From 72c979e3e82c38846c9562206cd76c7bc2f6109b Mon Sep 17 00:00:00 2001 From: Niklas Ye Date: Thu, 1 Oct 2026 10:56:05 +0200 Subject: [PATCH] DESIGN.md: record the now-resolved Team-lookup gap, fix credentialsSecretRef shape MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit §5's Team row now cites GET /api/teams?name= (terdut-server's TEAM-LOOKUP.md, landed today) -- without it the idempotent-create general rule's claim that every resource here has a real lookup to adopt-on-409 through wasn't actually true for Team specifically, confirmed by tracing it before writing any TerdutTeam code, same as Stage 1's bootstrap flow. Also: TerdutTeam.status.credentialsSecretRef drops namespace for key, matching the TerdutServer fix from Stage 1 -- same reasoning, missed there originally. --- DESIGN.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/DESIGN.md b/DESIGN.md index 657ad74..ba3284f 100644 --- a/DESIGN.md +++ b/DESIGN.md @@ -230,7 +230,7 @@ spec: status: conditions: [...] teamID: 42 # the server-side ID; needed by every child object's controller - credentialsSecretRef: {name: platform-oncall.platform-team-credentials, namespace: terdut-operator-system} # see §6; this team's own scoped key, in the OPERATOR's namespace + credentialsSecretRef: {name: platform-oncall.platform-team-credentials, key: token} # see §6; this team's own scoped key, always in the OPERATOR's own namespace (not stored here — same reasoning as TerdutServer's, §4.1) observedGeneration: 1 ``` @@ -354,7 +354,7 @@ resource a full update verb, so reconciliation strategy is per-resource: | Resource | Verbs available | Strategy | |---|---|---| -| Team | POST create, PUT rename, DELETE, PUT oidc-groups | Real update-in-place: diff spec vs. last-applied, PUT the changed pieces. | +| Team | POST create, PUT rename, DELETE, PUT oidc-groups, GET by name | Real update-in-place: diff spec vs. last-applied, PUT the changed pieces. `GET /api/teams?name=` (terdut-server's `TEAM-LOOKUP.md`, landed 2026-10-01) is what makes the idempotent-create general rule below actually true for Team — confirmed by checking: until that endpoint existed, an instance-scoped service account had no way to recover a team's id after a 409, unlike every other resource in this table, where the adopt-on-conflict rule had a real lookup to call. | | Escalation policy | GET/PUT whole-policy | Update-in-place: PUT the full desired policy every reconcile that finds drift; cheap because whole-policy is small and already loaded whole server-side. | | Dead man's switch | POST create, DELETE — **no PUT** | Delete-and-recreate on any spec diff other than `name`. The controller diffs against `status` (which mirrors what was last successfully applied) rather than re-reading the server every reconcile, to avoid a spurious recreate from field reordering. | | Integration (alert source) | POST create, PATCH rename, DELETE | Rename via PATCH; any other spec change (kind) is delete-and-recreate, which **rotates the webhook key** — called out loudly in the CRD's field docs and in a `Warning` event, since it breaks whatever sends to the old URL/key until the new Secret is picked up. (See the general rule below for what happens if the Secret is lost with *no* spec change.) |