Skip to content

vapi: pin search backend to origin IP (bypass broken CF colo path) - #926

Merged
feruzm merged 2 commits into
developfrom
feature/vapi-search-backend-pin
Jun 8, 2026
Merged

feruzm merged 2 commits into
developfrom
feature/vapi-search-backend-pin

Conversation

@feruzm

@feruzm feruzm commented Jun 8, 2026 •

Copy link
Copy Markdown
Member

Problem

vapi proxies search to api.hivesearcher.com (Cloudflare-proxied → the search origin). A degraded CF colo↔origin leg can make that server-to-server hop hang for minutes while the origin itself is healthy.

On 2026-06-08 the rebuilt US origin's vapi → api.hivesearcher.com hung 12–25s via the CF PDX colo (origin-direct was 1.2s). Since the CF worker routes US traffic to the US origin, all US-routed search + read-next broke: the SSR /similar prefetch aborted at the 2s SSR cap (no strip) and the client fetch aborted at the 4s cap (the 4000ms status-0 request in GTmetrix HARs). sin2/eu were fine (healthy colos).

Fix

Pin api.hivesearcher.com → the origin IP in the vapi service via extra_hosts, so vapi connects directly (bypassing CF), keeping the hostname for SNI/LE-cert and using the whitelisted IPv4.

  • The IP is supplied by a new HIVESEARCHER_ORIGIN_IP secret, wired through the deploy envs in master.yml (EU/US/SG) and staging.yml — so it never appears in this public repo.
  • Fails the deploy loudly (:?) if the secret is missing, rather than silently degrading.
  • vision-api's deploy uses docker service update --image (image-only), so it preserves this extra_hosts — no change needed there.

Applied as a runtime --host-add on all 3 origins already (immediate fix: US 12s→1.2s); this makes it survive docker stack deploy.

Before merge

The HIVESEARCHER_ORIGIN_IP repo secret is set. Update it if the search box IP ever changes.

Test plan

  • docker compose config resolves extra_hosts to the IP with the var set, and fails loudly without it.
  • No IP literal in the diff; YAML valid.

Summary by CodeRabbit

  • Chores
    • Updated deployment workflows and service configurations to optimize network routing reliability.

vapi reaches the search backend via api.hivesearcher.com (Cloudflare-proxied).
A bad CF colo<->origin leg can make that hop hang for minutes while the origin
is healthy — on 2026-06-08 the rebuilt US origin's vapi hung 12-25s via the CF
PDX colo, breaking all US-routed search and read-next (SSR /similar prefetch
aborted at the 2s cap, client fetch at 4s). Origin-direct was 1.2s.

Pin api.hivesearcher.com -> origin IP in the vapi service so it connects
directly (keeps the hostname for SNI/cert, uses the whitelisted IPv4). The IP
comes from the HIVESEARCHER_ORIGIN_IP secret (wired through the deploy envs in
master.yml/staging.yml) so it never lands in this public repo; the compose
fails the deploy loudly if the secret is missing. vision-api's deploy updates
only the image (docker service update --image), so it preserves this.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c94781152

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

HIVESIGNER_SECRET: ${{secrets.HIVESIGNER_SECRET}}
SEARCH_API_ADDR: ${{secrets.SEARCH_API_ADDR}}
SEARCH_API_SECRET: ${{secrets.SEARCH_API_SECRET}}
HIVESEARCHER_ORIGIN_IP: ${{secrets.HIVESEARCHER_ORIGIN_IP}}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Forward the new secret through ssh-action envs

In the inspected deploy jobs, adding HIVESEARCHER_ORIGIN_IP only under env: does not make it available inside the remote script; appleboy/ssh-action forwards only variables named in with.envs, and the envs: lists below still omit this new variable. Because the compose files now require ${HIVESEARCHER_ORIGIN_IP:?…}, docker-compose config will fail with the variable unset on the EU/US/SG production deploys (and staging has the same omission) even when the GitHub repo secret exists.

Useful? React with 👍 / 👎.

@greptile-apps

greptile-apps Bot commented Jun 8, 2026 •

Copy link
Copy Markdown

Greptile Summary

This PR pins api.hivesearcher.com to its origin IP in the vapi Docker service via extra_hosts, bypassing a degraded Cloudflare colo↔origin leg that was causing 12–25s hangs on US-routed search requests. The HIVESEARCHER_ORIGIN_IP secret is wired through all three deploy jobs in master.yml (EU/US/SG) and staging.yml with proper propagation at all three layers required by appleboy/ssh-action.

  • Docker Compose: Both docker-compose.yml (staging) and docker-compose.production.yml gain the same extra_hosts entry using ${HIVESEARCHER_ORIGIN_IP:?…} — fail-loud if the secret is missing, never exposes the IP in the repo.
  • CI workflows: HIVESEARCHER_ORIGIN_IP is correctly added to each job's env: block, the SSH action's envs: forwarding list, and the export statement in the remote script body — all three propagation layers are present for every origin.
  • Previous review gap resolved: The earlier finding that the variable never reached the remote host has been fully addressed in this revision.

Confidence Score: 5/5

Safe to merge — the fix is complete, well-scoped, and the previous review's forwarding gap has been resolved in all three deploy jobs.

All three propagation layers (env block, SSH envs list, remote export) are correctly added for every origin job in master.yml and for staging.yml. The Docker Compose extra_hosts entry uses :? fail-loud semantics so a missing secret surfaces immediately at deploy time rather than silently falling back to a broken CF path. No IP literal is committed to the repo. The change is narrowly targeted with no application code touched.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/master.yml Adds HIVESEARCHER_ORIGIN_IP to env block, envs forwarding list, and export in all three origin jobs (EU, US, SG) — all three propagation layers are present and consistent.
.github/workflows/staging.yml Adds HIVESEARCHER_ORIGIN_IP to env block, envs forwarding list, and export in the staging job — all three propagation layers match the master.yml pattern.
apps/web/docker-compose.production.yml Adds extra_hosts entry pinning api.hivesearcher.com to HIVESEARCHER_ORIGIN_IP with :? fail-loud syntax; well-commented explaining the CF bypass rationale.
apps/web/docker-compose.yml Same extra_hosts addition as production file; this is the staging compose file (develop image, 1 replica) so the :? fail-loud requirement is appropriate.

Sequence Diagram

sequenceDiagram
    participant GHA as GitHub Actions
    participant SSH as appleboy/ssh-action
    participant Remote as Remote Host
    participant DC as docker compose
    participant vapi as vapi container
    participant Origin as api.hivesearcher.com (origin IP)
    participant CF as Cloudflare CDN

    Note over GHA,Remote: Before this PR (broken path)
    GHA->>SSH: deploy (HIVESEARCHER_ORIGIN_IP missing from envs)
    SSH->>Remote: SSH script (var not forwarded)
    Remote->>DC: docker stack deploy (no extra_hosts)
    vapi->>CF: DNS → api.hivesearcher.com
    CF-->>vapi: route via degraded colo (12–25s hang)

    Note over GHA,Origin: After this PR (fixed path)
    GHA->>SSH: deploy (HIVESEARCHER_ORIGIN_IP in env+envs+export)
    SSH->>Remote: SSH script (var forwarded correctly)
    Remote->>DC: docker stack deploy (extra_hosts set)
    DC->>vapi: /etc/hosts: api.hivesearcher.com → origin IP
    vapi->>Origin: "direct TLS (SNI=api.hivesearcher.com, ~1.2s)"
    Note over vapi,Origin: Cloudflare colo bypassed entirely
Loading

Reviews (2): Last reviewed commit: "Forward HIVESEARCHER_ORIGIN_IP through s..." | Re-trigger Greptile

…deploy)

Setting it only under the step `env:` makes it available on the GitHub runner,
not in the remote deploy shell — so `docker-compose config` would see it empty
and the extra_hosts `:?` guard would fail every deploy. Add it to each job's
ssh-action `envs:` forwarding list and `export` it in the script, matching the
SEARCH_API_* pattern. (Addresses the PR review P1.)
@feruzm
feruzm merged commit 843f127 into develop Jun 8, 2026
4 of 5 checks passed
@feruzm
feruzm deleted the feature/vapi-search-backend-pin branch June 8, 2026 20:28
@coderabbitai

coderabbitai Bot commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 98c3f878-ef0b-4b52-8d13-414aa6caa634

📥 Commits

Reviewing files that changed from the base of the PR and between 8494302 and 274e933.

📒 Files selected for processing (4)
  • .github/workflows/master.yml
  • .github/workflows/staging.yml
  • apps/web/docker-compose.production.yml
  • apps/web/docker-compose.yml

📝 Walkthrough

Walkthrough

This PR introduces support for pinning the VAPI service directly to an origin IP address to mitigate Cloudflare connectivity hangs. The HIVESEARCHER_ORIGIN_IP secret is threaded through GitHub Actions workflows and then consumed in Docker Compose configurations to establish direct connectivity while preserving the hostname for SNI and certificate validation.

Changes

VAPI Origin IP Pinning

Layer / File(s) Summary
GitHub Actions secret passthrough to deploy scripts
.github/workflows/master.yml, .github/workflows/staging.yml
Master and staging workflows declare HIVESEARCHER_ORIGIN_IP in SSH environment blocks, add it to SSH action envs allowlists, and export it within deploy scripts across EU, US, and SG deployment regions.
Docker Compose VAPI service origin IP configuration
apps/web/docker-compose.yml, apps/web/docker-compose.production.yml
Docker Compose files configure the vapi service with an extra_hosts mapping to pin api.hivesearcher.com to the origin IP, with explanatory comments on the Cloudflare colo↔origin hang mitigation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Poem

🐰 A secret IP hops through pipelines clear,
Extra hosts in Compose bring origin near,
Cloudflare clouds part, direct paths appear,
VAPI dances swift without a fear!
✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and specifically describes the main change: pinning the vapi search backend to an origin IP to bypass a Cloudflare connection issue.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/vapi-search-backend-pin

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant