feat(sandbox): run new production sessions on E2B - #73
Merged
Merged
Conversation
Set SANDBOX_PROVIDER = "e2b" in wrangler.toml. The CI deploy now publishes this commit's E2B template and pins the Worker to it before deploying. Existing sessions keep the provider they started on; setting "cloudflare" again rolls new sessions back.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Switches production to the E2B sandbox provider added in #72.
What changes
packages/worker/wrangler.toml:SANDBOX_PROVIDER = "e2b".e2b-templateCI job builds this commit's sandbox image, pushes it to GHCR, and publishes it as the E2B template tagged with the commit SHA. Thedeployjob then ships the Worker pinned toE2B_TEMPLATE_ID = "codevil-sandbox:<sha>". A failed publish stops the deploy.Prerequisites (done)
E2B_API_KEYGitHub Actions secret in theproductionenvironment.E2B_API_KEYWorker secret.First E2B deploy is also the first live check of
GITHUB_TOKEN.defaulttag alongside the SHA tag.Sandbox.create("codevil-sandbox:<sha>")resolving the tagged build.If any fails, the publish job fails and the Worker is not deployed.
After deploy: manual check on production
npm installcomplete.max_idle_time: 2m, leave it idle; it pauses in the E2B dashboard.Rollback: set
SANDBOX_PROVIDER = "cloudflare"and merge. Keep theE2B_API_KEYsecret while any E2B sessions exist.Verification
pnpm verifypasses locally (typecheck + all package tests, 0 failures).🤖 Generated with Claude Code