← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz
Relationships
#2837 datastore setup extension overwrites the shared config tier with the repo-local copy and drops managedConfig from .swamp.yaml
Opened by hammz · 9/30/2026· Shipped 9/30/2026
Summary
Split from swamp-club#2495 (part e). On a managedConfig repo with an extension-backed datastore (S3/GCS), swamp datastore setup extension can overwrite the team's shared config tier with the instance-local copy, and it turns managedConfig off in .swamp.yaml.
Found by reading the code during the #2483 v5 review. The code path is confirmed on main (fe52cda6), but it has not been reproduced end to end yet.
What happens
- Migration copies the repo-local config tree into the cache.
src/libswamp/datastores/setup.ts(~454-470) migrates<repo>/.swampinto the cache.configis inDEFAULT_DATASTORE_SUBDIRS, so this includes.swamp/config/upstream_extensions.json, the instance-local auto-resolve lockfile that #2483 keeps as a transitional read.copyDirectoryinsrc/domain/datastore/datastore_migration_service.tsoverwrites existing files withDeno.copyFile. - Setup pushes before it hydrates.
pushChanged(~474-497) runs before the hydrate that follows it. On a fresh pod, the cache holds nothing from the remote yet. The push therefore uploads the instance-local files over the remote config tier, includingconfig/upstream_extensions.json. The S3/GCS push is last-writer-wins per file. - The source directories are then deleted (
cleanupSourceDirs, ~709-716). .swamp.yamllosesmanagedConfig.updateRepoConfig(~718-728) replaces the wholedatastoreblock. The extension branch (~567-581) writes only{ type, config, hydrationStrategy?, namespace? }, somanagedConfig: trueis dropped, and the repo silently stops using the config tier. The filesystem branch (~238-244) replaces the block the same way.
Impact
- The team's shared extension lockfile (and any other config-tier file at the same path) can be overwritten by one instance's local copy.
- The repo stops reading config from the tier with no warning.
Expected
- Setup never overwrites remote config-tier files with repo-local copies when the datastore already has a config tier. Either hydrate before migrating and skip or merge conflicting config-tier files, or leave
config/upstream_extensions.jsonout of the migration and let the #2495 legacy-lockfile retirement (part d) merge it. updateRepoConfigkeeps datastore-block keys that setup does not own,managedConfigin particular. It merges instead of replacing.
Tests
updateRepoConfigkeepsmanagedConfigon both the extension and filesystem branches.- Setup against a datastore whose config tier already holds
upstream_extensions.json(a temp-dir fake remote) leaves the remote entries intact.
Related
- swamp-club#2495: parent issue (this is part e)
- swamp-club#2483: transitional in-repo lockfile read
02Bog Flow
Shipped
Click a lifecycle step above to view its details.
03Sludge Pulse
Sign in to post a ripple.