Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/overlays-published.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ name: Overlays published
# .nojekyll so files are served byte-for-byte) publishes overlays/ at
# https://ontola.github.io/atomic-plugins/overlays/, where
# overlays/catalog/2026-10-02.json and integration-proxy's DEFAULT_CATALOG_PATH expect
# it. After each Pages build this checks that catalog.json and every overlay
# it. After each Pages build this checks that dated catalogs and every overlay
# it lists are served there and match the built commit. Pages' CDN caches
# for up to 10 minutes, so a mismatch is retried for up to 15 minutes before
# failing.
Expand Down
3 changes: 2 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -193,7 +193,8 @@ served at `https://ontola.github.io/atomic-plugins/overlays/<path>` —
`integration-proxy`'s default `CATALOG_PATH` is that folder's
`catalog/2026-10-02.json`. Dated catalogs and OAD-revision overlay filenames
are immutable; a new overlay does not change an existing catalog selection.
The unversioned catalog is temporarily deprecated pending the live switch. See
The unversioned catalog was removed after the verified localthought.io switch
on 2026-10-02. See
[`overlays/README.md`](overlays/README.md) for the publication model and its
checks. Provider paths mirror `openapi-directory` as
`overlays/APIs/<provider>/<service-if-any>/<version>/`.
Expand Down
33 changes: 22 additions & 11 deletions docs/agents/proxy-release.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,9 @@
runs it on Heroku through a small wrapper crate in a separate repository,
`localthought/integration-proxy` (template:
[`integration-proxy/examples/heroku-wrapper/`](../../integration-proxy/examples/heroku-wrapper/)).
On 2026-09-30 localthought.io ran 0.2.3 (Heroku release v81), from the
hand-over; not verified from here.
On 2026-10-02 localthought.io was verified running proxy 0.2.4 through
wrapper commit `1f89c7efb25f6fd0f7394997e69ed738fd1a4aad` (deployment v84),
with the dated catalog selected in Heroku release v85.

**Publishing a crate version and deploying to Heroku each need Michiel's OK,
per release** (#227 rule 10). The PRs leading up to them don't.
Expand All @@ -14,9 +15,7 @@ per release** (#227 rule 10). The PRs leading up to them don't.

1. **Release PR in this repo.** Set `version` in
`integration-proxy/Cargo.toml` and give the release its heading in
`integration-proxy/CHANGELOG.md`. (On 2026-09-30 the CHANGELOG still says
"0.2.3 (unreleased)" although 0.2.3 was published; fix that in the next
release PR.) Merge under rule 12.
`integration-proxy/CHANGELOG.md`. Merge under rule 12.
2. **Publish** (Michiel's OK). Tag the merge commit on `main`:

```sh
Expand All @@ -28,9 +27,9 @@ per release** (#227 rule 10). The PRs leading up to them don't.
Publishing (OIDC; no token is stored). A crates.io version is permanent.
3. **Wrapper PR** in `localthought/integration-proxy`: bump the crate in its
`Cargo.toml` and `Cargo.lock`. Merge it.
4. **Deploy** (Michiel's OK). Heroku's GitHub auto-deploy doesn't fire, so
push the wrapper's merged commit to the Heroku remote by hand, from a
checkout with Heroku access to the app `integration-proxy`:
4. **Deploy** (Michiel's OK). Check whether GitHub auto-deploy has produced
a release for the merged commit; if it has not, push that commit to the
Heroku remote by hand, from a checkout with Heroku access to the app `integration-proxy`:

```sh
git push https://git.heroku.com/integration-proxy.git <sha>:refs/heads/main
Expand All @@ -50,6 +49,18 @@ files and explicitly switch the default or `CATALOG_PATH` to opt in.
On 2026-10-02, before this rollout, Heroku's `CATALOG_PATH` was verified as
`https://raw.githubusercontent.com/ontola/atomic-plugins/refs/heads/main/overlays/catalog.json`
and its current release was v82, deploying wrapper commit `e31b4f2d`.
The unversioned file carries a `_comment` deprecation notice and retains the
prior OAD revisions until the authorized deployment is confirmed to load the
dated catalog. Only then remove it; published overlay revision files remain.
After proxy 0.2.4 was published to crates.io and wrapper PR
[localthought/integration-proxy#81](https://github.com/localthought/integration-proxy/pull/81)
merged, Heroku deployed that wrapper as v84. The authorized catalog switch
created release v85:

```sh
heroku config:set CATALOG_PATH=https://ontola.github.io/atomic-plugins/overlays/catalog/2026-10-02.json -a integration-proxy
```

The running web dyno was up, `/catalog` listed nine platforms, and
`/catalog/discord.yaml` changed from two paths to 153. With that switch
verified, the deprecated `overlays/catalog.json` was removed. Published
overlay revision files remain immutable. The full Discord document composes,
but its mixed bot-token/OAuth connection support awaits
[atomic-plugins#258](https://github.com/ontola/atomic-plugins/issues/258).
24 changes: 0 additions & 24 deletions integration-proxy/src/catalog.rs
Original file line number Diff line number Diff line change
Expand Up @@ -870,30 +870,6 @@ mod tests {
.is_ok());
}

#[tokio::test]
#[ignore = "downloads pinned OADs from the deprecated compatibility catalog"]
async fn deprecated_catalog_retains_connectable_security_profiles() {
let overlays = std::path::Path::new(env!("CARGO_MANIFEST_DIR")).join("../overlays");
let catalog = Catalog::load_with_mirror(
overlays.join("catalog.json").to_str().unwrap(),
&crate::build_http_client(),
Some(&overlays),
)
.await
.unwrap();
for name in catalog.names() {
catalog
.security_scheme(&name)
.unwrap_or_else(|error| panic!("{name}: {error}"));
}
assert!(catalog
.allows("discord", "GET", "/api/v10/users/@me")
.is_some());
assert!(catalog
.allows("discord", "POST", "/api/v10/channels/123/messages")
.is_none());
}

fn tempfile_path(name: &str) -> std::path::PathBuf {
let dir = std::env::temp_dir().join(format!(
"integration-proxy-test-{}-{}",
Expand Down
16 changes: 8 additions & 8 deletions overlays/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,12 +26,12 @@ to `main` changes what the proxy composes at its next start. The OAD
`ontola/openapi-directory` document at the full commit SHA that last changed
that file, rather than a later unrelated repository commit.

The unversioned `catalog.json` is a deprecated compatibility bridge; its
`_comment` carries the notice without invalidating JSON. It retains the
prior OAD revisions (including Discord's two-read subset and Clockify's
older revision), with their overlays under canonical revision filenames.
Keep it until the authorized localthought.io deployment is confirmed to use
the dated catalog, then remove it. Old overlay revision files stay published.
The unversioned `catalog.json` was removed after localthought.io switched to
this dated catalog on 2026-10-02 (Heroku release v85, wrapper commit
`1f89c7efb25f6fd0f7394997e69ed738fd1a4aad`, proxy 0.2.4). Its live Discord
document changed from two paths to 153, confirming the catalog switch.
Historical overlay revisions remain published, including Discord's two-read
subset and Clockify's older revision; existing revision URLs stay valid.

Dated catalogs and their selected revision files are immutable once on
`main`; publish a new dated catalog and update the proxy's default or its
Expand Down Expand Up @@ -92,7 +92,7 @@ python3 overlays/scripts/validate_oad_pins.py --directory /path/to/openapi-direc
```

Add `--fetch-missing` to fetch historical pins absent from current upstream
`main` (the compatibility catalog selects two of these).
`main` (historical Discord and Clockify revisions remain published).

The history check accepts old revisions but rejects a pin at a commit that
did not change the OAD. For an audit requiring every overlay to target the
Expand Down Expand Up @@ -155,7 +155,7 @@ Checks:
compose the selected dated catalog with the proxy's runtime loader, reading
overlays from this folder.
- `.github/workflows/overlays-published.yml` (after each Pages build): the
served dated catalogs, the deprecated compatibility catalog, every overlay and Pages-published OAD it lists, and
served dated catalogs, every overlay and Pages-published OAD they list, and
the pets demo's data match the built commit.

## Authenticated principal overlays
Expand Down
145 changes: 0 additions & 145 deletions overlays/catalog.json

This file was deleted.

Loading