Repository navigation
refactor(rpc)!: remove BYOK RPC and per-org/project RPC provider selection - #2216
Conversation
…tion Every project now reaches its cluster through the deployment's managed RPC pool. Organizations no longer bring RPC URLs or credentials, and nothing per organization or per project selects a provider. - Delete tenant RPC connections, credential mode, the internal RPC routes, /v1/rpc/providers, /v1/rpc/test, and the dashboard RPC integration surfaces. - The /v1/rpc/proxy relay is managed-pool only and reuses config's provider list. - Drop the rpc provider family, project rpcProvider/rpcEndpoint, and the onboarding RPC step. - Helius Rings keeps a guarded transport for its tenant URL; the host guard moves to @sdp/rpc/blocked-address. - Migration 0123 drops rpc_connections, the RPC provider credentials, and organizations.rpc_credential_mode, and strips the RPC settings keys.
|
React Doctor found no new issues. 🎉 Reviewed by React Doctor for commit |
|
…s out The migration-compat policy requires a breaking contraction to land in a migrations-only PR after the code that stops reading the dropped objects. Localized catalogs are synced on the release PR.
…ive provider family in the Clerk override test
|
@greptile-apps please re-review Triton accepts the token in the URL path for JSON-RPC and WebSocket https://.mainnet.rpcpool.com/ |
G1de0n
left a comment
There was a problem hiding this comment.
Looks good overall: runtime no longer touches rpc_connections/rpc_credential_mode/settings.rpcProvider, the guard move is byte-for-byte, proxy stays metered and doesn't expose the endpoint URL. A few things before merge:
- Triton auth header dropped. On main
resolveManagedProviderssentx-api-key: SOLANA_RPC_TRITON_API_KEY;ManagedRpcProvideris now{ id, url }andrelayToTargetonly sendsContent-Type. UnlessSOLANA_RPC_TRITON_URLcarries{API_KEY}, ~1/N proxy calls will 401 under round-robin. Please carryheadersthrough the managed provider → relay target, or confirm the URL template in Doppler. - Private Channels RPC ignores the project cluster.
project-rpc.ts:62buildscreateRpc(env)whileclustercomes from the project environment. A production project on aSOLANA_NETWORK=devnetdeployment reconciles against devnet and can fail a real deposit as "not found on chain".createClusterRpc(input.env, cluster)already exists (used by sponsorship) and fails closed. Same applies tosigner-check.ts:109. - Legacy settings are silently accepted and echoed.
projects/schemas.tsandorganizations/schemas.tssettings objects aren't.strict(), sorpcProvidergets a 200 no-op while OpenAPI says strict;project.service.ts:409casts stored JSON unchecked and:185writes stale keys back on every PATCH..strict()+ a zod parse on read removes the "stale keys on GET" caveat regardless of when #2217 runs.
Nits: mark the commit as breaking (refactor(rpc)!: + BREAKING CHANGE:, body still mentions migration 0123); add a non-dev test that Rings tenant URLs go through the guarded transport and loopback is refused; @solana/addresses is unused in packages/sdp-rpc. Deploy note: #2217 should go out in a later release than this one, since running 0123 during this rollout breaks old pods, and rollback is unsafe after it.
…cluster; reject and strip stale settings keys - signer-check and loadProjectRpcClient use createClusterRpc with the project's cluster, failing closed when the deployment has no endpoint for it. - Project and organization settings are strict on write; stored project settings are parsed on read so removed keys are neither returned nor merged back. - Drop the unused @solana/addresses dependency from sdp-rpc.
…d Rings tenant transport - signer-check and loadProjectRpcClient assertions move to createClusterRpc; production projects resolve mainnet-beta and fail closed without an endpoint. - Project/org settings reject removed keys; stored stale keys are stripped on read and not merged back. - Rings tenant URLs outside development go through guardedFetch; loopback is refused before any request.
…move-byok-rpc-the-managed-pool-per-cluster-is-the-only-rpc
G1de0n
left a comment
There was a problem hiding this comment.
Removal looks clean. Nothing reads rpc_connections, rpc_credential_mode or rpcProvider at runtime anymore, the proxy is still metered, and the Rings guard is intact.
Before merge
GET /provider-accessno longer returnsproviders.rpc. The current web doesObject.entries(data.providers.rpc), so the integrations page will crash during the web/API deploy skew. Returnrpc: {}for one release.- Org settings:
GETreturns stored keys as-is, stalerpcProviderincluded, butPATCHis strict. A GET→PATCH round trip 400s on keys we just returned, and regular PATCHes merge the stale keys back in. Use a plain object with an explicit 400 for the removed RPC keys, and strip them on read like projects do.
Non-blocking
- Map the missing-endpoint
Errorto a typedAppErrorand add a test. - Use
safeParseinparseStoredProjectSettings. - Can you confirm the prod Triton URL also carries the key? Prod has
SOLANA_RPC_TRITON_API_KEYset. - Dead code:
KVStoreSet,ORGANIZATION_RPC_PROVIDERSnaming, the "configured RPC" i18n copy,organizationSettingsDescription.
0123collides with0123_earn_observed_payout_keyson main.- Deleting
provider_credentialsshould also queuesecret_retirementsfor the BYOK secret versions.
|
Thanks @G1de0n.
The |
* refactor(rpc): remove BYOK RPC and per-org/project RPC provider selection Every project now reaches its cluster through the deployment's managed RPC pool. Organizations no longer bring RPC URLs or credentials, and nothing per organization or per project selects a provider. - Delete tenant RPC connections, credential mode, the internal RPC routes, /v1/rpc/providers, /v1/rpc/test, and the dashboard RPC integration surfaces. - The /v1/rpc/proxy relay is managed-pool only and reuses config's provider list. - Drop the rpc provider family, project rpcProvider/rpcEndpoint, and the onboarding RPC step. - Helius Rings keeps a guarded transport for its tenant URL; the host guard moves to @sdp/rpc/blocked-address. - Migration 0123 drops rpc_connections, the RPC provider credentials, and organizations.rpc_credential_mode, and strips the RPC settings keys. * chore(rpc): ship migration 0123 separately and keep localized catalogs out The migration-compat policy requires a breaking contraction to land in a migrations-only PR after the code that stops reading the dropped objects. Localized catalogs are synced on the release PR. * feat(db): drop BYOK RPC tables, credentials, and settings keys Contraction for #2216: drops rpc_connections and organizations.rpc_credential_mode, deletes the RPC-provider provider_credentials rows, and strips the RPC settings keys. Merge after #2216 is deployed. * test(api): seed custody config and wallet in one transaction; use a live provider family in the Clerk override test * fix(db): leave RPC-only settings as NULL after stripping the RPC keys * fix(db): queue RPC credentials' GCP secret versions for retirement before deleting them * fix(api): scope signer-check and Private Channels RPC to the project cluster; reject and strip stale settings keys - signer-check and loadProjectRpcClient use createClusterRpc with the project's cluster, failing closed when the deployment has no endpoint for it. - Project and organization settings are strict on write; stored project settings are parsed on read so removed keys are neither returned nor merged back. - Drop the unused @solana/addresses dependency from sdp-rpc. * test(api): cover project-cluster RPC, strict settings, and the guarded Rings tenant transport - signer-check and loadProjectRpcClient assertions move to createClusterRpc; production projects resolve mainnet-beta and fail closed without an endpoint. - Project/org settings reject removed keys; stored stale keys are stripped on read and not merged back. - Rings tenant URLs outside development go through guardedFetch; loopback is refused before any request. * test(web): drop the removed rpc tab from the Integrations submenu tab cases * chore(db): renumber the BYOK RPC removal migration to 0124 after main's 0123 * fix(db): tag BYOK RPC secret retirements with the renumbered 0124 migration
Removes BYOK RPC end to end. Every project uses the deployment's managed RPC pool; nothing per org or project brings or selects an endpoint.
/v1/rpc/providers,/v1/rpc/test,/internal/dashboard/rpc/*, tenant RPC connections, credential mode, the dashboard RPC integration pages, and the onboarding RPC step./v1/rpc/proxystays, round-robin over the managed pool. It returnsprovider: { id, endpoint }and no longer takes aprojectIdquery.settingsisnullwhen unset (it was always an object withrpcProvider: "default"). Project and org settings are strict:rpcProvider,rpcEndpointandproviderOverrides.rpcnow return 400, and stale keys in stored JSON are stripped on read, so they are never returned or written back.createClusterRpc) and fail closed when the deployment has no endpoint for that cluster.@sdp/rpc/blocked-address.rpc_connectionsorrpc_credential_mode, so this deploys safely onto the current schema. feat(db): drop BYOK RPC tables, credentials, and settings keys #2217 carries the contraction and must ship in a later release than this one: running 0123 under old pods breaks them, and rolling back after it runs is unsafe.BREAKING CHANGE:
/v1/rpc/providersand/v1/rpc/testare removed;/v1/rpc/proxydropsprojectId; RPC keys in project/org settings return 400.Verification: tsc clean on api/web/rpc/types; biome clean; sdp-rpc 66/66 node tests. Not run locally: the API and web vitest suites (CI runs them). Local app (devnet, Pi, 13/13 pass): relay genesis, key masking and rotation; removed routes 404; faucet, signer-check, transfer, issuance deploy+mint.