Skip to content

FEATURE: Add the Cloudflare Queues worker boundary - #33

Open
bmdavis419 wants to merge 3 commits into
review/hosted-03-pg-portfrom
review/hosted-04-queue-foundation
Open

bmdavis419 wants to merge 3 commits into
review/hosted-03-pg-portfrom
review/hosted-04-queue-foundation

Conversation

@bmdavis419

@bmdavis419 bmdavis419 commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Add the typed Cloudflare Queues boundary: the generated Worker signs each batch, forwards it into the SvelteKit bundle, and applies per-message acknowledgment or retry decisions. Missing decisions retry; invalid jobs are acknowledged and logged. Operation handlers are connected in #36.

The internal endpoint limits streamed UTF-8 bytes before verifying the signature over the unchanged request text. Behavioral tests execute the generated facade and cover signatures, mixed decisions, missing decisions, and failed consumers.

Important files:

  • apps/web/scripts/cloudflare-adapter.mjs: queue entrypoint and signed forwarding.
  • apps/web/src/lib/server/jobs/consumer.ts: typed dispatch and per-message decisions.
  • apps/web/src/routes/api/internal/jobs/+server.ts: authenticated, bounded batch ingestion.
  • apps/web/src/lib/server/services/jobs.ts and apps/web/wrangler.jsonc: producer service and environment bindings.

Validation: TypeScript/Effect/Svelte checks; formatting; Worker build; final independent Codex review clean. Cloudflare delivery remains a deployment-time check.

Stack layer 5/12: depends on #32; followed by #34.

Note

Add Cloudflare Queues worker boundary for job delivery

  • Adds a Cloudflare Queue consumer that signs each batch with an HMAC and POSTs it to a new internal jobs endpoint. The endpoint verifies the timestamp and signature, then returns per-message ack-or-retry decisions (+server.ts, cloudflare-adapter.mjs).
  • Defines a shared JobSchema union (index, purge, scan, site-cleanup) and a JobQueue service that publishes JSON jobs through the JOBS binding (index.ts, jobs.ts).
  • Adds job dispatch in consumer.ts. Invalid job bodies are acked, dispatch failures are retried, and valid jobs are logged but not yet executed.
  • Configures producer and consumer queue bindings with batch size 5, 5-second batching, 5 retries, concurrency 10, and dead-letter queues; release docs cover provisioning (wrangler.jsonc, release.md).
  • Behavioral Change: runJob logs and acks all four job kinds without performing indexing, scanning, purging, or site-cleanup work.
📊 Macroscope summarized 83a750a. 13 files reviewed, 1 issue evaluated, 0 issues filtered, 1 comment posted

🗂️ Filtered Issues

RetriggerConfidence Score: 5/5

The outstanding configuration-drift concern is non-blocking.

Fix All in CodexFindings

  1. P2 Check queue configuration drift ▶
Fix with agent prompt
### Issue 1
scripts/check-wrangler-drift.mjs:184-189
This check reduces producers to binding names and does not compare producer destinations or any consumer configuration. A production queue can therefore use a different destination, retry limit, or consumer queue while this release check reports no drift. This is non-blocking, but it removes the intended deployment safeguard and can leave jobs routed or retried differently in production.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

This PR adds a Cloudflare Queues boundary: the Worker forwards job batches to an authenticated internal endpoint and receives per-message acknowledgment or retry decisions. The existing queue-configuration drift gap remains outstanding.

Reviews (3) · Last reviewed commit: "BUGFIX: Bound queue requests before sign..."

@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 94885843-fbe3-4222-8308-ba7bf2861adc

📥 Commits

Reviewing files that changed from the base of the PR and between 0477bda and 83a750a.

📒 Files selected for processing (14)
  • apps/web/scripts/cloudflare-adapter.mjs
  • apps/web/src/lib/server/cron-auth.ts
  • apps/web/src/lib/server/edge.ts
  • apps/web/src/lib/server/jobs/consumer.ts
  • apps/web/src/lib/server/layer.ts
  • apps/web/src/lib/server/request-json.ts
  • apps/web/src/lib/server/services/bindings.ts
  • apps/web/src/lib/server/services/jobs.ts
  • apps/web/src/routes/api/internal/jobs/+server.ts
  • apps/web/worker-configuration.d.ts
  • apps/web/wrangler.jsonc
  • docs/release.md
  • packages/shared/src/index.ts
  • scripts/check-wrangler-drift.mjs

Included review availability: This review used your included allowance. 6 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour.


📝 Walkthrough

Walkthrough

This change adds typed background jobs, queue producer and consumer services, an authenticated endpoint for queue batches, and Cloudflare queue configuration. The consumer validates job bodies and returns per-message acknowledgment or retry decisions. Queue setup and operation are documented.

Changes

Background Job Queue

Layer / File(s) Summary
Job contract and producer wiring
packages/shared/src/index.ts, apps/web/src/lib/server/services/bindings.ts, apps/web/src/lib/server/services/jobs.ts, apps/web/src/lib/server/edge.ts, apps/web/src/lib/server/layer.ts
Defines the index, scan, purge, and site-cleanup job variants. Adds the Jobs binding and JobQueue service, including live and no-op implementations, and wires the live service into request infrastructure.
Batch decoding and job decisions
apps/web/src/lib/server/jobs/consumer.ts
Adds batch and decision shapes. Invalid job bodies are logged and acknowledged. Successful jobs are acknowledged, and execution failures are logged and marked for retry. runJob logs supported job kinds without performing job-specific work.
Authenticated queue delivery
apps/web/src/lib/server/request-json.ts, apps/web/src/lib/server/cron-auth.ts, apps/web/routes/api/internal/jobs/+server.ts, apps/web/scripts/cloudflare-adapter.mjs
Adds bounded text reading, HMAC signing and verification for queue batches, and a POST endpoint that validates and consumes batches. The worker forwards batches and applies returned acknowledgment or retry decisions.
Queue deployment configuration
apps/web/wrangler.jsonc, apps/web/worker-configuration.d.ts, docs/release.md, scripts/check-wrangler-drift.mjs
Configures local and production queue producers and consumers, adds JOBS environment bindings, documents queue setup and operation, and checks producer binding names for configuration drift.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 83a75

The queue foundation does not currently redirect application work into the unfinished job handlers. No actionable merge-blocking issue remains after normal checks.

🚥 Pre-merge checks | ✅ 5

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The description clearly explains the Cloudflare Queues boundary, signed batch forwarding, job decisions, configuration, and validation.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding the Cloudflare Queues worker boundary.

Comment @coderabbitai help to get the list of available commands.

@bmdavis419
bmdavis419 added this pull request to stack #41 September 11, 2026 04:32
@bmdavis419
bmdavis419 force-pushed the review/hosted-04-queue-foundation branch from 31c4541 to 7efff9d Compare September 11, 2026 05:22
@bmdavis419
bmdavis419 marked this pull request as ready for review September 11, 2026 08:23
Comment on lines +184 to +189
const queueProducers = (block) => bindingNames(block.queues?.producers);
if (!sameJson(queueProducers(config), queueProducers(prod))) {
drift.push(
`queues.producers bindings: local=${JSON.stringify(queueProducers(config))} production=${JSON.stringify(queueProducers(prod))}`
);
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Check queue configuration drift

This check reduces producers to binding names and does not compare producer destinations or any consumer configuration. A production queue can therefore use a different destination, retry limit, or consumer queue while this release check reports no drift. This is non-blocking, but it removes the intended deployment safeguard and can leave jobs routed or retried differently in production.

Knowledge Base Used:

Artifacts

Evidence from the check

  • The authored Node script clones the current Wrangler configuration into temporary directories, applies one queue-only mutation per run, and invokes the real drift checker; it reproduces the unchecked queue values.

Command output from the check

  • The real checker was executed against an unmodified temporary copy of the current Wrangler configuration and exited successfully with no drift.

Command output from the check

  • The real checker was executed against three temporary copies differing only in a producer destination, consumer retry setting, or consumer destination, and it passed all three; queue configuration drift is not detected.

View artifacts

T-Rex Ran code and verified through T-Rex

Prompt To Fix With AI
This is a comment left during a code review.
Path: scripts/check-wrangler-drift.mjs
Line: 184-189

Comment:
**Check queue configuration drift**

This check reduces producers to binding names and does not compare producer destinations or any consumer configuration. A production queue can therefore use a different destination, retry limit, or consumer queue while this release check reports no drift. This is non-blocking, but it removes the intended deployment safeguard and can leave jobs routed or retried differently in production.

**Knowledge Base Used:**
- [Runtime configuration and schema](https://app.greptile.com/davis7dotsh/-/custom-context/knowledge-base/davis7dotsh/adrive/-/docs/runtime-configuration-and-schema.md)
- [Release, backup, and safety automation](https://app.greptile.com/davis7dotsh/-/custom-context/knowledge-base/davis7dotsh/adrive/-/docs/release-backup-and-safety-automation.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Codex

@bmdavis419
bmdavis419 force-pushed the review/hosted-04-queue-foundation branch from 7efff9d to d460dfd Compare September 11, 2026 08:50
bmdavis419 and others added 3 commits September 25, 2026 14:54
Declares the adrive-jobs queue (producer JOBS plus consumer with a
dead-letter queue) at the top level and in env.production, keeps the
producer bindings covered by the drift check, and regenerates the Worker
types. Adds the shared Job discriminated union and JobSchema, a JobQueue
service (with a null layer) in the request layer, and a consumer that
decodes each message, acks invalid bodies, and retries failed jobs. The
Worker facade forwards queue batches to /api/internal/jobs in-process
under an HMAC signed over the batch body, then acks or retries per
message from the endpoint's decisions. No behaviour moves onto the queue
yet; runJob only logs until D2/D3.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@bmdavis419
bmdavis419 force-pushed the review/hosted-04-queue-foundation branch from d460dfd to 83a750a Compare September 25, 2026 22:06
);
}
}
const queueProducers = (block) => bindingNames(block.queues?.producers);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium scripts/check-wrangler-drift.mjs:184

The drift check reports no difference when a producer keeps the same binding but points to a different queue, so production jobs can be routed to the wrong queue without failing validation. queueProducers currently discards each entry's queue; include both fields when comparing producers.

Suggested change
const queueProducers = (block) => bindingNames(block.queues?.producers);
const queueProducers = (block) =>
(block.queues?.producers ?? [])
.map((entry) => [entry.binding, entry.queue])
.sort();
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @scripts/check-wrangler-drift.mjs around line 184:

The drift check reports no difference when a producer keeps the same `binding` but points to a different `queue`, so production jobs can be routed to the wrong queue without failing validation. `queueProducers` currently discards each entry's `queue`; include both fields when comparing producers.

@bmdavis419
bmdavis419 removed this pull request from stack #41 September 25, 2026 22:08
@bmdavis419
bmdavis419 added this pull request to stack #43 September 25, 2026 22:08

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant