Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fixes from problematic pr worth keeping - #415

Closed
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1
Closed

Fixes from problematic pr worth keeping#415
OisinKyne wants to merge 4 commits into
mainfrom
oisin/413-1

Conversation

@OisinKyne

@OisinKyneOisinKyne commented May 4, 2026

Copy link
Copy Markdown
Contributor

Problem to be solved

PR #413 is satisfactory and
slightly cleaner than what we
did. Compared side-by-side:

Equivalent or better:

  • Bootstrap rip-out, same
    architecture (image's
    /opt/hermes/.venv)
  • Bumps image v2026.4.23 →
    v2026.4.30 (we kept the older
    pin)
  • Fail-fast init-container
    check ("missing binary" /
    "missing extras") — slightly
    more defensive than what we had
  • agent wallet backup/restore
    usage strings made
    runtime-neutral
  • applyWalletMetadataConfigMap
    call added to Hermes restore —
    we missed this; restore would
    have left a stale
    wallet-metadata ConfigMap in
    the cluster after a wallet swap
  • Adds round-trip
    backup/restore tests for the
    Hermes path — we didn't write
    these

Not in #413 (consistent with
the PR body's note that they
punted on these intentionally
or scope-wise):

  1. Helmfile --server-side=true
    --force-conflicts on
    helmDefaults for both
    helmfiles. PR fix: simplify Hermes recreation lifecycle #413 says "main
    has the managed-fields
    mitigation" — but we now know
    the
    releaseLiteLLMConfigOwnership
    mitigation doesn't actually
    work (you hit
    before-first-apply on it). So
    the SSA conflict on
    litellm-config and
    remote-signer-keystore-password
    is unaddressed by main + fix: simplify Hermes recreation lifecycle #413
    together.
  2. ensureDevRegistries hoisted
    into both branches of
    K3dBackend.Up (so stopped
    registry caches come back on
    every up, not just on cluster
    create)
  3. docker rm -f recovery in
    ensureDevRegistry when start
    fails because the container's
    referenced Docker network was
    reaped

Recommendation: merge #413
as-is, then branch fresh from
main with those three
leftovers. They're tightly
scoped, mutually independent,
and not adjacent to the
bootstrap-rip-out diff.
Ordering inside the new branch:

Order: 1
Fix: helm SSA force-conflicts
Files: internal/embed/infrastru
cture/helmfile.yaml,
internal/hermes/hermes.go:gen
erateHelmfile
───────────────────────────────

Order: 2
Fix: Registry restart on every
up
Files: internal/stack/backend_k
3d.go:Up
───────────────────────────────

Order: 3
Fix: Registry orphaned-network
recovery
Ordering inside the new branch:

┌─────┬──────────────┬──────────────────────────────────────┐
│ Ord │ Fix │ Files │
│ er │ │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ helm SSA for │ internal/embed/infrastructure/helmfi │
│ 1 │ ce-conflicts │ le.yaml, internal/hermes/hermes.go:g │
│ │ │ enerateHelmfile │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 2 │ restart on │ internal/stack/backend_k3d.go:Up │
│ │ every up │ │
├─────┼──────────────┼──────────────────────────────────────┤
│ │ Registry │ │
│ 3 │ orphaned-net │ internal/stack/dev_registry.go:ensur │
│ │ work │ eDevRegistry │
│ │ recovery │ │
└─────┴──────────────┴──────────────────────────────────────┘

I'd also drop the releaseLiteLLMConfigOwnership from main in
that same fresh branch — it's load-bearing today (per the PR
body), but with --force-conflicts it becomes dead code, same
reasoning as we worked through earlier today.

One nit on #413 worth a one-line review comment, not blocking:
the init-hermes-data container in #413 runs as the pod default
user (uid 10000) — which is fine for the mkdir + state.db path,
but if the PVC has any pre-existing root-owned content from
won't bite anyone in practice but worth flagging.

Summary

All five tasks complete, build clean, tests passing.

Summary of changes on oisin/413-1:

File: internal/embed/infrastructure/helmfile.yaml
Change: New helmDefaults.args: ["--server-side=true",
"--force-conflicts"] block at the top
────────────────────────────────────────
File: internal/hermes/hermes.go (generateHelmfile)
Change: Same helmDefaults block in the generated per-instance
Hermes helmfile
────────────────────────────────────────
File: internal/stack/backend_k3d.go (Up)
Change: Hoisted ensureDevRegistries out of the else-only branch
so it runs on every Up — stopped registry containers come
back
even when the cluster is just being restarted
────────────────────────────────────────
File: internal/stack/dev_registry.go (ensureDevRegistry)
Change: When docker start fails on an existing stopped container

(typical cause: dangling network reference after reclaimLeakedDevK3dNetworks), force-rm the dead shell and fall
through to recreate. Cache content lives on the host

bind-mount
so layers survive
────────────────────────────────────────
File: internal/stack/stack.go
Change: Dropped the now-redundant releaseLiteLLMConfigOwnership
function and its call site in syncDefaults — --force-conflicts

is the load-bearing fix

Net effect: obol stack down/up cycles should be idempotent on
shared SSA fields, and dev-mode retries reuse cached image
layers instead of re-pulling from upstream every time.

@OisinKyne
OisinKyne requested a review from bussyjdMay 4, 2026 13:48
@bussyjdbussyjd mentioned this pull request May 4, 2026
6 tasks
@OisinKyne

Copy link
Copy Markdown
ContributorAuthor

favouring #417 and upstreams

@OisinKyne
OisinKyne deleted the oisin/413-1 branch May 5, 2026 22:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@OisinKyne@bussyjd