Skip to content

refactor(auth): nest internal packages under pkg/auth - #3338

Merged
tvi merged 3 commits into
mainfrom
refactor/auth-internals-under-pkg-auth
Jul 22, 2026
Merged

tvi merged 3 commits into
mainfrom
refactor/auth-internals-under-pkg-auth

Conversation

@ben-fornefeld

@ben-fornefeld ben-fornefeld commented Jul 22, 2026 •

Copy link
Copy Markdown
Member

Summary

Stacked on #3339 (facade re-exports — the belt unblocker); this PR is the layout change only. Retarget to main after #3339 merges.

Moves packages/auth/internal/* → packages/auth/pkg/auth/internal/* (history-preserving renames; import paths and otel tracer names updated). Consumers keep using the stable facade at github.com/e2b-dev/infra/packages/auth/pkg/auth — nothing outside the auth module changes except two Dockerfile lines.

Also removes the COPY ./auth/internal ./auth/internal lines from the api and dashboard-api Dockerfiles that #3323 added: with the implementation nested under pkg/auth, the existing COPY ./auth/pkg carries it, and the stale COPY would fail on a now-missing path.

Motivation

#3314 placed implementation packages at packages/auth/internal, outside pkg/. The api/dashboard-api image builds copy the auth module selectively (COPY ./auth/pkg), so post-merge image builds broke and #3323 hot-fixed them with an extra COPY. This class of breakage is only detectable post-merge (PR CI builds from a full checkout; Dockerfiles build only in build-and-upload-images.yml), so every current and future pkg-only copier must remember the extra line. Nesting internals under pkg/auth makes any pkg-only copy self-contained and deletes the failure mode structurally.

It also tightens Go's internal boundary: only the pkg/auth facade can reach the implementation now (previously any package under packages/auth/, e.g. pkg/types/pkg/tests, could).

Testing

  • go build ./… && go vet ./… && go test ./… in packages/auth; golangci-lint run ./packages/auth/… — 0 issues
  • go build ./packages/api/… ./packages/dashboard-api/…
  • Replicated both Docker build contexts (only COPY'd paths, no go.work, CGO_ENABLED=0 GOOS=linux): api and dashboard-api build OK — the exact scenario that broke after feat: add workspace admin API foundations #3314
  • Simulated an external module consumer (GOWORK=off, path replaces): facade import builds; direct import of pkg/auth/internal/… is rejected by the compiler as intended

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@cla-bot cla-bot Bot added the cla-signed label Jul 22, 2026
@cursor

cursor Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Mechanical package relocation and Dockerfile COPY cleanup with no auth behavior changes; external consumers still use the stable facade.

Overview
Auth implementation code moves from packages/auth/internal into packages/auth/pkg/auth/internal, with import paths and OpenTelemetry tracer names updated to match. The public pkg/auth facade keeps the same API for api and dashboard-api; only auth module internals and Docker image builds change.

Image builds for api and dashboard-api drop the extra COPY ./auth/internal step because COPY ./auth/pkg now includes the nested implementation, fixing the post-merge Docker break when auth lived outside pkg.

Reviewed by Cursor Bugbot for commit d7660f3. Bugbot is set up for automated code reviews on this repo. Configure here.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is a mechanical package move (history-preserving) plus thin facade re-exports; no auth logic changed.

Extended reasoning...

Overview

The PR moves packages/auth/internal/* to packages/auth/pkg/auth/internal/* (renames only, import paths and otel tracer names updated to match), adds facade re-exports in pkg/auth/token.go for IdentityLookup, OIDCVerifier, ErrIdentityNotFound, and NewOIDCVerifier (all thin type aliases / one-line wrapper calls into the existing oidc package), and drops the now-redundant COPY ./auth/internal line from the api and dashboard-api Dockerfiles.

Security risks

None. No authentication or authorization logic changes — the OIDC verifier, JWT validation, team/ban/block checks, and caching behavior are untouched; only their package location and how they're re-exported changed. I confirmed no stale references to the old packages/auth/internal import path remain anywhere in the repo.

Level of scrutiny

Low. This is a textbook mechanical refactor: git mv-style renames plus facade re-exports that are all type aliases or single-line delegating functions. The Dockerfile change is a straightforward removal of a workaround line that's no longer needed now that internals live under pkg/.

Other factors

The PR description documents thorough testing (build/vet/test in the auth module, Docker build replication for both affected services, and simulation of an external consumer importing the facade). No outstanding review comments to address — the only timeline activity is automated summaries from Gemini/Cursor bots, no unresolved feedback.

@ben-fornefeld
ben-fornefeld force-pushed the refactor/auth-internals-under-pkg-auth branch from 3ebeb25 to be22879 Compare July 22, 2026 18:12
…facade

External consumers (belt) previously imported pkg/auth/oidc directly
(oidc.NewVerifier, oidc.IdentityLookup, oidc.ErrIdentityNotFound) and used
auth.Verifier/auth.NewVerifier from the old facade. Both surfaces were
removed in #3314, which breaks belt's daily infra sync at go mod tidy
(module found, but does not contain package .../pkg/auth/oidc) and at
compile time in argus-api.

Expose the equivalents on the auth facade so all consumers use auth.*:

- IdentityLookup, ErrIdentityNotFound
- OIDCVerifier, NewOIDCVerifier (single issuer)
- ProviderVerifier, NewProviderVerifier (multi-issuer, keeps the
  (nil, nil) no-provider semantics of the old auth.NewVerifier)

Config/issuer types were already re-exported as JWTConfig/JWTIssuer.
Move packages/auth/internal/* to packages/auth/pkg/auth/internal/* so the
implementation lives inside the consumer-facing pkg tree. Consumers keep
importing the stable facade at .../packages/auth/pkg/auth.

Go's internal visibility now scopes the implementation to pkg/auth alone
(pkg/types and pkg/tests can no longer reach it), and image builds that
COPY ./auth/pkg pick up the implementation for free — drop the separate
./auth/internal COPY that #3323 added to unbreak image builds after #3314.
@ben-fornefeld
ben-fornefeld force-pushed the refactor/auth-internals-under-pkg-auth branch from be22879 to 57128f5 Compare July 22, 2026 18:30
@ben-fornefeld ben-fornefeld changed the title refactor(auth): nest internals under pkg/auth and re-export OIDC verifier via facade refactor(auth): nest internal packages under pkg/auth Jul 22, 2026
@ben-fornefeld
ben-fornefeld changed the base branch from main to feat/auth-oidc-provider-facade July 22, 2026 18:30
ben-fornefeld added a commit that referenced this pull request Jul 22, 2026
…facade (#3339)

## Summary

Restores the auth surface external consumers lost in #3314, without
touching the package layout.

Belt imports this module and used `pkg/auth/oidc` (`oidc.NewVerifier`,
`oidc.IdentityLookup`, `oidc.ErrIdentityNotFound`) plus the old facade's
`auth.Verifier`/`auth.NewVerifier`. #3314 moved both behind Go
`internal` packages, so belt's daily `sync-infra-repo` workflow fails at
`go mod tidy`:

> module …/packages/auth found, but does not contain package
…/packages/auth/pkg/auth/oidc

This PR re-exports the equivalents through the `auth.*` facade with
identical signatures:

- `auth.IdentityLookup`, `auth.ErrIdentityNotFound`
- `auth.OIDCVerifier` / `auth.NewOIDCVerifier` (single issuer)
- `auth.ProviderVerifier` / `auth.NewProviderVerifier` (multi-issuer;
keeps the `(nil, nil)` no-provider semantics of the old
`auth.NewVerifier`)

Config/issuer types were already exposed as
`auth.JWTConfig`/`auth.JWTIssuer`.

Companion belt PR migrating its imports to the facade:
e2b-dev/belt#1145. A follow-up PR (#3338) restructures the auth package
layout separately.

## Testing

- `go build ./… && go vet ./… && go test ./…` in `packages/auth`
- `golangci-lint run ./packages/auth/…` — 0 issues
- Belt compiled and tested against this commit (all 16 workspace modules
build; `shared/pkg/auth`, `billing-server/internal/auth`,
`argus-api/internal/handlers` green with `-race`)

<!-- codesmith:footer -->
---
<a
href="https://app.blacksmith.sh/e2b-dev/codesmith/infra/pr/3339"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img
alt="View with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a>
<a
href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787336953&installation_model_id=14389&pr_number=3339&repository=e2b-dev%2Finfra&return_to=https%3A%2F%2Fgithub.com%2Fe2b-dev%2Finfra%2Fpull%2F3339&signature=5551f98aca8e66952d8160dd7d79e3502f3e6cd0cc1c464e571035de4efef169"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img
alt="Autofix with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a>
<sup>Need help on this PR? Tag <code>/codesmith</code> with what you
need. Autofix is disabled.</sup>

<!-- codesmith:autofix:disabled -->
<!-- /codesmith:footer -->
Base automatically changed from feat/auth-oidc-provider-facade to main July 22, 2026 19:50
@tvi
tvi merged commit 7685796 into main Jul 22, 2026
38 of 40 checks passed
@tvi
tvi deleted the refactor/auth-internals-under-pkg-auth branch July 22, 2026 20:07
@codecov

codecov Bot commented Jul 22, 2026

Copy link
Copy Markdown

❌ 5 Tests Failed:

Tests completed Failed Passed Skipped
3471 5 3466 7
View the top 3 failed test(s) by shortest run time
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_1_lists_root_directory
Stack Traces | 0.01s run time
=== RUN   TestListDir/depth_1_lists_root_directory
=== PAUSE TestListDir/depth_1_lists_root_directory
=== CONT  TestListDir/depth_1_lists_root_directory
    filesystem_test.go:96: 
        	Error Trace:	.../tests/envd/filesystem_test.go:96
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_1_lists_root_directory
--- FAIL: TestListDir/depth_1_lists_root_directory (0.01s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
Stack Traces | 0.01s run time
=== RUN   TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
=== PAUSE TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
=== CONT  TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
    filesystem_test.go:96: 
        	Error Trace:	.../tests/envd/filesystem_test.go:96
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
--- FAIL: TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory) (0.01s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_0_lists_only_root_directory
Stack Traces | 0.04s run time
=== RUN   TestListDir/depth_0_lists_only_root_directory
=== PAUSE TestListDir/depth_0_lists_only_root_directory
=== CONT  TestListDir/depth_0_lists_only_root_directory
    filesystem_test.go:96: 
        	Error Trace:	.../tests/envd/filesystem_test.go:96
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_0_lists_only_root_directory
--- FAIL: TestListDir/depth_0_lists_only_root_directory (0.04s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir
Stack Traces | 0.47s run time
=== RUN   TestListDir
=== PAUSE TestListDir
=== CONT  TestListDir
--- FAIL: TestListDir (0.47s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/templates::TestDeleteTemplate
Stack Traces | 163s run time
=== RUN   TestDeleteTemplate
=== PAUSE TestDeleteTemplate
=== CONT  TestDeleteTemplate
    build_template_test.go:133: test-to-delete: [info] Building template 5dbbo9jmvy2p7kq90ow6/524f8d1a-41f7-4417-aae4-4fc11203031e
    build_template_test.go:133: test-to-delete: [info] [base] FROM ubuntu:22.04 [f9f564014e009a9561a82bf8c84f9314242971e833fb019936654ecba452f184]
    build_template_test.go:133: test-to-delete: [info] Base Docker image size: 30 MB
    build_template_test.go:133: test-to-delete: [info] Creating file system and pulling Docker image
    build_template_test.go:133: test-to-delete: [info] Uncompressing layer sha256:d6834b4a794c03efa2c998853e64969fa8851b11b2ade63292268872a37759d0 30 MB
    build_template_test.go:133: test-to-delete: [info] Uncompressing layer sha256:d0af96f8c74840fe62e38d76b1c930927f17ab368161d1bdc5b93191e8c167cf 13 MB
    build_template_test.go:133: test-to-delete: [info] Uncompressing layer sha256:8c4b1b28875140ed3abacaf16ad0d696f6bef912f52d2148f261a23e3349465b 168 B
    build_template_test.go:133: test-to-delete: [info] Layers extracted
    build_template_test.go:133: test-to-delete: [info] Root filesystem structure: bin, boot, dev, etc, home, lib, lib32, lib64, libx32, media, mnt, opt, proc, root, run, sbin, srv, sys, tmp, usr, var
    build_template_test.go:133: test-to-delete: [info] Provisioning sandbox template
    build_template_test.go:133: test-to-delete: [info] Provisioning was successful, cleaning up
    build_template_test.go:133: test-to-delete: [info] Sandbox template provisioned
    build_template_test.go:133: test-to-delete: [info] [base] DEFAULT USER user [49e586c2171254c6bc4a09e84eedac32dbcf113a158c24248129af2f49cbed74]
    build_template_test.go:133: test-to-delete: [info] [builder 1/1] RUN echo 'Hello, World!' [c72b4f813c2a16b0fc1a1c5da7b1365a304cbac516b22dc304a71f70aae48ac0]
    build_template_test.go:133: test-to-delete: [info] [builder 1/1] [stdout]: Hello, World!
    build_template_test.go:133: test-to-delete: [info] [finalize] Finalizing template build [92c524e30533398ebb41ce04c2596130f0cdecc9aa328e28fdb16a1b11f61d62]
    build_template_test.go:133: test-to-delete: [error] Build failed: An internal error occurred. Please try again or contact support with the build ID.
    delete_template_test.go:18: Build failed: {<nil> An internal error occurred. Please try again or contact support with the build ID. <nil>}
--- FAIL: TestDeleteTemplate (163.21s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/templates::TestDeleteTemplateFromAnotherTeamAPIKey
Stack Traces | 164s run time
=== RUN   TestDeleteTemplateFromAnotherTeamAPIKey
=== PAUSE TestDeleteTemplateFromAnotherTeamAPIKey
=== CONT  TestDeleteTemplateFromAnotherTeamAPIKey
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Building template 6olb45p0q74n4c9xd1au/f94677a9-e533-4f5c-9055-69b70cff0865
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] [base] FROM ubuntu:22.04 [f9f564014e009a9561a82bf8c84f9314242971e833fb019936654ecba452f184]
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Base Docker image size: 30 MB
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Creating file system and pulling Docker image
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Uncompressing layer sha256:d6834b4a794c03efa2c998853e64969fa8851b11b2ade63292268872a37759d0 30 MB
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Uncompressing layer sha256:d0af96f8c74840fe62e38d76b1c930927f17ab368161d1bdc5b93191e8c167cf 13 MB
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Uncompressing layer sha256:8c4b1b28875140ed3abacaf16ad0d696f6bef912f52d2148f261a23e3349465b 168 B
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Layers extracted
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Root filesystem structure: bin, boot, dev, etc, home, lib, lib32, lib64, libx32, media, mnt, opt, proc, root, run, sbin, srv, sys, tmp, usr, var
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Provisioning sandbox template
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Provisioning was successful, cleaning up
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] Sandbox template provisioned
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] [base] DEFAULT USER user [49e586c2171254c6bc4a09e84eedac32dbcf113a158c24248129af2f49cbed74]
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] [builder 1/1] RUN echo 'Hello, World!' [c72b4f813c2a16b0fc1a1c5da7b1365a304cbac516b22dc304a71f70aae48ac0]
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] [builder 1/1] [stdout]: Hello, World!
    build_template_test.go:133: test-to-delete-another-team-api-key: [info] [finalize] Finalizing template build [92c524e30533398ebb41ce04c2596130f0cdecc9aa328e28fdb16a1b11f61d62]
    build_template_test.go:133: test-to-delete-another-team-api-key: [error] Build failed: An internal error occurred. Please try again or contact support with the build ID.
    delete_template_test.go:51: Build failed: {<nil> An internal error occurred. Please try again or contact support with the build ID. <nil>}
--- FAIL: TestDeleteTemplateFromAnotherTeamAPIKey (163.81s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/templates::TestTemplateBuildCOPY
Stack Traces | 170s run time
=== RUN   TestTemplateBuildCOPY
=== PAUSE TestTemplateBuildCOPY
=== CONT  TestTemplateBuildCOPY
    build_template_test.go:133: test-ubuntu-copy: [info] Building template uzrxo532d184g5zdoenn/dcf03842-bdc2-4789-bbb5-bfb7b40e37ba
    build_template_test.go:133: test-ubuntu-copy: [info] [base] FROM ubuntu:24.04 [a9b3ad91e89daabce8685d67ae12aacb4a128e5aea703dc57457c0ef17079b25]
    build_template_test.go:133: test-ubuntu-copy: [info] Base Docker image size: 30 MB
    build_template_test.go:133: test-ubuntu-copy: [info] Creating file system and pulling Docker image
    build_template_test.go:133: test-ubuntu-copy: [info] Uncompressing layer sha256:ca2678b20700c15185707964d9211b1a6406196114bf675f568b6025d37b3888 30 MB
    build_template_test.go:133: test-ubuntu-copy: [info] Uncompressing layer sha256:d0af96f8c74840fe62e38d76b1c930927f17ab368161d1bdc5b93191e8c167cf 13 MB
    build_template_test.go:133: test-ubuntu-copy: [info] Uncompressing layer sha256:8c4b1b28875140ed3abacaf16ad0d696f6bef912f52d2148f261a23e3349465b 168 B
    build_template_test.go:133: test-ubuntu-copy: [info] Layers extracted
    build_template_test.go:133: test-ubuntu-copy: [info] Root filesystem structure: bin, boot, dev, etc, home, lib, lib64, media, mnt, opt, proc, root, run, sbin, srv, sys, tmp, usr, var
    build_template_test.go:133: test-ubuntu-copy: [info] Provisioning sandbox template
    build_template_test.go:133: test-ubuntu-copy: [info] Provisioning was successful, cleaning up
    build_template_test.go:133: test-ubuntu-copy: [info] Sandbox template provisioned
    build_template_test.go:133: test-ubuntu-copy: [info] [base] DEFAULT USER user [f9aaa150221ef19e492ba626b8d9200ab9434ed5f63d02341f9e3be29c4b8760]
    build_template_test.go:133: test-ubuntu-copy: [info] [builder 1/2] COPY . /app/ [2449098e8b0a6a85d9aaa0edf0136f8bc69e9d618dac9611e42bba7c698fd629]
    build_template_test.go:133: test-ubuntu-copy: [info] [builder 2/2] RUN cat /app/hello.txt | grep 'Hello from COPY!' [2f22b685841af46c090bf872491df49e98da0615c4d2c99657645a92a5b4ee67]
    build_template_test.go:133: test-ubuntu-copy: [info] [builder 2/2] [stdout]: Hello from COPY!
    build_template_test.go:133: test-ubuntu-copy: [info] [finalize] Finalizing template build [d8abedde856dad9179d9e99f9778f17106da49a5286a30633b898c2e893b0482]
    build_template_test.go:133: test-ubuntu-copy: [error] Build failed: An internal error occurred. Please try again or contact support with the build ID.
    build_template_test.go:1156: Build failed: {<nil> An internal error occurred. Please try again or contact support with the build ID. <nil>}
--- FAIL: TestTemplateBuildCOPY (170.12s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/templates::TestTemplateBuildFuseConfiguration
Stack Traces | 197s run time
=== RUN   TestTemplateBuildFuseConfiguration
=== PAUSE TestTemplateBuildFuseConfiguration
=== CONT  TestTemplateBuildFuseConfiguration
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Building template uk9pecjy06yl1uaidlv2/d254ada2-f3ef-4e11-8ba5-1e4800a7b63d
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [base] FROM ubuntu:22.04 [f9f564014e009a9561a82bf8c84f9314242971e833fb019936654ecba452f184]
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Base Docker image size: 30 MB
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Creating file system and pulling Docker image
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Uncompressing layer sha256:d6834b4a794c03efa2c998853e64969fa8851b11b2ade63292268872a37759d0 30 MB
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Uncompressing layer sha256:d0af96f8c74840fe62e38d76b1c930927f17ab368161d1bdc5b93191e8c167cf 13 MB
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Uncompressing layer sha256:8c4b1b28875140ed3abacaf16ad0d696f6bef912f52d2148f261a23e3349465b 168 B
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Layers extracted
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Root filesystem structure: bin, boot, dev, etc, home, lib, lib32, lib64, libx32, media, mnt, opt, proc, root, run, sbin, srv, sys, tmp, usr, var
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Provisioning sandbox template
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Provisioning was successful, cleaning up
    build_template_test.go:133: test-ubuntu-fuse-config: [info] Sandbox template provisioned
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [base] DEFAULT USER user [49e586c2171254c6bc4a09e84eedac32dbcf113a158c24248129af2f49cbed74]
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [builder 1/2] RUN grep -q 'z /dev/fuse 0666 root root -' /etc/tmpfiles.d/fuse.conf [064c2aa80e42051b5301f9fd4b4c1bab38adc2b717535b7ca42d5dc9fdc739d1]
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [builder 2/2] RUN echo "Checking /dev/fuse permissions:"; ls -la /dev/fuse; stat -c 'mode=%a owner=%U group=%G' /dev/fuse; test $(stat -c %a /dev/fuse) = '666' [53b9173a7399b3bca212e8c5d1b705f01c09a1180ef92f57f3d3fc1db134b289]
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [builder 2/2] [stdout]: Checking /dev/fuse permissions:
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [builder 2/2] [stdout]: crw-rw-rw- 1 root root 10, 229 Jul 22 20:00 /dev/fuse
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [builder 2/2] [stdout]: mode=666 owner=root group=root
    build_template_test.go:133: test-ubuntu-fuse-config: [info] [finalize] Finalizing template build [44ab07a644985d56c51c27da9742b1dd30905f459dd707130223567c87e03c43]
    build_template_test.go:133: test-ubuntu-fuse-config: [error] Build failed: An internal error occurred. Please try again or contact support with the build ID.
    build_template_test.go:1189: Build failed: {<nil> An internal error occurred. Please try again or contact support with the build ID. <nil>}
--- FAIL: TestTemplateBuildFuseConfiguration (197.00s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestCommandKillNextApp
Stack Traces | 294s run time
=== RUN   TestCommandKillNextApp
=== PAUSE TestCommandKillNextApp
=== CONT  TestCommandKillNextApp
    process_test.go:30: Build failed: {<nil> An internal error occurred. Please try again or contact support with the build ID. <nil>}
--- FAIL: TestCommandKillNextApp (294.50s)
View the full list of 1 ❄️ flaky test(s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_3_lists_all_directories_and_files

Flake rate in main: 30.77% (Passed 9 times, Failed 4 times)

Stack Traces | 0.01s run time
=== RUN   TestListDir/depth_3_lists_all_directories_and_files
=== PAUSE TestListDir/depth_3_lists_all_directories_and_files
=== CONT  TestListDir/depth_3_lists_all_directories_and_files
    filesystem_test.go:96: 
        	Error Trace:	.../tests/envd/filesystem_test.go:96
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_3_lists_all_directories_and_files
--- FAIL: TestListDir/depth_3_lists_all_directories_and_files (0.01s)

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

ben-fornefeld added a commit that referenced this pull request Jul 23, 2026
…g tests (#3340)

## Summary

`packages/dashboard-api/internal/provisioning` has not compiled on
`main` since yesterday: #3327 removed read-replica support (and with it
`authdb.Client.Read`), while #3328 — merged a few hours later — added
provisioning tests calling `testDB.AuthDB.Read.GetDefaultTeamByUserID`.
A semantic merge conflict CI didn't catch on either PR.

Every `lint / golangci-lint (packages/dashboard-api)` and dashboard-api
test job on PRs touching that module now fails with:

> team_test.go:159:36: testDB.AuthDB.Read undefined (type *authdb.Client
has no field or method Read)

(e.g.
https://github.com/e2b-dev/infra/actions/runs/29946947140/job/89014781860
on #3338).

Fix: call the sqlc queries embedded on the client directly — the same
style line 43 of the same file already uses.

## Testing

- `go vet ./internal/provisioning/...` — passes (was typecheck-broken)
- `golangci-lint run ./packages/dashboard-api/...` — 0 issues (was
failing)
- `go test ./internal/provisioning/ -count=1` against testcontainers —
ok (11.9s)

<!-- codesmith:footer -->
---
<a
href="https://app.blacksmith.sh/e2b-dev/codesmith/infra/pr/3340"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img
alt="View with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a>
<a
href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787338978&installation_model_id=14389&pr_number=3340&repository=e2b-dev%2Finfra&return_to=https%3A%2F%2Fgithub.com%2Fe2b-dev%2Finfra%2Fpull%2F3340&signature=bd78b61c20b04a9ca1d584ba99a19910922124c2af5a4c2c7e58d346f0bfa436"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img
alt="Autofix with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a>
<sup>Need help on this PR? Tag <code>/codesmith</code> with what you
need. Autofix is disabled.</sup>

<!-- codesmith:autofix:disabled -->
<!-- /codesmith:footer -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants