refactor(api,mcp,db)!: standardize API/MCP names and adopt Goose - #270
Merged
Merged
Conversation
vishr
commented
Oct 1, 2026
vishr
commented
Oct 1, 2026
vishr
commented
Oct 1, 2026
vishr
commented
Oct 1, 2026
vishr
commented
Oct 1, 2026
vishr
commented
Oct 1, 2026
vishr
commented
Oct 1, 2026
- Pin published migration bytes with .gitattributes so CRLF checkouts cannot fail the checksum ledger. - Read the applied-version check from goose.DefaultTablename, matching the table-existence query. - Register dashboard tools straight from the catalog. go-sdk AddTool copies each tool before inferring schemas, so the per-server array copy was unnecessary.
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Fanout's API and MCP names used inconsistent operation names, and the control database duplicated its schema between Atlas and sqlc. This change uses slash-separated HTTP resources/actions, verb-first MCP tool names, and a single embedded Goose migration source for SQLite and sqlc.
Breaking contracts
POST /api/auth/startPOST /api/auth/code/sendPOST /api/auth/verifyPOST /api/auth/code/verifyPOST /api/auth/login-linkPOST /api/auth/link/verify/api/rulesand children/api/alerting/rulesand childrenPUT /api/users/:idPATCH /api/users/:idPOST /api/users/:id/logout-allPOST /api/users/:id/access/revokePOST /api/settings/ingest/rotate-tokenPOST /api/settings/ingest/token/rotatePOST /api/agentPOST /api/agent/runsGET /-/metricsGET /metricsRemove the singular
/api/dashboardhandlers and duplicate/api/healthreadiness route. Retired routes return 404, including authenticated requests; there are no aliases or SPA fallbacks. User PATCH preserves omitted fields and applies explicitfalse. Access revocation invalidates existing browser sessions and OAuth tokens while allowing the account to sign in again.MCP tools become
get_observability_overview,get_service_topology,get_service_performance,inspect_trace,get_intelligence_snapshot,list_dashboards,get_dashboard,create_dashboard, andreplace_dashboard;search_logsis unchanged. Dashboard replacement explicitly removes omitted widgets. Update authorization, agent instructions, browser clients, embedded bundles, tests, and generated references together.SQLite migrations
Keep
modernc.org/sqlite,database/sql, sqlc, and DuckDB. Replace Atlas with Goose 3.28.0 and one fresh SQLite baseline. sqlc reads the migration directory directly. Remove Atlas dependencies/configuration/revision tracking, the duplicate schema file, the legacy dashboard canvas fallback, and the obsolete timestamp-normalization trigger.Existing Atlas-managed control databases require a fresh control database. Startup rejects databases without Goose version state before changing their schema or data. There is no automatic conversion or reset. Document backup/setup steps; telemetry and query files remain separate from control state.
Document the database, HTTP/MCP naming, and CalVer conventions in
AGENTS.md. Update development recipes and third-party notices. Changes are confined to Fanout.Dependency audit
Update the existing browser overrides to
fast-uri3.1.8 andip-address10.7.1 in both workspaces, with matching lockfiles and notices. The full gate surfaced five moderate advisories; both browser audits now report no vulnerabilities. Patch versions are confirmed by the upstream fast-uri advisory and ip-address advisories.Review follow-up
Verification
just testjust test-racejust lintsqlc generate -f internal/db/sqlc.yamljust docs-generate-checkjust site-buildjust notices-checkjust db-migrate-applyagainst a disposable SQLite database, then repeat to verify no pending migrations.Storage tests cover all control tables, reopening without data loss or repeated migrations, WAL mode, and refusal to mutate an unversioned database.
Regression tests reject existing schemas with empty, zero-only, or unapplied Goose metadata; metadata-only fresh initialization succeeds.
Built-server smoke test: first-admin setup, metrics authorization, retired route 404s, PATCH omitted/false behavior, MCP initialization and all 10 tools, graceful shutdown, and persisted sessions/dashboards/migration versions after restart. Fresh boot logs migration version/duration; restart does not log unapplied work.
Migration CLI smoke test: reject unversioned/empty/zero-only metadata without schema/data changes, fresh apply, and repeat as a no-op.
Two independent follow-up reviews found no actionable regressions.
just checkjust test-racewhen auth, API, ingest, query, MCP, or agent paths changedUser-facing behavior and configuration docs are current
No credentials, private telemetry, host details, or enterprise-only source are included
API, migration, ingest, MCP/AG-UI, or release-contract changes are called out