fix(db): inline RDS CA bundle to bypass Turbopack ignoring outputFileTracingIncludes - #2772
Merged
Merged
Conversation
…TracingIncludes Vercel deployments of apps/app and apps/portal use Turbopack (deployment metadata `bundler: "turbopack"`). Next.js's `outputFileTracingIncludes` is silently no-op'd under Turbopack — `next/dist/build/index.js` line ~1537 gates `collectBuildTraces` on `bundler !== Bundler.Turbopack`. So the file-based approach from PR #2761 never landed the cert at `/var/task/packages/db/certs/rds-global-bundle.pem` for App Router page function bundles, producing this warning at every cold start: Warning: Ignoring extra certs from `/var/task/packages/db/certs/rds-global-bundle.pem`, load failed: error:80000002:system library Connections still returned 200 because Node's default trust store happens to verify the AWS RDS Proxy chain — but the bundle was never actually loaded, defeating the verified-TLS work. Fix: inline the PEM as a TypeScript string constant (RDS_CA_BUNDLE) and pass it directly to the Postgres adapter via `ssl.ca`. Bundler-agnostic, no env var needed, no tracing hacks. Generated by `packages/db/scripts/generate-ca-bundle-ts.mjs` from the existing `packages/db/certs/rds-global-bundle.pem` source. Changes: - packages/db/src/rds-ca-bundle.ts (generated, committed) — exports the PEM as a string constant. - packages/db/src/ssl-config.ts — uses the inline bundle instead of reading NODE_EXTRA_CA_CERTS. Drops the throwing fallback (always have the cert now). Adds `ca` to the SslConfig type. - apps/app/prisma/, apps/portal/prisma/, apps/framework-editor/prisma/ — inlined ca-bundle TS file + client uses `ssl.ca` directly. These duplicate the constant rather than importing from `@trycompai/db` because the Trigger.dev indexer pins to the npm-published version, which lags behind workspace source. - apps/app/next.config.ts, apps/portal/next.config.ts — drop the now- redundant `outputFileTracingIncludes` for the cert. - @trycompai/db: 2.1.1 → 2.2.0. - Deploy checklist updated: `NODE_EXTRA_CA_CERTS` is no longer required on Vercel (and should be unset to silence the cold-start warning). apps/api/prisma/client.ts is unchanged — the Docker runtime sets `NODE_EXTRA_CA_CERTS` at the OS level and that path works fine. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Contributor
|
🎉 This PR is included in version 3.44.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
4 tasks
Marfuen
added a commit
that referenced
this pull request
May 6, 2026
) URGENT: production runtime fix. Staging is hitting: Error [PrismaClientKnownRequestError] Invalid `prisma.member.findFirst()` invocation Error opening a TLS connection: unable to get local issuer certificate code: 'P1011', driverAdapterError: TlsConnectionError Cause: PR #2772 set `ssl.ca = RDS_CA_BUNDLE` in the prisma adapter, which *replaces* Node's trust store rather than augmenting it. Our bundle only contains the 108 RDS-specific regional self-signed CAs — it does NOT contain Amazon Root CA 1, which is where AWS RDS Proxy chains terminate (and which lives in Node's default Mozilla bundle). So the chain failed to validate at runtime under the strict-TLS branch. Why apps/app and apps/portal didn't trip this in earlier checks: - The /auth route returned 200 because that codepath doesn't query the DB; it talks to apps/api over HTTP, and apps/api uses a different prisma client (Docker, NODE_EXTRA_CA_CERTS at OS level). - DB-touching SSR routes (e.g., /[orgId]/overview) are exactly what the reported staging failure exercises. Fix: drop the `ca:` field. Node's default trust store includes Amazon Root CA 1, which is sufficient for chain validation against RDS Proxy. Hostname check is still skipped (NLB topology — chain check still rejects forged or wrong-CA certs). PRISMA_ALLOW_INSECURE_TLS=1 remains the explicit insecure opt-out — the original Cubic finding fix is preserved. Files: - packages/db/src/ssl-config.ts: drop RDS_CA_BUNDLE import + usage - packages/db/src/client.test.ts: rewrite tests for new behavior (6 pass) - apps/{app,portal,framework-editor}/prisma/client.ts: drop the ca: branch - Delete: packages/db/{certs/rds-global-bundle.pem,src/rds-ca-bundle.ts, scripts/generate-ca-bundle-ts.mjs} and the inlined rds-ca-bundle.ts copies in apps/{app,portal,framework-editor}/prisma/ (~660KB removed) - packages/db: 2.2.0 → 2.3.0 (also drops `certs` from `files` array) - apps/api/prisma/client.ts: unchanged — Docker still uses NODE_EXTRA_CA_CERTS at OS level and that path is fine. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Investigation receipts
Post-merge action
Unset `NODE_EXTRA_CA_CERTS` on the Vercel team's shared variables once this rolls out — the path no longer exists on the function (cert is in-bundle now), and leaving the env var set will keep producing the cold-start warning.
Test plan
🤖 Generated with Claude Code
Summary by cubic
Inline the AWS RDS CA bundle as
RDS_CA_BUNDLEand pass it via Prismassl.caso verified Postgres TLS works under Turbopack and the cold‑start warning disappears. Removes the need forNODE_EXTRA_CA_CERTSand anyoutputFileTracingIncludes.Bug Fixes
outputFileTracingIncludes, so the PEM never shipped and cold starts logged “Ignoring extra certs…”.RDS_CA_BUNDLE) used inssl.ca; removedoutputFileTracingIncludes; addedpackages/db/scripts/generate-ca-bundle-ts.mjs; duplicatedrds-ca-bundle.tsin each app’sprisma/for Trigger.dev.@trycompai/dbto2.2.0.Migration
NODE_EXTRA_CA_CERTSforapps/appandapps/portal; no env vars or tracing config are needed now.apps/api; existing setups continue to work.Written for commit d4f3371. Summary will update on new commits.