examples/demo: add run-demo.sh, an automated kind-cluster demo #4

Merged
niklas merged 1 commits from examples-demo/run-demo-script into main 2026-10-02 20:13:37 +00:00
Owner

One script, two modes (run-demo.sh / run-demo.sh --teardown), that takes a fresh empty kind cluster all the way to a working demo:

  • Creates the kind cluster if needed, helm upgrade --installs this chart, applies every CRD kind in examples/demo, and kubectl waits all nine objects to Ready.
  • Does what the README's own first-login section can't: no credential this operator holds can call /api/admin/settings or POST /api/users (#3, and the sibling gap on terdut-server niklas/terdut-server#23), so it reaches into the demo's own throwaway Postgres directly — flips signup_mode to open, signs alice up for real over the ordinary signup endpoint, and joins her to both Platform and Payments (open signup always creates its own new team rather than joining an existing one by name, so without this she'd have a working login that can't see a single incident this demo fires — /api/incidents//api/alerts are both scoped to the caller's own team memberships).
  • Port-forwards the service and fires fire-alerts.sh at both teams, so a fresh run already has visible incidents waiting in the web UI.

Verification

Run end to end against a real kind cluster, including a second, genuinely-fresh run that hit #3 live (terdutteam-platform wedged in the exact 403 retry loop that issue describes). Confirmed the script itself fails cleanly on that — clear FAILED message, correct exit code, no orphaned port-forward — rather than hanging or leaving a mess, which is the most this script can reasonably do about a bug in the operator it's driving. Once that CR was manually cleared, the rest of the demo (all 9 CRs, alice's login, all 3 fired incidents visible to her) was confirmed working.

Related: #3, niklas/terdut-server#23

One script, two modes (`run-demo.sh` / `run-demo.sh --teardown`), that takes a fresh empty kind cluster all the way to a working demo: - Creates the kind cluster if needed, `helm upgrade --install`s this chart, applies every CRD kind in `examples/demo`, and `kubectl wait`s all nine objects to `Ready`. - Does what the README's own first-login section can't: no credential this operator holds can call `/api/admin/settings` or `POST /api/users` (#3, and the sibling gap on `terdut-server` niklas/terdut-server#23), so it reaches into the demo's own throwaway Postgres directly — flips `signup_mode` to `open`, signs `alice` up for real over the ordinary signup endpoint, and joins her to both Platform and Payments (open signup always creates its own new team rather than joining an existing one by name, so without this she'd have a working login that can't see a single incident this demo fires — `/api/incidents`/`/api/alerts` are both scoped to the caller's own team memberships). - Port-forwards the service and fires `fire-alerts.sh` at both teams, so a fresh run already has visible incidents waiting in the web UI. ## Verification Run end to end against a real kind cluster, including a second, genuinely-fresh run that hit #3 live (`terdutteam-platform` wedged in the exact 403 retry loop that issue describes). Confirmed the script itself fails cleanly on that — clear `FAILED` message, correct exit code, no orphaned port-forward — rather than hanging or leaving a mess, which is the most this script can reasonably do about a bug in the operator it's driving. Once that CR was manually cleared, the rest of the demo (all 9 CRs, alice's login, all 3 fired incidents visible to her) was confirmed working. Related: #3, niklas/terdut-server#23
niklas added 1 commit 2026-10-02 19:24:15 +00:00
examples/demo: add run-demo.sh, an automated kind-cluster demo
CI / chart (pull_request) Successful in 1s
CI / security (pull_request) Successful in 1m5s
CI / test (pull_request) Successful in 2m49s
2a08a8cd8e
One script, two modes (run-demo.sh / run-demo.sh --teardown), that takes a
fresh empty kind cluster all the way to a working demo: creates the
cluster if needed, helm-installs this chart, applies every CRD kind in
this directory, waits for all nine objects to go Ready, then does what
the README's own first-login section cannot (see niklas/terdut-server#23
and niklas/terdut-operator#3 -- no service-account credential this
operator holds can ever call /api/admin/settings or POST /api/users) by
reaching into the demo's own throwaway Postgres directly: flips
signup_mode to open, signs alice up for real over the ordinary signup
endpoint, and joins her to both Platform and Payments (open signup always
creates its own new team, never joins an existing one by name, so
without this she'd have a working login that can't see a single incident
this demo fires -- /api/incidents and /api/alerts are both scoped to the
caller's own team memberships). Finishes by port-forwarding the service
and firing fire-alerts.sh at both teams, so a fresh run already has
visible incidents waiting in the web UI.

Verified end to end against a real kind cluster, including a second,
genuinely-fresh run that hit niklas/terdut-operator#3 live (terdutteam-
platform wedged in the 403 retry loop that issue describes) -- confirmed
the script itself fails cleanly on that (clear FAILED message, correct
exit code, no orphaned port-forward) rather than hanging or leaving a
mess, which is the most this script can do about a bug in the operator
it's driving.
niklas merged commit fcc80b32d5 into main 2026-10-02 20:13:37 +00:00
niklas deleted branch examples-demo/run-demo-script 2026-10-02 20:13:37 +00:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: niklas/terdut-operator#4