4fcf7cb150
The specs in `spec/` were copied from their source repos by hand and had
drifted ~2,400 lines behind infra, so they are now imported with
Copybara (`copy.bara.sky`, run in a pinned Docker image by
`scripts/fetch-spec.sh`): `make codegen` re-fetches them at the commits
pinned in `spec/infra-ref` and `spec/belt-ref` before generating, and
the generated-files CI check fails if the tracked copies don't match the
pins. Regenerating from the current pins picks up the accumulated spec
changes in the generated JS/Python clients (renamed request schemas,
`SandboxNetworkConfig`, `SandboxIam` workload identity,
`FILE_TYPE_SYMLINK`, access-token auth deprecation, volume path-metadata
tweaks). The one handwritten SDK change follows from that: the public
`FileType` enums gain a `SYMLINK` member (JS and both Python surfaces)
so entries envd reports as symlinks show up in `files.list()` and
`getInfo()`/`get_info()` instead of being silently skipped as unknown
types. The custom `spec/remove_extra_tags.py` tag-filtering script is
replaced by Redocly CLI's `filter-in` decorator (`redocly.yaml`), which
produces identical generated JS output; a `filter-out` decorator
additionally drops any operation or component schema the upstream specs
mark `x-not-implemented: true` (currently the SOCKS5
`SandboxEgressProxyConfig`/`egressProxy` surface, which infra flagged as
spec-only); each SDK's bundle now goes to its own gitignored
`spec/openapi_generated.<api>.yml` instead of both pipelines overwriting
one shared file; Python client models now list fields in spec order
instead of alphabetical (mechanical reordering only — construct models
with keyword args). Spec fetches try whatever GitHub token is available
and fall back to the tracked copies with a warning (the public infra
specs also fetch anonymously); in CI a short-lived belt-scoped token is
minted from the org-wide Autofixer GitHub App (no new secrets), so fork
PRs simply fall back for the belt spec; the CI workflows also cache the
Copybara image alongside the codegen image, and the previously ignored
`CODEGEN_IMAGE` env is honored by the Makefile.
## Usage
```sh
# update the specs: bump a pin, then regenerate
echo <infra-commit-sha> > spec/infra-ref
make codegen
# fetch a single spec without regenerating
pnpm fetch:api-spec # spec/openapi.yml from infra
pnpm fetch:envd-spec # spec/envd/ from infra
pnpm fetch:volume-spec # spec/openapi-volumecontent.yml from belt
# try the latest spec without touching the pin
E2B_INFRA_REF=main pnpm fetch:api-spec
# change which endpoint tags an SDK exposes
$EDITOR redocly.yaml && make codegen
```
```ts
// symlinks are now visible in the filesystem API (JS; same shape in Python)
const entries = await sandbox.files.list('/home/user')
const link = entries.find((e) => e.type === FileType.SYMLINK)
console.log(link?.symlinkTarget)
```
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
80 lines
2.6 KiB
Plaintext
80 lines
2.6 KiB
Plaintext
# Copybara config that imports API specs from their source-of-truth
|
|
# repositories into spec/. The imported files are tracked here but must not
|
|
# be edited by hand — `make codegen` re-fetches the infra ones at the commit
|
|
# pinned in spec/infra-ref before generating the clients, and the
|
|
# generated-files CI check fails if the tracked copies don't match the pin.
|
|
# See spec/README.md.
|
|
#
|
|
# scripts/fetch-spec.sh runs these workflows with `--folder-dir` pointing at
|
|
# spec/ itself. Each workflow's destination_files glob declares the spec/
|
|
# paths its upstream owns: after a successful fetch, Copybara replaces
|
|
# exactly those paths (so files deleted upstream are deleted here too) and
|
|
# leaves the repo-owned files in spec/ untouched.
|
|
|
|
INFRA_REPO = "https://github.com/e2b-dev/infra.git"
|
|
BELT_REPO = "https://github.com/e2b-dev/belt.git"
|
|
|
|
AUTHORING = authoring.pass_thru("E2B <hello@e2b.dev>")
|
|
|
|
# REST API spec -> spec/openapi.yml
|
|
core.workflow(
|
|
name = "api-spec",
|
|
origin = git.github_origin(
|
|
url = INFRA_REPO,
|
|
),
|
|
destination = folder.destination(),
|
|
origin_files = glob(["spec/openapi.yml"]),
|
|
destination_files = glob(["openapi.yml"]),
|
|
authoring = AUTHORING,
|
|
mode = "SQUASH",
|
|
transformations = [
|
|
core.move("spec/openapi.yml", "openapi.yml"),
|
|
],
|
|
)
|
|
|
|
# envd spec (HTTP API + protobufs) -> spec/envd/
|
|
core.workflow(
|
|
name = "envd-spec",
|
|
origin = git.github_origin(
|
|
url = INFRA_REPO,
|
|
),
|
|
destination = folder.destination(),
|
|
origin_files = glob(
|
|
[
|
|
"packages/envd/spec/envd.yaml",
|
|
"packages/envd/spec/filesystem/**",
|
|
"packages/envd/spec/process/**",
|
|
],
|
|
# This repo has its own buf generation templates in spec/envd.
|
|
exclude = ["packages/envd/spec/buf*.yaml"],
|
|
),
|
|
destination_files = glob([
|
|
"envd/envd.yaml",
|
|
"envd/filesystem/**",
|
|
"envd/process/**",
|
|
]),
|
|
authoring = AUTHORING,
|
|
mode = "SQUASH",
|
|
transformations = [
|
|
core.move("packages/envd/spec", "envd"),
|
|
],
|
|
)
|
|
|
|
# Volume-content API spec -> spec/openapi-volumecontent.yml
|
|
# belt is private, so the fetch authenticates with a GitHub token
|
|
# (see scripts/fetch-spec.sh).
|
|
core.workflow(
|
|
name = "volume-api-spec",
|
|
origin = git.github_origin(
|
|
url = BELT_REPO,
|
|
),
|
|
destination = folder.destination(),
|
|
origin_files = glob(["packages/volume-content/openapi.yml"]),
|
|
destination_files = glob(["openapi-volumecontent.yml"]),
|
|
authoring = AUTHORING,
|
|
mode = "SQUASH",
|
|
transformations = [
|
|
core.move("packages/volume-content/openapi.yml", "openapi-volumecontent.yml"),
|
|
],
|
|
)
|