Skip to content

Commit 7d573d2

Browse files
raylimclaude
andauthored
Release the resource-data WSI stack to beta (wsi-serving-v5) (#695)
Pins beta blue and green, and the beta tile server, to the de-identified resource-data WSI release beta-wsi-rd-20261006-1: - portal: cBioPortal/cbioportal#12378 head b479612a95 (schema 3.6.0) - frontend: cBioPortal/cbioportal-frontend#5732 head 045105b07, immutable Netlify deploy 6ac48117bcbba50008ca68db - tile server: cBioPortal/cbioportal-tile-server#44 head 75dce4f488 (wsi_auth_version 3: slide_key plus an encrypted source claim) The tile server rejects a client-supplied X-WSI-Source, so the ingress hashes on the bearer capability instead. The release validator and the routing smoke test now expect wsi-serving-v5 and auth contract 3, and the smoke test checks that a browser-supplied source is refused. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent 0515de8 commit 7d573d2

6 files changed

Lines changed: 42 additions & 31 deletions

File tree

‎.github/scripts/smoke_wsi_triage.sh‎

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ ready_payload="$(curl --fail --silent --show-error "${base_url%/}/ready")"
1010
jq --exit-status \
1111
'.status == "ok"
1212
and .auth_required == true
13-
and .auth_contract_version == 2
14-
and .serving_contract_version == "wsi-serving-v3"' \
13+
and .auth_contract_version == 3
14+
and .serving_contract_version == "wsi-serving-v5"' \
1515
<<<"$ready_payload" >/dev/null || {
1616
echo "unexpected WSI readiness contract: $ready_payload" >&2
1717
exit 1
@@ -40,10 +40,20 @@ test "$status" = 401 || {
4040
exit 1
4141
}
4242

43+
# The capability carries the slide source; a browser-supplied one is refused
44+
# before authentication.
45+
status="$(curl --silent --show-error --output /dev/null --write-out '%{http_code}' \
46+
--header "X-WSI-Source: $source_url" \
47+
"$tile_path")"
48+
test "$status" = 400 || {
49+
echo "expected a client-supplied X-WSI-Source to return 400, got $status" >&2
50+
exit 1
51+
}
52+
4353
curl --silent --show-error --include --request OPTIONS \
4454
--header "Origin: $origin" \
4555
--header 'Access-Control-Request-Method: GET' \
46-
--header 'Access-Control-Request-Headers: authorization, x-wsi-source' \
56+
--header 'Access-Control-Request-Headers: authorization' \
4757
"$tile_path" \
4858
| grep -i "^access-control-allow-origin: $origin" >/dev/null || {
4959
echo "CORS preflight did not allow $origin" >&2
@@ -53,7 +63,6 @@ curl --silent --show-error --include --request OPTIONS \
5363
if [[ -n "${WSI_BEARER_TOKEN:-}" ]]; then
5464
status="$(curl --silent --show-error --output /dev/null --write-out '%{http_code}' \
5565
--header "Authorization: Bearer ${WSI_BEARER_TOKEN}" \
56-
--header "X-WSI-Source: $source_url" \
5766
"$tile_path")"
5867
test "$status" != 401 || {
5968
echo "provided WSI_BEARER_TOKEN was rejected" >&2

‎.github/scripts/validate_wsi_beta_release.py‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,7 @@ def portal_identity(path: Path) -> tuple[str, str, str, str]:
9595
expected_identity = {
9696
"--wsi.release-id": release_id,
9797
"--wsi.backend-git-sha": backend_image_match.group(1),
98-
"--wsi.serving-contract-version": "wsi-serving-v3",
98+
"--wsi.serving-contract-version": "wsi-serving-v5",
9999
}
100100
if any(
101101
runtime_identity.get(key) != expected
@@ -287,8 +287,8 @@ def assert_docker_digest(repository: str, digest: str) -> None:
287287
tile_env = env_map(tile_container)
288288
if tile_env.get("WSI_RELEASE_ID") != blue[0]:
289289
raise AssertionError("tile-server runtime release identity differs")
290-
if tile_env.get("WSI_SERVING_CONTRACT_VERSION") != "wsi-serving-v3":
291-
raise AssertionError("tile-server does not declare wsi-serving-v3")
290+
if tile_env.get("WSI_SERVING_CONTRACT_VERSION") != "wsi-serving-v5":
291+
raise AssertionError("tile-server does not declare wsi-serving-v5")
292292
if not re.fullmatch(r"[0-9a-f]{40}", tile_env.get("IMAGE_GIT_SHA", "")):
293293
raise AssertionError("tile-server does not declare a full immutable git SHA")
294294
tile_cors_origins = comma_separated_values(tile_env.get("CORS_ORIGINS", ""))

‎argocd/aws/666628074417/clusters/cbioportal-prod/apps/cbioportal/cbioportal-eks-msk-beta-blue-deployment-service.yaml‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -28,8 +28,8 @@ spec:
2828
metadata:
2929
annotations:
3030
admission.datadoghq.com/java-lib.version: v1.24.2
31-
wsi.cbioportal.org/release-id: "beta-wsi-v2-20260916-4"
32-
wsi.cbioportal.org/frontend-git-sha: "ca327132101fcce80732b53b098083a9e273344b"
31+
wsi.cbioportal.org/release-id: "beta-wsi-rd-20261006-1"
32+
wsi.cbioportal.org/frontend-git-sha: "045105b073e6f3afcdb2fde5240f8ef45469b0c3"
3333
labels:
3434
admission.datadoghq.com/enabled: "true"
3535
run: eks-msk-beta-blue
@@ -86,10 +86,10 @@ spec:
8686
- --com.sun.management.jmxremote.local.only=false
8787
- --java.rmi.server.hostname=localhost
8888
# /enable remote debug
89-
- --frontend.url=https://6aaad47e4dd99b00083d160d--cbioportalfrontend.netlify.app/
90-
- --wsi.release-id=beta-wsi-v2-20260916-4
91-
- --wsi.backend-git-sha=e56f407b2d31b45a6b1a314c5152be61b4954ae0
92-
- --wsi.serving-contract-version=wsi-serving-v3
89+
- --frontend.url=https://6ac48117bcbba50008ca68db--cbioportalfrontend.netlify.app/
90+
- --wsi.release-id=beta-wsi-rd-20261006-1
91+
- --wsi.backend-git-sha=b479612a9532a6581df750b24b5178c504be46ae
92+
- --wsi.serving-contract-version=wsi-serving-v5
9393
- --default_cross_cancer_study_session_id=5c8a7d55e4b046111fee2296
9494
- --quick_search.enabled=true
9595
- --default_cross_cancer_study_list=mskimpact
@@ -119,7 +119,7 @@ spec:
119119
- --dbconnector=dbcp
120120
- --authenticate=saml_plus_basic
121121
- --authorization=false
122-
- --security.cors.allowed-origins=https://beta.cbioportal.mskcc.org,https://keycloak.cbioportal.mskcc.org,https://6aaad47e4dd99b00083d160d--cbioportalfrontend.netlify.app
122+
- --security.cors.allowed-origins=https://beta.cbioportal.mskcc.org,https://keycloak.cbioportal.mskcc.org,https://6ac48117bcbba50008ca68db--cbioportalfrontend.netlify.app
123123
- --db.user=$(DB_USER)
124124
- --db.password=$(DB_PASSWORD)
125125
- --db.suppress_schema_version_mismatch_errors=true
@@ -273,7 +273,7 @@ spec:
273273
name: wsi-serving-policy
274274
- secretRef:
275275
name: cbioportal-msk-beta-blue
276-
image: cbioportal/cbioportal-dev:e56f407b2d31b45a6b1a314c5152be61b4954ae0-web-shenandoah@sha256:780fa5ec83b26eb5a0634a45a3b0494cc0144645a0683c4b69b210e7e668e9bd
276+
image: cbioportal/cbioportal-dev:b479612a9532a6581df750b24b5178c504be46ae-web-shenandoah@sha256:5b7f004c4daacf60f219ad185fc49a6bc762a544fc6dfe29ad0939f85284f569
277277
imagePullPolicy: Always
278278
livenessProbe:
279279
failureThreshold: 20

‎argocd/aws/666628074417/clusters/cbioportal-prod/apps/cbioportal/cbioportal-eks-msk-beta-green-deployment-service.yaml‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ spec:
2727
metadata:
2828
annotations:
2929
admission.datadoghq.com/java-lib.version: v1.24.2
30-
wsi.cbioportal.org/release-id: "beta-wsi-v2-20260916-4"
31-
wsi.cbioportal.org/frontend-git-sha: "ca327132101fcce80732b53b098083a9e273344b"
30+
wsi.cbioportal.org/release-id: "beta-wsi-rd-20261006-1"
31+
wsi.cbioportal.org/frontend-git-sha: "045105b073e6f3afcdb2fde5240f8ef45469b0c3"
3232
labels:
3333
admission.datadoghq.com/enabled: "true"
3434
run: eks-msk-beta-green
@@ -85,10 +85,10 @@ spec:
8585
- --com.sun.management.jmxremote.local.only=false
8686
- --java.rmi.server.hostname=localhost
8787
# /enable remote debug
88-
- --frontend.url=https://6aaad47e4dd99b00083d160d--cbioportalfrontend.netlify.app/
89-
- --wsi.release-id=beta-wsi-v2-20260916-4
90-
- --wsi.backend-git-sha=e56f407b2d31b45a6b1a314c5152be61b4954ae0
91-
- --wsi.serving-contract-version=wsi-serving-v3
88+
- --frontend.url=https://6ac48117bcbba50008ca68db--cbioportalfrontend.netlify.app/
89+
- --wsi.release-id=beta-wsi-rd-20261006-1
90+
- --wsi.backend-git-sha=b479612a9532a6581df750b24b5178c504be46ae
91+
- --wsi.serving-contract-version=wsi-serving-v5
9292
- --default_cross_cancer_study_session_id=5c8a7d55e4b046111fee2296
9393
- --quick_search.enabled=true
9494
- --default_cross_cancer_study_list=mskimpact
@@ -118,7 +118,7 @@ spec:
118118
- --dbconnector=dbcp
119119
- --authenticate=saml_plus_basic
120120
- --authorization=false
121-
- --security.cors.allowed-origins=https://beta.cbioportal.mskcc.org,https://keycloak.cbioportal.mskcc.org,https://6aaad47e4dd99b00083d160d--cbioportalfrontend.netlify.app
121+
- --security.cors.allowed-origins=https://beta.cbioportal.mskcc.org,https://keycloak.cbioportal.mskcc.org,https://6ac48117bcbba50008ca68db--cbioportalfrontend.netlify.app
122122
- --db.user=$(DB_USER)
123123
- --db.password=$(DB_PASSWORD)
124124
- --db.suppress_schema_version_mismatch_errors=true
@@ -270,7 +270,7 @@ spec:
270270
name: wsi-serving-policy
271271
- secretRef:
272272
name: cbioportal-msk-beta-green
273-
image: cbioportal/cbioportal-dev:e56f407b2d31b45a6b1a314c5152be61b4954ae0-web-shenandoah@sha256:780fa5ec83b26eb5a0634a45a3b0494cc0144645a0683c4b69b210e7e668e9bd
273+
image: cbioportal/cbioportal-dev:b479612a9532a6581df750b24b5178c504be46ae-web-shenandoah@sha256:5b7f004c4daacf60f219ad185fc49a6bc762a544fc6dfe29ad0939f85284f569
274274
imagePullPolicy: Always
275275
livenessProbe:
276276
failureThreshold: 20

‎argocd/aws/666628074417/clusters/cbioportal-prod/apps/slide-viewer-triage/deployment.yaml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ spec:
3131
labels:
3232
app: slide-viewer-triage
3333
annotations:
34-
wsi.cbioportal.org/release-id: "beta-wsi-v2-20260916-4"
34+
wsi.cbioportal.org/release-id: "beta-wsi-rd-20261006-1"
3535
# Restart the pod when the ConfigMap-backed CORS allowlist changes.
3636
# Force a clean beta block cache after source-region tile failures.
3737
slide-viewer-cache-revision: "2026-08-31-native-overview-cache-recovery"
@@ -80,7 +80,7 @@ spec:
8080
- ALL
8181
# Keep the channel tag for operator familiarity; the digest is the
8282
# immutable release identity validated by CI.
83-
image: cbioportal/cbioportal-tile-server:main@sha256:0638d904f004bc0cd2f678869ccc7dab8ec4e092c0b30f9872cb1095b4942197
83+
image: cbioportal/cbioportal-tile-server:beta-wsi-20261006-75dce4f488@sha256:2d6f3582f691c33ce52e6027dd17622a4113a5c75c9164441b0a84707f7bfbbc
8484
imagePullPolicy: Always
8585
resources:
8686
requests:
@@ -109,13 +109,13 @@ spec:
109109
- name: MAX_IMAGE_OPERATIONS
110110
value: "4"
111111
- name: CORS_ORIGINS
112-
value: "https://beta.cbioportal.mskcc.org,https://6aaad47e4dd99b00083d160d--cbioportalfrontend.netlify.app"
112+
value: "https://beta.cbioportal.mskcc.org,https://6ac48117bcbba50008ca68db--cbioportalfrontend.netlify.app"
113113
- name: WSI_RELEASE_ID
114-
value: "beta-wsi-v2-20260916-4"
114+
value: "beta-wsi-rd-20261006-1"
115115
- name: IMAGE_GIT_SHA
116-
value: "082c3f77ec7eb091bc4a17b96d89cf6d1618d73c"
116+
value: "75dce4f488d2cf4bb8616bb135840c78b6a6925a"
117117
- name: WSI_SERVING_CONTRACT_VERSION
118-
value: "wsi-serving-v3"
118+
value: "wsi-serving-v5"
119119
- name: AWS_ACCESS_KEY_ID
120120
valueFrom:
121121
secretKeyRef:

‎argocd/aws/666628074417/clusters/cbioportal-prod/apps/slide-viewer-triage/ingress.yaml‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,10 @@ metadata:
1616
# users behind one NAT address. The tile server still bounds expensive
1717
# image work independently with MAX_IMAGE_OPERATIONS.
1818
nginx.ingress.kubernetes.io/limit-connections: "300"
19-
# Keep a slide's cold-open cache and SlideCache affinity on one pod.
20-
nginx.ingress.kubernetes.io/upstream-hash-by: "$http_x_wsi_source"
19+
# Keep a slide's cold-open cache and SlideCache affinity on one pod. The
20+
# bearer capability is the only per-slide request input (it rotates with
21+
# its TTL, so affinity holds for one token lifetime).
22+
nginx.ingress.kubernetes.io/upstream-hash-by: "$http_authorization"
2123
# The browser uses a same-origin /wsi route while the FastAPI application
2224
# owns root-level /tiles, /thumbnails, /health, and /ready paths.
2325
nginx.ingress.kubernetes.io/use-regex: "true"

0 commit comments

Comments
 (0)