Skip to content

refactor(rpc): remove BYOK RPC and per-org/project RPC provider selection - #2216

Open
multipletwigs wants to merge 3 commits into
mainfrom
bashtwigs/hoo-1876-remove-byok-rpc-the-managed-pool-per-cluster-is-the-only-rpc
Open

multipletwigs wants to merge 3 commits into
mainfrom
bashtwigs/hoo-1876-remove-byok-rpc-the-managed-pool-per-cluster-is-the-only-rpc

Conversation

@multipletwigs

@multipletwigs multipletwigs commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Removes BYOK RPC end to end. Every project uses the deployment's managed RPC pool; nothing per org or project brings or selects an endpoint.

  • Deleted: /v1/rpc/providers, /v1/rpc/test, /internal/dashboard/rpc/*, tenant RPC connections, credential mode, the dashboard RPC integration pages, and the onboarding RPC step.
  • /v1/rpc/proxy stays, round-robin over the managed pool. It returns provider: { id, endpoint } and no longer takes a projectId query.
  • Project settings is null when unset (it was always an object with rpcProvider: "default"). rpcProvider, rpcEndpoint and providerOverrides.rpc are no longer accepted.
  • Helius Rings keeps its guarded tenant-URL transport. The host guard moved to @sdp/rpc/blocked-address.
  • No migration here. The code never reads rpc_connections or rpc_credential_mode, so this deploys safely onto the current schema. The contraction ships in feat(db): drop BYOK RPC tables, credentials, and settings keys #2217, merged after this deploys. Until then, stale rpcProvider keys still sitting in settings JSON come back on GETs.

Verification: tsc clean on api/web/rpc/types; biome clean; sdp-rpc 66/66 node tests. Not run locally: the API and web vitest suites (CI runs them). Local app (devnet, Pi, 13/13 pass): relay genesis, key masking and rotation; removed routes 404; faucet, signer-check, transfer, issuance deploy+mint.

…tion

Every project now reaches its cluster through the deployment's managed RPC
pool. Organizations no longer bring RPC URLs or credentials, and nothing per
organization or per project selects a provider.

- Delete tenant RPC connections, credential mode, the internal RPC routes,
  /v1/rpc/providers, /v1/rpc/test, and the dashboard RPC integration surfaces.
- The /v1/rpc/proxy relay is managed-pool only and reuses config's provider list.
- Drop the rpc provider family, project rpcProvider/rpcEndpoint, and the
  onboarding RPC step.
- Helius Rings keeps a guarded transport for its tenant URL; the host guard
  moves to @sdp/rpc/blocked-address.
- Migration 0123 drops rpc_connections, the RPC provider credentials, and
  organizations.rpc_credential_mode, and strips the RPC settings keys.
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
sdp-docs Ready Ready Preview Oct 5, 2026 10:50am UTC
sdp-web Ready Ready Preview Oct 5, 2026 10:50am UTC

Request Review

@linear

linear Bot commented Oct 5, 2026

Copy link
Copy Markdown

HOO-1876

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

React Doctor found no new issues. 🎉

Reviewed by React Doctor for commit d1af232.

@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Removes RPC provider selection and BYOK connection features.

No outstanding finding from this review appears to block merging this PR.

Findings

  1. P1 Triton API key is dropped ▶

Summary

This PR removes tenant-owned RPC selection and routes the remaining proxy through the managed provider pool.

  • Removes BYOK routes, dashboard controls, and related contracts.
  • Leaves schema contraction to the higher PR in the stack.
  • Updates custody test setup to use one transaction.

Reviews (4) · Last reviewed commit: "test(api): seed custody config and walle..."

Comment thread apps/sdp-api/src/routes/rpc/handlers.ts
Comment thread apps/sdp-api/src/db/migrations/postgres/0123_remove_byok_rpc.sql Outdated
Comment thread apps/sdp-web/messages/fr/dashboard-private-channels.json Outdated
…s out

The migration-compat policy requires a breaking contraction to land in a
migrations-only PR after the code that stops reading the dropped objects.
Localized catalogs are synced on the release PR.
…ive provider family in the Clerk override test
@multipletwigs

multipletwigs commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator Author

@greptile-apps please re-review Triton accepts the token in the URL path for JSON-RPC and WebSocket https://.mainnet.rpcpool.com/

@G1de0n G1de0n left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good overall: runtime no longer touches rpc_connections/rpc_credential_mode/settings.rpcProvider, the guard move is byte-for-byte, proxy stays metered and doesn't expose the endpoint URL. A few things before merge:

  1. Triton auth header dropped. On main resolveManagedProviders sent x-api-key: SOLANA_RPC_TRITON_API_KEY; ManagedRpcProvider is now { id, url } and relayToTarget only sends Content-Type. Unless SOLANA_RPC_TRITON_URL carries {API_KEY}, ~1/N proxy calls will 401 under round-robin. Please carry headers through the managed provider → relay target, or confirm the URL template in Doppler.
  2. Private Channels RPC ignores the project cluster. project-rpc.ts:62 builds createRpc(env) while cluster comes from the project environment. A production project on a SOLANA_NETWORK=devnet deployment reconciles against devnet and can fail a real deposit as "not found on chain". createClusterRpc(input.env, cluster) already exists (used by sponsorship) and fails closed. Same applies to signer-check.ts:109.
  3. Legacy settings are silently accepted and echoed. projects/schemas.ts and organizations/schemas.ts settings objects aren't .strict(), so rpcProvider gets a 200 no-op while OpenAPI says strict; project.service.ts:409 casts stored JSON unchecked and :185 writes stale keys back on every PATCH. .strict() + a zod parse on read removes the "stale keys on GET" caveat regardless of when #2217 runs.

Nits: mark the commit as breaking (refactor(rpc)!: + BREAKING CHANGE:, body still mentions migration 0123); add a non-dev test that Rings tenant URLs go through the guarded transport and loopback is refused; @solana/addresses is unused in packages/sdp-rpc. Deploy note: #2217 should go out in a later release than this one, since running 0123 during this rollout breaks old pods, and rollback is unsafe after it.

This branch was successfully deployed

2 active deployments
Preview – sdp-docs — d1af2323 Deployed Oct 5, 2026 by vercel[bot]
Preview – sdp-web — d1af2323 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants