Skip to content

feat(deploy): support API keys for builds and deployments - #917

Draft
huntcsg wants to merge 1 commit into
mainfrom
huntcsg/be-11394-deployment-api-keys
Draft

huntcsg wants to merge 1 commit into
mainfrom
huntcsg/be-11394-deployment-api-keys

Conversation

@huntcsg

@huntcsg huntcsg commented Sep 22, 2026 •

Copy link
Copy Markdown

Description

comfy build and comfy deploy can use COMFY_CLOUD_API_KEY or a key saved with comfy cloud set-key without an OAuth login. Both clients use the existing shared credential resolver and send the selected credential as a bearer token.

OAuth retains its existing precedence and refresh behavior. API keys and forwarded bearer tokens are never refreshed or replaced after a 401. Authentication errors and the README now describe the key-based workflow.

Depends on the server support in cloud#10161 being deployed. Companion draft for BE-11394.

Validation

  • uv run ruff check . and uv run ruff format --check .: passed.
  • 289 focused tests passed, including the complete build/deploy command matrix with API keys, real bearer-header construction, OAuth precedence, and no refresh/fallback on rejected keys.
  • Full suite with startup umask 022 and TERM=xterm-256color: 7,900 passed, 37 skipped, 1 failed. The existing test_edited_content_is_hashed_again[identical size] digest-cache test also fails on untouched origin/main (aec5220); no unrelated code was changed.
  • No live deployment performed.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Comment @coderabbitai help to get the list of available commands.

@vqt123 vqt123 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checks:

  • The key goes out in the shape the servers read. BuilderClient.from_session and DeployClient.from_session (comfy_cli/deploy_api.py:90) now take resolve_cloud_credential(purpose="cloud") and send its value as Authorization: Bearer; the WithIdentity change in cloud#10161 (comfy-builder and comfy-deploy httpkit/identity.go) branches on a Bearer comfyui- token, so the two sides match.
  • deploy run works with a key too: comfy_cli/command/deploy_run.py:201 reuses the control-plane credential for the deployment endpoint, and the gateway on main already accepts Bearer comfyui- (services/platform-gateway/server/auth.go:146).
  • Only a stored session refreshes: _refreshes_on_401 = credential.source == "session", so a key or a forwarded COMFY_CLOUD_AUTH_TOKEN is never swapped after a 401. COMFY_BUILDER_TOKEN still wins in _builder_client.
  • The red GPU-runner job is tests/e2e/test_e2e_uv_compile.py (Manager's uv-compile conflict message), not this diff; the three-platform test matrix passes.

Findings: none. Shipping this before cloud#10161 is deployed is harmless: a key-only caller gets a 401 whose hint already names the key.

~6.0M effective tokens for this review (41.8M raw; cache reads weighted 0.1x, cache writes 1.25-2x)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants