Files
e2b-dev--e2b/copy.bara.sky
T
Mish Ushakov 4fcf7cb150 feat: sync API specs from infra and belt with Copybara (#1564)
The specs in `spec/` were copied from their source repos by hand and had
drifted ~2,400 lines behind infra, so they are now imported with
Copybara (`copy.bara.sky`, run in a pinned Docker image by
`scripts/fetch-spec.sh`): `make codegen` re-fetches them at the commits
pinned in `spec/infra-ref` and `spec/belt-ref` before generating, and
the generated-files CI check fails if the tracked copies don't match the
pins. Regenerating from the current pins picks up the accumulated spec
changes in the generated JS/Python clients (renamed request schemas,
`SandboxNetworkConfig`, `SandboxIam` workload identity,
`FILE_TYPE_SYMLINK`, access-token auth deprecation, volume path-metadata
tweaks). The one handwritten SDK change follows from that: the public
`FileType` enums gain a `SYMLINK` member (JS and both Python surfaces)
so entries envd reports as symlinks show up in `files.list()` and
`getInfo()`/`get_info()` instead of being silently skipped as unknown
types. The custom `spec/remove_extra_tags.py` tag-filtering script is
replaced by Redocly CLI's `filter-in` decorator (`redocly.yaml`), which
produces identical generated JS output; a `filter-out` decorator
additionally drops any operation or component schema the upstream specs
mark `x-not-implemented: true` (currently the SOCKS5
`SandboxEgressProxyConfig`/`egressProxy` surface, which infra flagged as
spec-only); each SDK's bundle now goes to its own gitignored
`spec/openapi_generated.<api>.yml` instead of both pipelines overwriting
one shared file; Python client models now list fields in spec order
instead of alphabetical (mechanical reordering only — construct models
with keyword args). Spec fetches try whatever GitHub token is available
and fall back to the tracked copies with a warning (the public infra
specs also fetch anonymously); in CI a short-lived belt-scoped token is
minted from the org-wide Autofixer GitHub App (no new secrets), so fork
PRs simply fall back for the belt spec; the CI workflows also cache the
Copybara image alongside the codegen image, and the previously ignored
`CODEGEN_IMAGE` env is honored by the Makefile.

## Usage

```sh
# update the specs: bump a pin, then regenerate
echo <infra-commit-sha> > spec/infra-ref
make codegen

# fetch a single spec without regenerating
pnpm fetch:api-spec     # spec/openapi.yml from infra
pnpm fetch:envd-spec    # spec/envd/ from infra
pnpm fetch:volume-spec  # spec/openapi-volumecontent.yml from belt

# try the latest spec without touching the pin
E2B_INFRA_REF=main pnpm fetch:api-spec

# change which endpoint tags an SDK exposes
$EDITOR redocly.yaml && make codegen
```

```ts
// symlinks are now visible in the filesystem API (JS; same shape in Python)
const entries = await sandbox.files.list('/home/user')
const link = entries.find((e) => e.type === FileType.SYMLINK)
console.log(link?.symlinkTarget)
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 16:37:02 +02:00

80 lines
2.6 KiB
Plaintext

# Copybara config that imports API specs from their source-of-truth
# repositories into spec/. The imported files are tracked here but must not
# be edited by hand — `make codegen` re-fetches the infra ones at the commit
# pinned in spec/infra-ref before generating the clients, and the
# generated-files CI check fails if the tracked copies don't match the pin.
# See spec/README.md.
#
# scripts/fetch-spec.sh runs these workflows with `--folder-dir` pointing at
# spec/ itself. Each workflow's destination_files glob declares the spec/
# paths its upstream owns: after a successful fetch, Copybara replaces
# exactly those paths (so files deleted upstream are deleted here too) and
# leaves the repo-owned files in spec/ untouched.
INFRA_REPO = "https://github.com/e2b-dev/infra.git"
BELT_REPO = "https://github.com/e2b-dev/belt.git"
AUTHORING = authoring.pass_thru("E2B <hello@e2b.dev>")
# REST API spec -> spec/openapi.yml
core.workflow(
name = "api-spec",
origin = git.github_origin(
url = INFRA_REPO,
),
destination = folder.destination(),
origin_files = glob(["spec/openapi.yml"]),
destination_files = glob(["openapi.yml"]),
authoring = AUTHORING,
mode = "SQUASH",
transformations = [
core.move("spec/openapi.yml", "openapi.yml"),
],
)
# envd spec (HTTP API + protobufs) -> spec/envd/
core.workflow(
name = "envd-spec",
origin = git.github_origin(
url = INFRA_REPO,
),
destination = folder.destination(),
origin_files = glob(
[
"packages/envd/spec/envd.yaml",
"packages/envd/spec/filesystem/**",
"packages/envd/spec/process/**",
],
# This repo has its own buf generation templates in spec/envd.
exclude = ["packages/envd/spec/buf*.yaml"],
),
destination_files = glob([
"envd/envd.yaml",
"envd/filesystem/**",
"envd/process/**",
]),
authoring = AUTHORING,
mode = "SQUASH",
transformations = [
core.move("packages/envd/spec", "envd"),
],
)
# Volume-content API spec -> spec/openapi-volumecontent.yml
# belt is private, so the fetch authenticates with a GitHub token
# (see scripts/fetch-spec.sh).
core.workflow(
name = "volume-api-spec",
origin = git.github_origin(
url = BELT_REPO,
),
destination = folder.destination(),
origin_files = glob(["packages/volume-content/openapi.yml"]),
destination_files = glob(["openapi-volumecontent.yml"]),
authoring = AUTHORING,
mode = "SQUASH",
transformations = [
core.move("packages/volume-content/openapi.yml", "openapi-volumecontent.yml"),
],
)