fef60caf060c8628c1b4d218d46a7a0654a2097d
CI / test (push) Successful in 1m34s
Three real findings, same discipline as Stages 1/2: - Dead man's switches gained PUT update-in-place in terdut-server v0.33.0 (internal/api/teams.go's handleUpdateTeamDeadman, whose own doc comment names terdut-operator as the reason it was added) -- §5's table still described delete-and-recreate, written before that landed. Also: no unique-name constraint server-side at all, so this resource's idempotent-create step is GET-list-and-match-by-name, not adopt-on-409 the way Team/service-accounts work. - §4.3's username->user_id resolution needs an endpoint: GET /api/users, confirmed open to any authenticated caller (router.go's own "readable by anyone signed in"), so the team-scoped credential already in hand is enough -- no new server-side capability needed here, unlike TEAM-LOOKUP.md's gap. - §5's "a child never needs to chain up to TerdutServer" claim wasn't actually true as written -- a child still needs the server's URL to make any call, and the only way to get one was reading TerdutServer directly. Fixed at the root: TerdutTeam.status now carries serverEndpoint too (resolved once, by TerdutTeam's own controller, same reconcile as teamID/credentialsSecretRef), so the claim holds literally and child controllers need no terdutservers RBAC at all.
Terdut operator
Aims to expose most config as CRD's, so end users can self-service over gitops.
See DESIGN.md for the full design: CRD catalog and specs,
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
relationship to charts/terdut-server. This README stays a short pitch; the
open questions it used to carry are now resolved decisions there (§2).
CRD's
terdutServers
Creates a server — Deployment, Service, database wiring, bootstrap, operator
credentials, and allowedTeams consent for cross-namespace teams. See
DESIGN.md §4.1, §4.6.
terdutTeams
- team name
- oidc groups
serverRef— explicit reference to itsTerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by thatTerdutServer's ownallowedTeamsfield (DESIGN.md §2, §4.1, §4.2, §4.6)
terdutEscalationrules
- rule
teamRef— explicit reference to itsTerdutTeam(DESIGN.md §2, §4.3)
terdutDeadmansswitches
- rule
teamRef(DESIGN.md §4.4)
terdutAlertSources
teamRef(DESIGN.md §4.5)- URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly
Description
Languages
Go
90.8%
Makefile
6.5%
Shell
1.4%
Go Template
0.7%
Dockerfile
0.6%