v0.6.8 fixes - #1349
Conversation
There was a problem hiding this comment.
Claude Code Review
Claude Code Review is paused for this repository. To reconnect it, an admin of this repository's GitHub organization (or the account owner, for personal repositories) who can also manage your Claude organization's Code Review settings needs to re-link GitHub in Code Review settings. This is a one-time step.
Tip: disable this comment in your organization's Code Review settings.
There was a problem hiding this comment.
Pull request overview
This PR updates the GCP example/external-ALB composition by extracting the commented “networking” template into clearer dedicated files, and refreshes related documentation and the psoxy-test tool lockfile.
Changes:
- Replaces the monolithic
infra/examples-dev/gcp/networking.tftemplate with dedicatedexternal-api-alb.tf(ingress) andvpc.tf(egress) composition files. - Updates GCP module/example variable help text and checks to point at the new ALB composition file.
- Expands ALB troubleshooting guidance in docs and bumps transitive Node dependencies in
tools/psoxy-test/package-lock.json.
Reviewed changes
Copilot reviewed 10 out of 11 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
| tools/psoxy-test/package-lock.json | Bumps several transitive dependencies for the psoxy-test tool. |
| infra/modules/gcp-host/variables.tf | Updates api_connector_external_lb_host docs to reference the new example composition file. |
| infra/modules/gcp-host/main.tf | Updates check error message to reference external-api-alb.tf. |
| infra/examples-dev/gcp/vpc.tf | Adds a dedicated (commented) VPC egress composition template. |
| infra/examples-dev/gcp/variables.tf | Tightens environment_name validation and updates ALB-related variable descriptions. |
| infra/examples-dev/gcp/networking.tf | Removes the previous combined networking composition template. |
| infra/examples-dev/gcp/main.tf | Adds hashicorp/tls provider requirement to support self-signed ALB PoC mode. |
| infra/examples-dev/gcp/external-api-alb.tf | Adds a dedicated external ALB + Cloud Armor composition (managed TLS or self-signed PoC), plus outputs for testing. |
| docs/guides/psoxy-test-tool.md | Adds a troubleshooting table for common ALB testing errors. |
| docs/development/gcp-private-service-connect.md | Updates references from networking.tf to external-api-alb.tf. |
| docs/development/gcp-external-alb.md | Updates “current approach” references and adds troubleshooting section for TLS/403 behaviors. |
| docs/configuration/ip-allowlisting.md | Updates references to the new ALB composition file and adds guidance about Cloud Armor 403s. |
Files not reviewed (1)
- tools/psoxy-test/package-lock.json: Generated file
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Apache Commons Net SubnetUtils is IPv4-only, so valid IPv6-CIDR entries like /128 were rejected at startup. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Remove the misleading top-level api_connector_external_lb_host variable; document the commented main.tf binding instead. Clarify troubleshooting placeholders to use cloud-function-name and environment_id_prefix. Co-authored-by: Cursor <cursoragent@cursor.com>
* update release refs to rc-v0.6.8 * Review logging message (#1343) * Anthropic rules update (#1344) * Claude update * Fix file format * Recovering missing fields * LocalDate as date * document GCP APIs and DWD scope strings for Google Workspace connectors (#1345) * Document GCP APIs and DWD scope strings for Google Workspace connectors. Customers need explicit lists of APIs to enable and comma-separated OAuth scope URLs for Domain-wide Delegation grants, including a superset for shared service accounts. Co-authored-by: Cursor <cursoragent@cursor.com> * Merge DWD scope CSV into Required OAuth Scopes on connector pages. Avoid a separate Domain-wide Delegation section; keep the paste-ready scope string under the existing OAuth scopes heading. Co-authored-by: Cursor <cursoragent@cursor.com> * Revert docs/README.md Google Workspace table to short scope list. Keep detailed API and DWD scope documentation on the Google Workspace connector pages only. Co-authored-by: Cursor <cursoragent@cursor.com> * Classify Google setup errors and slim troubleshooting docs. Return specific X-Psoxy-Error codes and sanitized bodies for API-not-enabled and OAuth setup failures; document error-to-cause mapping as a skimmable list with dummy log examples. Co-authored-by: Cursor <cursoragent@cursor.com> * Rename SOURCE_DWD_NOT_GRANTED and inject GoogleApiSetupErrorInterpreter. Use SOURCE_AUTHORIZATION_NOT_GRANTED for cross-source admin-consent failures; wire ObjectMapper via Dagger constructor injection. Co-authored-by: Cursor <cursoragent@cursor.com> * Document raw Google error signals for older proxy versions. Show parsed log/response fragments that match GoogleApiSetupErrorInterpreter, with legacy X-Psoxy-Error fallbacks. Co-authored-by: Cursor <cursoragent@cursor.com> * Note that OAuth scope mismatch can surface as 401 Unauthorized. Document indistinguishable 401 for missing DWD vs wrong scopes; broaden SOURCE_AUTHORIZATION_NOT_GRANTED message accordingly. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix OAuth scope hint to reference OAUTH_SCOPES env var. Deployed proxies read scopes from the environment via EnvVarsConfigService, not config.yaml. Co-authored-by: Cursor <cursoragent@cursor.com> * Log OAuth token exchange failures at ERROR severity. 401 and other oauth2.googleapis.com/token failures now use SEVERE so they appear as errors in Cloud Logging. Co-authored-by: Cursor <cursoragent@cursor.com> * Always log connection-setup IOExceptions at SEVERE. Drop Google-specific oauth2.googleapis.com/token check from ApiDataRequestHandler; scope hint only when setup error interpreter matches. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove GoogleApiSetupErrorInterpreter; keep docs-only troubleshooting. Roll back Google-specific error classification code and rewrite troubleshooting around log signals mapped to setup conditions. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> * Zoom rules update (#1346) * Updated test * Updated rules * misc fixes for v0.6.8 (#1342) * Fix String.format placeholders in config cache retry log. MessageFormat-style {0} placeholders were passed to String.format, so retry attempt details were never interpolated. Co-authored-by: Cursor <cursoragent@cursor.com> * Bump minor Java and Node dependency versions. Routine maintenance: update Maven property versions and AWS/GCP-adjacent libraries, and confirm npm audit fix reports no vulnerabilities in tool packages. Co-authored-by: Cursor <cursoragent@cursor.com> * Upgrade Jackson to 2.22.0 via jackson-bom. Jackson 2.22 uses patch-less versioning for jackson-annotations; importing the BOM aligns module versions consistently with the main Worklytics codebase. Co-authored-by: Cursor <cursoragent@cursor.com> * Update Jackson BOM to latest --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Jose Lorenzo <jose@worklytics.co> * update release refs to v0.6.8 (#1348) * GCP support for application load balancer in front of API connector deployments (#1347) * Add beta GCP external ALB composition support via api_connector_external_lb_host. Wire ingress and public endpoint URLs from a customer-owned ALB host signal, document the pattern, and teach psoxy-test to call ALB URLs with self-signed TLS. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review: fix ALB IP CLI flags and cacert Promise errors. Extract LB host without regex capture groups, reject invalid --cacert paths asynchronously, and remove Terraform interpolation from the external_lb_base_url description so validate succeeds. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review: HTTPS enforcement and simpler IP/path handling. - Detect ALB IP hosts with cidrhost instead of regex - Require https:// for proxy endpoints (Terraform check + psoxy-test) - Simplify request path to pathname + search; warn on --allow-insecure-tls Co-authored-by: Cursor <cursoragent@cursor.com> * Fix CI: assert HTTPS on known external_lb_base_url only. Checking proxy_endpoint_url fails terraform test because the Cloud Function URI is unknown until apply. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix HTTPS check for Terraform <1.12 null short-circuit. Older Terraform evaluates both sides of ||, so startswith(null) failed module tests. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> * v0.6.8 fixes (#1349) * bump package-lock * improve docs * improve those docs * refactor ALB stuff * comment out external api alb in example * fix IPv6-CIDR parsing in IP allowlists Apache Commons Net SubnetUtils is IPv4-only, so valid IPv6-CIDR entries like /128 were rejected at startup. Co-authored-by: Cursor <cursoragent@cursor.com> * TODO to hide function url in prod; not possible via tf atm * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Address PR review comments on ALB example wiring Remove the misleading top-level api_connector_external_lb_host variable; document the commented main.tf binding instead. Clarify troubleshooting placeholders to use cloud-function-name and environment_id_prefix. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Keep example-repo scripts LF on publish for WSL shebang compatibility. (#1351) Co-authored-by: Cursor <cursoragent@cursor.com> * fix missing String::format --------- Co-authored-by: aperez-worklytics <75276364+aperez-worklytics@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Jose Lorenzo <jose@worklytics.co> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Fixes
package-lock.jsonbump.Change implications
package-lock.jsonwas bumped (likely transitive or tooling dependency updates; verify whether runtime behavior changed).CHANGELOG.mdanything that will show up interraform plan/applythat isn't obviously a no-op? Possibly — ALB refactor may rename or restructure Terraform resources; confirm whether plans show replacements or in-place updates.alpha, requires major version change — Review needed — ALB refactors can affect module interfaces or resource addressing; confirm whether consumers need migration steps.