feat(hosted): serve the rollback witness from the deployment-test control plane - #434
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…trol plane The hosted-path deployment test routes pairing and relay traffic, but /v1/e2ee/witness returned 404, so no real E2EE endpoint could register or advance against it and a phone could not pair through AWS. The deployment-test control plane now assembles a WitnessGateway over three in-process WitnessReplicas when AXL_TEST_WITNESS_KEYS is set: - Each replica signs with its own Ed25519 key from the new axl/hosted-path/witness-keys secret, which deploy.sh generates once. Admission, registration, and binding lookup accept only the single deployment-test account, matched against the request lineage. - Replica state is process memory. A replica can recover persisted state only from fresh endpoint-signed reads covering every lineage, so a restarted control plane starts empty instead and earlier endpoints fail closed until they pair again. The README says so. - Empty replicas bootstrap with one registration. The first signed read of that lineage drives the ordinary recovery exchange (each replica's recovery head, then recovery from the other two receipts), after which the replicas are ready for further lineages. - witness-trust.sh writes the public trust in the canonical ReplicaTrustSet configuration form for deployment-test client builds. Only public keys leave the secret. - /healthz reports whether the witness is served and the smoke test requires it. Checked locally against the native daemon and device endpoints built from the encoded trust: registration, bootstrap to ready on the first read, a second lineage after ready, and rejection of a foreign account. This is not the production witness topology: one process, one account, one failure domain. Signed-off-by: Lokesh <lokeshselvam7025@gmail.com>
a207c90 to
f5508e6
Compare
E2EE pairing accepts only UUIDv7 installation, crypto session, and device identities, but deploy.sh generated the deployment-test installation and device IDs with uuid4. A real endpoint registering with the stack's installation failed with identity_mismatch, so the stack could never pair an E2EE device. Generate both as UUIDv7; the account and relay instance IDs are not E2EE identities and stay uuid4. An existing secret keeps its values: deploy.sh only creates a missing secret, so rotate an older stack's secret to pick this up. Signed-off-by: Lokesh <lokeshselvam7025@gmail.com>
Summary
The hosted-path deployment test served pairing rendezvous and relay traffic but returned 404 on
/v1/e2ee/witness. As a result, no real E2EE endpoint could register or advance against AWS, and a phone could not pair through it. This PR serves the rollback witness from the deployment-test control plane.services/aws-control-plane/src/witness-deployment-test.tscreates aWitnessGatewayover three in-processWitnessReplicas. It is enabled only whenAXL_TEST_WITNESS_KEYSis set; without it the witness path stays unrouted, as it is today.axl/hosted-path/witness-keyssecret.deploy.shgenerates the secret once, and Terraform passes it to the control-plane task.witness-trust.shwrites the public trust in the canonicalReplicaTrustSetconfiguration form forAXL_E2EE_DEPLOYMENT_TEST_TRUST_FILE. Only public keys leave the secret./healthzreports whether the witness is served, and the smoke test requires it.Known limitation
Replica state lives only in process memory. A replica can recover persisted state only from fresh endpoint-signed reads covering every lineage, and nothing orchestrates that across a restart yet. A restarted or redeployed control plane therefore starts every replica empty. Endpoints registered before the restart then fail closed and must pair again. The stack README documents this.
This is not the production witness topology: one process, one account, one failure domain. Production gates are unchanged.
Test plan
pnpm --filter @axl/aws-control-plane typecheckandbuildterraform fmtandterraform validate;bash -non the stack scriptsReplicaTrustSet::decode_config)witness_unavailableforbiddensmoke-test.shAlso fixed: UUIDv7 identities
E2EE pairing accepts only UUIDv7 installation, crypto session, and device identities.
deploy.shgenerated the stack's installation and device IDs withuuid4, so a real endpoint using the stack's installation failed withidentity_mismatch. It now generates both as UUIDv7. An existing secret keeps its values, so an older stack needs its runtime secret rotated to pick this up.Deployed
axl-deploydeployment-test stack (ap-south-2) from this branch.smoke-test.shpasses;/healthzreports"witness":true.witness-trust.shregistered through the AWS witness (certified by all three replicas), then read and reconciledready.