Implement planned topic: 0005-nexus-caller-limits - #48
Merged
Conversation
Collaborator
|
I don't love that this mentions both |
Drop the paired `temporal cloud nexus` code blocks from the new nexus-caller-limits reference, folding the flag and behavior notes into the surviving tcld blocks. Also revert the whitespace-only edits to cloud-ops-api.md and connectivity.md, which were unrelated to this topic and removed a load-bearing line break. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
starfleeth
approved these changes
Aug 10, 2026
starfleeth
left a comment
Collaborator
There was a problem hiding this comment.
made updates- removed temporal cloud examples
…d reference Replace the standalone nexus-caller-limits.md with a section in cloud-namespace-admin.md, which already owns the Cloud tcld surface, and add both Nexus ceilings to that file's Limits list. Matches the house style used by accepted-client-ca and certificate-filters: subcommand table, shared flags, then the blast radius of the replace-everything verb. Also notes that `set` fights Terraform's allowed_caller_namespaces, and points Endpoint CRUD at the existing self-hosted-admin mapping. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…mespace set Dropping an entry revokes a live caller, which puts `set` in the destructive tier. The fold had weakened the draft's confirm-with-the-user step into run-list-first advice. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Validation Report —
nexus-caller-limitsBranch:
draft/0005-nexus-caller-limitsFiles validated:
references/ops/nexus-caller-limits.md(new, 203 lines)SKILL.md(two additions: routing-table row, reference-file index bullet)Independence: performed in a fresh session with no access to authoring artifacts.
Go/no-go
references/integrations.md.Overall verdict: GO.
Check 1 findings
None. All 18 unique cited docs ranges resolve and substantively support the anchored claim:
nexus-security.mdx:22-23limits.mdx:260limits.mdx:261nexus-security.mdx:27nexus-security.mdx:34-36nexus-registry.mdx:61limits.mdx:255cli/…/nexus.mdx:57-61allowed-namespace listrequires--name.tcld/nexus.mdx:194-204allowed-namespace listhas--name(aliasn).cli/…/nexus.mdx:150-162endpoint getrequires exactly one of--name/--id.cli/…/nexus.mdx:32-49addrequires--name+--namespace(string[]); already-listed silently ignored (line 35).tcld/nexus.mdx:164-192addflags and-n/-nsaliases present.cli/…/nexus.mdx:63-80remove; not-currently-allowed silently ignored (line 66).tcld/nexus.mdx:236-264removesection.cli/…/nexus.mdx:82-99set"replacing any previously allowed namespaces" (line 84-85).tcld/nexus.mdx:206-234setsection.cli/…/nexus.mdx:101-129createmarks--target-namespace/--target-task-queuerequired;--allow-namespaceoptional string[].tcld/nexus.mdx:53-93createaliasesn/tns/ttq/ansall present.cli/…/nexus.mdx:28-99, 118allowed-namespace;--allow-namespaceflag only onendpoint create(line 118).All user-facing
https://links use full URLs (no root-relative paths). No sub-check gate broken.Check 2 findings
None. Token extraction and grep-verification:
--allow-namespace,--id,--name,--namespace,--target-namespace,--target-task-queuecli/…/nexus.mdxn,ns,tns,ttq,anstcld/nexus.mdxtemporal cloud nexus endpoint …,tcld nexus endpoint …allowed-namespace,add,remove,list,set,create,get1,000caller Namespaces,100Endpointslimits.mdx:255,260)allowed_caller_namespacescloud/terraform-provider.mdx:360,375,455)No token required an
<!-- undocumented: … -->tag.Check 3 findings
None. Regression grep results:
--profile,TEMPORAL_TLS_*_PATH,tcld service-account,--output text|jsonl,saas-api.tmprl.cloud:7233) — 0 hits.allow-namespace add|remove|list|setused as subcommand — 0 hits.100 caller/1,000 Endpoints— 0 hits.Check 4 findings
None. Sample of 10 claims, each independently re-derived from docs and compared:
limits.mdx:260nexus-registry.mdx:61limits.mdx:255allowed-namespace listrequires--namecli/…/nexus.mdx:60(Required: Yes)endpoint getrequires exactly one of--name/--idcli/…/nexus.mdx:152-153--namespaceis string[] repeatable; already-listed silently ignoredcli/…/nexus.mdx:35, 46setreplaces the full list; entries not supplied are droppedcli/…/nexus.mdx:84-85--target-namespace+--target-task-queuerequired on create;--allow-namespaceoptional/repeatablecli/…/nexus.mdx:118, 128-129n,tns,ttq,anstcld/nexus.mdx:63, 81, 87, 93allowed_caller_namespacesterraform-provider.mdx:360,375Match rate: 10/10 = 100%. No documented defaults were omitted (the 1,000 cap and the empty-allowlist-at-create defaults are both stated explicitly).
Check 6 findings
Pattern 1 (workaround disclosure) — none.
setas a destructive operation" bullet (line 117) is positive safety guidance around a first-class supported command, not a workaround.Public Preview admonition (patterns 5-7): not required.
docs/encyclopedia/nexus/*anddocs/cloud/nexus/*no longer carry "Public Preview" markers for the Nexus product. The(EXPERIMENTAL)tags indocs/cloud/tcld/nexus.mdxare atcld-CLI-level auto-gen marker, not a Nexus-product-status marker; the reference file surfaces this factually at line 147 without paraphrasing it into a product-status claim.Minor observation (not gating):
(EXPERIMENTAL)in the auto-generated reference)" is a mild in-the-weeds note about the tcld auto-gen. It arguably reduces agent friction (pre-empts a "why is this EXPERIMENTAL" derail) but could be tightened or dropped in a follow-up polish. Not a MAJOR or MINOR-FIXES trigger.Other patterns (2, 3, 4, 8-15) — no hits:
Statistics
Verdict
GO. The
nexus-caller-limitsreference file and its twoSKILL.mdhookups are grounded, factually accurate, and free of workaround-disclosure or regression patterns. Safe to merge.