Skip to content

Feat/gateway certs improvements and improve pair registration - #215

Merged
cardosofede merged 2 commits into
mainfrom
feat/gateway_certs_improvements_and_improve_pair_registration
Aug 10, 2026
Merged

cardosofede merged 2 commits into
mainfrom
feat/gateway_certs_improvements_and_improve_pair_registration

Conversation

@cardosofede

Copy link
Copy Markdown
Contributor
  • Improve gateway certs generation
  • Fix ob validation for trading pair and cleanup

@greptile-apps

greptile-apps Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Greptile Summary

This PR prepares Gateway mTLS certificates during application startup, gates Gateway monitoring on container state, reconciles running containers against the expected certificate mount, and validates or rolls back trading-pair registration failures.

  • Generates and mirrors Gateway client certificates before constructing the in-process client.
  • Adds container-state and certificate-mount checks for Gateway startup reconciliation.
  • Validates exchange trading pairs before registration and removes failed registrations from connector trackers.

Confidence Score: 4/5

The certificate reconciliation defect should be fixed before merging because a mismatched running Gateway remains unusable after the attempted repair.

The new reconciliation path detects a foreign or missing certificate mount but only restarts the existing container; because complete local certificates are not regenerated and container mounts cannot change on restart, the detected mTLS mismatch persists.

Files Needing Attention: services/gateway_service.py

Important Files Changed

Filename Overview
main.py Moves certificate preparation earlier and starts Gateway monitoring only when an applicable Gateway target is available.
services/gateway_service.py Adds mount-aware certificate reconciliation, but the mismatch branch restarts an unchanged container and can leave mTLS incompatibility unresolved.
services/unified_connector_service.py Adds symbol-map validation and rollback of failed trading-pair registrations to avoid contaminating shared order-book subscriptions.

Sequence Diagram

sequenceDiagram
    participant API as API startup
    participant Certs as Certificate store
    participant Docker as Docker
    participant GW as Gateway container
    API->>Certs: ensure_gateway_certs()
    API->>Docker: inspect Gateway mount and status
    alt expected mount and complete certs
        API->>GW: start status monitor
    else mismatched mount or missing certs
        API->>Certs: ensure_gateway_certs()
        API->>GW: restart existing container
        Note over API,GW: Existing mount configuration is unchanged
    end
Loading

Comments Outside Diff (1)

  1. services/gateway_service.py, line 386-388 (link)

    P1 Certificate mismatch survives reconciliation

    When a running Gateway does not mount this API's certificate directory and the local certificate set is complete, ensure_gateway_certs preserves that set and restart() retains the container's original mounts, causing mTLS requests to remain unusable and the Gateway to restart again on subsequent API startups.

Reviews (1): Last reviewed commit: "(feat) adapt gateway certs" | Re-trigger Greptile

@rapcmia rapcmia moved this to Hummingbot-API in Pull Request Board Aug 10, 2026
@rapcmia rapcmia moved this from Hummingbot-API to Backlog in Pull Request Board Aug 10, 2026

@rapcmia rapcmia left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Starting Gateway with hummingbot/gateway:dev, Gateway ran successfully and returned network data through the Hummingbot API.
  • Gateway monitor side effect, Gateway-derived connectors appeared after startup.
  • Adding valid binance/BTC-USDT; the order book initialized successfully.
  • Rejecting invalid binance/BTC-NOTREAL, the pair was refused and did not break the active BTC-USDT order book.
  • Removing the failed pair, the API confirmed it was not being tracked.

@cardosofede
cardosofede merged commit 7de5154 into main Aug 10, 2026
1 check passed
@rapcmia rapcmia self-assigned this Aug 12, 2026
fengtality pushed a commit that referenced this pull request Aug 21, 2026
…ts_and_improve_pair_registration

Feat/gateway certs improvements and improve pair registration
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Hummingbot-API

Development

Successfully merging this pull request may close these issues.

2 participants