72c979e3e82c38846c9562206cd76c7bc2f6109b
CI / test (push) Successful in 1m34s
§5's Team row now cites GET /api/teams?name= (terdut-server's TEAM-LOOKUP.md, landed today) -- without it the idempotent-create general rule's claim that every resource here has a real lookup to adopt-on-409 through wasn't actually true for Team specifically, confirmed by tracing it before writing any TerdutTeam code, same as Stage 1's bootstrap flow. Also: TerdutTeam.status.credentialsSecretRef drops namespace for key, matching the TerdutServer fix from Stage 1 -- same reasoning, missed there originally.
Terdut operator
Aims to expose most config as CRD's, so end users can self-service over gitops.
See DESIGN.md for the full design: CRD catalog and specs,
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
relationship to charts/terdut-server. This README stays a short pitch; the
open questions it used to carry are now resolved decisions there (§2).
CRD's
terdutServers
Creates a server — Deployment, Service, database wiring, bootstrap, operator
credentials, and allowedTeams consent for cross-namespace teams. See
DESIGN.md §4.1, §4.6.
terdutTeams
- team name
- oidc groups
serverRef— explicit reference to itsTerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by thatTerdutServer's ownallowedTeamsfield (DESIGN.md §2, §4.1, §4.2, §4.6)
terdutEscalationrules
- rule
teamRef— explicit reference to itsTerdutTeam(DESIGN.md §2, §4.3)
terdutDeadmansswitches
- rule
teamRef(DESIGN.md §4.4)
terdutAlertSources
teamRef(DESIGN.md §4.5)- URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly
Description
Languages
Go
90.8%
Makefile
6.5%
Shell
1.4%
Go Template
0.7%
Dockerfile
0.6%