ROADMAP.md Stage 1: scope down to bring-your-own only, defer self-registration to Stage 5
CI / test (push) Successful in 1m23s

Stage 1's own setup (chart bootstraps before the CR exists) never
exercises the self-registration fallback, and the narrowed spec has
nowhere to put the username/email /api/bootstrap needs anyway. Matches
DESIGN.md's §6 rewrite (bring-your-own is now the primary path, not an
equal alternative).
This commit is contained in:
Niklas Ye
2026-09-30 22:22:09 +02:00
parent 5f93a530fa
commit ffc2e6441e
+15 -9
View File
@@ -53,15 +53,21 @@ land in Stage 5, not before.
## Stage 1 — `TerdutServer`, bootstrap/credentials only
- Deploy terdut-server via its existing chart into a fresh, disposable
namespace — manual, out-of-band, nothing operator-managed yet.
- `TerdutServer` CRD narrowed to `spec.endpoint` + `spec.allowedTeams`; the
rest of §4.1's spec (`image`, `replicas`, `networking`, `database`) waits
for Stage 5.
- Controller implements §6 exactly: call `/api/bootstrap` only on a
genuinely empty install; otherwise `GET /api/service-accounts?name=terdut-operator`
and `POST` one if it doesn't exist. Writes the instance-scoped key to a
generated Secret in the operator's own namespace; sets
`status.credentialsSecretRef` and the `Bootstrapped`/`Ready` conditions.
namespace — manual, out-of-band, nothing operator-managed yet. This chart
run bootstraps the server itself, before the `TerdutServer` CR exists.
- `TerdutServer` CRD narrowed to `spec.endpoint` + `spec.credentialsSecretRef`
+ `spec.allowedTeams`; the rest of §4.1's spec (`image`, `replicas`,
`networking`, `database`) waits for Stage 5.
- Controller implements §6's bring-your-own path only:
`spec.credentialsSecretRef` set and the Secret exists → adopt it,
`status.credentialsSecretRef` mirrors it, `Bootstrapped`/`Ready: True`.
Unset (or not found yet) → `Ready: False`, requeue, no API call made.
**Self-registration (the `/api/bootstrap`-race fallback in §6 point 1) is
explicitly deferred to Stage 5**, not implemented here: Stage 1's own
setup never exercises it (the chart always bootstraps first, per above),
and this narrowed spec has no username/email fields for it to call
`/api/bootstrap` with in the first place. Adding it later is additive,
not a breaking change to this stage's shape.
- No Deployment/Service reconciliation at all in this stage.
- First `envtest` suite (controller-runtime's fake API server) plus an
`httptest.Server` fake of terdut-server's bootstrap/service-account