Ran a full kind end-to-end pass per ROADMAP.md's open item: real kind
cluster, real disposable Postgres, the real terdut-server v0.33.0 image,
the operator built into a real image and deployed as a real Pod (not
`go run` against the cluster -- that was tried first and correctly failed
on cluster DNS not resolving from outside the cluster network, which is
expected, not a bug).
Result: TerdutServer went Ready, the generated credentials Secret held a
real tdsa_-prefixed service-account key, and that key successfully
authenticated and exercised its real intended capability against the
actual server (GET/POST /api/teams -> 200/201) -- confirmed from
terdut-server's own access log, not just our side. Stage 1's actual goal
(ROADMAP.md) is proven, not just asserted.
Two real bugs surfaced that no envtest suite could have caught, since
envtest's client bypasses RBAC entirely:
- .dockerignore's `!**/*.go` doesn't work under podman (the scaffold's
own comment already named this exact gotcha, buildah/containers#6417,
and pointed at the fix) -- `docker build` was silently building from an
empty source tree ("package cmd/main.go is not in std") until this was
pinned down. Fixed by re-including cmd/api/internal by name, as that
comment suggested doing if this happened.
- The controller had no RBAC for events.k8s.io (the new events API
GetEventRecorder uses, unlike the deprecated GetEventRecorderFor) --
every Event emission failed server-side ("Server rejected event (will
not retry!)"), silently, since event-recording failure doesn't fail
reconciliation. Reconciliation itself was never affected, but DESIGN.md
§12's observability goal (every externally-visible action emits an
Event) silently wasn't being met in any real deployment. Added
+kubebuilder:rbac for events.k8s.io/events (create, patch); confirmed
fixed by restarting the operator and checking `kubectl describe
terdutserver` actually shows the Event afterward, not just that the log
line stopped.
Also noted, not fixed here (a different repo's bug): terdut-server's own
GET /api/me 500s for a service-account caller rather than a clean 4xx --
that endpoint assumes a human user in context. Worth a terdut-server
issue, not an operator concern.
kubebuilder init --domain ryuvia.com --repo git.ryuvia.com/niklas/terdut-operator
(--license none, no per-file header boilerplate -- terdut-server's source carries
none either). Go 1.26.0/controller-runtime v0.25.0/controller-tools v0.22.0, whatever
the current kubebuilder CLI (v4.16.0) scaffolds -- not pinned back to terdut-server's
go 1.25.9, since this is a separate module with its own toolchain.
Verified locally: build, vet, fmt all clean; `make lint` (golangci-lint, fetched into
bin/) 0 issues; `make test` (controller-gen + setup-envtest, fetched into bin/,
downloads real envtest binaries from storage.googleapis.com) passes.
Dropped kubebuilder's default .github/workflows/* -- this org runs on Gitea, not
GitHub; ci.yaml (next commit) is the only CI this repo gets.