Skip to content

feat(verifier): serve the admin console from the verifier factories - #1501

Merged
tt-cll merged 1 commit into
tt/admin-1from
tt/admin-2
Oct 8, 2026
Merged

tt-cll merged 1 commit into
tt/admin-1from
tt/admin-2

Conversation

@tt-cll

@tt-cll tt-cll commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Summary

Middle of a 3-PR stack splitting #1471 (base: #1500). Wires the admin console into the verifier lifecycle:

  • Both factories (committee and token, so alt-VM verifiers inherit it) serve the console in-process when /etc/ccv-admin/config.toml (CCV_ADMIN_CONFIG_PATH) is present; no config file means disabled. The console shares the verifier's application DB and its [admin_ui] credential, and shuts down with the job.
  • The committee factory passes its first resolved aggregator as the default for attestation freshness checks (aggregator_address in the config file overrides).
  • ccv admin serve and the supervised sibling process are gone (per review); ccv admin check-config remains for pre-flight validation.

Stack: #1500 → this PR → docs.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Aggregator transport settings are lost, pre-flight validation is incomplete, and config access failures can silently disable the console.

3 open findings
What changed in this PR

Wires the admin console into committee and token verifier lifecycles and adds configuration validation through the CLI.

Changes:

  • Starts and stops the in-process console with verifier jobs.
  • Uses the committee verifier’s first aggregator by default.
  • Adds ccv admin check-config.
File Description
cmd/​verifier/​tokenfactory.go Integrates console lifecycle into token verifiers.
cmd/​verifier/​servicefactory.go Integrates console lifecycle and aggregator defaults.
cmd/​verifier/​run_ccv_cli.go Registers admin CLI commands.
cmd/​verifier/​adminconsole.go Implements shared console startup and shutdown.
cli/​admin/​commands.go Adds console configuration validation.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +480 to +482
if len(resolvedAggregators) > 0 {
aggregatorAddress = resolvedAggregators[0].Address
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — DialResultsClient now takes the transport mode, and the wiring passes the selected aggregator's insecure_connection through (startAdminConsole wraps it into admin.Deps.ResultsDialer). A config-file aggregator_address overrides the endpoint, not the transport mode, and the console's default dialer stays TLS.

Comment thread cli/admin/commands.go
Comment on lines +31 to +35
Action: func(c *cli.Context) error {
cfg, err := admin.LoadConfig(c.String("config"))
if err != nil {
return err
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — admin.Command now receives the CLI-loaded verifier secrets, and check-config runs BasicAuthFromSecrets plus ValidateAccessPolicy, so a non-loopback bind without an identity source or a half-supplied [admin_ui] pair fails exactly as startup would. The guide's pre-flight section is updated to match.

Comment on lines +25 to +27
if _, err := os.Stat(path); err != nil { //nolint:gosec // G703: operator-provided config path, not request input.
return nil, nil
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — only fs.ErrNotExist means disabled; any other stat error is returned so an unreadable-but-present config fails the startup visibly.

@makramkd

makramkd commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Wiring LGTM - I think some changes will happen if some of my suggestions are adopted from #1500.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Code coverage report:

Package main tt/admin-2 Diff
github.com/smartcontractkit/chainlink-ccv/aggregator 46.28% 46.28% +0.00%
github.com/smartcontractkit/chainlink-ccv/bootstrap 65.67% 65.67% +0.00%
github.com/smartcontractkit/chainlink-ccv/cli 54.90% 53.78% -1.12%
github.com/smartcontractkit/chainlink-ccv/cmd 45.05% 39.79% -5.26%
github.com/smartcontractkit/chainlink-ccv/common 46.11% 46.09% -0.02%
github.com/smartcontractkit/chainlink-ccv/executor 42.14% 42.14% +0.00%
github.com/smartcontractkit/chainlink-ccv/indexer 34.40% 34.40% +0.00%
github.com/smartcontractkit/chainlink-ccv/integration 61.99% 61.81% -0.18%
github.com/smartcontractkit/chainlink-ccv/internal 0.00% 0.00% +0.00%
github.com/smartcontractkit/chainlink-ccv/migration 78.70% 78.70% +0.00%
github.com/smartcontractkit/chainlink-ccv/pkg 84.62% 84.62% +0.00%
github.com/smartcontractkit/chainlink-ccv/pricer 0.00% 0.00% +0.00%
github.com/smartcontractkit/chainlink-ccv/protocol 66.31% 66.31% +0.00%
github.com/smartcontractkit/chainlink-ccv/tools 34.10% 38.36% +4.26%
github.com/smartcontractkit/chainlink-ccv/verifier 36.41% 40.05% +3.64%
Total 50.80% 45.50% -5.30%

Files added (in tt/admin-2):

  • github.com/smartcontractkit/chainlink-ccv/cli/admin/commands.go
  • github.com/smartcontractkit/chainlink-ccv/cmd/verifier/adminconsole.go
  • github.com/smartcontractkit/chainlink-ccv/integration/storageaccess/aggregator_results_client.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/actionlog.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/attestation.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/auth.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/config.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/detail.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/handlers.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/recoveryops.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/reschedule.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/search.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/server.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/stores.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/views/actions_templ.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/views/detail_templ.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/views/layout_templ.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/views/recovery_templ.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/views/reschedule_templ.go
  • github.com/smartcontractkit/chainlink-ccv/verifier/pkg/admin/views/search_templ.go

@tt-cll
tt-cll added this pull request to the merge queue Oct 8, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue because a pull request earlier in the stack was removed Oct 8, 2026
@tt-cll
tt-cll added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 65b1c81 Oct 8, 2026
57 checks passed
@tt-cll
tt-cll deleted the tt/admin-2 branch October 8, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants