Skip to content

feat(queen): hold every cron and skill as one Inngest app, t27-queen - #480

Merged
gHashTag merged 2 commits into
fix/queen-worker-provider-and-prompt-sizefrom
queen/inngest-scheduler
Sep 13, 2026
Merged

gHashTag merged 2 commits into
fix/queen-worker-provider-and-prompt-sizefrom
queen/inngest-scheduler

Conversation

@gHashTag

Copy link
Copy Markdown
Owner

What

The Queen's scheduler, as the contract in gHashTag/t27#3595 describes it
(specs/automation/inngest-queen-scheduler.t27; tool specs/tools/mcp/inngest-dev.t27,
held by agent T). One Inngest function per card under specs/crons and
specs/skills, read at start-up with the real compiler (vendored
t27_compiler.wasm, sha256 in specs/PIN) and never with a regex.

  • trios/agent-server/specs: 33 cron cards, 26 skill cards, the contract and
    the wasm, byte-identical to t27 @ 26294613; scripts/sync-t27-specs.sh
    refreshes them and rewrites the pin.
  • apps/server/src/inngest: t27-consts (wasm), spec-catalog (schema, refuse a
    bad card and serve the rest), plan (pure derivation, every rule a constant
    of the contract), dispatch (workflow_dispatch on the API's default branch;
    one open "[skill] " issue per skill, reused), functions, route, index.
  • /api/inngest served by inngest/hono (signature = auth, so outside the
    trusted-origin guard); GET /queen/scheduler is the read-only projection
    (functions, triggers, reasons, refused cards, WHICH env vars are set).
  • Derivation, measured: 59 functions, 12 with a cron trigger (all HOST
    github-actions), 21 tick-only (inngest/timer/railway-cron keep their own
    schedule, no double fire), 26 skills, 0 refused, 0 dangling RUNS.
  • The bee brief gains "The Queen's scheduler": the tool is the Queen's, a
    [skill] issue comes from skill/.run, WHEN is changed on the card, a bee
    sends no events and calls no Inngest MCP (no key on the machine).
  • docs/queen-inngest.md: the app, the env, the three-step move.
  • tests/api/queen-inngest.test.ts: 9 pass (catalog, refusal, plan, dispatch
    against a fake GitHub, routes; an unsigned invocation is refused).

Measured lenience of the wasm analyzer (str = ; and str = 12 typecheck
ok) is recorded in the tests; the schema check is the gate here, t27c is the
judge upstream. Two pre-existing tsc errors in queen-tick.ts (lines 2116,
2121) are on the base branch and untouched.

Stacked on the t27c-witness PR (base = queen/t27c-witness); merge that first. Spec side: gHashTag/t27#3595 (contract + tool card), gHashTag/trinity#994 (t27.ai Tools tab).

Evidence

  • bun test tests/api/queen-inngest.test.ts tests/api/queen-witness.test.ts tests/api/boundary-reach.test.ts: 39 pass, 0 fail.
  • biome lint src/inngest: clean. tsc --noEmit: 2 errors, both pre-existing on the base (queen-tick.ts 2116/2121, git stash measured).
  • specs/PIN: t27 @ 26294613; wasm sha256 4d9c0447b5ca288790ab03d3dffc2dda629ed47af9d6731a105fc923aea0aee4 (488,709 bytes).

After merge (operator, Railway UI)

Set INNGEST_BASE_URL=http://inngestinngest.railway.internal:8288, INNGEST_EVENT_KEY, INNGEST_SIGNING_KEY, INNGEST_SERVE_HOST=<public URL of this server>; then GET /queen/scheduler and Inngest MCP list_functions appId=t27-queen should both say 59. The schedule: removals (THE MOVE, step 3) are separate PRs in t27/trinity/999 and wait for that check.

Functions derived from the vendored cards

function cron trigger dispatch repo service
cron-timer-999-multibots-telegraf-agent-autopilot-l1118 - tick-only 999-multibots-telegraf agent-autopilot.ts:1118
cron-timer-999-multibots-telegraf-bot-owner-billing-l474 - tick-only 999-multibots-telegraf bot-owner-billing.ts:474
cron-inngest-999-multibots-telegraf-check-stuck-trainings - tick-only 999-multibots-telegraf checkStuckTrainings.ts
cron-github-actions-999-multibots-telegraf-ci 0 2 * * * workflow-dispatch 999-multibots-telegraf ci.yml
cron-timer-999-multibots-telegraf-crmproactive-l375 - tick-only 999-multibots-telegraf crmProactive.ts:375
cron-inngest-999-multibots-telegraf-daily-sales-advisor - tick-only 999-multibots-telegraf dailySalesAdvisor.ts
cron-timer-999-multibots-telegraf-generate-jobs-l164 - tick-only 999-multibots-telegraf generate-jobs.ts:164
cron-inngest-999-multibots-telegraf-health-check - tick-only 999-multibots-telegraf criticalErrorMonitor.ts
cron-inngest-999-multibots-telegraf-log-monitor - tick-only 999-multibots-telegraf logMonitor.ts
cron-timer-999-multibots-telegraf-notificationhandler-l318 - tick-only 999-multibots-telegraf notificationHandler.ts:318
cron-timer-999-multibots-telegraf-notificationhandler-l324 - tick-only 999-multibots-telegraf notificationHandler.ts:324
cron-inngest-999-multibots-telegraf-periodic-webhook-health-check - tick-only 999-multibots-telegraf webhookHealthGuard.ts
cron-timer-999-multibots-telegraf-production-monitor-l80 - tick-only 999-multibots-telegraf production-monitor.ts:80
cron-timer-999-multibots-telegraf-provider-health-monitor-l344 - tick-only 999-multibots-telegraf provider-health-monitor.ts:344
cron-timer-999-multibots-telegraf-render-server-l10845 - tick-only 999-multibots-telegraf render-server.ts:10845
cron-timer-999-multibots-telegraf-render-server-l2301 - tick-only 999-multibots-telegraf render-server.ts:2301
cron-timer-999-multibots-telegraf-render-server-l2325 - tick-only 999-multibots-telegraf render-server.ts:2325
cron-timer-999-multibots-telegraf-render-server-l919 - tick-only 999-multibots-telegraf render-server.ts:919
cron-github-actions-999-multibots-telegraf-security 0 3 * * 0 workflow-dispatch 999-multibots-telegraf security.yml
cron-inngest-999-multibots-telegraf-skill-detector - tick-only 999-multibots-telegraf skillDetector.ts
cron-timer-999-multibots-telegraf-taskcache-l27 - tick-only 999-multibots-telegraf taskCache.ts:27
cron-timer-999-multibots-telegraf-video-task-store-l156 - tick-only 999-multibots-telegraf video-task-store.ts:156
cron-railway-cron-999-jobsearch-cron - tick-only railway jobsearch-cron
cron-github-actions-t27-formal-mutation 0 5 * * 1 workflow-dispatch t27 formal-mutation.yml
cron-github-actions-t27-pr-dashboard 0 * * * * workflow-dispatch t27 pr-dashboard.yml
cron-github-actions-trinity-agent-cron-cleanup 0 */2 * * * workflow-dispatch trinity agent-cron-cleanup.yml
cron-github-actions-trinity-agent-queue-drain */5 * * * * workflow-dispatch trinity agent-queue-drain.yml
cron-github-actions-trinity-brain-ci 0 0 * * 0 workflow-dispatch trinity brain-ci.yml
cron-github-actions-trinity-codegen 0 0 * * * workflow-dispatch trinity codegen.yml
cron-github-actions-trinity-discover-callers 41 5 * * * workflow-dispatch trinity discover-callers.yml
cron-github-actions-trinity-pages-health-check */15 * * * * workflow-dispatch trinity pages-health-check.yml
cron-github-actions-trinity-signal-health-self 23 4 * * * workflow-dispatch trinity signal-health-self.yml
cron-github-actions-trinity-site-live-gate 17 6 * * * workflow-dispatch trinity site-live-gate.yml

skills: skill-t27-measure-corpus, skill-t27-phi-loop, skill-t27-tri-pipeline, skill-t27-tri, skill-t27-wave-audit, skill-t27-wrap-up, skill-trinity-blog-post, skill-trinity-board-sync, skill-trinity-cloud, skill-trinity-doctor, skill-trinity-farm-garden, skill-trinity-fpga-synth, skill-trinity-god-mode, skill-trinity-implement-issue, skill-trinity-queen-hive-visuals, skill-trinity-review-code, skill-trinity-run-tests, skill-trinity-scholar, skill-trinity-status, skill-trinity-tech-tree, skill-trinity-tri, skill-trinity-trinity-test, skill-trinity-ux-wave, skill-trinity-vibee-gen, skill-trinity-vsa-verify, skill-trinity-wave

@github-actions

github-actions Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

❌ Tests failed — 3/2119 failed

Suite Passed Failed Skipped
✅ agent 87/87 0 0
✅ build 9/9 0 0
✅ cdp-protocol 5/5 0 0
✅ eval 93/93 0 0
✅ server-agent 272/272 0 0
✅ server-api 971/1005 0 34
✅ server-browser 6/6 0 0
✅ server-integration 10/11 0 1
✅ server-lib 273/273 0 0
✅ server-pglive 3/3 0 0
✅ server-root 68/68 0 0
✅ server-skills 31/31 0 0
❌ server-tools 239/242 3 0
✅ shared 14/14 0 0
Failed tests
  • server-tools — navigation tools > new_hidden_page opens a hidden tab
  • server-tools — navigation tools > show_page restores a hidden page to visible
  • server-tools — window tools > create_hidden_window creates and closes a hidden window

View workflow run

gHashTag added 2 commits September 13, 2026 05:21
The Queen's scheduler, as the contract in gHashTag/t27#3595 describes it
(specs/automation/inngest-queen-scheduler.t27; tool specs/tools/mcp/inngest-dev.t27,
held by agent T). One Inngest function per card under specs/crons and
specs/skills, read at start-up with the real compiler (vendored
t27_compiler.wasm, sha256 in specs/PIN) and never with a regex.

- trios/agent-server/specs: 33 cron cards, 26 skill cards, the contract and
  the wasm, byte-identical to t27 @ 26294613; scripts/sync-t27-specs.sh
  refreshes them and rewrites the pin.
- apps/server/src/inngest: t27-consts (wasm), spec-catalog (schema, refuse a
  bad card and serve the rest), plan (pure derivation, every rule a constant
  of the contract), dispatch (workflow_dispatch on the API's default branch;
  one open "[skill] <ID>" issue per skill, reused), functions, route, index.
- /api/inngest served by inngest/hono (signature = auth, so outside the
  trusted-origin guard); GET /queen/scheduler is the read-only projection
  (functions, triggers, reasons, refused cards, WHICH env vars are set).
- Derivation, measured: 59 functions, 12 with a cron trigger (all HOST
  github-actions), 21 tick-only (inngest/timer/railway-cron keep their own
  schedule, no double fire), 26 skills, 0 refused, 0 dangling RUNS.
- The bee brief gains "The Queen's scheduler": the tool is the Queen's, a
  [skill] issue comes from skill/<ID>.run, WHEN is changed on the card, a bee
  sends no events and calls no Inngest MCP (no key on the machine).
- docs/queen-inngest.md: the app, the env, the three-step move.
- tests/api/queen-inngest.test.ts: 9 pass (catalog, refusal, plan, dispatch
  against a fake GitHub, routes; an unsigned invocation is refused).

Measured lenience of the wasm analyzer (`str = ;` and `str = 12` typecheck
ok) is recorded in the tests; the schema check is the gate here, t27c is the
judge upstream. Two pre-existing tsc errors in queen-tick.ts (lines 2116,
2121) are on the base branch and untouched.
…id so

CI (Tests / server-api) refused the branch: /api/inngest was an unguarded
mount and the pins said 40 mounts, 6 public-read, 18 under /queen. All three
were right to fail - a new mount with no guard is exactly what that gate is
for. This records why it is allowed:

- /api/inngest goes on the reasoned allowlist: Inngest signs every request
  with INNGEST_SIGNING_KEY and inngest/hono rejects the rest with 4xx before
  a function runs (queen-inngest.test.ts measures it); a trusted-origin check
  would only refuse Inngest, which sends no browser Origin.
- /queen/scheduler is the seventh public-read - an explicit
  publicReadCorsMiddleware() on a projection that names which env vars are
  set and never their values.
- Pins re-measured 2026-09-13: 42 mounts, 7 public-read, 19 /queen, seven
  exceptions without the allowlist. route-guard.test.ts 6 pass;
  tools/route-guard-audit.mjs: unguardedMounts 0.

Tests / server-tools fails on the base as well (Chrome: 'Hidden windows are
no longer supported', 3 tests) and is not touched here.
@gHashTag
gHashTag force-pushed the queen/inngest-scheduler branch from 0868b46 to de62d32 Compare September 13, 2026 05:21
@gHashTag
gHashTag changed the base branch from queen/t27c-witness to fix/queen-worker-provider-and-prompt-size September 13, 2026 05:21
@gHashTag
gHashTag merged commit 79cf6b4 into fix/queen-worker-provider-and-prompt-size Sep 13, 2026
29 of 33 checks passed
@gHashTag
gHashTag deleted the queen/inngest-scheduler branch September 13, 2026 05:27
gHashTag added a commit that referenced this pull request Sep 13, 2026
…ntract (#481)

The first GitHub deploy of #480 on Railway (2026-09-13) answered
GET /queen/scheduler with 503 "scheduler contract unreadable: ENOENT
/app/specs/t27_compiler.wasm". The route was truthful; the Dockerfile
copied apps/server and packages/* but never specs/, so the compiler and
the 59 cards were absent from the image.

- Dockerfile: COPY specs specs, then a RUN that fails the build unless the
  wasm sha256 equals the one specs/PIN names (measured locally:
  4d9c0447...0aee4 matches).
- docs/queen-inngest.md: how the env was actually set on Railway (variable
  references to the inngest/inngest service, explicit INNGEST_SERVE_HOST),
  that TRIOS_GITHUB_API_TOKEN is not set there yet, that the service now
  deploys from GitHub (root trios/agent-server) with auto deploy unavailable,
  and the 503 above with its fix.

Co-authored-by: gHashTag <oxicocicate35@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant