Skip to content

Modernize node labeling, CRD validation and controller lifecycle - #6

Open
guilhem wants to merge 1 commit into
masterfrom
codex/refresh-2026-10
Open

guilhem wants to merge 1 commit into
masterfrom
codex/refresh-2026-10

Conversation

@guilhem

@guilhem guilhem commented Oct 2, 2026

Copy link
Copy Markdown
Member

Restore reproducible builds with Go modules, Kubernetes 0.37.1 and Kooper 2.10, replacing obsolete dep/Travis configuration and the checked-in vendor tree. Add an installer-managed apiextensions/v1 CRD, scoped runtime RBAC, deployment examples, reproducible client generation and CI.

Taints merge additively by key and effect, preserving existing values and system taints. Metadata is deduplicated, dry-run prevents writes, and editing or deleting a Labeler stops its obsolete controller. The structural CRD validates known ObjectMeta/NodeSpec fields so a malformed rule cannot poison typed informer decoding; broader merge fields and unknown extensions remain preserved.

Migration: install the CRD before starting the operator. Runtime credentials no longer manage CRDs or node status. Existing values win conflicts, including empty-string labels/annotations; previously applied attributes are not removed. Go 1.26+ and a built/loaded or published image are required.

Validation: Go 1.26.8 and 1.27.1 race tests, vet, module verification/tidy, reproducible generation, static build/help, schema validation/pruning tests, deployment/RBAC schema checks, actionlint and diff checks passed. Independent testing on an isolated Kubernetes 1.36.2 API server verified dry-run, actual node updates, taint preservation, resync idempotence and edit/delete/shutdown behavior. The malformed-field regression failed before the schema correction and passes afterward.

CI builds and smoke-checks the container without publishing it. No deployment to a real cluster or Kubernetes 1.37 runtime test was performed; the operator uses a single replica without leader election.

@guilhem

guilhem commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

@codex review

Please review HEAD 081b3d9e30dcdfe4d192099682ceb88ea7801f6e.

Objective: make this node-labeling operator maintainable and safely usable on current Kubernetes APIs.
Scope: pinned modules and regenerated clients, explicit installer-owned structural CRD, narrow runtime RBAC, additive taint merging, working dry-run and controller cancellation on edit/delete, documentation and CI. The large deletion is removal of the obsolete checked-in vendor tree.
Watch for: node mutation authority, first-wins conflict behavior, CRD typed decoding and unknown-field preservation, dry-run, shutdown races, and migration notes. Previously applied attributes remain; one replica is supported.
Validation: local Go1.26.8 and1.27.1 race tests/vet/module/build/generation checks passed, plus schema and manifest validation/actionlint. Independent isolated Kubernetes1.36.2 envtest verified node writes, taint preservation, dry-run, resync idempotence and lifecycle; final CRD rejected35 malformed rules while valid/null/extension rules decoded and worked. The original informer-poisoning failure was reproduced and corrected. No production cluster change or Kubernetes1.37 runtime test claimed. GitHub CI is pending, including image build/help smoke without publication.

@guilhem
guilhem marked this pull request as ready for review October 2, 2026 04:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant