Skip to content

Revert PR 1: Central Auth migration - #2

Merged
junaidquraishi merged 1 commit into
mainfrom
revert/pr-1-postgres-auth
Sep 27, 2026
Merged

junaidquraishi merged 1 commit into
mainfrom
revert/pr-1-postgres-auth

Conversation

@junaidquraishi

Copy link
Copy Markdown
Contributor

Reverts merge 388693a because it was merged without the intended approval. This exactly restores the source tree at 3afbbb5. The original fix branch remains available. Validation: the staged tree matched the pre-merge tree exactly, and git diff --check passed. Runtime tests were not rerun. No deployments, Docker image publication, or database changes were performed. This is a source revert, not a database rollback; installations already migrated to PostgreSQL need a separate rollback plan before deploying the old MongoDB-backed runtime. This PR is for review only and will not be automatically merged.

Revert merge 388693a relative to its main parent, restoring the source tree at 3afbbb5.
Copilot AI lite review requested due to automatic review settings September 27, 2026 05:31
@junaidquraishi
junaidquraishi merged commit 5c018ed into main Sep 27, 2026
1 check passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate findings affect MongoDB startup, appliance compatibility, standalone enrollment networking, and process diagnostics.

Review effort: Lite
Findings: 4 High severity · 2 Medium severity

Open (6)
What changed in this PR

This PR reverts the Central Auth PostgreSQL migration and restores MongoDB-backed authentication and appliance integration.

Changes:

  • Restores MongoDB configuration, models, runtime supervision, and tests.
  • Removes PostgreSQL storage and migration infrastructure.
  • Reverts related deployment, networking, documentation, and build changes.

Review findings:

  • Critical (1 vote): Standalone MongoDB deployments leave retryable writes enabled in central/auth/src/db/mongoose.ts, ops/appliance/manager/services.go, and ops/unicron/docker-compose.unicron.yaml:413, causing writes to fail.
  • Critical (1 vote): MongoDB 7 lacks the required CPU compatibility preflight in ops/appliance/manager/supervise.go.
  • Moderate (4 votes): Standalone local-agent enrollment networking is broken in deploy/standalone/docker-compose.yml.
  • Moderate (4 votes): Signal-terminated processes report -1 instead of a conventional exit status in ops/appliance/manager/process.go.
  • Moderate (1 vote): Raw MongoDB credentials are not URI-encoded in ops/unicron/docker-compose.unicron.yaml:411.
File Summary
README.md Restores MongoDB documentation.
ops/​unicron/​scripts/​legacy-auth-mongodb.sh Removes the migration helper.
ops/​unicron/​docker-compose.unicron.yaml Restores MongoDB Compose wiring.
ops/​unicron/​.env.production.example Restores MongoDB production settings.
ops/​unicron/​.env.example Restores MongoDB defaults.
ops/​testing/​test-central-auth-compose.py Removes migration integration testing.
ops/​testing/​docker-compose.central-auth-test-postgres.yml Removes the PostgreSQL test service.
ops/​testing/​docker-compose.central-auth-test-mongo.yml Adds the MongoDB test service.
ops/​appliance/​manager/​supervise.go Restores MongoDB supervision.
ops/​appliance/​manager/​setup.go Restores MongoDB data setup.
ops/​appliance/​manager/​services.go Runs Central Auth against MongoDB.
ops/​appliance/​manager/​process.go Reverts process exit handling.
ops/​appliance/​manager/​preflight.go Removes migration preflight logic.
ops/​appliance/​manager/​preflight_test.go Removes migration preflight tests.
ops/​appliance/​manager/​main.go Removes migration startup checks.
ops/​appliance/​manager/​config.go Restores MongoDB configuration.
ops/​appliance/​Dockerfile Restores MongoDB runtime layout.
Makefile Switches auth test targets to MongoDB.
deploy/​standalone/​docker-compose.yml Reverts standalone network configuration.
central/​auth/​tests/​unit/​env.spec.ts Removes PostgreSQL environment tests.
central/​auth/​tests/​setup/​mongoose.ts Adds MongoDB test setup.
central/​auth/​tests/​setup/​app.ts Uses MongoDB in test app setup.
central/​auth/​tests/​integration/​postgres-schema.spec.ts Removes PostgreSQL schema tests.
central/​auth/​tests/​integration/​migration-guard.spec.ts Removes migration guard tests.
central/​auth/​tests/​integration/​auth.spec.ts Updates auth tests for MongoDB.
central/​auth/​test-support/​postgres.ts Removes PostgreSQL test support.
central/​auth/​src/​models/​verification.model.ts Adds the verification model.
central/​auth/​src/​models/​user.model.ts Adds the user model.
central/​auth/​src/​models/​session.model.ts Adds the session model.
central/​auth/​src/​models/​account.model.ts Adds the account model.
central/​auth/​src/​lib/​bootstrap-admin.ts Restores MongoDB admin bootstrap.
central/​auth/​src/​lib/​auth.ts Restores the MongoDB Better Auth adapter.
central/​auth/​src/​index.ts Restores MongoDB lifecycle handling.
central/​auth/​src/​db/​postgres.ts Removes the PostgreSQL connection layer.
central/​auth/​src/​db/​mongoose.ts Adds the Mongoose connection layer.
central/​auth/​src/​db/​legacy-mongodb-migration.ts Removes legacy migration logic.
central/​auth/​src/​db/​auth-store.ts Removes the PostgreSQL auth store.
central/​auth/​src/​config/​env.ts Restores MongoDB environment parsing.
central/​auth/​package.json Replaces pg with mongoose.
central/​auth/​package-lock.json Updates locked dependencies.
central/​auth/​.env.example Restores MongoDB development settings.
Files not reviewed (1)
  • central/auth/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

if (!params.has('retryWrites')) params.set('retryWrites', String(options.retryWrites ?? false));
if (params.has('tls')) params.set('tls', 'false');
} else {
if (!params.has('retryWrites')) params.set('retryWrites', String(options.retryWrites ?? env.MONGODB_RETRY_WRITES));
"PORT": "3020",
"MONGODB_URI": "mongodb://127.0.0.1:27017",
"MONGODB_DB_NAME": cfg.CentralAuthMongoDBName,
"MONGODB_TLS": "false",
return []ServiceSpec{
{Name: "postgres", StartSecs: 5 * time.Second, Critical: true},
{Name: "redis", StartSecs: 3 * time.Second, Critical: true},
{Name: "mongo", StartSecs: 5 * time.Second, Critical: true},
LEGACY_MONGODB_MIGRATION_MARKER: /migration/completed
MONGODB_URI: 'mongodb://${CENTRAL_AUTH_MONGO_ROOT_USERNAME:-root}:${CENTRAL_AUTH_MONGO_ROOT_PASSWORD:-password}@central-auth-mongodb:27017/?authSource=admin'
MONGODB_DB_NAME: '${CENTRAL_AUTH_MONGODB_DB_NAME:-unicron_central_auth}'
MONGODB_TLS: 'false'
@@ -25,11 +25,6 @@ services:
- unicron-stepca-ra:127.0.0.1
- unicron.central:127.0.0.1
- ${UNICRON_CENTRAL_FQDN:-localhost}:127.0.0.1
Comment on lines +141 to 145
var exitErr *exec.ExitError
if errors.As(err, &exitErr) {
if status, ok := exitErr.Sys().(syscall.WaitStatus); ok {
return status.ExitStatus()
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants