feat(mecak8s-kind): add one-shot kind-up and kind-down tasks - #2054
Draft
tgrunnagle wants to merge 2 commits into
Draft
tgrunnagle wants to merge 2 commits into
tgrunnagle wants to merge 2 commits into
Conversation
Compose the existing fixture targets into a single bring-up and teardown: - kind-up: kind-keycloak-setup, build, kind-hosts-add, kind-keycloak-demo, run sequentially. It recreates mecatl-dev, so it carries a Task prompt guard; without a terminal Task cancels it unless --yes is passed. - kind-down: mecatui logout (best effort), kind-hosts-remove, kind-destroy. kind-hosts-add and kind-hosts-remove now read the world-readable /etc/hosts unprivileged first and reach sudo only when an entry must change, so a converged run never prompts and removal no longer overwrites /etc/hosts.bak when there is nothing to remove. TestMecak8sKindFixture_OneShotLifecycle pins the prompt guard, the step order of both tasks, and the check-before-sudo order of the hosts tasks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
kind-setup writes deploy/mecak8s-kind/kconfig.yaml (cluster-admin client credentials for the disposable mecatl-dev cluster). Unlike the sibling mecak8s-vmcp fixture kubeconfig it was not ignored, so a stray `git add` could commit it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds one-shot bring-up and teardown targets to the operator-run mecak8s Kind fixture (
deploy/mecak8s-kind/Taskfile.yml), built entirely from existing targets:task mecak8s:kind-uprunskind-keycloak-setup→:build→kind-hosts-add→kind-keycloak-demoin order. It deletes and recreatesmecatl-dev, so it has a Taskprompt:guard. Without a terminal, Task cancels it (exit 205) unless--yesis passed.task mecak8s:kind-downrunsmecatui logoutagainst the fixture target (best effort), thenkind-hosts-removeandkind-destroy. It is safe to run again.Both use
cmds:, notdeps:, because Task runsdepsin parallel.The hosts tasks also no longer call
sudowhen nothing needs to change./etc/hostsis world-readable, sokind-hosts-addandkind-hosts-removecheck it without privileges first and callsudoonly to add a missing alias or remove one that is present. The privileged re-check inside the append stays, so adding is still safe to repeat. As a result:task --yes mecak8s:kind-upruns with no prompt, for example from a script;kind-hosts-removeno longer overwrites/etc/hosts.bakwhen there is nothing to remove.This PR also adds
/deploy/mecak8s-kind/kconfig.yamlto.gitignore. That generated kubeconfig holds admin credentials for the disposable cluster and, unlike themecak8s-vmcpfixture's kubeconfig, was not ignored.Development stage
Contract linkage
sudo. It changes no runtime, public API, protobuf, persistence, chart or trust-boundary interface, and the basekind-setupdependency boundary pinned by the fixture tests is unchanged.kind-upand the check-before-sudo change to the hosts tasks.Interface conformance
task mecak8s:kind-upandtask mecak8s:kind-down.Issue relationship
No tracking issue.
Type of change
Test plan
Baseline checks
task lint) — passes when run as Linux (GOOS=linux task lint, what CI targets). See the reviewer notes about macOS.task test) — covered by the race runtask test:race) — passes except one macOS-only failure this change didn't cause (see reviewer notes). Two other timing-sensitive packages failed under load and passed on an isolated-racererun.go run ./cmd/mecademo) — shows the tool call, permission ask and approval, and resulttask docs)user-docs/)/panel-review— not runFixture tests
TestMecak8sKindFixture_OneShotLifecyclechecks:kind-uphas aprompt:and nodeps:;/etc/hostsbefore reachingsudo.Removing the prompt or swapping
kind-hosts-addandkind-keycloak-demomakes it fail. The existing closure tests confirm every referenced task exists and that the basekind-setupchain still pulls in no identity layer.Live Kind run (Docker, mock provider, macOS arm64)
Prompt guard
kind-upcluster state (all verified):Cluster: node Ready. 16/16 pods Running with 0 restarts. All rollouts complete.
Helm:
cert-managerv1.17.2 andmecak8srevision 2 (base install, then the Keycloak overlay).Image: both replicas run the image ID built locally from this tree.
Provider:
--mockset and no provider Secret.Pod security: the namespace enforces the restricted policy.
Certificates: all three Ready. The exported
fixture-ca.crtmatches the cluster Secret byte for byte.Local files: kubeconfig and CA file
0600, state directory0700.Host access: host ports bound to
127.0.0.1only.TLS: verifies through the alias,
localhostand127.0.0.1. Fails without the fixture CA and with a wrong hostname.OIDC: login through a scripted Authorization Code + PKCE flow (the fixture user's password and the tokens were never printed). The discovery issuer matches, and tokens carry
aud=mecak8sandmecak8s:access. A spent authorization code can't be reused.API authentication:
Sessions: create returns 201. The session is stored in Redis, and each replica serves it when port-forwarded individually.
User isolation: a second user gets 404 on another user's session (read, transcript, rename).
Prompt: a mock prompt runs end to end over SSE.
Logs: no errors; only the warnings expected for this fixture.
No-sudo path: with the aliases present,
kind-hosts-addexited 0 without a terminal and never calledsudo.kind-down/etc/hosts.bakdiff shows only the two alias lines changed.sudo, and leaves/etc/hosts.bakunchanged.Changes
deploy/mecak8s-kind/Taskfile.ymlkind-up(prompt-guarded) andkind-down; hosts tasks callsudoonly when an entry must changedeploy/mecak8s-kind/fixture_test.goTestMecak8sKindFixture_OneShotLifecycleplus thefixtureTaskBlockandassertOrderedhelpersdeploy/mecak8s-kind/README.mdsudois needed.claude/skills/mecak8s-kind-manual-verify/SKILL.mdkind-upand cleanup atkind-down.gitignoredeploy/mecak8s-kind/kconfig.yamlUser-facing change
Operators of the local Kind fixture get two new commands,
task mecak8s:kind-upandtask mecak8s:kind-down.kind-hosts-addandkind-hosts-removenow ask for asudopassword only when/etc/hostsactually needs to change. No product runtime behavior changes.Special notes for reviewers
task linton darwin reports 3 staticcheck SA4023 findings ininternal/executionexecutorandcmd/mecatl-executor. The!linuxstub always returns an error, soerr != nillooks always true. The same packages show 0 issues when linted as Linux.TestMecatedCLICompositionValidatesMicroVMDefaultAfterReadiness(cmd/mecated/microvm_command_test.go) fails every time on darwin. It binds a socket under/dev/fd/<n>/, which works through/proc/self/fdon Linux but not on macOS.--mockprovider (internal/app/registry.go) is one process-widemockllmwith a single scripted text turn. After the first prompt on a replica, later prompts get empty replies and end withno_progress, so a second manual mock session on the fixture looks broken.kind-upstill deletes the existing cluster after confirmation, the same waykind-keycloak-setupdoes. To keep a healthy cluster, usekind-keycloak-applyas the README describes.🤖 Generated with Claude Code