Skip to content

feat(dev): set up the Cloud Agent sandbox for pnpm dev:start - #7251

Open
eshurakov wants to merge 35 commits into
mainfrom
kilo/tiny-chameleon-w2a
Open

eshurakov wants to merge 35 commits into
mainfrom
kilo/tiny-chameleon-w2a

Conversation

@eshurakov

@eshurakov eshurakov commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add .kilo/cloud-agent-setup.sh for Debian/Ubuntu Cloud Agent sandboxes. It prepares the environment once; the stack is then run with plain pnpm dev:start.
  • Setup: caps the dev workload in a cgroup at total sandbox memory minus a 2 GiB reserve, installs Docker/Compose v2/tmux/Chromium/agent-browser, starts dockerd if needed, installs dependencies, creates .env.local, pulls Compose images through mirror.gcr.io, migrates the local database and seeds a fake-login test account with credits.
  • Run: pnpm dev:start --no-attach app or pnpm dev:start --no-attach agents fake-llm. Setup installs a global pnpm wrapper that, inside this repository, moves the invocation into the capped cgroup and loads .wrangler/kilo-startup/env. Outside the repository it execs the real pnpm unchanged.
  • Run only what the sandbox needs: dev:start gains --without=a,b (default $KILO_DEV_WITHOUT; --without= starts everything). The sandbox env defaults it to notifications,event-service,cloudflare-webhook-agent-ingest,container-usage-meter,cloudflare-git-token-service, which takes the agents stack from 12 to 7 services (~5.8 GB → ~2.8 GB idle). The full stack does not fit the sandbox budget.
  • Sandbox containers get DNS: the sandbox mounts /proc/sys read-only, so dockerd runs without IP forwarding and workerd pins sandbox containers to public resolvers. Setup runs a dnsmasq forwarder on the bridge gateway and DNATs bridge DNS to it, so sandboxes can clone public repositories.
  • Cloud Agent sandbox images build in dockerd's own BuildKit (2 GiB builds cgroup, mirror.gcr.io registry mirror) instead of a docker-container buildx builder that re-exported every image on each wrangler dev start. Setup prebuilds all eight images by running wrangler dev once, so dev:start hits the layer cache (KILO_STARTUP_SANDBOX_IMAGES=0 skips).
  • The web app uses Next's default bundler (Turbopack).
  • .kilo/skills/cloud-agent-sandbox/SKILL.md documents setup, limits, memory diagnostics, DNS and harness usage for agents.

Verification

In a Debian trixie Cloud Agent sandbox (11 GiB workload cgroup → 9216 MiB dev cap):

  • bash -n, ShellCheck, and pnpm test:dev-local (408 pass) pass; new unit tests cover service exclusion.
  • Setup timing: cold 241 s / 225 s (apt 40–43 s, pnpm install 116 s, image pulls 30–42 s, test:db 14 s); warm rerun 19 s. In Cloud Agent sessions the platform already ran pnpm install, so cold setup is ~2 min.
  • pnpm dev:start --no-attach app: command returns in 51 s, first page at 83 s; agent-browser logs in the seeded account on /profile.
  • Image prebuild on a restarted machine: setup ~6 min total; images then ready 80 s after dev:start --no-attach agents fake-llm (was ~12 min); warm setup rerun <100 s with all 84 build steps cached; cold echo:hi passes.
  • Minimal agents stack with fake LLM (run.ts): cold echo:hi, cold-hot echo:hi, chunked-streaming slow:5:50, queue-while-busy, and legacy cold-hot echo:legacy pass with no memory pressure; the browser renders the resulting session transcripts. llm-error boom fails on a retry-status assertion, unrelated to the environment.

Notes

  • Requires Node.js 24 in the sandbox image, plus root or passwordless sudo.
  • Rerun setup after a sandbox restart (the cgroup, dockerd, dnsmasq and iptables rule do not persist).
  • Starting sessions from the UI needs a connected repository provider (GitHub/GitLab app credentials), which the sandbox does not have; harness-created sessions cannot be continued from the UI ("Session not found" from sendMessageV2).
  • Turbopack memory: turbopackMemoryEviction already defaults to auto; Next returned 4.2→2.8 GB and 4.4→2.0 GB after ~2 min idle. Hitting the cap comes from compiling many routes back to back.
  • High Redis/Postgres CPU is memory-pressure reclaim, not load: under pressure Redis spent 6 s user vs 1590 s system CPU over 90 min.
  • Each scenario leaves a ~750 MB sandbox container until its idle stop; remove them between runs in this budget.
  • The first session after dev:start can fail model validation (5 s timeout) while Turbopack compiles /api/openrouter/models/validate.

Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-setup.sh
@kilo-code-bot

kilo-code-bot Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: 2 Issues Found | Recommendation: Address before merge

Executive Summary

The incremental change replaces the BuildKit builder with dockerd's own BuildKit plus a prebuild step; two low-severity robustness/documentation issues remain, and no correctness or security defects were found.

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 2
Issue Details (click to expand)

SUGGESTION

File Line Issue
.kilo/skills/cloud-agent-sandbox/SKILL.md 10 Rerun timing "about 20 s" is stale; the new prebuild makes reruns take up to "under 2 minutes" as documented on line 35.
.kilo/cloud-agent-setup.sh 414 Unguarded kill -TERM can trip set -Eeuo pipefail, and the following wait is unbounded, so the prebuild teardown can fail or hang setup.
Files Reviewed (2 files)
  • .kilo/cloud-agent-setup.sh - 1 issue
  • .kilo/skills/cloud-agent-sandbox/SKILL.md - 1 issue

Fix these issues in Kilo Cloud

Previous Review Summaries (16 snapshots, latest commit 8b4c0fe)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 8b4c0fe)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental change is documentation-only: it clarifies the Cloud Agent sandbox image build in the cloud-agent-sandbox skill and adds the ShellCheck install note. The new wait-loop greps the exact Container image(s) ready marker previously used by the working setup script, and the log path dev/logs/cloud-agent-next.log and the "setup does not install ShellCheck" claim match the current code.

Files Reviewed (1 file)
  • .kilo/skills/cloud-agent-sandbox/SKILL.md

Previous review (commit ff097ab)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental change adds the cloud-agent-sandbox skill and links it from AGENTS.md, the local-development skill, and the setup script's closing output; the documented commands, ports, env vars, cgroup path, and schema columns match the current code, and no defect was found on the changed lines.

Files Reviewed (4 files)
  • .kilo/cloud-agent-setup.sh
  • .kilo/skills/cloud-agent-sandbox/SKILL.md
  • .kilo/skills/local-development/SKILL.md
  • AGENTS.md

Previous review (commit 59b810b)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental change defaults KILO_DEV_WITHOUT to five unneeded agents-stack services and replaces dockerd's --dns flag with a dnsmasq forwarder plus an idempotent iptables DNAT redirect on docker0; the excluded service names are valid, the redirect is guarded and re-runnable, and no new defect was found on the changed lines.

Files Reviewed (1 file)
  • .kilo/cloud-agent-setup.sh

Previous review (commit f910993)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental change adds a --without=/KILO_DEV_WITHOUT service-exclusion feature to dev:start and a dnsmasq bridge-gateway DNS forwarder to the sandbox Docker setup; the exclusion logic validates service names, warns about dependents that lose a skipped dependency, and the new unit tests cover the behavior, with no new defect found on the changed lines.

Files Reviewed (4 files)
  • .kilo/cloud-agent-setup.sh
  • dev/local/cli.ts
  • dev/local/services.ts
  • dev/local/services.test.ts

Previous review (commit a924ee5)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental change relocates a standalone (non-symlink) pnpm binary before the global wrapper is installed, correctly preventing the wrapper from overwriting the real pnpm and re-execing itself; a symlinked pnpm was already safe because install unlinks the destination rather than writing through it.

Files Reviewed (1 file)
  • .kilo/cloud-agent-setup.sh

Previous review (commit 9ef0295)

Status: 1 Issue Found | Recommendation: Address before merge

Executive Summary

The BuildKit budget-release change is correct, but the previous WARNING about installing the pnpm wrapper over the resolved global pnpm path remains unaddressed: when pnpm is a regular file the wrapper overwrites it and then re-execs itself.

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-setup.sh 279 real_pnpm=$(readlink -f "$global_pnpm") can equal $global_pnpm when pnpm is a regular file, so install ... "${global_pnpm:-/usr/local/bin/pnpm}" overwrites the real pnpm; the saved real-pnpm then points at the wrapper and exec "$real_pnpm" re-execs it forever.
Files Reviewed (1 file)
  • .kilo/cloud-agent-setup.sh - 1 issue

Fix these issues in Kilo Cloud

Previous review (commit 572535c)

Status: 1 Issue Found | Recommendation: Address before merge

Executive Summary

The setup/run split and env-file rewrite resolve all previously reported findings, but installing the pnpm wrapper over the resolved global pnpm path is unsafe when that path is a regular file, which can destroy the real pnpm and make the wrapper exec itself in a loop.

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-setup.sh 277 real_pnpm=$(readlink -f "$global_pnpm") can equal $global_pnpm when pnpm is a regular file, so install ... "${global_pnpm:-/usr/local/bin/pnpm}" overwrites the real pnpm; the saved real-pnpm then points at the wrapper and exec "$real_pnpm" re-execs it forever.
Files Reviewed (1 file)
  • .kilo/cloud-agent-setup.sh - 1 issue

Fix these issues in Kilo Cloud

Previous review (commit 063d164)

Status: 6 Issues Found | Recommendation: Address before merge

Executive Summary

The incremental commit only rewrites the cgroup memory-budget calculation (a dynamic default cap with validation moved into the embedded Node program) and introduces no new defect; the previously reported global-pnpm symlink self-exec loop, the seeded-login smoke test waiting on an unreachable / path, the Docker Hub mirror namespace, non-root Docker access, the infra-aware recovery loop, and the compose v1 fallback remain unresolved.

Overview

Severity Count
CRITICAL 1
WARNING 4
SUGGESTION 1
Issue Details (click to expand)

CRITICAL

File Line Issue
.kilo/cloud-agent-startup.sh 208 The global /usr/local/bin/pnpm symlink plus readlink -f on command -v pnpm makes real_pnpm resolve to the wrapper file, so the wrapper execs itself on any repeat run.

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 430 The seeded-login smoke test waits for and asserts window.location.pathname === "/", but callbackPath=/ is rejected by isValidCallbackPath (requires a segment), so /users/after-sign-in falls through to /profile; the wait and eval never match and startup aborts.
.kilo/cloud-agent-startup.sh 324 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7), so the mirror pull fails and silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 119 Only the package install and the dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated and cannot reach a sudo-started daemon on a non-root sandbox.
.kilo/cloud-agent-startup.sh 343 The recovery loop feeds infrastructure services (postgres, redis, redis-http) to pnpm dev:restart, which exits 1 for infra and aborts startup under set -e.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 94 The fallback installs docker-compose v1 but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 6 issues

Fix these issues in Kilo Cloud

Previous review (commit b68d970)

Status: 6 Issues Found | Recommendation: Address before merge

Executive Summary

The new seeded browser smoke test waits for window.location.pathname === "/", but callbackPath=/ is rejected by isValidCallbackPath so the fake login lands on /profile and the smoke test can never pass; the previously reported global-pnpm symlink self-exec loop, Docker Hub mirror namespace, non-root Docker access, compose v1 fallback, and infra-aware recovery loop remain unresolved.

Overview

Severity Count
CRITICAL 1
WARNING 4
SUGGESTION 1
Issue Details (click to expand)

CRITICAL

File Line Issue
.kilo/cloud-agent-startup.sh 201 The global /usr/local/bin/pnpm symlink plus readlink -f on command -v pnpm makes real_pnpm resolve to the wrapper file, so the wrapper execs itself on any repeat run.

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 423 The new smoke test waits for and asserts window.location.pathname === "/", but callbackPath=/ is invalid (isValidCallbackPath requires a segment), so /users/after-sign-in falls through to getProfileRedirectPath and lands on /profile; the wait and eval never match and startup aborts.
.kilo/cloud-agent-startup.sh 317 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7), so the mirror pull fails and silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 112 Only the package install and the dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated and cannot reach a sudo-started daemon on a non-root sandbox.
.kilo/cloud-agent-startup.sh 336 The recovery loop feeds infrastructure services (postgres, redis, redis-http) to pnpm dev:restart, which exits 1 for infra and aborts startup under set -e.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 87 The fallback installs docker-compose v1 but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 6 issues

Fix these issues in Kilo Cloud

Previous review (commit 41c51e0)

Status: 5 Issues Found | Recommendation: Address before merge

Executive Summary

The incremental commits only retune the default app memory budget and split two variable assignments into separate export statements; no new defects were introduced, and the previously reported global-pnpm symlink self-exec loop, Docker Hub mirror namespace, non-root Docker access, compose v1 fallback, and infra-aware recovery loop remain unresolved.

Overview

Severity Count
CRITICAL 1
WARNING 3
SUGGESTION 1
Issue Details (click to expand)

CRITICAL

File Line Issue
.kilo/cloud-agent-startup.sh 201 The global /usr/local/bin/pnpm symlink plus readlink -f on command -v pnpm makes real_pnpm resolve to the wrapper file, so the wrapper execs itself on any repeat run.

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 317 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7), so the mirror pull fails and silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 112 Only the package install and the dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated and cannot reach a sudo-started daemon on a non-root sandbox.
.kilo/cloud-agent-startup.sh 336 The recovery loop feeds infrastructure services (postgres, redis, redis-http) to pnpm dev:restart, which exits 1 for infra and aborts startup under set -e.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 87 The fallback installs docker-compose v1 but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 5 issues

Fix these issues in Kilo Cloud

Previous review (commit f3bc0dc)

Status: 5 Issues Found | Recommendation: Address before merge

Executive Summary

The new global /usr/local/bin/pnpm symlink makes real_pnpm resolve to the wrapper script itself, so repeat runs of the sandbox startup script exec the wrapper in a loop; the Docker Hub mirror namespace, non-root Docker access, the compose v1 fallback, and the infra-aware recovery loop remain unresolved.

Overview

Severity Count
CRITICAL 1
WARNING 3
SUGGESTION 1
Issue Details (click to expand)

CRITICAL

File Line Issue
.kilo/cloud-agent-startup.sh 197 The new /usr/local/bin/pnpm symlink plus readlink -f on command -v pnpm makes real_pnpm resolve to the wrapper file, so the wrapper execs itself forever on any repeat run.

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 312 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7), so the mirror pull fails and silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 108 Only the package install and the dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated and cannot reach a sudo-started daemon on a non-root sandbox.
.kilo/cloud-agent-startup.sh 331 The recovery loop feeds infrastructure services (postgres, redis, redis-http) to pnpm dev:restart, which exits 1 for infra and aborts startup under set -e.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 83 The fallback installs docker-compose v1 but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 5 issues

Fix these issues in Kilo Cloud

Previous review (commit b20016f)

Status: 4 Issues Found | Recommendation: Address before merge

Executive Summary

The incremental --webpack change now correctly matches the sandbox's pnpm --filter {./apps/web} run dev startup path, but the Docker Hub mirror path, the non-root Docker access, the compose v1 fallback, and the infra-aware recovery loop remain unresolved.

Overview

Severity Count
CRITICAL 0
WARNING 3
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 308 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7), so the mirror pull fails and silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 108 Only the package install and the dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated and cannot reach a sudo-started daemon on a non-root sandbox.
.kilo/cloud-agent-startup.sh 327 The recovery loop feeds infrastructure services (postgres, redis, redis-http) to pnpm dev:restart, which exits 1 for infra and aborts startup under set -e.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 83 The fallback installs docker-compose v1 but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 4 issues

Fix these issues in Kilo Cloud

Previous review (commit 4e6629a)

Status: 5 Issues Found | Recommendation: Address before merge

Executive Summary

The new --webpack opt-out sits behind a condition the sandbox's real web startup command (pnpm --filter {./apps/web} run dev) never matches, so it is a no-op; the four earlier findings on the Docker Hub mirror path, non-root Docker access, the compose v1 fallback, and the infra-aware recovery loop remain unresolved.

Overview

Severity Count
CRITICAL 0
WARNING 4
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 170 --webpack is only added when the wrapper is invoked as exactly pnpm run dev, but the dev stack launches pnpm --filter {./apps/web} run dev, so the flag never applies.
.kilo/cloud-agent-startup.sh 304 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7), so the mirror pull fails and silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 108 Only the package install and dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated and cannot reach a sudo-started daemon on a non-root sandbox.
.kilo/cloud-agent-startup.sh 323 The recovery loop feeds infrastructure services (postgres, redis, redis-http) to pnpm dev:restart, which exits 1 for infra and aborts startup under set -e.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 83 The fallback installs docker-compose v1 but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 5 issues

Fix these issues in Kilo Cloud

Previous review (commit 8d0fad3)

Status: 4 Issues Found | Recommendation: Address before merge

Executive Summary

The new service-recovery loop in .kilo/cloud-agent-startup.sh (lines 318-321) can invoke pnpm dev:restart on infrastructure services, which exits 1 for infra and aborts the whole startup under set -e; the three earlier findings on the Docker Hub mirror namespace, non-root Docker access, and the compose v1 fallback remain unresolved.

Overview

Severity Count
CRITICAL 0
WARNING 3
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 320 The new recovery loop calls pnpm dev:restart for every service not up, but dev:status --json includes infrastructure services (postgres, redis, redis-http). cmdRestart exits 1 for infra (dev/local/cli.ts:1333), so a down infra container aborts the entire startup under set -e.
.kilo/cloud-agent-startup.sh 301 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7 from dev/docker-compose.yml), so the mirror pull fails and the loop silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 108 Only the package install and dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated, so a sudo-started daemon (socket root:docker) is unreachable on a non-root sandbox and the script exits with a misleading message.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 83 The fallback installs docker-compose (v1) but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 4 issues

Fix these issues in Kilo Cloud

Previous review (commit bf896aa)

Status: 3 Issues Found | Recommendation: Address before merge

Executive Summary

The incremental commit (bf896aa) adds BuildKit registry-mirror and CA trust configuration, a builder resource-budget assertion, and a fresh-login browser smoke check; none introduce new defects, and the three previously reported startup issues remain unresolved.

Overview

Severity Count
CRITICAL 0
WARNING 2
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh 298 mirror.gcr.io/$image omits the library/ namespace for Docker Hub official images (e.g. redis:7 from dev/docker-compose.yml), so the mirror pull fails and the loop silently falls back to the unauthenticated Docker Hub pull it exists to avoid.
.kilo/cloud-agent-startup.sh 105 Only the package install and dockerd launch use ${root[@]}; later docker/docker compose calls run unelevated, so a sudo-started daemon (socket root:docker) is unreachable on a non-root sandbox and the script exits with a misleading message.

SUGGESTION

File Line Issue
.kilo/cloud-agent-startup.sh 80 The fallback installs docker-compose (v1) but every compose call uses the docker compose v2 plugin form.
Files Reviewed (1 file)
  • .kilo/cloud-agent-startup.sh - 3 issues

Fix these issues in Kilo Cloud

Previous review (commit e7d6948)

Status: 3 Issues Found | Recommendation: Address before merge

Executive Summary

The incremental kilo-shell wrapper (added so tmux service shells keep the resource wrappers in PATH) is sound and introduces no new defects; the three previously reported startup issues remain unresolved.

Overview

Severity Count
CRITICAL 0
WARNING 2
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.kilo/cloud-agent-startup.sh

[Snapshot truncated.]

Additional previous summary content was truncated to keep this comment within platform limits.


Reviewed by deepseek-v4.1-flash · Input: 118.4K · Output: 47.2K · Cached: 2.2M

Review guidance: REVIEW.md from base branch main

Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-startup.sh Outdated
Comment thread .kilo/cloud-agent-setup.sh
@eshurakov eshurakov changed the title feat(dev): bootstrap the Cloud Agent sandbox development stack feat(dev): set up the Cloud Agent sandbox for pnpm dev:start Oct 8, 2026

`.kilo/cloud-agent-setup.sh` prepares a Debian/Ubuntu Cloud Agent sandbox for
`pnpm dev:start`. It usually runs automatically when the machine starts. You can
run it at any time: reruns are safe and take about 20 s once the machine is set up.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: Rerun timing is now stale

This commit makes every cloud-agent-setup.sh run start wrangler dev and wait for Container image(s) ready, which the new text below documents as taking "under 2 minutes" on a rerun. The earlier claim that reruns "take about 20 s once the machine is set up" no longer holds; update it so the two timings agree.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

fi
sleep 5
done
kill -TERM -- "-$images_pid"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: Guard the prebuild teardown and bound the wait

kill -TERM -- "-$images_pid" runs under set -Eeuo pipefail. If the build process group has already exited by the time the ready marker appears (for example wrangler dev dies right after printing it), kill returns non-zero and the ERR trap fails setup even though the images built successfully. Add 2>/dev/null || true. The following wait "$images_pid" is also unbounded, so a wrangler dev that ignores SIGTERM would hang setup; consider a kill -KILL fallback.

Suggested change
kill -TERM -- "-$images_pid"
kill -TERM -- "-$images_pid" 2>/dev/null || true

Reply with @kilocode-bot fix it to have Kilo Code address this issue.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant