Files
Algis DumbrisandClaude Opus 4.7 069a985af5 feat(020): 14d window + token-budget circuit breaker + dream-agent + dashboard
Backend (Go, in this commit):
- migration 029_memory_dream_usage: per (date, owner) counters for
  tokens_in/out, jobs_started/succeeded/failed/circuit_broken
- DreamUsageStore + UsageGate (internal/messaging/dream_usage.go).
  Gate inspects today's usage against new env knobs:
  - SYNAPBUS_DREAM_RECENT_WINDOW (default 336h / 14d)
  - SYNAPBUS_DREAM_DAILY_TOKEN_LIMIT_IN (default 1M)
  - SYNAPBUS_DREAM_DAILY_TOKEN_LIMIT_OUT (default 200k)
  - SYNAPBUS_DREAM_DAILY_JOB_LIMIT (default 100)
- Consolidator now bounds watermarks + core_rewrite eligibility by the
  recency window. core_rewrite skipped for owners with no in-window
  activity. ForceRun honors the breaker.
- Recency fallback in BuildContextPacket + memory_list_unprocessed now
  accept RecentWindowDays so injection and dream queries see the same
  14d slice.
- Prometheus metrics registered (internal/metrics/metrics.go):
  synapbus_dream_jobs_total{owner,job_type,status},
  synapbus_dream_tokens_total{owner,direction},
  synapbus_dream_job_duration_seconds{owner,job_type},
  synapbus_dream_circuit_broken_total{owner,reason},
  synapbus_injection_packets_total{tool},
  synapbus_injection_memories_per_packet{tool},
  synapbus_injection_packet_chars{tool},
  synapbus_injection_skipped_total{tool,reason}.
- deploy/kubic/deployment.yaml: liveness/readiness timeoutSeconds: 1→5
  (root-causes the "connection refused" mcpproxy errors at 13:02 today —
  /readyz occasionally exceeded 1s under dream-worker tick load, so the
  pod fell out of the Service endpoints intermittently).

Dream-claude agent (Python, in /dream-agent/):
- dream_runner.py uses claude-agent-sdk 0.1.48 to drive Claude Code
  against SynapBus's MCP server. MCP transport carries
  Authorization: Bearer <api_key> AND X-Synapbus-Dispatch-Token from env
  via the SDK's McpHttpServerConfig.headers field — confirmed supported.
- Tools restricted via allowed_tools to mcp__synapbus__memory_*.
- Final JSON envelope reports tokens_in/out so harness.Usage stays
  populated and the circuit breaker can count consumption.
- Dockerfile builds linux/amd64 at 189 MB, mirroring searcher's
  agents/universal recipe.
- k8s-job-template.yaml: backoffLimit 0, ttl 600s, 512Mi/1CPU,
  Anthropic credentials via secret-ref.

Grafana dashboard (deploy/kubic/grafana/):
- dream-dashboard.json — 14 panels across 5 rows (dream activity,
  token usage vs limit, circuit breaker, injection layer, MCP
  transport health), all templated to ${DS_PROMETHEUS}.
- import.sh: resolves the cluster's Prometheus DS uid and POSTs the
  dashboard via Grafana API.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 13:58:28 +03:00

42 lines
1.6 KiB
Docker

# SynapBus dream-agent — slim Python container that runs Claude Code via
# claude-agent-sdk against SynapBus's MCP server. Built for linux/amd64.
#
# The proven recipe (per ~/repos/searcher/agents/universal/Dockerfile)
# is a single-stage image with `uv pip install --system`. Multi-stage
# saves little since claude-agent-sdk transitively pulls anyio/httpx,
# and the heavy bit (the `claude` CLI binary) ships inside the wheel as
# a JS bundle.
FROM python:3.12-slim
# Bring in `uv` from its official image. Pure binary, no apt.
COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv
# System deps: git (claude-agent-sdk shells out for some workspace ops),
# ca-certs + curl for TLS / health checks. Cleanup apt lists.
RUN apt-get update && \
apt-get install -y --no-install-recommends git ca-certificates curl && \
apt-get clean && rm -rf /var/lib/apt/lists/* && \
git config --global user.email "dream-agent@synapbus.dev" && \
git config --global user.name "SynapBus Dream Agent"
WORKDIR /app
# Pinned versions — keep aligned with pyproject.toml. claude-agent-sdk
# 0.1.48 bundles the `claude` CLI Node binary inside its wheel, so no
# separate `claude-code` install step is required.
RUN uv pip install --system --no-cache \
"claude-agent-sdk==0.1.48" \
"httpx>=0.27" \
"opentelemetry-api>=1.27" \
"opentelemetry-sdk>=1.27" \
"opentelemetry-exporter-otlp-proto-http>=1.27"
COPY dream_runner.py /app/dream_runner.py
# Non-root user (matches searcher convention)
RUN groupadd -g 1000 dream && useradd -u 1000 -g 1000 -m dream && \
chown -R dream:dream /app
USER dream
ENTRYPOINT ["python", "/app/dream_runner.py"]