Skip to content

Commit 461acc2

Browse files
committed
Initial public release
Code Interpreter: sandboxed code execution service for AI agents — powers LibreChat's Code Interpreter. Published from the ClickHouse AI monorepo; subsequent changes arrive as snapshot sync pull requests via its publish workflow.
0 parents  commit 461acc2

268 files changed

Lines changed: 51308 additions & 0 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.dockerignore‎

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
# Documentation
2+
docs/
3+
*.md
4+
mkdocs.yml
5+
.readthedocs.yaml
6+
7+
# Tests
8+
tests/
9+
__tests__/
10+
*.test.js
11+
*.test.ts
12+
*.spec.js
13+
*.spec.ts
14+
15+
# Development files
16+
.vscode/
17+
.env
18+
.env.*
19+
!.env.example
20+
.envrc
21+
.git/
22+
.gitignore
23+
.gitattributes
24+
.prettierrc.yaml
25+
.prettierignore
26+
27+
# Docker files (not needed in build context)
28+
docker-compose*.yml
29+
docker-compose*.yaml
30+
Dockerfile*
31+
32+
# Build artifacts
33+
node_modules/
34+
dist/
35+
build/
36+
*.log
37+
npm-debug.log*
38+
yarn-debug.log*
39+
yarn-error.log*
40+
41+
# IDE
42+
.idea/
43+
*.swp
44+
*.swo
45+
*~
46+
47+
# OS files
48+
.DS_Store
49+
Thumbs.db
50+
51+
# Helm charts (not needed for Docker build)
52+
helm/
53+
54+
# Scripts not needed in production
55+
scripts/dev/
56+
scripts/test/
57+
58+
# Temporary files
59+
tmp/
60+
temp/
61+
*.tmp

‎.env.example‎

Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
# File Server Configuration
2+
FILE_SERVER_PORT=3000
3+
4+
# MinIO Configuration
5+
MINIO_BUCKET=minio_bucket_name
6+
MINIO_ENDPOINT=minio_endpoint
7+
MINIO_USE_SSL=TRUE
8+
MINIO_ACCESS_KEY=minio_access_key
9+
MINIO_SECRET_KEY=minio_secret_key
10+
MINIO_NO_PORT=TRUE
11+
12+
# Redis Configuration
13+
REDIS_HOST=redis_host
14+
REDIS_PASSWORD=redis_password
15+
16+
# Sandbox Configuration
17+
# macOS local dev: use COMPOSE_FILE=docker-compose.yaml:docker-compose.mac.yml
18+
KVM_ENABLED=true
19+
KVM_DEVICE_PATH=/dev/kvm
20+
SANDBOX_USE_CGROUPV2=true
21+
SANDBOX_LOG_LEVEL=DEBUG
22+
SANDBOX_MAX_PROCESS_COUNT=100
23+
SANDBOX_RUN_CPU_TIME=10000
24+
SANDBOX_RUN_TIMEOUT=15000
25+
SANDBOX_OUTPUT_MAX_SIZE=65536
26+
27+
# Service Configuration
28+
PYTHON_CONCURRENCY=5
29+
OTHER_CONCURRENCY=15
30+
JOB_WINDOW=1000
31+
32+
# Database Configuration
33+
MONGODB_URI=mongo_uri
34+
35+
36+
# Logging
37+
LOGGING_SERVER_IP=host.docker.internal
38+
39+
# -----------------------------------------------------------------------------
40+
# Stripe: https://shipfa.st/docs/features/payments
41+
# -----------------------------------------------------------------------------
42+
STRIPE_PUBLIC_KEY=
43+
STRIPE_SECRET_KEY=
44+
STRIPE_WEBHOOK_SECRET=
45+
46+
# -----------------------------------------------------------------------------
47+
# Mailgun: https://shipfa.st/docs/features/emails
48+
# -----------------------------------------------------------------------------
49+
# EMAIL_SERVER=smtp://postmaster@[mail.yourdomain.com]:[copied_password]@smtp.mailgun.org:587 (without the brackets)
50+
EMAIL_SERVER=
51+
52+
# Newsletter
53+
NEWSLETTER_SECRET=somesecretvalue
54+
55+
# api.librechat.ai
56+
LOGGING_ENABLED=true
57+
58+
SANDBOX_ACCESS_TOKEN=

‎.envrc‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
use_nix

‎.gitattributes‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
# Force git to be case-sensitive on case-insensitive filesystems
2+
* text=auto
3+
*.js text eol=lf
4+
*.ts text eol=lf
5+
*.yml text eol=lf
6+
*.yaml text eol=lf
7+
*.json text eol=lf
8+
*.md text eol=lf

‎.github/workflows/ci.yml‎

Lines changed: 96 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,96 @@
1+
# Standalone CI for the public ClickHouse/code-interpreter repo, which is
2+
# published from services/codeapi as snapshot commits (see
3+
# .github/workflows/publish-codeapi.yml in the monorepo). This file is
4+
# inert inside the monorepo — GitHub only runs workflows from the repo
5+
# root — and becomes the root workflow in the published repo. Keep it in
6+
# sync with ci-codeapi.yml.
7+
name: CI
8+
9+
on:
10+
push:
11+
# sync/** is included because the sync PR is opened by the GitHub Actions
12+
# bot, whose events don't trigger pull_request workflows — the push-event
13+
# runs on the branch satisfy the PR's checks instead.
14+
branches: [main, 'sync/**']
15+
pull_request:
16+
17+
concurrency:
18+
group: ci-${{ github.ref_name }}
19+
cancel-in-progress: true
20+
21+
jobs:
22+
api-unit-tests:
23+
name: API Unit Tests
24+
runs-on: ubuntu-latest
25+
defaults:
26+
run:
27+
working-directory: api
28+
steps:
29+
- uses: actions/checkout@v6
30+
31+
- uses: oven-sh/setup-bun@v2
32+
with:
33+
bun-version: 1.3.13
34+
35+
- name: Cache Bun packages
36+
uses: actions/cache@v5
37+
with:
38+
path: ~/.bun/install/cache
39+
key: ${{ runner.os }}-codeapi-api-bun-1.3.13-${{ hashFiles('api/bun.lock') }}
40+
restore-keys: |
41+
${{ runner.os }}-codeapi-api-bun-1.3.13-
42+
43+
- name: Install dependencies
44+
run: bun ci
45+
46+
- name: Build API
47+
run: bun run build
48+
49+
- name: Compile + smoke spec-guard
50+
# spec-guard.c is otherwise only compiled by api/Dockerfile, which
51+
# the helm workflow builds post-merge. Catching syntax errors and
52+
# exec-semantic regressions pre-merge prevents broken sandbox
53+
# binaries from reaching the image build.
54+
working-directory: api/src
55+
run: |
56+
gcc -O2 -static -Wall -Wextra -Werror -o /tmp/spec-guard spec-guard.c
57+
# Smoke: spec-guard must execvp its argument cleanly. Use a
58+
# parent process with a known FD population so we also assert
59+
# the close-inherited-FDs path runs (child must see only the
60+
# FDs `ls` itself opens).
61+
PARENT_FDS=$(bash -c 'exec 10<&0 11<&0 12<&0 13<&0 14<&0; ls /proc/self/fd | wc -l')
62+
CHILD_FDS=$(bash -c 'exec 10<&0 11<&0 12<&0 13<&0 14<&0; /tmp/spec-guard /bin/ls /proc/self/fd | wc -l')
63+
echo "parent fds (with 5 extra inherited): $PARENT_FDS"
64+
echo "child fds via spec-guard: $CHILD_FDS"
65+
test "$PARENT_FDS" -ge 8 || { echo "FAIL: parent did not actually inherit extra FDs"; exit 1; }
66+
test "$CHILD_FDS" -le 5 || { echo "FAIL: spec-guard did not close inherited FDs (child saw $CHILD_FDS)"; exit 1; }
67+
68+
- name: Bun tests
69+
run: bun run test
70+
71+
service-unit-tests:
72+
name: Service Unit Tests
73+
runs-on: ubuntu-latest
74+
defaults:
75+
run:
76+
working-directory: service
77+
steps:
78+
- uses: actions/checkout@v6
79+
80+
- uses: oven-sh/setup-bun@v2
81+
with:
82+
bun-version: 1.3.13
83+
84+
- name: Cache Bun packages
85+
uses: actions/cache@v5
86+
with:
87+
path: ~/.bun/install/cache
88+
key: ${{ runner.os }}-codeapi-service-bun-1.3.13-${{ hashFiles('service/bun.lock') }}
89+
restore-keys: |
90+
${{ runner.os }}-codeapi-service-bun-1.3.13-
91+
92+
- name: Install dependencies
93+
run: bun ci
94+
95+
- name: Bun tests
96+
run: bun run test

‎.github/workflows/open-sync-pr.yml‎

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
# Companion to the monorepo publish pipeline: snapshots arrive on the
2+
# sync/main branch (pushed via deploy key), and this workflow makes sure an
3+
# open pull request into main exists for them. Merging that PR is the
4+
# release step — main accepts no direct pushes.
5+
name: Open sync PR
6+
7+
on:
8+
push:
9+
branches: ['sync/main']
10+
11+
permissions:
12+
contents: read
13+
pull-requests: write
14+
15+
jobs:
16+
open-pr:
17+
runs-on: ubuntu-latest
18+
steps:
19+
- uses: actions/checkout@v6
20+
21+
- name: Open PR from sync/main if none exists
22+
env:
23+
GH_TOKEN: ${{ github.token }}
24+
run: |
25+
OPEN=$(gh pr list --head sync/main --base main --state open --json number --jq length)
26+
if [ "$OPEN" -gt 0 ]; then
27+
echo "Sync PR already open."
28+
exit 0
29+
fi
30+
gh pr create \
31+
--head sync/main --base main \
32+
--title "$(git log -1 --format=%s)" \
33+
--body "Automated snapshot sync from the internal monorepo. Merging this PR releases the changes to main. Commit trailers reference the source commits."

‎.gitignore‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
data/
2+
node_modules
3+
.env
4+
.git
5+
.npmrc
6+
/logs/**/*
7+
/file-server-logs/**/*
8+
/service-logs/**/*
9+
/tool-call-server-logs/**/*
10+
11+
# Helm artifacts
12+
helm/*/charts/*.tgz
13+
helm/*/Chart.lock
14+
15+
# Local sandbox runtime data (docker volume mount)
16+
data/
17+
18+
19+
# Editor config
20+
.vscode/

‎.prettierignore‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
node_modules
2+
data/

‎.prettierrc.yaml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
singleQuote: true
2+
tabWidth: 4
3+
arrowParens: avoid

‎CONTRIBUTING.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# Contributing
2+
3+
Thanks for your interest in Code Interpreter!
4+
5+
## How this repository is maintained
6+
7+
This repository is published from an internal ClickHouse monorepo, which is
8+
the source of truth. Every change that lands internally is mirrored here as a
9+
snapshot commit on the `sync/main` branch (spot them by the
10+
`Source: ClickHouse/ai@<sha>` trailer); a maintainer merges the resulting
11+
sync pull request to release it to `main`.
12+
13+
Practical consequences:
14+
15+
- **Pull requests are welcome.** CI runs on every PR. A maintainer reviews
16+
your change, imports it into the internal repository, and it arrives back
17+
with the next sync PR. We preserve attribution with a `Co-authored-by:`
18+
trailer — your PR will be closed with a reference to the sync that
19+
contains it.
20+
- **`main` accepts no direct pushes.** It only advances by merging sync pull
21+
requests; branch rules enforce this with no exceptions.
22+
- **History is snapshot-based.** Commits here intentionally do not mirror the
23+
internal commit history.
24+
25+
## Development
26+
27+
See the [README](README.md) for the architecture overview and
28+
`docker compose up --build` for a local stack. Component-level docs live in
29+
`api/`, `service/`, and `helm/codeapi/`.
30+
31+
## Reporting issues
32+
33+
Open a GitHub issue with reproduction steps. For suspected security issues,
34+
please do not open a public issue — contact the maintainers instead.

0 commit comments

Comments
 (0)