Skip to content

launch: Cloud-first sign-in, org-secret links, and fixes from a MySQL + Postgres launch - #30

Merged
lukekim merged 2 commits into
trunkfrom
launch/cloud-login-mysql-postgres-fixes
Oct 7, 2026
Merged

lukekim merged 2 commits into
trunkfrom
launch/cloud-login-mysql-postgres-fixes

Conversation

@lukekim

@lukekim lukekim commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Summary

Tested the launch skill end to end by launching a Spice.ai Cloud project that federates MySQL and PostgreSQL, fixed what broke or misled along the way, and made Spice.ai Cloud sign-in the first step.

Test project: lukekim/fly-genomics (us-east-1, poc). It joins FlyBase's public PostgreSQL (genes, signaling pathways, disease models; accelerated, refreshed daily) with the UCSC Genome Browser's public MySQL (dm6 gene models; federated live) through two cross-source views. An OpenAI model has tools.

Final state:

  • deploy: succeeded in 35 s, with every dataset and the model Ready and the secret resolved through an org-secret link.
  • verify: 15/16 checks passed. The model answered "which chromosome arm carries the most Hippo pathway genes" with chr2R through the sql tool, which is correct. An MCP session made 8 calls and lost none. p50 was 599 ms and p99 1,354 ms on the cross-source query. The one WARN is the known gzip/OpenAI SDK issue.
  • monitors: 4 created; query_failures and llm_failures are unavailable in that org.

Changes

Cloud-first sign-in

  • New login: sign in, or sign up, with the CLI's device code, in two steps an agent can relay. It returns the URL and code at once, then --wait confirms the credential and lists orgs. OAuth clients and tokens are now only for unattended use.
  • OpenAI models default to SCP_OPENAI_API_KEY, the $25 OpenAI credit a new account gets as a platform-managed org secret.

Secrets

  • secrets links org secrets through the Management API (PUT /v1/projects/{id}/org-secrets/{name}). It no longer reports them unverified or needs a fork or portal step.
  • It also tries the link for unlisted platform secrets.
  • An org secret wins over a local value of the same name.
  • It fails on a secret found nowhere, instead of letting the deploy fail on it.
  • preflight lists the credential's orgs, and says for each reference whether it is local, an org secret, a project secret, or the platform credit.

local

  • Always runs and queries every dataset and view. Components whose secrets exist only in Cloud are reported (needs_cloud_secret), where before the whole check was skipped.
  • The "stalls" rationale for skipping was wrong: a model with a missing key failed in under 1 s.

deploy

  • Stops when a federated dataset stays Initializing (--init-timeout).
  • Deploys a paused project.
  • Accepts a deployment whose record stays in_progress once every instance is new, ready, and serving the new spicepod.
  • New pause command, so a stuck instance stops holding source connections.

fire-drill

  • Falls back to memory_working_set where the org can't use query_failures, which left it unable to start before.
  • Copies alert targets from any launch: monitor.

lint

  • Covers mysql_sslmode.
  • Words each TLS mode accurately: disable is plaintext, not just unverified.
  • Merges repeated notes into one per issue.

Docs

  • MySQL TLS modes (preferred does not fall back to plaintext).
  • Per-dataset connection pools on shared servers.
  • Views that wait for every dataset.
  • Per-org monitor template availability.
  • Troubleshooting rows for each failure seen.
  • An eval for a new user federating MySQL and Postgres.

Found in testing; to report upstream (not fixed here)

  • Runtime, MySQL: every MySQL dataset load runs an information_schema.TABLES ⨝ COLUMNS comment query with no timeout. On MySQL 5.x/MariaDB 10.0 it scans every database the user can see.
    • Ensembl's public server, with 26,257 schemas, never answered it, so the dataset hung in Initializing forever. Its US mirror failed with Disk full (/tmp/#sql…).
    • The fallback runs only on an error, not on a hang.
    • The skill documents the symptom and the workaround: a user granted only the needed databases, or MySQL 8.0+.
  • Runtime, views: one dataset in Error keeps every view from registering, including views that don't use it.
  • Runtime, Postgres: each dataset keeps its own pool.
    • A stuck instance with four datasets saturated FlyBase's PgBouncer, which serves about 6 sessions for all users, and locked out other clients until the project was paused.
    • The runtime reports this only as PostgreSQL connection failed. db error or Timed out in bb8.
  • Runtime, accelerations: a spurious WARN Ignoring parameter sort_columns: must be prefixed with arrow_ appears when the spicepod sets no sort_columns.
  • Cloud: a deployment started right after the spicepod upload cleared a pause stayed in_progress for good, while its instance was ready and serving (deployment 43228).
  • CLI: spice cloud login -o json subscription --device prints no URL or code, because the announcement is suppressed for JSON output, so it can never complete. The CLI also has no pause command.

Not exercised live

  • Approving a device login. I started and stopped flows without approving them, and tested the not-yet-approved and ended paths.
  • Linking SCP_OPENAI_API_KEY successfully. The test org predates the credit, so the link returns 404, which the code reports as missing.
  • The fire-drill run, which needs the account owner's consent to send a real alert.

Test plan

  • make check test-distribution release-preview
  • Live run of preflight, local, create, secrets, deploy, verify, monitors, pause, and status against lukekim/fly-genomics
  • Failure paths: unresolved secret (deploy stops early), MySQL TLS mismatch and a blocked view (local), FlyBase pool exhaustion (deploy stops with the datasets in Error), SCP_OPENAI_API_KEY missing
  • Approve a device login from a new account and confirm SCP_OPENAI_API_KEY links
  • fire-drill on an org without query_failures

… + Postgres launch

A live launch of a project federating MySQL (UCSC Genome Browser) and
PostgreSQL (FlyBase) through spice-launch.sh found gaps in each step. This
fixes them and makes Spice.ai Cloud sign-in the first step.

- login: sign in, or sign up, with the CLI's device code in two steps an
  agent can relay: the URL and code at once, then `--wait`. The Cloud path
  no longer starts with OAuth clients or tokens; those are for unattended use.
- OpenAI models default to SCP_OPENAI_API_KEY, the $25 OpenAI credit a new
  account gets as a platform-managed (unlisted) org secret.
- secrets: link org secrets through the Management API instead of reporting
  them unverified (no fork or portal step), try the link for unlisted
  platform secrets, prefer an org secret over a local value of the same name,
  and fail on a secret found nowhere instead of letting the deploy fail.
- preflight: list the credential's orgs, and say for each secret reference
  whether it is local, an org secret, a project secret, or the platform credit.
- local: always run, query every dataset and view, and report components
  whose secrets exist only in Cloud instead of skipping the whole check.
- deploy: stop when a federated dataset stays Initializing, deploy a paused
  project, and accept a deployment whose record stays in_progress once every
  instance is new, ready, and serving the new spicepod. pause stops a stuck
  instance from holding source connections.
- fire-drill: fall back to memory_working_set where the org cannot use the
  query_failures template, and copy targets from any launch monitor.
- lint: cover mysql_sslmode, word each TLS mode accurately (disable is
  plaintext, not unverified), and merge repeated notes.
- References: MySQL TLS modes (preferred does not fall back to plaintext),
  the MySQL 5.x/MariaDB metadata stall on servers with thousands of
  databases, per-dataset connection pools on shared servers, views that wait
  for every dataset, and per-org monitor template availability.
- An eval for a new user federating MySQL and Postgres.
@lukekim lukekim self-assigned this Oct 7, 2026
@lukekim lukekim added the enhancement New feature or request label Oct 7, 2026
@lukekim
lukekim merged commit 3126d1c into trunk Oct 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants