Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions .github/workflows/tdd-core-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,10 +45,10 @@ jobs:
# Scoped to the crates this fork owns or changes. `--all` would gate our
# CI on upstream's formatting, which we do not control and must not fight.
- name: Formatting (fork-owned crates)
run: cargo fmt -p infisical -p interpolate --check
run: cargo fmt -p infisical -p interpolate -p names_diff -p komodo_mcp --check

- name: Unit and integration tests
run: cargo test -p infisical -p interpolate --locked
run: cargo test -p infisical -p interpolate -p names_diff -p komodo_mcp --locked

# The guard is the safety-critical part: if it stops failing closed, a
# failed secret lookup would deploy a literal token as a password.
Expand All @@ -62,6 +62,10 @@ jobs:
- name: Both binaries still build
run: cargo check -p komodo_core -p komodo_periphery --locked

# Attribution + names-only change records hooked into Core (WI-865).
- name: Core fork hooks
run: cargo test -p komodo_core --locked tdd::

image:
needs: test
runs-on: [self-hosted, docker, publish]
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/tdd-upstream-parity.yml
Original file line number Diff line number Diff line change
Expand Up @@ -126,8 +126,8 @@ jobs:
continue-on-error: true
run: |
set -euo pipefail
cargo fmt -p infisical -p interpolate --check
cargo test -p infisical -p interpolate
cargo fmt -p infisical -p interpolate -p names_diff -p komodo_mcp --check
cargo test -p infisical -p interpolate -p names_diff -p komodo_mcp
cargo check -p komodo_core -p komodo_periphery

- name: Publish the rebased branch and report it is ready
Expand Down
29 changes: 29 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions bin/core/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ periphery_client.workspace = true
mogh_validations.workspace = true
interpolate.workspace = true
infisical.workspace = true
# FORK: names-only change records (WI-865). Path dep, so no root Cargo.toml line.
names_diff = { path = "../../lib/names_diff" }
mogh_secret_file.workspace = true
formatting.workspace = true
mogh_rate_limit.workspace = true
Expand Down
2 changes: 2 additions & 0 deletions bin/core/src/api/execute/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -173,6 +173,8 @@ pub fn router() -> Router {
.layer(middleware::from_fn(
authenticate_request::<KomodoAuthImpl, true>,
))
// FORK: X-Komodo-Actor/-Reason attribution (WI-865).
.layer(middleware::from_fn(crate::tdd::scope_layer))
}

async fn variant_handler(
Expand Down
5 changes: 4 additions & 1 deletion bin/core/src/api/write/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -226,6 +226,8 @@ pub fn router() -> Router {
.layer(middleware::from_fn(
authenticate_request::<KomodoAuthImpl, true>,
))
// FORK: X-Komodo-Actor/-Reason attribution (WI-865).
.layer(middleware::from_fn(crate::tdd::scope_layer))
}

async fn variant_handler(
Expand All @@ -244,7 +246,8 @@ async fn handler(
Extension(user): Extension<User>,
Json(request): Json<WriteRequest>,
) -> mogh_error::Result<axum::response::Response> {
let res = tokio::spawn(task(request, user))
// FORK: `propagate` carries the asserted actor into the spawned task.
let res = tokio::spawn(crate::tdd::propagate(task(request, user)))
.await
.context("failure in spawned task");

Expand Down
7 changes: 7 additions & 0 deletions bin/core/src/api/write/stack.rs
Original file line number Diff line number Diff line change
Expand Up @@ -214,6 +214,13 @@ impl Resolve<WriteArgs> for WriteStackFileContents {
make_update(&stack, Operation::WriteStackContents, user);

update.push_simple_log("File contents to write", &contents);
// FORK (WI-865): content-free summary of the change.
crate::tdd::push_file_change(
&mut update,
&stack,
&file_path,
&contents,
);

let id = stack.id.clone();

Expand Down
6 changes: 6 additions & 0 deletions bin/core/src/helpers/update.rs
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ pub fn make_update(
pub async fn add_update(
mut update: Update,
) -> anyhow::Result<String> {
crate::tdd::stamp(&mut update); // FORK (WI-865)
update.id = db_client()
.updates
.insert_one(&update)
Expand Down Expand Up @@ -77,6 +78,10 @@ pub async fn add_update_without_send(
}

pub async fn update_update(update: Update) -> anyhow::Result<()> {
// FORK (WI-865): re-stamp, idempotently, in case the caller's in-memory
// copy predates the stamp that add_update put on the stored one.
let mut update = update;
crate::tdd::stamp(&mut update);
update_one_by_id(&db_client().updates, &update.id, database::mungos::update::Update::Set(to_document(&update)?), None)
.await
.context("failed to update the update on db. the update build process was deleted")?;
Expand Down Expand Up @@ -271,6 +276,7 @@ pub async fn init_execution_update(

let mut update = make_update(target, operation, user);
update.in_progress();
crate::tdd::stamp(&mut update); // FORK (WI-865)

// Hold off on even adding update for DeployStackIfChanged
if !matches!(&request, ExecuteRequest::DeployStackIfChanged(_)) {
Expand Down
2 changes: 2 additions & 0 deletions bin/core/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@ mod startup;
mod state;
mod sync;
mod ts_client;
// FORK: attribution + names-only diffs on Updates (WI-865).
mod tdd;

async fn app() -> anyhow::Result<()> {
dotenvy::dotenv().ok();
Expand Down
4 changes: 4 additions & 0 deletions bin/core/src/resource/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -637,6 +637,10 @@ pub async fn update<T: KomodoResource>(
.push_simple_log("Failed export", format_serror(&e.into())),
}

// FORK (WI-865): names-only diff, so the change is readable without
// the secret-bearing prev_toml/current_toml.
crate::tdd::push_config_diff(&mut update);

let updated = get::<T>(id_or_name).await?;

T::post_update(&updated, &mut update).await?;
Expand Down
Loading