refactor: rename cli-v2 → cli, archive legacy cli, plus broker-side grants + auto-migrate
Some checks failed
CI / Lint (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Broker tests (Postgres) (push) Has been cancelled
CI / Docker build (linux/amd64) (push) Has been cancelled

- apps/cli/ is now the canonical CLI (was apps/cli-v2/).
- apps/cli/ legacy v0 archived as branch 'legacy-cli-archive' and tag
  'cli-v0-legacy-final' before deletion; git history preserves it too.
- .github/workflows/release-cli.yml paths updated.
- pnpm-lock.yaml regenerated.

Broker-side peer-grant enforcement (spec: 2026-04-15-per-peer-capabilities):
- 0020_peer-grants.sql adds peer_grants jsonb + GIN index on mesh.member.
- handleSend in broker fetches recipient grant maps once per send, drops
  messages silently when sender lacks the required capability.
- POST /cli/mesh/:slug/grants to update from CLI; broker_messages_dropped_by_grant_total metric.
- CLI grant/revoke/block now mirror to broker via syncToBroker.

Auto-migrate on broker startup:
- apps/broker/src/migrate.ts runs drizzle migrate with pg_advisory_lock
  before the HTTP server binds. Exits non-zero on failure so Coolify
  healthcheck fails closed.
- Dockerfile copies packages/db/migrations into /app/migrations.
- postgres 3.4.5 added as direct broker dep.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Alejandro Gutiérrez
2026-04-15 08:44:52 +01:00
parent c9ede3d469
commit ee12510ef1
374 changed files with 14706 additions and 11307 deletions

View File

@@ -0,0 +1,35 @@
import { URLS } from "~/constants/urls.js";
import { TIMINGS } from "~/constants/timings.js";
import { isNewer } from "~/utils/semver.js";
export interface UpdateInfo {
current: string;
latest: string;
updateAvailable: boolean;
}
export async function checkForUpdate(currentVersion: string): Promise<UpdateInfo> {
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), TIMINGS.API_TIMEOUT_MS);
try {
const res = await fetch(URLS.NPM_REGISTRY, {
signal: controller.signal,
headers: { Accept: "application/vnd.npm.install-v1+json" },
});
if (!res.ok) return { current: currentVersion, latest: currentVersion, updateAvailable: false };
const data = (await res.json()) as { "dist-tags"?: { latest?: string } };
const latest = data["dist-tags"]?.latest ?? currentVersion;
return {
current: currentVersion,
latest,
updateAvailable: isNewer(currentVersion, latest),
};
} catch {
return { current: currentVersion, latest: currentVersion, updateAvailable: false };
} finally {
clearTimeout(timeout);
}
}

View File

@@ -0,0 +1,2 @@
export { checkForUpdate } from "./check.js";
export type { UpdateInfo } from "./check.js";

View File

@@ -0,0 +1 @@
export * from "./facade.js";