Skip to content

chore(data-products): deploy verified controller fixes - #4555

Merged
devantler merged 2 commits into
mainfrom
codex/dpc-v248-4554
Oct 6, 2026
Merged

devantler merged 2 commits into
mainfrom
codex/dpc-v248-4554

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

The platform is four patch releases behind the controller's completed reliability fixes, so users cannot benefit from those fixes yet.

What

Deploy the current reliability fixes across the registry, Harbour sample and independent product host. Keep the current product features and appearance settings.

Fixes #4554

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Release evidence for ed8d317, based on efbd632:

  • Release tag v2.4.8 resolves to source a990601e9edef1c43f5a08d9639d257e227b368c, the landing commit of data-product-controller#341.
  • Image digest: sha256:c40aa8ba8696cb93766d216e4fe2db64b66006a79faa36faf6a3834bf8978f9f. Chart digest: sha256:b55c91a55963ad9b5d2e3929991ef3ba8b2e05079c3003c2d9576f941d39b362. Independent Cosign checks succeed with the expected image publisher revision, chart-tag workflow, repository, release ref and exact source commit. The actual chart pull returns the same digest, with chart/app version 2.4.8.
  • Published-image run 37413628987, smoke job 112107976185, exercises the image by verified digest. It passes the offline exporter with default-off and invalid-input controls, TLS/gateway UI-host modes with contract off/on, explicit appearance grants and offline publisher preflight. The signed chart publisher also succeeds in run 37413628371.
  • The exact Flux 2.8.8 / Helm 4.2.0 SDK guard pulls and renders the changed chart and applies its platform post-renderers in install and upgrade modes. The disruption-budget guard checks both cluster profiles; each of the three product budgets selects its intended workload. The existing trial regression preserves SSO, stripped browser credentials, scoped component policies and recovery validation.
  • A separate effective chart-and-patch render produces the controller, Harbour and portable-host Deployments with two replicas each and the same immutable image digest. Literal checks verify the actual sample identity, query, contract and UI URLs. Feature values, CRD, API, RBAC, network boundaries and post-renderers are unchanged; the only chart-schema difference since the deployed release further rejects interpolation syntax in the optional HTTP source URL.
  • Both required KSail static validation commands exit 0 and identify the changed application layer. Their embedded Helm rendering reports host-local credential-helper/cache warnings and skips some chart renders, including this OCI release. Those skipped renders are not treated as proof: the independent controller-SDK guard above actually pulled and rendered this exact chart successfully. Hosted manifest, policy, quality and publication checks remain required at this PR head.
  • The diff remains three immutable release-pin updates after a signed integration of current main. The published PR body passes the native template check. No feature flag is enabled and no provider credentials are read.

Before queue entry, require settled current-head CI and substantive review. The production merge group must verify actual current deployments/pods/routes and public application behavior; this comment does not claim deployment. Rollback is the previous reviewed immutable chart/image pair, restored together through normal GitOps.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 47 minutes.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 47 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f19eb395-9c45-456e-86bb-c67fdc327afa
📥 Commits

Reviewing files that changed from the base of the PR and between efbd632 and ed8d317.

📒 Files selected for processing (3)
  • k8s/bases/apps/data-product-controller/deployment-ui-kit.yaml
  • k8s/bases/apps/data-product-controller/helm-release.yaml
  • k8s/bases/apps/data-product-controller/oci-repository.yaml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: ed8d317
Reviewed base: efbd632
Availability observed: 2026-10-06 04:52 UTC, using direct authenticated provider responses and the complete current-PR artifact intake.

  • CodeRabbit: the current-head Platform request at 04:47:36 UTC returned a repository-specific included-review limit. Its summary, updated 04:47:51 UTC, names this exact base/head and three selected files, with a 47-minute reset (about 05:34:51 UTC). The quota status is a service response, not a review verdict.
  • Codex: its authenticated account-wide usage-limit response, created/updated 04:40:17 UTC, remains unchanged on fresh read. No reset is stated; recovery requires account limits to reset or a maintainer account change. No paid credits are authorized.
  • Cursor Bugbot: its authenticated user/team usage-limit response, created/updated 04:42:02 UTC, remains unchanged on fresh read. Recovery requires a user/team usage reset or an administrator change; no paid increase is authorized.

The complete current-PR intake contains four conversation comments, zero review objects and zero review threads, with no remaining pages. Its current-head check list contains no Bugbot run or provider finding. There is no hidden actionable review being discarded. All three lanes are currently unavailable, so the repository's local-review fallback applies without waiting for the quota window.

Correctness and security review:

  • I reviewed the entire three-file diff. It keeps the Helm-managed controller, Harbour application and independent portable host on the same immutable image, and pins the matching chart digest. The release tag resolves to the actual merged controller source.
  • Independent signature verification binds both artifacts to the expected issuer, repository, release ref, exact source commit and intended publishing workflow identities. The actual chart reports chart/app version 2.4.8 and supports the platform's Kubernetes version.
  • I checked the effective rendered workloads, published-image smoke evidence and exact Flux-controller SDK install/upgrade post-renderer evidence. All three workloads retain two replicas, existing restrictive security settings, public UI origins and explicit grants. The disruption budgets still select their intended workloads.
  • CRD, API/RBAC, persistence and routing contracts are unchanged. No adoption feature is enabled. The inactive HTTP-source schema adjustment rejects interpolation syntax. The update introduces no persistence migration.
  • The ordinary rollback restores the previous reviewed immutable chart/image pair together; the existing merge-group restoration of current main remains intact. No deployment script or shared production control is changed.
  • A separate independent read-only audit at this exact head reached the same clean verdict after its own artifact signature verification.

Limits: the two local KSail commands include skipped chart renders, which I do not count as complete render evidence; the independent controller-SDK guard actually pulled and rendered this chart. This review does not claim a deployed-runtime result. Hosted CI must settle at this head, and the production merge group must verify the actual rollout before merge.

Verdict: no P0/P1 findings

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Ready for normal protected queue entry at ed8d317.

  • All 33 reported current-head contexts are settled success/skipped. The CI run and required-check aggregate pass, including hosted manifests, policy/security guards, exact-chart post-rendering, disruption-budget selectors and consumer-discovery regressions. The three effective organization workflow requirements each pass.
  • Complete current-PR review/comment/thread intake has no remaining pages, zero unresolved threads and no actionable findings. The permitted fallback review is clean at this exact head; its authenticated, scoped three-provider quota evidence is recorded there. CodeRabbit's quota status is not counted as a review.
  • Signed release/source binding, published-image behavior and effective platform configuration are verified in the earlier evidence record. Local skipped-render warnings are retained as limitations, rather than counted as render proof.
  • Fresh authenticated main is c8d5857. Its change since the integrated base only tightens the Kyverno fixture evaluator and its regression; there is no data-product application overlap. The current PR patch still consists of only the three release pins. The normal merge group must retain that main repair and validate the combined revision.
  • The local holder check reports only this task's own process chain. The exact head and live base were freshly rebound before this readiness write.
  • The required-gate helper reports the managed Code Quality rule as UNVERIFIED, because its head analysis is not exposed through a readable API. This is not described as COMPLETE. GitHub reports CLEAN; normal protected queue entry remains the authority for that rule, without bypass or administrator merge.

The production merge group must still establish actual current deployment/pod/route identities and public application behavior. Queue entry is not a deployed-runtime claim.

@devantler
devantler marked this pull request as ready for review October 6, 2026 05:23
@devantler
devantler added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 0dce6fe Oct 6, 2026
33 checks passed
@devantler
devantler deleted the codex/dpc-v248-4554 branch October 6, 2026 09:09
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Release v2.4.8 is actually deployed. This PR merged at 0dce6fef66e4ed6e51d781624131ccf0231ef6a8 on 2026-10-06T09:08:57Z from the reviewed head ed8d31739194c6a26c524fcb4e9db91eb5997483.

Protected CI 37438356284 and production job 112188579333 succeeded for that exact merge-group commit. The deployed commit's three release pins match the independently verified image sha256:c40aa8ba8696cb93766d216e4fe2db64b66006a79faa36faf6a3834bf8978f9f and chart sha256:b55c91a55963ad9b5d2e3929991ef3ba8b2e05079c3003c2d9576f941d39b362. The actual rollout verifier completed at 09:08:20Z with complete=true, three deployments, six pods, three routes and nine public checks. It verified current workload/route identities and the selected immutable image's runtime manifests; this is this release's receipt.

Post-deployment browser acceptance passed on both the catalogue and the independent host: two synthetic observation rows, one row when filtering Nordhavn, connected v2 interface, explicit presentation grants, light/dark propagation into the frame, query retention across theme changes and dark preference persistence after reload. Explicit Close hides the portable frame and removes its URL. Both frames retain the opaque allow-forms allow-scripts sandbox. Original preferences and the older host's empty input/grants were restored.

Browser tooling could not deliver the attempted keyboard command and could not attach a new tab. Acceptance used native controls and the existing owned test tab; no manual keyboard or pixel/screen-reader result is claimed. Hosted browser regressions and published-image tests remain the separate automated evidence.

This completes #4554. Feature/adoption gates remain unchanged. The managed Code Quality detail is still UNVERIFIED through its API; normal protected queue enforcement was used without a bypass. The separate ARC recovery in #4544 remains a named operational HOLD, so this controller delivery does not claim platform-wide health.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

Deploy the verified controller patch to the registry and both product hosts

1 participant