From b74c6661435ed526f873f8130fad1b8d97f6754c Mon Sep 17 00:00:00 2001 From: gHashTag Date: Sun, 13 Sep 2026 06:09:27 +0000 Subject: [PATCH] fix(queen): ship specs/ in the image so the scheduler can read its contract The first GitHub deploy of #480 on Railway (2026-09-13) answered GET /queen/scheduler with 503 "scheduler contract unreadable: ENOENT /app/specs/t27_compiler.wasm". The route was truthful; the Dockerfile copied apps/server and packages/* but never specs/, so the compiler and the 59 cards were absent from the image. - Dockerfile: COPY specs specs, then a RUN that fails the build unless the wasm sha256 equals the one specs/PIN names (measured locally: 4d9c0447...0aee4 matches). - docs/queen-inngest.md: how the env was actually set on Railway (variable references to the inngest/inngest service, explicit INNGEST_SERVE_HOST), that TRIOS_GITHUB_API_TOKEN is not set there yet, that the service now deploys from GitHub (root trios/agent-server) with auto deploy unavailable, and the 503 above with its fix. --- trios/agent-server/Dockerfile | 14 ++++++++++++++ trios/agent-server/docs/queen-inngest.md | 24 ++++++++++++++++++++++++ 2 files changed, 38 insertions(+) diff --git a/trios/agent-server/Dockerfile b/trios/agent-server/Dockerfile index 472040ed7f..9583134b64 100644 --- a/trios/agent-server/Dockerfile +++ b/trios/agent-server/Dockerfile @@ -152,6 +152,20 @@ COPY apps/server apps/server COPY packages/shared packages/shared COPY packages/cdp-protocol packages/cdp-protocol +# The Queen's scheduler reads its cards and the compiler from here at start-up +# (apps/server/src/inngest/spec-catalog.ts, DEFAULT_SPECS_ROOT = ../../../../specs +# = /app/specs). The first GitHub deploy of #480 (Railway, 2026-09-13) came up +# with GET /queen/scheduler -> 503 "ENOENT /app/specs/t27_compiler.wasm": the +# route told the truth, the image simply did not carry the directory. The check +# below fails the build if the wasm is not the bytes specs/PIN names, so a +# drifted pin is caught here and not at the first request. +COPY specs specs +RUN test -f specs/t27_compiler.wasm \ + && want="$(sed -n 's/.*sha256 \([0-9a-f]\{64\}\).*/\1/p' specs/PIN | head -n1)" \ + && have="$(sha256sum specs/t27_compiler.wasm | cut -d' ' -f1)" \ + && test -n "$want" && test "$want" = "$have" \ + && echo "specs/t27_compiler.wasm sha256 $have matches specs/PIN" + # Where bees check out and work. # # THIS COMMENT USED TO SAY "A volume mounts here in production so a redeploy diff --git a/trios/agent-server/docs/queen-inngest.md b/trios/agent-server/docs/queen-inngest.md index 51de222f2b..6c122d89f1 100644 --- a/trios/agent-server/docs/queen-inngest.md +++ b/trios/agent-server/docs/queen-inngest.md @@ -65,6 +65,30 @@ upstream. Recorded in the tests rather than papered over. Values are set by the operator in Railway's own UI; no token is stored in this repository or handed to an agent (policy: Railway only via the owner's login). +### As deployed (Railway project 999, service trios-agent-server, 2026-09-13) + +- `INNGEST_BASE_URL` = `http://${{inngest/inngest.RAILWAY_PRIVATE_DOMAIN}}:${{inngest/inngest.INNGEST_PORT}}`, + `INNGEST_EVENT_KEY` = `${{inngest/inngest.INNGEST_EVENT_KEY}}`, + `INNGEST_SIGNING_KEY` = `${{inngest/inngest.INNGEST_SIGNING_KEY}}` - Railway + variable references to the self-hosted Inngest service (its display name is + `inngest/inngest`), so the keys are never copied by hand and rotate with it. +- `INNGEST_SERVE_HOST` = `https://trios-agent-server-production.up.railway.app`, + written out in full: `api.t27.ai` is attached to the service but its DNS is + still pending, and `${{RAILWAY_PUBLIC_DOMAIN}}` may resolve to it first. +- `TRIOS_GITHUB_API_TOKEN` was NOT among the service's variables at that date + (measured in the Variables tab; 28 variables before, 32 after). Until the + operator adds it, `dispatch` has no token: `/queen/scheduler` reports the + flag as unset and cron functions cannot `workflow_dispatch`. +- Source: the service was moved from `railway up` snapshots to GitHub + `gHashTag/BrowserOS`, branch `fix/queen-worker-provider-and-prompt-size`, + root directory `trios/agent-server`. Railway shows "Auto deploy unavailable" + (no project member's GitHub account is linked to the repo for the Railway + GitHub App), so after a merge the deploy is triggered by hand in the + Deployments tab until that link is made. +- First deploy of #480 from GitHub came up with `GET /queen/scheduler` -> 503 + `ENOENT /app/specs/t27_compiler.wasm`: the Dockerfile did not copy `specs/`. + Fixed by `COPY specs specs` plus a build-time sha256 check against `specs/PIN`. + ## The move (MOVE_STEPS = 3, CONTROL_AFTER_MOVE = inngest) 1. Deploy this server with the env above; check `GET /queen/scheduler` and the