Skip to content

Add owner-bound cloud workers and remote Fetch - #29

Draft
georgewhewell wants to merge 16 commits into
masterfrom
codex/cloud-workers
Draft

georgewhewell wants to merge 16 commits into
masterfrom
codex/cloud-workers

Conversation

@georgewhewell

@georgewhewell georgewhewell commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Deployed workers need a durable association with the Hellas identity that launched them. This adds Runpod provisioning, an inventory of owned cloud and bare-metal machines, and owner-authenticated administration and remote machine selection to the main CLI.

  • hellas cloud runpod --account NAME list|info|create|destroy supports environment and credential-command profiles. Creation resolves a digest-pinned template, preserves creator attribution, and verifies the allocated template and image. --interruptible requests spot capacity; on-demand is the default. Dry runs are offline. Missing account setup displays the Foundation referral link in CLI and internal-RPC errors.
  • hellas fetch|llm|gateway --machine NAME resolves an enrolled cloud worker or prepared bare-metal machine. Packaged Unix lean and Linux static CLIs include cloud management. The HTTP gateway's paid-pool mode requires --paid-work-config and rejects --machine; inventory selection does not create payment channels.
  • hellas-agent binds to one owner and refuses reassignment. Administration uses authenticated iroh; serve --owner restricts incoming Hellas RPC. machines configure delivers routes and credentials over that channel, validates before restarting, and preserves refreshed credentials across ordinary restarts. GUI/automation clients use the same operations through private Unix JSON-RPC. Inventory and receipts exclude upstream secrets.
  • CI publishes ordinary and managed network/CUDA/HIP images after its gates using the temporary CI token. Downloadable x86_64/ARM64 static and WASM Rust-library archives include checksums. Packaging fixes empty WASM archives and backports the musl UDP alignment fix, with real iroh enrollment checked during executable musl builds.

Managed images keep identity/content on the persistent volume and configuration/credentials on the container disk at /var/lib/hellas-private. Tested Runpod volumes ignored Unix directory permissions. After a provider stop/reset clears container storage, the owner must reinstall credentials; the persistent identity remains.

Rebased onto master ced53481 after #30 merged generic HTTPS. The PR uses that upstream implementation and retains both its CLI checks and the cloud integration checks. Local validation passes: 22 cloud tests, 185 CLI tests, the HTTP/machine argument check with and without node, Clippy for cloud and the relevant CLI feature sets, Rust/Nix formatting, and the explicit two-identity iroh integration covering ownership, private configuration, Fetch, gateway, and cache administration. Fresh PR CI is running.

Historical evidence: pre-rebase CI passed all checks and published six images. The older HTTPS acceptance revision and its CI produced the matched CLI/image used for nine live L4 checks, including template attribution, enrollment, private configuration, verified Fetch, gateway SSE, tool continuation, upstream errors, rejected WebSocket upgrade, and confirmed deletion. Those tests exercised the older direct HTTP gateway, not the newly merged paid gateway. Paid-pool cloud acceptance has not been run; the historical harness now rejects incompatible CLIs before allocation. The Foundation template still pins that tested historical image. A prior spot request returned HTTP 500 without allocation, so live spot capacity remains unconfirmed.

Ancillary publication, acceptance tooling, and documentation remain in the extras repository. Current limits: Unix management, software trust rather than measured boot, one owner without delegation/rotation, buffered HTTP request bodies, and no WebSocket upgrades. The management socket is separate from cache-control RPC.

@georgewhewell georgewhewell changed the title Add owner-bound cloud workers and publish managed images Add owner-bound cloud workers and remote Fetch Sep 24, 2026
@hellasbot

hellasbot commented Sep 25, 2026 •

Copy link
Copy Markdown

Hydra: passed

Head 1a04508f703a · Evaluation #191520 · Hydra jobset

All 39 builds passed.

georgewhewell added a commit that referenced this pull request Sep 28, 2026
Extend Fetch to signed HTTPS exchanges and let native API clients use
standard HTTP endpoints backed by funded work channels. The gateway
selects an account from the requested model, preserves the upstream
response, and completes payment through the existing channel protocol.

### Behavior

- Add a shared Fetch work profile alongside Evaluate, with SDK sessions,
provider admission, authenticated streaming and restart recovery. The
reusable SDK paid pool serves both the CLI and Gate; client and provider
features are separate, with typed configuration and errors. The provider
invokes upstream only after accepting the signed job against its funded
channel, credit and route policy. The HTTP gateway requires a paid pool;
SDK Fetch providers configured for paid work advertise only Work and
WorkSetup.
- Carry HTTP methods, ordered queries, headers, encoded bodies, SSE and
non-2xx responses through Fetch. Restrict provider-owned credentials by
origin, path and method. Reuse upstream HTTPS and authenticated
Work/WorkSetup connections, preserve streaming backpressure, and keep
paid RPCs open through slow responses and idle connections. Accepted
jobs queue under provider capacity pressure instead of becoming
permanent failures.
- Start transparent HTTP through dedicated `HttpGatewayOptions` with a
required paid backend; tokenizer, inference-cache and Evaluate settings
are absent. Route standard API paths by model across configured
accounts. Pin existing sessions to their account, share capacity and
cooldown for credential aliases, and direct new sessions toward
available backends.
- Archive gateway exchanges by default, with per-request or gateway-wide
ZDR opt-out. Archive failures report telemetry while serving continues.
Fetch payment journals retain accounting, hashes and signatures without
payloads. Recovery pays verified deliveries from retained evidence,
retransmits certificates idempotently, and skips lost payloads without
re-executing them. Compressed requests receive the same ZDR retention
checks as uncompressed requests.
- Keep validator reads in independent channel observers. Provider
connections verify the configured genesis before advancing payment
state. Short journal locks order closes and new signatures; stale
observations stop new exposure, while retained certificates remain
retransmittable. Established-channel requests perform no consensus RPCs.

### Validation

At `d9407a2d`, all local gates invoked by `nix run .#check` have passed
across the aggregate runs and resumed checks: workspace and
feature-specific strict Clippy, formatting and dependency checks,
kernel/model, validator, RPC/work/client, SDK, HTTP/provider/storage,
and WebAssembly builds. The SDK suite has 33 tests, the gateway 66, and
the provider 70; the SDK client-only, provider-only and paid-gateway
feature sets are also linted independently.

The aggregate runs were not uninterrupted successes: one existing
gateway local-control request timed out, and two existing filesystem
tests exceeded their two-second limits. Their complete suites passed
unchanged on rerun. The final checks also caught and fixed provider
dependency ordering. A stale read-only zstd header in the local
WebAssembly build cache needed its write permission restored; this
required no source change.

Gate's integration passed `nix develop --command make check` (bindings,
TypeScript, frontend build, formatting, strict Clippy and 19 Rust
tests); the final form edits also passed `make ui-build`. See
hellas-ai/gate#586. These checks ran on Linux;
production Apple enrollment was not exercised.

`420f5e7e` fixes CLI tests that pinned superseded file-error wording and
adds `check-cli` to the aggregate local gate. `nix run .#check-cli`
passes all 179 tests, including the five that failed in the earlier
hosted builds; formatting and Nix lint checks also pass.

Hosted CI for the updated commit is queued:
https://github.com/hellas-ai/hellas/actions/runs/36457595760.

Regression coverage includes slow and idle paid streams, restart between
verified delivery and payment, duplicate payment recovery, payload-free
journals, paid-only protocol negotiation, genesis mismatch, bounded
queues under saturation, observer stalls, and close/payment ordering.
New coverage exercises the public HTTP entry point over a real socket,
credential injection over local TLS, authenticated connection reuse and
reconnect checks, and startup recovery without accidentally funding from
counter files alone. CI explicitly runs the SDK feature combinations and
HTTP/provider/storage suites.

Earlier live devnet passes through Kimi Code, Codex and Claude Code
completed their tool loops. Each pass produced six HTTP 200 exchanges
and six units of acknowledged payment. Exported token counters matched
response usage; all twelve established request traces contained zero
validator RPCs. These were smoke tests, not latency benchmarks or final
on-chain settlement tests.

### Review boundaries

Paid Fetch changes Work/WorkSetup wire descriptors and the StreamResult
schema. Gateways and providers must upgrade together; the on-chain
payment certificate format is unchanged.

Jobs within one funded channel finish in order. Generic HTTP streams
remain open through EOF. WebSocket upgrades and streaming uploads are
unsupported. ZDR controls application payload persistence; it does not
attest OS swap/dump handling or upstream retention. Explicitly
configured Courtesy HTTP routes still have no token-based spend
accounting; paid channels charge their agreed fixed job price.

This targets `master` independently of #29 (Runpod worker provisioning).
No stacking is required.

Configuration: [HTTP
gateway](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/docs/http-gateway.md),
[paid
gateway](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/docs/paid-gateway.md),
[HTTPS
provider](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/crates/providers/HTTPS.md).
Resolve cloud and bare-metal inventory from Fetch, LLM and gateway. Validate and install route configuration and credentials over owner-authenticated iroh and internal RPC, preserving refreshed credentials across restarts. Publish static and WASM-target build archives. Accommodate observed Codex SSE headers and explicitly discard new service metadata.
Allow the initial empty argument string and discard delta obfuscation metadata. Keep final JSON validation, declared-tool authorization and delta consistency checks. Cover the observed SSE lifecycle and malformed or inconsistent terminal arguments.
Retain generic machine selection and private configuration delivery. Keep legacy Codex compatibility experiments outside the cloud PR; acceptance will compose this branch with the generic HTTPS Fetch implementation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants