From b0d50e305a435a9ebdac37caa91705cb8d107ce8 Mon Sep 17 00:00:00 2001 From: Niklas Ye Date: Thu, 1 Oct 2026 13:51:22 +0200 Subject: [PATCH] ROADMAP.md: mark Stage 3 done, fix stale dead man's switch reconciliation note --- ROADMAP.md | 29 ++++++++++++++++++++++++++--- 1 file changed, 26 insertions(+), 3 deletions(-) diff --git a/ROADMAP.md b/ROADMAP.md index 9a1c45d..ef45739 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -118,9 +118,32 @@ New commits build forward over the old ones; no git history rewrite. - Built together: both stay same-namespace-as-their-`TerdutTeam` (§1), so neither exercises cross-namespace complexity, but together they cover the two different reconciliation shapes §5's table calls out — whole-policy - PUT-on-drift for the escalation policy, delete-and-recreate (no PUT - available) for the dead man's switch — against the same shared - create/finalizer/resync scaffolding Stage 2 already built. + PUT-upsert for the escalation policy (no separate create step at all), + real create/update-in-place/delete for the dead man's switch (PUT added + in terdut-server `v0.33.0` specifically for this operator) — against the + same shared create/finalizer/resync scaffolding Stage 2 already built. +- New shared `resolveTeamAndClient` helper (`childref.go`) implements §5's + "every child resolves its own `teamRef` → `TerdutTeam.status`, never + chains up to `TerdutServer`" rule once, for both controllers — + `TerdutTeam.status.serverEndpoint`, added in this stage, is what makes + that literally true rather than just a stated intent. +- `TerdutEscalationRule` resolves each "user" target's username to a + user_id via `GET /api/users` (confirmed open to any authenticated + caller) and reports `Ready: False, reason: UnknownUser` if it doesn't + resolve. No `DELETE` exists for this resource, so its delete path `PUT`s + an empty policy as the closest available undo. +- `TerdutDeadmanSwitch` has no unique-name constraint server-side, so its + idempotent-create is `GET`-list-and-match-by-name rather than + adopt-on-409 (unlike every other resource in this operator). +- **Done, 2026-10-01**: `envtest` coverage for both controllers' happy + path, `TeamRefNotFound`/`WaitingForTeam`, `UnknownUser`, list-and-match + adoption, update-in-place on spec drift, and deletion. `make fmt lint + test build` all clean; `internal/controller` envtest coverage + 50.5% → 71.7%. No `kind` e2e pass for this stage — Stage 1's already + proved the real-cluster mechanics (RBAC, image, bootstrap) these two + controllers reuse unchanged, and neither introduces a new mechanism that + pass would exercise differently (same reasoning Stage 2 used to skip + one). ## Stage 4 — `TerdutAlertSource`