Repository navigation
Harden Iroh relay server activation - #8454
4 commits merged into
Conversation
📝 WalkthroughWalkthroughThe change adds self-hosted relay production environment requirements, stores relay catalog bodies in database state, and updates catalog acceptance to validate canonical digests, enforce safe rotations, and use workflow-provided timestamps. Migrations, error handling, workflow integration, and related tests are updated. ChangesRelay catalog and deployment configuration
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant RelayWorkflowConfig
participant RelayRepositoryLive
participant irohRelayCatalogState
RelayWorkflowConfig->>RelayRepositoryLive: acceptCatalog(catalog, nowSeconds)
RelayRepositoryLive->>irohRelayCatalogState: read persisted catalog state
RelayRepositoryLive->>RelayRepositoryLive: validate canonical digest and rotation safety
RelayRepositoryLive->>irohRelayCatalogState: persist catalog state and updatedAt
RelayRepositoryLive-->>RelayWorkflowConfig: return acceptance or typed error
Possibly related PRs
🚥 Pre-merge checks | ✅ 23 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (23 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@web/services/relay/repository.ts`:
- Around line 166-169: The persisted catalog verification in the repository’s
relay-catalog persistence flow should not depend on incidental key ordering from
JSON.stringify. Update relayCatalogDigest to use canonical JSON serialization,
or remove this redundant re-hashing check if the storage boundary is trusted;
preserve the existing digest validation behavior otherwise.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 82c415d2-1277-4547-86e3-cfad1a4f172c
📒 Files selected for processing (12)
web/app/env.tsweb/db/migrations/20260718120000_iroh_relay_status_validation/migration.sqlweb/db/migrations/20260718121000_iroh_relay_catalog_body/migration.sqlweb/db/schema.tsweb/services/iroh/README.mdweb/services/relay/errors.tsweb/services/relay/http.tsweb/services/relay/repository.tsweb/services/relay/workflows.tsweb/tests/client-config-env.test.tsweb/tests/iroh-db-behavior.test.tsweb/tests/relay-workflows.test.ts
|
Review feedback addressed in
Verification: 26 focused tests, TypeScript typecheck, changed-file lint, and all 11 database behavior files passed. Live preview from this head: https://cmux-afexr6dvi-manaflow.vercel.app |
Summary
Testing
bun test tests/client-config-env.test.ts tests/relay-policy.test.ts tests/relay-workflows.test.ts tests/relay-token.test.ts tests/relay-token-route.test.ts tests/relay-preferences-route.test.ts(45 pass)bun run typecheckbun run lint -- app/env.ts db/schema.ts services/relay/errors.ts services/relay/http.ts services/relay/repository.ts services/relay/workflows.ts tests/client-config-env.test.ts tests/iroh-db-behavior.test.ts tests/relay-workflows.test.tsCMUX_PORT=4681 bun run db:test(all 11 database behavior suites pass; Iroh suite 26 pass)bun run db:checkbun tools/generate-managed-iroh-relay-catalog.ts --checkA later full preflight retry reached the host Docker network allocator limit before starting Postgres. It did not invalidate the earlier green isolated database run.
Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Summary by cubic
Hardens activation of the self-hosted Iroh relay fleet by persisting the full managed catalog, using a canonical digest, and enforcing safe add-before-remove rotation. Production builds now require relay signing keys and rate‑limit IDs; previews stay credential‑free with sanitized error output for missing private config.
New Features
iroh_relay_catalog_state.catalog), verify previous digest, compute overlap, and reject unsafe transitions withRelayCatalogRollbackErrorreasonsprevious_catalog_unavailableandunsafe_transition(reason logged).RelayCatalogIntegrityError(HTTP 503, safe reason logged).acceptCatalog({ catalog, nowSeconds })computes the digest, timestamps updates, backfills the previous body on same-sequence, and validates rotation under lock.Migration
catalogJSONB column and validateiroh_relay_token_issuances_status_check.CMUX_RELAY_JWT_PRIVATE_KEY_PEM,CMUX_RELAY_POLICY_KEY_ID,CMUX_RELAY_POLICY_PRIVATE_KEY_PEM,CMUX_RELAY_TOKEN_RATE_LIMIT_ID(optionalCMUX_RELAY_PREFERENCES_RATE_LIMIT_ID). Previews/local remain credential-free.Written for commit 93c88c8. Summary will update on new commits.
Summary by CodeRabbit