Sandbox
@FullAgent/fulling

Full-stack AI workspace app for Next.js and Kubernetes

Fulling is a web application for dedicated AI workspaces. It combines GitHub sign-in, PostgreSQL-backed sessions, and a user-scoped Kubernetes credential boundary so the app can manage workspace identity and cluster access. The repository is the product itself, not a reusable agent toolkit. Its README and docs focus on the app foundation, deployment, and workspace model rather than packaged building blocks.

2,445 stars232 forksTypeScriptUpdated 1mo ago
Who it's for

Builders who want a web app for agent-led workspaces with GitHub login, database state, and Kubernetes access.

What it delivers

You can run a dedicated AI workspace app instead of stitching together identity, storage, and cluster access yourself.

What it does

GitHub sign-in

Uses Better Auth for GitHub-only authentication in the current foundation.

PostgreSQL-backed sessions

Stores users, provider accounts, and sessions in PostgreSQL.

Protected workspace entry

Provides an authenticated application workspace entry point.

Per-user kubeconfig storage

Stores one plaintext kubeconfig per user in the database.

Kubernetes credential validation

Validates kubeconfigs with Kubernetes `SelfSubjectReview`.

User-scoped Kubernetes client boundary

Limits Kubernetes access to the authenticated user’s stored credentials.

Deployment and reset docs

Includes guidance for local development, Vercel deployment, OAuth verification, and v2 resource cleanup.

How to get it

  1. 1Configure the GitHub OAuth callback as
    ${BETTER_AUTH_URL}/api/auth/callback/github
  2. 2Run
    npm ci
    npm run dev
  3. 3This starts the public application with sign-in disabled. To exercise the legacy…
    cp .env.template .env.local
    # Fill in the database, Better Auth, and GitHub values.
    npm run prisma:migrate
    npm run dev
  4. 4This release uses a new baseline schema. Run it against a new database or an explicitly…
    npm run dev              # Start the development server
    npm run build            # Generate Prisma client and build
    npm run lint             # Run ESLint
    npm test                 # Run Vitest
    npm run test:e2e         # Run Playwright
    npm run prisma:format    # Format the Prisma schema
    npm run prisma:validate  # Validate the Prisma schema
    npm run prisma:migrate   # Deploy the baseline migration

README

Fulling

Fulling is building dedicated AI workspaces: persistent environments that combine skills, files, memory, scripts, and runtime. The current v3 foundation provides the identity and Kubernetes credential boundary required for that product model.

Current Foundation

  • GitHub-only sign-in through Better Auth
  • PostgreSQL-backed users, provider accounts, and sessions
  • a protected application workspace entry
  • one plaintext kubeconfig per user
  • authenticated kubeconfig validation through Kubernetes SelfSubjectReview
  • a user-scoped Kubernetes client boundary

The repository intentionally contains no compatibility layer for the previous product model or authentication system.

Read docs/architecture.md for the target Workspace model. The user-level kubeconfig in this foundation is not the final Workspace Runtime ownership model.

Requirements

  • Node.js 24, including its bundled npm 11

The public application does not require PostgreSQL or an OAuth provider. The legacy authenticated workspace additionally requires PostgreSQL and a GitHub OAuth App.

Configure the GitHub OAuth callback as:

${BETTER_AUTH_URL}/api/auth/callback/github

Local Development

npm ci
npm run dev

This starts the public application with sign-in disabled. To exercise the legacy authenticated workspace instead:

cp .env.template .env.local
# Fill in the database, Better Auth, and GitHub values.
npm run prisma:migrate
npm run dev

Open http://localhost:3000.

This release uses a new baseline schema. Run it against a new database or an explicitly reset database; it does not migrate v2 data.

Commands

npm run dev              # Start the development server
npm run build            # Generate Prisma client and build
npm run lint             # Run ESLint
npm test                 # Run Vitest
npm run test:e2e         # Run Playwright
npm run prisma:format    # Format the Prisma schema
npm run prisma:validate  # Validate the Prisma schema
npm run prisma:migrate   # Deploy the baseline migration

Credential Boundary

Kubeconfigs are stored as plaintext in PostgreSQL. Database read access grants access to users' Kubernetes credentials. Browser-facing APIs never return saved content, and logs must not contain tokens, keys, certificates, or kubeconfig content.

Validation rejects executable credential plugins, auth-provider plugins, local file credential fields, proxy configuration, non-HTTPS API servers, redirects, and anonymous identities. Authenticated users may still configure an HTTPS API server on any network address. This authenticated outbound-request/SSRF boundary is an explicit deployment decision.

Deployment Reset

Before replacing a v2 deployment, follow docs/v2-resource-inventory.md. Resetting the Fulling database does not delete Kubernetes resources created by v2.

Use docs/github-oauth-verification.md to verify a real OAuth application before release.

Vercel Deployment

Fulling can use Vercel's native Next.js deployment without a vercel.json file. The public application builds and starts without environment variables. The current GitHub sign-in, database-backed workspace, and kubeconfig flows remain disabled until their complete legacy configuration is present.

Follow docs/vercel-deployment.md for the complete project setup, zero-configuration behavior, verification steps, and rollback procedure.

Files in the repo

Repository payload29 top-level entries
  • .github
  • app
  • components
  • docs
  • e2e
  • lib
  • prisma
  • public
  • .dockerignore
  • .env.template
  • .gitignore
  • .prettierignore
  • .prettierrc.json
  • AGENTS.md
  • components.json
  • CONTRIBUTING.md
  • Dockerfile
  • eslint.config.mjs
  • fulling-landing-reference.png
  • LICENSE
  • next.config.ts
  • package-lock.json
  • package.json
  • playwright.config.ts
  • postcss.config.mjs
  • prisma.config.ts
  • README.md
  • tsconfig.json
  • vitest.config.ts

Discussion (0)

Ask about usage, or say what you built with it

Sign in to join the discussion.

No comments yet. Be the first to say what this is good for.

More other

🎨 Best DeepSeek Harness Design Plugin. The open-source Claude Design alternative. 🖥️ Local-first desktop app. 🖼️ Your coding agent becomes the design engine: prototypes, landing pages, dashboards, slides, images & video — real files, HTML/PDF/PPTX/MP4 export. 🤖 Claude Code / Codex / Cursor / DeepSeek Harness / OpenCode & 20+ CLIs via BYOK.

95k
HKUDS/
Vibe-Trading

"Vibe-Trading: Your Personal Trading Agent"

33k
tinyhumansai/
openhuman

OpenHuman is an open source personal AI for Mac, Windows and Linux — local-first memory, agent orchestration, and deep research.

40k

Your Personal AI Assistant; easy to install, deploy on your own machine or on the cloud; supports multiple chat apps with easily extensible capabilities.

35k