Skip to content

Remove Orbit remote management - #6320

Merged
bert-e merged 7 commits into
development/9.5from
improvement/CLDSRV-1013-remove-remote-management
Oct 8, 2026
Merged

bert-e merged 7 commits into
development/9.5from
improvement/CLDSRV-1013-remove-remote-management

Conversation

@francoisferrand

@francoisferrand francoisferrand commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Remote management means cloudserver connecting to Orbit/pensieve-api to fetch its instance credentials, then polling or receiving configuration overlays and applying and saving them in the PENSIEVE metadata bucket. That has been dead for a long time.

Keeping the code around only forces Arsenal to keep exporting pensieve.credentialUtils and patches.locationConstraints.

What goes away:

  • The management init in the server, the management agent (managementAgent.js, managementAgent config, management_agent script) and node-forge.
  • The Orbit credentials, polling and overlay code they relied on (lib/management/{index,credentials,poll,configuration,agentClient}.js).
  • The zenko-instance-id user metadata tagging, since its value only ever came from an overlay.
  • The secure channel tunnel: bin/secure_channel_proxy.js and the channel payload/close handling in the push client. It only tunnelled Orbit browser access to S3, and zenko-operator stops deploying it in ZKOP-617.

The push client used by metrics_server stays (it now only answers metrics requests), as does overlayVersion in /_/report, which zenko-operator renders and pensieve-api reads.

The PR also bumps arsenal to 8.6.0-preview.4, which no longer has the pensieve/patches exports, and cloudserverclient to 1.0.13. The lockfile was refreshed: utapi now shares the same arsenal, aws-sdk is deduplicated, and shell-quote is 1.12.0. A **/request/form-data resolution mirrors utapi's own, to get rid of the critical form-data advisory.

Issue: CLDSRV-1013

@bert-e

bert-e commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Hello francoisferrand,

My role is to assist you with the merge of this
pull request. Please type @bert-e help to get information
on this process, or consult the user documentation.

Available options
name description privileged authored
/after_pull_request Wait for the given pull request id to be merged before continuing with the current one.
/bypass_author_approval Bypass the pull request author's approval ⭐
/bypass_build_status Bypass the build and test status ⭐
/bypass_commit_size Bypass the check on the size of the changeset TBA ⭐
/bypass_incompatible_branch Bypass the check on the source branch prefix ⭐
/bypass_jira_check Bypass the Jira issue check ⭐
/bypass_peer_approval Bypass the pull request peers' approval ⭐
/bypass_leader_approval Bypass the pull request leaders' approval ⭐
/bypass_source_branch_lineage Bypass the cross-branch contamination check ⭐
/approve Instruct Bert-E that the author has approved the pull request. ✍️
/create_pull_requests Allow the creation of integration pull requests.
/create_integration_branches Allow the creation of integration branches.
/no_octopus Prevent Wall-E from doing any octopus merge and use multiple consecutive merge instead
/unanimity Change review acceptance criteria from one reviewer at least to all reviewers
/wait Instruct Bert-E not to run until further notice.
Available commands
name description privileged
/help Print Bert-E's manual in the pull request.
/status Print Bert-E's current status in the pull request.
/clear Remove all comments from Bert-E from the history TBA
/retry Re-start a fresh build TBA
/build Re-start a fresh build TBA
/force_reset Delete integration branches & pull requests, and restart merge process from the beginning.
/reset Try to remove integration branches unless there are commits on them which do not appear on the source branch.

Status report is not available.

@bert-e

bert-e commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Waiting for approval

The following approvals are needed before I can proceed with the merge:

  • the author

  • 2 peers

Comment thread lib/utilities/reportHandler.js
@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 87.72%. Comparing base (17977b1) to head (f4110a3).
⚠️ Report is 21 commits behind head on development/9.5.
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
lib/management/push.js 0.00% 2 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

Files with missing lines Coverage Δ
lib/Config.js 80.83% <ø> (+0.38%) ⬆️
lib/api/apiUtils/object/createAndStoreObject.js 87.34% <ø> (-0.16%) ⬇️
lib/api/initiateMultipartUpload.js 92.00% <ø> (-0.10%) ⬇️
lib/api/objectCopy.js 89.80% <ø> (-0.06%) ⬇️
lib/management/ChannelMessageV0.js 95.00% <ø> (-5.00%) ⬇️
lib/server.js 88.46% <ø> (+0.03%) ⬆️
lib/management/push.js 0.00% <0.00%> (-30.35%) ⬇️

... and 1 file with indirect coverage changes

@@                 Coverage Diff                 @@
##           development/9.5    #6320      +/-   ##
===================================================
+ Coverage            86.55%   87.72%   +1.16%     
===================================================
  Files                  213      206       -7     
  Lines                14612    14196     -416     
===================================================
- Hits                 12647    12453     -194     
+ Misses                1965     1743     -222     
Flag Coverage Δ
checksums-disabled-tests 35.65% <0.00%> (+0.27%) ⬆️
file-ft-tests 71.35% <0.00%> (+1.35%) ⬆️
file-ft-tests-null-compat 71.78% <0.00%> (+1.20%) ⬆️
kmip-ft-tests 28.22% <0.00%> (+0.06%) ⬆️
mongo-v0-ft-tests 72.58% <0.00%> (+1.32%) ⬆️
mongo-v1-ft-tests 72.51% <0.00%> (+1.29%) ⬆️
multiple-backend 36.44% <0.00%> (+0.28%) ⬆️
s3c-ft-tests-v0 66.13% <0.00%> (+1.09%) ⬆️
s3c-ft-tests-v0-null-compat 66.20% <0.00%> (+1.11%) ⬆️
s3c-ft-tests-v1 66.11% <0.00%> (+1.09%) ⬆️
sur-tests 37.01% <0.00%> (-0.58%) ⬇️
sur-tests-inflights 39.89% <0.00%> (+0.37%) ⬆️
unit 75.15% <0.00%> (+0.83%) ⬆️
utapi-v2-tests 35.60% <0.00%> (+0.24%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@francoisferrand
francoisferrand force-pushed the improvement/CLDSRV-1013-remove-remote-management branch from 9cfb3ef to d4a05f9 Compare October 7, 2026 13:40
@francoisferrand
francoisferrand marked this pull request as ready for review October 7, 2026 13:42
@francoisferrand
francoisferrand force-pushed the improvement/CLDSRV-1013-remove-remote-management branch from d4a05f9 to d33c868 Compare October 7, 2026 13:46
@scality scality deleted a comment from bert-e Oct 7, 2026
@francoisferrand
francoisferrand requested review from a team, SylvainSenechal and delthas October 7, 2026 13:46
Comment thread package.json
Comment thread lib/Config.js
@francoisferrand
francoisferrand force-pushed the improvement/CLDSRV-1013-remove-remote-management branch from d33c868 to 4ffd418 Compare October 7, 2026 14:09
Comment thread lib/management/push.js
@francoisferrand
francoisferrand force-pushed the improvement/CLDSRV-1013-remove-remote-management branch 2 times, most recently from 69ad44b to e96c785 Compare October 7, 2026 14:52

@delthas delthas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very nice!

@SylvainSenechal

Copy link
Copy Markdown
Contributor

Sounds like too many test failures to be flaky 🤔

Remote management (cloudserver connecting to Orbit to fetch its
instance credentials, and polling or receiving configuration overlays
that it applied and saved in the PENSIEVE bucket) has been dead for a
long time: zenko-operator sets REMOTE_MANAGEMENT_DISABLE and renders
locationConfig.json itself, Orbit / Zenko 1.x are no longer supported,
and S3C never used it. Keeping it around only forces Arsenal to keep
exporting the pensieve credential utils and patchLocations.

This drops the management init in the server and the management agent,
with the Orbit credentials, polling and overlay code they relied on.
The zenko-instance-id user metadata goes too, as its value only ever
came from an overlay. The push client still used by the metrics server
and secure channel proxy now ignores overlay messages, and keeps
handling metrics requests and channel data as before.

overlayVersion is kept and still reported in /_/report: zenko-operator
renders it in config.json and pensieve-api reads it from the report.

The management config unit test happened to reset config.locationConstraints
between suites, which was masking a leak in objectReplicationMD.js
(it replaced the real awsbackend location and then deleted it). That test
now restores the original entries.

Issue: CLDSRV-1013
arsenal 8.6.0-preview.4 drops the pensieve and patches exports that
cloudserver no longer uses. utapi now shares the same arsenal instead
of carrying its own preview.1 copy.

Issue: CLDSRV-1013
Re-resolve dependencies within their existing ranges.

Issue: CLDSRV-1013
request is only pulled in by utapi (via oas-tools) and still asks for
form-data ~2.3.2, which has a critical advisory. utapi already forces
form-data ^2.5.6 under request, but yarn ignores resolutions from
dependencies, so mirror it here:
https://github.com/scality/utapi/blob/8.4.0/package.json#L61-L64

Issue: CLDSRV-1013
The push client could also tunnel raw S3 traffic from the push server
to cloudserver over the websocket: this is how the Orbit browser
reached S3 inside a deployment, through bin/secure_channel_proxy.js.
Nothing else uses it, and zenko-operator stops deploying the proxy
(ZKOP-617), so drop the script, the channel payload/close handling and
the browserAccessEnabled toggle that was only set from an overlay.

The push client is now only used by the metrics server, and only
answers metrics requests.

Issue: CLDSRV-1013
@francoisferrand
francoisferrand force-pushed the improvement/CLDSRV-1013-remove-remote-management branch from e96c785 to 1f97035 Compare October 7, 2026 21:33
Comment thread package.json Outdated
arsenal 8.6.0-preview.4 broke the file metadata backend: batch
operations without a type are rejected since the classic-level
migration, so the S3 server fails to start.

scubaclient 1.2.1 moves to axios 1.20, which fixes quite a few
more CVEs.

Issue: CLDSRV-1013
Issue: CDSRV-1013
@francoisferrand
francoisferrand force-pushed the improvement/CLDSRV-1013-remove-remote-management branch from 1f97035 to f4110a3 Compare October 8, 2026 09:55
@francoisferrand

Copy link
Copy Markdown
Contributor Author

/approve

@bert-e

bert-e commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

I have successfully merged the changeset of this pull request
into targetted development branches:

  • ✔️ development/9.5

The following branches have NOT changed:

  • development/7.10
  • development/7.4
  • development/7.70
  • development/8.8
  • development/9.0
  • development/9.1
  • development/9.2
  • development/9.3
  • development/9.4

This pull request did not target the following hotfix branch(es) so they
were left untouched:

  • hotfix/7.10.8
  • hotfix/7.6.0
  • hotfix/7.4.9
  • hotfix/7.70.11
  • hotfix/9.0.7
  • hotfix/7.10.49
  • hotfix/6.4.7
  • hotfix/7.10.2
  • hotfix/7.10.1
  • hotfix/7.10.30
  • hotfix/7.4.5
  • hotfix/7.4.8
  • hotfix/9.0.32
  • hotfix/7.10.4
  • hotfix/7.4.2
  • hotfix/7.4.4
  • hotfix/7.4.10
  • hotfix/7.70.51
  • hotfix/7.70.73
  • hotfix/7.4.7
  • hotfix/7.4.0
  • hotfix/7.4.1
  • hotfix/7.4.6
  • hotfix/7.70.45
  • hotfix/7.9.0
  • hotfix/7.2.0
  • hotfix/7.10.3
  • hotfix/8.8.45
  • hotfix/7.8.0
  • hotfix/7.10.28
  • hotfix/7.10.15
  • hotfix/7.7.0
  • hotfix/7.70.21
  • hotfix/9.3.13
  • hotfix/7.10.27
  • hotfix/9.2.36
  • hotfix/7.4.3
  • hotfix/9.2.24
  • hotfix/7.10.0

Please check the status of the associated issue CLDSRV-1013.

Goodbye francoisferrand.

The following options are set: approve

@bert-e
bert-e merged commit f4110a3 into development/9.5 Oct 8, 2026
36 of 37 checks passed
@bert-e
bert-e deleted the improvement/CLDSRV-1013-remove-remote-management branch October 8, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants