Repository navigation
fix(mcp): require operator spend caps before real purchases and price Savings Plan previews - #52
Conversation
Real purchases are refused unless CUDLY_MCP_MAX_COUNT (RIs, GCP vCPUs), CUDLY_MCP_MAX_HOURLY_COMMITMENT (Savings Plans) or CUDLY_MCP_MAX_MEMORY_GB (GCP CUDs) is set to a valid value and the request is within it. Caps are routed by CommitmentType, checked after the opt-in and before credentials. They are per call and are not USD caps; a USD cap and cumulative budget are tracked in #51. Refs #47 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Savings Plan previews report cost as the total commitment over the term (hourly x 8760 x years), computed without a provider call. README, server.json, the MCPB manifest and the changelog document the caps. Refs #47 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Warning Review limit reached
This review includes 17 billable files and costs up to $4.25.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Or wait 40 minutes for your next included review. View limit detailsLimit details: You’ve used the included review currently available. Your 87 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (17)
Comment |
Gate review (mcp gate-1): CHANGES REQUESTED at a701408Independent adversarial review of the full diff (money path). The safety logic is correct; one real source defect blocks the merge. Blocking
Non-blocking (author's call) Verified locally (fresh clone at the exact SHA, GOTOOLCHAIN=go1.26.9, mocks only, no cloud calls)
CI at this SHA: all completed checks green, |
…ing-and-preview-price
Gate re-review (mcp gate-1): APPROVED at 1418f8d
|
Summary
CUDLY_MCP_MAX_COUNT(RIs; vCPUs for GCP CUDs),CUDLY_MCP_MAX_HOURLY_COMMITMENT(Savings Plans),CUDLY_MCP_MAX_MEMORY_GB(GCP CUDs, whosememory_gbis not bounded by the count cap).CommitmentType(a Savings Plan with Count 0 or 5 still hits the hourly cap), checked inauthorizeRealPurchaseafter the opt-in and before credentials or any provider call. Previews need no caps and stay offline.cost= hourly x 8760 x term, computed locally. RI and CUD previews remain unpriced.PurchaseResponse.Costis documented in the schema. It has two meanings today (Savings Plan preview: total commitment over the term; executed purchase: provider-reported upfront cost); feat(mcp): USD spend cap on the execute path and a cumulative purchase budget #51 will unify it.Limits (documented in README)
Caps are per call and the count cap is not a USD cap (50 x
u-24tb1at about $218/h for 3 years is roughly $286M). The execute-path USD cap and a cumulative budget are tracked in #51.Behavior changes
NewAuditRecordreadsrec.CommitmentCost). The idempotency key is unchanged (test).numbersettings (min 1) in all three env blocks. The MANIFEST spec does not say what the host substitutes for an unset optional setting; an empty value and a literal${user_config...}placeholder both hit the refusal (tested), so either behavior fails closed. Not verified in a real Claude Desktop host.Verification (mocks only, no cloud calls)
go test -shorton./tools,./cmd/...,.pass;golangci-lint0 issues.>to>=, routing byCount == 0, dropping the>= 1parse check each make the cap tests fail.Follow-up: #51 execute-path USD cap + cumulative budget
Closes #47
🤖 Generated with Claude Code