Skip to content

fix(db): drop inlined RDS CA bundle (fixes staging P1011 TlsConnectionError) - #2775

Merged
Marfuen merged 1 commit into
mainfrom
mariano/drop-inline-bundle
May 6, 2026
Merged

Marfuen merged 1 commit into
mainfrom
mariano/drop-inline-bundle

Conversation

@Marfuen

@Marfuen Marfuen commented May 6, 2026 •

Copy link
Copy Markdown
Contributor

Production runtime fix. Staging is currently 500-ing on DB-touching SSR routes (e.g. `/[orgId]/overview`) with:

```
Error [PrismaClientKnownRequestError]
Invalid `prisma.member.findFirst()` invocation
Error opening a TLS connection: unable to get local issuer certificate
code: 'P1011', driverAdapterError: TlsConnectionError
```

Cause

PR #2772 set `ssl.ca = RDS_CA_BUNDLE` in the prisma adapter. Node's TLS treats `ssl.ca` as a replacement for the trust store, not an augmentation. Our bundle (`packages/db/certs/rds-global-bundle.pem`) only contains the 108 RDS-specific regional self-signed CAs — it does not contain Amazon Root CA 1, which is where AWS RDS Proxy cert chains terminate (and which lives in Node's default Mozilla bundle).

So under the strict-TLS branch (`isLocalhost ? undefined : allowInsecure ? insecure : { ca: RDS_CA_BUNDLE, ... }`), every non-localhost connection lost access to Amazon Root CA, and chain validation failed.

Why this didn't trip earlier preview-deploy checks: the routes I sampled (`/auth`, `/`) don't actually query the DB from apps/app's prisma client — they talk to apps/api over HTTP, and apps/api runs in Docker with `NODE_EXTRA_CA_CERTS` set at the OS level (a different code path that doesn't go through `ssl.ca`). DB-touching SSR routes like `/[orgId]/overview` are exactly what the reported failure exercises.

Fix

Drop `ssl.ca` entirely. Node's default trust store includes Amazon Root CA 1, which validates the RDS Proxy chain. Hostname check stays skipped (NLB topology — chain check still rejects forged certs). `PRISMA_ALLOW_INSECURE_TLS=1` remains the explicit opt-out, so the original Cubic finding (silent `rejectUnauthorized: false`) stays fixed.

Same shape as comp-private#277.

Files

  • `packages/db/src/ssl-config.ts` — drop `RDS_CA_BUNDLE` import + usage
  • `packages/db/src/client.test.ts` — rewrite for new behavior (6 pass)
  • `apps/{app,portal,framework-editor}/prisma/client.ts` — drop the `ca:` branch
  • Deleted: `packages/db/{certs/rds-global-bundle.pem,src/rds-ca-bundle.ts,scripts/generate-ca-bundle-ts.mjs}` plus the inlined `rds-ca-bundle.ts` copies in each app (~660KB removed from repo)
  • `packages/db`: 2.2.0 → 2.3.0 (also drops `certs` from `files` array)
  • `apps/api/prisma/client.ts` unchanged — Docker still uses `NODE_EXTRA_CA_CERTS` at OS level

Test plan

  • `packages/db` test suite — 6 passing
  • Verify preview deploy of this branch — `/[orgId]/overview` should render without `P1011`
  • After merge: publish `@trycompai/db@2.3.0`
  • After merge: verify staging cold-start has no `Ignoring extra certs` warning and no `TlsConnectionError`

🤖 Generated with Claude Code


Summary by cubic

Fix TLS errors in staging by removing the inlined RDS CA bundle and using Node’s default trust store. Restores DB connectivity for SSR routes while keeping the explicit PRISMA_ALLOW_INSECURE_TLS=1 opt-out.

  • Bug Fixes
    • Removed ssl.ca from Prisma adapters; rely on Node’s trust store (includes Amazon Root CA 1).
    • Kept hostname check skipped; chain validation still enforced.
    • Deleted inlined CA bundle and generator across apps; ~660 KB removed from repo.
    • Updated @trycompai/db to 2.3.0 and dropped certs from files.
    • Revised tests to match new verified-TLS behavior.
    • apps/api unchanged (Docker uses NODE_EXTRA_CA_CERTS).

Written for commit 0b21c8f. Summary will update on new commits.

URGENT: production runtime fix. Staging is hitting:

  Error [PrismaClientKnownRequestError]
  Invalid `prisma.member.findFirst()` invocation
  Error opening a TLS connection: unable to get local issuer certificate
  code: 'P1011', driverAdapterError: TlsConnectionError

Cause: PR #2772 set `ssl.ca = RDS_CA_BUNDLE` in the prisma adapter, which
*replaces* Node's trust store rather than augmenting it. Our bundle only
contains the 108 RDS-specific regional self-signed CAs — it does NOT
contain Amazon Root CA 1, which is where AWS RDS Proxy chains terminate
(and which lives in Node's default Mozilla bundle). So the chain failed
to validate at runtime under the strict-TLS branch.

Why apps/app and apps/portal didn't trip this in earlier checks:
- The /auth route returned 200 because that codepath doesn't query the
  DB; it talks to apps/api over HTTP, and apps/api uses a different
  prisma client (Docker, NODE_EXTRA_CA_CERTS at OS level).
- DB-touching SSR routes (e.g., /[orgId]/overview) are exactly what the
  reported staging failure exercises.

Fix: drop the `ca:` field. Node's default trust store includes Amazon
Root CA 1, which is sufficient for chain validation against RDS Proxy.
Hostname check is still skipped (NLB topology — chain check still
rejects forged or wrong-CA certs). PRISMA_ALLOW_INSECURE_TLS=1 remains
the explicit insecure opt-out — the original Cubic finding fix is
preserved.

Files:
- packages/db/src/ssl-config.ts: drop RDS_CA_BUNDLE import + usage
- packages/db/src/client.test.ts: rewrite tests for new behavior (6 pass)
- apps/{app,portal,framework-editor}/prisma/client.ts: drop the ca: branch
- Delete: packages/db/{certs/rds-global-bundle.pem,src/rds-ca-bundle.ts,
  scripts/generate-ca-bundle-ts.mjs} and the inlined rds-ca-bundle.ts
  copies in apps/{app,portal,framework-editor}/prisma/ (~660KB removed)
- packages/db: 2.2.0 → 2.3.0 (also drops `certs` from `files` array)
- apps/api/prisma/client.ts: unchanged — Docker still uses
  NODE_EXTRA_CA_CERTS at OS level and that path is fine.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented May 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Building Building Preview, Comment May 6, 2026 9:49pm
comp-framework-editor Ready Ready Preview, Comment May 6, 2026 9:49pm
portal Building Building Preview, Comment May 6, 2026 9:49pm

Request Review

@Marfuen
Marfuen merged commit cd5046c into main May 6, 2026
9 of 11 checks passed
@Marfuen
Marfuen deleted the mariano/drop-inline-bundle branch May 6, 2026 21:49
claudfuen pushed a commit that referenced this pull request May 6, 2026
## [3.44.2](v3.44.1...v3.44.2) (2026-05-06)

### Bug Fixes

* **db:** drop inlined RDS CA bundle, use Node default trust store ([#2775](#2775)) ([cd5046c](cd5046c)), closes [#2772](#2772)
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.44.2 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

3 active deployments
Preview – app — 0b21c8ff Deployed May 6, 2026 by vercel[bot]
Preview – portal — 0b21c8ff Deployed May 6, 2026 by vercel[bot]
Preview – comp-framework-editor — 0b21c8ff Deployed May 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants