Skip to content

RMAT-242: route CMO load-balancer sessions to the default upstream - #2183

Merged
kramduny-cps merged 9 commits into
developmentfrom
RMAT-242-cmo-default-upstream
Sep 18, 2026
Merged

kramduny-cps merged 9 commits into
developmentfrom
RMAT-242-cmo-default-upstream

Conversation

@shellisj-spc

Copy link
Copy Markdown
Collaborator

Problem

DDEI calls to the CMS proxy /internal-implementation/{corsham,farnborough}/CMS (the cms-modern-token / auth-refresh flow) were failing in UAT with:

CmsException: Could not extract CMS version ID from home route redirect response -> InvalidOperationException: Sequence contains no matching element

i.e. the upstream returned no Location header (no redirect).

Root cause

Commit 83bacc65 (RMAT-242, "Fix for proxy on Prod") changed cmsenv.js env detection from cookie.includes("mod") to cookie.includes("-cmo-lb"). Real UAT sessions carry a C-CMO-LBsessioncookie, so detection now returns env cmo - but there is no cmo upstream configured (nginx.conf js_vars and app settings define only default/cpt/cin2/cin4/cin5). proxyDestinationCorshamInternal therefore builds https://undefined, the proxy_pass fails, and no /CMS.<version> redirect is returned.

Before RMAT-242, C-CMO-LBsessioncookie contained no mod substring and fell through to default - and in UAT the default upstream is cmo.cps.gov.uk, so it worked.

Fix

Route CMO sessions to the default env. CMO has no dedicated upstream, and in UAT the default upstream is cmo.cps.gov.uk, so this restores the pre-RMAT-242 behaviour. Prod/dev/qa are unaffected (their defaults are cms/cin3, and CMO cookies do not legitimately occur there).

Scope / notes

  • One-line change in the live cmsenv.js (FORCE_REFRESH_CONFIG md5 will pick it up on apply).
  • The parallel "next" proxy config (proxy/config/.../cms-detection.js) still detects cmo from the mod token and carries the same latent "cmo has no upstream" quirk (documented in its QUIRKS.md). It is not deployed, so it is left as a follow-up rather than widening this PR.

dbarber-cps and others added 4 commits September 8, 2026 13:51
C-CMO-LBsessioncookie was detected as env 'cmo', which has no configured upstream, so the DDEI /CMS call proxied to an undefined host and returned no redirect (CmsException 'Could not extract CMS version ID'). In UAT the default upstream is cmo.cps.gov.uk, so route CMO sessions to the default env - restoring the pre-RMAT-242 behaviour.
kramduny-cps
kramduny-cps previously approved these changes Sep 16, 2026
cms-detection.js (the un-deployed 'next' config's cms-env primitive) had the same latent bug as the live cmsenv.js: cmo has no configured upstream, so mapping mod/cmo cookies to env 'cmo' would proxy to an undefined host. Route them to 'default' instead, matching the live fix. Updates the characterisation test and a stale comment in cms-proxy.js accordingly.
Both containers are local integration-test fixtures (not deployed), and already documented why they deliberately run as root: Dockerfile.nginx needs the master process bound to root to listen on port 80 and drop worker privileges per nginx.conf's own 'user nginx;' directive; Dockerfile.mock listens on the privileged port 443 to answer the hardcoded App Insights hostname. Added #checkov:skip=CKV_DOCKER_3 annotations with those reasons, matching the skip convention already used elsewhere in this repo's Terraform files, rather than adding a USER directive that would break either container.
@kramduny-cps
kramduny-cps changed the base branch from main to development September 17, 2026 10:15
@sonarqubecloud

sonarqubecloud Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

auto-merge was automatically disabled September 17, 2026 10:40

Merge commits are not allowed on this repository

@kramduny-cps
kramduny-cps merged commit 8971904 into development Sep 18, 2026
10 checks passed
@kramduny-cps
kramduny-cps deleted the RMAT-242-cmo-default-upstream branch September 18, 2026 09:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants