Repository navigation
Conversation
Depth on one target beats breadth across three, and AWS cost ~4,600 lines of the least testable code here plus eleven direct SDK modules. BREAKING CHANGE: `serverless.provider: aws` no longer resolves. Last release with Lambda/CloudFront support is v0.15.1; VPS is unaffected. Also deletes resource_view.go, an ACM/CloudFront report that already rendered empty cards on every Cloudflare deploy. Direct aws-sdk-go-v2 modules drop from 14 to 3, the ones R2's S3-compatible API needs.
…time The doc predated the SSR work and pointed users at AWS, which no longer exists. Checking the source rather than the commit messages exposed two stale comments, both corrected here: actions.mjs claimed results go out as JSON when they are Flight-encoded, and dispatcher.mjs claimed revalidation had not landed when cache.mjs is wired. It now states dynamic SSR as implemented but unverified, and adds a version matrix plus a failure-mode table mapping each status code to its cause.
…ated docs A fallback that has quietly rotted is worse than no fallback. NextCorePayload now carries a schema_version, validated by the daemon before any field is read; previously CLI/daemon skew became zero values and a release would deploy with no health path and report success. Adds vps-smoke.yml, which drives a real Next.js app through the VPS build path and asserts the artifact the daemon receives, and docs/vps.md with a 2026-03-05 review date.
…rypto Five CI failures on #48, diagnosed against main to separate mine from pre-existing. Mine: - internal/packaging/runtime/bridge.test.js was left behind when the AWS target went. bridge.js was the Lambda shim; the test outlived it, and magefile's TestUnit ran it via mg.Deps(TestBridge). `go test ./...` never touched it, which is why it passed locally and failed in CI — the repo's real unit entrypoint is `mage testUnit`, and that is what I should have run. Replaced TestBridge with TestRuntime, which runs the 156 tests under shared/nextcompile/runtime_src. Nothing in the magefile or in any workflow was running those: the dispatcher, RSC, SSR, Server Actions, metadata and middleware-matching tests — the code that actually executes on workerd — had zero automated coverage. The only Node test wired into CI was the one for the runtime we just deleted. - provider.go declared serverless.ServerlessResourceMap, which stutters (revive). Renamed to serverless.ResourceMap. - guide.go's verification section still printed ACM validation-CNAME examples (`dig _5f2eb7... CNAME`). That guide is VPS-only now, and VPS uses A records with Caddy issuing certs on first request, so the instructions were telling users to look up records that will never exist. Rewritten against A records, and it now takes the domain instead of hardcoding nextdeploy.org. Pre-existing on main, fixed here because they block the merge: - gofmt: main has 8 unformatted files. Deleting the AWS ones took it to 4; formatted the rest. Small diffs (3-28 lines each). - govulncheck: GO-2026-6354 and GO-2026-6355, two SSH DoS advisories in golang.org/x/crypto v0.53.0, reachable from server.connectSSH. Bumped to v0.56.0, the fixed version named by both advisories.
bridge.test.js outlived the Lambda shim it tested, and mage testUnit ran it; `go test ./...` did not, which is why this passed locally and failed in CI. Replaced it with TestRuntime, which runs the 156 tests under shared/nextcompile/runtime_src. Nothing was running those — the dispatcher, RSC, SSR and Server Actions tests had no automated coverage at all. Also renames the ServerlessResourceMap stutter, rewrites the VPS DNS guide's ACM-era dig examples, and clears main's gofmt backlog.
Four CI failures on #48, diagnosed against main to separate mine from pre-existing. Mine: - internal/packaging/runtime/bridge.test.js was left behind when the AWS target went. bridge.js was the Lambda shim; the test outlived it, and magefile's TestUnit ran it via mg.Deps(TestBridge). `go test ./...` never touched it, which is why it passed locally and failed in CI — the repo's real unit entrypoint is `mage testUnit`, and that is what I should have run. Replaced TestBridge with TestRuntime, which runs the 156 tests under shared/nextcompile/runtime_src. Nothing in the magefile or in any workflow was running those: the dispatcher, RSC, SSR, Server Actions, metadata and middleware-matching tests — the code that actually executes on workerd — had zero automated coverage. The only Node test wired into CI was the one for the runtime we just deleted. - provider.go declared serverless.ServerlessResourceMap, which stutters (revive). Renamed to serverless.ResourceMap. - guide.go's verification section still printed ACM validation-CNAME examples (`dig _5f2eb7... CNAME`). That guide is VPS-only now, and VPS uses A records with Caddy issuing certs on first request, so the instructions were telling users to look up records that will never exist. Rewritten against A records, and it now takes the domain instead of hardcoding nextdeploy.org. Pre-existing on main, fixed here because it blocks the merge: - gofmt: main has 8 unformatted files. Deleting the AWS ones took it to 4; formatted the rest. Small diffs (3-28 lines each). Left alone deliberately: the Vulnerability Check failure (GO-2026-6354 and GO-2026-6355, SSH DoS advisories in golang.org/x/crypto v0.53.0, reachable from server.connectSSH). It fails on main too. The fixed version, v0.56.0, requires Go 1.26, and go.mod currently declares 1.25.0 while five workflows pin GO_VERSION 1.25.x with GOTOOLCHAIN=local — so taking the fix means a repo-wide toolchain upgrade that also touches the release pipeline. That is a deliberate change of its own, not something to smuggle into an AWS removal.
b1070a0 to
667744d
Compare
Both are pre-existing code that my edits pulled into golangci-lint's new-issues diff. The G204 exec is annotated rather than restructured: resolveNextBinary only ever returns node_modules/.bin/next after stat'ing it, args are a fixed verb plus a closed flag set, and exec takes argv directly with no shell.
|
CI: 13 of 15 green. The two red checks are pre-existing on
I did try fixing it and backed it out. The fixed release, v0.56.0, requires Go 1.26, which bumps Worth flagging from fixing the other failures: nothing was running the 156 tests under Also: |
The AWS removal took out the adapters but left their vocabulary in places users read. `nextdeploy inspect` scored bundles against a 250MB Lambda limit; it now sizes the actual shipped worker.mjs against Cloudflare's real 64 MiB uncompressed limit and notes the 1-second startup budget. ship --verbose and creds also still advertised S3, Lambda and aws. CODE_QUALITY.md's examples move to Cloudflare equivalents, cloudflare.go's header no longer claims the adapter is unimplemented, and the tracked `last` file (contents: this repo's own path) is gone. pivot.md, burdenremoval.md and yussuf.md get status blocks rather than deletion.
4e1d8dd to
222c8be
Compare
Next's Deployment Adapter API went stable in 16.2 and replaces the manifest archaeology in shared/nextcore with a typed, versioned public contract. The package does one thing — serialize the build output to a versioned envelope — and deliberately contains no mapping or Cloudflare knowledge, so it cannot grow into a second implementation of the product. Records the five decisions that are expensive to change later: repo-relative path normalization, a whitelisted config subset, deterministic serialization, a schemaVersion validated Go-side, and atomic write-or-throw. Also notes that prerenders show no tags field in the reference, which needs confirming against a real build before the ISR tag store is designed around it.
Adds shared/ui and updates the apply/ship/generate-ci commands along with preview and workflow CI/CD internals.
Depth on one target is worth more than breadth across three. The AWS lane is occupied by OpenNext + SST with Amplify Hosting underneath, and holding it cost ~4,600 lines of the least testable code in the repo plus eleven direct AWS SDK dependencies — none of which transfers to the Cloudflare resource layer where the differentiated work actually lives.
BREAKING CHANGE:
serverless.provider: awsno longer resolves. The last release with Lambda/CloudFront support is v0.15.1. VPS is unaffected.63 files changed, +215 / −6,750.go build,go vet,go test ./...and the 156node --testruntime tests are green. golangci-lint adds no new findings.Three commits, and why they're together
This branch carries more than the AWS deletion, because the second and third commits fix things the first one exposed. Splitting them would leave commit 1 with a README link pointing at a gitignored file.
ed29aa864e485aCLOUDFLARE_PARITY.md— it pointed users at AWS, which no longer existsddbb6d1schema_version, smoke CI, a tracked VPS doc1 — AWS removal
Deleted: the 10
aws*.goadapter files (Lambda, CloudFront, S3, ACM, IAM, SQS, Secrets Manager),cmd/revalidator,cmd/imgoptand their embedded bootstrap binaries,build-lambdas.sh,dist-config.json, the Lambda config fields, the AWS scaffold template, the AWS CI branch, and the ACM/CloudFront half of the DNS guide.Also deleted
resource_view.go(856 lines). It was an ACM-validation and CloudFront walkthrough end to end, and it was already rendering empty CloudFront/Lambda/ACM cards on every Cloudflare deploy.shipnow logs an accurate summary instead. A Cloudflare-shaped report (worker, bindings, routes) is follow-up work, not something faked here.Direct
aws-sdk-go-v2modules: 14 → 3. The three that stay (core, credentials,service/s3) are what R2's S3-compatible API needs.Two judgment calls worth a look:
packaging.S3Asset/S3Assets/S3Keyrenamed toStaticAsset/StaticAssets/Key. Compiler-verified; R2 is the only consumer now. Happy to revert if you'd rather keep the churn out.2 — Parity doc
Verified against the source rather than the commit messages, which turned up two comments the code had outgrown (both corrected in place):
actions.mjsclaimed action results go out as JSON. They are Flight-encoded (text/x-component) viaencodeFlightReply; JSON is the fallback.dispatcher.mjsclaimed "revalidation arrives with cache.mjs".cache.mjsis wired —revalidatePath/revalidateTag/unstable_cache, an in-memory tier and a KV tier behindNEXTCOMPILE_CACHE.The doc now states that dynamic SSR is implemented but unverified, with both reasons cited:
ssr.test.mjsandrsc.test.mjsexclude the render path, and thereact-serverexport-condition gap invendor/README.mdis still open against--conditions=workerd,worker,node. It adds a version support matrix, a failure-mode table mapping each status code to its cause (including the quietest one — 200 with a blank page, when RSC encoding succeeded but the SSR builds were missing), and states ISR precisely: on-demand invalidation works, time-basedrevalidatenever fires, no R2 rewrite.3 — VPS freeze
VPS stays as the fallback for the quarter after a Next.js release Workers can't run yet. An unmaintained fallback that has quietly rotted is worse than no fallback, so freezing it means three things:
NextCorePayloadcarries aschema_version(the one real correctness gap). Written by the CLI, shipped in the tarball, unmarshalled by a separately versioned daemon — Go's decoder turns skew into zero values, so a stale daemon would deploy a release with no health path and no cgroup limits and report success.ValidateSchemanow runs before any field is read and names the remedy..github/workflows/vps-smoke.yml— builds the daemon for linux/amd64, runs daemon + payload tests, scaffolds a real Next.js app, drives the VPS build path, and asserts the artifact the daemon receives. No server, no SSH. Not yet executed; it runs on merge.docs/vps.md, tracked and curated, with a 2026-03-05 review date so the target gets deleted on evidence rather than argument. The olddocs/VPS_DEPLOY_FLOW.mdis gitignored as personal notes.Review notes
gofmtis clean;maincurrently has 8 unformatted files, and this branch clears them.shared/nextcompile/runtime_src.mage testUnitnow does.