Skip to content

refactor(rpc)!: remove BYOK RPC and per-org/project RPC provider selection - #2216

Merged
multipletwigs merged 7 commits into
mainfrom
bashtwigs/hoo-1876-remove-byok-rpc-the-managed-pool-per-cluster-is-the-only-rpc
Oct 7, 2026
Merged

multipletwigs merged 7 commits into
mainfrom
bashtwigs/hoo-1876-remove-byok-rpc-the-managed-pool-per-cluster-is-the-only-rpc

Conversation

@multipletwigs

@multipletwigs multipletwigs commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Removes BYOK RPC end to end. Every project uses the deployment's managed RPC pool; nothing per org or project brings or selects an endpoint.

  • Deleted: /v1/rpc/providers, /v1/rpc/test, /internal/dashboard/rpc/*, tenant RPC connections, credential mode, the dashboard RPC integration pages, and the onboarding RPC step.
  • /v1/rpc/proxy stays, round-robin over the managed pool. It returns provider: { id, endpoint } and no longer takes a projectId query.
  • Project settings is null when unset (it was always an object with rpcProvider: "default"). Project and org settings are strict: rpcProvider, rpcEndpoint and providerOverrides.rpc now return 400, and stale keys in stored JSON are stripped on read, so they are never returned or written back.
  • Signer-check and Private Channels use the project's cluster (createClusterRpc) and fail closed when the deployment has no endpoint for that cluster.
  • Helius Rings keeps its guarded tenant-URL transport. The host guard moved to @sdp/rpc/blocked-address.
  • No migration here. The code never reads rpc_connections or rpc_credential_mode, so this deploys safely onto the current schema. feat(db): drop BYOK RPC tables, credentials, and settings keys #2217 carries the contraction and must ship in a later release than this one: running 0123 under old pods breaks them, and rolling back after it runs is unsafe.

BREAKING CHANGE: /v1/rpc/providers and /v1/rpc/test are removed; /v1/rpc/proxy drops projectId; RPC keys in project/org settings return 400.

Verification: tsc clean on api/web/rpc/types; biome clean; sdp-rpc 66/66 node tests. Not run locally: the API and web vitest suites (CI runs them). Local app (devnet, Pi, 13/13 pass): relay genesis, key masking and rotation; removed routes 404; faucet, signer-check, transfer, issuance deploy+mint.

…tion

Every project now reaches its cluster through the deployment's managed RPC
pool. Organizations no longer bring RPC URLs or credentials, and nothing per
organization or per project selects a provider.

- Delete tenant RPC connections, credential mode, the internal RPC routes,
  /v1/rpc/providers, /v1/rpc/test, and the dashboard RPC integration surfaces.
- The /v1/rpc/proxy relay is managed-pool only and reuses config's provider list.
- Drop the rpc provider family, project rpcProvider/rpcEndpoint, and the
  onboarding RPC step.
- Helius Rings keeps a guarded transport for its tenant URL; the host guard
  moves to @sdp/rpc/blocked-address.
- Migration 0123 drops rpc_connections, the RPC provider credentials, and
  organizations.rpc_credential_mode, and strips the RPC settings keys.
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
sdp-docs Ready Ready Preview Oct 7, 2026 11:12am UTC
sdp-web Ready Ready Preview Oct 7, 2026 11:12am UTC

Request Review

@linear

linear Bot commented Oct 5, 2026

Copy link
Copy Markdown

HOO-1876

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

React Doctor found no new issues. 🎉

Reviewed by React Doctor for commit 818a447.

@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Removes RPC provider selection and BYOK infrastructure.

The PR appears safe to merge on the findings assessed here; no new actionable issue remains.

Summary

This PR removes tenant-owned RPC selection and BYOK administration, leaving the managed RPC pool as the relay path. It also removes the associated dashboard and API surfaces, strips legacy RPC settings from responses, and selects cluster RPC for signer-check and Private Channels.

Reviews (7) · Last reviewed commit: "test(web): drop the removed rpc tab from..." · Reviewed by Greptile

Comment thread apps/sdp-api/src/routes/rpc/handlers.ts
Comment thread apps/sdp-api/src/db/migrations/postgres/0123_remove_byok_rpc.sql Outdated
Comment thread apps/sdp-web/messages/fr/dashboard-private-channels.json Outdated
…s out

The migration-compat policy requires a breaking contraction to land in a
migrations-only PR after the code that stops reading the dropped objects.
Localized catalogs are synced on the release PR.
…ive provider family in the Clerk override test
@multipletwigs

multipletwigs commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator Author

@greptile-apps please re-review Triton accepts the token in the URL path for JSON-RPC and WebSocket https://.mainnet.rpcpool.com/

@G1de0n G1de0n left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good overall: runtime no longer touches rpc_connections/rpc_credential_mode/settings.rpcProvider, the guard move is byte-for-byte, proxy stays metered and doesn't expose the endpoint URL. A few things before merge:

  1. Triton auth header dropped. On main resolveManagedProviders sent x-api-key: SOLANA_RPC_TRITON_API_KEY; ManagedRpcProvider is now { id, url } and relayToTarget only sends Content-Type. Unless SOLANA_RPC_TRITON_URL carries {API_KEY}, ~1/N proxy calls will 401 under round-robin. Please carry headers through the managed provider → relay target, or confirm the URL template in Doppler.
  2. Private Channels RPC ignores the project cluster. project-rpc.ts:62 builds createRpc(env) while cluster comes from the project environment. A production project on a SOLANA_NETWORK=devnet deployment reconciles against devnet and can fail a real deposit as "not found on chain". createClusterRpc(input.env, cluster) already exists (used by sponsorship) and fails closed. Same applies to signer-check.ts:109.
  3. Legacy settings are silently accepted and echoed. projects/schemas.ts and organizations/schemas.ts settings objects aren't .strict(), so rpcProvider gets a 200 no-op while OpenAPI says strict; project.service.ts:409 casts stored JSON unchecked and :185 writes stale keys back on every PATCH. .strict() + a zod parse on read removes the "stale keys on GET" caveat regardless of when #2217 runs.

Nits: mark the commit as breaking (refactor(rpc)!: + BREAKING CHANGE:, body still mentions migration 0123); add a non-dev test that Rings tenant URLs go through the guarded transport and loopback is refused; @solana/addresses is unused in packages/sdp-rpc. Deploy note: #2217 should go out in a later release than this one, since running 0123 during this rollout breaks old pods, and rollback is unsafe after it.

…cluster; reject and strip stale settings keys

- signer-check and loadProjectRpcClient use createClusterRpc with the
  project's cluster, failing closed when the deployment has no endpoint
  for it.
- Project and organization settings are strict on write; stored project
  settings are parsed on read so removed keys are neither returned nor
  merged back.
- Drop the unused @solana/addresses dependency from sdp-rpc.
@multipletwigs multipletwigs changed the title refactor(rpc): remove BYOK RPC and per-org/project RPC provider selection refactor(rpc)!: remove BYOK RPC and per-org/project RPC provider selection Oct 7, 2026
Comment thread apps/sdp-api/src/routes/organizations/schemas.ts
…d Rings tenant transport

- signer-check and loadProjectRpcClient assertions move to createClusterRpc;
  production projects resolve mainnet-beta and fail closed without an endpoint.
- Project/org settings reject removed keys; stored stale keys are stripped on
  read and not merged back.
- Rings tenant URLs outside development go through guardedFetch; loopback is
  refused before any request.

@G1de0n G1de0n left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removal looks clean. Nothing reads rpc_connections, rpc_credential_mode or rpcProvider at runtime anymore, the proxy is still metered, and the Rings guard is intact.

Before merge

  1. GET /provider-access no longer returns providers.rpc. The current web does Object.entries(data.providers.rpc), so the integrations page will crash during the web/API deploy skew. Return rpc: {} for one release.
  2. Org settings: GET returns stored keys as-is, stale rpcProvider included, but PATCH is strict. A GET→PATCH round trip 400s on keys we just returned, and regular PATCHes merge the stale keys back in. Use a plain object with an explicit 400 for the removed RPC keys, and strip them on read like projects do.

Non-blocking

  • Map the missing-endpoint Error to a typed AppError and add a test.
  • Use safeParse in parseStoredProjectSettings.
  • Can you confirm the prod Triton URL also carries the key? Prod has SOLANA_RPC_TRITON_API_KEY set.
  • Dead code: KVStoreSet, ORGANIZATION_RPC_PROVIDERS naming, the "configured RPC" i18n copy, organizationSettingsDescription.

#2217

  • 0123 collides with 0123_earn_observed_payout_keys on main.
  • Deleting provider_credentials should also queue secret_retirements for the BYOK secret versions.

@multipletwigs

Copy link
Copy Markdown
Collaborator Author

Thanks @G1de0n.

  1. providers.rpc: we're not shimming it. refactor(rpc)!: remove BYOK RPC and per-org/project RPC provider selection #2216 and feat(db): drop BYOK RPC tables, credentials, and settings keys #2217 ship in one deploy, and there's no live traffic on the dashboard to hit the skew window.
  2. Org settings: 0123_remove_byok_rpc.sql in feat(db): drop BYOK RPC tables, credentials, and settings keys #2217 strips rpcProvider and providerOverrides.rpc from stored settings, so GET stops returning them and the strict PATCH correctly 400s any client still sending them. A read-side strip here would be dead once 0123 runs. I'll renumber 0123 in feat(db): drop BYOK RPC tables, credentials, and settings keys #2217 for the collision.

The parseOrganizationSettings swallow and the unused webhookSecret field are going into a separate cleanup.

@multipletwigs
multipletwigs requested a review from G1de0n October 7, 2026 12:35
@multipletwigs
multipletwigs merged commit 9c501de into main Oct 7, 2026
62 checks passed
@multipletwigs
multipletwigs deleted the bashtwigs/hoo-1876-remove-byok-rpc-the-managed-pool-per-cluster-is-the-only-rpc branch October 7, 2026 13:09
multipletwigs added a commit that referenced this pull request Oct 7, 2026
Contraction for #2216: drops rpc_connections and
organizations.rpc_credential_mode, deletes the RPC-provider
provider_credentials rows, and strips the RPC settings keys. Merge after
#2216 is deployed.
multipletwigs added a commit that referenced this pull request Oct 7, 2026
* refactor(rpc): remove BYOK RPC and per-org/project RPC provider selection

Every project now reaches its cluster through the deployment's managed RPC
pool. Organizations no longer bring RPC URLs or credentials, and nothing per
organization or per project selects a provider.

- Delete tenant RPC connections, credential mode, the internal RPC routes,
  /v1/rpc/providers, /v1/rpc/test, and the dashboard RPC integration surfaces.
- The /v1/rpc/proxy relay is managed-pool only and reuses config's provider list.
- Drop the rpc provider family, project rpcProvider/rpcEndpoint, and the
  onboarding RPC step.
- Helius Rings keeps a guarded transport for its tenant URL; the host guard
  moves to @sdp/rpc/blocked-address.
- Migration 0123 drops rpc_connections, the RPC provider credentials, and
  organizations.rpc_credential_mode, and strips the RPC settings keys.

* chore(rpc): ship migration 0123 separately and keep localized catalogs out

The migration-compat policy requires a breaking contraction to land in a
migrations-only PR after the code that stops reading the dropped objects.
Localized catalogs are synced on the release PR.

* feat(db): drop BYOK RPC tables, credentials, and settings keys

Contraction for #2216: drops rpc_connections and
organizations.rpc_credential_mode, deletes the RPC-provider
provider_credentials rows, and strips the RPC settings keys. Merge after
#2216 is deployed.

* test(api): seed custody config and wallet in one transaction; use a live provider family in the Clerk override test

* fix(db): leave RPC-only settings as NULL after stripping the RPC keys

* fix(db): queue RPC credentials' GCP secret versions for retirement before deleting them

* fix(api): scope signer-check and Private Channels RPC to the project cluster; reject and strip stale settings keys

- signer-check and loadProjectRpcClient use createClusterRpc with the
  project's cluster, failing closed when the deployment has no endpoint
  for it.
- Project and organization settings are strict on write; stored project
  settings are parsed on read so removed keys are neither returned nor
  merged back.
- Drop the unused @solana/addresses dependency from sdp-rpc.

* test(api): cover project-cluster RPC, strict settings, and the guarded Rings tenant transport

- signer-check and loadProjectRpcClient assertions move to createClusterRpc;
  production projects resolve mainnet-beta and fail closed without an endpoint.
- Project/org settings reject removed keys; stored stale keys are stripped on
  read and not merged back.
- Rings tenant URLs outside development go through guardedFetch; loopback is
  refused before any request.

* test(web): drop the removed rpc tab from the Integrations submenu tab cases

* chore(db): renumber the BYOK RPC removal migration to 0124 after main's 0123

* fix(db): tag BYOK RPC secret retirements with the renumbered 0124 migration

This branch was successfully deployed

2 active deployments
Preview – sdp-web — 818a4475 Deployed Oct 7, 2026 by vercel[bot]
Preview – sdp-docs — 818a4475 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants