fix(product): align DotNS deploy profile - #221
Conversation
✅ Deploy Preview for muzinga ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1419d1be99
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Outcome
Makes the Product DevNet deployment path resolve the same DotNS generation as the current Product Desktop host, and fails before build, signing, or publication when the installed deployer profile drifts.
Issue and context
Refs #158.
Local scope:
docs/backlog/implementation/W13-pilot-release.mdanddocs/backlog/implementation/evidence/W13.md.The W13 debug panel was present in Dotify's local Product build but absent from the bundle loaded by Product Desktop. Reproducing the journey with the current Product Desktop source showed that the host still resolved an older Dotify bundle. The deployment command was pinned to
@polkadot-community-foundation/polkadot-app-deploy@0.16.2, whose transient DevNet DotNS registry and resolver differ from the stable profile used by the current0.16.7deployer and Product host.This matters because clearing local cache cannot fix an identity mismatch upstream: the host and deploy command must address the same registry, resolver, Publisher, IPFS service, and web gateway before a CID or bundle comparison is meaningful.
Architecture and key concepts
The npm package's embedded
assets/environments.jsonis the authoritative deployment profile. Dotify records the expected Product DevNet identity in a small verifier, then inspects the exactpadpackage selected bynpm execrather than trusting a separately maintained version string.The journey harness also requires this preflight statically, so future script edits cannot silently remove it while leaving tests green.
How it works
deploy:product-devnetverifies that deployment authorization is available without printing the mnemonic.npm exec --package ...@0.16.7resolves the actual CLI package.product-deploy-environment-check.mjslocates that executable's package root and compares its version and DevNet fields with the accepted profile.pad devnetpublication command to run.Design decisions and tradeoffs
0.16.7instead of floatinglatest, keeping deployment reproducible while matching the current stable host generation.Security, failure, and operations
No secret, key, or mnemonic is persisted or logged. The verifier reads only public package metadata. Profile drift, a missing
devnetentry, an unexpected package, or an unresolved executable all fail closed before the build/publish stages.The verifier does not prove that a later chain transaction finalized or that a gateway serves the new CID. Those remain post-publication operational checks. Rollback and pilot promotion are still governed by the W13 runbook and require explicit authorization.
Review guide
Suggested order
web/scripts/product-deploy-environment-check.mjs: verify the source-of-truth lookup and exact profile invariants.web/package.json: verify the command order and pinned deployer version.web/scripts/product-devnet-journey-harness.mjs: verify deployment evidence cannot pass when the preflight is omitted.docs/operations/product-devnet-deployment.mdand W13 evidence: verify operator sequencing and the honest boundary between local validation and live Product proof.Verify carefully
npm exec, not a coincidental local install?Validation
npm run verify:product-deploy-environment0.16.7package contains the accepted Product DevNet identity.npm run test:product-deploy-environmentnode --test scripts/product-devnet-journey-harness.test.mjsnpm run test:unitnpm run lintApp.tsxandArtistShell.tsx.npm run fmt:checknode scripts/backlog-sync.mjs --check --offlineProduction readinessandProduct CDM host smoke, with no page errors.Known limitations and follow-ups
go,hold, orno-godecision.Metadata checklist
Refs #158)Dotify sprints)In Progress)