Creer v1.3 — optional mTLS transport + Docker Compose - #15
Draft
seven0070 wants to merge 15 commits into
Draft
Conversation
Scaffold AI repo generation end-to-end: planner/generator API with path validation, TypeScript extension command to write files into the workspace with optional git init, and a PLAN.md for v0.2 priorities. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Backend: curated templates, /plan + /templates, stronger validation, optional GitHub repo create API. Extension: plan preview before write, per-file overwrite protection, GitHub push flow, /creer chat entry and @creer participant, with path-safe writes and shell-safe git exec. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
…rdening Add SSE /generate/stream with per-file progress, OpenAI-compatible base URL and CREER_OFFLINE stubs, LICENSE/CI bake-ins, SecretStorage for GitHub tokens, and GIT_ASKPASS push so tokens never appear on argv or remote URLs. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add stream job_id cancellation, license/CI bake-in options with GET /bakeins, telemetry-free quality gates, and extension AbortSignal progress cancel plus bake-in QuickPicks. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add installable JSON/YAML template packs with /packs API and pack_id planning, extension multi-root workspace picker, and generated-content diff preview before writing files to disk. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add remote pack install/delete and marketplace catalog, side-by-side vscode.diff review for write conflicts, and vsce/ovsx packaging docs so the extension is ready to publish without shipping secrets. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add searchable /registry with JSON pack downloads, extension marketplace icon, Browse Pack Registry command, changelog, and verified vsix packaging path for Marketplace/Open VSX (signing remains a human PAT step). Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add multi-host registry federation via CREER_REGISTRY_PEERS and /registry/federated, Browse Federated Registry in the extension, plus GitHub Actions CI and artifact-first release that publishes only when VSCE_PAT/OVSX_PAT secrets are configured. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add peer status/probe APIs and ad-hoc peers on federated queries, Manage Registry Peers + peer-aware browse UI, GitHub Release assets on tags, and RELEASE.md for the human VSCE/OVSX token publish path. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add optional CREER_REGISTRY_TOKEN for pack/peer write endpoints, gossip-lite /registry/discover with federated discover=true expansion, and extension SecretStorage registry token plus Discover peers UX. Core generate stays public. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add SSRF/private-IP peer guards, allow/deny lists, hop budgets with cycle detection, max_hops on federated queries, and extension trust warnings for private peers plus policy-aware federation status. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add shared-secret HMAC signing for registry/discover payloads, trust modes off/optional/required for federated verification, and extension UX for trust status plus optional requireSignedPeers filtering. mTLS remains a human infra option beyond this. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
Add CREER_SSL_* peer/server TLS settings with shared peer_httpx_client, dev cert + run scripts, docs/MTLS.md, and a two-node docker compose demo alongside HMAC trust from v1.2. Co-authored-by: Sanath S Patil <sanathpatil8861@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements Creer v1.3.0: optional TLS/mTLS transport for registry peers plus Docker Compose multi-peer demo. Complements HMAC peer trust (v1.2).
Backend
CREER_SSL_*settings for server certs and client mTLSapp/http_client.peer_httpx_client()used for all federation outbound callstls_server_configured/mtls_client_configured1.3.0— 67 tests passedOps
docker-compose.yml— two offline peers with shared HMAC secretscripts/gen-dev-certs.sh+scripts/run_backend.shdocs/MTLS.md— how to enable TLS/mTLSStill human-only
Marketplace/Open VSX publish via
VSCE_PAT/OVSX_PAT(RELEASE.md).Test plan
/health→1.3.0+ TLS flags false by defaultdocker compose up --build→ curllocalhost:8000/registry/federated./scripts/gen-dev-certs.shproduces certs undercerts/./scripts/run_backend.shserves HTTPS