Skip to content

feat(api)!: require the application release prefix to be dot-free - #3411

Merged
Aleksei Sviridkin (lexfrei) merged 1 commit into
mainfrom
feat/application-release-prefix-dotfree
Jul 23, 2026
Merged

Aleksei Sviridkin (lexfrei) merged 1 commit into
mainfrom
feat/application-release-prefix-dotfree

Conversation

@lexfrei

@lexfrei Aleksei Sviridkin (lexfrei) commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does

Constrains ApplicationDefinition.spec.application.release.prefix to ^[a-z0-9-]*$, which excludes the dot. Release names are <prefix><app>, and the tenant CA trust anchor is projected to <release>.tenant-ca; the dot is the separator that keeps that name unreachable by any engine, so a prefix carrying a dot would break the guarantee. Every in-tree prefix already conforms. Split out from #3299.

feat(api)!: `ApplicationDefinition.spec.application.release.prefix` must match `^[a-z0-9-]*$` (dot-free). A definition with a prefix containing a dot or any other character is rejected at admission; correct it before applying this CRD.

Summary by CodeRabbit

  • Bug Fixes
    • Added validation for release prefixes to allow only lowercase letters, numbers, and hyphens.
    • Updated guidance explaining how prefixes affect generated release names and tenant CA trust anchors.

Constrain ApplicationDefinition spec.application.release.prefix to
lowercase DNS-1123 characters (^[a-z0-9-]*$), which excludes the dot.
Release names are "<prefix><app name>" and the tenant CA trust anchor is
projected to "<release>.tenant-ca"; the dot is the separator that makes
that name unreachable by any engine, so a prefix carrying a dot would
break the guarantee.

BREAKING CHANGE: an ApplicationDefinition whose release prefix contains a
dot, or any character outside [a-z0-9-], is now rejected at admission.
Existing definitions with such a prefix must be corrected before this CRD
is applied.

Assisted-By: Claude <[email protected]>
Signed-off-by: Aleksei Sviridkin <[email protected]>
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@github-actions github-actions Bot added area/api Issues or PRs related to the cozystack-api aggregated API server kind/breaking-change Indicates the change introduces a breaking API or behaviour change kind/feature Categorizes issue or PR as related to a new feature size/S This PR changes 10-29 lines, ignoring generated files labels Jul 21, 2026
@coderabbitai

coderabbitai Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 78ecee32-5efd-4477-9034-e5535b248ed7

📥 Commits

Reviewing files that changed from the base of the PR and between aef9e20 and d443a09.

📒 Files selected for processing (2)
  • api/v1alpha1/applicationdefinitions_types.go
  • packages/system/application-definition-crd/definition/cozystack.io_applicationdefinitions.yaml

📝 Walkthrough

Walkthrough

The release prefix field now documents generated naming rules and enforces lowercase DNS-1123-compatible characters without dots in both the API type and its CRD schema.

Changes

Application release prefix validation

Layer / File(s) Summary
Release prefix contract and CRD schema
api/v1alpha1/applicationdefinitions_types.go, packages/system/application-definition-crd/definition/cozystack.io_applicationdefinitions.yaml
The spec.release.prefix field documentation now describes release and tenant CA trust-anchor naming, while matching validation restricts prefixes to ^[a-z0-9-]*$.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Suggested reviewers: lllamnyp

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main breaking change: making the application release prefix dot-free.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/application-release-prefix-dotfree

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dosubot dosubot Bot added the kind/api-change Categorizes issue or PR as related to adding, removing, or otherwise changing an API label Jul 21, 2026

@lllamnyp Timofei Larkin (lllamnyp) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't relevant for just the tenant-ca. The release name is constructed from the prefix and most if not all rendered objects carry the release name, including, e.g., services, which aren't allowed to have a dot in the name anyway. Approved.

@lexfrei
Aleksei Sviridkin (lexfrei) merged commit 5a7e4c5 into main Jul 23, 2026
77 of 79 checks passed
@lexfrei
Aleksei Sviridkin (lexfrei) deleted the feat/application-release-prefix-dotfree branch July 23, 2026 11:14
Aleksei Sviridkin (lexfrei) added a commit to cozystack/community that referenced this pull request Sep 3, 2026
The tenant does not reach the trust anchor through a dashboard resource
map. No converged engine grants it there, and mongodb's resource map
carries the argument for why: a name grant conveys whatever occupies the
name, where the label path conveys only what the platform vouched for.
The sentence was target-tense at the merge base, describing a name
nothing had shipped; repointing it at the object now in the tree turned
it into a claim about shipped behaviour that the document's own RBAC
reasoning contradicts.

"Never shipped in a release" was the changelog's wording for the
ExposureClass/ServiceExposure removal, and it reads as stronger than it
is: the API was present in the v1.6.0 release candidates published before
it was dropped. Gone before v1.6.0 is the precise claim.

Decision 0001's Consequences say the enforced legs of the canonical name
are the application name and the release prefix. The prefix leg is
enforced only because cozystack/cozystack#3411 added the ^[a-z0-9-]*$
pattern to ApplicationDefinitionRelease.Prefix, and the record listed the
two PRs that built the controller but not the one that made that sentence
true. A record's header is the part kept in step with reality.

Assisted-by: LLM
Aleksei Sviridkin (lexfrei) added a commit to cozystack/community that referenced this pull request Sep 3, 2026
The tenant does not reach the trust anchor through a dashboard resource
map. No converged engine grants it there, and mongodb's resource map
carries the argument for why: a name grant conveys whatever occupies the
name, where the label path conveys only what the platform vouched for.
The sentence was target-tense at the merge base, describing a name
nothing had shipped; repointing it at the object now in the tree turned
it into a claim about shipped behaviour that the document's own RBAC
reasoning contradicts.

"Never shipped in a release" was the changelog's wording for the
ExposureClass/ServiceExposure removal, and it reads as stronger than it
is: the API was present in the v1.6.0 release candidates published before
it was dropped. Gone before v1.6.0 is the precise claim.

Decision 0001's Consequences say the enforced legs of the canonical name
are the application name and the release prefix. The prefix leg is
enforced only because cozystack/cozystack#3411 added the ^[a-z0-9-]*$
pattern to ApplicationDefinitionRelease.Prefix, and the record listed the
two PRs that built the controller but not the one that made that sentence
true. A record's header is the part kept in step with reality.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/api Issues or PRs related to the cozystack-api aggregated API server kind/api-change Categorizes issue or PR as related to adding, removing, or otherwise changing an API kind/breaking-change Indicates the change introduces a breaking API or behaviour change kind/feature Categorizes issue or PR as related to a new feature size/S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants