Task/cre 4017/offchain cre config - #23824
Draft
vyzaldysanchez wants to merge 19 commits into
Draft
vyzaldysanchez wants to merge 19 commits into
vyzaldysanchez wants to merge 19 commits into
Conversation
Contributor
|
✅ No conflicts with other open PRs targeting |
Contributor
CORA - Pending Reviewers
Legend: ✅ Approved | ❌ Changes Requested | 💬 Commented | 🚫 Dismissed | ⏳ Pending | ❓ Unknown For more details, see the full review summary. |
…hain-cre-config # Conflicts: # core/scripts/go.mod # core/scripts/go.sum # deployment/go.mod # deployment/go.sum # go.mod # go.sum # integration-tests/go.mod # integration-tests/go.sum # integration-tests/load/go.mod # integration-tests/load/go.sum # system-tests/lib/go.mod # system-tests/lib/go.sum # system-tests/tests/go.mod # system-tests/tests/go.sum
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




CRE-4017 — Offchain Capabilities Registry (node side):
spec_configsliceRequires
OffchainCapabilitiesRegistry/DONConfigproto (design-doc shape) — Adds proto chainlink-common#2415; bump to the merged version before merging)Supports
Summary
Node side of the Offchain Capabilities Registry design: capability config, today split across the on-chain
CapabilitiesRegistry, job specs and node TOML, is delivered to nodes as a single versioned offchain payload through the Job Distributor, using the existingcresettingsjob type.This PR covers the first migration slice from the ticket:
cresettingsjobs withconfig_type = "capabilities_registry"carry the payload. It is validated, saved to the database, enforced to be the only such job, and versions can only move forward, enforced in the database (survives job deletion and restarts).GlobalConfigholds the payload the node is currently using. It is kept equal to the committed job in the database, so a job change whose transaction rolls back never affects running capabilities.spec_configcutover: behind a per-node gate ([Capabilities.Local] UseOffchainRegistry, defaultfalse), each capability'sspec_configis resolved per (DON, capability) as TOML < on-chain < offchain. Keys the offchain payload omits keep their legacy value. With the gate off (default), behaviour is unchanged.Out of scope (follow-up slices):
method_configs(don2don), removing the TOML overrides incore/config/capabilities_config.go,oracle_factory_configs, and the CLD authoring tooling.ocr3_configsstays on-chain in this slice (OCR config digest and signer alignment are bound to the on-chain registry); a test pins this. No legacy config fields are removed.Payload
Matches the design doc. The proto lives in chainlink-common (see Requires).
Validation rules:
cresettingsacceptsschemaVersion1 or 2. The top-levelconfig_typeandoffchain_configfields require 2. Existing v1 settings and shard-assignment specs are unchanged. Nodes that predate this PR only accept 1, so they reject acapabilities_registryspec instead of storing it as an empty settings job.capabilityConfigs,ocrConfig) rejects the payload; it is never silently dropped. A payload that uses new schema fields must only be rolled out to nodes that understand them.spec_configvalue must convert to a config map. Values with no type, which would become JSONnull, are rejected, as are decimals without a coefficient, which would panic during conversion.config_typefield selectscapabilities_registry. Writingconfig_type = "capabilities_registry"insidesettingsis rejected, as are case and whitespace variants.Changes
Persistence (
#db_update) — migration0308config_typeandoffchain_configoncre_settings_specs, both default'', so existing rows resolve as before. Without them, acapabilities_registryjob would come back as asettingsjob after a restart.config_type = 'capabilities_registry'can carryoffchain_config, and those rows must have emptysettings.capabilities_registryjob. A duplicate fails at insert withjob.ErrCRESettingsCapRegistryExistsand is never saved. Otherwise a rejected duplicate could start first on the next boot (jobs start newest-first) and replace the config actually in use.cre_offchain_registry_high_water):SELECT … FOR UPDATE) in the same transaction that inserts the spec, so a rollback leaves it unchanged.job.ErrCRESettingsCapRegistryStale.configType/offchainConfig(omitted when empty).Delivery:
cresettingsdelegate andCapRegistryProjectorCapRegistryProjectorinstead: it reads the committedcapabilities_registryjob on a separate connection (opts.DS) and stores it intoGlobalConfig, or clears it if there is none. It reads:capabilities_registrydoesn't use the delegate's in-memory per-config-type slot (the database enforces uniqueness), so a rolled-back create cannot leave a stale reservation. For the settings config types, a rejected job now releases its slot.GlobalConfig: hands out deep copies (LoadParsed), so readers can't modify shared protobuf state. It notifies subscribers when the applied payload changes, and keeps the version high-water mark when cleared.Consumption:
LocalCapabilityManagerSpecConfig, (3) offchainspec_config(gate on only). The offchain layer is applied last; omitted keys keep their legacy value.Observability (Beholder)
platform_cap_config_applied_versiondomain,envplatform_cap_config_validation_errors_totaldomain,envcapabilities_registrypayloads rejected by validation or the stale-version checkplatform_cap_config_apply_errors_totaldomain,envplatform_offchain_registry_matched_capabilitiesplatform_offchain_registry_divergences_totalkindmissing_don,missing_capability,extra_don,extra_capability,config_mismatchThe cross-check is telemetry only; it never blocks or gates anything.
config_mismatchcounts capabilities whose offchainspec_configwould change the config they're launched with compared to TOML + on-chain. In other words, it shows what turning the gate on would change.Config
[Capabilities.Local] UseOffchainRegistry(defaultfalse). Updateddocs/CONFIG.mdand the config golden files.Rollout
platform_cap_config_applied_version,…_validation_errors_totalandplatform_offchain_registry_divergences_total.config_mismatch= 0, or only intended differences), enableUseOffchainRegistryon a canary node, then expand.capabilities_registryjob (takes effect without a restart).Test plan
All of the following were run locally and pass:
go build ./...,go vet,golangci-lint run --new-from-rev=HEAD(0 issues)go test -race -count=5 ./core/capabilities/globalconfig/... ./core/capabilities/localcapmgr/ ./core/services/cresettings/go test -race -count=3 -run 'CRESettings|CapRegistry' ./core/services/job/(real Postgres)FindJobsheavyweight):go test ./core/services/job/ ./core/services/feeds/ ./core/store/migrate/ ./core/web/presenters/ ./core/services/chainlink/ ./core/config/... ./core/services/cre/ ./core/services/standardcapabilities/ ./core/capabilities/Clearmakes the rollback and concurrency tests fail; disabling the version high-water check makes the restart test fail.Staging validation (to do):
platform_cap_config_applied_versionshows its version.schemaVersion = 1payload. All three should be rejected and counted in…_validation_errors_total.spec_configdiffers restart with the offchain values and that omitted keys keep their legacy value.Known limitations
TestDonNotifier_WaitForDon(core/capabilities) hangs intermittently. It's unrelated to this PR and passes on rerun.🤖 Generated with Claude Code