Repository navigation
Conversation
Code Review SummaryStatus: 2 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental change replaces the BuildKit builder with dockerd's own BuildKit plus a prebuild step; two low-severity robustness/documentation issues remain, and no correctness or security defects were found. Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (2 files)
Fix these issues in Kilo Cloud Previous Review Summaries (16 snapshots, latest commit 8b4c0fe)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 8b4c0fe)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental change is documentation-only: it clarifies the Cloud Agent sandbox image build in the Files Reviewed (1 file)
Previous review (commit ff097ab)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental change adds the Files Reviewed (4 files)
Previous review (commit 59b810b)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental change defaults Files Reviewed (1 file)
Previous review (commit f910993)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental change adds a Files Reviewed (4 files)
Previous review (commit a924ee5)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental change relocates a standalone (non-symlink) Files Reviewed (1 file)
Previous review (commit 9ef0295)Status: 1 Issue Found | Recommendation: Address before merge Executive SummaryThe BuildKit budget-release change is correct, but the previous WARNING about installing the pnpm wrapper over the resolved global Overview
Issue Details (click to expand)WARNING
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit 572535c)Status: 1 Issue Found | Recommendation: Address before merge Executive SummaryThe setup/run split and env-file rewrite resolve all previously reported findings, but installing the pnpm wrapper over the resolved global Overview
Issue Details (click to expand)WARNING
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit 063d164)Status: 6 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental commit only rewrites the cgroup memory-budget calculation (a dynamic default cap with validation moved into the embedded Node program) and introduces no new defect; the previously reported global- Overview
Issue Details (click to expand)CRITICAL
WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit b68d970)Status: 6 Issues Found | Recommendation: Address before merge Executive SummaryThe new seeded browser smoke test waits for Overview
Issue Details (click to expand)CRITICAL
WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit 41c51e0)Status: 5 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental commits only retune the default app memory budget and split two variable assignments into separate Overview
Issue Details (click to expand)CRITICAL
WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit f3bc0dc)Status: 5 Issues Found | Recommendation: Address before merge Executive SummaryThe new global Overview
Issue Details (click to expand)CRITICAL
WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit b20016f)Status: 4 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit 4e6629a)Status: 5 Issues Found | Recommendation: Address before merge Executive SummaryThe new Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit 8d0fad3)Status: 4 Issues Found | Recommendation: Address before merge Executive SummaryThe new service-recovery loop in Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit bf896aa)Status: 3 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental commit ( Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit e7d6948)Status: 3 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental Overview
Issue Details (click to expand)WARNING
[Snapshot truncated.] Additional previous summary content was truncated to keep this comment within platform limits. Reviewed by deepseek-v4.1-flash · Input: 118.4K · Output: 47.2K · Cached: 2.2M Review guidance: REVIEW.md from base branch |
Build images with dockerd's own BuildKit in a capped builds cgroup so unchanged images come from the layer cache, and run wrangler dev once during setup to build them. Document Turbopack memory and Redis CPU findings.
|
|
||
| `.kilo/cloud-agent-setup.sh` prepares a Debian/Ubuntu Cloud Agent sandbox for | ||
| `pnpm dev:start`. It usually runs automatically when the machine starts. You can | ||
| run it at any time: reruns are safe and take about 20 s once the machine is set up. |
There was a problem hiding this comment.
SUGGESTION: Rerun timing is now stale
This commit makes every cloud-agent-setup.sh run start wrangler dev and wait for Container image(s) ready, which the new text below documents as taking "under 2 minutes" on a rerun. The earlier claim that reruns "take about 20 s once the machine is set up" no longer holds; update it so the two timings agree.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
| fi | ||
| sleep 5 | ||
| done | ||
| kill -TERM -- "-$images_pid" |
There was a problem hiding this comment.
SUGGESTION: Guard the prebuild teardown and bound the wait
kill -TERM -- "-$images_pid" runs under set -Eeuo pipefail. If the build process group has already exited by the time the ready marker appears (for example wrangler dev dies right after printing it), kill returns non-zero and the ERR trap fails setup even though the images built successfully. Add 2>/dev/null || true. The following wait "$images_pid" is also unbounded, so a wrangler dev that ignores SIGTERM would hang setup; consider a kill -KILL fallback.
| kill -TERM -- "-$images_pid" | |
| kill -TERM -- "-$images_pid" 2>/dev/null || true |
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
Summary
.kilo/cloud-agent-setup.shfor Debian/Ubuntu Cloud Agent sandboxes. It prepares the environment once; the stack is then run with plainpnpm dev:start..env.local, pulls Compose images throughmirror.gcr.io, migrates the local database and seeds a fake-login test account with credits.pnpm dev:start --no-attach apporpnpm dev:start --no-attach agents fake-llm. Setup installs a globalpnpmwrapper that, inside this repository, moves the invocation into the capped cgroup and loads.wrangler/kilo-startup/env. Outside the repository it execs the real pnpm unchanged.dev:startgains--without=a,b(default$KILO_DEV_WITHOUT;--without=starts everything). The sandbox env defaults it tonotifications,event-service,cloudflare-webhook-agent-ingest,container-usage-meter,cloudflare-git-token-service, which takes the agents stack from 12 to 7 services (~5.8 GB → ~2.8 GB idle). The full stack does not fit the sandbox budget./proc/sysread-only, so dockerd runs without IP forwarding and workerd pins sandbox containers to public resolvers. Setup runs a dnsmasq forwarder on the bridge gateway and DNATs bridge DNS to it, so sandboxes can clone public repositories.buildscgroup,mirror.gcr.ioregistry mirror) instead of adocker-containerbuildx builder that re-exported every image on eachwrangler devstart. Setup prebuilds all eight images by runningwrangler devonce, sodev:starthits the layer cache (KILO_STARTUP_SANDBOX_IMAGES=0skips)..kilo/skills/cloud-agent-sandbox/SKILL.mddocuments setup, limits, memory diagnostics, DNS and harness usage for agents.Verification
In a Debian trixie Cloud Agent sandbox (11 GiB workload cgroup → 9216 MiB dev cap):
bash -n, ShellCheck, andpnpm test:dev-local(408 pass) pass; new unit tests cover service exclusion.pnpm install116 s, image pulls 30–42 s,test:db14 s); warm rerun 19 s. In Cloud Agent sessions the platform already ranpnpm install, so cold setup is ~2 min.pnpm dev:start --no-attach app: command returns in 51 s, first page at 83 s; agent-browser logs in the seeded account on/profile.dev:start --no-attach agents fake-llm(was ~12 min); warm setup rerun <100 s with all 84 build steps cached;cold echo:hipasses.run.ts):cold echo:hi,cold-hot echo:hi,chunked-streaming slow:5:50,queue-while-busy, and legacycold-hot echo:legacypass with no memory pressure; the browser renders the resulting session transcripts.llm-error boomfails on a retry-status assertion, unrelated to the environment.Notes
sendMessageV2).turbopackMemoryEvictionalready defaults toauto; Next returned 4.2→2.8 GB and 4.4→2.0 GB after ~2 min idle. Hitting the cap comes from compiling many routes back to back.dev:startcan fail model validation (5 s timeout) while Turbopack compiles/api/openrouter/models/validate.