Skip to content

refactor(api,mcp,db)!: standardize API/MCP names and adopt Goose - #270

Merged
vishr merged 4 commits into
mainfrom
codex/api-mcp-naming-goose
Oct 1, 2026
Merged

vishr merged 4 commits into
mainfrom
codex/api-mcp-naming-goose

Conversation

@vishr

@vishr vishr commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

What changed

Fanout's API and MCP names used inconsistent operation names, and the control database duplicated its schema between Atlas and sqlc. This change uses slash-separated HTTP resources/actions, verb-first MCP tool names, and a single embedded Goose migration source for SQLite and sqlc.

Breaking contracts

Before After
POST /api/auth/start POST /api/auth/code/send
POST /api/auth/verify POST /api/auth/code/verify
POST /api/auth/login-link POST /api/auth/link/verify
/api/rules and children /api/alerting/rules and children
PUT /api/users/:id PATCH /api/users/:id
POST /api/users/:id/logout-all POST /api/users/:id/access/revoke
POST /api/settings/ingest/rotate-token POST /api/settings/ingest/token/rotate
POST /api/agent POST /api/agent/runs
GET /-/metrics GET /metrics

Remove the singular /api/dashboard handlers and duplicate /api/health readiness route. Retired routes return 404, including authenticated requests; there are no aliases or SPA fallbacks. User PATCH preserves omitted fields and applies explicit false. Access revocation invalidates existing browser sessions and OAuth tokens while allowing the account to sign in again.

MCP tools become get_observability_overview, get_service_topology, get_service_performance, inspect_trace, get_intelligence_snapshot, list_dashboards, get_dashboard, create_dashboard, and replace_dashboard; search_logs is unchanged. Dashboard replacement explicitly removes omitted widgets. Update authorization, agent instructions, browser clients, embedded bundles, tests, and generated references together.

SQLite migrations

Keep modernc.org/sqlite, database/sql, sqlc, and DuckDB. Replace Atlas with Goose 3.28.0 and one fresh SQLite baseline. sqlc reads the migration directory directly. Remove Atlas dependencies/configuration/revision tracking, the duplicate schema file, the legacy dashboard canvas fallback, and the obsolete timestamp-normalization trigger.

Existing Atlas-managed control databases require a fresh control database. Startup rejects databases without Goose version state before changing their schema or data. There is no automatic conversion or reset. Document backup/setup steps; telemetry and query files remain separate from control state.

Document the database, HTTP/MCP naming, and CalVer conventions in AGENTS.md. Update development recipes and third-party notices. Changes are confined to Fanout.

Dependency audit

Update the existing browser overrides to fast-uri 3.1.8 and ip-address 10.7.1 in both workspaces, with matching lockfiles and notices. The full gate surfaced five moderate advisories; both browser audits now report no vulnerabilities. Patch versions are confirmed by the upstream fast-uri advisory and ip-address advisories.

Review follow-up

  • Require a positive applied Goose version for an existing application schema. The manual migration command now shares the startup guard and embedded migration path.
  • Pin migration SHA-256 checksums in the Go test gate and log every applied version with duration.
  • Return 404 for unknown reserved server paths before authentication, including retired metrics requests with valid bearer tokens. Document the scrape-path change.
  • Derive dashboard transport scopes from the MCP registration catalog, consolidate browser tool labels/titles, and remove the unused singleton dashboard service method.

Verification

  • just test

  • just test-race

  • just lint

  • sqlc generate -f internal/db/sqlc.yaml

  • just docs-generate-check

  • just site-build

  • just notices-check

  • just db-migrate-apply against a disposable SQLite database, then repeat to verify no pending migrations.

  • Storage tests cover all control tables, reopening without data loss or repeated migrations, WAL mode, and refusal to mutate an unversioned database.

  • Regression tests reject existing schemas with empty, zero-only, or unapplied Goose metadata; metadata-only fresh initialization succeeds.

  • Built-server smoke test: first-admin setup, metrics authorization, retired route 404s, PATCH omitted/false behavior, MCP initialization and all 10 tools, graceful shutdown, and persisted sessions/dashboards/migration versions after restart. Fresh boot logs migration version/duration; restart does not log unapplied work.

  • Migration CLI smoke test: reject unversioned/empty/zero-only metadata without schema/data changes, fresh apply, and repeat as a no-op.

  • Two independent follow-up reviews found no actionable regressions.

  • just check

  • just test-race when auth, API, ingest, query, MCP, or agent paths changed

  • User-facing behavior and configuration docs are current

  • No credentials, private telemetry, host details, or enterprise-only source are included

  • API, migration, ingest, MCP/AG-UI, or release-contract changes are called out

Comment thread internal/db/migrations.go Outdated
Comment thread internal/db/migrations.go
Comment thread internal/api/auth_middleware.go
Comment thread internal/api/oauth.go Outdated
Comment thread internal/dashboard/service.go
Comment thread ui/host/src/chat.tsx Outdated
Comment thread internal/db/migrations.go Outdated
- Pin published migration bytes with .gitattributes so CRLF checkouts
  cannot fail the checksum ledger.
- Read the applied-version check from goose.DefaultTablename, matching
  the table-existence query.
- Register dashboard tools straight from the catalog. go-sdk AddTool
  copies each tool before inferring schemas, so the per-server array
  copy was unnecessary.
@vishr
vishr merged commit 30ba9b9 into main Oct 1, 2026
8 checks passed
@vishr
vishr deleted the codex/api-mcp-naming-goose branch October 1, 2026 05:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant