Skip to content

Infisical Sole-Source-of-Truth: Runtime Settings Loader for Tunable Knobs - #1585

Merged
jaywedgeworth22 merged 8 commits into
mainfrom
infisical-sot
Oct 9, 2026
Merged

jaywedgeworth22 merged 8 commits into
mainfrom
infisical-sot

Conversation

@jaywedgeworth22

@jaywedgeworth22 jaywedgeworth22 commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Introduces a centralized appSettings service for 17 non-secret runtime knobs, loading Infisical values into an in-memory cache during Node startup and using process.env when credentials are unavailable or the initial Infisical load fails.
  • Adds periodic background refresh, SIGHUP refresh, and an admin-triggered refresh path while keeping routine settings reads network-free.
  • Adds session-gated GET, PUT, and POST /api/settings/runtime endpoints to inspect effective non-secret values and sources, validate and update supported settings, and force a refresh. Infisical-mode saves persist remotely before updating the cache; env-fallback saves update the local environment.
  • Migrates scheduler startup gating, adapter timeouts, OTLP and cost-ingestion switches, scoped-token enforcement, read-token configuration, alert delivery and routing, and readiness thresholds to centralized settings reads.
  • Updates existing alert settings saves to use write-through persistence and documents Infisical/env-sync ownership, fallback behavior, client responsibilities, rotation procedures, security boundaries, and admin workflows.

Tests

  • Added unit coverage for startup loading, cache-only reads, last-known-good refresh behavior, write ordering and failure handling, env fallback, typed parsing, defaults, schema validation, and settings metadata.
  • Added route coverage for session gating, secret exclusion, unknown or invalid values, valid fallback writes, and manual refresh.
  • No test execution results are included in the provided changes.

@jaywedgeworth22
jaywedgeworth22 enabled auto-merge (squash) October 4, 2026 01:13
Comment thread src/lib/app-settings.ts Fixed

Copy link
Copy Markdown
Collaborator Author

@kody start-review

@kody-ai

This comment has been minimized.

@kody-ai

kody-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

kody code-review Kody Rules medium

Re-export the intended public settings surface from src/index.ts and have package-level tests and consumers import through that entry point. This prevents the exported schema and utilities from being exercised only through an internal module path.

Kody rule violation: Every exported schema or utility ships with tests and must typecheck

@kody-ai

kody-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

kody code-review Kody Rules critical

Resolve the current session with better-auth and perform the application’s role or tenant authorization against that session before allowing settings to be read, reloaded, or mutated. A standalone verifySessionToken boolean does not satisfy the required current-session authorization contract.

Kody rule violation: Authenticate and validate every server mutation

@kody-ai

kody-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

kody code-review Kody Rules medium

Use two literal ASCII spaces after each period in this operator-facing log message so the required sentence spacing survives rendering.

Kody rule violation: Use two spaces between sentences in every human-facing string and agent-written paragraph

Comment thread INFISICAL.md Outdated
Comment thread INFISICAL.md Outdated
Comment thread src/app/api/settings/route.ts
Comment thread src/app/api/settings/runtime/route.ts Outdated
Comment thread src/app/api/settings/runtime/route.ts Outdated
Comment thread src/app/api/settings/runtime/route.ts Outdated
Comment thread src/instrumentation.ts
Comment thread src/instrumentation.ts Outdated
Comment thread src/instrumentation.ts Outdated
Comment thread src/lib/__tests__/app-settings.test.ts Outdated
Comment thread src/lib/app-settings.ts Outdated
Comment thread src/lib/app-settings.ts
Comment thread src/lib/app-settings.ts
Comment thread src/lib/ingest-auth.ts Outdated
jaywedgeworth22 pushed a commit that referenced this pull request Oct 4, 2026
@kody-ai

This comment has been minimized.

jaywedgeworth22 and others added 2 commits October 4, 2026 20:04
Defensive pin for GHSA-vfj7-8cjw-p6xm (braces stack-exhaustion DoS,
pulled in via chokidar and micromatch). Lockfile already resolves the
single hoisted copy to 3.0.3, so no lockfile diff; the override guards
against future re-resolution to a vulnerable 3.0.x.
@kody-ai

This comment has been minimized.

@kody-ai

kody-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

kody code-review Kody Rules medium

Add matching Vitest coverage for each changed source behavior because the PR currently tests the app-settings service changes without covering the other runtime behavior changes.

Kody rule violation: Keep type safety and test coverage for source changes

@kody-ai

kody-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

kody code-review Kody Rules medium

Export the new scheduler utility from src/index.ts and have package-level tests and consumers import it through that entry point because it is currently reachable only through private module aliases.

Kody rule violation: Every exported schema or utility ships with tests and must typecheck

@kody-ai

kody-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

kody code-review Kody Rules medium

Separate the two sentences in the runtime-settings summary bullet with   so the required two-space gap survives GitHub rendering.

Kody rule violation: Use two spaces between sentences in every human-facing string and agent-written paragraph

Comment thread src/app/api/ready/route.ts
Comment thread src/app/api/settings/route.ts
Comment thread src/app/api/settings/route.ts
Comment thread src/app/api/settings/route.ts
Comment thread src/instrumentation.ts Outdated
Comment thread src/lib/__tests__/app-settings.test.ts Outdated
Comment thread src/lib/app-settings.ts
Comment thread src/lib/app-settings.ts
Comment thread src/lib/ingest-auth.ts
- getWithSource(): same empty-string rule as get() so the admin surface
  reports the value actually in effect (Infisical-empty falls to env).
- Record the USAGE_SCHEDULER_ENABLED boot gate: readiness answers with the
  boot decision, not the live knob, so a post-boot knob flip cannot wedge
  /api/ready into a permanent not_ready/503 restart loop.  Doc scoped:
  the scheduler gate is boot-applied.
- PUT /api/settings: strict Zod body schema (unknown fields rejected);
  rollback failures log loudly instead of being swallowed.
- Regression coverage for the USAGE_INGEST_REQUIRE_SCOPED_TOKENS bool
  vocabulary (1/yes/on/TRUE deny, 0/no/off/FALSE allow); replaced the
  tautological getBool fallback assertion with a real env-fallback case.
- instrumentation test resets the recorded boot gate between register() runs.

Two findings evaluated as false positives (no code change):
- Test 'hardcoded client secret': values are synthetic fixtures ('id',
  'secret', 'bad-secret'); requiring runtime env vars would break hermeticity.
- 'server-only' guard on app-settings.ts: the module is value-imported by the
  'use client' FleetQuotaMatrixCard via quota-windows -> provider-manifest;
  the guard would fail the production build.  Credentials are read only in
  init() (nodejs runtime); the client bundle's process.env cannot carry them.
@kody-ai

This comment has been minimized.

Comment thread src/app/api/settings/route.ts Outdated
Comment thread src/app/api/settings/route.ts Outdated
Comment thread src/app/api/settings/route.ts Outdated
Comment thread src/lib/runtime-health.ts
Muse-Assist and others added 3 commits October 5, 2026 14:22
- Expose getAppliedSchedulerGate(); GET /api/settings/runtime annotates
  USAGE_SCHEDULER_ENABLED with appliedValue + restartRequired so the admin
  surface reports the boot-applied value, not the live knob.
- instrumentation test: regression test pinning the boot-gate invariant
  (post-boot flip leaves the recorded answer false); clear Infisical
  credential env vars in beforeEach so ambient creds cannot flip the
  service into Infisical mode mid-suite.
…1585)

Per kody re-review: keep the operator-visible Error message (the failure
visibility 4180153043 asked for), but replace String(rollbackError) for
non-Error throwables with a fixed 'UnknownError' so an arbitrary thrown
value is never serialized into logs.
…1585)

Reset appSettings and strip ambient Infisical creds in runtime route tests so
cloud VMs stay in env-fallback mode.  Add scheduler boot-gate unit coverage and
annotate GET /api/settings/runtime when the gate is recorded.

Co-authored-by: Jay Wedgeworth <jaywedgeworth22@users.noreply.github.com>
@kody-ai

kody-ai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Kody Review Complete

Great news! 🎉
No issues were found that match your current review configurations.

Keep up the excellent work! 🚀

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

​

cursoragent and others added 2 commits October 9, 2026 10:04
Remove committed Infisical project UUID from app-settings; resolve project
id from env only and mark the module server-only. Export strict Zod schemas
for settings PUT routes. Inject synthetic Infisical test credentials via
vitest setup instead of hardcoding secrets in tests. Align .env.example with
the Infisical-backed local dev launcher.

Co-authored-by: Jay Wedgeworth <jaywedgeworth22@users.noreply.github.com>
…build

The previous commit (af24b1a) added `import "server-only";` to
app-settings.ts to address a Kody critical finding (credential-handling
module should carry the server-only guard). This re-introduced a defect
that an earlier review round (1addfd4) had already identified and
deliberately left unfixed: app-settings.ts's read methods are
value-imported by src/lib/provider-manifest.ts, which is reachable from
the "use client" FleetQuotaMatrixCard (via quota-windows.ts ->
AgentsDashboard.tsx). Adding the server-only sentinel anywhere in that
import graph — confirmed via `npm run build`, including behind a dynamic
import() split (the pattern instrumentation.ts uses to dodge the
edge-runtime bundle; it does NOT dodge this specific RSC boundary check) —
fails the production build with "'server-only' cannot be imported from a
Client Component module". This was breaking build/verify/smoke CI on PR
#1585.

Revert to the pre-af24b1af state for this one guard; the real security
boundary already holds without it — init() (the only call site that reads
the Infisical client secret via resolveCredentials()) is invoked
exclusively from instrumentation.ts (Node server startup), never from
client-reachable code. Documented inline so a future Kody round does not
re-trigger this regression.

Also drops the now-unused server-only npm dependency and its vitest alias
stub, which existed only to support the reverted import.

Verified locally: tsc --noEmit, npm run lint, npm test (2850 passed),
npm run build (production build succeeds) all green.

Co-authored-by: Cursor <cursoragent@cursor.com>
@jaywedgeworth22

Copy link
Copy Markdown
Collaborator Author

@kody please re-review. Pushed commit 6c31b38 which reverts the one build-breaking change from af24b1a (the re-added import "server-only"; on src/lib/app-settings.ts, which fails the production build because this module is value-imported by a "use client" component chain — provider-manifest.ts -> quota-windows.ts -> FleetQuotaMatrixCard.tsx). Confirmed via local npm run build and now via green CI (build/verify/smoke/CodeQL/gitleaks all passing on 6c31b38). All 8 original critical findings, plus every subsequent round's findings, remain fixed in current code — only this one guard was reverted, with rationale documented inline in app-settings.ts.

@jaywedgeworth22
jaywedgeworth22 merged commit bd55e9b into main Oct 9, 2026
10 checks passed
@jaywedgeworth22
jaywedgeworth22 deleted the infisical-sot branch October 9, 2026 10:53
jaywedgeworth22 added a commit that referenced this pull request Oct 9, 2026
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants