Skip to content

Point subgraph-deploy at Ormi instead of Goldsky - #399

Merged
Siddharth2207 merged 4 commits into
mainfrom
devops-366-ormi-subgraph-deploy
Oct 6, 2026
Merged

Siddharth2207 merged 4 commits into
mainfrom
devops-366-ormi-subgraph-deploy

Conversation

@Siddharth2207

@Siddharth2207 Siddharth2207 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • subgraph-deploy now builds with the Graph CLI and deploys to Ormi (subgraph.api.ormilabs.com) using ORMI_DEPLOY_KEY, SUBGRAPH_NAME, and ORMI_QUERY_BASE.
  • A version that already answers on the query URL is skipped. The deploy command does not trace the key.
  • The Goldsky CLI is removed from rainix: the derivation, its place in subgraph-shell and the default shell, the check-shell smoke test, the README pin, and the sol-shell slim assertion. Its consumers now deploy with graph deploy to Ormi (gildlab/offchainAssetVault-subgraph, Deploy subgraphs to Ormi cyclofinance/cyclo.subgraph#66), and raindex runs subgraph-deploy. S01-Issuer/st0x-rewards still calls goldsky and is left alone.

Merge order

Merge this before rainlanguage/raindex#2894. That workflow calls nix develop github:rainlanguage/rainix#subgraph-shell, which tracks rainix main.

Ormi already indexes Robinhood Chain. The chain slug is robinhood (see the raindex PR), so this task deploys it as raindex-robinhood along with the other networks in networks.json.

Test plan

  • bats test/bats/task/subgraph-deploy.test.bats and subgraph-deploy-version.test.bats; cargo test in rainix-static (ormi-probe)
  • pre-commit on the changed files (deadnix, nil, nixfmt, shellcheck, statix)
  • After merge, and after ORMI_DEPLOY_KEY exists on raindex, dispatch Deploy subgraph and confirm the deployment lands on Ormi

Part of DEVOPS-366.

Summary by CodeRabbit

  • New Features
    • Added a command to check whether a specific subgraph version is deployed.
    • Deployments now target Ormi, skip versions that are already deployed, and avoid deploying when deployment status cannot be confirmed.
  • Bug Fixes
    • Deployment credentials are no longer exposed in routine command output.
  • Chores
    • Goldsky CLI is no longer included in the development shells.
  • Tests
    • Added coverage for deployment, existing-version skips, probe and deployment failures, and missing required settings.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: rainlanguage/rainix/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 12457988-2e75-4ad8-86d1-a723095eb33c
📥 Commits

Reviewing files that changed from the base of the PR and between 28c1ac8 and e2477a9.

📒 Files selected for processing (4)
  • .github/workflows/check-shell.yml
  • README.md
  • flake.nix
  • test/bats/devshell/sol-shell/slim.test.bats
💤 Files with no reviewable changes (3)
  • README.md
  • .github/workflows/check-shell.yml
  • test/bats/devshell/sol-shell/slim.test.bats

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The deployment task now uses an Ormi probe to check subgraph versions before deployment. The ormi-probe command validates inputs, classifies responses, and retries transient failures. The task skips deployed versions and deploys confirmed missing versions. Goldsky was removed from the development shells and related checks.

Changes

Ormi deployment

Layer / File(s) Summary
Ormi probe command and response handling
rainix-static/src/main.rs, rainix-static/src/ormi_probe.rs, rainix-static/src/soldeer_gate.rs
Adds the ormi-probe command, input validation, response classification, retry handling, and tests for probe outcomes and errors.
Deployment orchestration and task integration
flake.nix, lib/subgraph-deploy.sh, test/bats/task/subgraph-deploy.test.bats, .github/workflows/check-shell.yml, README.md, test/bats/devshell/sol-shell/slim.test.bats
Routes the task through subgraph_deploy. The script checks each network and skips deployed versions or deploys confirmed missing versions. Bats tests cover outcomes, required variables, and deploy-key handling. Goldsky was removed from shell inputs, the pinned versions list, and related checks.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant DeploymentTask
  participant subgraph_deploy
  participant rainix_static
  participant OrmiQueryEndpoint
  participant GraphCLI
  participant OrmiDeploymentEndpoint
  DeploymentTask->>subgraph_deploy: invoke deployment
  subgraph_deploy->>rainix_static: probe subgraph name and version
  rainix_static->>OrmiQueryEndpoint: POST _meta query
  OrmiQueryEndpoint-->>rainix_static: deployed, missing, or failure response
  rainix_static-->>subgraph_deploy: exit status
  subgraph_deploy->>GraphCLI: deploy confirmed missing version
  GraphCLI->>OrmiDeploymentEndpoint: deploy subgraph
Loading

Merge Risk: 🟡 Moderate · up to e2477

Resolve the deployment credential exposure before relying on this workflow in production CI.

Security Architecture Review

Security architecture risk: 🔵 Low · up to e2477

The deployment flow limits credential inheritance and refuses deployment when the version check is inconclusive. No introduced security vulnerability was established, but production credential permissions, runner isolation, and concurrent deployment behavior remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The intended publication scope is the configured subgraph name across networks in networks.json. The maximum scope of a compromised key cannot be bounded from this repository: Ormi account permissions, cross-project authority, and downstream runner exposure are unspecified.

Security Findings and Attack Paths

  • inferred — A malicious dependency process able to observe the later deployment command could obtain its credential. This trust mechanism predates the PR: the base ran dependency installation with its deployment-token environment and also passed the token on command lines. The head reduces those exposure channels; increased effective credential authority was not established.

Trust Boundaries and Controls

  • observed — The configurable query endpoint controls the skip-or-deploy decision but does not receive ORMI_DEPLOY_KEY through the helper's arguments or environment. Probe URLs require HTTPS, labels cannot reshape URL paths, and curl is invoked without redirect-following. Configuration must still select the correct account: the code does not bind the query base to deployment-key ownership.

Resilience and Maintainability Implications

  • observed — Tests cover failure containment, credential-environment removal, tracing, and missing prerequisites using substituted tools. Probe tests inject HTTP responses and transport failures. These support the local control logic but do not establish production CLI output, runner process isolation, or Ormi publication atomicity.

Hardening Proposals

  • proposed — Use a deployment-isolated runner and a narrowly scoped Ormi key, and protect query-base configuration alongside deployment credentials. These would bound the existing dependency/process trust and prevent configuration authority from silently controlling deployment decisions.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 76.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 5 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: redirecting subgraph deployment from Goldsky to Ormi.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 76.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 5 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@linear

linear Bot commented Sep 28, 2026

Copy link
Copy Markdown

DEVOPS-366

@findolor findolor left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please address the two findings below before merging.

Local validation passed: all nine focused Bats tests, ShellCheck, the Nix deployment-task build, and mocked dry runs covering skip, deploy, and failure paths. No live deployment was attempted.

Comment thread flake.nix Outdated
Comment thread flake.nix Outdated
Siddharth2207 added a commit that referenced this pull request Oct 1, 2026
Address review on #399.

- Tracing is off for the whole task, so ORMI_DEPLOY_KEY is never printed by
  set -x, including in the presence check.
- The deploy key is removed from the environment of npm ci, git, the probe
  and graph build; only graph deploy receives it.
- The skip decision moves from bash/jq into `rainix-static ormi-probe`. It
  deploys only on a confirmed-missing response; transport and HTTP errors
  (retried), unrecognised bodies and a wrong query base fail the task.
- The probe validates the query base (https only) and the name/version
  labels before building the URL.
- Task orchestration moves to lib/subgraph-deploy.sh with injectable tools,
  with bats tests for the skip/deploy/fail paths and key exposure.

Co-authored-by: Cursor <cursoragent@cursor.com>
@Siddharth2207

Copy link
Copy Markdown
Contributor Author

Pushed eac4e05, which fixes both review findings (replies on each thread). A security pass over the PR found the following; the first three are fixed in that commit.

  • Deploy key in other processes. It was in the environment of npm ci (dependency install scripts), git, graph build and the probe. It is now stripped from all of them, and only graph deploy receives it.
  • URL path injection. SUBGRAPH_NAME, the network keys and the addresses go into the probe URL path. They are now validated as plain labels before any request.
  • Query base. It must be https:// with no query or fragment. The deploy endpoint stays hardcoded, so ORMI_QUERY_BASE can never receive the key.
  • Not fixed: key in ps. graph deploy --deploy-key has no env or stdin form, so the key is visible in the runner process table for that one command.
  • Not verified: graph deploy and --network. graph build --network <net> runs first, but graph deploy may recompile subgraph.yaml without it. Please confirm against a real deploy that the deployed manifest carries the right chain. I could not check the graph-cli 0.69.2 source.
  • Related, in raindex#2894. The workflow uses the unpinned nix develop github:rainlanguage/rainix#subgraph-shell, which CLAUDE.md forbids; it should use a full sha.

Verification: cargo clippy and cargo fmt are clean. The ormi-probe unit tests pass, along with the new bats tests, the pre-commit hooks and the Nix build of subgraph-deploy. The probe was also run against the live Ormi endpoint. No live deployment was attempted.

@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@rain-marvin review

@rain-marvin

rain-marvin Bot commented Oct 1, 2026

Copy link
Copy Markdown

🔎 Reviewing 39f1904, started by @Siddharth2207. The review will appear here when it's done.

@rain-marvin rain-marvin Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Opus 5.5 (Claude 1)

This PR moves the shared subgraph-deploy task from Goldsky to Ormi. It builds with the Graph CLI and deploys with ORMI_DEPLOY_KEY, SUBGRAPH_NAME and ORMI_QUERY_BASE. A new rainix-static ormi-probe subcommand decides whether a version is already live. It skips on a confirmed live answer, deploys only on Ormi's exact "missing" body, and fails the task on anything else. The deploy logic now lives in lib/subgraph-deploy.sh, with tracing off and the key removed from the environment of the other tools.

Overall read: good. Both earlier threads (trace leak, probe failure falling through to a deploy) are fixed properly. The probe classification is strict and well tested in Rust. I found no blockers. Three minor points: the new bats suite is never run by CI; the claim that only graph deploy sees the key does not fully hold, because graph deploy compiles the subgraph again; and one failed or unsynced version stops the deploy of every network after it. The cutover order with raindex#2894 is already noted in the description: raindex deploys fail between the two merges.

Comment thread test/bats/task/subgraph-deploy.test.bats
Comment thread lib/subgraph-deploy.sh Outdated
Comment thread lib/subgraph-deploy.sh Outdated
@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@CodeRabbit review

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@rain-marvin review

@rain-marvin

rain-marvin Bot commented Oct 1, 2026

Copy link
Copy Markdown

🔎 Reviewing 28c1ac8, started by @Siddharth2207. The review will appear here when it's done.

@rain-marvin rain-marvin Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Opus 5.5 (Claude 1)

This PR moves the subgraph-deploy task from Goldsky to Ormi. A new rainix-static ormi-probe subcommand checks if each <name>/<version> is already live. Only a confirmed-missing answer (exit 10) leads to graph deploy. Any other probe result, or a failed deploy, skips that network and makes the task fail at the end. The deploy key is copied into a local and unset from the environment before anything runs, tracing is off, and only the hardcoded Ormi deploy endpoint gets the key.

All five earlier threads are fixed at 28c1ac8, and the fixes hold. The panel found no blocker. There are two minor points: a broken or empty networks.json makes the task pass while it deploys nothing, and raindex deploys will fail in the time between this merge and the raindex migration. The documented residual exposure (the key in graph deploy argv, and trust in the subgraph's npm dependencies) is a fair trade. Note that unset also does not remove the key from /proc/<pid>/environ of the task shell or its ancestors, so the trust statement in the comment is the real boundary. The PR description test plan still names only subgraph-deploy-version.test.bats. It could also list the new subgraph-deploy.test.bats suite and the Rust probe tests.

Comment thread lib/subgraph-deploy.sh
Comment thread lib/subgraph-deploy.sh
@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@CodeRabbit review

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@Siddharth2207
Siddharth2207 requested a review from findolor October 1, 2026 14:57
@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@CodeRabbit review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Pull request base or head changed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Siddharth2207 and others added 4 commits October 5, 2026 20:47
New deploys were still landing on Goldsky, which is how the Robinhood-era copies appeared. The Goldsky CLI stays on PATH because other repos still call it directly.

Co-authored-by: Cursor <cursoragent@cursor.com>
Address review on #399.

- Tracing is off for the whole task, so ORMI_DEPLOY_KEY is never printed by
  set -x, including in the presence check.
- The deploy key is removed from the environment of npm ci, git, the probe
  and graph build; only graph deploy receives it.
- The skip decision moves from bash/jq into `rainix-static ormi-probe`. It
  deploys only on a confirmed-missing response; transport and HTTP errors
  (retried), unrecognised bodies and a wrong query base fail the task.
- The probe validates the query base (https only) and the name/version
  labels before building the URL.
- Task orchestration moves to lib/subgraph-deploy.sh with injectable tools,
  with bats tests for the skip/deploy/fail paths and key exposure.

Co-authored-by: Cursor <cursoragent@cursor.com>
- default-shell-test now runs subgraph-deploy.test.bats, so the key-leak and
  probe-gating regressions are caught.
- graph deploy compiles the manifest itself, so drop the redundant
  graph build and pass --network to graph deploy. The key is moved out of the
  environment up front so no tool inherits it; the comment now states what is
  and is not protected (graph deploy's toolchain and argv).
- A probe that cannot answer (e.g. a failed or syncing version) or a failed
  deploy no longer stops the remaining networks: it is recorded, never
  deployed on a failed probe, and the task fails at the end naming it.

Co-authored-by: Cursor <cursoragent@cursor.com>
Its live consumers now deploy with graph deploy to Ormi, and subgraph-deploy
never called it. Drop the derivation, its place in subgraph-shell and the
default shell, the check-shell smoke test, the README pin, and the sol-shell
slim assertion that only existed because it was in the default shell.

Co-authored-by: Cursor <cursoragent@cursor.com>
@Siddharth2207
Siddharth2207 force-pushed the devops-366-ormi-subgraph-deploy branch from 95a2ff5 to e2477a9 Compare October 5, 2026 15:18
@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@rain-marvin review

@rain-marvin

rain-marvin Bot commented Oct 5, 2026

Copy link
Copy Markdown

🔎 Reviewing e2477a9, started by @Siddharth2207. The review will appear here when it's done.

@rain-marvin rain-marvin Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR moves the subgraph-deploy task from Goldsky to Ormi. A new rainix-static ormi-probe subcommand decides whether a version is already live, and only a confirmed-missing answer leads to graph deploy. The deploy key is taken out of the environment and kept out of trace output. The Goldsky CLI is removed from the shells, CI, README and slim test.

Overall this is in good shape. The probe accepts only Ormi's two known answers and refuses everything else. Retries cover only transport errors, 429 and 5xx. A failed probe or deploy marks that network as not done, and the task fails at the end. The bats suite now runs in CI. No new blocker was found.

One earlier point is still open in the code: the networks.json enumeration fix from a resolved thread is not in this head (comment below). There is also one small hardening note on the graph launcher. Merge order with rainlanguage/raindex#2894 still applies, as the description says.

claude-opus-5-5 · high · 17 min

Comment thread lib/subgraph-deploy.sh
Comment thread lib/subgraph-deploy.sh
@Siddharth2207

Copy link
Copy Markdown
Contributor Author

@CodeRabbit review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@Siddharth2207
Siddharth2207 merged commit 0a85350 into main Oct 6, 2026
22 checks passed
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment:

S/M/L PR Classification Guidelines:

This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed.

Small (S)

Characteristics:

  • Simple bug fixes, typos, or minor refactoring
  • Single-purpose changes affecting 1-2 files
  • Documentation updates
  • Configuration tweaks
  • Changes that require minimal context to review

Review Effort: Would have taken 5-10 minutes

Examples:

  • Fix typo in variable name
  • Update README with new instructions
  • Adjust configuration values
  • Simple one-line bug fixes
  • Import statement cleanup

Medium (M)

Characteristics:

  • Feature additions or enhancements
  • Refactoring that touches multiple files but maintains existing behavior
  • Breaking changes with backward compatibility
  • Changes requiring some domain knowledge to review

Review Effort: Would have taken 15-30 minutes

Examples:

  • Add new feature or component
  • Refactor common utility functions
  • Update dependencies with minor breaking changes
  • Add new component with tests
  • Performance optimizations
  • More complex bug fixes

Large (L)

Characteristics:

  • Major feature implementations
  • Breaking changes or API redesigns
  • Complex refactoring across multiple modules
  • New architectural patterns or significant design changes
  • Changes requiring deep context and multiple review rounds

Review Effort: Would have taken 45+ minutes

Examples:

  • Complete new feature with frontend/backend changes
  • Protocol upgrades or breaking changes
  • Major architectural refactoring
  • Framework or technology upgrades

Additional Factors to Consider

When deciding between sizes, also consider:

  • Test coverage impact: More comprehensive test changes lean toward larger classification
  • Risk level: Changes to critical systems bump up a size category
  • Team familiarity: Novel patterns or technologies increase complexity

Notes:

  • the assessment must be for the totality of the PR, that means comparing the base branch to the last commit of the PR
  • the assessment output must be exactly one of: S, M or L (single-line comment) in format of: SIZE={S/M/L}
  • do not include any additional text, only the size classification
  • your assessment comment must not include tips or additional sections
  • do NOT tag me or anyone else on your comment

graphite-app Bot pushed a commit to rainlanguage/raindex that referenced this pull request Oct 7, 2026
## Summary
- Deploy subgraph now passes `ORMI_DEPLOY_KEY`, `SUBGRAPH_NAME=raindex`, and the public Ormi query base into `subgraph-deploy`.
- The Robinhood chain slug in `subgraph/networks.json` is `robinhood`, matching the network Ormi indexes. `graph build --network` writes that slug into the manifest, and the DecimalFloat lookup uses the same string. The deployment name for that chain is `raindex-robinhood`.
- Depends on rainlanguage/rainix#399. Merge that one first. This workflow tracks rainix `main`, so dispatching before that merge still runs the Goldsky task while this workflow no longer supplies `GOLDSKY_TOKEN`.
- `CI_GOLDSKY_TOKEN` is no longer read. Leave the secret in place until a dispatch has landed on Ormi, then remove it. Kais still needs to set the `ORMI_DEPLOY_KEY` GitHub secret from Vault `secret/infra/rain/ormi` (`deploy_key`) before a dispatch can succeed.

Part of [DEVOPS-366](https://linear.app/makeitrain/issue/DEVOPS-366/raindex-ci-rainix-deploy-new-subgraphs-to-ormi-instead-of-goldsky).

## Test plan
- [x] prettier and the other pre-commit hooks on the slug change
- [ ] Merge the rainix PR, set `ORMI_DEPLOY_KEY`, then dispatch this workflow
- [ ] Confirm each deployment is on Ormi, including `raindex-robinhood`, and the run log has no `api.goldsky.com` call

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **Updates**
  * Updated subgraph deployment to use the Raindex configuration and Ormi query service.
  * Updated the supported network name to `robinhood`; its deployed contract address and indexing start point remain unchanged.
  * Subgraph data for this network continues to use the same contract deployment and indexing start point under the updated network name.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants