[dev] [Marfuen] mariano/fix-rds-ca-turbopack - #2773
Closed
github-actions[bot] wants to merge 2 commits into
Closed
github-actions[bot] wants to merge 2 commits into
github-actions[bot] wants to merge 2 commits into
Conversation
…TracingIncludes Vercel deployments of apps/app and apps/portal use Turbopack (deployment metadata `bundler: "turbopack"`). Next.js's `outputFileTracingIncludes` is silently no-op'd under Turbopack — `next/dist/build/index.js` line ~1537 gates `collectBuildTraces` on `bundler !== Bundler.Turbopack`. So the file-based approach from PR #2761 never landed the cert at `/var/task/packages/db/certs/rds-global-bundle.pem` for App Router page function bundles, producing this warning at every cold start: Warning: Ignoring extra certs from `/var/task/packages/db/certs/rds-global-bundle.pem`, load failed: error:80000002:system library Connections still returned 200 because Node's default trust store happens to verify the AWS RDS Proxy chain — but the bundle was never actually loaded, defeating the verified-TLS work. Fix: inline the PEM as a TypeScript string constant (RDS_CA_BUNDLE) and pass it directly to the Postgres adapter via `ssl.ca`. Bundler-agnostic, no env var needed, no tracing hacks. Generated by `packages/db/scripts/generate-ca-bundle-ts.mjs` from the existing `packages/db/certs/rds-global-bundle.pem` source. Changes: - packages/db/src/rds-ca-bundle.ts (generated, committed) — exports the PEM as a string constant. - packages/db/src/ssl-config.ts — uses the inline bundle instead of reading NODE_EXTRA_CA_CERTS. Drops the throwing fallback (always have the cert now). Adds `ca` to the SslConfig type. - apps/app/prisma/, apps/portal/prisma/, apps/framework-editor/prisma/ — inlined ca-bundle TS file + client uses `ssl.ca` directly. These duplicate the constant rather than importing from `@trycompai/db` because the Trigger.dev indexer pins to the npm-published version, which lags behind workspace source. - apps/app/next.config.ts, apps/portal/next.config.ts — drop the now- redundant `outputFileTracingIncludes` for the cert. - @trycompai/db: 2.1.1 → 2.2.0. - Deploy checklist updated: `NODE_EXTRA_CA_CERTS` is no longer required on Vercel (and should be unset to silence the cold-start warning). apps/api/prisma/client.ts is unchanged — the Docker runtime sets `NODE_EXTRA_CA_CERTS` at the OS level and that path works fine. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Setting `ssl.ca` *replaces* Node's trust store rather than augmenting it.
Our `rds-global-bundle.pem` only contains the 108 RDS-specific regional
self-signed CAs, NOT public roots like Amazon Root CA 1 (which is what
AWS RDS Proxy chains terminate at, and which lives in Node's default
Mozilla bundle).
Surfaced by comp-private's trust app at build time: prerender of
/sitemap.xml runs `prisma.trust.findMany()`, and TLS chain validation
fails against just our bundle:
Error opening a TLS connection: unable to get local issuer certificate
apps/app and apps/portal didn't trip this only because none of their
prerendered routes hit the DB. Latent issue if any do later.
Combine `RDS_CA_BUNDLE` with `tls.rootCertificates` so we trust both:
- Direct RDS instance certs (chain → regional RDS CA in our bundle)
- RDS Proxy certs (chain → Amazon Root CA 1 in Node defaults)
Strict-TLS preserved (still rejects forged or wrong-CA certs); broader
chain coverage. Bumps @trycompai/db to 2.2.1 so downstream consumers
(comp-private/apps/{trust,enterprise-api}) get the fix at the source on
their next dep bump.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Contributor
|
Replaced by #2774 — that branch is based off current main (no conflicts) and adds the scoped |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is an automated pull request to merge mariano/fix-rds-ca-turbopack into dev.
It was created by the [Auto Pull Request] action.
Summary by cubic
Inline the AWS RDS CA bundle and pass it to Prisma via
ssl.ca, fixing Turbopack builds that ignoredoutputFileTracingIncludesand removing the need forNODE_EXTRA_CA_CERTSon Vercel. Combine the inline bundle with Nodetls.rootCertificatesso both RDS instance and RDS Proxy chains validate; docs updated and@trycompai/dbbumped to2.2.1.NODE_EXTRA_CA_CERTSto silence cold-start warnings.caBundleExtension; removePRISMA_ALLOW_INSECURE_TLSif set.@trycompai/db/ssl-config: bump to@trycompai/db@2.2.1; no env var needed.Written for commit f2d1677. Summary will update on new commits.