Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

MGMT-23732/MGMT-23759: define PublicIPPool proto type and service - #392

Merged
openshift-merge-bot[bot] merged 3 commits into
osac-project:mainfrom
akshaynadkarni:mgmt-23732-publicippool-support
Apr 15, 2026
Merged

openshift-merge-bot[bot] merged 3 commits into
osac-project:mainfrom
akshaynadkarni:mgmt-23732-publicippool-support

Conversation

@akshaynadkarni

@akshaynadkarni akshaynadkarni commented Apr 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

MGMT-23759: Define the PublicIPPool proto type and gRPC service in the private API, the first subtask of MGMT-23732 (PublicIPPool Backend).

The type definition follows the CRD shape from osac-operator (single cidrs list + ip_family, not separate IPv4/IPv6 fields like Subnet). All spec fields are immutable after creation. The state enum uses PENDING (consistent with all other networking resources), and status includes capacity fields (total, allocated, available).

The service defines List, Get, Create, Update, Delete, and Signal RPCs with gRPC-gateway HTTP annotations on all except Signal.

Testing

Proto validation:

buf lint   # passed
buf generate   # 6 Go files generated (2 type + 4 service)
go build ./...   # passed
go run github.com/onsi/ginkgo/v2/ginkgo run -r --skip-package=it   # 33 suites, all passed

Container build and deploy to edge-22:

g-container-build -t fulfillment-service:mgmt-23732-proto .   # succeeded
podman push quay.io/rh-ee-anadkarn/fulfillment-service:mgmt-23732-proto   # succeeded
oc set image deployment/fulfillment-{controller,grpc-server,rest-gateway} ...   # all 3 rolled out
oc logs deployment/fulfillment-grpc-server -n osac-devel --since=2m   # clean startup, no errors
oc logs deployment/fulfillment-controller -n osac-devel --since=30s   # healthy after rollout settling

Pre-merge ToDos

  1. After merge, CI pushes new BSR tag for buf.build/osac-project/private-api
  2. Update osac-operator buf.gen.yaml to reference the new BSR tag, then buf mod update && buf generate (needed for MGMT-23733 Phase 5 feedback controller)

Related PRs

Ticket

MGMT-23759 (subtask of MGMT-23732, epic MGMT-23730)


Assisted-by: Cursor/Claude

Summary by CodeRabbit

  • New Features
    • Public IP Pool management: create, list (with pagination, filtering, ordering), retrieve, update, and delete pools.
    • Pools expose region, CIDR(s), IP family, lifecycle states, and capacity metrics (total, allocated, available).
    • Support for signaling reconciliation to trigger synchronization of an IP pool.

@openshift-ci

openshift-ci Bot commented Apr 13, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci-robot

openshift-ci-robot commented Apr 13, 2026 •

Copy link
Copy Markdown

@akshaynadkarni: This pull request references MGMT-23759 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

MGMT-23759: Define the PublicIPPool proto type and gRPC service in the private API, the first subtask of MGMT-23732 (PublicIPPool Backend).

The type definition follows the CRD shape from osac-operator (single cidrs list + ip_family, not separate IPv4/IPv6 fields like Subnet). All spec fields are immutable after creation. The state enum uses PENDING (consistent with all other networking resources), and status includes capacity fields (total, allocated, available).

The service defines List, Get, Create, Update, Delete, and Signal RPCs with gRPC-gateway HTTP annotations on all except Signal.

Testing

Proto validation:

buf lint   # passed
buf generate   # 6 Go files generated (2 type + 4 service)
go build ./...   # passed
go run github.com/onsi/ginkgo/v2/ginkgo run -r --skip-package=it   # 33 suites, all passed

Container build and deploy to edge-22:

g-container-build -t fulfillment-service:mgmt-23732-proto .   # succeeded
podman push quay.io/rh-ee-anadkarn/fulfillment-service:mgmt-23732-proto   # succeeded
oc set image deployment/fulfillment-{controller,grpc-server,rest-gateway} ...   # all 3 rolled out
oc logs deployment/fulfillment-grpc-server -n osac-devel --since=2m   # clean startup, no errors
oc logs deployment/fulfillment-controller -n osac-devel --since=30s   # healthy after rollout settling

Pre-merge ToDos

  1. After merge, CI pushes new BSR tag for buf.build/osac-project/private-api
  2. Update osac-operator buf.gen.yaml to reference the new BSR tag, then buf mod update && buf generate (needed for MGMT-23733 Phase 5 feedback controller)

Related PRs

Ticket

MGMT-23759 (subtask of MGMT-23732, epic MGMT-23730)


Assisted-by: Cursor/Claude

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

openshift-ci Bot commented Apr 13, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: akshaynadkarni

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot

openshift-ci-robot commented Apr 13, 2026 •

Copy link
Copy Markdown

@akshaynadkarni: This pull request references MGMT-23759 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

MGMT-23759: Define the PublicIPPool proto type and gRPC service in the private API, the first subtask of MGMT-23732 (PublicIPPool Backend).

The type definition follows the CRD shape from osac-operator (single cidrs list + ip_family, not separate IPv4/IPv6 fields like Subnet). All spec fields are immutable after creation. The state enum uses PENDING (consistent with all other networking resources), and status includes capacity fields (total, allocated, available).

The service defines List, Get, Create, Update, Delete, and Signal RPCs with gRPC-gateway HTTP annotations on all except Signal.

Testing

Proto validation:

buf lint   # passed
buf generate   # 6 Go files generated (2 type + 4 service)
go build ./...   # passed
go run github.com/onsi/ginkgo/v2/ginkgo run -r --skip-package=it   # 33 suites, all passed

Container build and deploy to edge-22:

g-container-build -t fulfillment-service:mgmt-23732-proto .   # succeeded
podman push quay.io/rh-ee-anadkarn/fulfillment-service:mgmt-23732-proto   # succeeded
oc set image deployment/fulfillment-{controller,grpc-server,rest-gateway} ...   # all 3 rolled out
oc logs deployment/fulfillment-grpc-server -n osac-devel --since=2m   # clean startup, no errors
oc logs deployment/fulfillment-controller -n osac-devel --since=30s   # healthy after rollout settling

Pre-merge ToDos

  1. After merge, CI pushes new BSR tag for buf.build/osac-project/private-api
  2. Update osac-operator buf.gen.yaml to reference the new BSR tag, then buf mod update && buf generate (needed for MGMT-23733 Phase 5 feedback controller)

Related PRs

Ticket

MGMT-23759 (subtask of MGMT-23732, epic MGMT-23730)


Assisted-by: Cursor/Claude

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@akshaynadkarni akshaynadkarni changed the title MGMT-23759: define PublicIPPool proto type and service MGMT-23732/MGMT-23759: define PublicIPPool proto type and service Apr 13, 2026
@akshaynadkarni
akshaynadkarni marked this pull request as ready for review April 13, 2026 21:00
@openshift-ci
openshift-ci Bot requested review from larsks and tzvatot April 13, 2026 21:00
@openshift-ci-robot

openshift-ci-robot commented Apr 13, 2026 •

Copy link
Copy Markdown

@akshaynadkarni: This pull request references MGMT-23759 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

MGMT-23759: Define the PublicIPPool proto type and gRPC service in the private API, the first subtask of MGMT-23732 (PublicIPPool Backend).

The type definition follows the CRD shape from osac-operator (single cidrs list + ip_family, not separate IPv4/IPv6 fields like Subnet). All spec fields are immutable after creation. The state enum uses PENDING (consistent with all other networking resources), and status includes capacity fields (total, allocated, available).

The service defines List, Get, Create, Update, Delete, and Signal RPCs with gRPC-gateway HTTP annotations on all except Signal.

Testing

Proto validation:

buf lint   # passed
buf generate   # 6 Go files generated (2 type + 4 service)
go build ./...   # passed
go run github.com/onsi/ginkgo/v2/ginkgo run -r --skip-package=it   # 33 suites, all passed

Container build and deploy to edge-22:

g-container-build -t fulfillment-service:mgmt-23732-proto .   # succeeded
podman push quay.io/rh-ee-anadkarn/fulfillment-service:mgmt-23732-proto   # succeeded
oc set image deployment/fulfillment-{controller,grpc-server,rest-gateway} ...   # all 3 rolled out
oc logs deployment/fulfillment-grpc-server -n osac-devel --since=2m   # clean startup, no errors
oc logs deployment/fulfillment-controller -n osac-devel --since=30s   # healthy after rollout settling

Pre-merge ToDos

  1. After merge, CI pushes new BSR tag for buf.build/osac-project/private-api
  2. Update osac-operator buf.gen.yaml to reference the new BSR tag, then buf mod update && buf generate (needed for MGMT-23733 Phase 5 feedback controller)

Related PRs

Ticket

MGMT-23759 (subtask of MGMT-23732, epic MGMT-23730)


Assisted-by: Cursor/Claude

Summary by CodeRabbit

Release Notes

  • New Features
  • Added Public IP Pool management functionality, enabling users to create, retrieve, update, and delete IP address pools.
  • IP pools now track lifecycle states, capacity metrics (total, allocated, available), and maintain regional configuration settings.
  • Added ability to signal reconciliation for IP pool synchronization.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Apr 13, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@akshaynadkarni has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 30 minutes and 12 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 30 minutes and 12 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9888025c-9906-4690-8329-086255d38c17

📥 Commits

Reviewing files that changed from the base of the PR and between 0a07c5c and cda16f4.

⛔ Files ignored due to path filters (6)
  • internal/api/osac/private/v1/public_ip_pool_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pool_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pools_service.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pools_service.pb.gw.go is excluded by !**/*.pb.gw.go
  • internal/api/osac/private/v1/public_ip_pools_service_grpc.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pools_service_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (2)
  • proto/private/osac/private/v1/public_ip_pool_type.proto
  • proto/private/osac/private/v1/public_ip_pools_service.proto

Walkthrough

Adds two new protobuf files in package osac.private.v1: public_ip_pool_type.proto defining PublicIPPool, PublicIPPoolSpec (fields: cidrs, ip_family, implementation_strategy marked output-only/immutable), PublicIPPoolStatus (state, optional message, hub, total, allocated, available), and enums IPFamily and PublicIPPoolState; and public_ip_pools_service.proto defining the PublicIPPools gRPC service with messages and RPCs for List, Get, Create, Update (with FieldMask and lock), Delete, and Signal. REST HTTP bindings are declared for all RPCs except Signal.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Suggested labels

lgtm

Suggested reviewers

  • adriengentil
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main changes: defining a new PublicIPPool proto type and service, with specific ticket references (MGMT-23732/MGMT-23759) for context.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@proto/private/osac/private/v1/public_ip_pool_type.proto`:
- Around line 115-127: Fields total, allocated, and available in
public_ip_pool_type.proto use int32 and will overflow for IPv6-sized pools;
change their types to int64 (or sint64/uint64 if unsigned semantics are desired)
for the fields `total`, `allocated`, and `available` in the message defined in
public_ip_pool_type.proto (the three field names exactly) so they can represent
large IPv6 CIDR capacities, and then regenerate any protobuf stubs and update
any consumer code that assumes 32-bit values to use 64-bit integers.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 58de3620-ae2c-47aa-b0a5-198955b709de

📥 Commits

Reviewing files that changed from the base of the PR and between 6be00c4 and 8751d9f.

⛔ Files ignored due to path filters (6)
  • internal/api/osac/private/v1/public_ip_pool_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pool_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pools_service.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pools_service.pb.gw.go is excluded by !**/*.pb.gw.go
  • internal/api/osac/private/v1/public_ip_pools_service_grpc.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pools_service_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (2)
  • proto/private/osac/private/v1/public_ip_pool_type.proto
  • proto/private/osac/private/v1/public_ip_pools_service.proto

Comment thread proto/private/osac/private/v1/public_ip_pool_type.proto Outdated
@akshaynadkarni

Copy link
Copy Markdown
Contributor Author

/hold

@eranco74

Copy link
Copy Markdown
Contributor

Code Review: PublicIPPool Proto Definition

✅ Overall Assessment

Excellent proto design that follows established patterns. The implementation is clean, well-documented, and consistent with existing networking resources (VirtualNetwork, Subnet, SecurityGroup).

Strengths:

  • Comprehensive proto documentation with clear state transition descriptions
  • Proper immutability design (spec fields immutable after creation)
  • Consistent state enum naming (PENDING maps from CRD Progressing phase)
  • Good capacity tracking fields (total/allocated/available)
  • All CI checks passing (buf lint, unit tests, integration tests)

🔴 Critical Issue: Integer Overflow Risk for IPv6 Pools

File: proto/private/osac/private/v1/public_ip_pool_type.proto
Lines: 115-127

Problem: The capacity fields use int32:

int32 total = 4;
int32 allocated = 5;
int32 available = 6;

Impact: A single IPv6 /64 CIDR contains 2^64 addresses (~18.4 quintillion), which exceeds int32 max value (2,147,483,647). This will cause integer overflow for any IPv6 pool.

Recommended Fix:

int64 total = 4;      // Changed from int32
int64 allocated = 5;  // Changed from int32
int64 available = 6;  // Changed from int32

Action Items:

  1. Update the three capacity fields in PublicIPPoolStatus to int64
  2. Run buf generate proto to regenerate Go code
  3. Verify the generated .pb.go files use int64
  4. Coordinate with osac-operator PR Add clearer error message when user attempts to access fulfillment-service with missing groups claim #176 to update CRD types to match

📝 Note on Proto Consistency

This issue also exists in the osac-operator CRD (api/v1alpha1/publicippool_types.go), which uses int32 for the same fields. Both should be updated together to maintain consistency between the proto schema and the Kubernetes CR.


Recommendation: Address the int64 change before merge, as it's a breaking schema change that's easier to fix now than after the BSR tag is published and consumed by osac-operator.

@openshift-ci-robot

openshift-ci-robot commented Apr 14, 2026 •

Copy link
Copy Markdown

@akshaynadkarni: This pull request references MGMT-23759 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

MGMT-23759: Define the PublicIPPool proto type and gRPC service in the private API, the first subtask of MGMT-23732 (PublicIPPool Backend).

The type definition follows the CRD shape from osac-operator (single cidrs list + ip_family, not separate IPv4/IPv6 fields like Subnet). All spec fields are immutable after creation. The state enum uses PENDING (consistent with all other networking resources), and status includes capacity fields (total, allocated, available).

The service defines List, Get, Create, Update, Delete, and Signal RPCs with gRPC-gateway HTTP annotations on all except Signal.

Testing

Proto validation:

buf lint   # passed
buf generate   # 6 Go files generated (2 type + 4 service)
go build ./...   # passed
go run github.com/onsi/ginkgo/v2/ginkgo run -r --skip-package=it   # 33 suites, all passed

Container build and deploy to edge-22:

g-container-build -t fulfillment-service:mgmt-23732-proto .   # succeeded
podman push quay.io/rh-ee-anadkarn/fulfillment-service:mgmt-23732-proto   # succeeded
oc set image deployment/fulfillment-{controller,grpc-server,rest-gateway} ...   # all 3 rolled out
oc logs deployment/fulfillment-grpc-server -n osac-devel --since=2m   # clean startup, no errors
oc logs deployment/fulfillment-controller -n osac-devel --since=30s   # healthy after rollout settling

Pre-merge ToDos

  1. After merge, CI pushes new BSR tag for buf.build/osac-project/private-api
  2. Update osac-operator buf.gen.yaml to reference the new BSR tag, then buf mod update && buf generate (needed for MGMT-23733 Phase 5 feedback controller)

Related PRs

Ticket

MGMT-23759 (subtask of MGMT-23732, epic MGMT-23730)


Assisted-by: Cursor/Claude

Summary by CodeRabbit

Release Notes

  • New Features
  • Public IP Pool management: create, list, retrieve, update, and delete IP pools.
  • Pools include region, CIDR(s), IP family, lifecycle states, and capacity metrics (total, allocated, available).
  • Support for signaling reconciliation to trigger synchronization of an IP pool.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
proto/private/osac/private/v1/public_ip_pool_type.proto (1)

42-43: Add google.api.field_behavior = OUTPUT_ONLY annotation to the status field.

The status field is documented as read-only but lacks the explicit OUTPUT_ONLY annotation used elsewhere in this file (e.g., on implementation_strategy). This annotation clarifies the read-only contract for generated clients and aligns with Google Cloud API conventions.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@proto/private/osac/private/v1/public_ip_pool_type.proto` around lines 42 -
43, The proto's status field is documented read-only but missing the explicit
annotation; update the status field declaration (the PublicIPPoolStatus status =
4 field) to include the google.api.field_behavior = OUTPUT_ONLY option—i.e., add
[(google.api.field_behavior) = OUTPUT_ONLY] to the field—making sure the
google/api/field_behavior.proto import is present (as used for
implementation_strategy) and that the field syntax and semicolon remain valid.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@proto/private/osac/private/v1/public_ip_pool_type.proto`:
- Around line 42-43: The proto's status field is documented read-only but
missing the explicit annotation; update the status field declaration (the
PublicIPPoolStatus status = 4 field) to include the google.api.field_behavior =
OUTPUT_ONLY option—i.e., add [(google.api.field_behavior) = OUTPUT_ONLY] to the
field—making sure the google/api/field_behavior.proto import is present (as used
for implementation_strategy) and that the field syntax and semicolon remain
valid.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9284d016-88b6-46d6-94b0-7a1922f2238e

📥 Commits

Reviewing files that changed from the base of the PR and between 8751d9f and 23d73ea.

⛔ Files ignored due to path filters (2)
  • internal/api/osac/private/v1/public_ip_pool_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/public_ip_pool_type_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (1)
  • proto/private/osac/private/v1/public_ip_pool_type.proto

@akshaynadkarni

akshaynadkarni commented Apr 14, 2026 •

Copy link
Copy Markdown
Contributor Author

Code Review: PublicIPPool Proto Definition

✅ Overall Assessment

Excellent proto design that follows established patterns. The implementation is clean, well-documented, and consistent with existing networking resources (VirtualNetwork, Subnet, SecurityGroup).

Strengths:

  • Comprehensive proto documentation with clear state transition descriptions
  • Proper immutability design (spec fields immutable after creation)
  • Consistent state enum naming (PENDING maps from CRD Progressing phase)
  • Good capacity tracking fields (total/allocated/available)
  • All CI checks passing (buf lint, unit tests, integration tests)

🔴 Critical Issue: Integer Overflow Risk for IPv6 Pools

File: proto/private/osac/private/v1/public_ip_pool_type.proto Lines: 115-127

Problem: The capacity fields use int32:

int32 total = 4;
int32 allocated = 5;
int32 available = 6;

Impact: A single IPv6 /64 CIDR contains 2^64 addresses (~18.4 quintillion), which exceeds int32 max value (2,147,483,647). This will cause integer overflow for any IPv6 pool.

Recommended Fix:

int64 total = 4;      // Changed from int32
int64 allocated = 5;  // Changed from int32
int64 available = 6;  // Changed from int32

Action Items:

  1. Update the three capacity fields in PublicIPPoolStatus to int64
  2. Run buf generate proto to regenerate Go code
  3. Verify the generated .pb.go files use int64
  4. Coordinate with osac-operator PR Add clearer error message when user attempts to access fulfillment-service with missing groups claim #176 to update CRD types to match

📝 Note on Proto Consistency

This issue also exists in the osac-operator CRD (api/v1alpha1/publicippool_types.go), which uses int32 for the same fields. Both should be updated together to maintain consistency between the proto schema and the Kubernetes CR.

Recommendation: Address the int64 change before merge, as it's a breaking schema change that's easier to fix now than after the BSR tag is published and consumed by osac-operator.

@eranco74 I have updated the counters to use int64. PTAL.

@eranco74

Copy link
Copy Markdown
Contributor

/lgtm

@akshaynadkarni

Copy link
Copy Markdown
Contributor Author

/unhold

@akshaynadkarni

Copy link
Copy Markdown
Contributor Author

/hold

@akshaynadkarni
akshaynadkarni force-pushed the mgmt-23732-publicippool-support branch from 23d73ea to 0a07c5c Compare April 14, 2026 15:53
@openshift-ci openshift-ci Bot removed the lgtm label Apr 14, 2026
@openshift-ci-robot

openshift-ci-robot commented Apr 14, 2026 •

Copy link
Copy Markdown

@akshaynadkarni: This pull request references MGMT-23759 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

MGMT-23759: Define the PublicIPPool proto type and gRPC service in the private API, the first subtask of MGMT-23732 (PublicIPPool Backend).

The type definition follows the CRD shape from osac-operator (single cidrs list + ip_family, not separate IPv4/IPv6 fields like Subnet). All spec fields are immutable after creation. The state enum uses PENDING (consistent with all other networking resources), and status includes capacity fields (total, allocated, available).

The service defines List, Get, Create, Update, Delete, and Signal RPCs with gRPC-gateway HTTP annotations on all except Signal.

Testing

Proto validation:

buf lint   # passed
buf generate   # 6 Go files generated (2 type + 4 service)
go build ./...   # passed
go run github.com/onsi/ginkgo/v2/ginkgo run -r --skip-package=it   # 33 suites, all passed

Container build and deploy to edge-22:

g-container-build -t fulfillment-service:mgmt-23732-proto .   # succeeded
podman push quay.io/rh-ee-anadkarn/fulfillment-service:mgmt-23732-proto   # succeeded
oc set image deployment/fulfillment-{controller,grpc-server,rest-gateway} ...   # all 3 rolled out
oc logs deployment/fulfillment-grpc-server -n osac-devel --since=2m   # clean startup, no errors
oc logs deployment/fulfillment-controller -n osac-devel --since=30s   # healthy after rollout settling

Pre-merge ToDos

  1. After merge, CI pushes new BSR tag for buf.build/osac-project/private-api
  2. Update osac-operator buf.gen.yaml to reference the new BSR tag, then buf mod update && buf generate (needed for MGMT-23733 Phase 5 feedback controller)

Related PRs

Ticket

MGMT-23759 (subtask of MGMT-23732, epic MGMT-23730)


Assisted-by: Cursor/Claude

Summary by CodeRabbit

  • New Features
  • Public IP Pool management: create, list (with pagination, filtering, ordering), retrieve, update, and delete pools.
  • Pools expose region, CIDR(s), IP family, lifecycle states, and capacity metrics (total, allocated, available).
  • Support for signaling reconciliation to trigger synchronization of an IP pool.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@akshaynadkarni
akshaynadkarni force-pushed the mgmt-23732-publicippool-support branch 3 times, most recently from af0c773 to 838cc56 Compare April 14, 2026 16:07
Add the PublicIPPool resource to the private API with a type definition
and a gRPC service supporting List, Get, Create, Update, Delete, and
Signal RPCs. HTTP annotations are on all RPCs except Signal (internal
controller use only).

The spec follows the CRD shape from osac-operator: single `cidrs` list
with an `ip_family` discriminator (not separate IPv4/IPv6 fields like
Subnet). All spec fields are immutable after creation. The Update RPC
is metadata-only (name, labels, annotations).
`implementation_strategy` is OUTPUT_ONLY, set by the server.

The state enum uses PENDING (not PROGRESSING), consistent with all
other networking resources in the private API. CRD phase "Progressing"
maps to proto PENDING via the feedback controller.

Status includes capacity fields (total, allocated, available) as int32,
matching the CRD.

Assisted-by: Cursor/Claude
The total, allocated, and available fields in PublicIPPoolStatus used
int32, which overflows for IPv6 CIDR ranges (a /96 alone exceeds
int32 max). Changed to int64 to correctly represent address counts
for both IPv4 and IPv6 pools.

Assisted-by: Cursor/Claude
Region is a placeholder with no current use. Removed it from the
PublicIPPoolSpec and all references in comments and filter examples.

Converted ip_family from string to an IPFamily enum (IP_FAMILY_IPV4,
IP_FAMILY_IPV6) for type safety, consistent with how the codebase
uses enums for constrained value sets (Protocol, State enums).

Assisted-by: Cursor/Claude
@akshaynadkarni
akshaynadkarni force-pushed the mgmt-23732-publicippool-support branch from 838cc56 to cda16f4 Compare April 14, 2026 19:07
@eranco74

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm label Apr 15, 2026
@akshaynadkarni

Copy link
Copy Markdown
Contributor Author

/unhold

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants