feat: P2 operator, preprocessing state/service, and runtime config lease

This commit is contained in:
2026-08-11 18:40:11 +02:00
parent ca391ba59c
commit f7c2b69837
10 changed files with 2501 additions and 31 deletions
+14 -19
View File
@@ -8,9 +8,8 @@ import { dirname, isAbsolute, join, relative, resolve } from "node:path";
import { parseAllDocuments } from "yaml";
import { clearPrincipalEnvironment, principalEnvironment, type PrincipalContext } from "../auth/principal.js";
import { secretValue, type SecretBundleConfig } from "../config/secret-bundle.js";
import { resolveRuntimeBindings } from "../workspaces/bindings.js";
import { renderWorkspaceRuntimeFromSnapshotPath } from "../workspaces/runtime-config-lease.js";
import {
renderRuntimeConfig,
type RuntimeInstallationOverlay,
type RuntimePaths,
type SemanticRuntimeConfig,
@@ -208,26 +207,22 @@ export class ThtRunner {
/** Render one immutable canonical registry revision into a backend-owned harness config. */
acquireWorkspaceRuntime(workspaceConfigPath: string): RuntimeConfigLease {
const canonical = this.readCanonicalWorkspaceSnapshot(workspaceConfigPath);
const bindings = resolveRuntimeBindings(
canonical.workspace,
process.env,
this.cfg.secretRoots ?? [],
);
const config = renderRuntimeConfig(
canonical.workspace,
bindings,
this.runtimePaths(canonical.workspaceId),
canonical,
this.installationOverlay(),
this.cfg.semanticRuntime,
);
const path = this.createRuntimeSnapshot(config);
const rendered = renderWorkspaceRuntimeFromSnapshotPath({
snapshotPath: workspaceConfigPath,
harnessDir: this.cfg.harnessDir,
configPath: this.cfg.configPath,
dataRoot: this.cfg.dataRoot ?? (() => {
throw new Error("registry workspace runtime requires an absolute data root");
})(),
secretRoots: this.cfg.secretRoots ?? [],
semanticRuntime: this.cfg.semanticRuntime,
});
const path = this.createRuntimeSnapshot(rendered.renderedConfig);
let released = false;
return {
path,
workspaceId: canonical.workspaceId,
workspaceRevision: canonical.workspaceRevision,
workspaceId: rendered.workspaceId,
workspaceRevision: rendered.workspaceRevision,
release: () => {
if (released) return;
released = true;