Repository navigation
feat(api)!: require the application release prefix to be dot-free - #3411
Conversation
Constrain ApplicationDefinition spec.application.release.prefix to lowercase DNS-1123 characters (^[a-z0-9-]*$), which excludes the dot. Release names are "<prefix><app name>" and the tenant CA trust anchor is projected to "<release>.tenant-ca"; the dot is the separator that makes that name unreachable by any engine, so a prefix carrying a dot would break the guarantee. BREAKING CHANGE: an ApplicationDefinition whose release prefix contains a dot, or any character outside [a-z0-9-], is now rejected at admission. Existing definitions with such a prefix must be corrected before this CRD is applied. Assisted-By: Claude <[email protected]> Signed-off-by: Aleksei Sviridkin <[email protected]>
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe release prefix field now documents generated naming rules and enforces lowercase DNS-1123-compatible characters without dots in both the API type and its CRD schema. ChangesApplication release prefix validation
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Timofei Larkin (lllamnyp)
left a comment
There was a problem hiding this comment.
This isn't relevant for just the tenant-ca. The release name is constructed from the prefix and most if not all rendered objects carry the release name, including, e.g., services, which aren't allowed to have a dot in the name anyway. Approved.
The tenant does not reach the trust anchor through a dashboard resource map. No converged engine grants it there, and mongodb's resource map carries the argument for why: a name grant conveys whatever occupies the name, where the label path conveys only what the platform vouched for. The sentence was target-tense at the merge base, describing a name nothing had shipped; repointing it at the object now in the tree turned it into a claim about shipped behaviour that the document's own RBAC reasoning contradicts. "Never shipped in a release" was the changelog's wording for the ExposureClass/ServiceExposure removal, and it reads as stronger than it is: the API was present in the v1.6.0 release candidates published before it was dropped. Gone before v1.6.0 is the precise claim. Decision 0001's Consequences say the enforced legs of the canonical name are the application name and the release prefix. The prefix leg is enforced only because cozystack/cozystack#3411 added the ^[a-z0-9-]*$ pattern to ApplicationDefinitionRelease.Prefix, and the record listed the two PRs that built the controller but not the one that made that sentence true. A record's header is the part kept in step with reality. Assisted-by: LLM
The tenant does not reach the trust anchor through a dashboard resource map. No converged engine grants it there, and mongodb's resource map carries the argument for why: a name grant conveys whatever occupies the name, where the label path conveys only what the platform vouched for. The sentence was target-tense at the merge base, describing a name nothing had shipped; repointing it at the object now in the tree turned it into a claim about shipped behaviour that the document's own RBAC reasoning contradicts. "Never shipped in a release" was the changelog's wording for the ExposureClass/ServiceExposure removal, and it reads as stronger than it is: the API was present in the v1.6.0 release candidates published before it was dropped. Gone before v1.6.0 is the precise claim. Decision 0001's Consequences say the enforced legs of the canonical name are the application name and the release prefix. The prefix leg is enforced only because cozystack/cozystack#3411 added the ^[a-z0-9-]*$ pattern to ApplicationDefinitionRelease.Prefix, and the record listed the two PRs that built the controller but not the one that made that sentence true. A record's header is the part kept in step with reality. Assisted-by: LLM Signed-off-by: Aleksei Sviridkin <[email protected]>
What this PR does
Constrains
ApplicationDefinition.spec.application.release.prefixto^[a-z0-9-]*$, which excludes the dot. Release names are<prefix><app>, and the tenant CA trust anchor is projected to<release>.tenant-ca; the dot is the separator that keeps that name unreachable by any engine, so a prefix carrying a dot would break the guarantee. Every in-tree prefix already conforms. Split out from #3299.Summary by CodeRabbit