Repository navigation
feat(decdn_node): add Arbitrum config parity (origin directory, blacklist, cache origin) - #15
Conversation
…klist, cache origin Bring the decdn_node role to parity with the upstream Arbitrum Sepolia node config example (examples/configs/arbitrum-sepolia.toml), whose rendered node.toml was missing several [blockchain] fields and had no [cache.origin] backend. - Expose the ADR 022 origin-directory pair (origin_assignment_address + publisher_registry_address, origin_directory_from_block), the ADR 011/031 content_blacklist_address (+ from_block), and a [cache.origin] pull-through backend (http/fs/s3) — each optional and omitted from node.toml when unset, following the existing ADR-028 slash-appeal knob pattern. - Add fail-loud asserts: origin-directory both-or-neither, blacklist address when set, integer-shape *_from_block, and cache-origin kind + required subfields (incl. decompress enum + path_style boolean shape). - Ship a ready-to-use Arbitrum Sepolia host_vars example with the real chain 421614 genesis addresses, cited to contracts/deployments/421614.json. Field names verified against decdn/crates/common/src/config/types.rs (BlockchainConfig; OriginConfig is a tagged enum kind=http|fs|s3). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
Next review available in: 15 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (5)
Note 🎁 Summarized by CodeRabbit FreeYour organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Pro by visiting https://app.coderabbit.ai/login. Comment |
There was a problem hiding this comment.
Code Review
This pull request adds support and validation for several optional decdn node features, including the ADR 022 origin directory, ADR 011/031 content blacklist compliance, and cache pull-through origins (HTTP, FS, and S3). The review feedback highlights a potential issue where using | length > 0 on optional variables can cause template compilation or evaluation errors if they are undefined or null, recommending the safer | default('') filter instead. Additionally, a bug was identified in the S3 path-style validation assertion, which fails to reject quoted string booleans; using the is boolean test is suggested to strictly enforce boolean types.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
There was a problem hiding this comment.
Pull request overview
This PR updates the ansible/roles/decdn_node role to render additional Arbitrum Sepolia config fields and to support a [cache.origin] pull-through backend, bringing the role’s node.toml output closer to the upstream Arbitrum Sepolia example and adding deploy-time validation + documentation for the new knobs.
Changes:
- Add optional
[blockchain]origin-directory + content-blacklist fields to the renderednode.toml, with corresponding defaults and validation asserts. - Add optional
[cache.origin]rendering withhttp/fs/s3variants, plus deploy-time validation of required fields and value shapes. - Update role README and the
decdn-node-1host_vars example to document and illustrate the new configuration knobs.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| ansible/roles/decdn_node/templates/node.toml.j2 | Emits optional origin-directory, content blacklist, and [cache.origin] config blocks when set. |
| ansible/roles/decdn_node/tasks/main.yml | Adds fail-loud asserts to validate new optional contract addresses, scan-floor blocks, and cache-origin config. |
| ansible/roles/decdn_node/README.md | Documents the new optional knobs and the operational impact of omitting a cache origin. |
| ansible/roles/decdn_node/defaults/main.yml | Introduces new default variables for origin directory, content blacklist, and cache origin kinds/fields. |
| ansible/inventory/host_vars/decdn-node-1.yml.example | Updates example host_vars with Arbitrum Sepolia addresses and demonstrates cache-origin configuration. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Address PR review (Copilot + gemini): the decompress and path_style asserts fired regardless of decdn_cache_origin_kind, so a leftover value for a non-selected kind — which the template never renders — could fail an unrelated deploy, contradicting the 'other kinds' fields are ignored' contract. Gate the decompress check to kind==http and path_style to kind==s3. Also switch path_style to `is boolean` so a quoted "false" is rejected loudly rather than accepted by the prior string check (which contradicted its own comment). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Brings the Ansible
decdn_noderole to full parity with the upstream deCDNArbitrum Sepolia node config example
(
examples/configs/arbitrum-sepolia.toml).The role already targeted Arbitrum Sepolia (
chain_id 421614) but its renderednode.tomlwas missing several[blockchain]fields the upstream exampleexposes and had no
[cache.origin]pull-through backend — which the upstreamconfig marks MUST-EDIT (absent ⇒ cache misses fail
NoOrigin).What changed
Following the established ADR-028 knob pattern (defaults + guarded template emit +
fail-loud assert + README + host_vars example):
defaults/main.yml— new optionaldecdn_*knobs (empty/zero defaults).templates/node.toml.j2— guarded emit of the ADR-022 origin-directory pair(
origin_assignment_address+publisher_registry_address,origin_directory_from_block), the ADR-011/031content_blacklist_address(+
content_blacklist_from_block), and akind-branched[cache.origin]sub-table (
http/fs/s3).tasks/main.yml— fail-loud asserts: origin-directory both-or-neither,blacklist-when-set, integer-shape
*_from_block, and cache-originkind + required subfields (incl.
decompressenum andpath_styleboolean shape).README.md— documents the new optional knobs.inventory/host_vars/decdn-node-1.yml.example— real chain-421614 genesisaddresses, each cited to
contracts/deployments/421614.json.Verification
decdn/crates/common/src/config/types.rs(
BlockchainConfig;OriginConfigis#[serde(tag="kind", rename_all="lowercase", deny_unknown_fields)]). Host_vars addresses matchdeployments/421614.jsonbyte-for-byte (EIP-55 checksums;
deployBlock 11249862).quoted-
"false"path_style), parsed withtomllib;path_stylecases confirmedthrough the real Ansible engine.
from_block, bad
decompress, garbagepath_styleall rejected).yamllint+ansible-lint(production profile) clean; KICS 0 critical / 0 high(no new findings);
decdn.nodecollection builds + passes galaxy-importer.Review notes
A multi-agent review flagged a "critical" that
content_blacklist_*are not realdaemon fields — a false positive from a stale local
decdn/checkout(commit
512beba, behindorigin/main). The fields exist onmain, aredeny_unknown_fields-safe, and appear in the upstream v0.1.0 example. Two genuinebugs the review surfaced are fixed here: the
path_styleJinja-truthinessinversion (quoted
"false"→path_style = true) and missingdecompress/path_styleshape validation.Not in scope
Arbitrum One (42161) — no upstream deployment exists to source addresses from;
the deprecated
relay_urlsingular alias; the[[cache.origins]]fallback array;content_blacklist_poll_interval_sec(sane default, not in the upstream example).🤖 Generated with Claude Code