Skip to content

fix(release): resolve the deploy identity from DFX_CONFIG_ROOT, not HOME - #670

Merged
MRmarioruci merged 2 commits into
mainfrom
fix/deploy-backend-dfxvm-home
Sep 22, 2026
Merged

MRmarioruci merged 2 commits into
mainfrom
fix/deploy-backend-dfxvm-home

Conversation

@MRmarioruci

Copy link
Copy Markdown
Contributor

Every backend deploy fails with error: dfx 0.30.2 is not installed, after the artifacts download and before anything ships.

scripts/deploy-backend isolated the identity store by pointing HOME at a temp directory. dfx is normally a dfxvm shim that resolves the version pinned in dfx.json under $HOME, so repointing it hides the toolchain setup-dfx just installed. HOME was only set because orbit-cli read the identity store from homedir() directly and would otherwise miss the identity dfx had imported.

orbit-cli now treats DFX_CONFIG_ROOT as a stand-in for the home directory, the same way dfx does, and the script sets only that.

Verified against a real dfxvm install: HOME repointed reproduces the error exactly, DFX_CONFIG_ROOT alone gives dfx 0.30.2. After the change the key lands at $DFX_CONFIG_ROOT/.config/dfx/identity/orbit-deploy/identity.pem, which is the path the CLI builds, dfx identity get-principal returns the playground deploy identity, and the real ~/.config/dfx/identity is untouched.

This was not CI-only. An operator running the script by hand hits the same failure.

deploy-backend isolated the identity store by pointing HOME at a temp
directory, because orbit-cli read the store from homedir() directly and
would otherwise miss the identity dfx had just imported. dfx is normally
a dfxvm shim that resolves the version pinned in dfx.json under HOME, so
repointing it hid the installed toolchain and every backend deploy died
with "dfx 0.30.2 is not installed".

orbit-cli now honours DFX_CONFIG_ROOT as a stand-in for the home
directory, the same way dfx does, and the script sets only that.
@MRmarioruci
MRmarioruci requested a review from a team as a code owner September 22, 2026 08:27
@zeropath-ai

zeropath-ai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

✅ No security or compliance issues detected. Reviewed everything up to 8ff9ca4.

Security Overview
Detected Code Changes
Change Type Relevant files
Refactor ► cli/src/utils.ts
    Update DFX_DEFAULT_IDENTITY_STORE_PATH to derive from DFX_CONFIG_ROOT or home directory
Refactor ► scripts/deploy-backend
    Change handling of identity store location: use DFX_CONFIG_ROOT exclusively instead of HOME

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused changes consistently address the reported deployment failure without introducing unresolved issues.

Review effort: Balanced
Findings: None

What changed in this PR

Updates deploy identity resolution so dfxvm retains access to its installed toolchain while deployment credentials remain isolated.

Changes:

  • Resolve the dfx identity store relative to DFX_CONFIG_ROOT, falling back to the user home.
  • Stop overriding HOME during backend deployments.
File Description
scripts/​deploy-backend Isolates dfx configuration without hiding dfxvm installations.
cli/​src/​utils.ts Honors DFX_CONFIG_ROOT when locating identity PEM files.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@MRmarioruci
MRmarioruci merged commit be83581 into main Sep 22, 2026
29 checks passed
@MRmarioruci
MRmarioruci deleted the fix/deploy-backend-dfxvm-home branch September 22, 2026 14:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants