Skip to content

feat: harden anonymous production infrastructure - #3

Merged
ilayalog merged 17 commits into
mainfrom
feat/scale-readiness
Sep 4, 2026
Merged

ilayalog merged 17 commits into
mainfrom
feat/scale-readiness

Conversation

@ilayalog

@ilayalog ilayalog commented Sep 3, 2026 •

Copy link
Copy Markdown
Member

What

Prepare WebMCP Computer for anonymous production traffic: enforce browser/container budgets and idle reclamation, harden gateway and publishing boundaries, add per-workspace publish quotas, establish deployment/operations guidance, and add optional privacy-bounded usage analytics and replay.

Why

The hosted demo currently exposes cost-bearing, stateful infrastructure without production-scale accounting, cleanup, abuse backstops, or a repeatable staging-first cutover procedure.

How to verify

cd web && bun test src server && bunx tsc --noEmit && bun run build
cd workers/computer && bun test src && bunx tsc --noEmit
cd workers/browser-session && bun test src && bunx tsc --noEmit
cd web && bun run test:e2e

The private staging Site and both staging Workers were also exercised with live Browser Run, cloud execution/filesystem, isolated publishing, quota, and analytics checks.

Checklist

  • Tests pass locally for every package touched
  • Typecheck passes in every package
  • Production web build passes
  • New/changed tools use snake_case WebMCP fields and declare an invocation class
  • Tests live beside the code they cover
  • No secrets, account IDs, tokens, or user data are in the diff
  • Shared contracts are coordinated across the Site and Workers
  • Operations, self-hosting, feature, and seeded agent documentation are updated

Deployment coordination

The Site and both Workers must be deployed together. Deploy production Workers first, verify them, then update the production Site with matching Worker URLs and gateway secret. Preserve legacy resources during the publication-retention grace period.

…nd ops runbook

- Enforce rolling 24-hour resource budgets (2h remote browser, 2h container)
  with transparent server-side alarm multiplexing and structured error codes
  (EBUDGET, EIDLE, EOWNER, ECAPACITY).
- Implement server-side idle reclamation: remote Chrome closes after 5m of
  inactivity/tab concealment; containers stop 5m after last exec.
- Browser Worker: introduce BrowserLease Durable Object, serialize concurrent
  creates, retain and retry failed setup rollback, and rate-limit per IP and subject.
- Computer Worker: introduce RuntimeLease Durable Object, multiplex container alarms,
  cap single write and batch request sizes, and sandbox published site origins.
- Web client: introduce machine lock with take-over support, gate keyboard and tool
  access via inert container on inactive tabs, and stream activity heartbeats.
- CI/CD & Docs: add GitHub Actions workflows, issue/PR templates, CONTRIBUTING.md,
  SECURITY.md, docs/OPERATIONS.md, and updated self-hosting guides.
}

function json(request: Request, body: unknown, status = 200, headers: HeadersInit = {}): Response {
return new Response(JSON.stringify(body), {
@ilayalog
ilayalog force-pushed the feat/scale-readiness branch from 251a20b to 256e13b Compare September 3, 2026 23:54
@ilayalog ilayalog changed the title Add scale-readiness controls and operational hardening feat: harden anonymous production infrastructure Sep 4, 2026
@ilayalog
ilayalog merged commit 96d1bb5 into main Sep 4, 2026
5 checks passed
@ilayalog
ilayalog deleted the feat/scale-readiness branch September 4, 2026 02:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants