Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
---
name: Bug report
about: Something is broken in the OS, a Worker, or the site
title: ""
labels: bug
assignees: ""
---

## What happened

<!-- One or two sentences. Include the exact error text if there is one. -->

## Steps to reproduce

1.
2.
3.

## Expected

## Where

- [ ] `web/` (the OS in the tab)
- [ ] `workers/browser-session`
- [ ] `workers/computer`
- [ ] `shared/` (capability / limits contract)
- [ ] Hosted site (`https://computer.webmcp.com`)

## Environment

- Browser and version (Chrome 151+ with `--enable-features=WebMCP`, or ChatGPT's browser):
- OS:
- Commit / URL:
- Tool call involved (wire name, e.g. `cloud_exec`), if any:

## Evidence

<!-- `dmesg` output from the OS, Tool Monitor entries, console errors, screenshots.
Do NOT paste capability tokens, cookies, or secrets. -->
25 changes: 25 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
---
name: Feature request
about: Propose a new tool, app, or capability
title: ""
labels: enhancement
assignees: ""
---

## Problem

<!-- What can an agent or a human not do today? -->

## Proposal

<!-- If this adds or changes a tool: wire name (`snake_case`), invocation class
(ask / act / transact), input schema sketch, and what the human sees when it runs. -->

## Alternatives considered

## Scope

- [ ] `web/` only (runs in the tab, no paid resources)
- [ ] Needs a Worker change (`workers/browser-session` or `workers/computer`)
- [ ] Changes the shared contract (`shared/`), i.e. requires a coordinated redeploy
- [ ] Changes resource budgets or cost exposure
23 changes: 23 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
## What

<!-- One paragraph. Link the issue if there is one. -->

## Why

## How to verify

<!-- Commands or clicks a reviewer can repeat. -->

## Checklist

- [ ] Tests pass locally for every package I touched
(`cd web && bun test src server`, `cd workers/computer && bun test src`,
`cd workers/browser-session && bun test src`)
- [ ] Typecheck passes (`bunx tsc --noEmit` in each touched package)
- [ ] `cd web && bun run build` passes if `web/` changed
- [ ] New or changed tools use `snake_case` wire names and declare an invocation class
- [ ] Tests live beside the code they cover; focused modules use matching test files where practical
- [ ] No secrets, account IDs, tokens, or user data in the diff
- [ ] `shared/` changes: both Workers and the site are updated together and
`docs/OPERATIONS.md` / `docs/SELF_HOSTING.md` reflect new limits
- [ ] Docs updated (`README.md`, `docs/features/`, `docs/agent-skills/`) where behaviour changed
91 changes: 91 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
name: CI

on:
pull_request:
push:
branches: [main]

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

env:
BUN_VERSION: "1.3"

jobs:
web:
name: web (test, typecheck, build)
runs-on: ubuntu-latest
defaults:
run:
working-directory: web
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: ${{ env.BUN_VERSION }}
- name: Cache Bun
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-web-${{ hashFiles('web/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-web-
- run: bun install --frozen-lockfile
- name: Test
run: bun test src server
- name: Typecheck
run: bunx tsc --noEmit
- name: Build
run: bun run build

computer:
name: workers/computer (test, typecheck)
runs-on: ubuntu-latest
defaults:
run:
working-directory: workers/computer
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: ${{ env.BUN_VERSION }}
- name: Cache Bun
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-computer-${{ hashFiles('workers/computer/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-computer-
- run: bun install --frozen-lockfile
- name: Test
run: bun test src
- name: Typecheck
run: bunx tsc --noEmit

browser-session:
name: workers/browser-session (test, typecheck)
runs-on: ubuntu-latest
defaults:
run:
working-directory: workers/browser-session
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: ${{ env.BUN_VERSION }}
- name: Cache Bun
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-browser-session-${{ hashFiles('workers/browser-session/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-browser-session-
- run: bun install --frozen-lockfile
- name: Test
run: bun test src
- name: Typecheck
run: bunx tsc --noEmit
123 changes: 123 additions & 0 deletions .github/workflows/deploy-workers.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,123 @@
name: Deploy Workers

# Manual deploy of the Cloudflare Workers. The GitHub environment is named after the
# `environment` input, so protection rules (required reviewers, branch restrictions)
# configured on the `staging` / `production` environments apply automatically.
#
# Required environment secrets:
# CLOUDFLARE_API_TOKEN - Wrangler deploy token (Workers Scripts, Containers, R2,
# Durable Objects edit on the nekuda.ai account)
# CLOUDFLARE_ACCOUNT_ID - target Cloudflare account (keep it in each GitHub environment)
#
# Runtime secrets (GATEWAY_SIGNING_SECRET, CF_ACCOUNT_ID, BROWSER_RENDERING_API_TOKEN,
# PUBLIC_SITE_ORIGIN) are NOT set here. Set them once with `wrangler secret put`; see
# docs/OPERATIONS.md.

on:
workflow_dispatch:
inputs:
environment:
description: Target environment
type: choice
required: true
default: staging
options:
- staging
- production
worker:
description: Which Worker(s) to deploy
type: choice
required: true
default: both
options:
- both
- computer
- browser-session

concurrency:
group: deploy-${{ inputs.environment }}
cancel-in-progress: false

permissions:
contents: read

env:
BUN_VERSION: "1.3"
WRANGLER_VERSION: "4.128.0"
# Top-level config is production; `--env staging` selects the staging env block.
WRANGLER_ENV_FLAG: ${{ inputs.environment == 'staging' && '--env staging' || '' }}

jobs:
validate-ref:
name: Validate deployment ref
runs-on: ubuntu-latest
steps:
- name: Production deploys must use main
if: ${{ inputs.environment == 'production' && github.ref != 'refs/heads/main' }}
run: |
echo "Production deployments must be dispatched from main." >&2
exit 1

computer:
name: Deploy webmcp-computer-cloud (${{ inputs.environment }})
needs: validate-ref
if: ${{ inputs.worker == 'both' || inputs.worker == 'computer' }}
# ubuntu-latest ships Docker; the computer Worker builds workers/computer/Dockerfile
# at deploy time.
runs-on: ubuntu-latest
environment: ${{ inputs.environment }}
defaults:
run:
working-directory: workers/computer
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: ${{ env.BUN_VERSION }}
- name: Cache Bun
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-computer-${{ hashFiles('workers/computer/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-computer-
- run: bun install --frozen-lockfile
- name: Check (tests + typecheck)
run: bun run check
- name: Docker is available
run: docker version
- name: Deploy
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
run: bunx wrangler@${{ env.WRANGLER_VERSION }} deploy ${{ env.WRANGLER_ENV_FLAG }}

browser-session:
name: Deploy webmcp-computer-browser-session (${{ inputs.environment }})
needs: validate-ref
if: ${{ inputs.worker == 'both' || inputs.worker == 'browser-session' }}
runs-on: ubuntu-latest
environment: ${{ inputs.environment }}
defaults:
run:
working-directory: workers/browser-session
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: ${{ env.BUN_VERSION }}
- name: Cache Bun
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-browser-session-${{ hashFiles('workers/browser-session/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-browser-session-
- run: bun install --frozen-lockfile
- name: Check (tests + typecheck)
run: bun run check
- name: Deploy
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
run: bunx wrangler@${{ env.WRANGLER_VERSION }} deploy ${{ env.WRANGLER_ENV_FLAG }}
Loading
Loading