Files
terdut-operator/config
Niklas Ye 1c45b7e80b
CI / test (push) Has been cancelled
Stage 1: fix two real bugs the kind e2e pass caught, neither envtest could
Ran a full kind end-to-end pass per ROADMAP.md's open item: real kind
cluster, real disposable Postgres, the real terdut-server v0.33.0 image,
the operator built into a real image and deployed as a real Pod (not
`go run` against the cluster -- that was tried first and correctly failed
on cluster DNS not resolving from outside the cluster network, which is
expected, not a bug).

Result: TerdutServer went Ready, the generated credentials Secret held a
real tdsa_-prefixed service-account key, and that key successfully
authenticated and exercised its real intended capability against the
actual server (GET/POST /api/teams -> 200/201) -- confirmed from
terdut-server's own access log, not just our side. Stage 1's actual goal
(ROADMAP.md) is proven, not just asserted.

Two real bugs surfaced that no envtest suite could have caught, since
envtest's client bypasses RBAC entirely:

- .dockerignore's `!**/*.go` doesn't work under podman (the scaffold's
  own comment already named this exact gotcha, buildah/containers#6417,
  and pointed at the fix) -- `docker build` was silently building from an
  empty source tree ("package cmd/main.go is not in std") until this was
  pinned down. Fixed by re-including cmd/api/internal by name, as that
  comment suggested doing if this happened.
- The controller had no RBAC for events.k8s.io (the new events API
  GetEventRecorder uses, unlike the deprecated GetEventRecorderFor) --
  every Event emission failed server-side ("Server rejected event (will
  not retry!)"), silently, since event-recording failure doesn't fail
  reconciliation. Reconciliation itself was never affected, but DESIGN.md
  §12's observability goal (every externally-visible action emits an
  Event) silently wasn't being met in any real deployment. Added
  +kubebuilder:rbac for events.k8s.io/events (create, patch); confirmed
  fixed by restarting the operator and checking `kubectl describe
  terdutserver` actually shows the Event afterward, not just that the log
  line stopped.

Also noted, not fixed here (a different repo's bug): terdut-server's own
GET /api/me 500s for a service-account caller rather than a clean 4xx --
that endpoint assumes a human user in context. Worth a terdut-server
issue, not an operator concern.
2026-10-01 10:15:26 +02:00
..