feat: integrate v4 slices 1-8 and performance optimizations - #205
Open
JLCode-tech wants to merge 23 commits into
Open
feat: integrate v4 slices 1-8 and performance optimizations#205JLCode-tech wants to merge 23 commits into
JLCode-tech wants to merge 23 commits into
Conversation
- Convert AWS/IBM region validators from hardcoded-list rejection to pattern-based acceptance so new or private regions are selectable. - Add Azure and GCP region validators using the same pattern-based approach; wire them into project, credential-template, and cluster schemas/routes. - Update frontend region selectors (AWS, Cloud, SystemDefaults) to free-form inputs with datalist suggestions instead of restrictive dropdowns. - Add KubernetesCluster.account_id and discovery_status columns plus fleet-health response fields for cloud context. - Update unit tests for validators, project schemas, k8s schemas, and frontend selectors.
…ctor - Extract shared is_operator_live_connected() helper and use it in the operator list, fleet health, and BNK health context. - Reuse services.scanner.nodes.parse_node() in BNK fetch instead of duplicating the zone/instance-type label fallback logic. - Add an optional label prop to CloudRegionSelector and reuse it in SystemDefaults to remove four near-identical region input blocks.
- Add connectivity and integration sections to BnkHealthResponse. - Reuse the cluster's persisted status for connectivity and the shared operator live-connection helper for integration. - Display ConnectivityBadge and IntegrationBadge in the dashboard banner. - Add backend unit tests and frontend dashboard tests for the new fields.
Add /detect-credentials endpoint that discovers existing Kubernetes clusters from a project's credential template for AWS, IBM Cloud, Azure, and GCP. Each provider lists accessible clusters, builds a kubeconfig from the template credentials, and registers the cluster in BNK-Forge. - New ClusterDiscoveryService orchestrates detection and registration. - Provider helpers: EKS, ROKS, AKS, GKE. - Frontend auto-detect switched to api.detectClustersFromCredentials(). - Backend + frontend tests updated; openapi.json and api-generated.ts regenerated.
- Move BNK Resources tab from System page to Fleet page - Make GET /api/system/bnk-consumption viewer-accessible - Move MCP Server from standalone sidebar page to System page tab - Move Benchmarks sidebar item from OPERATE to OBSERVE section - Update affected tests and regenerate OpenAPI types
- Add services/bnk/traffic_stats.py with analyze_traffic_stats() and fetch_tmm_traffic_stats() wrapping existing TMM debug helpers. - Add Pydantic schemas for listener/egress/firewall-rule traffic stats. - Wire trafficStats into the unified /f5bnk/data response. - Surface hit/connection badges on F5BNKTopologyViewer listener/egress nodes. - Add hits column to F5BNKPolicyViewer firewall-rule tables. - Add total-connections summary chips in TrafficFlowOverview. - Regenerate openapi.json and TypeScript generated types. - Add backend unit tests and frontend component/hook tests.
- Enrich BNK topology with gateway/listener/route accepted/programmed conditions - Add policy resolved/programmed status to topology and policy associations - Add response models for gateway topology and policy associations endpoints - Surface inline status badges in topology, traffic flow, and policy views - Visualize cross-namespace ReferenceGrants in topology and traffic flow - Extract shared ConditionsList component for Gateway/HTTPRoute/Service details - Add lightweight Service detail fallback and register it in resource registry - Regenerate OpenAPI spec and TypeScript generated types
…urce with settings Module Library sync failed for official-bnk-forge-modules because the clone used source.branch and then tried git checkout <git_ref>. A shallow branch clone does not fetch tags, so checking out a tag ref (v2.2.0) failed with 'pathspec did not match any file(s) known to git'. Use source.git_ref (falling back to branch) directly in git clone --branch, which accepts branch and tag names and already checks out the requested ref. Also reconcile the canonical official module source with the current module_library.git_* settings before a direct source sync, so a stale branch/git_ref on the source row does not override the configured ref. Validated: /api/module-sources/3/sync now succeeds, discovers 24 pack modules, and updates the source row to branch=git_ref=release/2.2.
…figview probes when no VS rows
…d CNE available state - Update has_condition() and get_condition_message() to inspect direct conditions arrays on parent_status dicts as well as standard K8s status.conditions. - Add get_policy_operational_status() to evaluate status.ancestors and status.descendants condition refs for BNKNetPolicy and BNKSecPolicy in BNK 2.3. - Update _build_cne_instance() to recognize Available/Reconciled condition states and populate default phase when healthy. - Update _match_routes_to_listener() to check parent_status condition acceptance.
Stop per-request ThreadPoolExecutors from spawning 20 workers each, which exploded backend PID count to 100+ under concurrent BNK page loads. Use module-level shared executors with small caps for BNK CRD fetches and TMM configview probes. Add Redis-backed short-term caches for: - EKS/GCP bearer tokens (10 min TTL) - fetch_all_bnk_data results (30 s TTL) - TMM traffic stats + configview uuid mappings (30 s / 5 min TTL) - CWC license status (30 s) and report (60 s) Each cache supports force=true to bypass when the UI explicitly refreshes. License activation invalidates the cached status/report so the new state is reflected immediately.
Add account_id, discovery_status, connectivity_status, integration_status,
zones, access_method, and node_count to the KubernetesCluster model, cluster
response schemas, serializers, and detail endpoints. Populate account_id from
credential-template discovery paths (AWS account, Azure subscription, GCP
project) and persist version/node_count/zones/last_synced_at from the scanner.
Includes migration v2_157 and a new GET /api/projects/{project_id}/connectivity
route backed by probe_project_clusters.
…uster The _build_bnk_context helper added in the health refactor queries ConnectedOperator by cluster.id. Tests that patched KubernetesService returned a MagicMock cluster, causing a SQLite bind error. Configure the mock to return the real test cluster so the endpoint can build its connectivity/integration context.
…se endpoints; fix project-switch refresh
…hes across tab navigation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR consolidates v4 Slices 1–8, Corporate CA / SSL proxy support, and the F5 BNK & Diagnostics Performance Optimizations onto
staging.Highlights
1. Core Feature Slices (1–8)
v2_156.nodeZone,nodeInstanceType, and per-component placement metadata.version,node_count,zones,last_synced_at,connectivity_status,access_method, andintegration_status; added project/cluster connectivity endpoints.2. Corporate CA & SSL Proxy Support
certs/into containers.SSL_CERT_FILE,GIT_SSL_CAINFO,REQUESTS_CA_BUNDLE).3. F5 BNK & Diagnostics Performance Optimizations
list_tmm_debug_podschecks warm BNK discovery caches (bnk:pods:{cluster_id}) to eliminate redundant cluster sweeps.Verification & CI Parity
make quick-check: Passed (Ruff, ESLint, TypeScripttsc --noEmit, OpenAPI freshness, migration chain validator).https://localhost).