feat(bridge): import the complete optional Kars Bridge application - #563
Draft
Pal Lakatos-Toth (pallakatos) wants to merge 178 commits into
Draft
feat(bridge): import the complete optional Kars Bridge application#563Pal Lakatos-Toth (pallakatos) wants to merge 178 commits into
Pal Lakatos-Toth (pallakatos) wants to merge 178 commits into
Conversation
Preserve optional standalone behavior and isolate GitHub App credentials by exact identity, installation and repository. Include governed Actions logs and reviewed gzip/permission repairs. Local Rust/runtime qualification and bounded automated closure are complete; operator materialization, SRE privacy-gate integration and full acceptance remain explicit blockers. This is a local checkpoint, not public readiness or deployment. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Local, unpublished implementation checkpoint. Rust and real API qualification remain pending; the operator observation and GitHub issuer seams require the approved privacy integration. No release or security sign-off is implied. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward merge 7dc7281 locally for downstream issuer integration. Candidate qualification is still pending; no public push or sign-off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Retain explicit unqualified lifecycle, UID and privacy blockers; this local checkpoint is not a publication or sign-off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact d3dc3ce and reuse its mount helper once. Existing privacy ancestor 7dc7281 remains intact. Combined issuer and observer Rust qualification and recorded authority/lifecycle closures remain pending; no publication or sign-off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep the reviewed runtime JSON schema unchanged. Rotate the private Secret and cached consumers for changed source/authority revisions even when material bytes are identical; preserve typed Pending privacy non-issuance. Add unrun Rust regressions and canonical App ID serialization. Combined Cargo qualification and recorded boundary closures remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact 068ae16 while retaining GitHub d3dc3ce and issuer rotation repairs. The offered Cargo lease was released unused before this prerequisite merge. Eleven read-only bootstrap fixtures and nineteen credential CLI/schema tests pass; combined Rust qualification and documented boundary closures remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use read-only preflight before ordinary Ready without a self-bootstrap cycle. Preserve status lineage and pause UID-owned governed execution instead of deleting namespace/state. Keep optional observer availability independent of source readiness and prevent retired GitHub projections from returning through the legacy optional mount. Twenty fast tests and CLI types pass; new Rust regressions remain unrun. No Cargo lease held or publication approval claimed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Retain valid delivery after writer retirement, protect enrolled reader names, and add explicit observer egress and purpose boundaries. Active-SRE observation privacy remains an explicit architecture blocker; no rollout is authorized. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward public 550 at 2d85d5a without copying private implementation. Keep credential candidate scope and standalone behavior intact; qualification is recorded separately. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record the public 550 forward, guarded Rust results, explicit lease release and remaining privacy/API qualification boundaries without claiming native Secret GET is UID-aware. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Verify current canonical observation credentials and full privacy authority on every bounded TLS request. Bind proofs to target, grant, recipient identities, purpose, version, scope and nonce; pin live verifier identity, expire credentials and gate readiness on real capability. Retain name-hold lifecycle guards and standalone defaults. Core qualification passed; real Kind/CNI, private BFF Rust and independent review remain required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Repair ordered-mask attenuation, persistent import removal intent, local legacy discovery failures and referenced-credential rollout revisions. Replace Team credential unlaunch with owned pause/quiescence, current authority/receipt regeneration and fenced resume. Add focused API/full-reconcile regressions. Fast checks pass; core Rust qualification and bounded re-review remain required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Apply the three explicitly approved compile corrections: point to the rebind tests, expose the unchanged runtime hold function at intended module scope, and import ListParams. Reviewed behavioral bodies are unchanged; private BFF is untouched. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Complete the approved test-module wiring correction without changing test or production behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use a lexical MutexGuard scope instead of explicit drop and collapse the equivalent CAS predicate in the API fixture. No production or test assertions changed; no lint waivers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record the approved mechanical corrections, passing targeted semantics and strict paired Clippy, immutable qualified code head, explicit Cargo lease release and remaining independent/private acceptance gates. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use the existing full SHA-256 provider boundary for controller revisions, GitHub connection names and shared observation proof digests. Preserve the full 64-hex proof/revision contract and 16-hex connection suffix; do not use the truncated content identifier. Add a fixed wire digest regression and update the fixture without adding dependencies or crypto waivers. 32 affected cases and strict paired Clippy pass under the 8.5 GiB floor. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…urce gates The production GitHub service now opens only its literal mounted configuration path; mutable path injection exists solely in test code, sharing the same bounded reader. No HTTP/configuration input can select another production file. Preserve credential rotation behavior and normal test fixtures. Extract the unchanged suspend/rebind replica decision into its owner module and cover all combinations, keeping the existing reconciler cap. Apply the full existing formatter instead of waiving CI. Affected tests, production binary checks, paired strict Clippy and the real cap/schema regression pass. No CodeQL alert is dismissed or query excluded. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep exact namespace UID checks using the actual Kubernetes JSON field despite the CEL NamespaceMetadata declaration mismatch. Add a native hosted positive/negative/positive probe using unchanged shipped predicates and owned fixtures, with precise denial assertions and bounded cleanup. Preserve bounded credential/GitHub schemas in generated Task/Team CRDs, compare rendered Helm includes, and add canonical grant CEL and standard labels. Local qualification: 30 Helm drift, 17 CNCF, 84 controller credential, 16 CLI contract and 53 Python harness cases; strict paired Clippy/fmt. Native API execution and complete hosted qualification remain pending. No audit signature or gate waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ures Replace the controller probe bytes_stream dependency with Response::chunk, preserving bounded buffering and explicit transport/JSON failure. Full paired builds masked the missing reqwest stream feature in controller-only benchmark compilation (job102638710681 at f8d641f). Add exact-limit, oversize, truncated-body-after-valid-JSON and invalid-JSON HTTP regressions. This is a LOCAL checkpoint: Rust execution and isolated-controller compilation are pending the exclusive composition qualification owner; no public push or benchmark waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Combine Secret key lists rather than heterogeneous byte/string value maps; compare the nullable paused envelope digest dynamically; and dynamically select kind-specific exposure fields behind unchanged kind guards. Keep every UID, purpose, current-generation, Ready=False, selector, resource, denial and Fail/Deny constraint. The broader native API run against f8d641f exposed these type-check warnings; 17 CLI contract cases and Helm rendering pass for the repair. Native positive/negative cases are being added separately and remain required. No warning suppression or audit waiver; local checkpoint only. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use unchanged rendered predicates in uniquely scoped real API fixtures. Require current warning-free type checks, exact intended allow/deny outcomes for Secret wire representations, nullable paused Task authority and public exposure, and UID-safe cleanup without starting custom controllers or public workloads. 74 unit/harness cases pass; no native result is claimed until hosted execution. Preserve all existing SRE/full gates and diagnostic privacy; native policy failure does not skip the unchanged bootstrap gate. No authentication, quiescence or CNI claim from administrative expression fixtures. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Kubernetes omits empty AdmissionRequest.subResource. Normalize only its absence to the primary-resource empty string across grant, reader-finalization and SRE token policies. Keep explicit status/token/finalize authority unchanged; no admission or permission bypass. Extend native policy qualification to install the actual grant-authority policy before primary creation, metadata and status updates, plus a regression refusing to pre-seed around admission. 75 unit/harness cases, 17 CLI contracts and Helm lint pass; expanded native qualification remains pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reuse the existing minimal SRE fixture chart for the fresh-install case instead of rendering every unrelated template under the test deadline. Preserve all namespace/account ownership assertions and existing live-lookup upgrade cases. Make fresh rendering explicitly client-only and bound its child process below the unchanged test deadline. All 24 related namespace, SRE-authority and credential-contract cases passed. No production changes, timeout increase or skipped assertions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward only the three match conditions from native-qualified SRE 3f20fac. Preserve protected oldObject names when collection DELETE omits request.name, without mixed string/dyn lists. Registrar/use/renew rules, bindings and existing optional-subresource repair remain intact. All three match-condition blocks compared byte-identical to 3f20; its job102698405012 proved nine ordinary/protected/admin collection cases. Current target passed 25 related CLI contracts and Helm lint. Target lifecycle/full SRE acceptance remains pending; no forced namespace finalization or gate waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real Kind API proof: Accept text/plain returns 406 for Pod logs, while application/json and wildcard return 200. Use wildcard only on the bounded upstream log path; keep the facade's plain-text response, byte/query caps, private authority checks and all JSON/media boundaries unchanged. Add HTTPS regression reproducing the native 406 before verifying raw log delivery. Python: 84 passed; no local Cargo, normal CI dependencies retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903 (cherry picked from commit 4b4a92a)
…ition Forward the reviewed typed-list projection from SRE026cda4f: native SecretList items may omit per-item TypeMeta, while conflicting types and typeless top-level values remain rejected. Preserve value/annotation redaction and list pagination metadata. The accurate native-list fixture exposed a 502 compatibility failure after the log-media forward; the corrected projection restores the intended 200 redacted response. All13 SRE proxy tests and strict paired-library Clippy pass under the8.5GiB guard (minimum9.79GiB). No raw credential exposure, ambient fallback or permission widening. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ledgement Include v2 and GitHub bindings in the existing 30-second credential refresh backstop while preserving 300-second legacy cadence. Stop rebind phase/detail toggling after authority is already retracted, retaining every initial UID/resourceVersion-fenced status patch before receipt/hold/pause side effects and all-Pod quiescence. Reproduce the original status-churn regression, preserve actual no-op API semantics in the HTTP fixture, and add stable waiting and stale-acknowledgement rejection coverage. Final 90 controller-binary credential tests and strict paired all-target Clippy pass. Independent bounded source review found no significant issues. Actual downstream Team-rebind and grant-disable acceptance remain pending; no timeout, admission, ownership, attestation or audit waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…e labels Share the exact existing runtime Pod labels between generation, observer RPC isolation proof, and approved sender egress evaluation. Correct the missing component-label false negative without changing any emitted label, NetworkPolicy, grant, namespace or port restriction. Add component baseline and exact-name sender regressions, retaining observer-only policy exclusion and foreign-selector rejection. All 92 controller-binary credential tests and strict paired all-target Clippy pass; bounded independent source review found no significant issues. Native observer/TLS/CNI and complete downstream acceptance remain required, with no human audit waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Normalize only uncaptured managedFields at the projection recheck, preserving all authority, data, revision and Deployment checks; cover the actual kubectl wire difference. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Share payload construction and response validation, preserve strict ownership and conflicts, and retain only bounded field-manager diagnostics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ents Preserve the default kube client stack and deadlines; keep request-local progress and suppress raw logging through complete response decoding. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…tures Preview complete owned payloads and retain UID/RV and external-drift fences; do not force or reassign production field ownership. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reject unknown, duplicate, extended and malformed diagnostic data; preserve command failure and existing message behavior without exposing argv or values. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve historical Rejected fixtures and exact data/UID/RV checks while honoring the installed CREATE-only policy; never persist or execute the probe. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve command input, authority and CAS behavior while discarding raw errors, argv and causes; phase labels describe attempted steps only. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Import exact hosted-qualified Mermaid 11.16.1, DOMPurify 3.4.13 and qs 6.16.0 locks. Preserve all package graph entries and unrelated pins; trusted-types 2.0.7 changes registry provenance only. Evidence: Azure/kars Actions run 34693066037, source f1f9b9e. Full component qualification still required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Import the Node 22 hosted-qualified Vitest 4.1.11 graph for GHSA-82fw-gwwq-j7x9. Preserve existing Vite/Rollup versions and byte-identical runtime dependency entries. Public run 34693494675 passed lint, types, build, 58 tests (three existing native skips), npm integrity install and zero-advisory audit. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Register executable proxy and link regression contracts in public Bridge CI and document safe upstream failure diagnostics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reject missing or unexpected job identities, exercise the real aggregate entrypoint, and document integration-only required-check activation without changing live protection. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Treat an omitted HTTPS URI port as 443 and compare canonical IP literals. Observe fixed positive TCP and HTTP setup events without recording upstream values or changing the request stack, TLS, authentication, or deadlines. Preserve old diagnostic records when the optional transport group is absent. Add real HTTP/TLS and cancellation regressions and document pooling and attribution limits. The native observer timeout remains unresolved; hosted Rust and native qualification are still required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
| .timeout(Duration::from_secs(8)) | ||
| .build() | ||
| && let Ok(resp) = imds | ||
| .get("http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://ai.azure.com/") |
Mirror production startup and the existing test setup before constructing kube clients. Nextest runs each test in its own process, so these tests cannot rely on another test installing the Rustls provider. Preserve all real connection, pooling and cancellation assertions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Classify the observed template-review refusal without retrying or changing approval. Compare pre-preview runtime, controller and BFF snapshots against the existing review and live UID/RV-fenced objects using the actual shipped CLI templateDigest. Emit only fixed comparison booleans; retain no template values or hashes. Preserve the original failed outcome. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reread only recognized moving snapshots before judging an empty projection or typed lineage-template refusal. Preserve the rejected snapshot's transition check, all authority and data fences, actual withdrawal/pause/refill witnesses, and the existing deadline. Recheck identity after lineage before settlement. Native diagnostics retain fixed typed-error and writer-failure categories without publishing private values. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep runtime acceptance and production deadlines unchanged. Emit a closed boolean restoration comparison on the existing refusal and project it through native diagnostics without values or hashes. Expand failure-only template comparisons to writer restoration. Exercise actual kubectl printing with a delayed response and bounded fixture budgets; retain safe child-failure facts. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Recover only a confirmed Pausing Sandbox conflict after full scope, runtime, Task, private-key and root revalidation. Require a different live revision before another guarded update, cap attempts at three within the existing deadline, and preserve all other failures. Exercise the native Pending-induced status race, bounded recovery, expiry, stale identities/intent and already-applied pause behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Observe endpoint-filtered Cilium drop, trace and policy verdicts before and during the existing failure-only experiment. Retain only bounded validated facts with provenance checks and exact-child cleanup. Keep packet receipt timing distinct from request freshness and policy realization; do not change the original failed outcome, shipping network policy, or readiness deadlines. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Require the full native diagnostic unittest inventory in the existing scope job and assert that wiring in CLI workflow contracts. Keep real API and runtime acceptance mandatory; unit diagnostics do not qualify live behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…tics Do not copy pod-template-hash into a Cilium endpoint selector: the pinned Cilium release excludes it from security identity labels. Verify source-qualified sandbox and namespace labels against CEP and agent identities, while retaining complete rollout, Pod UID, process and inventory fences. Reject old, foreign, orphaned, duplicate, paginated and changed consumers. Production policy and native acceptance remain unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The Sandbox reconciler can pause and revoke its projection while the independent Task controller remains Ready. Require the witnessed owned pause and empty projection without inventing a mandatory transient Task status. Preserve current Task authorization, fresh refill and consumed grant/Deployment revisions, old-Pod retirement, and all identity/data fences. Observed Task withdrawal still requires fresh attestation. Cover both schedules and double the negative authority matrix. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reuse canonical exact API targets in the owned observer policy. For installed Cilium, manage only a namespaced API-entity policy with validated ports and effective selectors. Preserve original namespace/claim/UID/RV fences, remove stale extensions, and retain a cleanup hint for interrupted retirement. Grant CNP management only to the controller; no new CNI installation, global settings, agent privileges, TLS or deadline changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record only a fixed failure category and actual exit status before removing private logs. Reap the owned child without a stale-PID cleanup attempt. Preserve the one-shot startup and all authentication, scope and cleanup assertions; do not retry an unexplained failure. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
|
|
||
| it("limits optional observer Cilium permissions to the controller and namespaced policies",()=>{ | ||
| const owners=manifests.filter(item=>["Role","ClusterRole"].includes(item.kind) | ||
| &&item.rules?.some((rule:{apiGroups?:string[]})=>rule.apiGroups?.includes("cilium.io"))); |
| const owners=manifests.filter(item=>["Role","ClusterRole"].includes(item.kind) | ||
| &&item.rules?.some((rule:{apiGroups?:string[]})=>rule.apiGroups?.includes("cilium.io"))); | ||
| expect(owners.map(item=>item.metadata.name)).toEqual(["kars-credential-grant-controller"]); | ||
| expect(owners[0].rules.filter((rule:{apiGroups:string[]})=>rule.apiGroups.includes("cilium.io"))) |
Map only a successful namespace recheck to unit, preserving validation and error propagation. Split lifecycle/fencing regressions into a shared-fixture child module so every new file meets the existing size limit. Retain all twenty regression functions and assertions; no gate exception or policy behavior change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The real operator may replace Pods during writer retirement before recording the private-key retirement baseline. Verify that neither generation survives and bind the Qualified receipt to the original runtime, Task authorization, Deployment and admin Secret instead of requiring different phase UID sets to be identical. Preserve source/root data, key rotation and old/new-key HTTP assertions. Add positive phase-ordering and negative binding/data/auth regressions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Conform imported Bridge source to the existing repository copyright check and MIT license. Insert headers only; preserve all original source bytes, existing author notices, file modes and shebang positions. No runtime code, license change or gate exemption. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve pinned Kind, kubectl and metrics-server versions. Validate official checksums before executable publication, bound HTTPS acquisition and transient retries, and separate metrics manifest acquisition from one-shot Kubernetes apply. Keep global deadlines, integrity checks and runtime assertions; exercise real partial-transfer cleanup and exact topology preservation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Cover all tracked first-party comment-capable formats while preserving source bytes, directives, frontmatter, modes and existing notices. Explicitly account for strict data, legal files, generated artifacts and upstream ownership without corrupting payloads or changing licensing. Restrict generated coverage to reviewed exact paths; reject unknown authored formats. Keep existing checker/applier entrypoints and test enforcement. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Complete Kars Bridge application, optional add-on
Draft; not beta/release-approved. Target:
kars-bridge.Head:
191a320291aa5431dc4b481e2bf5f03ac004deca.Prerequisite: #554 at
3a09cd7708ea9575557f414dd15a2f6f978e01ef.Integration ancestor:
b5ad6791f9085e908cbf3d16b5de9021eb4b43a7.Publishes the existing Bridge application under
bridge/: Rust BFF, Next.jsWorkspace/Console/Audit, optional Teams gateway, separate Helm chart, development
entrypoints, documentation and acceptance fixtures. The original snapshot is
0a10472ed7e2940235b714276e8def3c0d9190f4; all 398 imported product paths remain.Private history, credentials, operator state, deployment overlays, caches and
frozen SDK/probe ancestry are excluded.
Core remains independently usable. Bridge has separate packages, opt-in builds
and a separate Helm release. Adding/removing Bridge must preserve core identities,
resources and customer data.
/sandboxremains ephemeral; no PVC feature is added.Current public qualification
All qualification runs in Azure/kars. Current heads must establish their own
results; no historical outcome is substituted or failure waived.
Current correction queue: public copyright checks pass in both candidates.
Full CLI/Rust validation exposed a header-style regression in chart files also
read as raw YAML: Go-template comments are not valid for those readers. The
correction must preserve raw schema objects and Helm rendering, not weaken tests.
Core and application each report the same four Rust schema failures and the same
CLI staging failures.
A separate RustSec advisory published on 2026-09-14,
RUSTSEC-2026-0285,affects core Rustls 0.23.43 and BFF Rustls 0.23.41. Local commits update both to
0.23.45 with the required aws-lc/webpki family. Provider/features and unrelated
locked package choices are unchanged; Cargo validates the minimized locked graph.
This security patch is not yet published or execution-qualified.
The latest native artifact
10360357779reports 17 passes and one rotationtimeout: the workspace grant advanced to generation 4 while status remained at
generation 3. Initial observer readiness and other preceding cases passed.
The cause of that liveness symptom is being traced separately; no speculative
runtime change or timeout extension is included.
Verified preceding native result
At
24c85cd1, native run 34853257629passed all 18 runtime cases, all three cold API installs and the required aggregate.
Artifact
10353631768binds both revisions to that head and reportsruntimeQualified=true,networkPolicyEnforcementQualified=true, zero failuresand zero blocked cases. Executed checks include:
This is the
controlled-no-LLM-agent,no-active-sre-nativelane.activeSreCombinedQualified=falseremains explicit. It is not proof of the realstanding-Team maintenance/PR journey or the full supported-pair matrix.
The preceding component workflow also passed all 11 jobs. Core
344a371fpassedall 21 core jobs and all twenty new observer-egress Rust regressions.
The original observer timeout was traced to actual Cilium API SYN denials.
A correctly targeted temporary allowance produced an authenticated API HTTP 200;
the controller-generated permanent policy then achieved observer Ready without
that intervention. Diagnostic outcomes were never promoted into passing cases.
Latest changes
Bounded CI acquisition
The previous app core workflow failed while fetching/applying metrics-server;
its single unchanged-source retry failed earlier on malformed Kind checksum input.
The current CI-only repair retains Kind
v0.24.0, kubectlv1.30.5and metricsv0.7.2, with strict official Kind checksum/SHA validation before executablepublication. HTTPS acquisition, redirects and transient retries are bounded;
no integrity fallback or unverified cached binary is accepted.
Metrics download and local-manifest apply have separate diagnostics within the
existing 90-second/phase budget, with no Kubernetes mutation retry. Metrics retains
its existing HTTPS provenance, not a new checksum guarantee.
Repository-wide Microsoft/MIT coverage
The original 390 missing Bridge source headers were inserted without deleting
source bytes or existing author notices. Repo-wide coverage now accounts for all
2,292 tracked files: 2,041 inline headers and 251 explicitly covered strict-data,
legal, generated and third-party files. Binary/strict-data files are not claimed
to contain comment headers. Original ownership and MIT licensing are preserved.
The shared checker/applier handles appropriate comment syntax and preserves
shebangs, encoding declarations, Docker directives, frontend directives and
Markdown frontmatter. Generated-source coverage requires reviewed exact paths;
authored files cannot bypass checks merely by appearing beneath
build,distor similar names. Unknown first-party formats fail.
Byte-sensitive inputs—including the verbatim Helm AGT profile and its runtime
digest—remain unchanged under explicit license coverage. No templates or product
logic were rewritten to accommodate headers. Legal notices, upstream assets and
vendored payloads retain their licensing.
Validation and preserved contracts
Both worktrees passed 28 copyright, 27 acquisition and 28 harness tests, existing
size/copyright checks, type/manifest checks and preserved Helm renders. The native
180-test contract suite also passed locally after the header pass. Local npm-cache
versions differ from the lock; hosted results remain authoritative.
The bounded runtime corrections preserve original namespace/claim/UID/RV fences,
current authorization, actual pause/revocation/refill, consumed revisions and
old-Pod retirement. Only the controller gained management of namespaced Cilium
policies required by enrolled observers; no CNI installation, world/node allowance,
UID-1000 bypass, agent/BFF privileges or TLS/authentication weakening was added.
The native test now distinguishes the two real retirement-phase Pod baselines
while retaining identity, data, root, rotation and old/new-key assertions.
Existing receipt pinning, standard digest/signature adapters and the explicit
legacy-v1 credential-key compatibility boundary remain unchanged. Their scoped
reviews and regressions are not whole-application security sign-off.
Remaining gates and rollout boundary
Complete current-head CI, genuine capability-audit sign-offs and required PR
review before merge. No signature, ownership claim, alert dismissal or approval
is fabricated. The earlier bounded BFF review did not establish its proposed
issues as reproducible current-flow defects; complete flow acceptance is still
required, not replaced by those reviews.
Land the core prerequisite first, then activate stable Bridge component/native
requirements while retaining existing branch protections before application merge.
Once the integrated public
kars-bridgebranch is beta-ready, H100 acceptance willexercise core alone, optional Bridge installation, the real authenticated standing
Team/maintenance/evidence/review/revision flow, explicitly authorized merge, and
Bridge removal with core intact. The current BFF leaves actual merges to a human
GitHub action; no automatic merge authority is introduced.
No
mainor normal-release change, image publication, H100 deployment or privaterepository visibility change is included in this PR.