Files
terdut-operator/ROADMAP.md
T
Niklas Ye e1103f2b7d Authenticate with a seeded operator key; fold escalation and switches into TerdutTeam
Credentials: the TerdutServer controller generates <name>-operator-key in
the server's own namespace (owned by it) and hands it to the pods as
TERDUT_OPERATOR_KEY; the server creates its instance-scoped account from it
at every start. A replaced Secret rolls the pods. The bootstrap handshake,
the checkpoint Secret, per-team service accounts and credentials Secrets,
BootstrapStateLost and credentials.deletionPolicy are gone.

CRDs: TerdutServer, TerdutTeam and TerdutAlertSource. TerdutEscalationRule
and TerdutDeadmanSwitch become spec.escalation and spec.deadmanSwitches[]
on the team (matched by name, extras removed); team invites are removed.
A team is created under the identity <namespace>/<name> (external_id), so a
retry, a lost status or a deleted team heal by repeating the same call, and
a display name owned by another team is TeamNameTaken instead of an
adoption. The server resolves escalation usernames (UnknownUser condition).
OIDC claim names and trustEmail are spec fields.

Fixes: query values are URL-escaped; every delete treats 404 as success;
deleting a team no longer depends on allowedTeams consent; a switch or
integration deleted on the server is recreated; unnamed switches take the
CR's name.

Cleanup: scaffold e2e test, AGENTS.md, devcontainer, unused config/ pieces
and Client.Version() removed; DESIGN.md, README, ROADMAP and the demo
(run-demo.sh, manifests) rewritten for the new design. Secret RBAC stays
cluster-wide, now stated in DESIGN.md section 9.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
2026-10-09 14:56:22 +02:00

1.2 KiB

terdut-operator status and deferred work

The staged build plan this file used to hold (scaffolding, TerdutServer, TerdutTeam, the child kinds, the installer chart and first release) is done and shipped; the history is in git. The design it implemented is in DESIGN.md, and its revision section at the top is the current shape of credentials and the CRD catalog.

Validation

There is no CI end-to-end job. The golden path (create every kind against a real terdut-server on kind, check the server's own API, delete, check it is gone) is a manual pass, using examples/demo/run-demo.sh. It has not been re-run since the credential and CRD redesign (2026-10): do that before the next release.

Deferred

  • Narrower Secret RBAC: per-namespace Roles and a restricted cache (today a ClusterRole with Secret access cluster-wide, DESIGN.md §9).
  • CloudNativePG support alongside the Zalando postgresClusterRef.
  • Gitops-managed team membership.
  • Automatic Deployment restart on upstream Postgres credential rotation.
  • Admission webhooks beyond CEL validation.
  • OLM packaging.
  • A shared API types module (or generated client) between terdut-server, terdut-operator and terdut-tui, so contract drift is a compile error and not a manual mirror.