feat(deploy): deploy the hosted demo to a Hugging Face Space - #24
Merged
Merged
Conversation
A Hugging Face Space shows the app on huggingface.co inside a frame from hf.space, a different site. Browsers drop SameSite=Lax cookies there, so every uploaded file started a new library and the import found an empty batch. Over HTTPS the cookie is now SameSite=None, Secure, and Partitioned, which keeps it apart for each site that frames the demo. The X-ChatLore header still guards every change. Starlette only writes Partitioned on Python 3.14, so the header is written directly, and removed with the same attributes since a partitioned cookie is only replaced by one.
A free Space builds the existing Dockerfile and keeps the container running with a disk, which visitors' libraries and background imports need. The workflow uploads only what the image builds from, with a README whose front matter configures the Space, and creates the Space on the first run. It runs for every released version and on request, and is skipped until HF_SPACE is set, so forks are not affected.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Finishes M9, the hosted demo: a workflow that deploys it to a free Hugging Face Space, plus a fix so visitors can upload their own data when the demo is shown on the Space's page. The Space builds the existing
Dockerfileunchanged. Vercel's free plan was ruled out: it has no persistent disk and limits each request to 4.5 MB, so uploads and visitors' libraries can't work there.Changes
.github/workflows/deploy.yml, a new Deploy workflow. It runs onv*tags and on request, and is skipped until the repository variableHF_SPACEis set, so forks aren't affected. What it does:sdk: docker,app_port: 7860);hf upload, which handles the binarydemo.zipthat a plain git push to the Hub would reject.src/chatlore/api.py: the Space page shows the app in a frame fromhf.spaceonhuggingface.co, a different site. Browsers dropSameSite=Laxcookies there, so every uploaded file started a new library and the import then found an empty batch. Over HTTPS, the library cookie is nowSameSite=None; Secure; Partitioned, so each site that frames the demo gets its own cookie. Over HTTP it is unchanged. Changes still need theX-ChatLoreheader, which another site can't send. Starlette only writesPartitionedon Python 3.14, so the header is written directly, and deleting the library removes the cookie with the same attributes.docs/hosting.md: setup steps for the Space (token, variable, run the workflow, model key with a credit limit), the demo and MCP addresses, and what a free Space's sleep and restarts mean for visitors' libraries. The cookie attributes are described too.CHANGELOG.mdand the README roadmap.How it was tested
ruff,ruff format --check, strictmypy, andpytestpass.SameSite=None,Secure,Partitioned, andHttpOnly, and deleting it sendsMax-Age=0withPartitioned. The existing test still seesSameSite=Laxover HTTP.hf repos createandhf uploadoptions were checked against huggingface_hub 1.32. The workflow itself first runs once this is merged andHF_SPACEandHF_TOKENare set.Checklist
uv run ruff check .anduv run ruff format --check .passuv run mypypassesuv run pytestpassesCHANGELOG.mdupdated under Unreleased