Skip to content

Draft: managed extensions, source inspection and themed Cloudflare marketplace - #1911

Draft
colbymchenry wants to merge 61 commits into
mainfrom
feature/extensions-author-kit-20260922
Draft

colbymchenry wants to merge 61 commits into
mainfrom
feature/extensions-author-kit-20260922

Conversation

@colbymchenry

@colbymchenry colbymchenry commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Projects can install framework extensions from a durable Cloudflare marketplace through an explicit local companion, select a compatible release and refresh their real graph. Managed operations preserve the previous graph/configuration on failure. This draft includes author tooling, signed immutable publication, official Drupal import and atomic recovery.

The exact-package source inspector verifies SHA-256 and identity, renders every bundled file as inert text and prevents reviewed-version substitution during compatibility/catalog races. Historical Drupal 0.1.0/0.1.1 and existing fixtures remain immutable. Source availability is not malware certification or reproducible-build proof.

Latest bounded change: CodeGraph theme and deployed source UI

Live: https://codegraph-marketplace-preview.colby-7d9.workers.dev

Catalog, detail, publisher, connection and source inspection now match CodeGraph's Archivo Variable / IBM Plex Mono, paper/ink palette, thin rules and square corners. The exact local asset build pins Lucide 0.468.0, Archivo 5.2.8 and IBM Plex Mono 5.2.7; it bundles only 26 used SVG icons and four WOFF2 files with license notices. Actual CodeGraph/Drupal marks are preserved. Icons use accessible text controls and currentColor. No runtime CDN or new service.

Tested source b4dcb40d92f9ea19bd5098b58c1115296d65eb60. Final local checks: 13 real workerd source-browser checks, 15 publisher/browser checks, 10 compatibility checks / 12 CLI commands, nine theme-browser checks, five marketplace HTTP tests, TypeScript compile and deterministic asset check. Includes nested SVG child actions, keyboard focus, 320/390px layouts, real managed graph/failure preservation and version-race safety.

One authorized UI-only deploy to version d87a4fa0-165e-4fb5-a6c7-96c4e0dd000a. The exact accepted Worker SHA-256 43dc01b6bd20160381d409c80ecd4f447ab6539a34890110e6dcad6684060561 remains unchanged. Before/after version resource objects match exactly: bindings, CPU1000, asset routing/CSP, compatibility and publishing=false. Existing observability/config retained. All 17 served static assets match SHA-256. Both main and detached restore health/catalog/Drupal metadata bodies are unchanged; live Drupal package digest is exact.

Nine actual live HTTPS theme-browser checks pass with no overlay, including loaded fonts/icons and digest-verified inert source inspection. Live screenshots are in the report. No new hosted installation or storage/load matrix claim: earlier hosted graph/provider acceptance is reused, current managed graph regression is local. Ten failed attempts and one interrupted pre-restart attempt are preserved; final serial runs passed without weakening assertions.

Theme report, live screenshots and exact receipts · Pinned assets and licenses

Source admission and budget boundary

General publishing remains disabled. The future hosted source gate is committed and locally tested at ca6c375, with an empty production approval list, but was not deployed in this UI-only rollout. It requires an operator review of identical package bytes in a public immutable GitHub commit, bound to publisher/id/version/digest. Portable Node admission remains local/legacy tooling. Historical repository claims remain explicitly unverified under this new policy. The prior expired-OAuth blocker was resolved through supported login before deployment.

Prior accepted source-budget tests: 11 policy, 21 Worker, 20 official-import (two mocked remote contracts), four deadline, 18 operator guards and 16 shared tests; real unauthenticated GitHub review matched Drupal 0.1.0 bytes. These unaffected checks were reused at their original source.

The model for 500–1,000 downloads/day, an equal number of source views and few uploads fits the existing $5 base only if shared allowances remain available. It is not a hard cap or total-account invoice promise. Unrelated services, growth, logging and taxes remain separate. This rollout adds self-hosted static files served before the Worker, with no resource/billing/plan changes. Free static fallback and owner-only alert proposals remain documented, not activated.

Source/budget evidence · Cost assumptions and source-review procedure

Reused hosted and engine evidence

  • Detached restore remains read-only at https://codegraph-marketplace-preview-restore-20260922.colby-7d9.workers.dev; no redeployment/cutover.
  • Prior actual HTTPS official Drupal proof: eight checkpoints and four asserted Pathauto links. Compatibility ten / 14 CLI commands; publisher/browser 15. One connection/Install, updates, disable/removal and failure preservation passed.
  • Prior provider redeployment/detached restore preserved 17 releases, eight owners, registry identity and 17 objects / 8,742,210 bytes. No repeat large-package or restore matrix in this increment.
  • Prior 8 MiB publication used 379 ms CPU; downloads 22/26/20 ms. Free's 10 ms budget remains unsuitable for that measured contract. Peak deployed memory, concurrent headroom and independent retention remain open.
  • Core graph engine source 7575dcc remains unchanged. Prior Linux at e0885ee: 4,577 passed / 192 skipped, all 284 files once; Windows162/4 skips and macOS165/1, recovery/corpus evidence retain original revisions. They were reused, not presented as current-head CI. This increment's only src change is bounded static asset delivery in the portable Node marketplace.

Original hosted evidence

Keep general publication closed. Shared-account review, source-policy rollout, independent backup retention/RPO/RTO, pagination beyond1,000, fixture cleanup, memory/concurrency and distribution remain open. Deliberate incompatible/broken fixtures remain. Global semantic/full-candidate costs persist; selective skipping is still a no-go, with historical22–30% and mixed warm/cold performance retained. No DNS/custom domain, production merge, release or npm publication.

Evidence HEAD: 59009c5c6c451f60c558007dbb4fc17fce9f5162; final commit changes report/ledger/screenshots only.

@colbymchenry colbymchenry changed the title Add managed framework extensions, Drupal preview and local marketplace Add managed framework extensions, author kit and local marketplace preview Sep 22, 2026
@colbymchenry colbymchenry changed the title Add managed framework extensions, author kit and local marketplace preview Add managed framework extensions, compatible marketplace installs, and author SDK Sep 22, 2026
@colbymchenry colbymchenry changed the title Add managed framework extensions, compatible marketplace installs, and author SDK Add managed extensions with author tooling, compatible installs, and recovery Sep 22, 2026
@colbymchenry colbymchenry changed the title Add managed extensions with author tooling, compatible installs, and recovery Add managed extensions, author tooling and durable marketplace registry Sep 22, 2026
@colbymchenry colbymchenry changed the title feat: managed framework extensions and Cloudflare marketplace registry Draft: managed framework extensions, Cloudflare marketplace and atomic semantic updates Sep 22, 2026
@colbymchenry colbymchenry changed the title Draft: managed framework extensions, Cloudflare marketplace and atomic semantic updates Draft: managed extensions and a durable Cloudflare marketplace preview Sep 22, 2026
@colbymchenry colbymchenry changed the title Draft: managed extensions and a durable Cloudflare marketplace preview Draft: managed extensions, inspectable source and Cloudflare marketplace preview Sep 23, 2026
@colbymchenry colbymchenry changed the title Draft: managed extensions, inspectable source and Cloudflare marketplace preview Draft: managed extensions, source inspection and themed Cloudflare marketplace Sep 23, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant