Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
144 commits
Select commit Hold shift + click to select a range
1205237
feat(settings): manage Codex session prewarm from the dashboard (#2264)
Soju06 Sep 9, 2026
efe0f58
feat(settings): manage stream and bridge request budgets from the das…
Soju06 Sep 9, 2026
f1ff7c7
feat(settings): per-model context window overrides in the dashboard (…
Soju06 Sep 9, 2026
069b82b
feat(settings): pause background schedulers from the dashboard (#2281)
Soju06 Sep 9, 2026
39e5f44
feat(settings): conversation archive toggle in the dashboard (#2275)
Soju06 Sep 9, 2026
ef1af87
docs(openspec): archive the round-3 settings changes (#2293)
Soju06 Sep 9, 2026
81b9fbd
fix(load-balancer): keep soft sticky owner when it is only request-lo…
Soju06 Sep 10, 2026
a408b57
perf(dashboard): bound the raw tail of the conversation presence unio…
Soju06 Sep 10, 2026
95a9cab
feat(proxy): trace terminal-frame delivery on Responses SSE streams (…
Soju06 Sep 10, 2026
984ba4a
refactor(egress): route direct usage GETs through native helper (#2263)
Soju06 Sep 10, 2026
66a3e70
feat(proxy): subscription-exhaustion overflow to a designated model s…
Soju06 Sep 10, 2026
913c6eb
perf(dashboard): memoize weekly demand delta aggregates with a short …
Soju06 Sep 10, 2026
cb24e90
test(oauth): control callback expiry deadline in integration test (#2…
JustYannicc Sep 10, 2026
be7dc02
test(shutdown): synchronize preStop response completion (#2283)
JustYannicc Sep 10, 2026
8e6e260
perf(request-logs): speed up SQLite filter options (#2253)
JustYannicc Sep 10, 2026
44c635b
perf(request-logs): add live-row partial indexes for facet option que…
Soju06 Sep 10, 2026
dda902d
feat(load-balancer): discount relatively slow accounts (first-token l…
Soju06 Sep 10, 2026
b383d09
docs: add codex-lb-status community companion (#2116)
VictorStatko Sep 10, 2026
a7785a8
fix(warmup): warm unused Free quota once (#2205)
HulianBuligon Sep 10, 2026
7887ef1
docs(companions): add Codex LB for Omarchy (#2172)
janaki-sasidhar Sep 10, 2026
d2b2e77
fix(db): preserve rollback after SQLite invalidation (#2193)
NikitaMGrimm Sep 10, 2026
1a412c7
test(request-logs): control live facet indexes in both layouts (#2296)
Soju06 Sep 10, 2026
ab0daae
chore(deps): upgrade Vitest runner and coverage to 5 together (#2159)
dependabot[bot] Sep 10, 2026
f85a558
chore(deps): bump httpx2 from 2.10.0 to 2.12.0 (#2206)
dependabot[bot] Sep 10, 2026
1622227
test(spec): model ownership and timeout invariants with TLC controls …
Komzpa Sep 10, 2026
43a45f7
refactor(egress): interpret WebSocket routing metadata in Rust
Soju06 Sep 10, 2026
7559861
chore(docker): bump astral-sh/uv from 0.12.10 to 0.12.12 (#2299)
dependabot[bot] Sep 10, 2026
2554fdd
feat(metadata): automate pricing and Codex version updates with cost …
Soju06 Sep 10, 2026
f58c06e
chore(deps): bump frontend minor dependencies
dependabot[bot] Sep 10, 2026
5be82ef
fix(proxy): sanitize rebuilt HTTP hop-by-hop headers
elmakus Sep 10, 2026
68dfc0e
fix(ui): constrain model source dialogs to viewport (#2059)
evaldass Sep 10, 2026
0f6a31c
fix(ui): offer the reactivate action for deactivated accounts (#2060)
evaldass Sep 10, 2026
c858dcc
chore: release v1.25.0-beta.7 (#2249)
Soju06 Sep 10, 2026
07f42aa
chore(helm): drop the pre-1.13 StatefulSet migration shim (#2333)
Soju06 Sep 10, 2026
3b4222a
refactor(bridge): resolve admission and reconnect settings before the…
Soju06 Sep 10, 2026
1f34281
fix(db): retry the startup sentinel seed on SQLite lock contention an…
Soju06 Sep 10, 2026
c52941a
perf(bridge): resolve the prewarm snapshot only for eligible payloads…
Soju06 Sep 10, 2026
aae61f6
refactor(bridge): keep fail-closed ambiguous-continuation handling an…
Soju06 Sep 10, 2026
6d11e56
feat(settings): manage the bridge operation spool retention from the …
Soju06 Sep 10, 2026
9559603
feat(auth)!: add resource-scoped dashboard permission vocabulary (#2196)
Soju06 Sep 10, 2026
d6a7ca6
feat(auth): restrict guest-visible sensitive surfaces and make guest …
Soju06 Sep 10, 2026
478e960
feat(dashboard): hide restricted surfaces from read-only guests (#2203)
Soju06 Sep 10, 2026
e040053
feat(auth): reject cross-site dashboard mutations and start the clien…
Soju06 Sep 10, 2026
08f9634
feat(auth): add dashboard role rows with code-defined preset grants (…
Soju06 Sep 10, 2026
195b33b
feat(auth): add dashboard user tables and migrate the shared admin in…
Soju06 Sep 10, 2026
9cfce7f
feat(auth): make dashboard users the source of truth for login and se…
Soju06 Sep 10, 2026
8e57607
feat(audit): record the acting account, target and severity on audit …
Soju06 Sep 10, 2026
561311d
feat(users): add account management, invite links and the roles read …
Soju06 Sep 10, 2026
04a309d
feat(frontend): tier the login form and header by account facts, add …
Soju06 Sep 10, 2026
53253c1
feat(frontend): fold the auth cards into one Access card that grows w…
Soju06 Sep 10, 2026
aa75e1c
feat(auth): enable the operator and viewer presets end to end, requir…
Soju06 Sep 10, 2026
94fb4d0
feat(auth): resolve trusted-header identities to accounts through sig…
Soju06 Sep 11, 2026
c9d5443
feat(auth): re-verify a credential before sensitive dashboard changes…
Soju06 Sep 11, 2026
4096c18
feat(auth): map identity-provider groups to roles and add the organis…
Soju06 Sep 11, 2026
9368d49
fix(overflow): keep a delivered source turn anchored before the first…
Soju06 Sep 11, 2026
789a2dd
docs(openspec): archive the landed campaign changes and repair one st…
Soju06 Sep 11, 2026
21eedbf
feat(dashboard): surface subscription-overflow attribution in the req…
Soju06 Sep 11, 2026
e32f85c
feat(proxy): persist hashed affinity decisions on request logs (#2352)
JustYannicc Sep 11, 2026
6b3d031
fix(proxy): retire a denied proxy-injected WebSocket anchor instead o…
Abaddollyon Sep 11, 2026
92c7f62
fix(images): select compatible host for images and probes (#2320)
JustYannicc Sep 11, 2026
98d2256
fix(http-bridge): reuse reservation during local recovery (#2353)
Komzpa Sep 11, 2026
09b8e89
fix(proxy): bound aggregate detached retirement lock waits (#2315)
JustYannicc Sep 11, 2026
ab372cd
test: stub ambient account deletion scheduler (#2342)
JustYannicc Sep 11, 2026
53f9687
fix(db): merge the pin-index and affinity alembic heads (#2368)
Soju06 Sep 11, 2026
7f79297
fix(balancer): count bare server_error terminals toward overload back…
Soju06 Sep 11, 2026
976d20b
fix(proxy): route anonymous output frames to the created response (#2…
mjakl Sep 11, 2026
e715165
refactor(db): route every SQLite lock check through the shared predic…
Soju06 Sep 11, 2026
53a198d
refactor(bridge): retire the durable recovery-dispatch storage surfac…
Soju06 Sep 11, 2026
bb400e9
refactor(config): constantize the token refresh interval (#2365)
Soju06 Sep 11, 2026
c62bdd8
fix(accounts): let the deletion scheduler exit its wait promptly (#2362)
Soju06 Sep 11, 2026
e24b57c
refactor(db): give the lock report one owner and state the driver-evi…
Soju06 Sep 11, 2026
a096b60
revert(bridge): restore the recovery-dispatch claim and its fence (#2…
Soju06 Sep 11, 2026
9db05a1
fix(proxy): fork model-transition owner conflicts (#2083)
Komzpa Sep 11, 2026
cb21daa
fix(proxy): narrow the input-image upstream transport pin (#2386)
Soju06 Sep 11, 2026
b04b278
fix(proxy): deliver the denied-anchor refusal to native clients (#2387)
Soju06 Sep 11, 2026
2c85399
fix(balancer): stop waiting on a hard affinity owner the caller exclu…
Soju06 Sep 11, 2026
065842e
chore(dashboard): keep the request-log source literals in sync with t…
Soju06 Sep 11, 2026
3d90273
fix(http-bridge): bound terminal spool writes (#1997)
choi138 Sep 11, 2026
42c8526
chore(ci): fail migration authoring when the revision graph forks (#2…
Soju06 Sep 11, 2026
1330855
feat(auth): gate local password sign-in behind a policy and protect b…
Soju06 Sep 11, 2026
cc25f27
fix(observability): derive sticky_key_source once, from the resolved …
Soju06 Sep 12, 2026
ef70105
fix(proxy): anchor unanchored HTTP threads to a stable cache key (#2367)
Soju06 Sep 12, 2026
b36e5a0
feat(dashboard): surface thread identity and cache locality metrics (…
Soju06 Sep 12, 2026
8256755
feat(dashboard): add a cross-account prompt cache isolation probe (#2…
Soju06 Sep 12, 2026
f32a7d6
ci(openspec): strictly validate changed active folders (#2306)
JustYannicc Sep 12, 2026
63314a1
fix(proxy): attribute refused cross-account continuity replays (#2384)
Soju06 Sep 12, 2026
ec79c2b
test(dashboard): make the clean-install overflow statement count dete…
Soju06 Sep 12, 2026
800c965
chore(overflow): discover the request-log source constants in the spe…
Soju06 Sep 12, 2026
10cd71a
fix(proxy): retire durably unroutable bridge continuity owners (#2390)
Soju06 Sep 12, 2026
883c914
feat(proxy): add shared/isolated thread cache identity modes (default…
Soju06 Sep 12, 2026
2852cf6
fix(proxy): retire a continuity owner that cannot return in time (#2397)
Soju06 Sep 12, 2026
d28b3ad
fix(db): converge the forked thread-cache and bridge-retirement heads…
Soju06 Sep 12, 2026
bb4db9d
chore: release v1.25.0-beta.8 (#2341)
Soju06 Sep 12, 2026
24d2226
test(overflow): add the pre-flip canary drill suite (#2399)
Soju06 Sep 12, 2026
b5dc5ff
chore(traffic): capture and sanitise real Codex bodies for parity fix…
Soju06 Sep 12, 2026
0a43bea
refactor(auth): retire the legacy dashboard credential mirror (#2402)
Soju06 Sep 12, 2026
e54d974
fix(balancer): retain warm soft sticky owners through overload isolat…
Soju06 Sep 13, 2026
3d501ac
fix(accounts): recover a rate-limited account on any confirmed window…
Soju06 Sep 13, 2026
2a24140
fix(docker): update installed Debian runtime packages (#2407)
dpearson2699 Sep 13, 2026
837964b
feat(auth): add an OIDC identity provider with UI-configured, encrypt…
Soju06 Sep 13, 2026
982125a
revert(overflow): remove the subscription-exhaustion model-source fal…
Soju06 Sep 14, 2026
69f128a
chore: release v1.25.0-beta.9 (#2412)
Soju06 Sep 14, 2026
ca243de
feat(auth): connect company sign-in from Organisation settings (#2417)
Soju06 Sep 14, 2026
f94dd50
fix(utils): consume a shared future's exception when no waiter is lef…
Soju06 Sep 14, 2026
821189b
chore(metadata): refresh model pricing and Codex version (#2414)
Soju06 Sep 14, 2026
bb98cdf
fix(clients): reuse system trust for Python WSS (#2110)
dpearson2699 Sep 14, 2026
b28d9af
fix(proxy): keep safety policy blocks account-neutral (#2131)
msmahdinejad Sep 14, 2026
d1fd2f2
fix(proxy): publish HTTP response owners before delivery (#2111)
dpearson2699 Sep 14, 2026
bbcd12b
chore(metadata): refresh model pricing and Codex version (#2441)
Soju06 Sep 18, 2026
0731b61
chore(ci): bump DeterminateSystems/nix-installer-action from 22 to 23…
dependabot[bot] Sep 18, 2026
aad7e0c
chore(ci): bump github/codeql-action/upload-sarif from 4.37.9 to 4.38…
dependabot[bot] Sep 18, 2026
95f6dd6
chore(deps): bump the frontend-minor-patch group (#2435)
dependabot[bot] Sep 18, 2026
edf1f35
chore(docker): bump astral-sh/uv from 0.12.12 to 0.12.13 (#2434)
dependabot[bot] Sep 18, 2026
947c8f6
chore(docker): bump pgautoupgrade/pgautoupgrade (#2432)
dependabot[bot] Sep 18, 2026
ff6f6a1
refactor(proxy): skip unused HTTP preparation serialization (#2113)
dpearson2699 Sep 18, 2026
986a9bf
fix(ci): unbreak main — rustls advisory, missing contributor, stale b…
Soju06 Sep 18, 2026
8eeaad9
docs(companions): add Codex-LB Rates (#2346)
uniskela Sep 18, 2026
74dddf2
fix(test): follow the rustls and aws-lc-rs pins bumped in #2453 (#2454)
Soju06 Sep 18, 2026
2c358ee
ci: classify contributor PRs and newly opened issues additively (#2316)
JustYannicc Sep 18, 2026
1d4ad21
feat(auth): provision and deprovision accounts over SCIM 2.0 (#2431)
Soju06 Sep 18, 2026
9637bde
chore(db): drop the withdrawn subscription-overflow schema (#2422)
Soju06 Sep 18, 2026
143e07d
fix(proxy): read the usage-limit rejection off the frame upstream act…
Soju06 Sep 21, 2026
5918362
docs(openspec): propose walking the account pool before surfacing a 4…
Soju06 Sep 21, 2026
3d23d53
docs(openspec): propose relocating anchored turns across accounts (#2…
Soju06 Sep 21, 2026
09a140f
fix(db): converge the SCIM token and subscription-overflow heads (#2461)
Soju06 Sep 24, 2026
c6c1688
fix(test): settle the viewport before measuring and tolerate drain po…
Soju06 Sep 28, 2026
4183216
fix(ci): run the backend suite on native packaging changes (#2494)
Soju06 Sep 28, 2026
4dcf8f7
chore(metadata): refresh model pricing and Codex version (#2459)
Soju06 Sep 28, 2026
3c4906e
chore(ci): bump docker/setup-qemu-action from 4.3.0 to 4.4.0 (#2479)
dependabot[bot] Sep 28, 2026
52b9a0d
chore(ci): bump docker/build-push-action from 7.3.0 to 7.4.0 (#2481)
dependabot[bot] Sep 28, 2026
2913f4d
chore(ci): bump github/codeql-action/upload-sarif from 4.38.0 to 4.38…
dependabot[bot] Sep 28, 2026
bd65477
chore(docker): bump astral-sh/uv from 0.12.13 to 0.12.19 (#2476)
dependabot[bot] Sep 28, 2026
ec99459
fix(accounts): preserve quota chart samples and account display state…
NikitaMGrimm Sep 28, 2026
a3aa8ca
fix(quota): validate planner timezones and tolerate legacy keys (#2468)
mastertyko Sep 28, 2026
6b10052
fix(proxy): preserve routed file failover provenance (#2469)
mastertyko Sep 28, 2026
70effa3
perf(usage): cap SQLite bulk usage history reads per account (#2484)
lkraider Sep 28, 2026
3b75bb2
fix(shutdown): deny WebSocket upgrades during drain with 503 instead …
Abaddollyon Sep 28, 2026
da70ac5
fix(accounts): require spendable credits for quota override (#2119)
Komzpa Sep 28, 2026
cd9b408
chore(db): add advisory migration benchmark (#2329)
JustYannicc Sep 28, 2026
73f5f03
fix(proxy): send a single Content-Type on codex control requests (#2513)
Soju06 Sep 28, 2026
4725a10
fix(dashboard-users): take the owner row before the owned-key cascade…
Soju06 Sep 28, 2026
e8cdb34
chore(ci): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 (#2480)
dependabot[bot] Sep 28, 2026
bcf0a96
chore(ci): bump astral-sh/setup-uv from 10.0.1 to 10.2.0 (#2433)
dependabot[bot] Sep 28, 2026
f8ffbac
fix(accounts): omit unsupported field from force probe (#2496)
tubededentifrice-dev Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
96 changes: 96 additions & 0 deletions .all-contributorsrc
Original file line number Diff line number Diff line change
Expand Up @@ -1264,6 +1264,17 @@
"test"
]
},
{
"login": "NikitaMGrimm",
"name": "Nikita Maximilian Grimm",
"avatar_url": "https://avatars.githubusercontent.com/u/65914808?v=4",
"profile": "https://github.com/NikitaMGrimm",
"contributions": [
"code",
"doc",
"test"
]
},
{
"login": "BrenticusMaximus",
"name": "BrenticusMaximus",
Expand Down Expand Up @@ -1436,6 +1447,91 @@
"test",
"doc"
]
},
{
"login": "VictorStatko",
"name": "Victor Statko",
"avatar_url": "https://avatars.githubusercontent.com/u/34319599?v=4",
"profile": "https://github.com/VictorStatko",
"contributions": [
"doc"
]
},
{
"login": "janaki-sasidhar",
"name": "flameboy",
"avatar_url": "https://avatars.githubusercontent.com/u/42799643?v=4",
"profile": "https://github.com/janaki-sasidhar",
"contributions": [
"doc"
]
},
{
"login": "elmakus",
"name": "elmakus",
"avatar_url": "https://avatars.githubusercontent.com/u/76910687?v=4",
"profile": "https://github.com/elmakus",
"contributions": [
"code",
"test",
"bug"
]
},
{
"login": "Abaddollyon",
"name": "Abaddollyon",
"avatar_url": "https://avatars.githubusercontent.com/u/31712865?v=4",
"profile": "https://github.com/Abaddollyon",
"contributions": [
"code",
"test"
]
},
{
"login": "mjakl",
"name": "Markus Jakl",
"avatar_url": "https://avatars.githubusercontent.com/u/40384?v=4",
"profile": "https://github.com/mjakl",
"contributions": [
"code",
"test",
"bug"
]
},
{
"login": "felixcake618",
"name": "Felix Cake",
"avatar_url": "https://avatars.githubusercontent.com/u/91266981?v=4",
"profile": "https://github.com/felixcake618",
"contributions": [
"code"
]
},
{
"login": "uniskela",
"name": "Uniskela",
"avatar_url": "https://avatars.githubusercontent.com/u/104075208?v=4",
"profile": "https://github.com/uniskela",
"contributions": [
"doc" ]
},
{
"login": "nhdong1993",
"name": "nhdong1993",
"avatar_url": "https://avatars.githubusercontent.com/u/86702790?v=4",
"profile": "https://github.com/nhdong1993",
"contributions": [
"code"
]
},
{
"login": "tubededentifrice-dev",
"name": "Vincent Dev",
"avatar_url": "https://avatars.githubusercontent.com/u/246649517?v=4",
"profile": "https://github.com/tubededentifrice-dev",
"contributions": [
"code"
]
}
],
"contributorsPerLine": 7,
Expand Down
1 change: 1 addition & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@
# https://soju06.github.io/codex-lb/authentication/
# CODEX_LB_DASHBOARD_AUTH_MODE=standard
# CODEX_LB_DASHBOARD_AUTH_PROXY_HEADER=Remote-User
# CODEX_LB_DASHBOARD_AUTH_PROXY_GROUPS_HEADER=Remote-Groups

# Behind a reverse proxy? Trust X-Forwarded-For from these sources only:
# https://soju06.github.io/codex-lb/deployment/remote/
Expand Down
4 changes: 4 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,10 @@ updates:
day: "monday"
open-pull-requests-limit: 10
groups:
vitest:
patterns:
- "vitest"
- "@vitest/*"
frontend-minor-patch:
update-types:
- "minor"
Expand Down
35 changes: 35 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,38 @@ db migration:
- changed-files:
- any-glob-to-any-file:
- app/db/alembic/versions/**

documentation:
- changed-files:
- any-glob-to-any-file:
- '**/*.md'
- docs/**
- openspec/**
- mkdocs.yml

python:
- changed-files:
- any-glob-to-any-file:
- '**/*.py'
- pyproject.toml
- uv.lock

frontend:
- changed-files:
- any-glob-to-any-file:
- frontend/**

ci:
- changed-files:
- any-glob-to-any-file:
- .github/workflows/**
- .github/labeler.yml
- .github/actions/**

docker:
- changed-files:
- any-glob-to-any-file:
- '**/Dockerfile*'
- '**/*compose*.yml'
- '**/*compose*.yaml'
- .dockerignore
8 changes: 8 additions & 0 deletions .github/scripts/detect_changed_areas.py
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,11 @@
"docs/reference/settings.md",
".env.example",
".github/simplicity-budgets.toml",
"Cargo.toml",
"Cargo.lock",
"crates/**",
"Dockerfile",
"Dockerfile.*",
],
"rust": [
"Cargo.toml",
Expand All @@ -45,6 +50,7 @@
"app/core/clients/codex.py",
"app/core/clients/http.py",
"app/core/clients/native_egress.py",
"app/core/clients/usage.py",
"app/core/clients/stream_errors.py",
"app/core/clients/proxy.py",
"app/core/clients/proxy_websocket.py",
Expand All @@ -55,10 +61,12 @@
"pyproject.toml",
"uv.lock",
"tests/unit/test_native_egress.py",
"tests/unit/test_usage_client.py",
"tests/unit/test_native_egress_packaging.py",
"tests/unit/test_native_sse_fixtures.py",
"tests/integration/test_native_routed_egress.py",
"tests/integration/test_native_sse_egress.py",
"tests/integration/test_native_usage_egress.py",
"Dockerfile",
"Dockerfile.*",
"Makefile",
Expand Down
57 changes: 57 additions & 0 deletions .github/scripts/validate_changed_openspec.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
"""Strictly validate active OpenSpec changes touched by the GitHub event."""

from __future__ import annotations

import json
import os
import subprocess
from pathlib import Path


def git(*args: str) -> str:
return subprocess.check_output(["git", *args], text=True)


def main() -> None:
event = json.loads(Path(os.environ["GITHUB_EVENT_PATH"]).read_text())
event_name = os.environ["GITHUB_EVENT_NAME"]
if event_name == "pull_request":
pull_request = event["pull_request"]
head = pull_request["head"]["sha"]
base = git("merge-base", pull_request["base"]["sha"], head).strip()
elif event_name == "push":
base, head = event["before"], event["after"]
elif event_name == "merge_group":
base, head = event["merge_group"]["base_sha"], event["merge_group"]["head_sha"]
else:
raise ValueError(f"Unsupported event: {event_name}")
if event_name == "push" and base == "0" * 40:
paths = git("ls-tree", "-r", "--name-only", "-z", head, "--", "openspec/changes/")
else:
paths = git("diff", "--name-only", "-z", "--no-renames", base, head, "--", "openspec/changes/")
changes = set()
for path in paths.split("\0"):
parts = path.split("/")
if len(parts) >= 4 and parts[:2] == ["openspec", "changes"] and parts[2] != "archive":
if Path(*parts[:3]).is_dir():
changes.add(parts[2])
for change in sorted(changes):
subprocess.run(
[
"npx",
"--yes",
"@fission-ai/openspec@1.11.0",
"validate",
"--type",
"change",
"--strict",
"--no-interactive",
"--",
change,
],
check=True,
)


if __name__ == "__main__":
main()
14 changes: 12 additions & 2 deletions .github/simplicity-budgets.toml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ max_lines = 60
# Single source of truth for dashboard nav width. If the nav refactor moves or
# renames this array, the checker exits 2 until path/array here are repointed —
# that coupling is intentional.
path = "frontend/src/components/layout/app-header.tsx"
path = "frontend/src/components/layout/nav-items.ts"
array = "CORE_NAV_ITEMS"
max_items = 5

Expand Down Expand Up @@ -51,7 +51,16 @@ max_items = 5
# 130 -> 103 constantize-core-tunables turned 27 never-tuned core tunables
# into fixed constants (#1340 precedent, slop-removal 0908 K1); 103 -> 96
# K2 bridge: constantize-session-bridge-tunables fixed seven never-tuned
# HTTP session bridge tunables.
# HTTP session bridge tunables; 96 -> 95 drop-bridge-recovery-modes deleted
# the ambiguous-continuation recovery mode selector (fail-closed is the only
# behaviour now); 95 -> 96 dashboard_auth_proxy_groups_header (the reverse
# proxy's group header must match that proxy's config, so it cannot be a
# dashboard row, PR-2c-2); 96 -> 95 constantize-token-refresh-interval fixed
# the proactive token-refresh window at eight days and emptied the `MIGRATING`
# backlog; 95 -> 96 thread_cache_identity_mode (a fleet-wide behaviour switch an
# operator must be able to roll back without a deploy, so it needs a dashboard
# home; the environment leg exists only so an operator locked out of the
# dashboard can still pin the mode at boot, and it is a fallback, never a seed).
max = 96

[root_files]
Expand Down Expand Up @@ -99,6 +108,7 @@ allowed = [
"renovate.json",
"rust-toolchain.toml",
"scripts",
"spec",
"tests",
"uv.lock",
]
Loading