Repository navigation
feat(cloud-environment): derive the cloud plugin list from the marketplace catalog - #663
Conversation
…place catalog setup.sh now builds /opt/melodic-fleet-plugins.json from the melodic-software marketplace catalog: every entry whose defaultEnabled is not false. The file keeps its settings shape, so the cloud bootstrap and its distributed copies read it unchanged. A failed fetch still leaves no list. Delete the hand-kept fleet-plugins.json, check-plugin-baseline.sh and its test, and the CI step and seed-drift job that compared against the list. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 3m 53s —— View job Code review complete
This repo runs a dedicated security lane ( One finding, posted inline on 🔴 Important — deleting Everything else held up well on review:
Note: the PR body's verification claims (73-entry count against the live catalog, local test runs, linters) are author-reported and not independently re-verified here. |
|
Claude finished @kyle-sexton's task in 2m 54s —— View job Security review
Scope: only the 8 files changed in this PR ( IMPORTANT — SUGGESTION — Also considered, not reported as findings:
|
There was a problem hiding this comment.
💡 Codex Review
standards/.github/workflows/ci.yml
Line 986 in 8e90407
Removing this job eliminates the only check that the separate dotfiles workstation seed names every cloud-default plugin. The new catalog derivation updates cloud snapshots automatically, but it does not update .chezmoidata/claude.json; therefore a newly default-enabled catalog plugin can again be silently absent from local workstations—the exact drift this deleted job documents as having previously lost four IDs. The gate should derive its expected IDs from the catalog rather than being removed with the old static baseline.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Enable a catalog entry only when defaultEnabled is absent or true, so a mistyped "false" leaves the plugin off. A catalog whose entries are all off now yields an empty fleet list instead of none, so the repo bootstrap still overlays a repo's opt-ins; a catalog with no entries still yields no list. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 2m 31s —— View job Code review complete
Per Commit
No new correctness/maintainability issues found in this commit. One item from the previous round on this PR remains open and unaddressed by this commit (not re-filed here as it's already an existing inline thread on this PR): the Note: I was unable to run |
|
Claude finished @kyle-sexton's task in 2m 35s —— View job Security review
Scope: the 8 files changed in this PR, diffed as What the new commit (
Carried forward, still unresolved — posted inline on 🔴 IMPORTANT — the trust boundary for the cloud fleet's auto-installed plugin set moved from a reviewed file in this repo ( Also considered, not reported as findings (consistent with the prior review of this PR):
|
|
Replies to the review-body findings (Codex review 5396574274 and the claude[bot] summaries):
|
|
Codex review 5396574274 (retain seed coverage checking): Disposition (PR owner decision): VALID. It will be resolved by removing the second list, not by checking it. A follow-up PR to melodic-software/dotfiles will stop |
…ed fleet list (#5936) No related issue: melodic-software/standards#663 deleted the fleet list this gate fetched, so `lint-2` and `ci-status` fail on every PR and on main. ## Summary `scripts/check-plugin-catalog-enablement.sh` downloaded `components/cloud-environment/fleet-plugins.json` from standards. standards#663 deleted it and now derives the cloud plugin list from this repo's catalog: every entry whose `defaultEnabled` is absent or `true`. The download returns 404, and the gate exits 2. The user chose to drop per-plugin coverage rather than add `true` keys. `.claude/settings.json` is project scope, so a `true` key would enable each off-by-default plugin in every local session here: 5 today, about 54 after #5897, including `miro` and `dometrain-mcp`, whose servers need credentials. With the list derived from the catalog, every catalogued plugin is either on by default or recorded off there, so none can go missing unannounced. ## Fix - `check-plugin-catalog-enablement.sh`: no download and no UNENABLED check. It keeps the three checks that still guard something: a key naming no catalogued plugin (it silently no-ops), keys out of byte order, and `cloud-bootstrap.sh`'s `marketplace_name` matching the declared marketplace. - Its test drops the fleet-list and download cases and adds "catalogued plugins with no key pass". - `ci.yml`: step name and comment describe the new check. - `docs/cloud-sessions.md`: states plainly that a plugin marked `defaultEnabled: false` is not installed in this repo's cloud sessions unless the settings block opts it in, and that a `true` key also enables it locally. ## Verification - Gate on this tree: exit 0, "Every enabledPlugins key for 'melodic-software' names one of the 84 catalogued plugins; none orphaned; keys sorted". - `check-plugin-catalog-enablement.test.sh`: PASS=13 FAIL=0. - `shellcheck`, `shfmt -d`, `actionlint`, and `markdownlint-cli2` on the changed files: clean. ## Related - melodic-software/standards#663 (the change that deleted the list) - #5897 needs no settings keys under this gate. Its body says the gate needs no change; that no longer holds once this merges. - #5933 took the other approach (adding `true` keys) and is closed with `do-not-merge`. - Unblocks #5918, #5921, #5923 and #5935. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
No related issue: removes the hand-kept cloud plugin list in favor of the catalog's
defaultEnabledfield (pairs with melodic-software/claude-code-plugins#5897).Summary
The cloud environment's base plugin set is now every plugin in the melodic-software marketplace catalog whose entry does not set
defaultEnabled: false, read at cache build fromclaude-code-plugins/.claude-plugin/marketplace.json. Repos carry only deltas in their committedenabledPlugins:falseto opt out,trueto opt in to an off-by-default plugin. The cloud bootstrap already installs a repo'strueentries.Fix
setup.sh: newfleet_list_from_catalogwrites/opt/melodic-fleet-plugins.jsonfrom the catalog with jq, in the same settings shape (extraKnownMarketplaces+enabledPlugins), socloud-bootstrap.shand its distributed copies read it unchanged. A failed fetch, unparsable catalog, or empty result leaves no list, as before.SCRIPT_VERSIONbumped.components/cloud-environment/fleet-plugins.json,distribution/check-plugin-baseline.shand its test, the CI test step, and theplugin-seed-driftjob (removed fromci-statusneeds and results). The list they guarded no longer exists.setup.test.sh: tests the derivation against a fixture catalog (an off entry excluded; an explicit-true entry and an entry without the field included; an all-off or unparsable catalog yields no file) and the catalog URL.components/cloud-environment,distribution) describe the catalog-derived list.With today's catalog on main (10 of 83 off) the derived list has 73 entries; after claude-code-plugins#5897 it drops to about 29.
Verification
defaultEnabled: false(both computed by jq).shellcheck,shfmt -d,actionlint,typos,markdownlint-cli2clean on touched files; lefthook pre-commit passed.cloud-bootstrap.test.shpasses.setup.test.shpasses every new assertion locally; two existing install-census assertions fail on Windows Git Bash on unmodified main too, so CI's Linux run is the check for those.Related
defaultEnabled: falseon the off-by-default plugins)🤖 Generated with Claude Code