DreamLake

Queue mounts development note

Tracking: #274 and master #247.

2026-09-15 — Mount action scope deployed and verified

Staging PR #291 merged after all four CI jobs passed. Deployment 6aa9458fd917650008ac4265 serves source 5f18ef6. Production PR #293 merged after its own CI passed. Deployment 6aa947cb4eb7b600086c8c24 serves production source 9c739b3.

Real Chromium checks passed in both environments without API mocks. Queue mounts omit daemon enrollment controls and retain Jobs, Workers, Storage and the token editor. The editor keeps connection identity read-only and starts with a blank password field. The existing legacy connection retains its launch form; no enrollment token was generated. Both rendered views were inspected.

Each temporary mount and its Vault copies were removed. Separate readbacks confirmed mount 404, zero live fixture credentials and the original legacy connection still healthy. The published deployment stayed unchanged throughout the check. No jobs or workers were created.

Acceptance receipt. Ge review/testing and the new-connection flow in draft #275 remain separate. Both temporary mounts used the development Lakeshore namespace; these checks do not establish production worker execution.

2026-09-15 — Queue mount action scope

UI PR #280 removes the daemon enrollment form from queue mount pages. Mounted proxies deliberately reject enrollment-token operations. Legacy server connections keep their existing launch and revocation controls; mount token editing and resource tabs remain available. This does not decide the new-connection flow in draft #275.

PR #280 merged as f6de2dc after all four remote CI jobs passed on d4f8560: formatting, lockfile/typecheck/build, component tests and browser tests. Full local validation passed 1,479 component tests (five skipped) and 125 Chromium tests (17 skipped). Earlier billing failures remain in the CI history.

Staging deployment PR #291 uses the current production base, preserving the published Notes preview. Its first CI run found formatting errors in two preview files; 9571bf1 formats those files without changing behavior. All 13 affected component tests and the formatting check passed locally. An initial legacy redirect assertion failed during candidate validation; focused and full reruns passed without changing redirect behavior or assertions.

New-head CI, deployment and hosted mount/legacy control checks remain pending. Ge review and testing are unconfirmed.

2026-09-15 — Mount token editor deployed and verified

UI PR #277 merged as 38cd75e after all four CI checks passed. Staging deploy 6aa925f7349a320008908e45 and production deploy 6aa926a43695790008b74054 serve that source.

Real Chromium checks passed in both environments without API mocks. Connection identity is read-only and the token is hidden and required. A rejected replacement leaves the mount healthy; retrying with Enter sends only the token. Reopening clears the token, and the subsequent mount identity probe succeeds. Both rendered dialogs were inspected.

Each run used its own temporary mount connected to the existing development Lakeshore queues-dev namespace. Independent readbacks confirmed mount 404, zero live fixture Vault entries and a healthy original development mount. No jobs or workers were created.

Deployment and cleanup receipt. This verifies existing-mount editing. New connection creation remains in draft UI PR #275; production worker execution and Ge review/testing remain separate.

2026-09-15 — Existing mount token editor

UI PR #277, under #518, adds a token replacement dialog for existing Vault-backed mounts. The mount prefix, server and namespace are read-only. Saving sends only the replacement token; the returned identity and healthy state must match before the dialog closes. Changing the namespace or selected mount clears the token and ignores pending results from the previous selection.

Local typecheck, 1,476 tests (five skipped) and the production build passed. Twelve focused tests cover request handling, response identity, namespace changes and the existing host-enrollment creation flow. At source 559c1f7, all nine local Lakeshore Chromium tests pass. The editor test covers token-only PATCH, rejected-write retry using Enter and an empty token when reopened. Browser testing found that the shared dialog actions were spans; this dialog now uses native buttons. The rendered dialog was inspected.

An initial legacy client redirect test failed. Both redirect cases then passed five repetitions each and the full nine-test suite, without changing redirect code or assertions. The initial intermittent failure remains recorded in PR validation. These browser tests use mocked APIs. Remote formatting, component tests, typecheck and build passed; the broader E2E job is pending.

New connection creation remains in draft PR #275, pending the host-enrollment and queue-mount flow decision. This editor is not yet merged or deployed. Hosted browser acceptance and Ge review/testing remain open.

2026-09-15 — Production API and CLI acceptance

Production task 119 serves source 95ba146d; the running image digest matched ECR after deployment completed and task 118 drained. The existing rollout owner performed this deployment; acceptance did not change runtime settings.

The production DreamLake API mounted the existing development Lakeshore queues-dev namespace under a unique temporary prefix. Mount identity, queue/job/worker reads, empty-queue creation, drain/archive/unarchive, statistics, JSON events, rejected enrollment proxying and token replacement passed. An invalid replacement left the mount healthy. CLI 0.21.1 bytes matched the verified public release and passed queue, job and worker reads against this production mount.

Cleanup deleted the owned queue and mount and retired both new Vault copies. Independent readbacks confirmed mount 404, queue 404 through the original development connection, zero live fixture credentials and a healthy original mount. No jobs were submitted, workers attached or original token revoked.

Acceptance receipt · Deployment. This verifies the production DreamLake mount boundary against a development Lakeshore endpoint. Production worker execution, dashboard/browser acceptance and Ge review/testing remain separate.

2026-09-15 — CLI 0.21.1 released

CLI 0.21.1 combines queue-mount commands with the Vault uncertain-write transport fix. All eight public native and npm platform binaries match the release manifest; the npm wrapper matches reviewed source. Native and npm latest both read back as 0.21.1 after guarded promotion. Existing installers and other npm tags were preserved.

A fresh npm installation with scripts disabled passed checksum/version checks, all 34 SSH/import HTTP/PTY checks and detached HTTP mount/list checks. The public native macOS binary also passed queue, job and worker reads through the existing development mount. These reads made no mutations; temporary installations were removed. They do not establish production mutation or browser acceptance.

CLI docs and the 0.21.1 snapshot are published. Each deployment passed 48 served-file comparisons against the reviewed build, preserving all 38 previous HTML routes and the newer Vault notes.

Release receipt · Docs publication. Production mount/browser acceptance and Ge review/testing remain open.

2026-09-15 — Staging deployment and API acceptance

Staging task 168 runs reviewed source 24215a76. The running image digest matches ECR, and deployment attempt 2 completed after the preceding Vault canary settled. The identical source tree passed full CI. Vault remains enabled; private runs and KMS migration remain disabled.

Real staging checks passed for mount creation and identity, queue/job/worker reads, an owned FIFO queue's drain/archive/unarchive controls, statistics and JSON events. An enrollment proxy request was denied. Invalid token replacement left the healthy mount unchanged; valid replacement and identity recheck passed.

Independent cleanup confirmed the queue and mount return 404, both newly stored Vault copies are retired, and the existing staging connection remains. No jobs were submitted or workers attached. The original development token was not revoked or changed.

At this staging checkpoint, the CLI candidate had passed native development reads and a local npm installation rehearsal; the later 0.21.1 release is recorded above. Production, dashboard browser acceptance and Ge review/testing remain open. The dashboard form stays draft under #518 pending the host-enrollment versus queue-mount flow decision.

Staging receipt · Deployment · Recorded checks

2026-09-15 — Dashboard mount editing contract

Issue #518 tracks the dashboard connection form. Connection responses now identify connectionType as mount or legacy, without returning credential references. The UI can keep mounted identities immutable and replace only their access token.

The paired UI work switches creation to the Vault-backed mount endpoint, requires a hidden namespace access token, and refuses credential-request redirects and upstream error-body rendering. Implementation and UI verification are tracked in #518; no deployment or browser acceptance is claimed here.

Backend TypeScript and 99 mount tests pass, including serialized mount/legacy responses and credential-field exclusion.

The branch incorporates main 70b594db, retaining the private-run capability notes and multi-provider KMS routing. TypeScript and 103 mount/KMS-router tests pass on the combined tree. Full CI passed on the pre-reconciliation metadata head; the combined head requires a fresh full CI result.

2026-09-15 — Queue monitoring through mounts

Mounts permit the existing queue stats and paginated events JSON reads used by the dashboard. Query parameters are forwarded unchanged. The mapped namespace, read permission, response-size limit and request timeout still apply; write and streaming variants are denied.

Both HTTP regressions fail with 403 on parent c42ef2d2. The correction passes 98 mount tests and server TypeScript, including filter forwarding and denial before credential retrieval. The policy tests now distinguish these JSON reads from unsupported streaming paths. No deployment or live dashboard acceptance is claimed.

2026-09-15 — Reconcile Vault runtime consumers

The mount branch now incorporates main 8b9aaf8d. Startup obtains one Vault runtime and initializes both queue-mount credentials and private-run services from it. Private repository origins and both sets of release notes are retained.

The combined Prisma client generates successfully; server TypeScript and all 94 mount tests pass. Full CI and parent review remain required. This reconciliation does not deploy or enable either capability on a live server.

2026-09-15 — Invalid upstream responses mark mounts unhealthy

A successful HTTP response with invalid JSON now records a mount error and check time before returning 502. The stored error excludes upstream response contents. An explicit successful identity recheck clears the error.

The regression failed on parent 06904131: the proxy returned 502 while the mount retained status: ok. All 94 mount tests and server TypeScript now pass. This correction targets backend draft #469. Deployment and live dashboard acceptance remain pending.

2026-09-15 — Bulk queued cancellation through a mount

The mount allowlist now permits the existing namespace-scoped POST /v1/namespaces/:namespace/invocations/bulk-cancel operation. Its optional queue filter is forwarded unchanged. The control plane selects queued, unassigned invocations; this route does not cancel running jobs.

On parent f87494a8, the new policy and HTTP-route regressions failed because an authorized request returned 403. The correction passed all 93 mount transport, route and credential tests, including the queue-filter response, cross-namespace denial and permission denial before credential retrieval or forwarding.

This is a follow-up to draft backend #469, paired with CLI #69. No development or production deployment is claimed by these tests. Live queued-job cancellation, dashboard verification and Ge testing remain open.

2026-09-14 — SSH development loop ready

The first slice now runs on dreamlake-dev in Kubernetes namespace dreamlake-queues-dev, with dedicated MongoDB/Redis and an AWS KMS development key. A source mount and tsx watch allow ./scripts/queues-dev sync to reload working-tree changes over SSH. The wrapper runs the built CLI against a private SSH tunnel and a separate dev login, preserving the user's production login.

Live acceptance passed: mount lab, identity check, queue/job/worker reads, source reload, and rechecking the persisted mount after restart. The test remote namespace contains its default queue and no jobs/workers. The dev login has a 24-hour lifetime and ./scripts/queues-dev login renews it. Six wrapper tests and a fresh isolated-Mongo bootstrap check passed; server TypeScript passed.

Run ./scripts/queues-dev cli queues list lab in the configured checkout to start testing now. See infra/queues-dev/README.md for setup, Kubernetes manifests, managed-key inventory and boundaries. This is a live development deployment; production deployment, published CLI release and dashboard browser verification remain pending. The former Docker-only bootstrap database/cache containers were removed after moving both services into Kubernetes.

2026-09-14 — first implementation, unreleased

The CLI now implements dreamlake queues mount --uri <https-origin> --prefix lab. It shows the DreamLake environment and namespace, asks for the remote Lakeshore namespace, and takes a hidden access-token prompt or --token-stdin. It never imports a local Lakeshore login or uses LAKESHORE_ADMIN_TOKEN implicitly.

The new POST /namespaces/:slug/lakeshores/mount route reuses the existing Lakeshore registration and DreamLake permissions. It validates the access token through /whoami without listing or creating queues, then stores the token in Vault and saves only the immutable Vault entry ID/name on the registration. The proxy resolves that reference for each request and checks owner liveness, retirement, expiry, and entry identity. Admin and open-mode tokens are rejected.

The CLI can list mounts, inspect the connection, list queues/jobs/workers, replace a token, and unmount. The new proxy is restricted to the mapped remote namespace and supported queue, invocation, and worker paths. It uses public HTTPS origins, DNS-pinned address checks, no redirect following, and bounded JSON responses. Failed credentials and unavailable servers are reported as errors. Existing legacy registrations keep their current behavior.

  1. Mount after deploying both changes. Run dreamlake queues mount --uri "$LAKESHORE_URL" --prefix lab --lakeshore-namespace default. Enter a Lakeshore access token, not the server admin token.
  2. Inspect the server. Run dreamlake queues inspect lab, then dreamlake queues list lab, dreamlake queues jobs lab, and dreamlake queues workers lab.
  3. Replace or disconnect. Run dreamlake queues token lab to verify and save a replacement, or dreamlake queues unmount lab to remove the registration. Unmounting does not stop Lakeshore, revoke its token, or delete Vault entries. An unmounted prefix can be mounted again.

Validation: 91 focused server tests passed, covering Vault identity/liveness, network/path constraints, mounting, rechecking, rotation, unmount/remount, error redaction, and namespace/permission failures. All 12 existing Lakeshore route regression tests passed against an isolated temporary Mongo replica set. Server TypeScript passed. CLI validation is recorded in the companion PR.

Run ./scripts/test-queues-mount.sh /path/to/dreamlake-cli-checkout for the focused server/CLI checks without live credentials. Install each package's frozen lockfile first. The optional Prisma fields require regenerating the client; there is no new database index or backfill.

Remaining release work: review/merge both PRs, deploy the backend with Vault configured, release/install the CLI, and verify the real mount in the dashboard. No production configuration, token, namespace, or mount was changed by these tests.

First-version limits: personal DreamLake namespaces only (current Vault scope), public HTTPS Lakeshore endpoints, and bounded JSON reads; streaming logs and provider administration are outside this slice. A mount prefix names resources; it does not narrow Lakeshore's token permissions or same-organization list aggregation. Vault entries left by replacement, disconnect, or failed persistence are retained for explicit owner cleanup. No new worker or queue engine is needed.

Python API: dreamlake-lakeshore.