Feat/gateway certs improvements and improve pair registration - #215
cardosofede merged 2 commits into
Conversation
cardosofede
commented
Aug 7, 2026
- Improve gateway certs generation
- Fix ob validation for trading pair and cleanup
Greptile SummaryThis PR prepares Gateway mTLS certificates during application startup, gates Gateway monitoring on container state, reconciles running containers against the expected certificate mount, and validates or rolls back trading-pair registration failures.
Confidence Score: 4/5The certificate reconciliation defect should be fixed before merging because a mismatched running Gateway remains unusable after the attempted repair. The new reconciliation path detects a foreign or missing certificate mount but only restarts the existing container; because complete local certificates are not regenerated and container mounts cannot change on restart, the detected mTLS mismatch persists. Files Needing Attention: services/gateway_service.py
|
| Filename | Overview |
|---|---|
| main.py | Moves certificate preparation earlier and starts Gateway monitoring only when an applicable Gateway target is available. |
| services/gateway_service.py | Adds mount-aware certificate reconciliation, but the mismatch branch restarts an unchanged container and can leave mTLS incompatibility unresolved. |
| services/unified_connector_service.py | Adds symbol-map validation and rollback of failed trading-pair registrations to avoid contaminating shared order-book subscriptions. |
Sequence Diagram
sequenceDiagram
participant API as API startup
participant Certs as Certificate store
participant Docker as Docker
participant GW as Gateway container
API->>Certs: ensure_gateway_certs()
API->>Docker: inspect Gateway mount and status
alt expected mount and complete certs
API->>GW: start status monitor
else mismatched mount or missing certs
API->>Certs: ensure_gateway_certs()
API->>GW: restart existing container
Note over API,GW: Existing mount configuration is unchanged
end
Comments Outside Diff (1)
-
services/gateway_service.py, line 386-388 (link)Certificate mismatch survives reconciliation
When a running Gateway does not mount this API's certificate directory and the local certificate set is complete,
ensure_gateway_certspreserves that set andrestart()retains the container's original mounts, causing mTLS requests to remain unusable and the Gateway to restart again on subsequent API startups.
Reviews (1): Last reviewed commit: "(feat) adapt gateway certs" | Re-trigger Greptile
rapcmia
left a comment
There was a problem hiding this comment.
- Starting Gateway with hummingbot/gateway:dev, Gateway ran successfully and returned network data through the Hummingbot API.
- Gateway monitor side effect, Gateway-derived connectors appeared after startup.
- Adding valid binance/BTC-USDT; the order book initialized successfully.
- Rejecting invalid binance/BTC-NOTREAL, the pair was refused and did not break the active BTC-USDT order book.
- Removing the failed pair, the API confirmed it was not being tracked.
…ts_and_improve_pair_registration Feat/gateway certs improvements and improve pair registration