fix(deps): update dependency @opentelemetry/auto-instrumentations-node to ^0.80.0 - #71
Closed
renovate[bot] wants to merge 75 commits into
Closed
renovate[bot] wants to merge 75 commits into
renovate[bot] wants to merge 75 commits into
Conversation
Deliver Mantle product CloudEvents to halo-api's /catalog-sync webhook (envelope mode, x-catalog-signature). hmacSecret must match halo-api's CATALOG_WEBHOOK_SECRET.
Upserts the halo-order-confirmed workflow and creates a per-organization event routing rule (halo.order.confirmed / omni.halo). Run once per Halo store org that should send order emails.
The halo-order-confirmed workflow now prefers Herald (when HERALD_SEND_ENABLED is set on the worker) and falls back to Resend; update the seed's docstring to match.
Iggy's topic messageExpiry is microseconds; we passed RETENTION_SECONDS (7,776,000 = 90 days in seconds) directly, so the server interpreted it as ~7.776s and deleted events ~8s after publish. Extract a RETENTION_MICROSECONDS constant (seconds * 1_000_000) and use it. Existing topics updated out-of-band. Contributing bug, not the full cause: the worker's Iggy consumer also hangs on message.poll after the startup drain (fixed separately).
eventWorkflows.seed runs at vortex-api boot and UPDATES existing workflows (idempotent upsert), so it was the real source of truth: it would overwrite the live gatekeeper-email-send and fractal-email-send workflows back to Resend on every deploy. Both now send via Herald's POST /messages, matching the worker templates. This is what unblocks deleting the Resend account.
…d one (#63) * chore(authz): use the providers Warden client instead of a hand-rolled one Replace the bespoke Warden client (circuit breaker, TTL cache, fetch to /check and /tuples) with @omnidotdev/providers createAuthzProvider, making providers the single source of truth for the transport. writeTuples, deleteTuples, and checkPermission keep their signatures (the existing call seam, including graphile-export EXPORTABLE usage) and delegate to the providers client, which authenticates with the service key. The authz instance is kept local to this module rather than the shared lib/providers so authz mocking in other test files cannot destabilize it. * fix(graphql): make plugin helpers exportable and regenerate schema graphql:generate was failing on master: the createMcpServer mutation and the eventLog audit-log plans reference the authorize and checkFeatureEnabled helpers, which graphile-export inlined and failed on because they reference module-scope values. Add both to the exportSchema modules map so they are emitted as imports instead of inlined. Regenerate the executable schema and SDL, which were stale because generation had been failing. Pre-dates the providers authz client migration in this branch. * chore(catalog): regenerate integration catalog from installed pieces Refresh the integration catalog from the vortex-worker generator so the freshness check passes (it flags catalogs older than 7 days, and this one was 15 days old). Regenerated from the current @activepieces piece set: 602 of 604 installed pieces loaded (airtable and amazon-ses fail to load at the piece level). --------- Co-authored-by: Brian Cooper <brian@brian-cooper.com>
#64) * refactor(server): make module import side-effect-free and add test seams Importing lib/config/env.config previously validated required variables (and logged optional-integration warnings) at module load, throwing before any test could import its system under test. That import-time throw is what forced unit tests to mock env.config (and, transitively, db/providers/cache) just to load the code they exercise. Move the validation and startup warnings into an exported validateEnv() called from the server bootstrap, so importing the module has no side effects while the running server keeps its fail-fast behavior. Add a silent log level so tests can mute output via LOG_LEVEL. Add optional dependency parameters (defaulting to the real singletons and env flags) to the functions unit tests need to control: isExecutionAllowed, the authorize wrapper, validateSession, resolveAuth, and the workflow cron lock helpers. Production call sites are unchanged; tests pass fakes instead of mutating the global module registry. * test(vortex): run the unit suite in one process without module mocking Bun's mock.module is process-global and permanent, so the 14 unit files that mocked the same modules (env.config, db, warden/client, providers, cache, logger) to conflicting shapes leaked state across a shared-process run. The workaround was scripts/test.ts, which spawned a fresh bun process per file: it is correct but slow and costly to scale in CI. With imports now side-effect-free, a preloaded setup.ts sets a hermetic, silent environment (required vars defaulted with ??= so an explicit env file still wins; authz/billing/cache intentionally unset so their clients resolve to null). Tests then inject fakes through the new dependency parameters instead of mocking modules. Several cases that only exercised an in-memory fake (user provisioning, workflow run records) or asserted on a stub now use a local fake directly, and a few vacuous or stale assertions were dropped or corrected. Two single-file mocks remain by necessity and are leakage-safe because no other test imports the module: lib/integrations/catalogSync (avoids real npm/registry I/O) and server (keeps exercising the publish plugin from booting the server entrypoint). Delete scripts/test.ts and run the suite with a plain `bun test`. * test(vortex): remove orphaned helm chart assertions The project no longer maintains a Helm chart (deploy is Pulumi / docker compose, per the metarepo README). helmChart.test.ts read a chart template that is neither tracked nor generated, so it errored at module load. Remove it. * chore(catalog): regenerate integration catalog from installed pieces Refresh the integration catalog from the vortex-worker generator so the freshness check passes (it flags catalogs older than 7 days, and this one was 15 days old). Regenerated from the current @activepieces piece set: 602 of 604 installed pieces loaded (airtable and amazon-ses fail to load at the piece level). * ci(vortex): run the unit suite in a single bun test step CI sharded the suite into five `bun test` invocations to work around mock.module leaking across a shared process. That leakage is gone, so collapse the steps into one `bun test`. The Postgres service and migration step are kept as a sanity check that migrations apply cleanly; the hermetic suite itself uses no real database. Also force the optional integrations (billing, authz, cache) off in the test preload so the suite is deterministic regardless of the ambient environment. CI set BILLING_BASE_URL, which made the self-hosted entitlement tests see billing as configured and fail; the preload now unsets these so their clients resolve to null and tests inject the enabled paths explicitly. --------- Co-authored-by: Brian Cooper <brian@brian-cooper.com>
The functional migration off Resend already landed; update the gatekeeper workflow description and halo order-email comment to reference Herald.
* refactor(server): make module import side-effect-free and add test seams Importing lib/config/env.config previously validated required variables (and logged optional-integration warnings) at module load, throwing before any test could import its system under test. That import-time throw is what forced unit tests to mock env.config (and, transitively, db/providers/cache) just to load the code they exercise. Move the validation and startup warnings into an exported validateEnv() called from the server bootstrap, so importing the module has no side effects while the running server keeps its fail-fast behavior. Add a silent log level so tests can mute output via LOG_LEVEL. Add optional dependency parameters (defaulting to the real singletons and env flags) to the functions unit tests need to control: isExecutionAllowed, the authorize wrapper, validateSession, resolveAuth, and the workflow cron lock helpers. Production call sites are unchanged; tests pass fakes instead of mutating the global module registry. * test(vortex): run the unit suite in one process without module mocking Bun's mock.module is process-global and permanent, so the 14 unit files that mocked the same modules (env.config, db, warden/client, providers, cache, logger) to conflicting shapes leaked state across a shared-process run. The workaround was scripts/test.ts, which spawned a fresh bun process per file: it is correct but slow and costly to scale in CI. With imports now side-effect-free, a preloaded setup.ts sets a hermetic, silent environment (required vars defaulted with ??= so an explicit env file still wins; authz/billing/cache intentionally unset so their clients resolve to null). Tests then inject fakes through the new dependency parameters instead of mocking modules. Several cases that only exercised an in-memory fake (user provisioning, workflow run records) or asserted on a stub now use a local fake directly, and a few vacuous or stale assertions were dropped or corrected. Two single-file mocks remain by necessity and are leakage-safe because no other test imports the module: lib/integrations/catalogSync (avoids real npm/registry I/O) and server (keeps exercising the publish plugin from booting the server entrypoint). Delete scripts/test.ts and run the suite with a plain `bun test`. * test(vortex): remove orphaned helm chart assertions The project no longer maintains a Helm chart (deploy is Pulumi / docker compose, per the metarepo README). helmChart.test.ts read a chart template that is neither tracked nor generated, so it errored at module load. Remove it. * chore(catalog): regenerate integration catalog from installed pieces Refresh the integration catalog from the vortex-worker generator so the freshness check passes (it flags catalogs older than 7 days, and this one was 15 days old). Regenerated from the current @activepieces piece set: 602 of 604 installed pieces loaded (airtable and amazon-ses fail to load at the piece level). * ci(vortex): run the unit suite in a single bun test step CI sharded the suite into five `bun test` invocations to work around mock.module leaking across a shared process. That leakage is gone, so collapse the steps into one `bun test`. The Postgres service and migration step are kept as a sanity check that migrations apply cleanly; the hermetic suite itself uses no real database. Also force the optional integrations (billing, authz, cache) off in the test preload so the suite is deterministic regardless of the ambient environment. CI set BILLING_BASE_URL, which made the self-hosted entitlement tests see billing as configured and fail; the preload now unsets these so their clients resolve to null and tests inject the enabled paths explicitly. * feat(events): migrate to apache-iggy@0.8.0 SDK Replace the legacy @iggy.rs/sdk@1.0.6 with the maintained, version-matched apache-iggy@0.8.0 (the publish-side counterpart to the vortex-worker change). import @iggy.rs/sdk -> apache-iggy; CompressionAlgorithmKind -> CompressionAlgorithm; topic.create drops the topicId field. send already used partition + names, so the publish path is otherwise unchanged. Requires the server on apache/iggy:0.8.x (separate infra change). --------- Co-authored-by: hobbescodes <hobbes@omni.dev>
apache-iggy/iggy 0.8.x server-assigns stream ids (the SDK does not
serialize a requested numeric id), so referencing the stream by numeric
STREAM_ID=1 failed every send with 'Stream with ID not found'. Reference
the stream by its stable name ('omni-events') and drop the ignored
streamId from stream.create. (Follow-up to the apache-iggy migration.)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
bun 1.3.13's bundler emits a module init-order bug for this source (`ReferenceError: PROTECT_ROUTES is not defined` at boot from the bundled env.config). bun 1.3.14 bundles the same source correctly (verified locally; the worker image is already on 1.3.14). Surfaced when the apache-iggy change shifted the bundle.
The bundled build crashed at boot with 'ReferenceError: PROTECT_ROUTES is not defined'. bun build bundles server.ts + instrumentation.ts together and could order this module's top-level destructuring after another module that consumes its exports at init, leaving the destructured consts in the TDZ. The module-init computed exports (isDevEnv/isProdEnv/LOG_LEVEL/protectRoutes/ isAuthzEnabled/hasBilling) now read the always-available process.env global directly, so no init-time reference to a not-yet-initialized const remains. validateEnv()/getOAuthCredentials() and the re-exports keep the destructured consts (used at runtime, not init).
Nothing imports the raw PROTECT_ROUTES (the computed protectRoutes reads process.env directly), but the bundler's re-export setup referenced the destructured const before init, crashing the bundled build with 'ReferenceError: PROTECT_ROUTES is not defined'. Remove the dead binding (destructure + re-export) entirely.
bun build mangles the `const { ... } = process.env` destructuring under this
bundle, emitting TDZ references to each bare const and crashing at boot
(ReferenceError: PROTECT_ROUTES / AUTH_DEBUG / ... is not defined - it moved
to the next bare var each time one was removed). Individual
`const X = process.env.X` initializers bundle cleanly. No behavior change.
The dev-only `tls: { certFile, keyFile }` passed non-existent key.pem/cert.pem,
which bun >= 1.3.14's Bun.serve rejects with 'Unable to access keyFile path'
(older bun tolerated it). The api runs behind the TLS-terminating ingress in
production, so guard the TLS block on the cert files actually existing -
plain HTTP otherwise.
apache-iggy stream.get/topic.get return null when absent rather than
throwing, so the try{get}catch{create} pattern never created the stream or
topics (the catch never fired) and every publish failed 'Stream not found'.
Check the null result instead.
The fractal.* routing rule matched every fractal CloudEvent, including the high-frequency owner-less firehose (service.reconciled, rebuild_triggered, backup.*; ~1.7M events). Each spawned a workflow run that could never resolve a recipient, churning Bun worker threads until the worker segfaulted under memory pressure (exit 139) every few hours. Add a celCondition requiring a non-empty event.data.owner so only the owner-bearing events the workflow actually emails on (deploy.succeeded, service.crashed, build.failed) route. Wire celCondition through the seed's insert/update so fresh seeds and re-seeds stay in sync with the live fix already applied to prod.
Switch the fractal-email-send code steps from the Bun Worker sandbox to the in-process "native" sandbox, eliminating the per-execution Worker spawn/terminate churn that segfaulted vortex-worker under load. The worker gates "native" to the platform org (vortex-worker 9f04810); non-platform orgs are transparently downgraded to "worker". The native-capable worker is already deployed, so the startup re-seed activates this safely.
Add catalog schemas for the account-security domain events Gatekeeper now emits (password_changed, two_factor_enabled, two_factor_disabled). These are audit/fan-out signals; the user-facing alert is sent directly by Gatekeeper, so they are not routed to the email-send workflow.
Codify the verified prod hotfix that activated Halo order-confirmation emails into the boot seed so a fresh environment reproduces it. - Add the canonical, prod-verified definition as haloOrderConfirmed.workflow.json and seed it as the halo-order-confirmed system workflow with a halo.order.confirmed / omni.halo routing rule under the platform org. This is the first hatchet executor workflow (existing seeds are temporal). - Derive the workflow executor from definition.executor on both insert and update instead of hardcoding "temporal", so hatchet workflows seed correctly on fresh envs (no-op for the existing temporal workflows). - Remove the obsolete scripts/seedHaloOrderEmailWorkflow.ts: it is broken in prod (its createEventRoutingRule mutation needs a Gatekeeper user observer the service key lacks) and fully replaced by the boot seed.
Seed an event_subscription under the platform org that forwards backfeed.* events to Chronicle's ingest endpoint (HMAC-signed, envelope mode, JSONata transform to Chronicle's schema). Env-gated on CHRONICLE_API_URL / CHRONICLE_WEBHOOK_SECRET so boot degrades gracefully when unset. Transform key order matches Chronicle's ingest schema (it verifies the HMAC over the re-serialized body).
Seed per-entity Chronicle subscriptions for Herald, scoped to its audit event types (herald.sending_domain.*, herald.api_key.*). Herald's high-volume herald.message.* delivery telemetry is deliberately excluded: it is not audit data and would flood the audit log, and matchGlobPattern treats * as .* so a single herald.* cannot exclude it. Parameterizes chronicleSubscription with an optional typePattern (defaulting to the whole product stream, unchanged for backfeed/runa).
…#81) * chore(catalog): refresh integration catalog timestamp * fix(events): pin ingested event source to the authenticated principal The `/api/v1/events` ingest endpoint let any caller set an arbitrary CloudEvents `source`, including the reserved `omni.platform` used by the Omni API for `platform.plan.*` mutations. A tenant/product key could forge that source and have the worker amplify it into a platform-wide Aether entitlement reseed. Pin `source` via `resolveEventSource`: only the internal service principal may emit `omni.platform`; other keys forging it get 403. Also wire `idempotencyKey` end to end (ingest body and the GraphQL publishEvent mutation, previously accepted and ignored) so the worker can deduplicate on it rather than on the shared `correlationId`.
renovate
Bot
force-pushed
the
renovate/opentelemetry-js-contrib-monorepo
branch
from
August 31, 2026 21:17
b456dad to
5612d52
Compare
…83) This service builds its S3 client with the default @aws-sdk/client-s3 request handler, which pools keep-alive sockets with no aborting request timeout. Against an S3 endpoint reached over a NAT/edge that silently idle-drops connections, the pool fills with zombie sockets and every reuse hangs ~30s until the upstream 503s. This is the failure that took down halo-api media serving on 2026-09-01; hardening here pre-empts it. Route the client through a shared createResilientS3Client factory: keepAlive:false so a socket is never reused, plus requestTimeout with throwOnRequestTimeout (a plain requestTimeout on @smithy/node-http-handler v4 only warns and keeps hanging on Bun) and a connectionTimeout. Regression tests assert the config.
Manual seed (mirrors seedFractalEmailWorkflow) that upserts the halo-order-email-send workflow and an event routing rule for halo.order.confirmed / omni.halo. Run to activate store-branded order receipts; prereq: vortex-worker env HALO_API_URL + HALO_INTERNAL_SERVICE_KEY.
The check-seller condition compared inside the template braces
(`{{ steps['build-emails'].output.hasSeller === true }}`). The DSL
executor treats everything between {{ }} as a single path, so the whole
`... === true` was resolved as a lookup, returned undefined, and the
condition always evaluated false: the seller was never emailed even when
a seller existed. Move the comparison outside the braces so the resolved
boolean is compared.
The halo order-email pipeline is already covered by the boot-seeded halo-order-confirmed system workflow (eventWorkflows.seed.ts). This standalone script registered a duplicate workflow that would double-send; it was never run against a live environment. Removing it.
Store/creator-branded donor receipt + creator notification for Crystal
donations, rendered inline from a self-contained crystal.donation.received
payload (hatchet), mirroring halo-order-confirmed. Uses the corrected
condition form (comparison outside the {{ }}) so the creator branch fires.
NOT yet wired into eventWorkflows.seed.ts: inert until crystal-api emits the
enriched payload and go-live is deliberate. Render logic unit-tested.
…inert) Payer receipt + creator notification workflows for the remaining Crystal paid flows (digital-product purchase, sponsorship created, sponsorship renewed [sponsor-only], bounty funded), mirroring crystal-donation-received: hatchet, inline render from self-contained payloads, corrected condition form, HTML-escaped. NOT wired into eventWorkflows.seed.ts (inert until a deliberate go-live). Payout intentionally omitted (Stripe Connect already emails Express account holders about payouts). Render logic unit-tested.
Sponsor-only cancellation confirmation for crystal.sponsorship.cancelled, mirroring the other crystal receipt workflows. Inert (not wired into eventWorkflows.seed.ts). Render logic unit-tested.
…(inert) Sponsor-only action-required notice on crystal.sponsorship.payment_failed, prompting a payment-method update to keep the sponsorship active. Inert (not wired into eventWorkflows.seed.ts); note double-send should be checked against Stripe Connect dunning at go-live. Render logic unit-tested.
Wire the Crystal receipt/notification workflows into the boot seed so they route live: donation, digital-product purchase, sponsorship created/renewed/ cancelled, and bounty funded. Sponsorship payment-failed dunning is held out pending a Stripe Connect dunning-settings check (double-send risk).
Stripe's failed-payment customer emails are off by default and follow the connected account's settings for direct charges; Crystal creates Express accounts without enabling them, so Stripe sends sponsors no dunning email. Ours is therefore the only one (no double-send), so activate it.
Buyer dunning (halo.subscription.payment_failed) and cancellation confirmation (halo.subscription.canceled) workflows, wired into the boot seed. Closes the storefront-subscription email gap (renewals were already covered via the order path). Render logic unit-tested.
renovate
Bot
force-pushed
the
renovate/opentelemetry-js-contrib-monorepo
branch
from
September 7, 2026 17:16
5612d52 to
1ef5824
Compare
renovate
Bot
force-pushed
the
renovate/opentelemetry-js-contrib-monorepo
branch
from
September 15, 2026 20:47
1ef5824 to
719bfa4
Compare
…RLS backstop (#84) * chore(catalog): refresh integration catalog timestamp * fix(security): lock down GraphQL mutations, fail closed on auth, add RLS backstop Pre-GTM security remediation (P0/P1). Closes the arbitrary CRUD and cross-tenant read surface on the Postgraphile schema: - Omit all auto-generated mutations for user, user_organization, oauth_token, and ~20 internal tables via smart tags; drop `*ById` (nodeId) mutation variants globally. Mutation surface is now the 7 guarded entities' PK CUD + publishEvent. - Fail closed on a null observer: remove the fail-open Bearer branch in the auth gate; scopeSingleItem / scopeChildSingleItem no longer early-return when the observer is null. - Scope node(id) and userOrganization(s); remove user/users/userByEmail/ userByIdentityProviderId root queries and userById/outboxById node accessors (PII enumeration surface gone). - Omit oauth_token.access_token / refresh_token from the schema entirely. - Enable RLS + organization_isolation policy on 19 org tables as a backstop (not forced; inert under the owner role today). - Fail closed when AUTHZ_API_URL is unset; assert it required in production. - Move the workflow webhook secret to an x-webhook-secret header; timing-safe service-key comparison on /authz. - Build the schema at boot via makeSchema (drop the stale pre-compiled schema.executable.ts) so the lockdown is not inert in prod. Regression tests: authGateFailClosed, authorizeFailClosed, organizationScopeFailClosed, graphqlSchemaLockdown, rlsBackstop, webhookSecretHandling.
renovate
Bot
force-pushed
the
renovate/opentelemetry-js-contrib-monorepo
branch
from
September 18, 2026 04:37
719bfa4 to
088866f
Compare
renovate
Bot
force-pushed
the
renovate/opentelemetry-js-contrib-monorepo
branch
from
September 18, 2026 23:47
088866f to
9a0c77c
Compare
Author
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.76.0→^0.80.0Release Notes
open-telemetry/opentelemetry-js-contrib (@opentelemetry/auto-instrumentations-node)
v0.80.0Compare Source
Features
Dependencies
v0.79.0Compare Source
Features
Bug Fixes
Dependencies
v0.78.0Compare Source
Features
Dependencies
v0.77.0Compare Source
Features
Dependencies
Configuration
📅 Schedule: (in timezone America/Denver)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.