Repository navigation
Revert PR 1: Central Auth migration - #2
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical and moderate findings affect MongoDB startup, appliance compatibility, standalone enrollment networking, and process diagnostics.
Review effort: Lite
Findings: 4
Open (6)
Disable retryable writes for standalone MongoDB · New Disable retryable writes for appliance MongoDB · New Restore MongoDB CPU compatibility preflight · New Disable retryable writes for Compose MongoDB · New Align local-agent and appliance Docker networks · New Preserve signal termination status in exit reporting · New
What changed in this PR
This PR reverts the Central Auth PostgreSQL migration and restores MongoDB-backed authentication and appliance integration.
Changes:
- Restores MongoDB configuration, models, runtime supervision, and tests.
- Removes PostgreSQL storage and migration infrastructure.
- Reverts related deployment, networking, documentation, and build changes.
Review findings:
- Critical (1 vote): Standalone MongoDB deployments leave retryable writes enabled in
central/auth/src/db/mongoose.ts,ops/appliance/manager/services.go, andops/unicron/docker-compose.unicron.yaml:413, causing writes to fail. - Critical (1 vote): MongoDB 7 lacks the required CPU compatibility preflight in
ops/appliance/manager/supervise.go. - Moderate (4 votes): Standalone local-agent enrollment networking is broken in
deploy/standalone/docker-compose.yml. - Moderate (4 votes): Signal-terminated processes report
-1instead of a conventional exit status inops/appliance/manager/process.go. - Moderate (1 vote): Raw MongoDB credentials are not URI-encoded in
ops/unicron/docker-compose.unicron.yaml:411.
| File | Summary |
|---|---|
README.md |
Restores MongoDB documentation. |
ops/unicron/scripts/legacy-auth-mongodb.sh |
Removes the migration helper. |
ops/unicron/docker-compose.unicron.yaml |
Restores MongoDB Compose wiring. |
ops/unicron/.env.production.example |
Restores MongoDB production settings. |
ops/unicron/.env.example |
Restores MongoDB defaults. |
ops/testing/test-central-auth-compose.py |
Removes migration integration testing. |
ops/testing/docker-compose.central-auth-test-postgres.yml |
Removes the PostgreSQL test service. |
ops/testing/docker-compose.central-auth-test-mongo.yml |
Adds the MongoDB test service. |
ops/appliance/manager/supervise.go |
Restores MongoDB supervision. |
ops/appliance/manager/setup.go |
Restores MongoDB data setup. |
ops/appliance/manager/services.go |
Runs Central Auth against MongoDB. |
ops/appliance/manager/process.go |
Reverts process exit handling. |
ops/appliance/manager/preflight.go |
Removes migration preflight logic. |
ops/appliance/manager/preflight_test.go |
Removes migration preflight tests. |
ops/appliance/manager/main.go |
Removes migration startup checks. |
ops/appliance/manager/config.go |
Restores MongoDB configuration. |
ops/appliance/Dockerfile |
Restores MongoDB runtime layout. |
Makefile |
Switches auth test targets to MongoDB. |
deploy/standalone/docker-compose.yml |
Reverts standalone network configuration. |
central/auth/tests/unit/env.spec.ts |
Removes PostgreSQL environment tests. |
central/auth/tests/setup/mongoose.ts |
Adds MongoDB test setup. |
central/auth/tests/setup/app.ts |
Uses MongoDB in test app setup. |
central/auth/tests/integration/postgres-schema.spec.ts |
Removes PostgreSQL schema tests. |
central/auth/tests/integration/migration-guard.spec.ts |
Removes migration guard tests. |
central/auth/tests/integration/auth.spec.ts |
Updates auth tests for MongoDB. |
central/auth/test-support/postgres.ts |
Removes PostgreSQL test support. |
central/auth/src/models/verification.model.ts |
Adds the verification model. |
central/auth/src/models/user.model.ts |
Adds the user model. |
central/auth/src/models/session.model.ts |
Adds the session model. |
central/auth/src/models/account.model.ts |
Adds the account model. |
central/auth/src/lib/bootstrap-admin.ts |
Restores MongoDB admin bootstrap. |
central/auth/src/lib/auth.ts |
Restores the MongoDB Better Auth adapter. |
central/auth/src/index.ts |
Restores MongoDB lifecycle handling. |
central/auth/src/db/postgres.ts |
Removes the PostgreSQL connection layer. |
central/auth/src/db/mongoose.ts |
Adds the Mongoose connection layer. |
central/auth/src/db/legacy-mongodb-migration.ts |
Removes legacy migration logic. |
central/auth/src/db/auth-store.ts |
Removes the PostgreSQL auth store. |
central/auth/src/config/env.ts |
Restores MongoDB environment parsing. |
central/auth/package.json |
Replaces pg with mongoose. |
central/auth/package-lock.json |
Updates locked dependencies. |
central/auth/.env.example |
Restores MongoDB development settings. |
Files not reviewed (1)
- central/auth/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if (!params.has('retryWrites')) params.set('retryWrites', String(options.retryWrites ?? false)); | ||
| if (params.has('tls')) params.set('tls', 'false'); | ||
| } else { | ||
| if (!params.has('retryWrites')) params.set('retryWrites', String(options.retryWrites ?? env.MONGODB_RETRY_WRITES)); |
| "PORT": "3020", | ||
| "MONGODB_URI": "mongodb://127.0.0.1:27017", | ||
| "MONGODB_DB_NAME": cfg.CentralAuthMongoDBName, | ||
| "MONGODB_TLS": "false", |
| return []ServiceSpec{ | ||
| {Name: "postgres", StartSecs: 5 * time.Second, Critical: true}, | ||
| {Name: "redis", StartSecs: 3 * time.Second, Critical: true}, | ||
| {Name: "mongo", StartSecs: 5 * time.Second, Critical: true}, |
| LEGACY_MONGODB_MIGRATION_MARKER: /migration/completed | ||
| MONGODB_URI: 'mongodb://${CENTRAL_AUTH_MONGO_ROOT_USERNAME:-root}:${CENTRAL_AUTH_MONGO_ROOT_PASSWORD:-password}@central-auth-mongodb:27017/?authSource=admin' | ||
| MONGODB_DB_NAME: '${CENTRAL_AUTH_MONGODB_DB_NAME:-unicron_central_auth}' | ||
| MONGODB_TLS: 'false' |
| @@ -25,11 +25,6 @@ services: | |||
| - unicron-stepca-ra:127.0.0.1 | |||
| - unicron.central:127.0.0.1 | |||
| - ${UNICRON_CENTRAL_FQDN:-localhost}:127.0.0.1 | |||
Comment on lines
+141
to
145
| var exitErr *exec.ExitError | ||
| if errors.As(err, &exitErr) { | ||
| if status, ok := exitErr.Sys().(syscall.WaitStatus); ok { | ||
| return status.ExitStatus() | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Reverts merge 388693a because it was merged without the intended approval. This exactly restores the source tree at 3afbbb5. The original fix branch remains available. Validation: the staged tree matched the pre-merge tree exactly, and git diff --check passed. Runtime tests were not rerun. No deployments, Docker image publication, or database changes were performed. This is a source revert, not a database rollback; installations already migrated to PostgreSQL need a separate rollback plan before deploying the old MongoDB-backed runtime. This PR is for review only and will not be automatically merged.