Credentials: the TerdutServer controller generates <name>-operator-key in
the server's own namespace (owned by it) and hands it to the pods as
TERDUT_OPERATOR_KEY; the server creates its instance-scoped account from it
at every start. A replaced Secret rolls the pods. The bootstrap handshake,
the checkpoint Secret, per-team service accounts and credentials Secrets,
BootstrapStateLost and credentials.deletionPolicy are gone.
CRDs: TerdutServer, TerdutTeam and TerdutAlertSource. TerdutEscalationRule
and TerdutDeadmanSwitch become spec.escalation and spec.deadmanSwitches[]
on the team (matched by name, extras removed); team invites are removed.
A team is created under the identity <namespace>/<name> (external_id), so a
retry, a lost status or a deleted team heal by repeating the same call, and
a display name owned by another team is TeamNameTaken instead of an
adoption. The server resolves escalation usernames (UnknownUser condition).
OIDC claim names and trustEmail are spec fields.
Fixes: query values are URL-escaped; every delete treats 404 as success;
deleting a team no longer depends on allowedTeams consent; a switch or
integration deleted on the server is recreated; unnamed switches take the
CR's name.
Cleanup: scaffold e2e test, AGENTS.md, devcontainer, unused config/ pieces
and Client.Version() removed; DESIGN.md, README, ROADMAP and the demo
(run-demo.sh, manifests) rewritten for the new design. Secret RBAC stays
cluster-wide, now stated in DESIGN.md section 9.
Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
Implements the narrowed Stage 1 scope from ROADMAP.md, against the
bootstrap-flow fix from DESIGN.md §4.1/§6 (the earlier self-registration
flow couldn't work unauthenticated against terdut-server's real
AuthMiddleware -- see that commit for the full trace).
- api/v1alpha1: TerdutServer with spec.endpoint + spec.credentialsSecretRef
+ spec.allowedTeams (image/replicas/networking/database deferred to
Stage 5, per DESIGN.md's own narrowing). SecretKeyRef has no namespace
field -- always the operator's own, by construction.
- internal/controller: TerdutServerReconciler implements exactly the
bring-your-own path -- adopt spec.credentialsSecretRef if the Secret
exists and has data under the given key, probe GET /api/version as a
reachability check, set Ready/Bootstrapped conditions accordingly.
Self-registration (the /api/bootstrap race) is not implemented; unset
spec.credentialsSecretRef reports Ready: False, reason:
CredentialsSecretRefRequired, not an attempt at a flow that would fail
unauthenticated anyway. No finalizer: this stage creates nothing
server-side and adopts rather than generates its Secret, so there's
nothing to clean up on delete yet.
- internal/tdclient: minimal terdut-server API client (Version only, the
one call this stage needs), styled after terdut-tui's own
internal/api/client.go per terdut/CLAUDE.md's mirroring convention.
- Tests: envtest suite covering all four not-ready paths plus the happy
path (fake terdut-server via httptest.Server, per DESIGN.md §11), and a
focused unit suite for tdclient. 75.6%/82.4% coverage.
- Event recording uses the new events.k8s.io/v1 recorder API
(mgr.GetEventRecorder), not the deprecated GetEventRecorderFor --
caught by golangci-lint's staticcheck before it shipped.
Verified locally: make fmt lint test build all clean, 0 lint issues, all
specs pass.
kubebuilder init --domain ryuvia.com --repo git.ryuvia.com/niklas/terdut-operator
(--license none, no per-file header boilerplate -- terdut-server's source carries
none either). Go 1.26.0/controller-runtime v0.25.0/controller-tools v0.22.0, whatever
the current kubebuilder CLI (v4.16.0) scaffolds -- not pinned back to terdut-server's
go 1.25.9, since this is a separate module with its own toolchain.
Verified locally: build, vet, fmt all clean; `make lint` (golangci-lint, fetched into
bin/) 0 issues; `make test` (controller-gen + setup-envtest, fetched into bin/,
downloads real envtest binaries from storage.googleapis.com) passes.
Dropped kubebuilder's default .github/workflows/* -- this org runs on Gitea, not
GitHub; ci.yaml (next commit) is the only CI this repo gets.