ktx/scripts/check-boundaries.mjs
Andrey Avtomonov 9dad936ac7
feat: npm-managed Python runtime for @kaelio/ktx (#7)
* docs: add npm managed python runtime design

* build: add bundled python runtime wheel builder

* build: make local embedding dependencies optional

* build: bundle python runtime wheel in cli artifacts

* build: track bundled python runtime release artifact

* test: verify bundled python runtime wheel

* docs: add plan for bundled python runtime wheel

* test: cover managed python runtime lifecycle

* feat: add managed python runtime installer

* feat: add runtime command runner

* feat: expose runtime management commands

* test: verify managed python runtime commands

* docs: add plan for managed python runtime installer

* feat: add managed python command helper

* feat: use managed runtime for sl query compute

* feat: route sl query managed runtime policy

* docs: add plan for managed runtime sl query integration

* feat: add managed runtime daemon metadata

* feat: manage python daemon lifecycle

* feat: add runtime daemon start stop commands

* fix: verify managed runtime daemon lifecycle

* docs: add plan for managed runtime daemon lifecycle

* feat: add managed local embeddings config marker

* feat: add managed local embeddings daemon helper

* feat: use managed runtime for local embedding setup

* feat: pass managed runtime policy through setup

* docs: add plan for managed local embeddings runtime

* feat: read CLI package metadata dynamically

* feat: assemble public kaelio ktx npm package

* feat: release one public kaelio ktx npm artifact

* test: cover public kaelio ktx package invocations

* chore: verify public kaelio ktx package artifacts

* docs: add plan for public kaelio ktx npm package

* test: verify managed runtime in public package smoke

* test: finalize managed runtime release smoke

* docs: add plan for managed runtime release smoke

* test: specify local embeddings release smoke

* feat: add local embeddings runtime smoke

* chore: register local embeddings smoke

* fix: verify local embeddings smoke

* fix: restore artifact smoke python env helper

* docs: add plan for managed local embeddings release smoke

* refactor: share managed runtime install policy parsing

* feat: use managed runtime for agent semantic queries

* feat: use managed runtime for MCP semantic compute

* docs: add plan for managed agent and MCP semantic runtime

* feat(cli): add managed daemon HTTP helpers

* feat(cli): route local adapters through managed daemon

* feat(cli): use managed daemon for ingest helpers

* feat(cli): pass managed daemon options to scan

* feat(context): pass MCP ingest pull config options

* feat(cli): pass managed daemon options to serve ingest

* test: verify managed local ingest daemon runtime

* docs: add plan for managed local ingest daemon runtime

* docs: align managed runtime examples

* docs: add plan for managed runtime docs cleanup

* test: cover published package runtime smoke commands

* test: validate published package smoke outputs

* docs: add plan for published package runtime smoke

* build: stamp public npm package version

* release: add npm public release policy

* release: add guarded npm publish script

* release: document public npm release handoff

* docs: add plan for public npm release handoff

* test: cover managed runtime prune in package smoke

* docs: document managed runtime prune

* docs: add plan for managed runtime prune smoke and docs

* chore: encode uv runtime prerequisite policy

* fix: clarify missing uv runtime error

* docs: document uv runtime prerequisite

* docs: add plan for uv runtime prerequisite contract

* refactor: limit release artifacts to public package runtime

* chore: align release policy with bundled runtime wheel

* docs: describe single public runtime artifact surface

* test: verify single public runtime artifact contract

* docs: add plan for single public runtime artifact cleanup

* fix: align local embeddings smoke with public version

* docs: add plan for local embeddings smoke public version

* release: soft-launch as @kaelio/ktx@0.1.0-rc.0 on next tag

Publish target moves to the pre-release version 0.1.0-rc.0 under the next
dist-tag so npm install @kaelio/ktx (which resolves to latest) does not
pick up the soft-launch build. Users opt in via @kaelio/ktx@next.

* Fix release script boundary checks

* Remove PostHog from public package bundle
2026-05-11 15:50:34 +02:00

225 lines
6.5 KiB
JavaScript

#!/usr/bin/env node
import { readdir, readFile } from 'node:fs/promises';
import path from 'node:path';
import { fileURLToPath, pathToFileURL } from 'node:url';
const codeExtensions = new Set(['.ts', '.tsx', '.js', '.jsx', '.mjs', '.cjs', '.py']);
const runtimeAssetPatterns = [/^packages\/[^/]+\/prompts\/.+\.md$/, /^packages\/[^/]+\/skills\/.+\.md$/];
const identifierSkipPrefixes = ['docs/', 'examples/', 'python/ktx-sl/plans/', 'python/ktx-sl/openspec/'];
const identifierAllowPatterns = [
/^packages\/cli\/src\/(?:index|managed-local-embeddings|managed-python-command|managed-python-daemon|managed-python-runtime|runtime)(?:\.test)?\.ts$/,
/^scripts\/(?:build-public-npm-package|build-python-runtime-wheel|local-embeddings-runtime-smoke|package-artifacts|publish-public-npm-package|published-package-smoke|release-readiness)(?:\.test)?\.mjs$/,
];
const forbiddenIdentifierTerms = ['kae' + 'lio', 'Kae' + 'lio', 'KAE' + 'LIO_'];
const appImportPatterns = [
{
label: 'server source import',
pattern: /(?:from\s+['"][^'"]*|import\s*\(\s*['"][^'"]*|import\s+['"][^'"]*)(?:@server\/|server\/src|(?:\.\.\/)+server\/src)/,
},
{
label: 'frontend source import',
pattern: /(?:from\s+['"][^'"]*|import\s*\(\s*['"][^'"]*|import\s+['"][^'"]*)(?:@frontend\/|frontend\/src|(?:\.\.\/)+frontend\/src)/,
},
{
label: 'python service app import',
pattern: /(?:from\s+['"][^'"]*|import\s*\(\s*['"][^'"]*|import\s+['"][^'"]*|from\s+)(?:python-service\/app|python_service\.app|app\.)/,
},
];
const llmBoundaryPatterns = [
{
label: 'direct Anthropic provider construction',
pattern: /\bcreateAnthropic\b/,
},
{
label: 'direct Vertex Anthropic provider construction',
pattern: /\bcreateVertexAnthropic\b/,
},
{
label: 'direct AI SDK gateway construction',
pattern: /\bcreateGateway\b/,
},
{
label: 'direct AI SDK embedding execution',
pattern: /\bembedMany\b/,
},
{
label: 'legacy context LLM provider port',
pattern: /\bLlmProviderPort\b/,
},
{
label: 'legacy scan LLM provider port',
pattern: /\bKtxScanLlmPort\b/,
},
{
label: 'legacy gateway LLM provider helper',
pattern: /\bcreateGatewayLlmProvider\b/,
},
];
const contextProductionLlmBoundaryPatterns = [
{
label: 'context getModelByName call',
pattern: /\.\s*getModelByName\s*\(/,
},
];
function normalizePath(filePath) {
return filePath.split(path.sep).join('/');
}
function isCodeSource(relativePath) {
return codeExtensions.has(path.extname(relativePath));
}
function isRuntimeAsset(relativePath) {
return runtimeAssetPatterns.some((pattern) => pattern.test(relativePath));
}
function scansForAppImports(relativePath) {
return isCodeSource(relativePath);
}
function scansForLlmBoundaries(relativePath) {
return isCodeSource(relativePath) && relativePath.startsWith('packages/context/src/');
}
function isTestSource(relativePath) {
return /(?:^|\/)[^/]+\.(?:test|spec)\.[cm]?[jt]sx?$/.test(relativePath);
}
function scansForContextProductionLlmBoundaries(relativePath) {
return scansForLlmBoundaries(relativePath) && !isTestSource(relativePath);
}
function scansForForbiddenIdentifiers(relativePath) {
return isCodeSource(relativePath) || isRuntimeAsset(relativePath);
}
function skipsIdentifierScan(relativePath) {
return identifierSkipPrefixes.some((prefix) => relativePath.startsWith(prefix));
}
function allowsForbiddenIdentifier(relativePath) {
return identifierAllowPatterns.some((pattern) => pattern.test(relativePath));
}
export function scanFileContent(relativePath, content) {
const normalizedPath = normalizePath(relativePath);
const violations = [];
if (scansForAppImports(normalizedPath)) {
for (const appImportPattern of appImportPatterns) {
if (appImportPattern.pattern.test(content)) {
violations.push({
file: normalizedPath,
kind: 'app-import',
message: `Forbidden ${appImportPattern.label}`,
});
}
}
}
if (scansForLlmBoundaries(normalizedPath)) {
for (const llmBoundaryPattern of llmBoundaryPatterns) {
if (llmBoundaryPattern.pattern.test(content)) {
violations.push({
file: normalizedPath,
kind: 'llm-boundary',
message: `Forbidden ${llmBoundaryPattern.label}; use @ktx/llm`,
});
}
}
}
if (scansForContextProductionLlmBoundaries(normalizedPath)) {
for (const llmBoundaryPattern of contextProductionLlmBoundaryPatterns) {
if (llmBoundaryPattern.pattern.test(content)) {
violations.push({
file: normalizedPath,
kind: 'llm-boundary',
message: `Forbidden ${llmBoundaryPattern.label}; use getModel(role) inside @ktx/context`,
});
}
}
}
if (
scansForForbiddenIdentifiers(normalizedPath) &&
!skipsIdentifierScan(normalizedPath) &&
!allowsForbiddenIdentifier(normalizedPath)
) {
for (const term of forbiddenIdentifierTerms) {
if (content.includes(term)) {
violations.push({
file: normalizedPath,
kind: 'identifier',
message: `Forbidden product identifier "${term}"`,
});
}
}
}
return violations;
}
async function collectFiles(rootDir, currentDir = rootDir) {
const entries = await readdir(currentDir, { withFileTypes: true });
const files = [];
for (const entry of entries) {
const fullPath = path.join(currentDir, entry.name);
if (entry.isDirectory()) {
if (entry.name === 'node_modules' || entry.name === 'dist' || entry.name === '.venv') {
continue;
}
files.push(...(await collectFiles(rootDir, fullPath)));
continue;
}
if (entry.isFile()) {
files.push(fullPath);
}
}
return files;
}
export async function collectViolations(rootDir) {
const files = await collectFiles(rootDir);
const violations = [];
for (const file of files) {
const relativePath = normalizePath(path.relative(rootDir, file));
const content = await readFile(file, 'utf8');
violations.push(...scanFileContent(relativePath, content));
}
return violations;
}
async function main() {
const scriptDir = path.dirname(fileURLToPath(import.meta.url));
const rootDir = path.resolve(scriptDir, '..');
const violations = await collectViolations(rootDir);
if (violations.length === 0) {
process.stdout.write('ktx boundary check passed\n');
return;
}
for (const violation of violations) {
process.stderr.write(`${violation.file}: ${violation.message}\n`);
}
process.exitCode = 1;
}
if (import.meta.url === pathToFileURL(process.argv[1] ?? '').href) {
await main();
}