Bumps the go-minor-and-patch group with 1 update in the /alerting directory: [github.com/jackc/pgx/v5](https://github.com/jackc/pgx). Bumps the go-minor-and-patch group with 2 updates in the /api directory: [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) and [golang.org/x/crypto](https://github.com/golang/crypto). Bumps the go-minor-and-patch group with 1 update in the /enterprise directory: [github.com/jackc/pgx/v5](https://github.com/jackc/pgx). Bumps the go-minor-and-patch group with 1 update in the /ingest directory: [github.com/jackc/pgx/v5](https://github.com/jackc/pgx). Updates `github.com/jackc/pgx/v5` from 5.10.0 to 5.11.0 - [Release notes](https://github.com/jackc/pgx/releases) - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](https://github.com/jackc/pgx/compare/v5.10.0...v5.11.0) Updates `github.com/jackc/pgx/v5` from 5.10.0 to 5.11.0 - [Release notes](https://github.com/jackc/pgx/releases) - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](https://github.com/jackc/pgx/compare/v5.10.0...v5.11.0) Updates `golang.org/x/crypto` from 0.56.0 to 0.57.0 - [Commits](https://github.com/golang/crypto/compare/v0.56.0...v0.57.0) Updates `github.com/jackc/pgx/v5` from 5.10.0 to 5.11.0 - [Release notes](https://github.com/jackc/pgx/releases) - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](https://github.com/jackc/pgx/compare/v5.10.0...v5.11.0) Updates `github.com/jackc/pgx/v5` from 5.10.0 to 5.11.0 - [Release notes](https://github.com/jackc/pgx/releases) - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](https://github.com/jackc/pgx/compare/v5.10.0...v5.11.0) --- updated-dependencies: - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-and-patch - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-and-patch - dependency-name: golang.org/x/crypto dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-and-patch - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-and-patch - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-and-patch ... Signed-off-by: dependabot[bot] <[email protected]>
deploy/operator
A small controller-runtime Operator managing one CRD: Tenant
(cairnobs.io/v1alpha1). See internal/controller/tenant_controller.go's
doc comment for exactly what it reconciles and -- just as importantly --
what it deliberately doesn't (no ClickHouse calls, no Tantivy filesystem
access, no enterprise/internal/rbacstore wiring; those are
enterprise/internal/tenantprovision, still unbuilt).
Not kubebuilder-scaffolded
No kubebuilder/controller-gen binary was available in this
environment, so this package is hand-written rather than generated:
api/v1alpha1/zz_generated.deepcopy.go-- normallycontroller-gen objectoutput; hand-written here, covered byapi/v1alpha1/api_test.go's round-trip tests (mutate a copy, assert the original is untouched -- exactly the class of bug a hand-writtenDeepCopyis prone to).config/crd/cairnobs.io_tenants.yaml-- normallycontroller-gen crdoutput from the+kubebuilder:validation:*markers onapi/v1alpha1/tenant_types.go; hand-written here and only as strong as keeping the two in sync by hand. Validated by strict-unmarshaling it into the realk8s.io/apiextensions-apiserverGo type (see/deploy/README.md's verification section) -- catches YAML/structural mistakes, not a drift between the CRD's field descriptions and the Go doc comments.+kubebuilder:rbacmarkers oninternal/controller/tenant_controller.goare present as documentation/intent (matching kubebuilder convention) but were never run throughcontroller-gen rbac-- the actual ClusterRole is hand-written in/deploy/helm/cairnobs/templates/tenant-operator.yaml, kept in sync with those markers by hand, same caveat as the CRD above.
Layout
api/v1alpha1/ Tenant, TenantSpec, TenantStatus -- the CRD's Go types
internal/controller/ TenantReconciler -- see its doc comment
cmd/tenant-operator/ main.go -- manager setup, matches every other
service's cmd/<name>/main.go convention in this repo
config/crd/ hand-written CRD YAML (see above)
Building & testing
go build ./...
go vet ./...
go test ./...
Tests use sigs.k8s.io/controller-runtime/pkg/client/fake, not
envtest -- envtest needs a real kube-apiserver/etcd binary pair
(setup-envtest) not available in this environment. The fake client
exercises real reconcile logic (object CRUD, owner references, status
writes) but not anything a real apiserver does for you (admission,
garbage collection, watch-triggered re-reconciliation) -- see
internal/controller/tenant_controller_test.go's doc comment.
docker build -f Dockerfile -t cairnobs-tenant-operator . # context is deploy/operator/, not the repo root
Not verified in this session -- see /deploy/README.md.
Trying it against a real cluster
kubectl apply -f config/crd/cairnobs.io_tenants.yaml
kubectl apply -f - <<'EOF'
apiVersion: cairnobs.io/v1alpha1
kind: Tenant
metadata:
name: acme
spec:
displayName: "Acme Corp"
EOF
kubectl get tenant acme -o yaml # status.phase should reach Active
kubectl get secret cairnobs-tenant-acme-clickhouse -o yaml