Skip to content

merge to main - #49

Merged
Lftobs merged 149 commits into
mainfrom
dev
Sep 20, 2026
Merged

Lftobs merged 149 commits into
mainfrom
dev

Conversation

@Lftobs

@Lftobs Lftobs commented Sep 20, 2026

Copy link
Copy Markdown
Owner

No description provided.

Lftobs and others added 30 commits July 20, 2026 23:19
time

- Add `finished_at` column to deployments table
- Implement status-based timestamping for
  deployment completion
- Update runtime reconciliation to skip
  non-existent containers
- Fix Ko-fi popup mounting in dashboard sidebar
- Update docker-compose configuration for local
  builds
customization

- Add `project_type`, `buildCommand`, and
  `startCommand` fields to projects.
- Implement dynamic `railpack.json` generation for
  better build/runtime compatibility.
- Add `ProjectSettingsTab` to the dashboard for
  managing build settings.
- Update Caddy reverse proxy to correctly pass the
  Host header to upstream containers.
project deployments

- Update database schema to store compose-specific
  metadata
- Enhance Caddy dynamic ingress to route traffic
  to specific services
- Extend project/domain APIs to support service
  target configuration
- Refactor documentation landing page and UI
  components
management

- Migrate databases to a standalone resource model
  with project-optional attachment
- Implement database lifecycle management: start,
  stop, restart, and retry
- Add public access controls with CIDR
  allowlisting
- Introduce Redis and MongoDB support
- Add granular storage monitoring and credential
  management
- Replace legacy project-scoped database tab with
  global dashboard view
time

- Add `finished_at` column to deployments table
- Implement status-based timestamping for
  deployment completion
- Update runtime reconciliation to skip
  non-existent containers
- Fix Ko-fi popup mounting in dashboard sidebar
- Update docker-compose configuration for local
  builds
customization

- Add `project_type`, `buildCommand`, and
  `startCommand` fields to projects.
- Implement dynamic `railpack.json` generation for
  better build/runtime compatibility.
- Add `ProjectSettingsTab` to the dashboard for
  managing build settings.
- Update Caddy reverse proxy to correctly pass the
  Host header to upstream containers.
management

- Migrate databases to a standalone resource model
  with project-optional attachment
- Implement database lifecycle management: start,
  stop, restart, and retry
- Add public access controls with CIDR
  allowlisting
- Introduce Redis and MongoDB support
- Add granular storage monitoring and credential
  management
- Replace legacy project-scoped database tab with
  global dashboard view
project deployments

- Update database schema to store compose-specific
  metadata
- Enhance Caddy dynamic ingress to route traffic
  to specific services
- Extend project/domain APIs to support service
  target configuration
- Refactor documentation landing page and UI
  components
and update landing page

- Ensure environment variables are created before
  initial deployments to
  prevent runtime errors for apps requiring
  specific configuration.
- Update hero copy and stats on the documentation
  site for better
  messaging and accuracy.
deployment support

- Refactor compose service parsing to support
  long-form port syntax.
- Extract compose deployment logic into dedicated
  module.
- Add validation to block rollbacks for compose
  deployments.
- Add error handling for database provisioning
  timeouts.
- Include `yaml` package to improve parsing
  reliability.
management

- Migrate databases to a standalone resource model
  with project-optional attachment
- Implement database lifecycle management: start,
  stop, restart, and retry
- Add public access controls with CIDR
  allowlisting
- Introduce Redis and MongoDB support
- Add granular storage monitoring and credential
  management
- Replace legacy project-scoped database tab with
  global dashboard view
and update landing page

- Ensure environment variables are created before
  initial deployments to
  prevent runtime errors for apps requiring
  specific configuration.
- Update hero copy and stats on the documentation
  site for better
  messaging and accuracy.
…oyment errors

Add install_command and output_dir project columns (migration 0008) and
wire them through the railpack config generator. Summarize deployment and
rollback failures to the most actionable line instead of the full raw
stderr transcript.
projects

Add `installCommand` and `outputDir` fields to the
project schema and
repository to allow custom build configurations.
Introduce an error
summarizer utility to extract actionable build
failure messages from
noisy logs.
Lftobs and others added 28 commits September 3, 2026 14:57
When GitHub OAuth sessions are lost (e.g. API restart), the RepoPicker
now shows a 'Connect GitHub' button alongside 'Retry' so users can
re-authenticate without manually navigating to the OAuth URL.

Also passes onConnectGithub from SourceSelectionSection to RepoPicker.
Replace in-memory file-based GitHub sessions with encrypted DB storage.
Sessions survive API container restarts. Uses the same encryptValue/
decryptValue pattern as env vars and SSH keys.
* feat(agent): introduce remote deployment agent

- Add `apps/agent` for remote deployment
  orchestration
- Implement agent-server P2P protocol with
  heartbeat, job leasing, and task execution
- Add WireGuard tunneling support for
  agent-to-server connectivity
- Extend API to support agent registration, job
  queuing, and status sync
- Update UI to allow selecting deployment targets
  for projects
- Add database migrations for agent foundations,
  credentials, and job state management

* feat(orchestrator): add server preparation and
failover

- Implement `prepare` service for remote SSH and
  Agent server setup.
- Add `failoverProject` logic to automatically
  redeploy projects when servers become
  unreachable.
- Introduce `routes` database table and ingress
  routing management.
- Add `platform_settings` table to track ingress
  server configuration.
- Update Docker Compose to support configurable
  profiles (default: control-plane).

* refactor(api): inject dependencies in tests

Update Caddy and database utilities to accept
dependencies via options,
enabling synchronous file system access and easier
mocking in tests.

* refactor(db): migrate from SQLite to PostgreSQL

- Update Drizzle configuration and schema to
  PostgreSQL
- Replace `bun:sqlite` with `pg` and
  `drizzle-orm/node-postgres`
- Update migrations to use PostgreSQL syntax
- Reorganize test infrastructure to support
  Postgres pools
- Update configuration to use `DATABASE_URL`
  instead of `DATABASE_PATH`

* refactore(db): migrate to PostgreSQL

- Replace SQLite with PostgreSQL
- Introduce `deployment_events` table for tracking
- Add event repository
- Update migration runner to handle existing
  tables
- Update docker-compose and test configurations

* fix(orchestrator): use HTTP health check instead of TCP for failover

* docs: add agent Caddy routes lifecycle documentation

* feat(api): add domain DNS/TLS status check endpoint

* feat(web): add live DNS/TLS status badges to domains tab

* feat(api): re-render all ingress routes when ingress server changes

* refactor(test): migrate integration tests to
external runners

Move complex database-dependent tests to
standalone runners to ensure
proper environment setup, and update repository
and orchestrator logic
to support required operations.

* fix(api): add docker_tcp server support and
improve stability

- Introduce `docker_tcp` server mode
- Add timeout configurations for SSH and API
  operations
- Enhance WireGuard tunnel recovery logic
- Improve agent registration error handling and
  stats validation
- Update server preparation and scaling engine for
  better compatibility

* refactor(api): standardize API responses and
update release pipeline

- Introduce standardized `ApiResponse` type and
  helper functions (`ok`, `created`, `fail`)
- Update API routes to use new response wrappers
- Update CI workflow to support pre-release
  tagging and image naming
- Enhance CLI `update` and `install` scripts to
  support pre-release versions

* chore: improve stability and environment security

- Add `.env.example` for better configuration
  management
- Enhance database security with generated
  passwords and improved URL handling
- Update `rerenderAllIngressRoutes` to prevent
  unnecessary route syncing
- Fix race conditions in `AgentStatsCache` and
  `domains-status-runner`
- Improve database connection management in tests
  and migrations
- Add `isPrivateGitUrl` utility for improved
  security validation

* chore(release): v0.3.0-rc.1

* fix(auth): add missing PAM service config for dequel group auth

* fix(e2e): resolve remote server deployment, buildkit, caddy ingress, and database provisioning issues

* fix(rc): use next tag for RC image testing

* fix(rc): resolve login, caddy reload, and missing db migration

- Fix secure cookie blocking HTTP login (derive from X-Forwarded-Proto)
- Add getCaddyContainer function for Caddy reload
- Add missing DB migration for ssh_key/ssh_password columns
- Document E2E test findings

* fix(migration): make ssh_key migration idempotent for existing DBs

* fix: add timeout to Loki fetch, default LogsTab to runtime mode

- Added 5s AbortController timeout to request-logs Loki fetch to prevent infinite loading
- Changed LogsTab default from 'request' to 'runtime' since request logs require Loki

* chore: bump version to v0.3.0-rc.4

* refactor: remove Docker Compose profiles, start all services by default

The monitoring stack (Loki, Promtail, Grafana, Prometheus, cAdvisor) is
required for request logs to work. Profiles added complexity and broke
features silently when the default excluded monitoring.

- Remove profiles: ['monitoring'] from cadvisor, prometheus, loki, promtail, grafana
- Remove profile logic from dequel CLI and install.sh
- Update docs to reflect simplified setup
- All services now start with 'dequel start' or 'docker compose up -d'

* chore: bump version to v0.3.0-rc.5

* feat(ui): add SSH private key input to server form

- Textarea for pasting PEM private key content
- Key shown in server table as [key] indicator
- API already supports sshKey field, UI was missing it

* chore: bump version to v0.3.0-rc.6

* security: encrypt SSH private keys at rest

- Add ssh_key_iv and ssh_key_tag columns to servers table
- Encrypt sshKey with AES-256-GCM before storing in database
- Decrypt on read in mapServer and listServerConnections
- Uses existing encryptValue/decryptValue from crypto.ts
- Migration: 0003_add_server_ssh_key_encryption.sql

* chore: bump version to v0.3.0-rc.7

* chore: ignore local verify-dequel agent skills

* fix(ingress): default local ingress, emit :80 worker routes, plain caddy domains

* feat(cli): rc/prerelease update targets with zero-downtime rolling restart

- dequel update vX.Y.Z-rc.N | --rc | --pre | --pre-release targets
- pull images before recreating only api/web (deployed apps untouched)
- graceful caddy reload applies new Caddyfile without dropped traffic
- health check after update with rollback hint

* fix(caddy): update domain and email configuration

Remove hardcoded default email and update base
domain handling to support
flexible deployment environments.

* fix: skip empty string subdomain in compose service validation

* feat: add Docker Compose deployment support for remote SSH servers

- New ssh-compose-script.ts: bash script generator, result parser, destroy script
- SSH executor now checks buildType and branches to compose path
- Full ingress routing: worker Caddy gets :80 listener, control plane gets hostname route
- Compose-aware destroy and rollback rejection

* fix: use per-service ports and filter non-web containers in compose Caddy routing

* fix: handle composeServices as both string and array (jsonb from Drizzle)

* fix: bind worker Caddy routes to HTTP :80 for ingress deployments

Worker Caddy only exposes port 80 via Docker. Hostname-only routes
(open-saas-openship.intrep.xyz { }) default to HTTPS (port 443) which
is unreachable. Append :80 to all domains in each route block when
viaIngress is true, so Caddy creates a single HTTP server that can
match on hostname. This fixes multi-project routing on workers where
Superteam's catch-all :80 route was winning over hostname-specific
routes.

Also moved ingress detection before snippet generation for cleaner
control flow.

* fix(ci): bust GHA cache per-commit using BUILD_TIME arg

Add BUILD_TIME build arg and scope cache per image per commit.
This prevents stale layer reuse when only source files change
between tag pushes.

* fix: create ingress routes for compose subdomains (api, server, etc.)

Previously, deployComposeRemote() only created one ingress route on the
control plane Caddy for the primary hostname. Subdomains like
api.{slug}.{domain} had Caddy blocks on the worker but no matching
route on the control plane, so external traffic to those subdomains
never reached the worker.

- Add computeComposeIngressHostnames() to compute all ingress hostnames
  for a compose stack (primary + subdomains), excluding DB services
- Add syncComposeIngressRoutes() and removeComposeIngressRoutes() to
  manage per-subdomain route files on the control plane
- Add listRoutesByDeployment() query for cleanup
- Modify deployComposeRemote() to create routes for all subdomains
- Modify destroy() to clean up all subdomain route files from both
  worker and control plane

* fix: include all compose services in webServices for ingress routing

Non-primary services without custom mappings (e.g. 'server' when no
composeServicesJson is configured) were excluded from webServices,
causing computeComposeIngressHostnames to only see the primary service
and produce no subdomain routes.

* fix: use actual container ports from remote compose result for Caddy routes

The remote compose script now outputs port mappings via
docker compose ps --format '{{.Service}}|{{.Name}}|{{.Ports}}'.
parseRemoteComposeResult extracts the host port from each service.
The webServices array now uses these parsed ports for Caddy reverse
proxy configuration, ensuring routes point to the correct container
port (e.g. server:3001 instead of server:3000).

* fix: use container-internal port for Caddy routes, not host-mapped port

The regex now captures group 2 (container port) instead of group 1
(host port) from docker compose ps port output like
'0.0.0.0:32793->3001/tcp'. Caddy runs on the same Docker network
and needs the container-internal port to connect.

* fix: prevent empty catch-all domains in Caddy snippets

- buildCaddySnippet now falls back to slug.baseDomain if defaultDomains
  is empty, preventing catch-all :80 blocks
- deployComposeRemote adds a safety check: if the generated snippet
  starts with ':' (empty domain), it rebuilds with slug.baseDomain
- Fixes superteam catch-all :80 overriding specific hostname routes

* feat(settings): add project deletion and
modularize settings page

* fix: add ON DELETE CASCADE to deployment_logs FK, bump to 0.3.0-rc.10

* fix: install docker compose plugin in API container for local compose deploys

* fix: add Connect GitHub button to RepoPicker when session expires

When GitHub OAuth sessions are lost (e.g. API restart), the RepoPicker
now shows a 'Connect GitHub' button alongside 'Retry' so users can
re-authenticate without manually navigating to the OAuth URL.

Also passes onConnectGithub from SourceSelectionSection to RepoPicker.

* feat: persist GitHub OAuth sessions in DB with AES-256-GCM encryption

Replace in-memory file-based GitHub sessions with encrypted DB storage.
Sessions survive API container restarts. Uses the same encryptValue/
decryptValue pattern as env vars and SSH keys.

* fix(api): exclude database services from compose
remote ingress routes

* chore: release v0.3.0
- Add biome.json with tabs, double quotes, trailing commas, a11y warnings
- Add .githooks/pre-commit that formats staged .ts/.tsx/.json files
- Configure git to use .githooks/ directory
- Add lint/lint:check scripts to root package.json
- Fix server table display: show [key] indicator for pool keys (sshKeyId)
- Fix unused import in Keys.tsx
- Fix indentation inconsistency in ServersSection.tsx SSH key dropdown
- Fix a11y: add htmlFor to labels, type=button to sidebar nav buttons
- Format entire codebase with Biome
# Conflicts:
#	.gitignore
#	apps/agent/src/config.ts
#	apps/agent/src/protocol.ts
#	apps/agent/src/stats.ts
#	apps/api/src/agents/job-channel.ts
#	apps/api/src/api/github/index.ts
#	apps/api/src/db/repo/github-sessions.ts
#	apps/api/src/db/repo/index.ts
#	apps/api/src/db/schema.ts
#	apps/api/src/executors/agent.ts
#	apps/api/src/executors/ssh-compose-script.ts
#	apps/api/src/executors/ssh.ts
#	apps/api/src/utils/compose-ingress.ts
#	apps/api/src/utils/domain-verifier.ts
#	apps/api/src/utils/ssh.ts
#	apps/web/src/components/github/RepoPicker.tsx
#	apps/web/src/components/project/create/SourceSelectionSection.tsx
#	apps/web/src/components/settings/ApiKeysSection.tsx
#	apps/web/src/components/settings/GithubIntegrationSection.tsx
#	apps/web/src/components/settings/ServersSection.tsx
#	apps/web/src/components/settings/SmtpSection.tsx
#	apps/web/src/routes/Settings.tsx
pages with tabbed navigation

- Update compose environment inheritance, refactor
  keys and settings views
  with modern dashboard components, hero headers,
  and tabbed layouts.
Refactor keys and settings views with tabbed navigation
feat(ui): make dequel dashboard 100% mobile responsive
- Fix hardcoded containerName 'postgres' → POSTGRES_CONTAINER env var
  (actual container is dequel-postgres-1, causing all internal backups to fail)
- Fix storageType always showing 'local' in UI → now reads from StorageConfig
- Add dequel-db-backup/ prefix for S3 uploads via shared S3_BACKUP_PREFIX constant
- Extract S3_BACKUP_PREFIX to types.ts to prevent drift between scheduler and API
- Refactor orchestrator to take StorageConfig instead of BackupConfig
- Add system backup schedule/retention to backup_storage_settings table (migration 0033)
- Remove backup env vars from docker-compose (settings read from DB)
- Add pagination component for backup lists
- Upload returns { path, size } for accurate sizeBytes on completion
fix(api):  improves the backup system to support per-database backup scheduling and retention
@coderabbitai

coderabbitai Bot commented Sep 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 6f29252b-fb8b-4420-a38f-73048844a9cd

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Lftobs
Lftobs merged commit 8991b3f into main Sep 20, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant