Skip to content

The host runs Composer 0.26.0: one config file, no prisma-composer binary (8.0.0-rc.20) - #330

Merged
wmadden-electric merged 8 commits into
mainfrom
one-config-file/composer-0-26
Oct 5, 2026
Merged

wmadden-electric merged 8 commits into
mainfrom
one-config-file/composer-0-26

Conversation

@wmadden-electric

Copy link
Copy Markdown
Contributor

Slice 3 of the one-config-file project (prisma/orm#30536). Composer 0.26.0 published the merged config (prisma/composer#328) and dropped the prisma-composer binary (prisma/composer#331); this PR makes the host carry it. Merging publishes prisma@8.0.0-rc.20.

From a Composer project outside any workspace, with this branch's prisma and Composer 0.26.0 from the registry:

$ prisma dev module.ts           # with prisma-composer.config.ts left beside prisma.config.ts
CLI.CONFIG_SECTION_INVALID  The 'composer' section of .../prisma.config.ts is invalid.
  CONFIG.FILE_RETIRED  .../prisma-composer.config.ts is no longer read. Composer reads its
  configuration only from the `composer` section of prisma.config.ts. ...
$ prisma --version
8.0.0-rc.20

The decision

@prisma/cli and prisma pin @prisma/composer-cli and @prisma/composer at 0.26.0 and the version advances to 8.0.0-rc.20, so prisma@latest runs Composer's family with the composer section of prisma.config.ts as its configuration. The automatic pin-bump workflow did not fire (Composer's publish could not notify this repository), so this PR carries the bump.

What the bump changes in the host

  • Tests. The config fixture that held composer: { configPath } now proves the retirement: dev --config against it fails with the engine's CLI.CONFIG_SECTION_INVALID headline and Composer's CONFIG.FIELD_RETIRED diagnostic, exit 2, on every platform, since validation now fails before the handler runs. A second fixture holds a valid section built with defineConfig as composer from @prisma/composer/config and proves the handler runs against it.
  • Conformance. The composer-cli engine-pin exception in scripts/conformance.ts is removed, as its own note said this bump would do. The suite reports nothing.
  • The shipped skill. skills/prisma-platform-core-concepts/SKILL.md no longer says prisma-composer.config.ts is mandatory or that dev fails with CONFIG.FILE_MISSING. It describes the composer section and the three retirement codes in the same terms as Composer's own skill, with the fix for each.
  • Isolation. composer-isolation.test.ts passes unchanged: mounting the 0.26.0 family still loads neither Alchemy nor effect on an unrelated command.

Verification

  • Build, typecheck, lint, cli tests (1027), cli-engine tests (1025), test:scripts, check:skill-packaging, manifest-pins, composer-isolation, and check:conformance with zero failing and zero allowed.
  • Manual QA against the published 0.26.0 in a project outside the workspace, recorded in the project folder: --version, deploy --help, dev --help exit 0 and list neither destroy nor log; the retired file gives CONFIG.FILE_RETIRED; the retired field gives CONFIG.FIELD_RETIRED; an effect forced to 4.0.0-rc.118 gives CLI.CONFIG_UNREADABLE naming the missing module while --version still exits 0.
  • prisma dev to ready still needs alchemy as a direct dependency in a plain pnpm project; that is a Composer defect fixed in prisma/composer#332, not a host matter, and will ship in Composer's next release.

Not in this PR

  • New commands. destroy and log remain operations on @prisma/composer/control; their command-line form is a separate grammar project.
  • The prisma/web pages, which land in their own PR after this release is on latest.

Agent: columbo-17

🤖 Generated with Claude Code

wmadden-electric and others added 8 commits October 5, 2026 15:37
Composer 0.26.0 moves its configuration into the composer section of
prisma.config.ts and drops the prisma-composer binary. Until it is on
the registry, both manifests pin the preview of prisma/composer#331.
The preview's composer-cli depends on @prisma/composer by URL, which
pnpm refuses in subdependencies unless blockExoticSubdeps is off.
Both go back to 0.26.0 before this merges.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 peers @prisma/cli-engine 0.6.2, the version the shell
ships, so the tarball check no longer needs to excuse a mismatch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
…es it

A composer section that still names a config file is now refused by
Composer's section validator before any handler runs: the result is
CLI.CONFIG_SECTION_INVALID carrying CONFIG.FIELD_RETIRED, exit 2, on
every platform, so the Windows variant of the test goes away.

A second fixture builds a valid section with defineConfig from
@prisma/composer/config and nodeBuild(), and shows dev accepting it and
reaching its handler. Its state descriptor is written by hand: the
Prisma Cloud control entry would bring the whole cloud target and the
ORM toolchain into the host's dev dependencies.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
prisma init installs this skill into every new project, and it still
said dev and deploy need a separate prisma-composer.config.ts. With
Composer 0.26.0 that file is refused; the skill now shows the composer
section and the three CONFIG codes the way Composer's own skill does.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
The configPath test now checks the headline summary, which names the
section and the file, and the diagnostic's severity. The valid-section
test checks that the handler's failure names the entry the host
passed, so it shows the argv reached composer's dev rather than only
that some composer code came back.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
A new project with no composer section gets CONFIG.SECTION_MISSING and
has no old file to move, so the skill now says to write the section in
that case and to move the old contents only for the other two codes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 is on latest, so both manifests pin it in place of the
pkg.pr.new preview, and the workspace stops allowing URL dependencies
below the top level, which only the preview needed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Merging publishes prisma@latest pinning Composer 0.26.0, whose
configuration is the composer section of prisma.config.ts.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: a17bab11-2b49-4956-98cb-3317c800ac77
📥 Commits

Reviewing files that changed from the base of the PR and between 5be86dd and 2b26755.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (13)
  • package.json
  • packages/cli-conformance/package.json
  • packages/cli-engine/package.json
  • packages/cli-telemetry/package.json
  • packages/cli/package.json
  • packages/cli/scripts/conformance.ts
  • packages/cli/tests/bin.test.ts
  • packages/cli/tests/fixtures/config/composer-config-path.config.ts
  • packages/cli/tests/fixtures/config/composer-valid.config.ts
  • packages/compute/package.json
  • packages/prisma/package.json
  • packages/tsconfig/package.json
  • skills/prisma-platform-core-concepts/SKILL.md
💤 Files with no reviewable changes (1)
  • packages/cli/scripts/conformance.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes
    • Composer commands now validate configuration consistently: the retired configPath field is rejected with a specific diagnostic, while valid Composer settings proceed to platform or entry-point checks.
  • Documentation
    • Updated setup guidance to use a single prisma.config.ts for ORM, Composer, and Skills settings. Clarified that dev and deploy read the Composer section and documented migration away from separate Composer config files and the retired configPath field.

Walkthrough

Package and workspace versions advance to 8.0.0-rc.20, and Composer CLI dependencies advance to 0.26.0. CLI tests and skill documentation describe a single prisma.config.ts configuration with a composer section. Tests check the retired configPath diagnostic and the result of loading a valid Composer entry.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 2b267

This change updates package versions and Composer configuration guidance and tests. No concrete merge-blocking issue was found, so it appears ready to merge after normal CI checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2b267

The configuration contract changes, but the host retains validation before command execution. No introduced security issue was established. Composer 0.26.0’s internal state-management and recovery behavior could not be independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant exposure is the existing local CLI process consuming project configuration and invoking Composer handlers. The inspected change does not establish a new remote entrypoint or expanded tenant authority. Maximum downstream asset, environment, and data-store exposure cannot be bounded without the target Composer implementation and its configured extensions.

Trust Boundaries and Controls

  • observed — The loader evaluates the selected config through c12 and checks that the resolved file matches the requested real path. Section validation occurs afterward, before handler execution. Thus the validation gate controls command dispatch; it is not a sandbox for configuration evaluation. This ordering predates the PR.

Resilience and Maintainability Implications

  • observed — The host returns before dispatch on configuration errors and centrally settles handler outcomes. These controls support failure containment, but neither they nor the intentionally throwing fixture establish Composer 0.26.0’s persistent-resource behavior after partial failure, interruption, repeated invocation, or concurrent execution. The available installed Composer CLI is the older 0.25.0 release.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the Composer 0.26.0 upgrade and the move to one config file without the prisma-composer binary.
Description check ✅ Passed The description explains the Composer upgrade, config changes, tests, verification, and scope. It is directly related to the changeset.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 3 files. (9 skipped: 9 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 5, 2026

Copy link
Copy Markdown

Open in StackBlitz

npx https://pkg.pr.new/@prisma/cli@330
npx https://pkg.pr.new/@prisma/cli-engine@330

commit: 2b26755

@wmadden-electric
wmadden-electric merged commit 6c41548 into main Oct 5, 2026
16 checks passed
@wmadden-electric
wmadden-electric deleted the one-config-file/composer-0-26 branch October 5, 2026 14:34
RyanGarber pushed a commit to RyanGarber/prisma-orm-tmep that referenced this pull request Oct 9, 2026
```
$ git diff --stat main...HEAD | tail -1
 25 files changed, 1 insertion(+), 2833 deletions(-)
```

This closes the one-config-file project. It deletes the project's
working folder, `projects/one-config-file/`, and fixes one duplicate
number in the failure-mode catalogue. Linear: TML-3340.

The project moved Prisma Composer's configuration out of its own
`prisma-composer.config.ts` into the `composer` section of
`prisma.config.ts`, and deleted Composer's standalone `prisma-composer`
binary. Prisma 8 now has one CLI and one config file. The rest of this
description is the close-out record the Drive process asks for: what was
checked, where each decision now lives, and where each unfinished item
is tracked.

## What was delivered

| PR | What it did |
| --- | --- |
| prisma/composer#328 | Composer's configuration is the `composer`
section of `prisma.config.ts`. The old file and `configPath` are
refused. |
| prisma/composer#331 | The `prisma-composer` binary is gone. Docs,
examples and the shipped skill say `prisma deploy` and `prisma dev`.
Released as Composer 0.26.0. |
| prisma/prisma-cli#330 | The `prisma` host runs Composer 0.26.0.
Released as `prisma@8.0.0-rc.20`. |
| prisma/web#8387 | The public Composer docs describe the `composer`
section. |
| prisma/composer#332 | Found during testing: `prisma dev` and `prisma
deploy` failed in pnpm projects. Merged, not yet released (TML-3520). |
| prisma/composer#333 | An emulator test race that made CI flaky, plus
`PRISMA_COMPOSER_EMULATORS_DIR`. |

Three more PRs came out of this close-out and are open:

- prisma/composer#347 writes ADR-0050, which records the binary's
retirement. Without it the close-out failed the ADR audit, and four
older ADRs still described `prisma-composer` as the entry point.
- prisma/web#8415 fixes a tutorial page that still told readers to write
`prisma-composer.config.ts`.
- prisma/pdp-control-plane#5608 makes the platform's Compute import flow
write the `composer` section into `prisma.config.ts`, and recognise
repositories that already have it. Until now it wrote
`prisma-composer.config.mjs` and pinned Composer 0.25.0, so imported
repositories broke on upgrading to 0.26.0.

## Definition of Done

| Item | Verdict | Evidence |
| --- | --- | --- |
| orm-demo has one config file, and `prisma deploy` and `prisma dev` run
against it from the host | Met, with deviations | `examples/orm-demo`
has only `prisma.config.ts`. `prisma dev` from the host build reached
ready (slice 3 QA). A real `prisma deploy` of orm-demo succeeds in
Composer's e2e workflow on `main`, using the published host with the
workspace family. No deploy ran from the host build itself, because no
service token was available. |
| The old file and `configPath` get their diagnostics | Met, with a
deviation | `CONFIG.FILE_RETIRED` and `CONFIG.FIELD_RETIRED`, exit 2,
from the host binary. Shown with `prisma dev`, because `deploy` checks
credentials before reading the config. Both commands use the same
validator. |
| A broken `effect` install fails with `CLI.CONFIG_UNREADABLE`, and
`prisma --version` still works | Met, with the same deviation | Slice 3
QA, step 5. |
| Published packages have no `bin` and no stale name | Met |
`@prisma/composer-cli` and `@prisma/composer` 0.28.0 declare no `bin`.
Their unpacked tarballs name the old file only in the messages that
refuse it. |
| A CI check keeps the old name out | Met | `pnpm
lint:retired-binary-name` runs in CI. Its test plants a mention and
expects a failure. |
| TML-3340 Done, web pages updated | Met | TML-3340 is Done with a
closing comment. One page missed by #8387 is fixed in prisma/web#8415. |
| The consolidation plan says `deploy` and `dev` stay bare | Met |
`projects/consolidate-clis/cli-consolidation-plan.md`, and now ADR-0050
in prisma/composer. |
| Retro run, ADR merged, folder deleted | Met once #347 and this PR
merge | The retro's lesson is failure mode F42. ADR-0049 is merged.
ADR-0050 is in #347. |
| Repository references to the folder removed | Met | Nothing outside
the folder links to it. |
| Manual QA for each user-facing slice | Met, with a deviation | Slice 3
has a QA transcript. Slices 1 and 2 recorded their manual QA in the
Verification sections of #328 and #331. |

## Where each decision lives now

Every decision recorded in the deleted spec and design notes has a home
outside the folder:

- **Composer's configuration is the `composer` section, validated by the
section, with the old file and field refused:** ADR-0049, and the
`CONFIG` code list in ADR-0044.
- **The `effect` version pre-flight is deleted; a broken tree fails with
the engine's error:** ADR-0049. #347 adds the four rejected
alternatives, which until now were only in #328's description.
- **The binary is retired, and `destroy` and `log` stay programmatic:**
ADR-0050 in #347.
- **`deploy` and `dev` stay bare commands; `destroy` is not mounted:**
ADR-0050, and the consolidation plan.
- **The examples' `destroy` scripts keep `--production` and `--stage`:**
ADR-0050 records this as a repository-internal script grammar, not a
public command.
- **Examples and CI run the published host with a workspace override:**
`gotchas.md` and `scripts/check-cli-engine-pin*.mjs` in prisma/composer,
which enforce it.
- **Composer runs the `alchemy` installed beside `@prisma/composer`:**
ADR-0007's amendment and `docs/design/10-domains/deploy-cli.md` in
prisma/composer.

## Deferred items and their tickets

| Ticket | Item |
| --- | --- |
| TML-3520 | Release Composer 0.29.0 and pin it in the host, so
`prisma@latest` gets the pnpm fix. |
| TML-3521 | Teardown and logs have no `prisma` command. |
| TML-3522 | Two checkouts of one app still share a local Postgres
server. |
| TML-3523 | A compute emulator test is too tight on time and flakes
under load. |
| TML-3524 | Composer's examples pin an older `prisma` host than
`latest`. |
| TML-3525 | Drop the exact `effect` pin once `effect` 4 is stable or
Alchemy pins its peer. |
| TML-3526 | dependency-cruiser skips the examples' `prisma.config.ts`.
|
| TML-3527 | Edge cases in how Composer starts Alchemy. |
| TML-3528 | prisma/asks and prisma/streams still use the retired config
or command. |

Two smaller review notes are accepted without tickets. The prisma-cli
conformance check needs a new exception on each joint engine release,
which is visible when it happens. Windows edge cases are out of scope,
because Windows is documented as unsupported for local tooling.

## What this PR deletes

Every file under `projects/one-config-file/` is transient under
`drive/project/README.md`: the spec, plan, design notes, retro log,
README, and each slice's spec, plan, grounding notes, reviews and QA
transcript. None is methodology to migrate. The decisions are mapped
above. The full files stay readable in the history of prisma/orm#30536.

## The failure-mode number

The retro added its lesson to `drive/calibration/failure-modes.md` as
F39. prisma/orm#30613 had already used F39 two days earlier. This PR
renumbers ours to F42, the next free number.

Agent: saruman-38

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant