Skip to content

[dev] [Marfuen] mariano/fix-rds-ca-turbopack - #2773

Closed
github-actions[bot] wants to merge 2 commits into
mainfrom
mariano/fix-rds-ca-turbopack
Closed

github-actions[bot] wants to merge 2 commits into
mainfrom
mariano/fix-rds-ca-turbopack

Conversation

@github-actions

@github-actions github-actions Bot commented May 6, 2026 •

Copy link
Copy Markdown
Contributor

This is an automated pull request to merge mariano/fix-rds-ca-turbopack into dev.
It was created by the [Auto Pull Request] action.


Summary by cubic

Inline the AWS RDS CA bundle and pass it to Prisma via ssl.ca, fixing Turbopack builds that ignored outputFileTracingIncludes and removing the need for NODE_EXTRA_CA_CERTS on Vercel. Combine the inline bundle with Node tls.rootCertificates so both RDS instance and RDS Proxy chains validate; docs updated and @trycompai/db bumped to 2.2.1.

  • Migration
    • Vercel (apps/app, apps/portal): unset NODE_EXTRA_CA_CERTS to silence cold-start warnings.
    • Trigger.dev: keep the caBundleExtension; remove PRISMA_ALLOW_INSECURE_TLS if set.
    • API Docker: no change.
    • Downstream apps using @trycompai/db/ssl-config: bump to @trycompai/db@2.2.1; no env var needed.

Written for commit f2d1677. Summary will update on new commits.

Marfuen and others added 2 commits May 6, 2026 21:38
…TracingIncludes

Vercel deployments of apps/app and apps/portal use Turbopack (deployment
metadata `bundler: "turbopack"`). Next.js's `outputFileTracingIncludes` is
silently no-op'd under Turbopack — `next/dist/build/index.js` line ~1537
gates `collectBuildTraces` on `bundler !== Bundler.Turbopack`. So the
file-based approach from PR #2761 never landed the cert at
`/var/task/packages/db/certs/rds-global-bundle.pem` for App Router page
function bundles, producing this warning at every cold start:

  Warning: Ignoring extra certs from
  `/var/task/packages/db/certs/rds-global-bundle.pem`, load failed:
  error:80000002:system library

Connections still returned 200 because Node's default trust store happens
to verify the AWS RDS Proxy chain — but the bundle was never actually
loaded, defeating the verified-TLS work.

Fix: inline the PEM as a TypeScript string constant (RDS_CA_BUNDLE) and
pass it directly to the Postgres adapter via `ssl.ca`. Bundler-agnostic,
no env var needed, no tracing hacks. Generated by
`packages/db/scripts/generate-ca-bundle-ts.mjs` from the existing
`packages/db/certs/rds-global-bundle.pem` source.

Changes:
- packages/db/src/rds-ca-bundle.ts (generated, committed) — exports the
  PEM as a string constant.
- packages/db/src/ssl-config.ts — uses the inline bundle instead of
  reading NODE_EXTRA_CA_CERTS. Drops the throwing fallback (always have
  the cert now). Adds `ca` to the SslConfig type.
- apps/app/prisma/, apps/portal/prisma/, apps/framework-editor/prisma/ —
  inlined ca-bundle TS file + client uses `ssl.ca` directly. These
  duplicate the constant rather than importing from `@trycompai/db`
  because the Trigger.dev indexer pins to the npm-published version,
  which lags behind workspace source.
- apps/app/next.config.ts, apps/portal/next.config.ts — drop the now-
  redundant `outputFileTracingIncludes` for the cert.
- @trycompai/db: 2.1.1 → 2.2.0.
- Deploy checklist updated: `NODE_EXTRA_CA_CERTS` is no longer required
  on Vercel (and should be unset to silence the cold-start warning).

apps/api/prisma/client.ts is unchanged — the Docker runtime sets
`NODE_EXTRA_CA_CERTS` at the OS level and that path works fine.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Setting `ssl.ca` *replaces* Node's trust store rather than augmenting it.
Our `rds-global-bundle.pem` only contains the 108 RDS-specific regional
self-signed CAs, NOT public roots like Amazon Root CA 1 (which is what
AWS RDS Proxy chains terminate at, and which lives in Node's default
Mozilla bundle).

Surfaced by comp-private's trust app at build time: prerender of
/sitemap.xml runs `prisma.trust.findMany()`, and TLS chain validation
fails against just our bundle:

  Error opening a TLS connection: unable to get local issuer certificate

apps/app and apps/portal didn't trip this only because none of their
prerendered routes hit the DB. Latent issue if any do later.

Combine `RDS_CA_BUNDLE` with `tls.rootCertificates` so we trust both:
- Direct RDS instance certs (chain → regional RDS CA in our bundle)
- RDS Proxy certs (chain → Amazon Root CA 1 in Node defaults)

Strict-TLS preserved (still rejects forged or wrong-CA certs); broader
chain coverage. Bumps @trycompai/db to 2.2.1 so downstream consumers
(comp-private/apps/{trust,enterprise-api}) get the fix at the source on
their next dep bump.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented May 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment May 6, 2026 9:16pm
comp-framework-editor Ready Ready Preview, Comment May 6, 2026 9:16pm
portal Ready Ready Preview, Comment May 6, 2026 9:16pm

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 13 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

@Marfuen

Marfuen commented May 6, 2026

Copy link
Copy Markdown
Contributor

Replaced by #2774 — that branch is based off current main (no conflicts) and adds the scoped rdsServerIdentity fix on top of the combine fix. Closing this in favor of the new PR.

@Marfuen Marfuen closed this May 6, 2026

This branch was successfully deployed

3 active deployments
Preview – comp-framework-editor — f2d1677d Deployed May 6, 2026 by vercel[bot]
Preview – app — f2d1677d Deployed May 6, 2026 by vercel[bot]
Preview – portal — f2d1677d Deployed May 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant