feat: Adding client-proxy and clickhouse to e2b-artifacts - #3210
Conversation
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
There was a problem hiding this comment.
Code Review
This pull request configures release-please for the client-proxy and clickhouse packages and updates their Makefiles to support pulling prebuilt, versioned images from an E2B artifacts registry when a version variable is provided. However, a critical syntax error was identified in packages/client-proxy/Makefile where the ifeq conditional directive is incorrectly placed inside the target's recipe, which will cause GNU Make to fail. A fix has been suggested to structure the conditional block outside of the target definition.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
❌ 5 Tests Failed:
View the top 3 failed test(s) by shortest run time
View the full list of 1 ❄️ flaky test(s)
To view more test analytics, go to the Test Analytics Dashboard |
There was a problem hiding this comment.
LGTM — mirrors the existing docker-reverse-proxy release-please pattern for two more images.
Extended reasoning...
Overview
This PR extends the existing release-please onboarding (originally set up for docker-reverse-proxy) to two more packages: packages/client-proxy and packages/clickhouse. It touches five files: adds two new publish jobs to .github/workflows/release-please.yml, seeds two entries in .release-please-manifest.json, registers both packages in release-please-config.json, and adds a CLIENT_PROXY_VERSION / CLICKHOUSE_MIGRATOR_VERSION released-image hook to each package's Makefile. All changes are mechanical copies of the established pattern.
Security risks
None material. The new workflow jobs reuse the same WIF provider and publisher service account (E2B_ARTIFACTS_WIF_PROVIDER / E2B_ARTIFACTS_PUBLISH_SA) that were vetted for the docker-reverse-proxy publish job, with the same persist-credentials: false checkout and the same --provenance=false --sbom=false Artifact Registry compatibility flags. The Makefile change is guarded on an opt-in env var and defaults to the existing source-build path.
Level of scrutiny
Low. This is CI/CD plumbing and build-tooling, not production runtime code. It doesn't touch auth, request handling, sandbox logic, or database access. The released-image Makefile hook is opt-in and default-off, so the existing source-build path for all self-hosters is unchanged. The workflow jobs only fire on release-please tag creation, gated on *_released == 'true'.
Other factors
The three findings from the bug-hunting pass are all explicitly nits: a hardcoded linux/amd64 platform that mirrors the publish job (moot until multi-arch publish is added), missing .env.*.template entries for the new version-hook variables (docs discoverability), and a telemetry-version constant that won't match release tags (observability data quality only). None are merge-blocking, and the inline comments already document them for follow-up. The pattern being extended has one prior successful merge (docker-reverse-proxy).
| { | ||
| "packages/docker-reverse-proxy": "0.2.2" | ||
| "packages/docker-reverse-proxy": "0.2.2", | ||
| "packages/client-proxy": "0.0.0", |
There was a problem hiding this comment.
🟡 The client-proxy's telemetry version won't match the release tag. packages/client-proxy/main.go:45 hardcodes const version = "1.2.0", but the release-please manifest starts at 0.0.0 — the first release will produce tags like v0.0.1/v0.1.0 while every published image reports telemetry version 1.2.0. Either seed the manifest at 1.2.0, or wire VERSION through Dockerfile/Makefile/workflow like docker-reverse-proxy does (change const→var, add -X=main.version= ldflag, add ARG VERSION to Dockerfile, pass --build-arg VERSION="${IMAGE_TAG}" in the publish job).
Extended reasoning...
The mismatch
packages/client-proxy/main.go:45 declares:
const (
serviceName = "client-proxy"
// ...
version = "1.2.0"
)and main.go:63 passes it to telemetry:
tel, err := telemetry.New(ctx, nodeID, serviceName, commitSHA, version, instanceID)This PR seeds .release-please-manifest.json with "packages/client-proxy": "0.0.0". On the first release, release-please will therefore produce a tag like client-proxy-v0.0.1 or client-proxy-v0.1.0, and the new publish-client-proxy job in .github/workflows/release-please.yml will push an image tagged v0.0.1 (or similar). That image's telemetry, however, will report version="1.2.0" forever.
Why the existing plumbing doesn't fix it
packages/client-proxy/Makefile build target has -ldflags "-X=main.commitSHA=$(COMMIT_SHA)" — it stamps only commitSHA, not version. And even if the ldflag were added, version is a const (not a var), so -X main.version=... would silently do nothing. packages/client-proxy/Dockerfile accepts ARG COMMIT_SHA but has no ARG VERSION. The new publish-client-proxy job passes --build-arg COMMIT_SHA but no --build-arg VERSION.
Contrast with the sibling pattern this PR copies
The publish-reverse-proxy job in the same workflow does thread the version through end-to-end:
packages/docker-reverse-proxy/main.godeclaresvar version = "dev"(avar, stamped via ldflags).- Its
Makefilehas-X=main.version=$(VERSION). - Its
DockerfilehasARG VERSION=devand passesVERSION=${VERSION}tomake build. - The workflow passes
--build-arg VERSION="${IMAGE_TAG}".
The client-proxy publish job omits that last piece and the underlying plumbing was never added.
Step-by-step proof
- Someone merges a
feat:commit that touchespackages/client-proxy/. - release-please opens the release PR bumping
packages/client-proxyfrom0.0.0to0.1.0. - Release PR merges; workflow tags
client-proxy-v0.1.0and triggerspublish-client-proxywithVERSION=0.1.0. - The job runs
docker buildx build ... --tag us-docker.pkg.dev/e2b-artifacts/client-proxy/client-proxy:v0.1.0 ...(no--build-arg VERSION). - Inside the container, Go binary was compiled with
const version = "1.2.0". - Container starts, calls
telemetry.New(..., serviceName, commitSHA, "1.2.0", instanceID). - Grafana/Tempo/etc. see
service.version=1.2.0on a v0.1.0 image. Debugging "which release is prod on" gets confusing.
Impact and fix
Telemetry data-quality only — nothing crashes and the proxy works correctly. Two fixes, either works:
- Cheap: bump
.release-please-manifest.jsonentry forpackages/client-proxyto"1.2.0", so the first release-please tag isv1.2.1/v1.3.0. - Aligned with docker-reverse-proxy: flip
const version = "1.2.0"tovar version = "dev", add-X=main.version=$(VERSION)to the client-proxy Makefile ldflags, addARG VERSIONtopackages/client-proxy/Dockerfile, and pass--build-arg VERSION="${IMAGE_TAG}"inpublish-client-proxy.
(clickhouse-migrator has no comparable in-binary version constant so it isn't affected.)
🤖 I have created a release *beep* *boop* --- ## 1.0.0 (2026-07-07) ### Features * Adding client-proxy and clickhouse to e2b-artifacts ([#3210](#3210)) ([5686d88](5686d88)) * **api:** LD-gated ClickHouse read switcher ([#3061](#3061)) ([29e74ca](29e74ca)) * **clickhouse:** implement multi-cluster fan-out for events and stats ([#2925](#2925)) ([39594c6](39594c6)) * **migrations:** add webhook deliveries table to ClickHouse ([#2741](#2741)) ([f55a5bd](f55a5bd)) * **orchestrator:** LD-gated ClickHouse write fan-out feature flag ([#3152](#3152)) ([f046fcf](f046fcf)) * **orch:** re-enable memory.peak per-FD reset (cgroups v2) ([#2430](#2430)) ([5d9ac5f](5d9ac5f)) * per-team events TTL limit (tier + addons) ([#3181](#3181)) ([f76b2cb](f76b2cb)) ### Bug Fixes * push clickhouse-migrator image to both latest and commit SHA tags ([#2954](#2954)) ([3b780d5](3b780d5)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: e2b-release-please[bot] <298072688+e2b-release-please[bot]@users.noreply.github.com>
🤖 I have created a release *beep* *boop* --- ## 1.0.0 (2026-07-07) ### Features * Adding client-proxy and clickhouse to e2b-artifacts ([#3210](#3210)) ([5686d88](5686d88)) ### Bug Fixes * **local-dev:** rename API_GRPC_ADDRESS to API_INTERNAL_GRPC_ADDRESS in local dev env ([#2589](#2589)) ([6c0bcb1](6c0bcb1)) * push client-proxy, dashboard-api, and docker-reverse-proxy image… ([#2953](#2953)) ([1d930ee](1d930ee)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: e2b-release-please[bot] <298072688+e2b-release-please[bot]@users.noreply.github.com> Co-authored-by: Charlie Wyse <charlie.wyse@e2b.dev>
🤖 I have created a release *beep* *boop* --- ## 1.0.0 (2026-07-07) ### Features * Adding client-proxy and clickhouse to e2b-artifacts ([#3210](#3210)) ([5686d88](5686d88)) ### Bug Fixes * **local-dev:** rename API_GRPC_ADDRESS to API_INTERNAL_GRPC_ADDRESS in local dev env ([#2589](#2589)) ([6c0bcb1](6c0bcb1)) * push client-proxy, dashboard-api, and docker-reverse-proxy image… ([#2953](#2953)) ([1d930ee](1d930ee)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: e2b-release-please[bot] <298072688+e2b-release-please[bot]@users.noreply.github.com>
🤖 I have created a release *beep* *boop* --- ## 0.0.1 (2026-07-10) ### Features * Adding client-proxy and clickhouse to e2b-artifacts ([#3210](#3210)) ([5686d88](5686d88)) ### Bug Fixes * correct 3 CVES ([#3218](#3218)) ([076823b](076823b)) * **local-dev:** rename API_GRPC_ADDRESS to API_INTERNAL_GRPC_ADDRESS in local dev env ([#2589](#2589)) ([6c0bcb1](6c0bcb1)) * push client-proxy, dashboard-api, and docker-reverse-proxy image… ([#2953](#2953)) ([1d930ee](1d930ee)) * reset artifacts ([#3259](#3259)) ([93f7eb5](93f7eb5)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: e2b-release-please[bot] <298072688+e2b-release-please[bot]@users.noreply.github.com> Co-authored-by: Charlie Wyse <charlie.wyse@e2b.dev>
🤖 I have created a release *beep* *boop* --- ## 0.0.1 (2026-07-10) ### Features * Adding client-proxy and clickhouse to e2b-artifacts ([#3210](#3210)) ([5686d88](5686d88)) * **api:** LD-gated ClickHouse read switcher ([#3061](#3061)) ([29e74ca](29e74ca)) * **clickhouse:** implement multi-cluster fan-out for events and stats ([#2925](#2925)) ([39594c6](39594c6)) * **migrations:** add webhook deliveries table to ClickHouse ([#2741](#2741)) ([f55a5bd](f55a5bd)) * **orchestrator:** LD-gated ClickHouse write fan-out feature flag ([#3152](#3152)) ([f046fcf](f046fcf)) * per-team events TTL limit (tier + addons) ([#3181](#3181)) ([f76b2cb](f76b2cb)) ### Bug Fixes * correct 3 CVES ([#3218](#3218)) ([076823b](076823b)) * push clickhouse-migrator image to both latest and commit SHA tags ([#2954](#2954)) ([3b780d5](3b780d5)) * reset artifacts ([#3259](#3259)) ([93f7eb5](93f7eb5)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: e2b-release-please[bot] <298072688+e2b-release-please[bot]@users.noreply.github.com> Co-authored-by: Charlie Wyse <charlie.wyse@e2b.dev>
🤖 I have created a release *beep* *boop* --- ## 0.0.1 (2026-07-11) ### Features * Adding client-proxy and clickhouse to e2b-artifacts ([#3210](#3210)) ([5686d88](5686d88)) ### Bug Fixes * added changelog file to trigger client-proxy buld ([#3268](#3268)) ([70b0ee9](70b0ee9)) * correct 3 CVES ([#3218](#3218)) ([076823b](076823b)) * **local-dev:** rename API_GRPC_ADDRESS to API_INTERNAL_GRPC_ADDRESS in local dev env ([#2589](#2589)) ([6c0bcb1](6c0bcb1)) * push client-proxy, dashboard-api, and docker-reverse-proxy image… ([#2953](#2953)) ([1d930ee](1d930ee)) * reset artifacts ([#3259](#3259)) ([93f7eb5](93f7eb5)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: e2b-release-please[bot] <298072688+e2b-release-please[bot]@users.noreply.github.com>
No description provided.