Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz

Relationships

#2837 datastore setup extension overwrites the shared config tier with the repo-local copy and drops managedConfig from .swamp.yaml

Opened by hammz · 9/30/2026· Shipped 9/30/2026

Summary

Split from swamp-club#2495 (part e). On a managedConfig repo with an extension-backed datastore (S3/GCS), swamp datastore setup extension can overwrite the team's shared config tier with the instance-local copy, and it turns managedConfig off in .swamp.yaml.

Found by reading the code during the #2483 v5 review. The code path is confirmed on main (fe52cda6), but it has not been reproduced end to end yet.

What happens

  1. Migration copies the repo-local config tree into the cache. src/libswamp/datastores/setup.ts (~454-470) migrates <repo>/.swamp into the cache. config is in DEFAULT_DATASTORE_SUBDIRS, so this includes .swamp/config/upstream_extensions.json, the instance-local auto-resolve lockfile that #2483 keeps as a transitional read. copyDirectory in src/domain/datastore/datastore_migration_service.ts overwrites existing files with Deno.copyFile.
  2. Setup pushes before it hydrates. pushChanged (~474-497) runs before the hydrate that follows it. On a fresh pod, the cache holds nothing from the remote yet. The push therefore uploads the instance-local files over the remote config tier, including config/upstream_extensions.json. The S3/GCS push is last-writer-wins per file.
  3. The source directories are then deleted (cleanupSourceDirs, ~709-716).
  4. .swamp.yaml loses managedConfig. updateRepoConfig (~718-728) replaces the whole datastore block. The extension branch (~567-581) writes only { type, config, hydrationStrategy?, namespace? }, so managedConfig: true is dropped, and the repo silently stops using the config tier. The filesystem branch (~238-244) replaces the block the same way.

Impact

  • The team's shared extension lockfile (and any other config-tier file at the same path) can be overwritten by one instance's local copy.
  • The repo stops reading config from the tier with no warning.

Expected

  • Setup never overwrites remote config-tier files with repo-local copies when the datastore already has a config tier. Either hydrate before migrating and skip or merge conflicting config-tier files, or leave config/upstream_extensions.json out of the migration and let the #2495 legacy-lockfile retirement (part d) merge it.
  • updateRepoConfig keeps datastore-block keys that setup does not own, managedConfig in particular. It merges instead of replacing.

Tests

  • updateRepoConfig keeps managedConfig on both the extension and filesystem branches.
  • Setup against a datastore whose config tier already holds upstream_extensions.json (a temp-dir fake remote) leaves the remote entries intact.
  • swamp-club#2495: parent issue (this is part e)
  • swamp-club#2483: transitional in-repo lockfile read
02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 10 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/30/2026, 10:27:39 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
hammz assigned hammz9/30/2026, 8:11:21 PM

Sign in to post a ripple.