Repository navigation
Conversation
(cherry picked from commit 0cdf988)
* feat(connectivities): provision scoped non-god ledger credentials for Connectivity Jira: EN-2490 * fix: address review feedback (EN-2490) * feat(connectivities): use Ledger bundle for Stack-managed Connectivity (#546) * test(connectivities): exercise credential generation guard * feat(connectivities): delegate Ledger Credentials Secret to Connectivity * fix(connectivities): retain existing binding for non-god credentials * fix(connectivities): restore scoped credentials with the existing key binding * test(connectivities): wait for complete Stack credential distribution * fix(connectivities): bind auth to distributed Ledger Secret * fix(connectivities): use scoped superuser credentials after Ledger API rename --------- Co-authored-by: shipfox-ai[bot] <307629549+shipfox-ai[bot]@users.noreply.github.com> Co-authored-by: David Ragot <35502263+Dav-14@users.noreply.github.com> Co-authored-by: Maxence Maireaux <maxence@formance.com> (cherry picked from commit be3c687)
|
🟡 [minor] Correct and complete the schema migration inventory The upgrade gate says monitoring.traces is removed, but the head CRD retains traces and removes only traces.sampling (config CRD lines 2120–2144). The diff also removes persistence.coldCache and replaces monitoring.pyroscope.authToken/basicAuthPassword with Secret references, neither of which is listed. An operator using this inventory to prepare migration can overlook pruned profiling credentials/cache configuration while unnecessarily removing valid tracing configuration. Suggestion: List traces.sampling rather than traces, include coldCache and both Pyroscope credential replacements, and document moving the profiling credentials into referenced Secrets before applying the schema. |
|
Addressed the schema migration finding in head The notes now list all 35 removed property paths, including Verified against the generated candidate schema and |
|
Current-head CI checkpoint for Tests and Dirty passed. Kubernetes E2E 1.31 and 1.32 passed after one individual retry each for Docker Hub HTTP 500 errors before tests; 1.35 passed initially. Kubernetes 1.34 also passed after its single individual network retry. The run is complete and remains failed solely on the 1.33 cleanup below. No further job retry is planned.
The independent review confirms the cleanup observation and that this test fixture is unchanged from v3.16.0. Root-cause evidence is still needed before changing the frozen candidate ( |
Summary
Prepare the explicitly selected Operator v3.16.1 candidate for OVH sandbox, starting from v3.16.0 and backporting only already-merged #548 and #544. Align
operator/operator-crdschart versions and application versions, regenerate the dependency lock, and document migration and GitOps qualification gates.Release preparation: EN-2723. Credential behavior: EN-2490; sandbox qualification remains EN-2227 / EN-2231. The Manager owns Jira updates; no Jira write was performed here.
Frozen source
Base
chore/v3.16.1-baselineis exactly the existing v3.16.0 tag,5c92b82d3d1c33f6e28f674ab476c589ecc5be33. This dedicated preparation base avoids incorporating #547 or reverting unrelated main changes. The eventual integration/ref-to-tag decision remains open; this is not a release branch authorization.0cdf98803609dd1510ce02bd79e44e23d209378d265f63e5be3c687a68ba13c8096ca1b5cc943f5c7a0696c8e3501912Range-diff confirms the backports preserve the patches (only provenance trailers differ). Excluded: #547 Job node selectors, #545 Ledger cluster-ID preservation, #542 security dependency updates. The excluded security update requires owner assessment before publication; exclusion is not a safety assertion.
Compatibility impacts — publication blocked
The requested patch number does not certify backward compatibility. Existing Credentials are narrowed to
superuser=falseand exactly five scopes. A Core still emitting superuser tokens is incompatible. Ledger Credentials CRD/controller must supportsuperuser; Regions currently locks Ledger Operator beta.1, which usesgod, and is not a valid candidate prerequisite.#548 also removes LedgerConfiguration fields (
coldStorage,dnsEndpoint,receiptSigning,monitoring.traces.sampling), changes DNS representation and removes the cluster-ID default. Kubernetes pruning plus the reconciler's full Cluster-spec replacement can lose configuration. Inventory real LedgerConfiguration/Cluster objects and obtain an approved migration before applying this candidate.Required gates: linked explicit human approval of these impacts; compatible Ledger operator/CRDs, Connectivity CRDs and scoped-token Core; actual existing-key migration showing applied grants, ingestion/cursor progress and denial of unrelated privileges; authenticated API qualification; exercised recovery stating the Ledger operator/schema tuple. Ready/observedGeneration proves distribution, not applied grants. Rollback widens privileges and is version-skewed.
The release note includes a
LedgerCredentialsPendingincompatibility diagnostic (source-derived inference, not exercised) and the exact chart/image evidence still needed. Target is OVH sandbox through its owning GitOps path only; no manual cluster deployment. Stack/GitOps owner selection, final Regions pins and immutable artifact digests remain external qualification gates. AWS/prod is excluded.Schema inventory correction
The release note now contains all 35 removed schema property paths (parents and descendants).
monitoring.tracesitself remains present; only itssamplingsubtree is removed.persistence.data.accessModeretains its original type/default. Source comparison corrects broader textual-diff claims. The Infra owner reports zero explicit LedgerConfiguration objects; Settings, private Secret-backed valuesFrom, chart defaults and existing Cluster specs remain unqualified. The shared Flux CI validation contract is also uninspected. These limits do not waive migration/qualification gates.OVH compatibility hold — Infra checkpoint
The infrastructure owner independently inspected the live OVH Credentials CRD: cluster-scoped
v1alpha1, served/storage, with exactlyadditionalNamespaces,god,scopes, andselector;superuseris absent. Its read-only evidence packet is retained by the Infra lane. This is corroborating owner evidence, not a live inspection performed by the patch owner. Do not pin or qualify 3.16.1 against the current beta.1 operator/CRD tuple.The Ledger Operator release owner must be confirmed before any external activation or bump. Require independently proven controller image + served Credentials schema + Core credential format, and inventory removed LedgerConfiguration fields against effective OVH values without exposing secrets. The selected candidate retains key-mode Secret references; a request to verify credential formats does not add a bundle migration or new bundle capability. No manual deployment, CR/Secret mutation, GitOps merge/sync/reconciliation, or external pin change is part of this PR.
Review checkpoint
Head
7a760262e8c7baf38ec165a52e8b0d4f1d624d9bcompletes the Pyroscope Secret-reference migration procedure. The owner reply records exact-head independent doc review and finding disposition. Prior headccf152b0passed Tests, Dirty and all five Kubernetes E2E cells in run37600883537; those results do not transfer to the new head. Current-head CI is pending. No Slack communication; the PR remains draft under the compatibility/publication hold.Evidence
Before: v3.16.0 lacks #548/#544 and the charts lock operator-crds 3.16.0. After: the selected backports are present; the generated lock selects 3.16.1 and both rendered charts validate. Runtime/test qualification remains incomplete.
helm lint --strictandhelm templatefor both charts; rendered Operator image and utils versionv3.16.1;git diff --check; exclusion/path inventory and backport range-diff.no space left on device; no passing tests are claimed.just pre-commitcould not realize the SDK because local disk space was exhausted. Unit/envtest suite, Kubernetes matrix and exact-head PR CI remain gates.c9407e31: Principal/Product/SRE PASS for that disclosure only; affected inventory and Pyroscope procedure independently rechecked at7a760262: Principal/Product/SRE PASS for documentation accuracy only; it does not approve runtime correctness or publication.Merge Danger
Door: one-way for a deployed CRD/credential migration without separately verified recovery. Blast Radius: stacks. The PR itself only prepares an isolated candidate; deploying it can prune configuration and narrow grants. Human compatibility approval and real migration evidence remain mandatory.
Draft preparation only. No merge, tag, release, publication, deployment, sync, reconciliation or destructive operation is authorized. No
build-images/deploy-staginglabel or Slack review request.