feat(contracts): ingest published API contracts and gate changesets on them #567
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!567
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/contract-ingest"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Phase 2a of the semantic control plane: ForgeGraph can now receive the contract an app declares, store it against the commit it was compiled from, and use it as merge evidence.
Stacked on #564 — base is
feat/contract-package, so this diff is only the Phase 2 work. Merge #564 first.Plan: https://7n04n7hhuesf.postplan.dev — Phase 2, tasks 2.1–2.3 and 2.7.
Tables
contract_snapshotscontract_operationsir.operations, so operations can be listed, filtered and joined without opening the jsonboperation_idis the semantic identity<serviceId>.<group>.<endpoint>. It survives route changes and is also the span name the app already reports, which is what a later observed-traffic join keys on.Route
POST /api/fg/contractsvalidates with the samevalidateContractthe compiler runs, upserts on (app, commit), and replaces the operation rows rather than upserting them — an endpoint can be removed from a contract, and a plain upsert would leave the deleted one behind looking like it still exists.It satisfies the new
api_contractgate only when the changeset's head is still that commit, so evidence from a superseded push cannot keep a moved changeset green.GETreads one back.Warnings are advisory on purpose
contractWarningsreports aserviceIdthat is not the app slug (telemetry would never join), a declared authentication its middleware does not back, and a public anonymous mutation. None of them reject the publish: a contract that validated is a fact about the code, and refusing to record it would only hide the problem.Verification
37 new tests: 8 on the pure projection, 10 on the route (including a genuinely fingerprinted document, a tampered one, and the superseded-commit case), 19 schema-shape. Typecheck clean across db, api and web; oxlint clean of errors.
⚠️ Before merging
packages/db/drizzle/0102_contracts.sql, then0102a_contracts_grants.sql, to the live database. Merging first turns prod deploys red on schema drift while the app stays healthy on the old build.pnpm install—packages/apiandapps/webgain@forgegraph/contractas a workspace dependency.🤖 Generated with Claude Code
9997bcdb63551d078178