fix: harden workspace activation and snapshot retention

This commit is contained in:
2026-08-04 09:25:06 +02:00
parent 3b23cf3714
commit e4fdbed864
14 changed files with 474 additions and 103 deletions
+6
View File
@@ -227,6 +227,12 @@ The local listener is `127.0.0.1` only. The process is terminated in cleanup aft
probe, on timeout, or on failure. There is no accept-new mode, no disabled host-key checking, and
no persistent forwarding.
In this release, `ssh_tunnel` is therefore a diagnostic-only connector transport. A successful
probe is followed by `workspace_not_activatable`, and `POST /sessions` rejects the workspace before
persisting a manifest or starting Pi. Use direct PostgreSQL/pgvector or REST for runtime sessions
until the backend owns a tunnel for the full runtime lifecycle. This restriction does not apply to
using SSH as the transport for the workspace Git remote.
## Reader-only fallback
A workspace may be fully valid in Git but non-activatable locally when a required reader binding,