Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: fix connecting to clickhouse from edge servers #2128

Conversation

NathanFlurry
Copy link
Member

@NathanFlurry NathanFlurry commented Mar 6, 2025

Fixes RVT-4647

Copy link

Deploying rivet with  Cloudflare Pages  Cloudflare Pages

Latest commit: 794228f
Status:🚫  Build failed.

View logs

Copy link

@greptile-apps greptile-apps bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR Summary

Implements TLS support for ClickHouse connections from edge servers with a temporary certificate validation bypass.

  • Added tokio-native-tls dependency in packages/common/pools/Cargo.toml for TLS connection handling
  • Modified packages/common/pools/src/db/clickhouse.rs to use custom TLS configuration with danger_accept_invalid_certs (temporary fix for RVT-4649)
  • Potential security concern: Using unwrap() on TLS builder could cause runtime panics
  • Security risk: Accepting invalid certificates needs to be addressed before production deployment

2 file(s) reviewed, 1 comment(s)
Edit PR Review Bot Settings | Greptile

Comment on lines +23 to +24
.build()
.unwrap();
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

logic: Replace unwrap() with proper error handling to prevent potential panics

Suggested change
.build()
.unwrap();
.build()
.map_err(|e| Error::Global(Box::new(e)))?;

Copy link
Member Author

NathanFlurry commented Mar 6, 2025

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more


How to use the Graphite Merge Queue

Add the label merge-queue to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

Copy link

linear bot commented Mar 6, 2025

Copy link

Deploying rivet-hub with  Cloudflare Pages  Cloudflare Pages

Latest commit: 794228f
Status: ✅  Deploy successful!
Preview URL: https://21e7a95e.rivet-hub-7jb.pages.dev
Branch Preview URL: https://03-06-fix-fix-connecting-to.rivet-hub-7jb.pages.dev

View logs

Copy link
Contributor

graphite-app bot commented Mar 6, 2025

Merge activity

  • Mar 6, 4:30 AM EST: A user added this pull request to the Graphite merge queue.
  • Mar 6, 4:31 AM EST: CI is running for this PR on a draft PR: #2130
  • Mar 6, 4:32 AM EST: A user merged this pull request with the Graphite merge queue via draft PR: #2130.

graphite-app bot pushed a commit that referenced this pull request Mar 6, 2025
@graphite-app graphite-app bot closed this Mar 6, 2025
@graphite-app graphite-app bot deleted the 03-06-fix_fix_connecting_to_clickhouse_from_edge_servers branch March 6, 2025 09:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant