You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Implement adapter stores or retire dead store manifests #1139
PR #1049's documentation refresh recorded unimplemented adapter stores and dead manifest declarations. That finding is historical. At 666953a0d, Cloudflare and Spin build request-time config and KV adapters from EdgeZero context handles; Spin also loads startup configuration from its default KV-backed config store. Axum reads configuration and secrets from environment variables and has no request-time KV implementation. Cloudflare startup still reads a nested TRUSTED_SERVER_CONFIG Worker variable, and its admin EC lookup and key-management routes return unsupported responses. The current Cloudflare guide still says its request-time stores are unwired, which disagrees with platform.rs.
Desired outcome
Every declared adapter store has a documented purpose and a tested path from the runtime binding to the feature that consumes it. Unsupported capabilities are accurately described and are not implied by a manifest entry.
Scoped work
Reconcile edgezero.toml and adapter manifests with the current Cloudflare, Spin, and Axum implementations. For each declared config, KV, and secret store, record its startup and request-time use or its unsupported status.
For a genuinely dead declaration, either implement the intended adapter path and tests or remove the declaration and narrow the associated API and deployment documentation. Keep this choice with maintainers; the PR Add full-surface documentation refresh spec #1049 finding alone does not justify removing a now-used store.
Check request-signing metadata and key access against Spin's current default KV and encoded secret-variable scheme; the original claim that kid variables are unreachable is no longer sufficient evidence by itself.
Correct the Cloudflare guide's stale request-time-store statement and any other matrix entries that disagree with the verified behavior.
Done when
A store inventory identifies every adapter manifest declaration and the code path or explicit unsupported contract for it.
Tests exercise supported store reads through each adapter's actual binding or context path, and unsupported paths return documented results.
Dead declarations, if any, are removed or implemented according to the recorded decision.
Deployment and API documentation matches the tested adapter behavior.
Evidence
Source finding: PR #1049 documentation refresh. Current code inspected at 666953a0d: Cloudflare and Spin platform.rs, Axum platform.rs, adapter startup loaders, edgezero.toml, and docs/guide/cloudflare.md. This is an inventory task, not a claim that all PR #1049 gaps still exist.
We need runtime KV on all four adapters for an integration we are building, so we traced how RuntimeServices::kv_store() is wired at 666953a0. Three findings may help the inventory:
Cloudflare and Spin get no KV handle, even when the binding exists. Both adapters read ctx.kv_store_default(). Only the Fastly adapter implements Hooks::stores(), so EdgeZero builds an empty KV registry on Cloudflare and Spin, and the default handle is None. The result is UnavailableKvStore even with TRUSTED_SERVER_KV bound in wrangler.toml.
Fastly declares the store but does not wire it. The Fastly metadata declares trusted_server_kv, but RuntimeServices receives UnavailableKvStore.
Declaring the store through Hooks::stores() would make it mandatory. On Cloudflare, EdgeZero resolves a declared binding as required and fails the request before routing when it is missing. Spin returns an error when a declared label cannot be opened. Either would break every publisher who has not created the namespace or label, including those who never use KV.
No production code calls kv_store() at the pin, only tests, so wiring it changes no current behavior.
We have a branch that opens the store as optional on each adapter. A missing binding keeps today's behavior, KvError::Unavailable, and requests are still served.
Fastly: opens the linked store at startup.
Cloudflare: opens the TRUSTED_SERVER_KV binding per request.
Spin: opens a dedicated trusted_server_kv label on first use. It never opens default, which holds startup config and signing metadata.
Axum: opens a file store when TRUSTED_SERVER_KV_PATH is set. It runs store operations on the blocking pool, so a slow write cannot hold the request task.
The branch leaves edgezero.toml and the adapter manifests alone; that decision stays with you, as this issue says. It adds tests for each adapter's selection and open logic and corrects the stale line in the Cloudflare guide. We have also run it on wrangler dev --local and spin up with the binding present and absent.
Would a PR that references this issue, without closing it, be useful? We would rebase it on current main first.
Context
PR #1049's documentation refresh recorded unimplemented adapter stores and dead manifest declarations. That finding is historical. At
666953a0d, Cloudflare and Spin build request-time config and KV adapters from EdgeZero context handles; Spin also loads startup configuration from its default KV-backed config store. Axum reads configuration and secrets from environment variables and has no request-time KV implementation. Cloudflare startup still reads a nestedTRUSTED_SERVER_CONFIGWorker variable, and its admin EC lookup and key-management routes return unsupported responses. The current Cloudflare guide still says its request-time stores are unwired, which disagrees withplatform.rs.Desired outcome
Every declared adapter store has a documented purpose and a tested path from the runtime binding to the feature that consumes it. Unsupported capabilities are accurately described and are not implied by a manifest entry.
Scoped work
edgezero.tomland adapter manifests with the current Cloudflare, Spin, and Axum implementations. For each declared config, KV, and secret store, record its startup and request-time use or its unsupported status.kidvariables are unreachable is no longer sufficient evidence by itself.Done when
Evidence
Source finding: PR #1049 documentation refresh. Current code inspected at
666953a0d: Cloudflare and Spinplatform.rs, Axumplatform.rs, adapter startup loaders,edgezero.toml, anddocs/guide/cloudflare.md. This is an inventory task, not a claim that all PR #1049 gaps still exist.