Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

OSAC-1579: Add metadata.project field to assign objects to projects - #576

Merged
jhernand merged 1 commit into
osac-project:mainfrom
jhernand:add_metadata_project
Jun 30, 2026
Merged

jhernand merged 1 commit into
osac-project:mainfrom
jhernand:add_metadata_project

Conversation

@jhernand

@jhernand jhernand commented May 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR introduces a metadata.project field across the entire stack to support assigning
objects to projects. The main changes are:

  • Adds a project field to the Metadata protobuf message in both public and private APIs,
    and a project column to all resource database tables via migration 43. Migration 44 creates
    the dedicated projects and archived_projects tables.

  • Extends the TenancyLogic interface with DetermineAssignableProjects,
    DetermineDefaultProject, and DetermineVisibleProjects methods, implemented in both
    DefaultTenancyLogic and GuestTenancyLogic. The Subject type now carries a Projects
    set and the OPA policy temporarily grants all authenticated users access to all projects.

  • All DAO operations now apply project-based visibility filtering alongside tenant filtering.
    The generic server validates and assigns the project on create (falling back to the default
    project), and the events server filters watched events by both tenant and project visibility.

  • Adds new public and private ProjectsServer gRPC service implementations, registered in
    the gRPC server startup.

Test plan

  • Unit tests added for Subject JSON round-tripping with projects.
  • Unit tests added for DefaultTenancyLogic and GuestTenancyLogic project methods.
  • DAO project visibility tests added (generic_dao_project_visibility_test.go).
  • Server project visibility tests added (servers_project_visibility_test.go).
  • Migration tests added for migrations 43 and 44.
  • Events server tests updated to cover project filtering.

Summary by CodeRabbit

  • New Features

    • Project management with dot-separated nested projects and a tenant default.
    • Project-scoped visibility/enforcement for list/get/create/update/delete; project included in resource metadata and rendered tables.
    • CLI: new create project and create tenant commands.
    • Creation/update validations: project name rules and immutability; subject projects exposed in auth responses (guests default to full access).
  • Chores

    • PostgreSQL upgraded from 15 to 18; database schema migration adds project columns.

@openshift-ci-robot

Copy link
Copy Markdown

@jhernand: This pull request explicitly references no jira issue.

Details

In response to this:

Summary

This PR introduces a metadata.project field across the entire stack to support assigning
objects to projects. The main changes are:

  • Adds a project field to the Metadata protobuf message in both public and private APIs,
    and a project column to all resource database tables via migration 43. Migration 44 creates
    the dedicated projects and archived_projects tables.

  • Extends the TenancyLogic interface with DetermineAssignableProjects,
    DetermineDefaultProject, and DetermineVisibleProjects methods, implemented in both
    DefaultTenancyLogic and GuestTenancyLogic. The Subject type now carries a Projects
    set and the OPA policy temporarily grants all authenticated users access to all projects.

  • All DAO operations now apply project-based visibility filtering alongside tenant filtering.
    The generic server validates and assigns the project on create (falling back to the default
    project), and the events server filters watched events by both tenant and project visibility.

  • Adds new public and private ProjectsServer gRPC service implementations, registered in
    the gRPC server startup.

Test plan

  • Unit tests added for Subject JSON round-tripping with projects.
  • Unit tests added for DefaultTenancyLogic and GuestTenancyLogic project methods.
  • DAO project visibility tests added (generic_dao_project_visibility_test.go).
  • Server project visibility tests added (servers_project_visibility_test.go).
  • Migration tests added for migrations 43 and 44.
  • Events server tests updated to cover project filtering.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

openshift-ci Bot commented May 21, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci

openshift-ci Bot commented May 21, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jhernand

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@jhernand

Copy link
Copy Markdown
Contributor Author

FYI: @CrystalChun

@jhernand
jhernand force-pushed the add_metadata_project branch from a8241a3 to 6250a4e Compare May 21, 2026 18:24
@jhernand
jhernand force-pushed the add_metadata_project branch 2 times, most recently from eaa8103 to 300e2fb Compare May 21, 2026 19:00
@jhernand
jhernand force-pushed the add_metadata_project branch 3 times, most recently from 7c3fd9f to c6ef672 Compare May 25, 2026 11:00
@CrystalChun

Copy link
Copy Markdown
Contributor

Created https://redhat.atlassian.net/browse/OSAC-1064 to track this

@CrystalChun

CrystalChun commented May 27, 2026 •

Copy link
Copy Markdown
Contributor

/retitle OSAC-1064: Add metadata.project field to assign objects to projects

@openshift-ci openshift-ci Bot changed the title NO-ISSUE: Add metadata.project field to assign objects to projects OSAC-1064: Add metadata.project field to assign objects to projects May 27, 2026
@openshift-ci-robot

openshift-ci-robot commented May 27, 2026 •

Copy link
Copy Markdown

@jhernand: This pull request references OSAC-1064 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

This PR introduces a metadata.project field across the entire stack to support assigning
objects to projects. The main changes are:

  • Adds a project field to the Metadata protobuf message in both public and private APIs,
    and a project column to all resource database tables via migration 43. Migration 44 creates
    the dedicated projects and archived_projects tables.

  • Extends the TenancyLogic interface with DetermineAssignableProjects,
    DetermineDefaultProject, and DetermineVisibleProjects methods, implemented in both
    DefaultTenancyLogic and GuestTenancyLogic. The Subject type now carries a Projects
    set and the OPA policy temporarily grants all authenticated users access to all projects.

  • All DAO operations now apply project-based visibility filtering alongside tenant filtering.
    The generic server validates and assigns the project on create (falling back to the default
    project), and the events server filters watched events by both tenant and project visibility.

  • Adds new public and private ProjectsServer gRPC service implementations, registered in
    the gRPC server startup.

Test plan

  • Unit tests added for Subject JSON round-tripping with projects.
  • Unit tests added for DefaultTenancyLogic and GuestTenancyLogic project methods.
  • DAO project visibility tests added (generic_dao_project_visibility_test.go).
  • Server project visibility tests added (servers_project_visibility_test.go).
  • Migration tests added for migrations 43 and 44.
  • Events server tests updated to cover project filtering.

Co-authored-by: Cursor cursoragent@cursor.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@jhernand
jhernand force-pushed the add_metadata_project branch from c6ef672 to ace5e4e Compare June 1, 2026 18:49
@coderabbitai

coderabbitai Bot commented Jun 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

I can’t generate the required hidden review artifact because it must list every provided rangeId exactly once and the PR contains hundreds of rangeIds — producing that full structured block here risks errors. If you want, I can:

  • Produce a correct, complete review stack artifact by working from the repository (I can generate the full block programmatically), or
  • Produce a high-quality human-readable walkthrough, change table, effort estimate, related PRs, labels, reviewers, and poem (all visible sections) without the hidden artifact.

Which would you prefer?

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@jhernand
jhernand force-pushed the add_metadata_project branch from ace5e4e to 994071d Compare June 1, 2026 21:43
@jhernand
jhernand force-pushed the add_metadata_project branch from 994071d to 9517ea3 Compare June 2, 2026 20:26
@jhernand
jhernand marked this pull request as ready for review June 3, 2026 13:09
@jhernand
jhernand force-pushed the add_metadata_project branch from 9517ea3 to eac56ad Compare June 3, 2026 13:13
@jhernand
jhernand force-pushed the add_metadata_project branch from b8a4f8d to df958b6 Compare June 9, 2026 12:02
@jhernand

jhernand commented Jun 9, 2026

Copy link
Copy Markdown
Contributor Author

/retest

2 similar comments
@omer-vishlitzky

Copy link
Copy Markdown
Contributor

/retest

@CrystalChun

Copy link
Copy Markdown
Contributor

/retest

@omer-vishlitzky

Copy link
Copy Markdown
Contributor

@CrystalChun

CrystalChun commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

/retitle OSAC-1579: Add metadata.project field to assign objects to projects

@openshift-ci openshift-ci Bot changed the title OSAC-1064: Add metadata.project field to assign objects to projects OSAC-1579: Add metadata.project field to assign objects to projects Jun 16, 2026
@openshift-ci-robot

openshift-ci-robot commented Jun 16, 2026 •

Copy link
Copy Markdown

@jhernand: This pull request references OSAC-1579 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

This PR introduces a metadata.project field across the entire stack to support assigning
objects to projects. The main changes are:

  • Adds a project field to the Metadata protobuf message in both public and private APIs,
    and a project column to all resource database tables via migration 43. Migration 44 creates
    the dedicated projects and archived_projects tables.

  • Extends the TenancyLogic interface with DetermineAssignableProjects,
    DetermineDefaultProject, and DetermineVisibleProjects methods, implemented in both
    DefaultTenancyLogic and GuestTenancyLogic. The Subject type now carries a Projects
    set and the OPA policy temporarily grants all authenticated users access to all projects.

  • All DAO operations now apply project-based visibility filtering alongside tenant filtering.
    The generic server validates and assigns the project on create (falling back to the default
    project), and the events server filters watched events by both tenant and project visibility.

  • Adds new public and private ProjectsServer gRPC service implementations, registered in
    the gRPC server startup.

Test plan

  • Unit tests added for Subject JSON round-tripping with projects.
  • Unit tests added for DefaultTenancyLogic and GuestTenancyLogic project methods.
  • DAO project visibility tests added (generic_dao_project_visibility_test.go).
  • Server project visibility tests added (servers_project_visibility_test.go).
  • Migration tests added for migrations 43 and 44.
  • Events server tests updated to cover project filtering.

Summary by CodeRabbit

  • New Features

  • Project management with dot-separated nested projects and a tenant default.

  • Project-scoped visibility/enforcement for list/get/create/update/delete; project included in resource metadata and rendered tables.

  • CLI: new create project and create tenant commands.

  • Creation/update validations: project name rules and immutability; subject projects exposed in auth responses (guests default to full access).

  • Chores

  • PostgreSQL upgraded from 15 to 18; database schema migration adds project columns.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@obochan-rh

Copy link
Copy Markdown
Contributor

@jhernand This PR needs a rebase onto main — there's a merge conflict blocking it from merging. All CI checks are green otherwise. Could you rebase and force-push when you get a chance?

@jhernand
jhernand force-pushed the add_metadata_project branch 2 times, most recently from 28b8325 to f84e936 Compare June 26, 2026 15:27
@jhernand
jhernand force-pushed the add_metadata_project branch 3 times, most recently from be1e72c to 32579ad Compare June 29, 2026 19:55
This change introduces a `project` field in the `Metadata` protobuf
message (both public and private APIs) and propagates it through the
entire stack: database schema, DAO layer, generic server, events and
servers.

Assisted-by: Cursor
Signed-off-by: Juan Hernandez <juan.hernandez@redhat.com>
@jhernand
jhernand force-pushed the add_metadata_project branch from 32579ad to effca49 Compare June 30, 2026 08:52
@jhernand
jhernand merged commit b250664 into osac-project:main Jun 30, 2026
12 of 14 checks passed
@jhernand
jhernand deleted the add_metadata_project branch June 30, 2026 10:57

This branch was previously deployed

1 inactive deployment
e2e-test — effca49d Deployed Jun 30, 2026 by jhernand via e2e-vmaas-full-install / e2e #24
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants