Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

MGMT-22992: Add role and role binding reconciler skeletons - #486

Merged
openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
jhernand:MGMT_22992_add_role_and_role_binding_reconcilers
May 5, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
jhernand:MGMT_22992_add_role_and_role_binding_reconcilers

Conversation

@jhernand

@jhernand jhernand commented May 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add role and role_binding payloads to both the private and public Event messages so that the reconciler watch/LIST sync mechanisms and public event streaming work correctly.
  • Register both types in GenericServer.setPayload for NOTIFY and add corresponding extractMetadata cases in the public events server.
  • Wire skeleton reconcilers in start_controller_cmd that add the controller finalizer, set default status, and log the reconciled object. The actual reconciliation logic will be added in later patches.

Test plan

  • buf lint passes.
  • go build ./... succeeds.
  • Existing unit tests pass (ginkgo run -r internal).
  • Verify that role and role binding CRUD operations generate events picked up by the new reconcilers.

Related: https://redhat.atlassian.net/browse/MGMT-22992

Summary by CodeRabbit

  • New Features
    • Added automatic reconciliation and synchronization capabilities for Role and RoleBinding resources to maintain consistent state across the system.
    • Extended event notifications to include Role and RoleBinding resource events, enabling real-time visibility into role and role binding lifecycle changes including creation, updates, and deletions.

@openshift-ci-robot

openshift-ci-robot commented May 5, 2026 •

Copy link
Copy Markdown

@jhernand: This pull request references MGMT-22992 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Add role and role_binding payloads to both the private and public Event messages so that the reconciler watch/LIST sync mechanisms and public event streaming work correctly.
  • Register both types in GenericServer.setPayload for NOTIFY and add corresponding extractMetadata cases in the public events server.
  • Wire skeleton reconcilers in start_controller_cmd that add the controller finalizer, set default status, and log the reconciled object. The actual reconciliation logic will be added in later patches.

Test plan

  • buf lint passes.
  • go build ./... succeeds.
  • Existing unit tests pass (ginkgo run -r internal).
  • Verify that role and role binding CRUD operations generate events picked up by the new reconcilers.

Related: https://redhat.atlassian.net/browse/MGMT-22992

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from adriengentil and eranco74 May 5, 2026 11:10
@openshift-ci openshift-ci Bot added the approved label May 5, 2026
@jhernand
jhernand requested review from CrystalChun and removed request for adriengentil and eranco74 May 5, 2026 11:10
@coderabbitai

coderabbitai Bot commented May 5, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@jhernand has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 34 minutes and 51 seconds before requesting another review.

To keep reviews running without waiting, you can enable usage-based add-on for your organization. This allows additional reviews beyond the hourly cap. Account admins can enable it under billing.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: c9489393-46c0-4299-af15-f2ceb3f25452

📥 Commits

Reviewing files that changed from the base of the PR and between fd1cd8c and 7128249.

⛔ Files ignored due to path filters (4)
  • internal/api/osac/private/v1/event_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/event_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/event_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/event_type_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (10)
  • internal/cmd/service/start/controller/start_controller_cmd.go
  • internal/controllers/role/role_reconciler_function.go
  • internal/controllers/rolebinding/role_binding_reconciler_function.go
  • internal/servers/events_server.go
  • internal/servers/generic_server.go
  • it/it_role_binding_reconciler_test.go
  • it/it_role_reconciler_test.go
  • it/it_roles_test.go
  • proto/private/osac/private/v1/event_type.proto
  • proto/public/osac/public/v1/event_type.proto

Walkthrough

This pull request adds support for two new Kubernetes reconcilers—Role and RoleBinding—to the controller service. The changes include implementing two reconciler functions with a FunctionBuilder pattern, wiring them into the controller startup flow, extending protobuf event message definitions to support Role and RoleBinding payloads in both public and private event types, and updating server-side payload handling to process the new event object types in both the generic and events servers.

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

Suggested reviewers

  • CrystalChun
  • akshaynadkarni
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: adding role and role binding reconciler skeletons. It is concise, specific, and directly related to the primary objective of the pull request.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
internal/controllers/role/role_reconciler_function.go (1)

64-70: 💤 Low value

Consider explicitly capturing the result of masks.NewCalculator().Build()

Although Build() currently returns only *Calculator, inlining it into the struct literal means any future error return would be silently dropped. Extracting it would be safer for future maintenance:

maskCalculator, err := masks.NewCalculator().Build()
if err != nil {
  return nil, err
}
result = &function{
  logger:      b.logger,
  rolesClient: privatev1.NewRolesClient(b.connection),
  maskCalculator: maskCalculator,
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/controllers/role/role_reconciler_function.go` around lines 64 - 70,
Extract the call to masks.NewCalculator().Build() into a local variable (e.g.,
maskCalculator, err := masks.NewCalculator().Build()), check and return the
error if non-nil, and then set maskCalculator in the &function{...} struct
instead of inlining the call; update the surrounding constructor that returns
result to propagate the error (return nil, err) when Build() fails so future
changes to Build() won't silently drop errors.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@internal/controllers/role/role_reconciler_function.go`:
- Around line 64-70: Extract the call to masks.NewCalculator().Build() into a
local variable (e.g., maskCalculator, err := masks.NewCalculator().Build()),
check and return the error if non-nil, and then set maskCalculator in the
&function{...} struct instead of inlining the call; update the surrounding
constructor that returns result to propagate the error (return nil, err) when
Build() fails so future changes to Build() won't silently drop errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: c75454fb-5019-49ac-b03e-2b4418491185

📥 Commits

Reviewing files that changed from the base of the PR and between d0b6b0c and fd1cd8c.

⛔ Files ignored due to path filters (4)
  • internal/api/osac/private/v1/event_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/event_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/event_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/event_type_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (7)
  • internal/cmd/service/start/controller/start_controller_cmd.go
  • internal/controllers/role/role_reconciler_function.go
  • internal/controllers/rolebinding/role_binding_reconciler_function.go
  • internal/servers/events_server.go
  • internal/servers/generic_server.go
  • proto/private/osac/private/v1/event_type.proto
  • proto/public/osac/public/v1/event_type.proto

Add `role` and `role_binding` payloads to both the private and public
`Event` messages so the reconciler watch and list sync mechanisms work
correctly. Register both types in `GenericServer.setPayload` for notify
and add the corresponding `extractMetadata` cases in the public events
server.

Wire the reconcilers in `start_controller_cmd`. For now these are only
skeletons that add the controller finalizer, set default status, and log
the object being reconciled. The actual reconciliation logic will be
added in later patches.

Related: https://redhat.atlassian.net/browse/MGMT-22992
Signed-off-by: Juan Hernandez <juan.hernandez@redhat.com>
@jhernand
jhernand force-pushed the MGMT_22992_add_role_and_role_binding_reconcilers branch from fd1cd8c to 7128249 Compare May 5, 2026 11:35

@CrystalChun CrystalChun left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci

openshift-ci Bot commented May 5, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: CrystalChun, jhernand

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit b70fa71 into osac-project:main May 5, 2026
12 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants