Skip to content

OSAC-2632: Design - Unified Networking UI Addendum - #207

Merged
openshift-merge-bot[bot] merged 4 commits into
osac-project:mainfrom
batzionb:design/OSAC-2632-ui
Aug 16, 2026
Merged

openshift-merge-bot[bot] merged 4 commits into
osac-project:mainfrom
batzionb:design/OSAC-2632-ui

Conversation

@batzionb

@batzionb batzionb commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Design: Unified Networking — UI Design Addendum

Jira: https://redhat.atlassian.net/browse/OSAC-2632 (tracked alongside OSAC-1433, OSAC-3621, OSAC-3622)
Backend design: design.md (already merged/accepted)

Summary

Adds the remaining osac-ui work for unified networking: Cloud Provider Admin
management of ExternalIPPool, a NAT Gateway field/action on VirtualNetwork
(tenant-facing), and simplified tenant-facing External IP management. No
backend/proto changes.

Requesting Review On

General review — no specific items flagged.

How to Review

  • Comment inline on specific sections
  • Approve when the design accurately reflects a viable implementation approach

Summary by CodeRabbit

  • Documentation
    • Added UI guidance for unified networking workflows.
    • Documented management of external IP pools, NAT Gateway attachment, and tenant external IPs.
    • Defined navigation, forms, validation, mutation behavior, status labels, and failure handling.
    • Added requirements for API interactions, test fixtures, and resource provenance.
    • Removed superseded design and product requirement documentation for the proposed VMaaS networking UI scope.

@openshift-ci-robot

openshift-ci-robot commented Aug 12, 2026 •

Copy link
Copy Markdown

@batzionb: This pull request references OSAC-2632 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Design: Unified Networking — UI Design Addendum

Jira: https://redhat.atlassian.net/browse/OSAC-2632 (tracked alongside OSAC-1433, OSAC-3621, OSAC-3622)
Backend design: design.md (already merged/accepted)

Summary

Adds the remaining osac-ui work for unified networking: Cloud Provider Admin
management of ExternalIPPool, a NAT Gateway field/action on VirtualNetwork
(tenant-facing), and simplified tenant-facing External IP management. No
backend/proto changes.

Requesting Review On

General review — no specific items flagged.

How to Review

  • Comment inline on specific sections
  • Approve when the design accurately reflects a viable implementation approach

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: a062a30a-c69f-45bc-8458-5e322d7219d0

📥 Commits

Reviewing files that changed from the base of the PR and between 7542ba8 and ad073f2.

📒 Files selected for processing (3)
  • enhancements/OSAC-1425-networking-ui-vmaas-scope/design.md
  • enhancements/OSAC-1425-networking-ui-vmaas-scope/prd.md
  • enhancements/OSAC-1433-unified-networking/ui-design.md
💤 Files with no reviewable changes (2)
  • enhancements/OSAC-1425-networking-ui-vmaas-scope/prd.md
  • enhancements/OSAC-1425-networking-ui-vmaas-scope/design.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • enhancements/OSAC-1433-unified-networking/ui-design.md

Walkthrough

The pull request adds a unified networking UI design addendum and removes the OSAC-1425 VMaaS networking UI design and PRD. The addendum covers provider and tenant networking workflows, error handling, API integration, navigation, validation, and test fixtures.

Changes

Unified networking UI

Layer / File(s) Summary
Design scope and structure
enhancements/OSAC-1433-unified-networking/ui-design.md, enhancements/OSAC-1425-networking-ui-vmaas-scope/design.md, enhancements/OSAC-1425-networking-ui-vmaas-scope/prd.md
Adds the unified networking design addendum and removes the previous OSAC-1425 design and PRD.
Provider networking workflows
enhancements/OSAC-1433-unified-networking/ui-design.md
Defines ExternalIPPool administration and VirtualNetwork NAT Gateway display, filtering, attachment, detachment, and replacement flows.
Tenant flows and implementation wiring
enhancements/OSAC-1433-unified-networking/ui-design.md
Defines tenant External IP operations, error handling, hooks, routes, type exports, status labels, navigation, and mock fixtures.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Mergeability Score: ⚪ Minimal · up to ad073

This design-only UI addendum introduces no evidenced merge-blocking risk; it is merge-ready after normal checks and review.

Possibly related PRs

Suggested labels: approved, lgtm, rfe-creator-auto-reviewed

Suggested reviewers: jhernand, oourfali

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Ai-Attribution ⚠️ Warning The added ui-design.md includes an explicit ai-workflow-provenance record, but all four PR commits have no Assisted-by or Generated-by trailers; no Co-Authored-By trailer is present. Add an Assisted-by or Generated-by trailer naming the AI tool to each AI-assisted commit. Do not use Co-Authored-By for the AI tool.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change as the OSAC-2632 unified networking UI design addendum.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed The patch adds only design text and Jira URLs; scans found no credential assignments, secret-shaped URLs, private-key material, JWTs, or long base64/hex blobs.
No-Weak-Crypto ✅ Passed The parent-to-HEAD diff changes Markdown only. Added content contains no MD5, SHA1, DES, RC4, Blowfish, ECB, custom crypto, or secret comparisons.
No-Injection-Vectors ✅ Passed The PR adds one Markdown design document and deletes two Markdown documents; the added text contains no SQL, shell, eval/exec, pickle, unsafe YAML, os.system, or dangerouslySetInnerHTML code.
Container-Privileges ✅ Passed The PR changes only Markdown design documents; added lines contain no Kubernetes manifests or privileged, hostPID, hostNetwork, hostIPC, SYS_ADMIN, or allowPrivilegeEscalation settings.
No-Sensitive-Data-In-Logs ✅ Passed The patch changes only Markdown design documents. Added lines define UI resources and hooks, with no logging statements or sensitive values; the deleted documents cannot introduce log exposure.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@batzionb
batzionb marked this pull request as ready for review August 12, 2026 20:10
@openshift-ci
openshift-ci Bot requested review from jhernand and oourfali August 12, 2026 20:10

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
enhancements/OSAC-1433-unified-networking/ui-design.md (1)

59-73: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Batch NAT Gateway queries on the list page.

Calling useNatGatewayForVirtualNetwork(vnId) for each table row creates an N+1 NatGateways.List request pattern. Fetch NAT gateways once for the list page and index them by spec.virtual_network.id. Keep the filtered hook for the detail page.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@enhancements/OSAC-1433-unified-networking/ui-design.md` around lines 59 - 73,
Update VirtualNetworksListPage to fetch NAT gateways once, then index the
results by spec.virtual_network.id for row rendering instead of calling
useNatGatewayForVirtualNetwork per row. Keep useNatGatewayForVirtualNetwork
unchanged for VirtualNetworkDetailPage.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@enhancements/OSAC-1433-unified-networking/ui-design.md`:
- Around line 57-69: Condition the Attach NAT Gateway actions in
VirtualNetworksListPage and VirtualNetworkDetailPage on
useNatGatewayForVirtualNetwork(vnId) returning no gateway, preventing creation
when one already exists. On the detail page, label the empty-state action
“Attach NAT Gateway”; use “Edit” only for an existing gateway when replacement
is supported.
- Line 10: Update the prd field in the unified networking design metadata to
reference the existing OSAC-1433 PRD at
enhancements/OSAC-1433-unified-networking/prd.md instead of "N/A", preserving
proposal traceability.

---

Nitpick comments:
In `@enhancements/OSAC-1433-unified-networking/ui-design.md`:
- Around line 59-73: Update VirtualNetworksListPage to fetch NAT gateways once,
then index the results by spec.virtual_network.id for row rendering instead of
calling useNatGatewayForVirtualNetwork per row. Keep
useNatGatewayForVirtualNetwork unchanged for VirtualNetworkDetailPage.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a283d64-c43e-4354-b8c6-6cb955476195

📥 Commits

Reviewing files that changed from the base of the PR and between 7b09375 and 18a72cb.

📒 Files selected for processing (1)
  • enhancements/OSAC-1433-unified-networking/ui-design.md

Comment thread enhancements/OSAC-1433-unified-networking/ui-design.md Outdated
Comment thread enhancements/OSAC-1433-unified-networking/ui-design.md Outdated
…25 into ui-design.md

OSAC-1425's design.md/prd.md described VirtualNetwork/Subnet/SecurityGroup/
PublicIP UI management, already shipped under OSAC-1898/OSAC-1899. Removing
the standalone docs and summarizing the existing VirtualNetwork list/detail
page here for context, since this design's NAT Gateway field extends it.
@github-actions

github-actions Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

AI EP Review: EP-207

Score: 3/10 | Verdict: FAIL

Criterion Score Notes
WHAT (clear need) 1/2 The document identifies three new platform capabilities (Cloud Provider Admin ExternalIPPool CRUD, tenant NAT Gateway attach/detach on VirtualNetworks, tenant External IP management) and names affected personas (Cloud Provider Admin, Tenant User, Tenant Admin). However, it is explicitly a 'UI Design Addendum,' not a PRD. There are no user stories, no articulation of user needs, and the capabilities are described through component specifications rather than product requirements. Scored 1 for havi
WHY (justification) 0/2 No business justification is provided anywhere in the document. There is no statement of user pain, business need, or strategic goal. The document opens by saying it 'extends the accepted backend design' and references Jira tickets, but never explains WHY these capabilities matter to users or the business. The old OSAC-1425 PRD (which contained a Problem Statement and Motivation) was deleted in this same PR, and the new document does not carry forward any business rationale.
User-Facing Focus 0/2 The document is heavily implementation-prescriptive. It names specific Go server files (internal/servers/private_external_ip_pools_server.go), React component names (ExternalIpPoolsListPage, ExternalIpPoolFormPage), TypeScript hook names (useCreateNatGateway, useDeleteExternalIPPool), form libraries (Formik+Yup, FieldArray), file paths (api/v1/networking.ts, api/v1/private/external-ip-pools.ts), barrel export fixes (libs/types/src/index.ts), gRPC service methods (NatGateways.List), filter expres
Right-Sized 2/2 The scope is focused and coherent: three related networking UI capabilities (ExternalIPPool admin management, NAT Gateway field on VirtualNetworks, tenant External IP management) that are all part of the unified networking feature under OSAC-1433/OSAC-2632. The existing VirtualNetwork/Subnet/SecurityGroup management is explicitly excluded as already shipped. The features are logically connected — External IPs feed into NAT Gateways, which attach to VirtualNetworks, and ExternalIPPools are the ad
Testability 0/2 The document contains zero acceptance criteria, zero verifiable requirements, and zero test scenarios. The failure handling table describes implementation-level error responses, not PM/QA-verifiable behaviors. There is no way for a PM or QA engineer to derive pass/fail criteria from this document. The deleted OSAC-1425 PRD had 22 acceptance criteria; the new document has none.

Verdict: This is a well-scoped UI design addendum, not a PRD — it has zero business justification, zero acceptance criteria, and deeply prescribes implementation (component names, file paths, hooks, Go server files), earning three zero scores and a total of 3/10.

Feedback: This document needs to be either (a) paired with an actual PRD that provides business justification, user stories, and acceptance criteria, or (b) restructured as a PRD itself. Add a Problem Statement explaining why these three capabilities matter to Cloud Provider Admins and Tenant Users — what pain they solve, what workflows they enable. Replace implementation details (hook names, file paths, component names, barrel exports) with user-observable requirements: 'A Cloud Provider Admin can create an External IP Pool with a name, IP family, and one or more CIDRs' instead of 'ExternalIpPoolFormPage, Formik+Yup, FieldArray, useCreateExternalIPPool()'. Add acceptance criteria that a PM or QA engineer can verify against the running product.

Critical (3)

  1. No business justification (why=0): The document never states why these capabilities matter — no user pain, no business need, no strategic goal. The deleted OSAC-1425 PRD had a Problem Statement section; the replacement has nothing equivalent.
  2. No acceptance criteria (testability=0): The document contains zero verifiable requirements. A PM or QA engineer cannot determine what 'done' looks like from this document alone.
  3. Pervasive design leakage (user_facing_focus=0): Implementation details are woven throughout — Go server file paths, React component names, TypeScript hook signatures, form library choices, barrel export fixes, test mock transport files. A PRD should describe what users see and do, not how developers build it.

Important (2)

  1. The old OSAC-1425 PRD (165 lines with Problem Statement, Goals, 44 functional requirements, 22 acceptance criteria) was deleted in this PR, but the replacement document carries forward none of that PRD structure. If the old PRD is being superseded, the new document should reference or replace its business rationale.
  2. The prd frontmatter field references 'prd.md' but no prd.md is added in this PR — it's unclear whether a companion PRD exists or is planned.

Suggestions (2)

  1. Consider splitting this into a lightweight PRD (what/why/acceptance criteria) and a design addendum (how). The design content is solid for a design document — it just isn't a PRD.
  2. The failure handling table is good design documentation but should be complemented with user-facing error behavior acceptance criteria (e.g., 'When a Cloud Provider Admin attempts to delete a pool with allocated IPs, the UI shows the server error message and the pool remains listed').

Review cost

Model: claude-opus-4-6
Cost: $0.6967
Tokens: 6 in / 4.7k out
Cache: 193.4k read
Active time: 1m 41s
API calls: 0

@github-actions github-actions Bot added the rfe-creator-auto-reviewed EP was reviewed by AI label Aug 13, 2026
@github-actions

github-actions Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

AI Design Review: EP-207

Score: 7/8 | Verdict: PASS

Criterion Score Notes
Feasibility 2/2 Pure UI addendum consuming existing backend services with no proto/backend changes. References concrete existing patterns (storage-backends.ts, SecurityGroupStatusLabel), names specific files, hooks, and API routes. The N+1 avoidance for NAT Gateway (fetch all, index by VN ID) is practical. ExternalIPPool CRUD via existing private API is straightforward. The CEL-like filter expression for unattached ExternalIPs should be verified against the actual API filter grammar, but is a minor implementati
Testability 1/2 No test plan section at all — the deleted OSAC-1425 design had comprehensive unit/integration/E2E/a11y test plans, but this addendum omits testing entirely. The failure handling table (8 scenarios with expected behaviors) is valuable and implicitly defines test cases, but there are no explicit test strategies, coverage targets, or testing deliverables. For a 155-line addendum this is tolerable, but the absence is a clear gap.
Scope 2/2 Well-bounded: three distinct UI areas (ExternalIPPool admin, NAT Gateway on VN, External IP tenant management), explicitly no backend changes, clear separation of new work vs existing context (VN management summarized as unchanged). Jira traceability is strong (OSAC-2632, OSAC-1433, OSAC-1898, OSAC-1899). The deletion of the old OSAC-1425 design in the same PR is unexplained but appears to be intentional cleanup of a shipped feature.
Architecture 2/2 Follows established osac-ui patterns: hooks follow storage-backends.ts shape, status labels wrap ResourceStatusLabel, admin hooks use private API separation, nav placement is consistent with existing admin/tenant structure. The NAT Gateway immutability constraint (detach+attach, not in-place edit) correctly mirrors the backend design. Missing: cache invalidation details for NAT Gateway hooks — attaching/detaching a NAT Gateway should invalidate VN queries, NGW queries, and ExternalIP queries, bu

Verdict: A well-scoped, architecturally sound UI design addendum that is clearly implementable, but lacks any test plan section — the only meaningful gap in an otherwise solid document.

Feedback: Add a brief test plan section: at minimum, specify unit tests for the new hooks (useCreateNatGateway, useDeleteNatGateway, useCreateExternalIPPool, etc.), component tests for the NAT Gateway attach modal flow, and which failure-handling scenarios from your table warrant E2E coverage. Specify cache invalidation callbacks for NAT Gateway mutations — attaching a NAT Gateway must invalidate VirtualNetwork, NatGateway, and ExternalIP queries to keep list/detail pages consistent. The OSAC-1425 design deletion should be explained in the PR description (was it shipped under OSAC-1898?) so reviewers understand the intent.

Critical (0)

None.

Important (3)

  1. No test plan section: the design specifies no testing strategy, coverage targets, or test deliverables, unlike the deleted OSAC-1425 design which had comprehensive unit/integration/E2E/a11y plans. Even as an addendum, the three new UI areas (ExternalIPPool admin, NAT Gateway, External IP) warrant at minimum a brief test plan.
  2. Missing cache invalidation specification for NAT Gateway hooks: useCreateNatGateway and useDeleteNatGateway onSuccess callbacks must invalidate at least three query families — VirtualNetwork queries (list/detail pages show NAT Gateway column/field), NatGateway queries, and ExternalIP queries (the attach modal filters to unattached IPs). Without this, list and detail pages will show stale data after attach/detach operations.
  3. Unexplained deletion of OSAC-1425 design and PRD (1047 lines removed): the PR description does not mention or justify removing the shipped OSAC-1425 networking UI design. If this is intentional cleanup of a shipped feature, it should be stated; if accidental, the files should be preserved.

Suggestions (3)

  1. Consider specifying the ExternalIP filter expression's compatibility with the fulfillment API's actual filter grammar — the CEL-like syntax (this.status.state == EXTERNAL_IP_STATE_ALLOCATED && this.status.attached == false) should be verified during implementation.
  2. The ExternalIPPool edit form says 'only Name is editable' with IP family and CIDRs disabled — consider adding helper text explaining why these fields are immutable to avoid admin confusion.
  3. The Provenance section at the bottom references 'dirty' workspace state — consider cleaning this up before merge for a cleaner document history.

Review cost

Model: claude-opus-4-6
Cost: $1.0114
Tokens: 17 in / 5.4k out
Cache: 1.1M read
Active time: 2m 17s
API calls: 0

@openshift-ci

openshift-ci Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: batzionb, danmanor

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit e773452 into osac-project:main Aug 16, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants