Skip to content

feat(deploy): deploy the hosted demo to a Hugging Face Space - #24

Merged
cl0ver012 merged 3 commits into
mainfrom
feat/m9-deploy-space
Oct 1, 2026
Merged

cl0ver012 merged 3 commits into
mainfrom
feat/m9-deploy-space

Conversation

@cl0ver012

Copy link
Copy Markdown
Owner

Summary

Finishes M9, the hosted demo: a workflow that deploys it to a free Hugging Face Space, plus a fix so visitors can upload their own data when the demo is shown on the Space's page. The Space builds the existing Dockerfile unchanged. Vercel's free plan was ruled out: it has no persistent disk and limits each request to 4.5 MB, so uploads and visitors' libraries can't work there.

Changes

  • .github/workflows/deploy.yml, a new Deploy workflow. It runs on v* tags and on request, and is skipped until the repository variable HF_SPACE is set, so forks aren't affected. What it does:
    • copies only what the image builds from;
    • writes the Space's README with front matter (sdk: docker, app_port: 7860);
    • creates the Space if needed, then uploads with hf upload, which handles the binary demo.zip that a plain git push to the Hub would reject.
  • src/chatlore/api.py: the Space page shows the app in a frame from hf.space on huggingface.co, a different site. Browsers drop SameSite=Lax cookies there, so every uploaded file started a new library and the import then found an empty batch. Over HTTPS, the library cookie is now SameSite=None; Secure; Partitioned, so each site that frames the demo gets its own cookie. Over HTTP it is unchanged. Changes still need the X-ChatLore header, which another site can't send. Starlette only writes Partitioned on Python 3.14, so the header is written directly, and deleting the library removes the cookie with the same attributes.
  • docs/hosting.md: setup steps for the Space (token, variable, run the workflow, model key with a credit limit), the demo and MCP addresses, and what a free Space's sleep and restarts mean for visitors' libraries. The cookie attributes are described too.
  • CHANGELOG.md and the README roadmap.

How it was tested

  • ruff, ruff format --check, strict mypy, and pytest pass.
  • New test: over HTTPS, a visitor uploads, sees only their own conversations, and deletes their library. The cookie it gets has SameSite=None, Secure, Partitioned, and HttpOnly, and deleting it sends Max-Age=0 with Partitioned. The existing test still sees SameSite=Lax over HTTP.
  • The workflow's gather step was run locally on a copy of the repository. It produces the Space's README with valid front matter and only the files the image needs. The hf repos create and hf upload options were checked against huggingface_hub 1.32. The workflow itself first runs once this is merged and HF_SPACE and HF_TOKEN are set.

Checklist

  • uv run ruff check . and uv run ruff format --check . pass
  • uv run mypy passes
  • uv run pytest passes
  • No real exports, databases, or keys are included
  • CHANGELOG.md updated under Unreleased

A Hugging Face Space shows the app on huggingface.co inside a frame from
hf.space, a different site. Browsers drop SameSite=Lax cookies there, so
every uploaded file started a new library and the import found an empty
batch. Over HTTPS the cookie is now SameSite=None, Secure, and Partitioned,
which keeps it apart for each site that frames the demo. The X-ChatLore
header still guards every change. Starlette only writes Partitioned on
Python 3.14, so the header is written directly, and removed with the same
attributes since a partitioned cookie is only replaced by one.
A free Space builds the existing Dockerfile and keeps the container running
with a disk, which visitors' libraries and background imports need. The
workflow uploads only what the image builds from, with a README whose front
matter configures the Space, and creates the Space on the first run. It runs
for every released version and on request, and is skipped until HF_SPACE is
set, so forks are not affected.
@cl0ver012
cl0ver012 merged commit cc9491f into main Oct 1, 2026
8 checks passed
@cl0ver012
cl0ver012 deleted the feat/m9-deploy-space branch October 1, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant