Skip to content

feat(IOP): add IOP mode support with custom routes - #2695

Merged
Siasurai merged 1 commit into
RedHatInsights:foreman-3.16from
adonispuente:iop
Jul 8, 2026
Merged

Siasurai merged 1 commit into
RedHatInsights:foreman-3.16from
adonispuente:iop

Conversation

@adonispuente

@adonispuente adonispuente commented Jun 24, 2026 •

Copy link
Copy Markdown
Contributor

This is a long summary but I wanted to catch all pain points. Essentially the goal is for iop branches to just be able to run npm run start:proxy:iop on appropriate branches and thats it.

Adds IOP (Insights on Premises) mode support for local development against Satellite/Foreman instances.

Changes

  • package.json: Added start:proxy:iop and start:proxy:iop:local scripts with dynamic IOP_URL
  • fec.config.js: Disabled Chrome SPA fallback in IOP mode (SPAFallback: process.env.IOP !== 'true')
  • custom_routes.json: Routes vulnerability assets/APIs to local dev server with strip_prefix support

Testing (Before Dependencies Merge)

  1. Build local frontend-components package:
    cd frontend-components
    git checkout IOP
    npm install && npm run build
    cd packages/config
    npm pack # Creates .tgz file

  2. Build local proxy image:
    cd frontend-development-proxy
    git checkout config

Comment out test lines 23-28 in Dockerfile (local Docker build issue)

podman build -t ghcr.io/redhatinsights/frontend-development-proxy:latest .

  1. Install and run:
    cd vulnerability-ui
    npm install /path/to/redhat-cloud-services-frontend-components-config-*.tgz
    IOP_URL="https://your-iop-instance.example.com" npm run start:proxy:iop:local

Access at: https://iop.foo.redhat.com:1337/insights/vulnerability

After Dependencies Merge

Just run:
IOP_URL="https://your-iop-instance.example.com" npm run start:proxy:iop

@sourcery-ai

sourcery-ai Bot commented Jun 24, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

Adds an IOP (Insights on Premises) development mode that proxies a local vulnerability-ui build through a dedicated dev proxy to a Satellite/Foreman IOP instance, wired via a new npm script, webpack config flag, and custom proxy routing configuration.

Sequence diagram for start:proxy:iop IOP development workflow

sequenceDiagram
  actor Developer
  participant npm
  participant fec_dev_proxy
  participant webpack_dev_server
  participant IOP_instance

  Developer->>npm: npm run start:proxy:iop
  npm->>fec_dev_proxy: PROXY=true IOP=true HCC_ENV=iop HCC_ENV_URL=$IOP_URL FEC_IOP_CUSTOM_ROUTES_PATH=custom_routes.json fec dev-proxy --iop
  fec_dev_proxy->>webpack_dev_server: start webpack in watch mode on port 8003
  fec_dev_proxy->>webpack_dev_server: apply fec.config SPAFallback with IOP=true
  fec_dev_proxy->>IOP_instance: establish proxy to IOP_URL
  Developer->>IOP_instance: access https://iop.foo.redhat.com:1337 via proxy
  IOP_instance-->>webpack_dev_server: requests for /assets/apps/vulnerability/*
  IOP_instance-->>Developer: responses combining IOP data and local vulnerability-ui assets
Loading

File-Level Changes

Change Details Files
Add IOP-specific dev startup script and environment wiring for running vulnerability-ui against an IOP instance via frontend-development-proxy.
  • Introduce npm script that enables PROXY mode, sets IOP and HCC_ENV=iop, wires HCC_ENV_URL to IOP_URL, and passes a custom routes file into fec dev-proxy --iop.
  • Document how to set IOP_URL and FEC_DEV_PROXY_IMAGE and how the IOP startup flow works end-to-end, including proxy behavior and certificate/redirect handling.
package.json
README.md
Adjust frontend configuration to behave correctly in IOP mode and route vulnerability assets from the local dev server.
  • Add SPAFallback flag controlled by the IOP environment variable so that Chrome is not locally intercepted in IOP mode.
  • Provide a custom_routes.json mapping vulnerability assets and app paths to the local dev server at host.docker.internal:8003 for use by the dev proxy.
fec.config.js
custom_routes.json

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • The start:proxy:iop npm script relies on shell-specific syntax like $(pwd) and inline env vars, which may not work on non-POSIX environments; consider using a cross-platform approach (e.g., cross-env and avoiding subshells) if this needs to run on macOS/Windows as well.
  • The SPAFallback: process.env.IOP !== 'true' condition inversely couples SPA behavior to a string-valued env var, which may be brittle; you might want to centralize and normalize IOP mode detection (e.g., a small helper that handles absence, case, and non-'true' values) to avoid subtle misconfigurations.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- The `start:proxy:iop` npm script relies on shell-specific syntax like `$(pwd)` and inline env vars, which may not work on non-POSIX environments; consider using a cross-platform approach (e.g., `cross-env` and avoiding subshells) if this needs to run on macOS/Windows as well.
- The `SPAFallback: process.env.IOP !== 'true'` condition inversely couples SPA behavior to a string-valued env var, which may be brittle; you might want to centralize and normalize IOP mode detection (e.g., a small helper that handles absence, case, and non-'true' values) to avoid subtle misconfigurations.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@Siasurai Siasurai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thank you so much!

@adonispuente
adonispuente force-pushed the iop branch 3 times, most recently from 9f6fc69 to b19611a Compare June 25, 2026 21:13
Add IOP (Insights on Premises) development mode configuration:
- Created custom_routes.json defining vulnerability asset and API route mappings
- Added start:proxy:iop npm script for launching IOP development proxy
- Routes /assets/apps/vulnerability/* to local webpack dev server (port 8002) with path stripping
- Routes /api/vulnerability/* to local backend API (port 8000)

This enables local vulnerability-ui development against IOP/Satellite instances,
building on existing IOP support in fec.config.js and patchFederationForIop.js.

Requires frontend-components IOP branch for fec dev-proxy --iop command.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@Siasurai
Siasurai merged commit 77f04c4 into RedHatInsights:foreman-3.16 Jul 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants