Skip to content

fix(ui): mark Shell and Party Registry SSR routes with their UI release marker - #1031

Merged
BleedingDev merged 1 commit into
mainfrom
fix/cloudflare-ui-marker
Sep 30, 2026
Merged

BleedingDev merged 1 commit into
mainfrom
fix/cloudflare-ui-marker

Conversation

@BleedingDev

@BleedingDev BleedingDev commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Why the change

Most requests to the stage Catalog and commerce-customer-context Workers die with Cloudflare error 1102 because they need far more CPU than the 100 ms vertical cap, and this gives those two Workers a cap based on what stage analytics actually measured.

Special things to note

  • Root cause: each BFF request builds and disposes the whole Effect HTTP API runtime (workerd won't let I/O objects cross requests), so CPU grows with endpoint count. Catalog has ~200 endpoints and commerce-customer-context ~115; the next biggest vertical has ~20. wrangler tail shows every 1102 as exceededCpu, killed at 100 ms when warm and at ~2100 ms when cold.
  • Stage analytics, last 72 h: the largest successful requests used 1590 ms (Catalog) and 2015 ms (commerce-customer-context), and requests that got cut off had already used up to 2539 ms. 3000 ms is the smallest round cap above all of those. Every other vertical keeps 100 ms and the Shell keeps 200 ms.
  • The account CPU allowance and the hourly stage cost guard stay the same. The cap only limits one runaway request.

Change outline

CPU budgets

-CLOUDFLARE_WORKER_CPU_MS = { shell: 200, vertical: 100 }
+CLOUDFLARE_WORKER_CPU_MS = { largeApiVertical: 3000, shell: 200, vertical: 100 }

How each Worker picks its budget

 createModernConfig({ ..., cloudflareCpuMs = vertical })
-  createCloudflareDeployment(build, { name, unitServiceBindings })   // always vertical
+  createCloudflareDeployment(build, { cpuMs, name, unitServiceBindings })

 commerce-customer-context/modern.config.ts
+  cloudflareCpuMs: largeApiVertical
 catalog/modern.config.ts
-  createCloudflareWorkerConfig(env, { cpuMs: vertical, ... })
+  createCloudflareWorkerConfig(env, { cpuMs: largeApiVertical, ... })

Generated wrangler.json

 app-catalog                    limits: { cpu_ms: 100 → 3000 }
 app-commerce-customer-context  limits: { cpu_ms: 100 → 3000 }
 every other app-* Worker       limits unchanged

@semanticdiff-com

semanticdiff-com Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 84028af4-db0a-4e42-aa29-a95d45b0e7fc

📥 Commits

Reviewing files that changed from the base of the PR and between 42d9606 and 57c2816.

📒 Files selected for processing (5)
  • app/apps/shell-super-app/shared/ultramodern-build.ts
  • app/apps/shell-super-app/src/routes/layout.tsx
  • app/apps/shell-super-app/tests/unit/layout.test.tsx
  • app/verticals/party-registry/src/routes/layout.tsx
  • app/verticals/party-registry/tests/components/layout.test.tsx

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (14)
  • GitHub Check: Complete Unit and Component Tests
  • GitHub Check: Module Entrypoint Contracts
  • GitHub Check: OntOS API Boundary Rules
  • GitHub Check: Database Access Boundaries
  • GitHub Check: Effect Rule Implementation
  • GitHub Check: Codesmith and Generation Tests
  • GitHub Check: Static Contracts
  • GitHub Check: Repository Tooling Tests
  • GitHub Check: Node Backend Federation Artifact Proof
  • GitHub Check: Database, Migration, RLS, Authorization, and Outbox Integration
  • GitHub Check: Deployment Impact Planner Tests
  • GitHub Check: Typecheck
  • GitHub Check: Cloudflare Workerd Artifact Proof
  • GitHub Check: Quality Audit Guardrails
🧰 Additional context used
📓 Path-based instructions (1)
Source excerpt: Before changing files under `app/`, read [the application coding guide](./README.md).

📄 CodeRabbit inference engine (app/AGENTS.md)

Files:

  • app/verticals/party-registry/src/routes/layout.tsx
  • app/apps/shell-super-app/shared/ultramodern-build.ts
  • app/apps/shell-super-app/tests/unit/layout.test.tsx
  • app/verticals/party-registry/tests/components/layout.test.tsx
  • app/apps/shell-super-app/src/routes/layout.tsx
🔇 Additional comments (5)
app/apps/shell-super-app/shared/ultramodern-build.ts (1)

58-58: LGTM!

app/apps/shell-super-app/src/routes/layout.tsx (1)

3-3: LGTM!

Also applies to: 9-9

app/verticals/party-registry/src/routes/layout.tsx (1)

4-4: LGTM!

Also applies to: 9-9

app/apps/shell-super-app/tests/unit/layout.test.tsx (1)

14-14: LGTM!

Also applies to: 157-162

app/verticals/party-registry/tests/components/layout.test.tsx (1)

1-19: LGTM!


Walkthrough

The shell and Party Registry layouts now expose the UI build marker on their root elements. Tests check that each rendered layout has the expected marker.

Changes

UI build marker

Layer / File(s) Summary
Expose UI build marker on layouts
app/apps/shell-super-app/shared/ultramodern-build.ts, app/apps/shell-super-app/src/routes/layout.tsx, app/verticals/party-registry/src/routes/layout.tsx, app/apps/shell-super-app/tests/unit/layout.test.tsx, app/verticals/party-registry/tests/components/layout.test.tsx
Exports ultramodernUiMarker from the UI surface of ultramodernBuildArtifact. Both layout roots set data-build-marker to its build value. Tests check the marker on each rendered layout. The Party Registry test also checks the rendered route text.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 57c28

Both application roots expose their configured UI build marker, and Party Registry’s marker aligns with its API build. No actionable merge risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 57c28

The layouts publish only each application’s build identifier and preserve their existing route outlets. No security issue was established, but the production source and validation of injected build identifiers remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The direct exposure added by the inspected changes is build metadata in HTML rendered through the two application layouts. These changes do not themselves introduce access to another tenant, data store, credential, or privileged service.

Trust Boundaries and Controls

  • observed — The existing Shell artifact resolver receives callbacks for ambient build-marker and source-revision constants. The checked-in UI build value is a fixed release-like string. The inspected test supplies synthetic injected values; it does not establish who controls production injection or how the resolver validates it. No request-to-marker attack path was established.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 5…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding the UI release marker to Shell and Party Registry SSR routes.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…se marker

The Cloudflare public-URL proof reads data-build-marker from each app's
cloudflare.routes.ssr page. The marker was dropped from the Shell home page
with the login flow and from Party Registry when Contacts merged into it, so
/en (Shell, anonymous) and /en/contacts (Party Registry) rendered none.

Shell: carry it on the root layout wrapper, so every route and auth state
renders it. Party Registry: its pages double as Shell module pages and its
root layout is pinned to the generated scaffold, so carry it on a new
[lang] layout that only the vertical's own Worker renders.
@BleedingDev
BleedingDev force-pushed the fix/cloudflare-ui-marker branch from 57c2816 to 4716c31 Compare September 30, 2026 13:45
@BleedingDev
BleedingDev merged commit 6a10e1a into main Sep 30, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant