Repository navigation
refactor!: rename to cryptos-node and own the node API protos - #342
Merged
Merged
Conversation
Bugs5382
marked this pull request as ready for review
October 1, 2026 20:29
Bugs5382
force-pushed
the
refactor/341-cryptos-node
branch
from
October 1, 2026 20:35
63f55a7 to
68460de
Compare
The repository is now CryptOS-PKI/cryptos-node and the module path is github.com/CryptOS-PKI/cryptos-node. The node API protos move in from the api repo to proto/cryptos/node/v1, with the proto package renamed from cryptos.v1 to cryptos.node.v1 and the Go stubs generated under gen/go/cryptos/node/v1 (package nodev1) by the pinned plugins (task tools, task generate). The messages, fields and RPCs are unchanged; only the package, and with it the gRPC method paths (/cryptos.node.v1.NodeService/<Method>), change. task ci now lints the protos and fails when gen/ is stale, and CI installs a checksum-pinned buf. The api repo's contract tests move to internal/apiconformance next to a new round-trip test that dials the mTLS server with the generated client and checks every NodeService RPC reaches its handler. BREAKING CHANGE: the Go module path, the stub import path and the proto package all change. Clients must call /cryptos.node.v1.NodeService/... Signed-off-by: Bugs5382 <Bugs5382@users.noreply.github.com>
Contributor
Author
|
Closing summary: the repo is renamed to cryptos-node and the module path follows. The node API protos now live in proto/cryptos/node/v1 (package cryptos.node.v1), with Go stubs generated under gen/go/cryptos/node/v1, and api is no longer a dependency. task ci lints the protos and checks gen/ is current. The api contract tests moved to internal/apiconformance, alongside a round-trip test that covers all 39 NodeService RPCs over mTLS. All CI checks are green, the image suite included. buf breaking is re-baselined at this merge. |
This was referenced Oct 1, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
The repository is now
CryptOS-PKI/cryptos-node(renamed on GitHub; the old URLs redirect). This PR moves everything to the new name and makes the node own the API it serves.github.com/CryptOS-PKI/cryptosbecomesgithub.com/CryptOS-PKI/cryptos-node, ingo.mod, every import, the build scripts'-ldflags -Xpaths and the image coverage scripts.apitoproto/cryptos/node/v1(audit, ceremony, config, identity, node, scep, status, tsa). The package becomescryptos.node.v1; the Go stubs are generated undergen/go/cryptos/node/v1(packagenodev1) with the plugin versionsapipinned. The fleet protos stay inapiuntil the manager takes them. The messages, fields and RPCs are unchanged, so only the package name and the gRPC method paths (/cryptos.node.v1.NodeService/<Method>) change.apiis no longer required:go mod tidydrops it.task tools,task generate,task generate:verify,task proto:lintandtask proto:breaking.task cinow lints the protos and fails whengen/is stale, andci-goinstalls a checksum-pinned buf.internal/apiconformanceholds the contract tests moved fromapiand a new round-trip test. It starts the mTLS server with throwaway certs and every dependency faked, dials it with the generated client, and checks that each RPC the service descriptor declares reaches a handler.SignCSR(debug-only) andListTsaCertificates(not served yet) are allowed their own Unimplemented answer, but not the framework's unknown-method one.Breaking: the module path, the stub import path and the proto package change. Nothing is tagged yet.
buf breakingis re-baselined at this PR, becausemainhas no protos until it merges, sotask proto:breaking(againstmain) starts gating from the next proto change.Interim note: the manager still imports
github.com/CryptOS-PKI/apiand calls/cryptos.v1.NodeService/.... A manager built from its currentmaincan't talk to a node built from this commit until the manager moves to these stubs in its own restructure PR.Refs #341
Verification
How this was verified
task cipasses locally (fmt, buf lint and format, generated-code check, golangci-lint, vet, the full test suite, build).api'sproto/cryptos/v1byte for byte once the package name, import paths andgo_packageare normalised.grep -rnE 'CryptOS-PKI/(api|cryptos)([^-]|$)'has no hits outside the CHANGELOG.