Skip to content

docs(nexus-pdp): the image is permitio/nexus-pdp, not permitio/pdp-v3 - #657

Merged
EliMoshkovich merged 5 commits into
masterfrom
eli/per-16042-nexus-pdp-image-name
Sep 30, 2026
Merged

EliMoshkovich merged 5 commits into
masterfrom
eli/per-16042-nexus-pdp-image-name

Conversation

@EliMoshkovich

@EliMoshkovich EliMoshkovich commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Renames the Nexus PDP image in the public docs from permitio/pdp-v3 to permitio/nexus-pdp, on six pages: nexus-pdp.mdx, nexus-pdp-deployment.mdx, nexus-pdp-configuration.mdx, nexus-pdp-feature-parity.mdx, nexus-pdp-how-it-works.mdx and overview.mdx. permitio/pdp-v2 references are untouched.

After Zeev's review, it also:

  • Names the right key. PDP_API_KEY is the environment's Nexus PDP API key (Copy Nexus PDP API Key in the dashboard's user menu, once Nexus PDP is activated for the environment). The ordinary environment API key doesn't work: the container fails at startup. This is fixed in the prerequisites, the requirements table, the Docker and pod-spec intros (the shell variable is now NEXUS_PDP_API_KEY and the secret is nexus-pdp-api-key), and the configuration reference.
  • Explains the tags. permitio/nexus-pdp has no latest tag, so the image row now warns about moving tags such as 0-beta, and the Docker step says to pin an exact tag.
  • Adds an "Image name and tags" section on the overview. Releases up to 0.6.1 are permitio/pdp-v3, which gets no new tags. Readers upgrading from it switch to permitio/nexus-pdp, and shouldn't reuse a pdp-v3 tag name, because some names point to different images in the two repositories.
  • Renames the architecture diagram (static/images/pdp/nexus-pdp-architecture.svg) from "New Edge PDP" to "Nexus PDP".

Why

permitio/cloud-pdp#157 (PER-16042) made CI publish the edge image to permitio/nexus-pdp only. permitio/pdp-v3 is frozen: its existing tags still resolve, but it gets no new builds.

Merge timing

As of 2026-09-30, permitio/nexus-pdp has no release (x.y.z) tag yet, only numbered betas such as 0.7.0-beta.12 and moving beta tags. The pages no longer point readers at a release tag that doesn't exist. They say which repository holds which releases and tell readers to pin an exact tag. So this PR can merge before the first nexus-pdp release.

Update (2026-09-30): Zeev's second review

  • Callers send the Nexus PDP API key. Services that query Nexus PDP use it as their SDK token, and the environment API key gets 401 (confirmed in cloud-pdp edge-pdp/src/auth.rs). This is fixed in the prerequisites, the verify step, request authentication, the feature-parity page and the AuthZen section. A service that also calls the Permit API uses a separate SDK client with the environment API key.
  • Pin by digest. Docker Hub tag immutability is off on permitio/nexus-pdp, and a numbered beta name can be republished (0.7.0-beta.6 already differs between pdp-v3 and nexus-pdp). The pages show permitio/nexus-pdp@sha256:<digest> and how to read the digest with docker buildx imagetools inspect.
  • Pod spec. The intro names the secret's PDP_API_KEY key and gives the kubectl create secret command.
  • Configuration caution. It points at "Image name and tags" instead of "a specific tag".

Follow-up after merge: the dashboard label

Production's dashboard still shows Copy PDP v3 API Key, because the frontend rename (permit-frontend#1575) hasn't been deployed to production. nexus-pdp-deployment.mdx (Prerequisites) and nexus-pdp-configuration.mdx (PDP_API_KEY) name that label. Once the rename reaches production, change both to Copy Nexus PDP API Key.

Update (2026-09-30): Zeev's approving review

  • The Permit API accepts the Nexus PDP API key with the same access as the environment API key (PER-15400). The pages now say one SDK client serves both checks and permit.api, and that the key needs the same protection.
  • The digest step prints only the multi-platform index digest (--format '{{.Manifest.Digest}}') and explains the sha256: prefix. 0-beta moves on beta and release builds only.
  • The dashboard label is dated ("As of September 2026 … Copy PDP v3 API Key", which needs edit permission on the environment).

Follow-ups outside this PR (from Zeev's review)

  • docs/concepts/pdp/overview.mdx AuthZen section: on Nexus PDP, a missing or wrong token gets 401 with {"message":"Unauthorized"} (not the AuthZen unauthorized code), and a missing required field gets 422 (not 400 invalid_request).
  • docs/overview/get-api-key.mdx and the check, user-permissions and authorized-users how-tos under docs/how-to/enforce-permissions/ still say the PDP takes the environment API key, and none mentions the Nexus PDP API key.

Checks

npm run build passes: redirect lint, relative links, Docusaurus build, 0 bad links and 0 bad anchors, all 525 routes resolve, and sidebar coverage is OK. The branch is merged up to current master.

🤖 Generated with Claude Code

cloud-pdp#157 (PER-16042) publishes the Nexus PDP image as
permitio/nexus-pdp only; the old repository is frozen. Merge before, or
with, the first cloud-pdp release after #157 merges.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 23, 2026 20:56
@netlify

netlify Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for permitio-docs ready!

Name Link
🔨 Latest commit 2913d96
🔍 Latest deploy log https://app.netlify.com/projects/permitio-docs/deploys/6abd2e191732da000839fad9
😎 Deploy Preview https://deploy-preview-657--permitio-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@linear-code

linear-code Bot commented Sep 23, 2026

Copy link
Copy Markdown

PER-16042

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@EliMoshkovich
EliMoshkovich requested review from omer9564 and zeevmoney and removed request for zeevmoney September 23, 2026 21:40

@zeevmoney zeevmoney left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — 1 HIGH, 1 MEDIUM, 2 LOW.

Blocking:

  • HIGH docs/concepts/pdp/nexus-pdp-deployment.mdx:35 — PDP_API_KEY must be the Nexus PDP API key, not the ordinary environment API key (same claim at lines 13, 23, 48 and nexus-pdp-configuration.mdx:20)

Non-blocking:

  • MEDIUM docs/concepts/pdp/nexus-pdp-deployment.mdx:43 — permitio/nexus-pdp has no release tag on Docker Hub yet
  • LOW docs/concepts/pdp/nexus-pdp-deployment.mdx:22 — the "unpinned" consequence assumes a latest tag that permitio/nexus-pdp does not have
  • LOW docs/concepts/pdp/nexus-pdp.mdx:14 — no pointer for readers already running permitio/pdp-v3

Outside the diff (not posted inline):

  • LOW static/images/pdp/nexus-pdp-architecture.svg:38 — the diagram's title, description and container label still say "New Edge PDP"

Details are in the inline comments on each line.

Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp.mdx
EliMoshkovich and others added 2 commits September 30, 2026 08:54
- PDP_API_KEY is the environment's Nexus PDP API key (Copy Nexus PDP API
  Key in the dashboard), not the ordinary environment API key, which
  fails at startup: prerequisites, requirements table, Docker and pod-spec
  intros, and the configuration reference.
- permitio/nexus-pdp has no latest tag and no release tag yet: the image
  row now warns about moving tags such as 0-beta, and the Docker step says
  to pin an exact tag.
- New 'Image name and tags' section on the overview: releases up to 0.6.1
  are permitio/pdp-v3, which gets no new tags; don't reuse a pdp-v3 tag
  name under nexus-pdp.
- The architecture diagram says Nexus PDP, not New Edge PDP.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 30, 2026 13:57
@EliMoshkovich

Copy link
Copy Markdown
Contributor Author

Thanks Zeev. All four threads are addressed in 083fed8 and resolved. The one outside the diff: static/images/pdp/nexus-pdp-architecture.svg now says Nexus PDP instead of "New Edge PDP" in the title, description, container label and every node tooltip (29 occurrences; still valid XML).

I also merged current master into the branch. npm run build passes: 0 bad links, 0 bad anchors, all 525 routes, sidebar coverage OK. The PR description is updated, including the merge-timing note.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@zeevmoney zeevmoney left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — 1 HIGH, 2 MEDIUM, 2 LOW.

Blocking:

  • HIGH docs/concepts/pdp/nexus-pdp-deployment.mdx:13 — services that query Nexus PDP are still told to send the environment API key (also lines 89 and 157, nexus-pdp-feature-parity.mdx:16, overview.mdx:378)

Non-blocking:

  • MEDIUM docs/concepts/pdp/nexus-pdp-deployment.mdx:22 — numbered beta tags are exact but not immutable
  • MEDIUM docs/concepts/pdp/nexus-pdp-configuration.mdx:20 — the production dashboard doesn't show Copy Nexus PDP API Key yet (same label at nexus-pdp-deployment.mdx:13)
  • LOW docs/concepts/pdp/nexus-pdp-deployment.mdx:48 — the pod-spec intro doesn't name the secret's PDP_API_KEY key
  • LOW docs/concepts/pdp/nexus-pdp-configuration.mdx:11 — the configuration caution still allows a moving tag

Still open from the previous review:

  • HIGH docs/concepts/pdp/nexus-pdp-deployment.mdx:35 (earlier PDP_API_KEY thread) — the container side is fixed; the caller side is still open and is raised with line references in the HIGH comment at nexus-pdp-deployment.mdx:13.

Details are in the inline comments on each line.

Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-configuration.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-configuration.mdx Outdated
- Callers: services that query Nexus PDP send the Nexus PDP API key as their
  SDK token; the environment API key gets 401. Said in the prerequisites,
  the verify step, the request-authentication section, the feature-parity
  page and the AuthZen section. Permit API calls use a separate SDK client
  with the environment API key.
- Tags are not immutable (Docker Hub immutability is off, and numbered beta
  names can be republished), so the docs pin by digest and show how to read
  it.
- The dashboard label is the one production shows today, Copy PDP v3 API
  Key, until the frontend rename is deployed.
- The pod-spec intro names the secret's PDP_API_KEY key and gives the
  kubectl command; the configuration caution points at Image name and tags.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 30, 2026 14:51
@EliMoshkovich

Copy link
Copy Markdown
Contributor Author

Thanks Zeev, round 2 is addressed in 28498fa, and all threads are replied to and resolved. I verified each point before changing it: the bearer check in edge-pdp/src/auth.rs, Docker Hub immutability and the 0.7.0-beta.6 digests, and the frontend's last production deploy (09-28, before #1575). npm run build: 0 bad links, 0 bad anchors. The PR description has the update and a follow-up note for the dashboard label.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@zeevmoney zeevmoney left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved — no CRITICAL or HIGH issues found.

Non-blocking:

  • MEDIUM docs/concepts/pdp/nexus-pdp-deployment.mdx:13 — the Permit API accepts the Nexus PDP API key, so the separate permit.api client isn't needed (this also contradicts nexus-pdp-feature-parity.mdx:16)
  • LOW docs/concepts/pdp/nexus-pdp.mdx:26 — the digest step prints several digests, the printed value already starts with sha256:, and 0-beta doesn't move on dev builds
  • LOW docs/concepts/pdp/nexus-pdp-configuration.mdx:20 — date the dashboard label ("As of September 2026") rather than calling it "current" (same at nexus-pdp-deployment.mdx:13)

Outside this PR's diff (not blocking, for a follow-up):

  • MEDIUM docs/concepts/pdp/overview.mdx:380 — the AuthZen error codes don't hold on Nexus PDP. A missing or wrong bearer token gets 401 with the JSON body {"message":"Unauthorized"}, not the AuthZen code unauthorized, and a request missing a required field gets 422, not 400 invalid_request. Line 378 of this PR now points Nexus PDP readers at this section.
  • LOW docs/overview/get-api-key.mdx:9 and the check, user-permissions and authorized-users how-tos under docs/how-to/enforce-permissions/ still say the PDP takes the environment API key, and none of them mentions the Nexus PDP API key. The feature-parity page links to these how-tos as supported Nexus PDP endpoints.

Details are in the inline comments on each line.

Comment thread docs/concepts/pdp/nexus-pdp-deployment.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp.mdx Outdated
Comment thread docs/concepts/pdp/nexus-pdp-configuration.mdx Outdated
- The Permit API accepts the Nexus PDP API key with the same access as the
  environment API key (PER-15400), so one SDK client serves both; protect the
  key like the environment key (prerequisites, request authentication,
  configuration reference).
- Digest step prints only the multi-platform index digest, explains the
  sha256: prefix, and 0-beta moves on beta or release builds only.
- Date the dashboard label: As of September 2026 it is Copy PDP v3 API Key,
  in the user menu and environment card menu, and needs edit permission.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 30, 2026 15:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@EliMoshkovich
EliMoshkovich merged commit 5386067 into master Sep 30, 2026
4 of 5 checks passed
@EliMoshkovich
EliMoshkovich deleted the eli/per-16042-nexus-pdp-image-name branch September 30, 2026 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants