Files
clawmates/migrations/0016_terminal_ws_tickets.sql
T
Omar SobhandClaude Opus 4.8 e9ce368ec1 Scaling Phase 1: multi-tenant onboarding + replica-safe coordination
Decouples "many users" + "many server replicas" from "many machines" so the
platform is tenant-isolated and horizontally safe on the current single node.

- Per-signup workspaces (cm-auth): a new hosted-identity sign-in provisions and
  owns its own workspace instead of joining the first. Config-gated by
  auth.per_signup_workspace (default off); concurrent first-logins serialized by
  a per-subject advisory lock so no duplicate workspaces.
- Terminal tickets in Postgres (migration 0016, hashed, single-use): any replica
  can redeem a ticket minted by another. Drops the in-process ticket map.
- Container registry in Postgres (migration 0017, agent_containers): Terminal
  and Sandbox managers resolve an agent's container through a shared registry,
  so a 2nd replica reuses it instead of spawning a duplicate. node_id recorded
  as 'local' (Phase 2 hook). Boot reconcile removes only true orphans, so
  terminals now survive a redeploy (tmux sessions resume).
- Per-workspace quotas (cm-api/quota.rs): plan-tier caps on agents + live
  containers, enforced at agent create + terminal spin-up (reconnects allowed),
  returned as HTTP 402. New GET /api/quota surfaces usage vs limits.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-23 18:24:51 -07:00

13 lines
630 B
SQL

-- Short-lived single-use terminal-WS tickets, stored hashed in Postgres so any
-- server replica (not just the one that minted it) can redeem the handshake.
-- Replaces the former in-process ticket map. Rows are deleted on redeem and
-- swept on expiry.
CREATE TABLE terminal_ws_tickets (
token_hash TEXT PRIMARY KEY,
agent_id UUID NOT NULL REFERENCES agents (id) ON DELETE CASCADE,
workspace_id UUID NOT NULL REFERENCES workspaces (id) ON DELETE CASCADE,
label TEXT NOT NULL,
expires_at TIMESTAMPTZ NOT NULL
);
CREATE INDEX terminal_ws_tickets_expires_idx ON terminal_ws_tickets (expires_at);