Commit 81cecee
authored
fix(selfhost): fail preflight on half-configured ledger anchoring instead of silently skipping it (#9771)
Anchoring has nine LOOPOVER_LEDGER_ANCHOR_* vars, all documented in env.d.ts and
all genuinely read, and not one of them appeared in any self-host preflight or
config-lint. An operator got zero boot-time guidance.
That matters more than a normal missing-config warning because the failure is
completely silent: runScheduledLedgerAnchor logs ledger_anchor_skipped_unconfigured
and returns, while the job keeps firing every couple of minutes doing two queries
and nothing else. A self-host container DOES run the scheduler and DOES have a
populated decision_ledger, so it is genuinely one keypair away from working -- and
nothing tells the operator that.
Anchoring stays OPT-IN: configuring none of it is deliberately not a problem, and
there is an invariant test pinning that so a future edit cannot turn an optional
feature into a boot requirement. What now fails preflight is PARTIAL
configuration, every case of which silently disables anchoring while looking
configured:
- a published key list with no private half, or a private key with nothing
published (anchors would be unverifiable)
- a key list that parses to zero usable entries -- malformed JSON and entries
missing a required field are both dropped silently at runtime
- no entry with notAfter: null, or MORE than one: currentAnchorKey fails closed
on an ambiguous rotation rather than guessing which key signs
- a git owner/repo without an installation id (no write token can be minted, so
job-dispatch resolves submitGit to null), a non-positive-integer id, or half a
git target
The key checks call the real parseAnchorPublicKeys/currentAnchorKey rather than
re-validating the shape locally, so preflight can never disagree with what the
scheduler will actually do -- a second hand-written copy of those rules is exactly
how this drifts back apart.
Regenerating the self-host env reference is a side benefit worth naming: because
preflight now reads these vars under src/selfhost/**, all five appear in the
generated operator-facing env documentation for the first time.
Closes #97691 parent 8e02fab commit 81cecee
3 files changed
Lines changed: 203 additions & 0 deletions
File tree
- apps/loopover-ui/src/lib
- src/selfhost
- test/unit
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
281 | 281 | | |
282 | 282 | | |
283 | 283 | | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
284 | 304 | | |
285 | 305 | | |
286 | 306 | | |
| |||
759 | 779 | | |
760 | 780 | | |
761 | 781 | | |
| 782 | + | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
| 786 | + | |
762 | 787 | | |
763 | 788 | | |
764 | 789 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | 5 | | |
5 | 6 | | |
| |||
70 | 71 | | |
71 | 72 | | |
72 | 73 | | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
73 | 151 | | |
74 | 152 | | |
75 | 153 | | |
| |||
266 | 344 | | |
267 | 345 | | |
268 | 346 | | |
| 347 | + | |
| 348 | + | |
269 | 349 | | |
270 | 350 | | |
271 | 351 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
440 | 440 | | |
441 | 441 | | |
442 | 442 | | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
0 commit comments