Skip to content

feat: NyxBot automations — schedules and webhook triggers for NyxBot and specialists (0.39.0) - #1719

Merged
chronoai-kai merged 3 commits into
mainfrom
nyxbot/schedules
Oct 1, 2026
Merged

chronoai-kai merged 3 commits into
mainfrom
nyxbot/schedules

Conversation

@chronoai-kai

Copy link
Copy Markdown
Contributor

Summary

NyxBot and its specialists can now act on their own, on a schedule or when a webhook arrives. This builds on NyxID Triggers rather than adding a parallel system. Version 0.39.0.

  • Schedules. A trigger gains a source: webhook (default, unchanged) or schedule.
    • Schedule kinds are cron, every and at, with IANA timezones and DST handling. A time in a spring-forward gap fires once at the first valid instant; a repeated (fall-back) time fires once.
    • Settings: start/end, maximum runs, a grace window for missed runs, and the next three runs previewed.
    • Limits: minimum interval 5 minutes, at most 100 schedules per owner.
    • Runs are exactly-once, with UUID v5 run IDs and leased, fenced claims through the covered trigger_work index.
    • Missed runs after downtime become one summary record and one audit event, never a burst.
  • Assistant delivery. A new assistant delivery starts a turn for NyxBot or a specialist.
    • Thread: home, dedicated or new.
    • The turn receives an owner-written instruction.
    • Results go to the thread, a channel chat (live posting ACLs) or a push notification.
    • Runs keep normal owner and agent authority and the existing team pool, are exempt from the event-streak guard, and have separate owner budgets (30/hour and 300/day by default) plus a per-trigger overlap policy.
    • Confirmation cards wake the same run when decided; continuations consume no extra budget.
  • Webhook safety.
    • Webhook-sourced runs default to a dedicated thread and confirmation_policy = changes: every changing call raises an owner card, classified by HTTP semantics and NyxID markers, never word lists.
    • Choosing home or destructive is an explicit owner choice with warnings.
    • Event payloads are bounded and labelled untrusted.
  • NyxBot tools. nyxid__create_schedule, list_schedules, update_schedule, delete_schedule and run_schedule_now.
    • Webhook triggers are set up through a private, prefilled Automations page, so secrets never enter chat. The prefill is stored on an owner-bound watch, single-use, and the URL carries only an ID.
    • NyxBot resumes when the trigger is created.
  • Web. A new Automations page (sidebar beside the assistant) with:
    • calendar, time and timezone pickers, and live previews;
    • run history with thread links;
    • pause/resume, run now and delete;
    • timezone and budget preferences.
      Developer > Triggers remains for webhook secrets and replay.
  • Hardening. Every /assistant/nyxagent/* route now refuses developer-app OAuth access tokens. Previously a third-party app with the owner's consent could drive NyxBot.

Rollout

Upgrade all replicas before creating automations. Old replicas cannot deserialize the new verification or delivery variants, so an affected owner's trigger list and ingress fail on them; no old sweeper deletes or retries these rows. No new environment variables.

Performance (S7)

Measurement Result
Due discovery, 10,000 schedules (covered index scan, 0 docs examined) 0.435 ms
Fenced claim 4.279 ms
Idle tick 0.418 ms
List API, 100 schedules with previews 9.508 ms
Next cron occurrence 91 µs
Scheduled time → admitted turn 246 ms
Confirmation decision → completed continuation 487 ms
Three-day outage recovery (864 missed) 112 ms

Owners without triggers gain no database round trips on proxy, MCP, turn start or channel inbound.

Verification

  • Backend (MongoDB replica set): handlers 1993, services 3828, rest 1137 passed; clippy 1.98.1 -D warnings clean.
  • Frontend: 4039 tests passed on the merged tree; type-check and lint clean (0 errors).
  • Two review rounds (28 + 4 findings) fixed. The design doc is docs/NYXBOT_SCHEDULES.md.

chrono-kw added 2 commits October 1, 2026 08:12
…yxBot or specialists

Triggers gain a schedule source (cron/every/at with IANA timezones and DST,
grace windows, per-owner budgets and overlap policy, exactly-once leased runs)
and an assistant delivery that starts a NyxBot or specialist turn in a home,
dedicated or per-run thread, delivering results to the thread, a channel chat
or push. NyxBot creates and manages schedules from chat; webhook triggers are
set up through a private prefilled Automations page so secrets never enter chat.
Webhook runs default to dedicated threads and confirm every changing action.
Developer-app OAuth tokens are refused on all NyxAgent routes.
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 87.69% 73% ✅ 🔺 +0.06
CLI (nyxid-cli) 72.59% 64% ✅ — 0.00
Frontend (vitest) 71.46% 15% ✅ 🔺 +0.07

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

@chronoai-kai
chronoai-kai merged commit be1883b into main Oct 1, 2026
34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant