Repository navigation
fix(sandbox): emit a heartbeat from the GCP Agent Platform template controller - #541
Merged
ItamarZand88 merged 1 commit intoAug 30, 2026
Merged
Conversation
…ontroller A GCP sandbox reconciled healthy and reported no observation at all: neither GCP controller emitted a heartbeat, and SandboxHeartbeatData carried no variant they could emit. The template controller's Ready handler already reads the template's lifecycle state every 30s and fails fast on anything but ACTIVE, so the emission adds no cloud API call and needs no permission it does not already hold. It reports the engine and template it read, and nothing about sessions: counting those needs a list verb only the management set grants.
Greptile SummaryThe PR adds recurring health observations for GCP Agent Platform sandbox templates after confirming that the provider reports them as active.
Confidence Score: 5/5The PR appears safe to merge, with the heartbeat producer and relevant serialized Manager contracts aligned. The heartbeat is emitted only after the existing ACTIVE-state check, repeats through the delayed Ready transition, and has consistent core, OpenAPI, and generated-client wire representations.
|
| Filename | Overview |
|---|---|
| crates/alien-core/src/heartbeat.rs | Adds the serialized GCP Agent Platform sandbox heartbeat contract and an exact wire-format round-trip test. |
| crates/alien-infra/src/sandbox/gcp_agent_platform_template.rs | Emits a healthy heartbeat after each successful ACTIVE template check while retaining the 30-second Ready loop. |
| crates/alien-deployment/src/manager_api_transport.rs | Adds coverage proving the new core heartbeat converts through the generated Manager request type. |
| client-sdks/manager/openapi.json | Extends the Manager client contract with the tagged GCP Agent Platform sandbox heartbeat schema. |
| crates/alien-manager/openapi.json | Keeps the Manager service OpenAPI contract aligned with the new heartbeat variant. |
Sequence Diagram
sequenceDiagram
participant R as Ready reconciler
participant G as GCP Agent Platform
participant C as Heartbeat collector
participant M as Manager transport
R->>G: Read sandbox template
G-->>R: Template state and identity
alt State is ACTIVE
R->>C: Emit healthy GCP sandbox heartbeat
C->>M: Include heartbeat in reconciliation
R-->>R: Schedule Ready after 30 seconds
else State is not ACTIVE
R-->>R: Return ResourceDrift error
end
Reviews (1): Last reviewed commit: "fix(sandbox): emit a heartbeat from the ..." | Re-trigger Greptile
ItamarZand88
deleted the
itamar/alien-622-gcp-sandbox-emits-no-heartbeat
branch
August 30, 2026 23:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A GCP sandbox reconciled healthy and reported no observation at all: neither GCP controller
emitted a heartbeat, and
SandboxHeartbeatDatahad no variant they could emit.Readyhandler already reads the template's lifecycle stateevery 30 seconds and returns an error on anything but
ACTIVE.only be produced after that
ACTIVEcheck passed.Readyreturns to itself, so the observation refreshes on every reconcile instead offreezing at create time.
This turns a controller that measured a template's health and discarded it into one that
reports it.
What I did
Added a
GcpAgentPlatformvariant toSandboxHeartbeatDataand emitted it from thetemplate controller. The engine controller observes nothing at
Readyby design, so thetemplate controller is the right emitter.
The emission sits after the
ACTIVEcheck, which returns early on anything else, so ahealthy status is only ever reported when
ACTIVEwas actually read. It carries no sessioncount: counting sessions needs a list verb no sandbox permission set grants, and inventing
the number would be worse than leaving it out.
This adds no cloud API call and needs no permission the controller does not already
hold. The read was already there, and the diff touches no permission set.
Files touched
crates/alien-core/src/heartbeat.rs·crates/alien-infra/src/sandbox/gcp_agent_platform_template.rs·crates/alien-deployment/src/manager_api_transport.rs· regenerated OpenAPI and zod artifactsHow I tested
cargo test -p alien-infra --features all-platforms,test-utils --lib sandbox::gcp_agent_platform_template— 16 passed. The new test drives three consecutive
Readyreconciles and asserts exactlyone healthy heartbeat each, which is what separates a steady-state emitter from one that
fires once and goes stale.
the reported lifecycle away from running.
round-trip passes even when the tag is wrong.
and rebuilding produces
data did not match any variant of untagged enum SandboxHeartbeatData— a client-side failure before any HTTP call, which looks nothinglike a missing schema. A test in
manager_api_transport.rsnow pins it.pnpm run generate:manager-rust-sdkandpnpm --filter @alienplatform/core generate.cargo check --workspace --all-targetsin the consuming workspace, which enumerates everyvariant of this enum — the new one breaks nothing.
Not validated against a live GCP project, so the above proves the logic, the wire shape and
the regeneration, not that the call succeeds in a real cloud.