Skip to content

Publish to npm, trim OpenTelemetry to metrics, and fall back to FileDB when LMDB cannot load - #692

Merged
satyakigh merged 5 commits into
mainfrom
npm-publish
Oct 9, 2026
Merged

satyakigh merged 5 commits into
mainfrom
npm-publish

Conversation

@satyakigh

@satyakigh satyakigh commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Production releases are published to npm as @aws/cloudformation-languageserver, so standalone editors can install the server without downloading a platform archive:

npm install -g @aws/cloudformation-languageserver
cloudformation-languageserver --stdio

Two runtime changes make that package practical. The OpenTelemetry setup is reduced to the metrics pipeline the server actually uses, which removes most of the installed dependency tree, and the server falls back to the encrypted file store when the lmdb native addon cannot be loaded, since npm consumers run on hosts the release matrix does not cover. GitHub Release archives are unchanged apart from their generated package.json; they remain the source for cfn-init and the legacy glibc 2.28 builds, which the npm package does not include.

Published package

The production bundle directory is the npm package. The build writes a publish-ready package.json into it: main and bin point at cfn-lsp-server-standalone.js, which now carries a Node shebang; engines.node is >=20; and dependencies are the 17 packages the compiled bundle loads at runtime, pinned to lockfile versions and derived from the compiled module graph so the list cannot drift from the code. The tarball is platform-independent: node_modules/ and bin/cfn-init are excluded, and npm resolves the native prebuilds for lmdb and tree-sitter on the consumer's machine. It packs to 73 files and 37 MB compressed, 33 MB of which is the bundled cfn-lint wheels. The root manifest becomes private: true and gains the repository, homepage, and bugs metadata npm displays. The package name already exists on the registry as a 0.0.0 placeholder, so the first workflow publication becomes latest.

Telemetry

OTELInstrumentation builds a MeterProvider with the same OTLP exporter, export interval, and views as before, plus the single RuntimeNodeInstrumentation that was the only enabled one, instead of a NodeSDK carrying auto-instrumentations-node with every other instrumentation switched off. The trace and log SDKs are dropped, and ScopedTelemetry loses the Tracer it never used. Emitted metrics, resource attributes, and export cadence are unchanged. The lockfile's production closure shrinks from 382 packages to 265 (OpenTelemetry from 80 to 13); THIRD-PARTY-LICENSES.txt and the SBOM are regenerated for the smaller tree.

LMDB fallback

lmdb binds its native addon while the module is evaluated, so a host without a usable prebuild fails on import rather than on the first open(). All runtime loading of lmdb goes through src/datastore/lmdb/LMDBModule.ts, and MultiDataStoreFactoryProvider probes it before choosing a store: on failure it logs the cause, emits lmdb.unavailable under the DataStore telemetry scope, and uses FileStoreFactory. Windows and the FileDb feature flag still select the file store without probing. Tests cover the fallback, the no-probe path, and the loader against the real module.

Release workflow

release.yml gains two jobs that run for stable tags only, after the long-running soak has exercised the release bundles on Node 18 through 24 across macOS, Linux, and Windows. publish-npm publishes the linux-x64 bundle through npm trusted publishing (OIDC, release-npm environment) with npm publish --provenance, after confirming the bundle version matches the tag and the tarball contains the required files and no platform-specific ones. It is idempotent: a version already on the registry is skipped. verify-publish-npm installs the published version into a clean project and confirms the executable is linked, signatures audit clean, and a provenance attestation is attached.

@satyakigh
satyakigh requested a review from a team as a code owner September 25, 2026 17:45
@github-code-quality

github-code-quality Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/vitest

The overall line coverage in commit 60c0a88 in the npm-publish branch remains at 91%, unchanged from commit e1dc3fe in the main branch.

Show a line coverage summary of the most impacted files.
File main e1dc3fe npm-publish 60c0a88 +/-
src/telemetry/S...pedTelemetry.ts 96% 87% -9%
src/datastore/DataStore.ts 92% 94% +2%
src/datastore/l...b/LMDBModule.ts 0% 100% +100%

Updated October 06, 2026 13:56 UTC

@satyakigh satyakigh changed the title Prepare repo so we can publish to npm, use FileDB if LMDB cannot be l… Publish to npm and fall back to FileDB when LMDB cannot load Sep 25, 2026
@satyakigh satyakigh changed the title Publish to npm and fall back to FileDB when LMDB cannot load Publish to npm, trim OpenTelemetry to metrics, and fall back to FileDB when LMDB cannot load Sep 27, 2026
@satyakigh
satyakigh added this pull request to stack #701 October 7, 2026 20:03

@mrinaudo-aws mrinaudo-aws left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@satyakigh
satyakigh merged commit 19e02f7 into main Oct 9, 2026
19 checks passed
@satyakigh
satyakigh deleted the npm-publish branch October 9, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants