feat(queen): hold every cron and skill as one Inngest app, t27-queen - #480
Merged
gHashTag merged 2 commits intoSep 13, 2026
Merged
Conversation
❌ Tests failed — 3/2119 failed
Failed tests
|
added 2 commits
September 13, 2026 05:21
The Queen's scheduler, as the contract in gHashTag/t27#3595 describes it (specs/automation/inngest-queen-scheduler.t27; tool specs/tools/mcp/inngest-dev.t27, held by agent T). One Inngest function per card under specs/crons and specs/skills, read at start-up with the real compiler (vendored t27_compiler.wasm, sha256 in specs/PIN) and never with a regex. - trios/agent-server/specs: 33 cron cards, 26 skill cards, the contract and the wasm, byte-identical to t27 @ 26294613; scripts/sync-t27-specs.sh refreshes them and rewrites the pin. - apps/server/src/inngest: t27-consts (wasm), spec-catalog (schema, refuse a bad card and serve the rest), plan (pure derivation, every rule a constant of the contract), dispatch (workflow_dispatch on the API's default branch; one open "[skill] <ID>" issue per skill, reused), functions, route, index. - /api/inngest served by inngest/hono (signature = auth, so outside the trusted-origin guard); GET /queen/scheduler is the read-only projection (functions, triggers, reasons, refused cards, WHICH env vars are set). - Derivation, measured: 59 functions, 12 with a cron trigger (all HOST github-actions), 21 tick-only (inngest/timer/railway-cron keep their own schedule, no double fire), 26 skills, 0 refused, 0 dangling RUNS. - The bee brief gains "The Queen's scheduler": the tool is the Queen's, a [skill] issue comes from skill/<ID>.run, WHEN is changed on the card, a bee sends no events and calls no Inngest MCP (no key on the machine). - docs/queen-inngest.md: the app, the env, the three-step move. - tests/api/queen-inngest.test.ts: 9 pass (catalog, refusal, plan, dispatch against a fake GitHub, routes; an unsigned invocation is refused). Measured lenience of the wasm analyzer (`str = ;` and `str = 12` typecheck ok) is recorded in the tests; the schema check is the gate here, t27c is the judge upstream. Two pre-existing tsc errors in queen-tick.ts (lines 2116, 2121) are on the base branch and untouched.
…id so CI (Tests / server-api) refused the branch: /api/inngest was an unguarded mount and the pins said 40 mounts, 6 public-read, 18 under /queen. All three were right to fail - a new mount with no guard is exactly what that gate is for. This records why it is allowed: - /api/inngest goes on the reasoned allowlist: Inngest signs every request with INNGEST_SIGNING_KEY and inngest/hono rejects the rest with 4xx before a function runs (queen-inngest.test.ts measures it); a trusted-origin check would only refuse Inngest, which sends no browser Origin. - /queen/scheduler is the seventh public-read - an explicit publicReadCorsMiddleware() on a projection that names which env vars are set and never their values. - Pins re-measured 2026-09-13: 42 mounts, 7 public-read, 19 /queen, seven exceptions without the allowlist. route-guard.test.ts 6 pass; tools/route-guard-audit.mjs: unguardedMounts 0. Tests / server-tools fails on the base as well (Chrome: 'Hidden windows are no longer supported', 3 tests) and is not touched here.
gHashTag
force-pushed
the
queen/inngest-scheduler
branch
from
September 13, 2026 05:21
0868b46 to
de62d32
Compare
gHashTag
changed the base branch from
queen/t27c-witness
to
fix/queen-worker-provider-and-prompt-size
September 13, 2026 05:21
gHashTag
merged commit Sep 13, 2026
79cf6b4
into
fix/queen-worker-provider-and-prompt-size
29 of 33 checks passed
gHashTag
added a commit
that referenced
this pull request
Sep 13, 2026
…ntract (#481) The first GitHub deploy of #480 on Railway (2026-09-13) answered GET /queen/scheduler with 503 "scheduler contract unreadable: ENOENT /app/specs/t27_compiler.wasm". The route was truthful; the Dockerfile copied apps/server and packages/* but never specs/, so the compiler and the 59 cards were absent from the image. - Dockerfile: COPY specs specs, then a RUN that fails the build unless the wasm sha256 equals the one specs/PIN names (measured locally: 4d9c0447...0aee4 matches). - docs/queen-inngest.md: how the env was actually set on Railway (variable references to the inngest/inngest service, explicit INNGEST_SERVE_HOST), that TRIOS_GITHUB_API_TOKEN is not set there yet, that the service now deploys from GitHub (root trios/agent-server) with auto deploy unavailable, and the 503 above with its fix. Co-authored-by: gHashTag <oxicocicate35@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The Queen's scheduler, as the contract in gHashTag/t27#3595 describes it
(specs/automation/inngest-queen-scheduler.t27; tool specs/tools/mcp/inngest-dev.t27,
held by agent T). One Inngest function per card under specs/crons and
specs/skills, read at start-up with the real compiler (vendored
t27_compiler.wasm, sha256 in specs/PIN) and never with a regex.
the wasm, byte-identical to t27 @ 26294613; scripts/sync-t27-specs.sh
refreshes them and rewrites the pin.
bad card and serve the rest), plan (pure derivation, every rule a constant
of the contract), dispatch (workflow_dispatch on the API's default branch;
one open "[skill] " issue per skill, reused), functions, route, index.
trusted-origin guard); GET /queen/scheduler is the read-only projection
(functions, triggers, reasons, refused cards, WHICH env vars are set).
github-actions), 21 tick-only (inngest/timer/railway-cron keep their own
schedule, no double fire), 26 skills, 0 refused, 0 dangling RUNS.
[skill] issue comes from skill/.run, WHEN is changed on the card, a bee
sends no events and calls no Inngest MCP (no key on the machine).
against a fake GitHub, routes; an unsigned invocation is refused).
Measured lenience of the wasm analyzer (
str = ;andstr = 12typecheckok) is recorded in the tests; the schema check is the gate here, t27c is the
judge upstream. Two pre-existing tsc errors in queen-tick.ts (lines 2116,
2121) are on the base branch and untouched.
Stacked on the t27c-witness PR (base =
queen/t27c-witness); merge that first. Spec side: gHashTag/t27#3595 (contract + tool card), gHashTag/trinity#994 (t27.ai Tools tab).Evidence
bun test tests/api/queen-inngest.test.ts tests/api/queen-witness.test.ts tests/api/boundary-reach.test.ts: 39 pass, 0 fail.biome lint src/inngest: clean.tsc --noEmit: 2 errors, both pre-existing on the base (queen-tick.ts 2116/2121,git stashmeasured).specs/PIN: t27 @ 26294613; wasm sha256 4d9c0447b5ca288790ab03d3dffc2dda629ed47af9d6731a105fc923aea0aee4 (488,709 bytes).After merge (operator, Railway UI)
Set
INNGEST_BASE_URL=http://inngestinngest.railway.internal:8288,INNGEST_EVENT_KEY,INNGEST_SIGNING_KEY,INNGEST_SERVE_HOST=<public URL of this server>; thenGET /queen/schedulerand Inngest MCPlist_functions appId=t27-queenshould both say 59. Theschedule:removals (THE MOVE, step 3) are separate PRs in t27/trinity/999 and wait for that check.Functions derived from the vendored cards
cron-timer-999-multibots-telegraf-agent-autopilot-l1118cron-timer-999-multibots-telegraf-bot-owner-billing-l474cron-inngest-999-multibots-telegraf-check-stuck-trainingscron-github-actions-999-multibots-telegraf-ci0 2 * * *cron-timer-999-multibots-telegraf-crmproactive-l375cron-inngest-999-multibots-telegraf-daily-sales-advisorcron-timer-999-multibots-telegraf-generate-jobs-l164cron-inngest-999-multibots-telegraf-health-checkcron-inngest-999-multibots-telegraf-log-monitorcron-timer-999-multibots-telegraf-notificationhandler-l318cron-timer-999-multibots-telegraf-notificationhandler-l324cron-inngest-999-multibots-telegraf-periodic-webhook-health-checkcron-timer-999-multibots-telegraf-production-monitor-l80cron-timer-999-multibots-telegraf-provider-health-monitor-l344cron-timer-999-multibots-telegraf-render-server-l10845cron-timer-999-multibots-telegraf-render-server-l2301cron-timer-999-multibots-telegraf-render-server-l2325cron-timer-999-multibots-telegraf-render-server-l919cron-github-actions-999-multibots-telegraf-security0 3 * * 0cron-inngest-999-multibots-telegraf-skill-detectorcron-timer-999-multibots-telegraf-taskcache-l27cron-timer-999-multibots-telegraf-video-task-store-l156cron-railway-cron-999-jobsearch-croncron-github-actions-t27-formal-mutation0 5 * * 1cron-github-actions-t27-pr-dashboard0 * * * *cron-github-actions-trinity-agent-cron-cleanup0 */2 * * *cron-github-actions-trinity-agent-queue-drain*/5 * * * *cron-github-actions-trinity-brain-ci0 0 * * 0cron-github-actions-trinity-codegen0 0 * * *cron-github-actions-trinity-discover-callers41 5 * * *cron-github-actions-trinity-pages-health-check*/15 * * * *cron-github-actions-trinity-signal-health-self23 4 * * *cron-github-actions-trinity-site-live-gate17 6 * * *skills:
skill-t27-measure-corpus,skill-t27-phi-loop,skill-t27-tri-pipeline,skill-t27-tri,skill-t27-wave-audit,skill-t27-wrap-up,skill-trinity-blog-post,skill-trinity-board-sync,skill-trinity-cloud,skill-trinity-doctor,skill-trinity-farm-garden,skill-trinity-fpga-synth,skill-trinity-god-mode,skill-trinity-implement-issue,skill-trinity-queen-hive-visuals,skill-trinity-review-code,skill-trinity-run-tests,skill-trinity-scholar,skill-trinity-status,skill-trinity-tech-tree,skill-trinity-tri,skill-trinity-trinity-test,skill-trinity-ux-wave,skill-trinity-vibee-gen,skill-trinity-vsa-verify,skill-trinity-wave