Skip to content

feat(decdn_node): add Arbitrum config parity (origin directory, blacklist, cache origin) - #15

Merged
thiras merged 2 commits into
mainfrom
feat/arbitrum-config-parity
Jul 11, 2026
Merged

thiras merged 2 commits into
mainfrom
feat/arbitrum-config-parity

Conversation

@thiras

@thiras thiras commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

Brings the Ansible decdn_node role to full parity with the upstream deCDN
Arbitrum Sepolia node config example
(examples/configs/arbitrum-sepolia.toml).
The role already targeted Arbitrum Sepolia (chain_id 421614) but its rendered
node.toml was missing several [blockchain] fields the upstream example
exposes and had no [cache.origin] pull-through backend — which the upstream
config marks MUST-EDIT (absent ⇒ cache misses fail NoOrigin).

What changed

Following the established ADR-028 knob pattern (defaults + guarded template emit +
fail-loud assert + README + host_vars example):

  • defaults/main.yml — new optional decdn_* knobs (empty/zero defaults).
  • templates/node.toml.j2 — guarded emit of the ADR-022 origin-directory pair
    (origin_assignment_address + publisher_registry_address,
    origin_directory_from_block), the ADR-011/031 content_blacklist_address
    (+ content_blacklist_from_block), and a kind-branched [cache.origin]
    sub-table (http / fs / s3).
  • tasks/main.yml — fail-loud asserts: origin-directory both-or-neither,
    blacklist-when-set, integer-shape *_from_block, and cache-origin
    kind + required subfields (incl. decompress enum and path_style boolean shape).
  • README.md — documents the new optional knobs.
  • inventory/host_vars/decdn-node-1.yml.example — real chain-421614 genesis
    addresses, each cited to contracts/deployments/421614.json.

Verification

  • Schema field names verified against decdn/crates/common/src/config/types.rs
    (BlockchainConfig; OriginConfig is #[serde(tag="kind", rename_all="lowercase", deny_unknown_fields)]). Host_vars addresses match deployments/421614.json
    byte-for-byte (EIP-55 checksums; deployBlock 11249862).
  • Template renders valid TOML across all branches (populated / minimal / s3 /
    quoted-"false" path_style), parsed with tomllib; path_style cases confirmed
    through the real Ansible engine.
  • Assert logic exercised (one-sided pair, bad kind, http-without-url, non-integer
    from_block, bad decompress, garbage path_style all rejected).
  • yamllint + ansible-lint (production profile) clean; KICS 0 critical / 0 high
    (no new findings); decdn.node collection builds + passes galaxy-importer.

Review notes

A multi-agent review flagged a "critical" that content_blacklist_* are not real
daemon fields — a false positive from a stale local decdn/ checkout
(commit 512beba, behind origin/main). The fields exist on main, are
deny_unknown_fields-safe, and appear in the upstream v0.1.0 example. Two genuine
bugs the review surfaced are fixed here: the path_style Jinja-truthiness
inversion (quoted "false" → path_style = true) and missing decompress /
path_style shape validation.

Not in scope

Arbitrum One (42161) — no upstream deployment exists to source addresses from;
the deprecated relay_url singular alias; the [[cache.origins]] fallback array;
content_blacklist_poll_interval_sec (sane default, not in the upstream example).

🤖 Generated with Claude Code

…klist, cache origin

Bring the decdn_node role to parity with the upstream Arbitrum Sepolia node
config example (examples/configs/arbitrum-sepolia.toml), whose rendered node.toml
was missing several [blockchain] fields and had no [cache.origin] backend.

- Expose the ADR 022 origin-directory pair (origin_assignment_address +
  publisher_registry_address, origin_directory_from_block), the ADR 011/031
  content_blacklist_address (+ from_block), and a [cache.origin] pull-through
  backend (http/fs/s3) — each optional and omitted from node.toml when unset,
  following the existing ADR-028 slash-appeal knob pattern.
- Add fail-loud asserts: origin-directory both-or-neither, blacklist address
  when set, integer-shape *_from_block, and cache-origin kind + required
  subfields (incl. decompress enum + path_style boolean shape).
- Ship a ready-to-use Arbitrum Sepolia host_vars example with the real chain
  421614 genesis addresses, cited to contracts/deployments/421614.json.

Field names verified against decdn/crates/common/src/config/types.rs
(BlockchainConfig; OriginConfig is a tagged enum kind=http|fs|s3).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 11, 2026 14:03
@coderabbitai

coderabbitai Bot commented Jul 11, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@thiras, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 15 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: 3391d111-b44e-4765-aeab-a23e13a93a9a

📥 Commits

Reviewing files that changed from the base of the PR and between 5764f71 and 64522d0.

📒 Files selected for processing (5)
  • ansible/inventory/host_vars/decdn-node-1.yml.example
  • ansible/roles/decdn_node/README.md
  • ansible/roles/decdn_node/defaults/main.yml
  • ansible/roles/decdn_node/tasks/main.yml
  • ansible/roles/decdn_node/templates/node.toml.j2

Note

🎁 Summarized by CodeRabbit Free

Your organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Pro by visiting https://app.coderabbit.ai/login.

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds support and validation for several optional decdn node features, including the ADR 022 origin directory, ADR 011/031 content blacklist compliance, and cache pull-through origins (HTTP, FS, and S3). The review feedback highlights a potential issue where using | length > 0 on optional variables can cause template compilation or evaluation errors if they are undefined or null, recommending the safer | default('') filter instead. Additionally, a bug was identified in the S3 path-style validation assertion, which fails to reject quoted string booleans; using the is boolean test is suggested to strictly enforce boolean types.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread ansible/roles/decdn_node/templates/node.toml.j2
Comment thread ansible/roles/decdn_node/templates/node.toml.j2
Comment thread ansible/roles/decdn_node/tasks/main.yml
Comment thread ansible/roles/decdn_node/tasks/main.yml
Comment thread ansible/roles/decdn_node/tasks/main.yml
Comment thread ansible/roles/decdn_node/tasks/main.yml Outdated
Comment thread ansible/roles/decdn_node/tasks/main.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the ansible/roles/decdn_node role to render additional Arbitrum Sepolia config fields and to support a [cache.origin] pull-through backend, bringing the role’s node.toml output closer to the upstream Arbitrum Sepolia example and adding deploy-time validation + documentation for the new knobs.

Changes:

  • Add optional [blockchain] origin-directory + content-blacklist fields to the rendered node.toml, with corresponding defaults and validation asserts.
  • Add optional [cache.origin] rendering with http/fs/s3 variants, plus deploy-time validation of required fields and value shapes.
  • Update role README and the decdn-node-1 host_vars example to document and illustrate the new configuration knobs.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
ansible/roles/decdn_node/templates/node.toml.j2 Emits optional origin-directory, content blacklist, and [cache.origin] config blocks when set.
ansible/roles/decdn_node/tasks/main.yml Adds fail-loud asserts to validate new optional contract addresses, scan-floor blocks, and cache-origin config.
ansible/roles/decdn_node/README.md Documents the new optional knobs and the operational impact of omitting a cache origin.
ansible/roles/decdn_node/defaults/main.yml Introduces new default variables for origin directory, content blacklist, and cache origin kinds/fields.
ansible/inventory/host_vars/decdn-node-1.yml.example Updates example host_vars with Arbitrum Sepolia addresses and demonstrates cache-origin configuration.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread ansible/roles/decdn_node/tasks/main.yml Outdated
Address PR review (Copilot + gemini): the decompress and path_style asserts
fired regardless of decdn_cache_origin_kind, so a leftover value for a
non-selected kind — which the template never renders — could fail an unrelated
deploy, contradicting the 'other kinds' fields are ignored' contract. Gate the
decompress check to kind==http and path_style to kind==s3. Also switch path_style
to `is boolean` so a quoted "false" is rejected loudly rather than accepted by
the prior string check (which contradicted its own comment).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@thiras
thiras merged commit e636235 into main Jul 11, 2026
8 checks passed
@thiras
thiras deleted the feat/arbitrum-config-parity branch July 11, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants