Repository navigation
docs(nexus-pdp): the image is permitio/nexus-pdp, not permitio/pdp-v3 - #657
Conversation
cloud-pdp#157 (PER-16042) publishes the Nexus PDP image as permitio/nexus-pdp only; the old repository is frozen. Merge before, or with, the first cloud-pdp release after #157 merges. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
✅ Deploy Preview for permitio-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
zeevmoney
left a comment
There was a problem hiding this comment.
Changes requested — 1 HIGH, 1 MEDIUM, 2 LOW.
Blocking:
- HIGH
docs/concepts/pdp/nexus-pdp-deployment.mdx:35—PDP_API_KEYmust be the Nexus PDP API key, not the ordinary environment API key (same claim at lines 13, 23, 48 andnexus-pdp-configuration.mdx:20)
Non-blocking:
- MEDIUM
docs/concepts/pdp/nexus-pdp-deployment.mdx:43—permitio/nexus-pdphas no release tag on Docker Hub yet - LOW
docs/concepts/pdp/nexus-pdp-deployment.mdx:22— the "unpinned" consequence assumes alatesttag thatpermitio/nexus-pdpdoes not have - LOW
docs/concepts/pdp/nexus-pdp.mdx:14— no pointer for readers already runningpermitio/pdp-v3
Outside the diff (not posted inline):
- LOW
static/images/pdp/nexus-pdp-architecture.svg:38— the diagram's title, description and container label still say "New Edge PDP"
Details are in the inline comments on each line.
- PDP_API_KEY is the environment's Nexus PDP API key (Copy Nexus PDP API Key in the dashboard), not the ordinary environment API key, which fails at startup: prerequisites, requirements table, Docker and pod-spec intros, and the configuration reference. - permitio/nexus-pdp has no latest tag and no release tag yet: the image row now warns about moving tags such as 0-beta, and the Docker step says to pin an exact tag. - New 'Image name and tags' section on the overview: releases up to 0.6.1 are permitio/pdp-v3, which gets no new tags; don't reuse a pdp-v3 tag name under nexus-pdp. - The architecture diagram says Nexus PDP, not New Edge PDP. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks Zeev. All four threads are addressed in 083fed8 and resolved. The one outside the diff: I also merged current |
zeevmoney
left a comment
There was a problem hiding this comment.
Changes requested — 1 HIGH, 2 MEDIUM, 2 LOW.
Blocking:
- HIGH
docs/concepts/pdp/nexus-pdp-deployment.mdx:13— services that query Nexus PDP are still told to send the environment API key (also lines 89 and 157,nexus-pdp-feature-parity.mdx:16,overview.mdx:378)
Non-blocking:
- MEDIUM
docs/concepts/pdp/nexus-pdp-deployment.mdx:22— numbered beta tags are exact but not immutable - MEDIUM
docs/concepts/pdp/nexus-pdp-configuration.mdx:20— the production dashboard doesn't show Copy Nexus PDP API Key yet (same label atnexus-pdp-deployment.mdx:13) - LOW
docs/concepts/pdp/nexus-pdp-deployment.mdx:48— the pod-spec intro doesn't name the secret'sPDP_API_KEYkey - LOW
docs/concepts/pdp/nexus-pdp-configuration.mdx:11— the configuration caution still allows a moving tag
Still open from the previous review:
- HIGH
docs/concepts/pdp/nexus-pdp-deployment.mdx:35(earlierPDP_API_KEYthread) — the container side is fixed; the caller side is still open and is raised with line references in the HIGH comment atnexus-pdp-deployment.mdx:13.
Details are in the inline comments on each line.
- Callers: services that query Nexus PDP send the Nexus PDP API key as their SDK token; the environment API key gets 401. Said in the prerequisites, the verify step, the request-authentication section, the feature-parity page and the AuthZen section. Permit API calls use a separate SDK client with the environment API key. - Tags are not immutable (Docker Hub immutability is off, and numbered beta names can be republished), so the docs pin by digest and show how to read it. - The dashboard label is the one production shows today, Copy PDP v3 API Key, until the frontend rename is deployed. - The pod-spec intro names the secret's PDP_API_KEY key and gives the kubectl command; the configuration caution points at Image name and tags. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks Zeev, round 2 is addressed in 28498fa, and all threads are replied to and resolved. I verified each point before changing it: the bearer check in |
zeevmoney
left a comment
There was a problem hiding this comment.
Approved — no CRITICAL or HIGH issues found.
Non-blocking:
- MEDIUM
docs/concepts/pdp/nexus-pdp-deployment.mdx:13— the Permit API accepts the Nexus PDP API key, so the separatepermit.apiclient isn't needed (this also contradictsnexus-pdp-feature-parity.mdx:16) - LOW
docs/concepts/pdp/nexus-pdp.mdx:26— the digest step prints several digests, the printed value already starts withsha256:, and0-betadoesn't move on dev builds - LOW
docs/concepts/pdp/nexus-pdp-configuration.mdx:20— date the dashboard label ("As of September 2026") rather than calling it "current" (same atnexus-pdp-deployment.mdx:13)
Outside this PR's diff (not blocking, for a follow-up):
- MEDIUM
docs/concepts/pdp/overview.mdx:380— the AuthZen error codes don't hold on Nexus PDP. A missing or wrong bearer token gets401with the JSON body{"message":"Unauthorized"}, not the AuthZen codeunauthorized, and a request missing a required field gets422, not400invalid_request. Line 378 of this PR now points Nexus PDP readers at this section. - LOW
docs/overview/get-api-key.mdx:9and the check, user-permissions and authorized-users how-tos underdocs/how-to/enforce-permissions/still say the PDP takes the environment API key, and none of them mentions the Nexus PDP API key. The feature-parity page links to these how-tos as supported Nexus PDP endpoints.
Details are in the inline comments on each line.
- The Permit API accepts the Nexus PDP API key with the same access as the environment API key (PER-15400), so one SDK client serves both; protect the key like the environment key (prerequisites, request authentication, configuration reference). - Digest step prints only the multi-platform index digest, explains the sha256: prefix, and 0-beta moves on beta or release builds only. - Date the dashboard label: As of September 2026 it is Copy PDP v3 API Key, in the user menu and environment card menu, and needs edit permission. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
Renames the Nexus PDP image in the public docs from
permitio/pdp-v3topermitio/nexus-pdp, on six pages:nexus-pdp.mdx,nexus-pdp-deployment.mdx,nexus-pdp-configuration.mdx,nexus-pdp-feature-parity.mdx,nexus-pdp-how-it-works.mdxandoverview.mdx.permitio/pdp-v2references are untouched.After Zeev's review, it also:
PDP_API_KEYis the environment's Nexus PDP API key (Copy Nexus PDP API Key in the dashboard's user menu, once Nexus PDP is activated for the environment). The ordinary environment API key doesn't work: the container fails at startup. This is fixed in the prerequisites, the requirements table, the Docker and pod-spec intros (the shell variable is nowNEXUS_PDP_API_KEYand the secret isnexus-pdp-api-key), and the configuration reference.permitio/nexus-pdphas nolatesttag, so the image row now warns about moving tags such as0-beta, and the Docker step says to pin an exact tag.permitio/pdp-v3, which gets no new tags. Readers upgrading from it switch topermitio/nexus-pdp, and shouldn't reuse apdp-v3tag name, because some names point to different images in the two repositories.static/images/pdp/nexus-pdp-architecture.svg) from "New Edge PDP" to "Nexus PDP".Why
permitio/cloud-pdp#157 (PER-16042) made CI publish the edge image to
permitio/nexus-pdponly.permitio/pdp-v3is frozen: its existing tags still resolve, but it gets no new builds.Merge timing
As of 2026-09-30,
permitio/nexus-pdphas no release (x.y.z) tag yet, only numbered betas such as0.7.0-beta.12and moving beta tags. The pages no longer point readers at a release tag that doesn't exist. They say which repository holds which releases and tell readers to pin an exact tag. So this PR can merge before the firstnexus-pdprelease.Update (2026-09-30): Zeev's second review
token, and the environment API key gets401(confirmed in cloud-pdpedge-pdp/src/auth.rs). This is fixed in the prerequisites, the verify step, request authentication, the feature-parity page and the AuthZen section. A service that also calls the Permit API uses a separate SDK client with the environment API key.permitio/nexus-pdp, and a numbered beta name can be republished (0.7.0-beta.6already differs betweenpdp-v3andnexus-pdp). The pages showpermitio/nexus-pdp@sha256:<digest>and how to read the digest withdocker buildx imagetools inspect.PDP_API_KEYkey and gives thekubectl create secretcommand.Follow-up after merge: the dashboard label
Production's dashboard still shows Copy PDP v3 API Key, because the frontend rename (permit-frontend#1575) hasn't been deployed to production.
nexus-pdp-deployment.mdx(Prerequisites) andnexus-pdp-configuration.mdx(PDP_API_KEY) name that label. Once the rename reaches production, change both to Copy Nexus PDP API Key.Update (2026-09-30): Zeev's approving review
permit.api, and that the key needs the same protection.--format '{{.Manifest.Digest}}') and explains thesha256:prefix.0-betamoves on beta and release builds only.Follow-ups outside this PR (from Zeev's review)
docs/concepts/pdp/overview.mdxAuthZen section: on Nexus PDP, a missing or wrong token gets401with{"message":"Unauthorized"}(not the AuthZenunauthorizedcode), and a missing required field gets422(not400invalid_request).docs/overview/get-api-key.mdxand the check, user-permissions and authorized-users how-tos underdocs/how-to/enforce-permissions/still say the PDP takes the environment API key, and none mentions the Nexus PDP API key.Checks
npm run buildpasses: redirect lint, relative links, Docusaurus build, 0 bad links and 0 bad anchors, all 525 routes resolve, and sidebar coverage is OK. The branch is merged up to currentmaster.🤖 Generated with Claude Code