Skip to content

refactor!: rename to cryptos-node and own the node API protos - #342

Merged
Bugs5382 merged 1 commit into
mainfrom
refactor/341-cryptos-node
Oct 1, 2026
Merged

Bugs5382 merged 1 commit into
mainfrom
refactor/341-cryptos-node

Conversation

@Bugs5382

@Bugs5382 Bugs5382 commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What and why

The repository is now CryptOS-PKI/cryptos-node (renamed on GitHub; the old URLs redirect). This PR moves everything to the new name and makes the node own the API it serves.

  • Module path: github.com/CryptOS-PKI/cryptos becomes github.com/CryptOS-PKI/cryptos-node, in go.mod, every import, the build scripts' -ldflags -X paths and the image coverage scripts.
  • Node API protos move in from api to proto/cryptos/node/v1 (audit, ceremony, config, identity, node, scep, status, tsa). The package becomes cryptos.node.v1; the Go stubs are generated under gen/go/cryptos/node/v1 (package nodev1) with the plugin versions api pinned. The fleet protos stay in api until the manager takes them. The messages, fields and RPCs are unchanged, so only the package name and the gRPC method paths (/cryptos.node.v1.NodeService/<Method>) change.
  • api is no longer required: go mod tidy drops it.
  • Tooling: task tools, task generate, task generate:verify, task proto:lint and task proto:breaking. task ci now lints the protos and fails when gen/ is stale, and ci-go installs a checksum-pinned buf.
  • Tests: internal/apiconformance holds the contract tests moved from api and a new round-trip test. It starts the mTLS server with throwaway certs and every dependency faked, dials it with the generated client, and checks that each RPC the service descriptor declares reaches a handler. SignCSR (debug-only) and ListTsaCertificates (not served yet) are allowed their own Unimplemented answer, but not the framework's unknown-method one.
  • Docs: README (name, layout, a Node API section, build requirements, CI), AGENTS/CLAUDE titles and the release links.

Breaking: the module path, the stub import path and the proto package change. Nothing is tagged yet. buf breaking is re-baselined at this PR, because main has no protos until it merges, so task proto:breaking (against main) starts gating from the next proto change.

Interim note: the manager still imports github.com/CryptOS-PKI/api and calls /cryptos.v1.NodeService/.... A manager built from its current main can't talk to a node built from this commit until the manager moves to these stubs in its own restructure PR.

Refs #341

Verification

  • Lint clean
  • Tests pass
  • Build succeeds
  • Documentation updated (if behavior or API changed)

How this was verified

  • task ci passes locally (fmt, buf lint and format, generated-code check, golangci-lint, vet, the full test suite, build).
  • The round-trip test fails before the move (the stub package doesn't exist) and passes after it. All 39 NodeService RPCs reach their handlers.
  • The moved protos match api's proto/cryptos/v1 byte for byte once the package name, import paths and go_package are normalised.
  • grep -rnE 'CryptOS-PKI/(api|cryptos)([^-]|$)' has no hits outside the CHANGELOG.

@Bugs5382 Bugs5382 added this to the v0.1.0 milestone Oct 1, 2026
@Bugs5382 Bugs5382 self-assigned this Oct 1, 2026
@Bugs5382
Bugs5382 marked this pull request as ready for review October 1, 2026 20:29
@github-actions github-actions Bot added the breaking Breaking change. Major version bump. label Oct 1, 2026
@Bugs5382
Bugs5382 force-pushed the refactor/341-cryptos-node branch from 63f55a7 to 68460de Compare October 1, 2026 20:35
The repository is now CryptOS-PKI/cryptos-node and the module path is
github.com/CryptOS-PKI/cryptos-node.

The node API protos move in from the api repo to proto/cryptos/node/v1,
with the proto package renamed from cryptos.v1 to cryptos.node.v1 and the
Go stubs generated under gen/go/cryptos/node/v1 (package nodev1) by the
pinned plugins (task tools, task generate). The messages, fields and RPCs
are unchanged; only the package, and with it the gRPC method paths
(/cryptos.node.v1.NodeService/<Method>), change.

task ci now lints the protos and fails when gen/ is stale, and CI installs
a checksum-pinned buf. The api repo's contract tests move to
internal/apiconformance next to a new round-trip test that dials the
mTLS server with the generated client and checks every NodeService RPC
reaches its handler.

BREAKING CHANGE: the Go module path, the stub import path and the proto
package all change. Clients must call /cryptos.node.v1.NodeService/...

Signed-off-by: Bugs5382 <Bugs5382@users.noreply.github.com>
@Bugs5382

Bugs5382 commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Closing summary: the repo is renamed to cryptos-node and the module path follows. The node API protos now live in proto/cryptos/node/v1 (package cryptos.node.v1), with Go stubs generated under gen/go/cryptos/node/v1, and api is no longer a dependency. task ci lints the protos and checks gen/ is current. The api contract tests moved to internal/apiconformance, alongside a round-trip test that covers all 39 NodeService RPCs over mTLS. All CI checks are green, the image suite included. buf breaking is re-baselined at this merge.

@Bugs5382
Bugs5382 merged commit 8d8b52d into main Oct 1, 2026
16 checks passed
@Bugs5382
Bugs5382 deleted the refactor/341-cryptos-node branch October 1, 2026 20:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking Breaking change. Major version bump.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant