refactor(rpc): remove BYOK RPC and per-org/project RPC provider selection - #2216
multipletwigs wants to merge 3 commits into
Conversation
…tion Every project now reaches its cluster through the deployment's managed RPC pool. Organizations no longer bring RPC URLs or credentials, and nothing per organization or per project selects a provider. - Delete tenant RPC connections, credential mode, the internal RPC routes, /v1/rpc/providers, /v1/rpc/test, and the dashboard RPC integration surfaces. - The /v1/rpc/proxy relay is managed-pool only and reuses config's provider list. - Drop the rpc provider family, project rpcProvider/rpcEndpoint, and the onboarding RPC step. - Helius Rings keeps a guarded transport for its tenant URL; the host guard moves to @sdp/rpc/blocked-address. - Migration 0123 drops rpc_connections, the RPC provider credentials, and organizations.rpc_credential_mode, and strips the RPC settings keys.
|
React Doctor found no new issues. 🎉 Reviewed by React Doctor for commit |
|
…s out The migration-compat policy requires a breaking contraction to land in a migrations-only PR after the code that stops reading the dropped objects. Localized catalogs are synced on the release PR.
…ive provider family in the Clerk override test
|
@greptile-apps please re-review Triton accepts the token in the URL path for JSON-RPC and WebSocket https://.mainnet.rpcpool.com/ |
G1de0n
left a comment
There was a problem hiding this comment.
Looks good overall: runtime no longer touches rpc_connections/rpc_credential_mode/settings.rpcProvider, the guard move is byte-for-byte, proxy stays metered and doesn't expose the endpoint URL. A few things before merge:
- Triton auth header dropped. On main
resolveManagedProviderssentx-api-key: SOLANA_RPC_TRITON_API_KEY;ManagedRpcProvideris now{ id, url }andrelayToTargetonly sendsContent-Type. UnlessSOLANA_RPC_TRITON_URLcarries{API_KEY}, ~1/N proxy calls will 401 under round-robin. Please carryheadersthrough the managed provider → relay target, or confirm the URL template in Doppler. - Private Channels RPC ignores the project cluster.
project-rpc.ts:62buildscreateRpc(env)whileclustercomes from the project environment. A production project on aSOLANA_NETWORK=devnetdeployment reconciles against devnet and can fail a real deposit as "not found on chain".createClusterRpc(input.env, cluster)already exists (used by sponsorship) and fails closed. Same applies tosigner-check.ts:109. - Legacy settings are silently accepted and echoed.
projects/schemas.tsandorganizations/schemas.tssettings objects aren't.strict(), sorpcProvidergets a 200 no-op while OpenAPI says strict;project.service.ts:409casts stored JSON unchecked and:185writes stale keys back on every PATCH..strict()+ a zod parse on read removes the "stale keys on GET" caveat regardless of when #2217 runs.
Nits: mark the commit as breaking (refactor(rpc)!: + BREAKING CHANGE:, body still mentions migration 0123); add a non-dev test that Rings tenant URLs go through the guarded transport and loopback is refused; @solana/addresses is unused in packages/sdp-rpc. Deploy note: #2217 should go out in a later release than this one, since running 0123 during this rollout breaks old pods, and rollback is unsafe after it.
Removes BYOK RPC end to end. Every project uses the deployment's managed RPC pool; nothing per org or project brings or selects an endpoint.
/v1/rpc/providers,/v1/rpc/test,/internal/dashboard/rpc/*, tenant RPC connections, credential mode, the dashboard RPC integration pages, and the onboarding RPC step./v1/rpc/proxystays, round-robin over the managed pool. It returnsprovider: { id, endpoint }and no longer takes aprojectIdquery.settingsisnullwhen unset (it was always an object withrpcProvider: "default").rpcProvider,rpcEndpointandproviderOverrides.rpcare no longer accepted.@sdp/rpc/blocked-address.rpc_connectionsorrpc_credential_mode, so this deploys safely onto the current schema. The contraction ships in feat(db): drop BYOK RPC tables, credentials, and settings keys #2217, merged after this deploys. Until then, stalerpcProviderkeys still sitting in settings JSON come back on GETs.Verification: tsc clean on api/web/rpc/types; biome clean; sdp-rpc 66/66 node tests. Not run locally: the API and web vitest suites (CI runs them). Local app (devnet, Pi, 13/13 pass): relay genesis, key masking and rotation; removed routes 404; faucet, signer-check, transfer, issuance deploy+mint.