Auto-start both processes at logon and self-update from master

Instances were started by hand and updated by hand, so they drifted behind
master silently. Now: PM2 supervises the dashboard and the clicker, a logon
task brings them up, and a 5-minute task pulls, rebuilds and restarts when
master moves.

Restarting on every push is only safe because the scheduler now survives it.
It was pure in-memory state (_global.__autoTrader), so any restart silently
stopped automated trading with the dashboard simply showing it as off. It now
mirrors running/action/symbol/stopAfterAll to the settings table, and
resumeSchedulerIfPersisted() picks it back up from the getClients() bootstrap.
No sync-wait was needed there: tick() already skips while a client reports
!syncComplete and while any account holds a position.

A failed build is never deployed — the build runs before anything restarts, so
a broken push leaves the previous build serving.

start-all and update-check both warm the app with a request afterwards. That is
load-bearing: getClients() is lazily bootstrapped, so until something makes an
HTTP request the Tradovate clients, the reporter and the resumed schedule never
start. That was already true of manual restarts.

Logic lives in Node so a macOS or Linux port only needs an equivalent of
install-autostart.ps1. Python deps are hash-guarded, so the common path is one
hash and one import with no network, and failure is non-fatal since only the
clicker needs them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Brandon Li
2026-08-30 17:36:25 -05:00
co-authored by Claude Opus 5
parent 7e7bd985c2
commit 4288d8c298
11 changed files with 593 additions and 44 deletions
+99
View File
@@ -0,0 +1,99 @@
/**
* Keep clicker/requirements.txt applied, cheaply.
*
* Called from start-all.mjs on every boot, and from update-check.mjs when a
* pull touches requirements.txt. Running `pip install` unconditionally would
* add seconds to every start and fail outright on a machine whose network is
* not up yet, so the work is guarded by a hash plus an import probe.
*
* Failure is never fatal: the dashboard and the trading loops do not need
* Python. Only the clicker does.
*/
import { createHash } from 'node:crypto';
import { existsSync, readFileSync, writeFileSync } from 'node:fs';
import { spawnSync } from 'node:child_process';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
const REQUIREMENTS = path.join(ROOT, 'clicker', 'requirements.txt');
const HASH_FILE = path.join(ROOT, 'scripts', '.deps-hash');
const PYTHON_CMD_FILE = path.join(ROOT, 'scripts', '.python-cmd');
/** Run `<cmd> <args>`; cmd may carry arguments of its own, e.g. "py -3". */
function run(cmd, args, opts = {}) {
const parts = cmd.split(/\s+/);
return spawnSync(parts[0], [...parts.slice(1), ...args], {
cwd: ROOT,
encoding: 'utf8',
shell: process.platform === 'win32',
...opts,
});
}
/** A real interpreter answers with its major version. The Microsoft Store stub
* that Windows puts on PATH produces nothing, which is how we tell them apart. */
function isRealPython(cmd) {
const r = run(cmd, ['-c', 'import sys;print(sys.version_info[0])']);
return r.status === 0 && (r.stdout ?? '').trim() === '3';
}
export function resolvePython() {
// setup-windows.bat already did this detection properly, stub check included,
// and recorded what it found. Prefer that over guessing again.
if (existsSync(PYTHON_CMD_FILE)) {
const saved = readFileSync(PYTHON_CMD_FILE, 'utf8').trim();
if (saved && isRealPython(saved)) return saved;
}
for (const candidate of ['py -3', 'python3', 'python']) {
if (isRealPython(candidate)) return candidate;
}
return null;
}
export function ensurePythonDeps({ log = console.log, force = false } = {}) {
if (!existsSync(REQUIREMENTS)) {
return { ok: true, action: 'skipped', reason: 'no requirements.txt' };
}
const python = resolvePython();
if (!python) {
log('[deps] python not found — clicker dependencies skipped (dashboard is unaffected)');
return { ok: false, action: 'skipped', reason: 'no python' };
}
const wanted = createHash('sha256').update(readFileSync(REQUIREMENTS)).digest('hex');
const recorded = existsSync(HASH_FILE) ? readFileSync(HASH_FILE, 'utf8').trim() : '';
const importsOk = run(python, ['-c', 'import pyautogui']).status === 0;
if (!force && wanted === recorded && importsOk) {
return { ok: true, action: 'up-to-date', python };
}
log(`[deps] installing clicker dependencies via "${python}"${importsOk ? '' : ' (pyautogui does not import)'}`);
const install = run(python, [
'-m', 'pip', 'install', '--disable-pip-version-check', '--quiet',
'-r', path.join('clicker', 'requirements.txt'),
], { stdio: 'inherit' });
if (install.status !== 0) {
log('[deps] pip install failed — the clicker will not work until this is fixed');
return { ok: false, action: 'failed', python };
}
if (run(python, ['-c', 'import pyautogui']).status !== 0) {
log('[deps] pip reported success but pyautogui still does not import');
return { ok: false, action: 'failed', python };
}
writeFileSync(HASH_FILE, wanted + '\n');
log('[deps] clicker dependencies ready');
return { ok: true, action: 'installed', python };
}
// Allow `node scripts/ensure-python-deps.mjs` directly.
if (import.meta.url === `file://${process.argv[1]}`) {
const result = ensurePythonDeps({ force: process.argv.includes('--force') });
console.log(JSON.stringify(result));
process.exit(result.ok ? 0 : 1);
}
+122
View File
@@ -0,0 +1,122 @@
<#
.SYNOPSIS
Register AutoFirmer to start at logon and keep itself updated.
.DESCRIPTION
The only Windows-specific piece of the setup. Everything it schedules is
plain Node, so porting to macOS or Linux means replacing this file alone.
Two scheduled tasks are created, both running as the current user with
LogonType Interactive. That is not incidental: the clicker drives real mouse
and keyboard input and must own a desktop, which a Windows service (session
0) does not have.
Idempotent - re-running replaces the tasks rather than duplicating them.
No elevation required.
.PARAMETER IntervalMinutes
How often to check master for updates. Default 5.
.PARAMETER SkipClicker
Register only the dashboard, leaving the clicker to be run by hand.
#>
[CmdletBinding()]
param(
[int]$IntervalMinutes = 5,
[switch]$SkipClicker
)
$ErrorActionPreference = 'Stop'
$Root = Split-Path -Parent $PSScriptRoot
$StartTask = 'AutoFirmer Start'
$UpdateTask = 'AutoFirmer Update'
function Info($m) { Write-Host " $m" }
function Warn($m) { Write-Host " ! $m" -ForegroundColor Yellow }
Info "project root: $Root"
# ── PM2 ─────────────────────────────────────────────────────────────────────
if (-not (Get-Command pm2 -ErrorAction SilentlyContinue)) {
Info 'installing PM2 globally...'
npm install -g pm2
if ($LASTEXITCODE -ne 0) { throw 'npm install -g pm2 failed' }
# A fresh global install is not on this session's PATH yet.
$npmPrefix = (npm prefix -g).Trim()
$env:PATH = "$npmPrefix;$env:PATH"
if (-not (Get-Command pm2 -ErrorAction SilentlyContinue)) {
throw "PM2 installed but not found on PATH. Open a new terminal and re-run."
}
}
Info "pm2: $((Get-Command pm2).Source)"
Push-Location $Root
try {
# delete + recreate rather than reusing, so a changed path or interpreter
# actually takes effect
pm2 delete autofirmer 2>$null | Out-Null
pm2 start npm --name autofirmer -- start
if ($LASTEXITCODE -ne 0) { throw 'pm2 start autofirmer failed' }
Info 'pm2: autofirmer registered'
if (-not $SkipClicker) {
# pm2 --interpreter wants one executable, so resolve the real path
# rather than passing something like "py -3".
$pyCmdFile = Join-Path $Root 'scripts\.python-cmd'
$pyCmd = if (Test-Path $pyCmdFile) { (Get-Content $pyCmdFile -Raw).Trim() } else { 'python' }
$pyExe = $null
try { $pyExe = (& ([scriptblock]::Create("$pyCmd -c `"import sys;print(sys.executable)`""))).Trim() } catch { }
if ($pyExe -and (Test-Path $pyExe)) {
pm2 delete clicker 2>$null | Out-Null
pm2 start (Join-Path $Root 'clicker\runner.py') --name clicker --interpreter $pyExe
if ($LASTEXITCODE -eq 0) { Info "pm2: clicker registered ($pyExe)" }
else { Warn 'pm2 start clicker failed - the dashboard is unaffected' }
} else {
Warn 'python not found - skipping the clicker. Re-run setup once Python is installed.'
}
}
pm2 save | Out-Null
Info 'pm2: process list saved'
} finally {
Pop-Location
}
# ── Scheduled tasks ─────────────────────────────────────────────────────────
# LogonType Interactive is what grants the desktop the clicker needs.
$principal = New-ScheduledTaskPrincipal -UserId "$env:USERDOMAIN\$env:USERNAME" `
-LogonType Interactive -RunLevel Limited
$settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries `
-DontStopIfGoingOnBatteries -StartWhenAvailable `
-MultipleInstances IgnoreNew -ExecutionTimeLimit (New-TimeSpan -Hours 1)
function Register-Task($Name, $Action, $Triggers, $Description) {
Unregister-ScheduledTask -TaskName $Name -Confirm:$false -ErrorAction SilentlyContinue
Register-ScheduledTask -TaskName $Name -Action $Action -Trigger $Triggers `
-Principal $principal -Settings $settings -Description $Description | Out-Null
Info "task registered: $Name"
}
Register-Task $StartTask `
(New-ScheduledTaskAction -Execute 'cmd.exe' `
-Argument "/c `"$(Join-Path $Root 'scripts\start-all.bat')`"" -WorkingDirectory $Root) `
(New-ScheduledTaskTrigger -AtLogOn) `
'Start AutoFirmer and the clicker at logon.'
# AtLogOn covers a reboot; the repeating Once trigger covers the rest of the day.
$repeat = New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) `
-RepetitionInterval (New-TimeSpan -Minutes $IntervalMinutes) `
-RepetitionDuration (New-TimeSpan -Days 3650)
Register-Task $UpdateTask `
(New-ScheduledTaskAction -Execute 'node.exe' `
-Argument 'scripts\update-check.mjs' -WorkingDirectory $Root) `
@((New-ScheduledTaskTrigger -AtLogOn), $repeat) `
"Check master for updates every $IntervalMinutes minutes; rebuild and restart when it moves."
Write-Host ''
Info 'Done. Both processes are registered and will come back at logon.'
Info "Update checks run every $IntervalMinutes minutes; see scripts\update.log"
Info 'Useful: pm2 list | pm2 logs autofirmer | pm2 logs clicker'
+5
View File
@@ -0,0 +1,5 @@
@echo off
REM Thin wrapper so Task Scheduler has a single entry point. All the logic is in
REM start-all.mjs, which is platform-neutral.
cd /d "%~dp0.."
node scripts\start-all.mjs
+74
View File
@@ -0,0 +1,74 @@
/**
* Bring an instance up: clicker dependencies, PM2 processes, then a warm-up.
*
* Run by the "at log on" scheduled task. Safe to run by hand at any time.
*
* The warm-up is not cosmetic. getClients() in lib/clients.ts is lazily
* bootstrapped — Tradovate clients, the contract resolver, the reporter and the
* persisted-schedule resume all start inside it — so until something makes an
* HTTP request the process sits idle and none of that happens.
*/
import { spawnSync } from 'node:child_process';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
import { ensurePythonDeps } from './ensure-python-deps.mjs';
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
const PORT = process.env.AUTOFIRMER_PORT ?? '3000';
const BASE = `http://127.0.0.1:${PORT}`;
const log = (msg) => console.log(`[start-all] ${msg}`);
function run(cmd, args) {
return spawnSync(cmd, args, {
cwd: ROOT,
encoding: 'utf8',
stdio: 'inherit',
shell: process.platform === 'win32',
});
}
async function waitForApp(timeoutMs = 120_000) {
const deadline = Date.now() + timeoutMs;
while (Date.now() < deadline) {
try {
const res = await fetch(`${BASE}/api/auto-trade`, { signal: AbortSignal.timeout(5_000) });
if (res.ok) return true;
} catch { /* not up yet */ }
await new Promise((r) => setTimeout(r, 2_000));
}
return false;
}
// ── clicker dependencies (non-fatal) ────────────────────────────────────────
ensurePythonDeps({ log });
// ── PM2 ─────────────────────────────────────────────────────────────────────
log('restoring PM2 processes');
if (run('pm2', ['resurrect']).status !== 0) {
log('pm2 resurrect failed — is PM2 installed and has `pm2 save` been run?');
process.exit(1);
}
// ── warm-up ─────────────────────────────────────────────────────────────────
log('waiting for the dashboard to answer');
if (!(await waitForApp())) {
log(`dashboard did not come up on ${BASE} within 120s — check \`pm2 logs autofirmer\``);
process.exit(1);
}
log('warming up (this is what triggers the client bootstrap)');
try {
await fetch(`${BASE}/api/state`, { signal: AbortSignal.timeout(60_000) });
} catch (err) {
log(`warm-up request failed: ${err.message}`);
}
try {
const status = await (await fetch(`${BASE}/api/auto-trade`)).json();
log(status.running
? `scheduler resumed — ${status.action} ${status.symbol}`
: 'scheduler is stopped');
} catch { /* non-critical */ }
log('up');
+153
View File
@@ -0,0 +1,153 @@
/**
* Pull master, rebuild, restart — once per invocation.
*
* A scheduled task fires this every few minutes. Deliberately not a long-lived
* loop: if a run dies, the next fire is a clean slate.
*
* The important guarantee is that a broken push cannot take a trading PC down.
* The build runs before anything is restarted, and a failed build stops the run
* with the previous build still serving.
*
* node scripts/update-check.mjs # normal
* node scripts/update-check.mjs --dry-run # report only, change nothing
*/
import { spawnSync } from 'node:child_process';
import { appendFileSync, existsSync, mkdirSync, readFileSync, rmSync, writeFileSync } from 'node:fs';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
import { ensurePythonDeps } from './ensure-python-deps.mjs';
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
const LOG_FILE = path.join(ROOT, 'scripts', 'update.log');
const LOCK_FILE = path.join(ROOT, 'scripts', '.update.lock');
const BRANCH = process.env.AUTOFIRMER_BRANCH ?? 'master';
const PORT = process.env.AUTOFIRMER_PORT ?? '3000';
const BASE = `http://127.0.0.1:${PORT}`;
const DRY_RUN = process.argv.includes('--dry-run');
const STALE_LOCK_MS = 60 * 60 * 1000;
function log(msg) {
const line = `${new Date().toISOString()} ${msg}`;
console.log(line);
try { appendFileSync(LOG_FILE, line + '\n'); } catch { /* logging must never throw */ }
}
function run(cmd, args, { capture = false } = {}) {
return spawnSync(cmd, args, {
cwd: ROOT,
encoding: 'utf8',
stdio: capture ? 'pipe' : 'inherit',
shell: process.platform === 'win32',
});
}
function git(...args) {
const r = run('git', args, { capture: true });
if (r.status !== 0) throw new Error(`git ${args.join(' ')} failed: ${(r.stderr ?? '').trim()}`);
return (r.stdout ?? '').trim();
}
// ── lock ────────────────────────────────────────────────────────────────────
// A build outlasts the schedule interval, so overlapping runs are otherwise a
// certainty rather than a risk.
function acquireLock() {
if (existsSync(LOCK_FILE)) {
const age = Date.now() - Number(readFileSync(LOCK_FILE, 'utf8').trim() || 0);
if (age < STALE_LOCK_MS) return false;
log(`clearing a stale lock (${Math.round(age / 60000)} min old)`);
}
writeFileSync(LOCK_FILE, String(Date.now()));
return true;
}
const releaseLock = () => { try { rmSync(LOCK_FILE, { force: true }); } catch { /* ignore */ } };
async function main() {
mkdirSync(path.join(ROOT, 'scripts'), { recursive: true });
if (!DRY_RUN && !acquireLock()) {
console.log('another update is already running — exiting');
return 0;
}
try {
git('fetch', 'origin', BRANCH);
const local = git('rev-parse', 'HEAD');
const remote = git('rev-parse', `origin/${BRANCH}`);
if (local === remote) return 0; // the common path: silent no-op
log(`update available: ${local.slice(0, 8)} -> ${remote.slice(0, 8)}`);
const changed = git('diff', '--name-only', local, remote).split('\n').filter(Boolean);
log(`${changed.length} file(s) changed`);
if (DRY_RUN) {
log('dry run — stopping before any change');
log(`would run: ${[
changed.includes('package-lock.json') && 'npm install',
changed.includes('clicker/requirements.txt') && 'pip install',
'npm run build',
'pm2 restart autofirmer',
changed.some((f) => f.startsWith('clicker/')) && 'pm2 restart clicker',
].filter(Boolean).join(', ')}`);
return 0;
}
git('pull', '--ff-only', 'origin', BRANCH);
if (changed.includes('package-lock.json')) {
log('package-lock.json changed — npm install');
if (run('npm', ['install']).status !== 0) { log('ABORTED: npm install failed'); return 1; }
}
if (changed.includes('clicker/requirements.txt')) {
log('clicker/requirements.txt changed — refreshing python deps');
ensurePythonDeps({ log: (m) => log(m) }); // non-fatal by design
}
// Build BEFORE restarting. A failed build leaves the running process
// untouched, which is the whole point of doing it in this order.
log('building');
if (run('npm', ['run', 'build']).status !== 0) {
log('ABORTED: build failed — the previous build is still serving, nothing was restarted');
return 1;
}
log('restarting autofirmer');
if (run('pm2', ['restart', 'autofirmer']).status !== 0) { log('pm2 restart autofirmer failed'); return 1; }
if (changed.some((f) => f.startsWith('clicker/'))) {
log('clicker changed — restarting it too');
run('pm2', ['restart', 'clicker']);
}
await warmUp();
log(`updated to ${remote.slice(0, 8)}`);
return 0;
} catch (err) {
log(`ERROR: ${err.message}`);
return 1;
} finally {
if (!DRY_RUN) releaseLock();
}
}
async function warmUp() {
const deadline = Date.now() + 120_000;
while (Date.now() < deadline) {
try {
if ((await fetch(`${BASE}/api/auto-trade`, { signal: AbortSignal.timeout(5_000) })).ok) break;
} catch { /* still restarting */ }
await new Promise((r) => setTimeout(r, 2_000));
}
try {
await fetch(`${BASE}/api/state`, { signal: AbortSignal.timeout(60_000) });
const status = await (await fetch(`${BASE}/api/auto-trade`)).json();
log(status.running ? `scheduler resumed — ${status.action} ${status.symbol}` : 'scheduler is stopped');
const runner = await (await fetch(`${BASE}/api/autobuyer/runner`)).json();
log(`runner ${runner.online ? 'online' : 'OFFLINE'}${runner.stale ? ' (version stale — reload the extension)' : ''}`);
} catch (err) {
log(`post-restart check failed: ${err.message}`);
}
}
process.exit(await main());