finished_at` column to deployments table - Implement status-based timestamping for deployment completion - Update runtime reconciliation to skip non-existent containers - Fix Ko-fi popup mounting in dashboard sidebar - Update docker-compose configuration for local builds
customization - Add `project_type`, `buildCommand`, and `startCommand` fields to projects. - Implement dynamic `railpack.json` generation for better build/runtime compatibility. - Add `ProjectSettingsTab` to the dashboard for managing build settings. - Update Caddy reverse proxy to correctly pass the Host header to upstream containers.
management - Migrate databases to a standalone resource model with project-optional attachment - Implement database lifecycle management: start, stop, restart, and retry - Add public access controls with CIDR allowlisting - Introduce Redis and MongoDB support - Add granular storage monitoring and credential management - Replace legacy project-scoped database tab with global dashboard view
project deployments - Update database schema to store compose-specific metadata - Enhance Caddy dynamic ingress to route traffic to specific services - Extend project/domain APIs to support service target configuration - Refactor documentation landing page and UI components
and update landing page - Ensure environment variables are created before initial deployments to prevent runtime errors for apps requiring specific configuration. - Update hero copy and stats on the documentation site for better messaging and accuracy.
deployment support - Refactor compose service parsing to support long-form port syntax. - Extract compose deployment logic into dedicated module. - Add validation to block rollbacks for compose deployments. - Add error handling for database provisioning timeouts. - Include `yaml` package to improve parsing reliability.
…l into feat/managed-db-and-compose
management - Migrate databases to a standalone resource model with project-optional attachment - Implement database lifecycle management: start, stop, restart, and retry - Add public access controls with CIDR allowlisting - Introduce Redis and MongoDB support - Add granular storage monitoring and credential management - Replace legacy project-scoped database tab with global dashboard view
and update landing page - Ensure environment variables are created before initial deployments to prevent runtime errors for apps requiring specific configuration. - Update hero copy and stats on the documentation site for better messaging and accuracy.
…oyment errors Add install_command and output_dir project columns (migration 0008) and wire them through the railpack config generator. Summarize deployment and rollback failures to the most actionable line instead of the full raw stderr transcript.
projects Add `installCommand` and `outputDir` fields to the project schema and repository to allow custom build configurations. Introduce an error summarizer utility to extract actionable build failure messages from noisy logs.
When GitHub OAuth sessions are lost (e.g. API restart), the RepoPicker now shows a 'Connect GitHub' button alongside 'Retry' so users can re-authenticate without manually navigating to the OAuth URL. Also passes onConnectGithub from SourceSelectionSection to RepoPicker.
Replace in-memory file-based GitHub sessions with encrypted DB storage. Sessions survive API container restarts. Uses the same encryptValue/ decryptValue pattern as env vars and SSH keys.
remote ingress routes
* feat(agent): introduce remote deployment agent
- Add `apps/agent` for remote deployment
orchestration
- Implement agent-server P2P protocol with
heartbeat, job leasing, and task execution
- Add WireGuard tunneling support for
agent-to-server connectivity
- Extend API to support agent registration, job
queuing, and status sync
- Update UI to allow selecting deployment targets
for projects
- Add database migrations for agent foundations,
credentials, and job state management
* feat(orchestrator): add server preparation and
failover
- Implement `prepare` service for remote SSH and
Agent server setup.
- Add `failoverProject` logic to automatically
redeploy projects when servers become
unreachable.
- Introduce `routes` database table and ingress
routing management.
- Add `platform_settings` table to track ingress
server configuration.
- Update Docker Compose to support configurable
profiles (default: control-plane).
* refactor(api): inject dependencies in tests
Update Caddy and database utilities to accept
dependencies via options,
enabling synchronous file system access and easier
mocking in tests.
* refactor(db): migrate from SQLite to PostgreSQL
- Update Drizzle configuration and schema to
PostgreSQL
- Replace `bun:sqlite` with `pg` and
`drizzle-orm/node-postgres`
- Update migrations to use PostgreSQL syntax
- Reorganize test infrastructure to support
Postgres pools
- Update configuration to use `DATABASE_URL`
instead of `DATABASE_PATH`
* refactore(db): migrate to PostgreSQL
- Replace SQLite with PostgreSQL
- Introduce `deployment_events` table for tracking
- Add event repository
- Update migration runner to handle existing
tables
- Update docker-compose and test configurations
* fix(orchestrator): use HTTP health check instead of TCP for failover
* docs: add agent Caddy routes lifecycle documentation
* feat(api): add domain DNS/TLS status check endpoint
* feat(web): add live DNS/TLS status badges to domains tab
* feat(api): re-render all ingress routes when ingress server changes
* refactor(test): migrate integration tests to
external runners
Move complex database-dependent tests to
standalone runners to ensure
proper environment setup, and update repository
and orchestrator logic
to support required operations.
* fix(api): add docker_tcp server support and
improve stability
- Introduce `docker_tcp` server mode
- Add timeout configurations for SSH and API
operations
- Enhance WireGuard tunnel recovery logic
- Improve agent registration error handling and
stats validation
- Update server preparation and scaling engine for
better compatibility
* refactor(api): standardize API responses and
update release pipeline
- Introduce standardized `ApiResponse` type and
helper functions (`ok`, `created`, `fail`)
- Update API routes to use new response wrappers
- Update CI workflow to support pre-release
tagging and image naming
- Enhance CLI `update` and `install` scripts to
support pre-release versions
* chore: improve stability and environment security
- Add `.env.example` for better configuration
management
- Enhance database security with generated
passwords and improved URL handling
- Update `rerenderAllIngressRoutes` to prevent
unnecessary route syncing
- Fix race conditions in `AgentStatsCache` and
`domains-status-runner`
- Improve database connection management in tests
and migrations
- Add `isPrivateGitUrl` utility for improved
security validation
* chore(release): v0.3.0-rc.1
* fix(auth): add missing PAM service config for dequel group auth
* fix(e2e): resolve remote server deployment, buildkit, caddy ingress, and database provisioning issues
* fix(rc): use next tag for RC image testing
* fix(rc): resolve login, caddy reload, and missing db migration
- Fix secure cookie blocking HTTP login (derive from X-Forwarded-Proto)
- Add getCaddyContainer function for Caddy reload
- Add missing DB migration for ssh_key/ssh_password columns
- Document E2E test findings
* fix(migration): make ssh_key migration idempotent for existing DBs
* fix: add timeout to Loki fetch, default LogsTab to runtime mode
- Added 5s AbortController timeout to request-logs Loki fetch to prevent infinite loading
- Changed LogsTab default from 'request' to 'runtime' since request logs require Loki
* chore: bump version to v0.3.0-rc.4
* refactor: remove Docker Compose profiles, start all services by default
The monitoring stack (Loki, Promtail, Grafana, Prometheus, cAdvisor) is
required for request logs to work. Profiles added complexity and broke
features silently when the default excluded monitoring.
- Remove profiles: ['monitoring'] from cadvisor, prometheus, loki, promtail, grafana
- Remove profile logic from dequel CLI and install.sh
- Update docs to reflect simplified setup
- All services now start with 'dequel start' or 'docker compose up -d'
* chore: bump version to v0.3.0-rc.5
* feat(ui): add SSH private key input to server form
- Textarea for pasting PEM private key content
- Key shown in server table as [key] indicator
- API already supports sshKey field, UI was missing it
* chore: bump version to v0.3.0-rc.6
* security: encrypt SSH private keys at rest
- Add ssh_key_iv and ssh_key_tag columns to servers table
- Encrypt sshKey with AES-256-GCM before storing in database
- Decrypt on read in mapServer and listServerConnections
- Uses existing encryptValue/decryptValue from crypto.ts
- Migration: 0003_add_server_ssh_key_encryption.sql
* chore: bump version to v0.3.0-rc.7
* chore: ignore local verify-dequel agent skills
* fix(ingress): default local ingress, emit :80 worker routes, plain caddy domains
* feat(cli): rc/prerelease update targets with zero-downtime rolling restart
- dequel update vX.Y.Z-rc.N | --rc | --pre | --pre-release targets
- pull images before recreating only api/web (deployed apps untouched)
- graceful caddy reload applies new Caddyfile without dropped traffic
- health check after update with rollback hint
* fix(caddy): update domain and email configuration
Remove hardcoded default email and update base
domain handling to support
flexible deployment environments.
* fix: skip empty string subdomain in compose service validation
* feat: add Docker Compose deployment support for remote SSH servers
- New ssh-compose-script.ts: bash script generator, result parser, destroy script
- SSH executor now checks buildType and branches to compose path
- Full ingress routing: worker Caddy gets :80 listener, control plane gets hostname route
- Compose-aware destroy and rollback rejection
* fix: use per-service ports and filter non-web containers in compose Caddy routing
* fix: handle composeServices as both string and array (jsonb from Drizzle)
* fix: bind worker Caddy routes to HTTP :80 for ingress deployments
Worker Caddy only exposes port 80 via Docker. Hostname-only routes
(open-saas-openship.intrep.xyz { }) default to HTTPS (port 443) which
is unreachable. Append :80 to all domains in each route block when
viaIngress is true, so Caddy creates a single HTTP server that can
match on hostname. This fixes multi-project routing on workers where
Superteam's catch-all :80 route was winning over hostname-specific
routes.
Also moved ingress detection before snippet generation for cleaner
control flow.
* fix(ci): bust GHA cache per-commit using BUILD_TIME arg
Add BUILD_TIME build arg and scope cache per image per commit.
This prevents stale layer reuse when only source files change
between tag pushes.
* fix: create ingress routes for compose subdomains (api, server, etc.)
Previously, deployComposeRemote() only created one ingress route on the
control plane Caddy for the primary hostname. Subdomains like
api.{slug}.{domain} had Caddy blocks on the worker but no matching
route on the control plane, so external traffic to those subdomains
never reached the worker.
- Add computeComposeIngressHostnames() to compute all ingress hostnames
for a compose stack (primary + subdomains), excluding DB services
- Add syncComposeIngressRoutes() and removeComposeIngressRoutes() to
manage per-subdomain route files on the control plane
- Add listRoutesByDeployment() query for cleanup
- Modify deployComposeRemote() to create routes for all subdomains
- Modify destroy() to clean up all subdomain route files from both
worker and control plane
* fix: include all compose services in webServices for ingress routing
Non-primary services without custom mappings (e.g. 'server' when no
composeServicesJson is configured) were excluded from webServices,
causing computeComposeIngressHostnames to only see the primary service
and produce no subdomain routes.
* fix: use actual container ports from remote compose result for Caddy routes
The remote compose script now outputs port mappings via
docker compose ps --format '{{.Service}}|{{.Name}}|{{.Ports}}'.
parseRemoteComposeResult extracts the host port from each service.
The webServices array now uses these parsed ports for Caddy reverse
proxy configuration, ensuring routes point to the correct container
port (e.g. server:3001 instead of server:3000).
* fix: use container-internal port for Caddy routes, not host-mapped port
The regex now captures group 2 (container port) instead of group 1
(host port) from docker compose ps port output like
'0.0.0.0:32793->3001/tcp'. Caddy runs on the same Docker network
and needs the container-internal port to connect.
* fix: prevent empty catch-all domains in Caddy snippets
- buildCaddySnippet now falls back to slug.baseDomain if defaultDomains
is empty, preventing catch-all :80 blocks
- deployComposeRemote adds a safety check: if the generated snippet
starts with ':' (empty domain), it rebuilds with slug.baseDomain
- Fixes superteam catch-all :80 overriding specific hostname routes
* feat(settings): add project deletion and
modularize settings page
* fix: add ON DELETE CASCADE to deployment_logs FK, bump to 0.3.0-rc.10
* fix: install docker compose plugin in API container for local compose deploys
* fix: add Connect GitHub button to RepoPicker when session expires
When GitHub OAuth sessions are lost (e.g. API restart), the RepoPicker
now shows a 'Connect GitHub' button alongside 'Retry' so users can
re-authenticate without manually navigating to the OAuth URL.
Also passes onConnectGithub from SourceSelectionSection to RepoPicker.
* feat: persist GitHub OAuth sessions in DB with AES-256-GCM encryption
Replace in-memory file-based GitHub sessions with encrypted DB storage.
Sessions survive API container restarts. Uses the same encryptValue/
decryptValue pattern as env vars and SSH keys.
* fix(api): exclude database services from compose
remote ingress routes
* chore: release v0.3.0
pool management
- Add biome.json with tabs, double quotes, trailing commas, a11y warnings - Add .githooks/pre-commit that formats staged .ts/.tsx/.json files - Configure git to use .githooks/ directory - Add lint/lint:check scripts to root package.json - Fix server table display: show [key] indicator for pool keys (sshKeyId) - Fix unused import in Keys.tsx - Fix indentation inconsistency in ServersSection.tsx SSH key dropdown - Fix a11y: add htmlFor to labels, type=button to sidebar nav buttons - Format entire codebase with Biome
This reverts commit c6feaa9.
This reverts commit d6c75f9.
# Conflicts: # .gitignore # apps/agent/src/config.ts # apps/agent/src/protocol.ts # apps/agent/src/stats.ts # apps/api/src/agents/job-channel.ts # apps/api/src/api/github/index.ts # apps/api/src/db/repo/github-sessions.ts # apps/api/src/db/repo/index.ts # apps/api/src/db/schema.ts # apps/api/src/executors/agent.ts # apps/api/src/executors/ssh-compose-script.ts # apps/api/src/executors/ssh.ts # apps/api/src/utils/compose-ingress.ts # apps/api/src/utils/domain-verifier.ts # apps/api/src/utils/ssh.ts # apps/web/src/components/github/RepoPicker.tsx # apps/web/src/components/project/create/SourceSelectionSection.tsx # apps/web/src/components/settings/ApiKeysSection.tsx # apps/web/src/components/settings/GithubIntegrationSection.tsx # apps/web/src/components/settings/ServersSection.tsx # apps/web/src/components/settings/SmtpSection.tsx # apps/web/src/routes/Settings.tsx
pages with tabbed navigation - Update compose environment inheritance, refactor keys and settings views with modern dashboard components, hero headers, and tabbed layouts.
Refactor keys and settings views with tabbed navigation
restore system
…mobile responsive
feat(ui): make dequel dashboard 100% mobile responsive
…onfiguration, and capsule tabs
tabs overflow behavior
- Fix hardcoded containerName 'postgres' → POSTGRES_CONTAINER env var
(actual container is dequel-postgres-1, causing all internal backups to fail)
- Fix storageType always showing 'local' in UI → now reads from StorageConfig
- Add dequel-db-backup/ prefix for S3 uploads via shared S3_BACKUP_PREFIX constant
- Extract S3_BACKUP_PREFIX to types.ts to prevent drift between scheduler and API
- Refactor orchestrator to take StorageConfig instead of BackupConfig
- Add system backup schedule/retention to backup_storage_settings table (migration 0033)
- Remove backup env vars from docker-compose (settings read from DB)
- Add pagination component for backup lists
- Upload returns { path, size } for accurate sizeBytes on completion
fix(api): improves the backup system to support per-database backup scheduling and retention
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.