Skip to content

feat(HNT-3496): upgrade Apollo Server 3 to 5 - #392

Draft
mmiermans wants to merge 2 commits into
mmiermans/HNT-3495-node-24from
mmiermans/HNT-3496-apollo-server-5
Draft

mmiermans wants to merge 2 commits into
mmiermans/HNT-3495-node-24from
mmiermans/HNT-3496-apollo-server-5

Conversation

@mmiermans

@mmiermans mmiermans commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Move admin-api off EOL Apollo Server 3 to @apollo/server 5.

  • apollo-server-express 3 → @apollo/server 5.5.1 + @as-integrations/express4
  • The 289-line upload fork → @profusion/apollo-federation-upload 4.2.0 (with graphql-upload 15)
  • @pocket-tools/apollo-utils 2.2.0, which depends on Apollo Server 3, is replaced by a ported 30-line sentryPlugin
  • The memcached cache is removed (it was created but never used)
  • TypeScript 5.9 (previously 4.7, transitive only), with skipLibCheck; @types/node 24
  • Security bumps: @apollo/gateway 2.13.4 (drops vulnerable tar/ip), express 4.22.3, @sentry/node 7.120.4, plus npm audit fix
  • Production advisories across the stack: 42 → 9 (critical 3 → 0, high 22 → 2). Both remaining highs are profusion's lodash.set, which has no fix; the prototype-pollution test in test(HNT-3494): add file upload integration test #390 shows it isn't reachable.

I'd love feedback/perspectives on:

Implementation Decisions

  • applyMiddleware used to provide the /.well-known/apollo/server-health endpoint (used by the ECS and ALB health checks), cors() and express.json(). All three are now explicit.
  • Status codes are unchanged:
    • Variable coercion errors return 400 (the AS5 default, same as AS3).
    • An invalid JWT returns 400 UNAUTHENTICATED, set via extensions.http.status.
    • A missing JWT returns 500.
    • server.spec.ts pins all of these, and passes on both AS3 and AS5.
  • @apollo/gateway 2.13.4 rather than 2.14.x: 2.14 pulls in OpenTelemetry packages with 13 more moderate advisories. No federation or @link changes.
  • The landing page is disabled in production as before. In development it is Apollo Sandbox, because AS5 has no GraphQL Playground.

Deployment steps

  • Merge after chore(HNT-3495): upgrade Node 18 to 24 #391 (Node 24) has deployed
  • Dev: ECS task healthy, image upload works in the curation admin tools
  • Prod: same checks; watch Sentry and the section-manager/corpus-scheduler lambdas for errors

References

JIRA ticket:

Stacked on #391. Supersedes #353.

@mmiermans mmiermans closed this Oct 1, 2026
@mmiermans mmiermans reopened this Oct 1, 2026
@mmiermans
mmiermans force-pushed the mmiermans/HNT-3495-node-24 branch from fb59505 to 6226e13 Compare October 1, 2026 19:16
- Replace apollo-server-express 3 with @apollo/server 5 and
  @as-integrations/express4, keeping the health check, CORS and JSON body
  parsing that applyMiddleware provided
- Replace the upload fork with @profusion/apollo-federation-upload 4.2.0
  and graphql-upload 15
- Inline the Sentry plugin and drop @pocket-tools/apollo-utils 2.x, which
  depended on Apollo Server 3
- Remove the unused memcached cache
- Add tests for the health check, CORS, coercion and auth status codes
- @apollo/gateway 2.10.5 -> 2.13.4 (drops vulnerable tar, ip and socks)
- express 4.22.3, @sentry/node and @sentry/tracing 7.120.4
- npm audit fix for remaining transitive advisories
@mmiermans
mmiermans force-pushed the mmiermans/HNT-3496-apollo-server-5 branch from 2b5893a to b70cc61 Compare October 1, 2026 19:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant