Skip to content

sync - #1

Merged
dhanzhelo merged 569 commits into
indevlab:mainfrom
warp-tech:main
Aug 27, 2026
Merged

dhanzhelo merged 569 commits into
indevlab:mainfrom
warp-tech:main

Conversation

@dhanzhelo

Copy link
Copy Markdown
Member

No description provided.

Eugeny and others added 30 commits July 15, 2026 15:51
## Description
Looking through the authorization code, I noticed that there is some
very significant potential for performance improvements. Its main issue
is that authorization work requires 5 DB queries, which needs to be
performed on every request.

This PR makes quite a few core changes that would drastically drop the
amount of work needed for authorization. The main changes are:
- Remove the global config-provider mutex and converted its API to
immutable shared access, as it should be safe to do this without the
mutex. This dominates a lot of the changes in this PR, even though I
expect its impact on performance to be minimal.
- HTTP requests initially fetch the target, only keep its name, do some
work, and then later the target is looked up again by-name. Instead keep
the full target and reuse it later so we don't have to do the second DB
query.
- Create a single role-assignment query to replace the 5 individual
queries needed during authorization
- Add DB indexes for data needed commonly during authorization
- Use ID-based authorization (`authorize_target_by_id`) for targets
where this is possible (HTTP, Kubernetes, web SSH, ticket requests etc)
to avoid an unncessary DB query, while keeping the old name-based
authorization (authorize_target) for SSH, MySQL and PostreSQL,.

This PR is currently very light on testing and benchmarking, as I am
running at the end of my workday and would like to get this PR out. Some
things have not even been tested beyond compile-checking yet. I am
planning to perform some proper testing and benchmarking on this on
Monday, but I would definitely not mind a review before then.

## AI Usage

Choose the level of AI involvement for this PR.

* [ ] Fully vibe coded
* [x] AI-designed, AI-coded, manually checked
* [ ] Human-designed, AI-coded
* [ ] Human-designed, human-coded (includes AI autocompletions and
boilerplate gen)

*<sub>This is not to block AI contributions but rather to speed up PR
review (saves time on trying to deduce the logic behind AI
hallucinations).</sub>*

---------

Co-authored-by: Eugene <inbox@null.page>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
…2211)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
…b in the version-bumps group (#2222)

Signed-off-by: dependabot[bot] <support@github.com>
Adds @LarsSven as a contributor for code.

This was requested by Eugeny [in this
comment](#2220 (comment))

---------

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
…up (#2232)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
…ps group (#2227)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Eugeny and others added 29 commits August 20, 2026 11:49
…handshake (#2462)

Co-authored-by: Eugene <inbox@null.page>
Signed-off-by: dependabot[bot] <support@github.com>
Adds @fergusean as a contributor for code.

This was requested by Eugeny [in this
comment](#2468 (comment))

---------

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
Co-authored-by: Eugene <inbox@null.page>
Co-authored-by: Eugene <x@null.page>
Signed-off-by: dependabot[bot] <support@github.com>
…dates group (#2481)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
@dhanzhelo
dhanzhelo merged commit f9124b9 into indevlab:main Aug 27, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.