Route Checkpoints Through entire:// Mirrors · Entire

When I push things still go via SSH to GitHub

I'd prefer pushes (of checkpoints as well as my other git operations) all use entire:// push-through mirrors. Figure out from @.entire/settings.json why this isn't the case.

Found it: Your settings force checkpoints onto GitHub, and the resolver can't produce entire:// URLs at all.

Bottom line: Your normal pushes already go through the mirror (origin is entire://aws-ap-southeast-2.entire.io/gh/entireio/cli). The SSH-to-GitHub traffic is the checkpoint machinery, caused by checkpoint_remote: {"provider": "github", ...} in .entire/settings.json:5-8 — and there is currently no way to configure a checkpoint remote that routes via entire://. It's a feature gap, not a settings mistake.

The exact chain:

Your options:

  1. Delete the checkpoint_remote block — checkpoints then push to origin, i.e. through the entire:// mirror, but they land on entire/checkpoints/v1 of entireio/cli itself instead of the separate cli-checkpoints repo. Tradeoff: you lose the separate-repo isolation, gain full mirror routing immediately.
  2. Keep the separate repo, add the feature — teach checkpoint_remote to accept an entire:// target (e.g. {\"url\": \"entire://<cluster>/gh/entireio/cli-checkpoints\"}), plus create a push-through mirror for cli-checkpoints. That's a CLI change in checkpoint/remote/util.go + settings.go.

Side observations: the remote.entire://eukanuba.partial.to/... promisor entry is a stale leftover from an old mirror host, and remote.origin.entiredb-original-url confirms origin was already migrated off SSH — so the checkpoint path is the only SSH user left in this repo's config.

Want me to implement option 2 (an entire://-capable checkpoint remote), or just flip you to option 1?

Yes, we need to add the feature. Make it so our tool understands how to push to entire://, then configure the checkpoint remote to use that. The cluster we'll use is entire://aws-ap-southeast-2.entire.io.

Done — committed as 855b8cdab on swirling-doodling-waffle (not pushed, per your rules).

Bottom line: Checkpoints now follow origin through the mirror: with your existing settings, the checkpoint URL resolves to entire://aws-ap-southeast-2.entire.io/gh/entireio/cli-checkpoints — no settings.json edit needed, and I confirmed that mirror is live.

What changed:

Why no config change:

The resolver's design derives transport from the push remote, so the cluster is inherited from origin — which is already entire://aws-ap-southeast-2.entire.io/gh/entireio/cli. This also keeps the committed settings.json portable: teammates on SSH origins keep SSH, anyone on a mirror uses their mirror, all landing in the same cli-checkpoints repo. Tradeoff: if you ever want the cluster pinned independent of origin, that needs an explicit URL-form config we didn't add.

Verified:

mise run fmt && mise run lint clean (diff checked after), targeted package tests pass (checkpoint/..., gitremote, settings, strategy), and git ls-remote entire://aws-ap-southeast-2.entire.io/gh/entireio/cli-checkpoints returns HEAD plus existing checkpoint refs. Full suite left to CI per your preference. Your next real push's pre-push hook is the live confirmation — the checkpoint leg should dial the cluster instead of opening an SSH connection to github.com.

One inert leftover: the shared .git/config still has git@github.com:... promisor entries from old filtered fetches. They're harmless (fetches will now create an entire:// promisor entry), and I left the shared config untouched from this worktree.

855b8cd Route checkpoints through entire:// push-through mirrors

When origin (or the push remote) is an entire:// mirror URL and its forge matches the configured checkpoint_remote provider (gh <-> github), derive the checkpoint URL on the same cluster (entire:////) instead of falling back to direct SSH/HTTPS against the provider host. The provider-host fallback remains for file:// and forge-mismatched mirrors, and ENTIRE_CHECKPOINT_TOKEN still forces provider HTTPS since the token cannot ride through the helper.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 01KXCGE6FQGMQB906H5TAVVRZ9+100/-35