Niklas Ye 1c45b7e80b
CI / test (push) Has been cancelled
Stage 1: fix two real bugs the kind e2e pass caught, neither envtest could
Ran a full kind end-to-end pass per ROADMAP.md's open item: real kind
cluster, real disposable Postgres, the real terdut-server v0.33.0 image,
the operator built into a real image and deployed as a real Pod (not
`go run` against the cluster -- that was tried first and correctly failed
on cluster DNS not resolving from outside the cluster network, which is
expected, not a bug).

Result: TerdutServer went Ready, the generated credentials Secret held a
real tdsa_-prefixed service-account key, and that key successfully
authenticated and exercised its real intended capability against the
actual server (GET/POST /api/teams -> 200/201) -- confirmed from
terdut-server's own access log, not just our side. Stage 1's actual goal
(ROADMAP.md) is proven, not just asserted.

Two real bugs surfaced that no envtest suite could have caught, since
envtest's client bypasses RBAC entirely:

- .dockerignore's `!**/*.go` doesn't work under podman (the scaffold's
  own comment already named this exact gotcha, buildah/containers#6417,
  and pointed at the fix) -- `docker build` was silently building from an
  empty source tree ("package cmd/main.go is not in std") until this was
  pinned down. Fixed by re-including cmd/api/internal by name, as that
  comment suggested doing if this happened.
- The controller had no RBAC for events.k8s.io (the new events API
  GetEventRecorder uses, unlike the deprecated GetEventRecorderFor) --
  every Event emission failed server-side ("Server rejected event (will
  not retry!)"), silently, since event-recording failure doesn't fail
  reconciliation. Reconciliation itself was never affected, but DESIGN.md
  §12's observability goal (every externally-visible action emits an
  Event) silently wasn't being met in any real deployment. Added
  +kubebuilder:rbac for events.k8s.io/events (create, patch); confirmed
  fixed by restarting the operator and checking `kubectl describe
  terdutserver` actually shows the Event afterward, not just that the log
  line stopped.

Also noted, not fixed here (a different repo's bug): terdut-server's own
GET /api/me 500s for a service-account caller rather than a clean 4xx --
that endpoint assumes a human user in context. Worth a terdut-server
issue, not an operator concern.
2026-10-01 10:15:26 +02:00
2026-09-30 19:22:09 +02:00
2026-09-30 19:22:09 +02:00
2026-09-30 19:22:09 +02:00
2026-09-30 19:22:09 +02:00
2026-09-30 19:22:09 +02:00

Terdut operator

Aims to expose most config as CRD's, so end users can self-service over gitops.

See DESIGN.md for the full design: CRD catalog and specs, reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the relationship to charts/terdut-server. This README stays a short pitch; the open questions it used to carry are now resolved decisions there (§2).

CRD's

terdutServers

Creates a server — Deployment, Service, database wiring, bootstrap, operator credentials, and allowedTeams consent for cross-namespace teams. See DESIGN.md §4.1, §4.6.

terdutTeams

  • team name
  • oidc groups
  • serverRef — explicit reference to its TerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by that TerdutServer's own allowedTeams field (DESIGN.md §2, §4.1, §4.2, §4.6)

terdutEscalationrules

  • rule
  • teamRef — explicit reference to its TerdutTeam (DESIGN.md §2, §4.3)

terdutDeadmansswitches

  • rule
  • teamRef (DESIGN.md §4.4)

terdutAlertSources

  • teamRef (DESIGN.md §4.5)
  • URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly
S
Description
No description provided
Readme 1.1 MiB
Languages
Go 90.8%
Makefile 6.5%
Shell 1.4%
Go Template 0.7%
Dockerfile 0.6%