Skip to content

merge queue: checking #12594 on main (82fa6ed), stacked on #12659, #12658 and #12646 - #12669

Closed
mergify[bot] wants to merge 9 commits into
mainfrom
mergify/merge-queue/c60704af4f
Closed

merge queue: checking #12594 on main (82fa6ed), stacked on #12659, #12658 and #12646#12669
mergify[bot] wants to merge 9 commits into
mainfrom
mergify/merge-queue/c60704af4f

Conversation

@mergify

@mergify mergify Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request has been checked successfully and will be merged soon. 🎉

#12594 is queued for merge on branch main (82fa6ed).

Stacked behind 3 pull requests queued ahead of this batch, not part of it. These checks run on a tip that also carries their commits, so a failure here can come from them as much as from #12594.

Queued ahead of this batch:

This pull request has been created by Mergify to speculatively check the mergeability of #12594.
You don't need to do anything. Mergify will close this pull request automatically when it is complete.

Required conditions of queue rule default for merge:

Required conditions to stay in the queue:

---
checking_base_sha: 105fe4f4e6c1d6196b33f49723bc8301f8381ba6
previous_check_retries: []
previous_failed_batches: []
pull_requests:
  - number: 12594
    scopes: []
scopes: []
...

jd and others added 9 commits August 28, 2026 17:08
`getOgImageUrl` strips the leading and trailing slashes off the pathname to
build the image filename. For the homepage that pathname is `/`, so stripping
left an empty string and the lookup missed — every docs page had an OpenGraph
image and the homepage shipped `<meta property="og:image">` with no content.

The homepage's collection id is `index`, which is what `getStaticPaths` names
its image, so fall back to that when the slug comes out empty.

Covered by a regression test that fails against the old expression. The
generated-image set comes from the content collection and needs the Astro build
pipeline, so the test stubs it and exercises the derivation, which is the half
that was wrong.

Change-Id: Ifb9a23ea2caa20d28489a4f21363d85ed5e3342c
Docset cards rendered their title as `h4`. Almost every grid sits directly
under an `##`, so the outline jumped h2 to h4 — including on the homepage,
whose whole body is the "Products" grid. Screen readers and anything parsing
the document outline read that as a missing level.

Default the card heading to `h3` and make it a prop, because one grid does
belong at h4: the "Components" grid in `ci-insights.mdx` is nested under an
`### Components`, where h3 would make the cards siblings of their own section
heading instead of children.

Change-Id: Ie01f4c2b03f1f2b7f798ae89b056135a5b00800e
The diagrams were not ugly because Graphviz is ugly. They were ugly because 63
hand-typed colors across 18 pages had no palette to be consistent with, and
their dark mode was a hardcoded list of six strings the plugin string-matched.
Four dialects had grown — queue-green, emoji-pastel, nineties-pastel and
near-white-blueprint — and `enterprise/architecture` rendered as a stack of
white slabs on the dark page, because the plugin deliberately skips a cluster
that has a fill and every fill on that page is near-white.

Graphviz supports a `class` attribute on graphs, nodes, edges and clusters and
copies it verbatim into the SVG. So the plugin stops handling color entirely.
It injects shape and spacing defaults, drops the opaque canvas, tags each
element with a *role*, strips the inline paint, and one stylesheet resolves
surface, border and label at paint time. Dark mode then arrives through the
same `:root.theme-dark` block as every other surface on the site — no second
render, no flash, no string matching — and the built SVGs now contain no color
at all.

The 19 fences are not touched. A table in the plugin maps the colors the docs
were drawn with onto roles, so the whole corpus is recolored with zero MDX
edits and this reverts in one commit. The table maps by hue family, so elements
drawn alike still read alike; it is lossy the other way — PostgreSQL and Redis
both land on `datastore` — and that is paid back one page at a time as each
fence names its own roles. It is a shim with a known end: when no fence spells
a color, nothing reaches it.

Three things change that are worth knowing before reviewing screenshots:

- A graph-level caption moves above the figure. Graphviz's default is below;
  `labelloc="t"` is injected, so every fence with a `label=` that does not set
  `labelloc` itself now captions on top.
- Diagram text is painted in Inter rather than the browser's default sans.
  Graphviz still measures in Helvetica, so widths drift by about 3%; the
  injected node margins absorb it.
- Borders lift toward white in dark mode. The product accents themselves are
  untouched, as DESIGN.md requires — what changes is a value derived from them,
  because a #347d39 outline on the dark page surface is too dim to read.

Two roles deliberately share an accent (`queued` and `mergify` are both Merge
Queue teal): the same color under two names, because "waiting in the queue"
and "a service we run" are the same idea on two kinds of diagram, and a role
name that lies is worse than a duplicated accent.

`--color-green-700` is not a new color. It is the green nine diagrams already
had hardcoded, promoted so it has a name.

Verified by rendering all 35 diagrams on the site in both themes and comparing
them against the same page before the change.

Change-Id: I4100df168b1a98d79cd2f0eca15697cb2a9db1cb
The enterprise docs never said how to make an on-premise deployment trust a
private or self-signed certificate authority, and installation.mdx told
operators to disable Redis TLS verification instead, which is the anti-pattern
this was raised about.

Add an enterprise page for MERGIFYENGINE_EXTRA_CA_BUNDLE: what belongs in the
bundle, how to mount it, how to confirm it took effect, and the places where
the setting alone is not enough. PostgreSQL needs sslmode=verify-full before
libpq consults the roots at all, REDIS_SSL_VERIFY_MODE_CERT_NONE overrides the
bundle, SSL_CERT_DIR reaches only part of the engine, and the bundle is read
once per process so rotating the CA needs a restart. The PostgreSQL and Redis
caveats come before the verification steps on purpose: a connectivity check
against a connection that verifies nothing reports ok either way.

installation.mdx now leads its self-signed Redis section with the bundle and
keeps REDIS_SSL_VERIFY_MODE_CERT_NONE only as the fallback for a certificate
you cannot obtain, while still telling a truly self-signed deployment to put
the server certificate itself in the bundle, and pointing managed-Redis users
at the CA their provider publishes. Its vague PostgreSQL "configure the
connection options accordingly" becomes the concrete sslmode. The section
heading is unchanged so its existing anchor keeps resolving.

Troubleshooting and requirements link the page from the two places an operator
hits the wall: a connectivity check that fails on certificate verification, and
an egress proxy that re-signs the subscription calls.

Fixes MRGFY-8831

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018XJzBXXpAFeRk3pLsADvjw
Change-Id: Ib0ef33d61614b688512cfe24897e121790072193
@mergify
mergify Bot deployed to Mergify Merge Protections September 3, 2026 07:44 Active
@mergify mergify Bot closed this Sep 3, 2026
@mergify
mergify Bot deleted the mergify/merge-queue/c60704af4f branch September 3, 2026 07:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants