Repository navigation
docs(insta): manifest pgVersion, storage buckets and strict service keys - #161
Conversation
The template manifest section shows a postgres pgVersion and a public storage bucket bound through env.platform, lists the five storage keys, and adds the storage and unknown-key rows to the rules table with the CLI version floor for storage. A bucket takes no region.
A public bucket's URL is built from BUCKET_NAME plus the platform's public storage host, which no env.platform key carries. Say so and point at the storage reference section that explains where the host comes from.
…m's real refusals The complete minimal manifest set public: true uncommented, so an agent copying it created a world-readable bucket. Show public as a comment and leave the bucket private. Bind AWS_REGION through env.platform like the other storage keys, since many S3 SDKs refuse to start without a region. The public rule quoted the oss runtime's sentence. Quote the platform's own, one for a web or worker and one for a managed database, and say the deploy is gated by service.setAccess rather than that it always needs an approval.
There was a problem hiding this comment.
1 issue found across 1 file
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="insta/cli-reference.md">
<violation number="1" location="insta/cli-reference.md:571">
P3: These examples drop the braces required by the documented `${{services...}}` syntax, so they are not valid manifest references. Spell both refused examples as `${{services.<name>.url}}` and `${{services.<name>.host}}`.</violation>
</file>
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
| in this same manifest and the credential key it mints. A postgres service mints `DATABASE_URL`. A | ||
| storage service mints `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_ENDPOINT_URL_S3`, | ||
| `BUCKET_NAME` and `AWS_REGION`. The platform resolves the reference while writing variables, before | ||
| the app starts. A database and a bucket have no address, so `${services.<name>.url}` and `.host` |
There was a problem hiding this comment.
P3: These examples drop the braces required by the documented ${{services...}} syntax, so they are not valid manifest references. Spell both refused examples as ${{services.<name>.url}} and ${{services.<name>.host}}.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At insta/cli-reference.md, line 571:
<comment>These examples drop the braces required by the documented `${{services...}}` syntax, so they are not valid manifest references. Spell both refused examples as `${{services.<name>.url}}` and `${{services.<name>.host}}`.</comment>
<file context>
@@ -554,10 +563,15 @@ services:
+in this same manifest and the credential key it mints. A postgres service mints `DATABASE_URL`. A
+storage service mints `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_ENDPOINT_URL_S3`,
+`BUCKET_NAME` and `AWS_REGION`. The platform resolves the reference while writing variables, before
+the app starts. A database and a bucket have no address, so `${services.<name>.url}` and `.host`
+are refused for them. A public bucket's address is not a reference either: the app builds it from
+`BUCKET_NAME` plus the platform's public storage host, which no `env.platform` key carries, see
</file context>
| the app starts. A database and a bucket have no address, so `${services.<name>.url}` and `.host` | |
| the app starts. A database and a bucket have no address, so `${{services.<name>.url}}` and `${{services.<name>.host}}` |
jwfing
left a comment
There was a problem hiding this comment.
Summary
The manifest guidance is broadly consistent with the stated intent, but the unreplaced CLI-version token blocks publication.
Requirements context
I assessed the change against the PR description, the repository’s existing Templates and storage guidance, and the related CLI PR #351. The referenced superproject design document is not present in this checkout, and platform PR #625 was not publicly accessible; CLI PR #351 confirms that the compatibility floor must come from the release cut after that currently open CLI change merges.
Findings
Critical
- Replace the unresolved release placeholders before merging. Both compatibility notices render the literal
@CLI_VERSION@, so readers cannot determine which CLI accepts storage services or displays the new service details. This also directly contradicts the PR’s verification statement that no such token remains. Wait for the dependent CLI release, then substitute its actual version in both locations. (insta/cli-reference.md:85-85,insta/cli-reference.md:606-606)
Suggestion
(none)
Information
- Software engineering: This is documentation-only, so no behavioral unit tests are expected. The head commit’s repository
sanitycheck passed, including Markdown fence/table validation, andgit diff --checkis clean. (insta/cli-reference.md:535-616) - Functionality: Apart from the version floor, the sample and surrounding rules cover
pgVersion, private-by-default storage, all five platform keys, region behavior, strict service fields, and changed validation ownership. (insta/cli-reference.md:535-616) - Security: No executable security surface changes. The guidance explicitly warns that public buckets permit anonymous reads and identifies the
service.setAccessgate. (insta/cli-reference.md:542-542,insta/cli-reference.md:606-606) - Performance: No performance-relevant changes; this PR modifies static documentation only. (
insta/cli-reference.md:85-616)
Verdict
Request changes — one Critical finding must be resolved by replacing both placeholders with the released CLI version.
The two compatibility notices name the released CLI that carries InsForge/instacloud-cli#351, in place of the placeholder.
jwfing
left a comment
There was a problem hiding this comment.
Summary
The PR accurately documents the new template service definition, with one minor reference-syntax typo.
Requirements context
I assessed the change against the PR title and description, existing template/storage guidance, and repository conventions. The referenced superproject design document is not present in this checkout and was not publicly accessible, so its requirements could not be independently inspected.
Findings
Critical
(none)
Suggestion
insta/cli-reference.md:566-572— The paragraph first defines references as${{services.<service>.<KEY>}}, but the negative URL example uses${services.<name>.url}with only one pair of braces. Write${{services.<name>.url}}(and preferably${{services.<name>.host}}) so the example demonstrates rejection of a syntactically valid reference for semantic reasons, rather than rejection caused by malformed syntax.
Information
- Software engineering/functionality: The focused documentation change covers
pgVersion, a private-by-default storage example, all five canonical storage keys, the CLI/platform validation boundary, strict service keys, region behavior, and the CLI 0.1.19 floor (insta/cli-reference.md:85-86,insta/cli-reference.md:502-616). No runtime test coverage is applicable.git diff --checkpassed, no@CLI_VERSION@token remains, and an equivalent execution of the repository's fence/table validation logic passed; the exact Python script could not run because Python is unavailable in the review image (.github/check-markdown.py:1-93). - Security: The copied manifest remains private by default, and the documentation explicitly warns that public buckets are anonymously readable and governed by
service.setAccess; no secrets are embedded or exposed (insta/cli-reference.md:540-556,insta/cli-reference.md:606-606). - Performance: This PR changes documentation only and introduces no runtime code, queries, loops, allocations, or I/O behavior (
insta/cli-reference.md:85-86,insta/cli-reference.md:492-616).
Verdict
Approved under the stated verdict rule: zero Critical findings. The syntax correction is recommended but non-blocking.
What
insta/cli-reference.mdteaches agents the new template manifest fields:pgVersionon a postgres service, astoragebucket withpublic, the five storage keys reachable throughenv.platform, and that a bucket takes no region. The rules table gains astoragerow, which carries the CLI version floor, and a row saying a misspelt service key is now refused by name. The validation paragraph says what the CLI no longer checks locally. Thetemplate infoand--regionwording follow the CLI change.Spec: docs/superpowers/specs/2026-10-05-template-service-definition-v1-design.md in the insta-cloud superproject (section 5, skills). Merge after the CLI release that carries the change, and after the platform change (InsForge/instacloud-platform#625) is live in production.
How
pgVersion, a privatefilesbucket withpublic: trueshown only as a comment (so a copied sample never makes a world-readable bucket), andenv.platformlines for its keys,AWS_REGIONincluded.CANONICAL_KEYS.storagein the platform'ssrc/provisioning/secretNames.tsat 8bdadd38, not copied from another doc.storagerule tells the agent to say so to the person it deploys for, because a public bucket is readable by anyone, and says the deploy is gated byservice.setAccess. The quoted refusals are the platform's own sentences.Verify
python3 .github/check-markdown.pypasses, so every code fence pairs and every table row matches its header.@CLI_VERSION@token is left in the file, and the floor equals the released CLI version.🤖 Generated with Claude Code
Summary by cubic
Documents new template manifest fields in
insta/cli-reference.md:pgVersionon a postgres service, astoragebucket with optionalpublic, the five storage keys reachable throughenv.platform, and that a bucket takes no region. Also records that misspelt service keys are now refused by name, that the CLI no longer validates non-web/workerservice types locally, and that storage andtemplate infoneed CLI ≥ 0.1.19.public: trueshown only as a comment) and binds all five storage keys viaenv.platform,AWS_REGIONincluded.storagerule says to tell the person you deploy for that a public bucket is readable by anyone, and that deploying one is gated byservice.setAccess.Written for commit 5f6a1e3. Summary will update on new commits.