feat(webhook): trigger brain-sync on Gitea push instead of 15-min poll
Adds POST /webhooks/brain-sync: verifies Gitea's HMAC-SHA256 signature, checks the push is to mathias/brain main, then creates a one-off Job from the existing brain-sync CronJob's template (same script the 15-min poll already runs, just triggered on-demand). Off by default -- opt in via GITEA_WEBHOOK_SECRET, since it needs Job-create RBAC in the "brain" namespace a fresh deploy won't have. 10 new tests (internal/webhook), including a fake-clientset reactor to simulate server-side GenerateName expansion, which the plain fake tracker doesn't do on its own. Needs (follow-up, infra repo): RBAC granting ingestion's ServiceAccount get on cronjobs/brain-sync + create on jobs in the brain namespace, the GITEA_WEBHOOK_SECRET env, and the actual Gitea webhook registration.
This commit is contained in:
@@ -34,8 +34,27 @@ import (
|
||||
"github.com/mathiasbq/hyperguild/ingestion/internal/search"
|
||||
"github.com/mathiasbq/hyperguild/ingestion/internal/vectorstore"
|
||||
"github.com/mathiasbq/hyperguild/ingestion/internal/watcher"
|
||||
"github.com/mathiasbq/hyperguild/ingestion/internal/webhook"
|
||||
"k8s.io/client-go/kubernetes"
|
||||
"k8s.io/client-go/rest"
|
||||
"k8s.io/client-go/tools/clientcmd"
|
||||
)
|
||||
|
||||
// kubeClient builds an in-cluster Kubernetes client (falls back to
|
||||
// $KUBECONFIG for local dev/testing against a real cluster).
|
||||
func kubeClient() (kubernetes.Interface, error) {
|
||||
if cfg, err := rest.InClusterConfig(); err == nil {
|
||||
return kubernetes.NewForConfig(cfg)
|
||||
}
|
||||
rules := clientcmd.NewDefaultClientConfigLoadingRules()
|
||||
cc := clientcmd.NewNonInteractiveDeferredLoadingClientConfig(rules, &clientcmd.ConfigOverrides{})
|
||||
cfg, err := cc.ClientConfig()
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("kube config (no in-cluster, no kubeconfig): %w", err)
|
||||
}
|
||||
return kubernetes.NewForConfig(cfg)
|
||||
}
|
||||
|
||||
// claudeSink converts each claudewatcher.Batch into a raw session dump
|
||||
// under brain/archive/claude-sessions/<host>/. Deliberately NOT a wiki
|
||||
// note (api.WriteNote / brain/wiki/) — raw full transcripts out-ranked
|
||||
@@ -352,6 +371,29 @@ func main() {
|
||||
logger.Info("claudewatcher started",
|
||||
"sessions_dir", claudeDir, "host", host, "interval", interval)
|
||||
}
|
||||
|
||||
// Gitea push webhook -> on-demand brain-sync Job, instead of waiting up
|
||||
// to 15 minutes for the next CronJob poll. Off by default (opt in via
|
||||
// GITEA_WEBHOOK_SECRET) since it needs Job-create RBAC in the "brain"
|
||||
// namespace that a fresh deploy won't have granted yet.
|
||||
var webhookHandler *webhook.Handler
|
||||
if webhookSecret := os.Getenv("GITEA_WEBHOOK_SECRET"); webhookSecret != "" {
|
||||
kc, err := kubeClient()
|
||||
if err != nil {
|
||||
logger.Error("brain-sync webhook: kube client", "err", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
webhookHandler = &webhook.Handler{
|
||||
Secret: webhookSecret,
|
||||
Clientset: kc,
|
||||
Namespace: envOr("BRAIN_SYNC_NAMESPACE", "brain"),
|
||||
CronJobName: envOr("BRAIN_SYNC_CRONJOB", "brain-sync"),
|
||||
WatchRepo: envOr("BRAIN_SYNC_WATCH_REPO", "mathias/brain"),
|
||||
Logger: logger,
|
||||
}
|
||||
logger.Info("brain-sync webhook enabled", "namespace", webhookHandler.Namespace, "cronjob", webhookHandler.CronJobName)
|
||||
}
|
||||
|
||||
if vectorStore != nil {
|
||||
embedSyncInterval := envInt("BRAIN_EMBED_SYNC_INTERVAL", 300)
|
||||
vectorstore.StartSync(ctx, brainDir, vectorStore,
|
||||
@@ -373,6 +415,9 @@ func main() {
|
||||
mux.HandleFunc("POST /promote", h.Promote)
|
||||
mux.HandleFunc("POST /backfill-embeddings", h.BackfillEmbeddings)
|
||||
mux.HandleFunc("GET /pass-rate", h.PassRate)
|
||||
if webhookHandler != nil {
|
||||
mux.Handle("POST /webhooks/brain-sync", webhookHandler)
|
||||
}
|
||||
jwtValidator, err := chassisauth.NewJWTValidator(ctx, os.Getenv("DEX_ISSUER_URL"), os.Getenv("MCP_AUDIENCE"))
|
||||
if err != nil {
|
||||
logger.Error("build jwt validator", "err", err)
|
||||
|
||||
Reference in New Issue
Block a user