Skip to content

Speed up macOS VM rebuilds and add a --no-secrets opt-out - #47

Merged
DimmKirr merged 4 commits into
mainfrom
feature/wip
Sep 21, 2026
Merged

DimmKirr merged 4 commits into
mainfrom
feature/wip

Conversation

@DimmKirr

@DimmKirr DimmKirr commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

macOS (tart) VM rebuilds now finish in a fraction of the time: cell build --stage=base bakes a reusable base template once, and full builds clone from it locally instead of re-pulling from the OCI registry. Users can also fully opt out of secrets injection with --no-secrets (old --no-1password kept as alias), typo'd subcommands now fail loudly with help instead of silently feeding the default agent, and the marketing site copy was reworked around the "agent's own computer" framing.

Breaking changes

  • Unknown positional arguments are no longer forwarded to the default command: cell <word> for an unrecognized <word> now errors with help instead of launching the default agent with it as input. Pass positional input by naming the command explicitly (e.g. cell claude <input>).
  • --no-1password (and DEVCELL_NO_1PASSWORD) now also suppress the op run -- prefix, not just the document lookup. If a workflow relied on op run env injection while skipping documents, drop the flag and control documents via [op] config instead.
  • In tart VMs the project is now mounted at its host-mirrored path instead of ~/<basename> — scripts that hard-coded the old in-VM path need updating.

Changes

  • feat(build): add --stage=base|full to cell build for the tart engine — full builds clone locally from the base template, so repeat builds skip the OCI pull (--update now implies --force)
  • feat(tart): self-heal broken VM templates at start — repair the shadowed /nix mount and re-activate nix-darwin/s6 when missing
  • feat(tart): share the host's /nix store into the VM as a read-only substituter and mount the project at its host-mirrored path — fewer downloads from cache.nixos.org, paths match between host and VM
  • fix(runner): give each app its own thin-builder container name and reclaim only crashed/orphaned builders, never a running one — concurrent builds no longer kill each other
  • feat(cmd): add --no-secrets / --skip-secrets flags and DEVCELL_NO_SECRETS env var, keeping --no-1password / DEVCELL_NO_1PASSWORD as aliases — opting out now skips secrets injection entirely
  • fix(cmd): unknown subcommands print help plus an "unknown command" error instead of running as default-command input
  • docs(web): rework site copy — merge stacks into one 6-stack comparison (dropping Electronics & DIY), consolidate feature cards into "gains"/"boundary", rewrite hero and trim the FAQ
  • build(darwin): add a no-cgo stub for the Vision OCR helper so non-darwin builds compile, plus Taskfile targets for tart integration tests and nix diagnostics
  • chore(deps): bump go.mod/go.sum and flake.nix vendorHash; pin @astrojs/cloudflare in web/package-lock.json

…as default-command input

- fix(cmd): stop rewriting unrecognized positionals into default-command args — typo'd subcommands like `cell abc` fail loudly instead of running silently
- fix(cmd): rootCmd.RunE prints help alongside the "unknown command" error — users see valid subcommands right where the failure occurs
- test(cmd): cover unrewritten unknown positionals and rootCmd.RunE's help+error output — locks in the new failure behavior against regressions
- feat(cmd): add --no-secrets/--skip-secrets flags, keep --no-1password as alias — old scripts keep working, new names are clearer
- feat(runner): thread NoSecrets through RunSpec to also suppress `op run --` — opting out now skips secrets fully, not just item lookup
- refactor(op): reword ShouldResolve docs for the generalized flag/env names — no user-facing impact
- test(runner): cover that NoSecrets suppresses the op argv prefix — catches regressions in the opt-out path
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
devcell b8ac1a0 Commit Preview URL

Branch Preview URL
Sep 21 2026, 06:47 AM

…cleanup no longer kills active builds

- feat(build): add --stage=base|full so full builds clone locally from a base template — repeat builds skip the OCI pull
- feat(tart): repair pre-fix templates' shadowed /nix mount and re-activate nix-darwin/s6 when missing — session start self-heals broken VMs
- feat(tart): share host's /nix store into the VM as a read-only substituter when detected — fewer packages fetched from cache.nixos.org
- fix(runner): reclaim only a crashed/orphaned thin-builder container, never one still running — concurrent builds for other apps stay untouched
- feat(tart): mount the project at its host-mirrored path instead of ~/basename — paths match between host and VM
- build(darwin): add stub OCR module for non-darwin builds and Taskfile targets for tart integration tests and nix diagnostics — no user-facing change
- chore(deps): bump go.mod/go.sum and flake.nix vendorHash for the above — no user-facing change
…trim FAQ

- feat(web/whatsinside): merge stack table into one 6-stack comparison, dropping the Electronics & DIY (KiCad/ngspice/ESPHome) row — visitors compare fewer, more accurate stacks
- refactor(web/featurecards): split "Why" into "gains"/"boundary" sections, merging the stealth-browser and MCP-server rows into two consolidated cards — fewer, denser feature blocks to scan
- docs(web/hero): rewrite headline and terminal demo around "agent's own computer" framing — visitors get sharper positioning on first load
- docs(web/quickstart): note Claude Max/Pro/API keys all work in step 2 — answers a licensing question before the FAQ
- docs(web/faq): drop the Vagrant/native-macOS and cell-login Q&As, folding their content into other answers — fewer redundant entries, same coverage
- docs(web/base): rename nav anchor to "What it gains"/"The boundary" and update page title/description to match new copy — nav links resolve to the right sections
- chore(web/deps): pin @astrojs/cloudflare to "12" instead of "^12.6.13" in package-lock.json — locks the exact resolved version for reproducible builds
@DimmKirr DimmKirr changed the title Add --no-secrets opt-out and fail loudly on unknown subcommands Speed up macOS VM rebuilds and add a --no-secrets opt-out Sep 21, 2026
@DimmKirr
DimmKirr merged commit 7fd88a4 into main Sep 21, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant