Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

NO-ISSUE: Add builtin system and shared organizations - #596

Merged
jhernand merged 1 commit into
osac-project:mainfrom
jhernand:add_builtin_tenants
May 28, 2026
Merged

jhernand merged 1 commit into
osac-project:mainfrom
jhernand:add_builtin_tenants

Conversation

@jhernand

@jhernand jhernand commented May 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This is a preparatory step towards making the tenant field mandatory and enforcing that every
tenant references an existing organization via a database foreign key constraint. For that to
work the system and shared tenants, which are already used by convention throughout the
codebase, must exist as rows in the organizations table.

  • Migration 46 inserts both organizations with matching id, name, and tenant columns
    (e.g. system/system/system).
  • The list tests in the organization servers are updated to filter by name so they remain
    deterministic now that the table is no longer empty at test start.
  • A migration test verifies the rows are created correctly.
  • An integration test confirms both organizations are retrievable through the private gRPC API.

Test plan

  • Migration test passes (ginkgo run --focus="Add builtin tenants" internal/database/migrations)
  • Migration coverage test passes (new migration has a corresponding test file)
  • All 30 migration tests pass (ginkgo run internal/database/migrations)
  • Organization server unit tests pass with filter adjustments
  • Integration test compiles (go vet ./it/...)
  • CI passes

Summary by CodeRabbit

Release Notes

  • New Features

    • Added builtin system and shared tenants to the platform infrastructure.
  • Tests

    • Added integration tests for builtin tenant retrieval and listing via private API.
    • Implemented explicit timeout handling (1 hour) for all test runs to improve reliability.
    • Enhanced migration test suite to support context-aware operations for better async handling.

Review Change Stack

@openshift-ci-robot

Copy link
Copy Markdown

@jhernand: This pull request explicitly references no jira issue.

Details

In response to this:

Summary

This is a preparatory step towards making the tenant field mandatory and enforcing that every
tenant references an existing organization via a database foreign key constraint. For that to
work the system and shared tenants, which are already used by convention throughout the
codebase, must exist as rows in the organizations table.

  • Migration 46 inserts both organizations with matching id, name, and tenant columns
    (e.g. system/system/system).
  • The list tests in the organization servers are updated to filter by name so they remain
    deterministic now that the table is no longer empty at test start.
  • A migration test verifies the rows are created correctly.
  • An integration test confirms both organizations are retrievable through the private gRPC API.

Test plan

  • Migration test passes (ginkgo run --focus="Add builtin tenants" internal/database/migrations)
  • Migration coverage test passes (new migration has a corresponding test file)
  • All 30 migration tests pass (ginkgo run internal/database/migrations)
  • Organization server unit tests pass with filter adjustments
  • Integration test compiles (go vet ./it/...)
  • CI passes

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested a review from adriengentil May 27, 2026 14:23
@openshift-ci

openshift-ci Bot commented May 27, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jhernand

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci
openshift-ci Bot requested a review from larsks May 27, 2026 14:23
@coderabbitai

coderabbitai Bot commented May 27, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

This PR introduces builtin tenants (system, shared) by adding migration 48 that seeds the organizations table. Context threading is applied to the migration test harness and all existing migration test cases (39–47) for consistent async handling. Integration tests validate private API access to builtin tenants. CI workflow Ginkgo invocations add explicit --timeout 1h.

Changes

Builtin Tenants Migration and Tests

Layer / File(s) Summary
Migration test harness updated to use context
internal/database/migrations/migrations_suite_test.go
BeforeSuite and DescribeMigration hooks now accept context.Context; database container start/stop and per-test setup use the provided context instead of suite-local timeout variables.
Existing migration tests (39–47) updated for context
internal/database/migrations/{39...47}_*_test.go
DescribeTable/It callbacks and local helper functions (insert, softDelete) now accept context.Context as the first parameter and thread it through all database operations. Cosmetic whitespace adjustments in test files also included.
Migration 48: builtin tenants schema and test
internal/database/migrations/48_add_builtin_tenants.up.sql, internal/database/migrations/48_add_builtin_tenants_test.go
Migration inserts two builtin organizations with id/name/tenant set to system and shared, creator set to system, and data as empty JSON. Test validates both rows exist with correct column values.
Integration tests for builtin tenants
it/it_builtin_tenants_test.go
Private OrganizationsClient is instantiated from admin connection and used to test Get and List operations on builtin tenant IDs, validating metadata presence and correct ID matching.

CI Ginkgo Timeout Configuration

Layer / File(s) Summary
Add --timeout 1h to CI ginkgo invocations
.github/workflows/check-pull-request.yaml
Three ginkgo run commands add explicit --timeout 1h flag to internal unit test, Helm integration test, and Kustomize integration test steps.

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

The PR applies consistent context-threading pattern across many migration test files (refactoring), introduces a new migration with seed data and validation, and adds integration tests. The changes are heterogeneous (context updates, SQL migration, Go tests, CI workflow) but follow clear, predictable patterns.


Possibly Related PRs


Suggested Labels

lgtm


Suggested Reviewers

  • adriengentil

Poem

🏗️ Contexts flow like rivers through the test suite,
Builtin tenants planted, system and shared take root,
Integration paths now validated and sound,
A timeout hour ensures no code gets stuck in the ground. ✨


🔕 Pre-merge checks override applied

The pre-merge checks have been overridden successfully. You can now proceed with the merge.

Overridden by @jhernand via checkbox on 2026-05-27T21:53:34.390Z.

❌ Failed checks (1 error)

Check name Status Explanation Resolution
No-Injection-Vectors ❌ Error [IGNORED] SQL injection vulnerability in newly-created 44_add_public_ip_attachments_unique_indexes_test.go: publicIP and computeInstance parameters concatenated into JSON without escaping. Use proper JSON encoding (encoding/json package) or escape special characters to prevent quote-breaking attacks in the JSON payload.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main objective of the PR: adding builtin system and shared organizations to the database. It is concise, clear, and directly related to the primary change.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets, API keys, tokens, passwords detected. Migration inserts only legitimate org identifiers (system/shared). No credential references in workflow.
No-Weak-Crypto ✅ Passed No weak cryptographic algorithms (MD5, SHA1, DES, RC4, 3DES, Blowfish, ECB), custom crypto implementations, or non-constant-time secret comparisons detected in PR changes.
Container-Privileges ✅ Passed PR adds only test files, SQL migration, and CI timeout configs. No container privileges, K8s manifests, or privilege escalation settings are modified.
No-Sensitive-Data-In-Logs ✅ Passed PR contains no logging of sensitive data; all added code introduces only non-sensitive builtin organization metadata (system/shared IDs and names) without credential exposure or debugging logs.
Ai-Attribution ✅ Passed AI tool (Cursor) used and properly attributed with "Assisted-by" trailer in commit 889af76; no improper "Co-Authored-By" for AI detected.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

@jhernand
jhernand force-pushed the add_builtin_tenants branch 2 times, most recently from 245a285 to 4eb465c Compare May 27, 2026 15:59

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@internal/database/migrations/47_add_builtin_tenants_test.go`:
- Around line 28-33: The test currently selects and asserts only name and tenant
from the seeded organization row; extend the QueryRow/row.Scan call to also scan
into variables for creator and data (e.g., add creator and data variables), then
add Expect assertions verifying creator equals the expected creator value and
that data contains or equals the expected payload (use
Expect(data).ToNot(BeNil()) or a more specific equality/match as appropriate);
update the row.Scan(&name, &tenant) to row.Scan(&name, &tenant, &creator, &data)
and add corresponding Expect(...) checks to fully cover all inserted migration
fields.
- Around line 25-31: The migration test currently uses an unbounded context
which can hang CI; create a bounded context with a timeout (e.g., via
context.WithTimeout) and use that context when calling tool.Migrate(ctx, 47) and
conn.QueryRow(ctx, ...) (and any subsequent row.Scan operations), ensuring you
call cancel() with defer to clean up; update references in this test (functions:
tool.Migrate, conn.QueryRow, row.Scan) to use the new timeout context so the
test will abort rather than hang.

In `@it/it_builtin_tenants_test.go`:
- Around line 32-35: Replace the unbounded context in the BeforeEach setup with
a timeout-scoped context by calling context.WithTimeout(context.Background(),
<reasonable duration>) and assign both ctx and its cancel function (ensure
cancel is invoked appropriately e.g., in AfterEach or via defer in the test) so
private API RPCs (used by privatev1.NewOrganizationsClient) cannot hang CI;
additionally, after calling client.Get(...) add an assertion
Expect(response).ToNot(BeNil()) before any use of response.GetObject() to avoid
dereferencing a nil response (mirror the nil-check already done for List calls).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: d1b5aa7d-0e32-45d3-8523-add47c898331

📥 Commits

Reviewing files that changed from the base of the PR and between 24fe7fb and 4eb465c.

📒 Files selected for processing (3)
  • internal/database/migrations/47_add_builtin_tenants.up.sql
  • internal/database/migrations/47_add_builtin_tenants_test.go
  • it/it_builtin_tenants_test.go

Comment thread internal/database/migrations/47_add_builtin_tenants_test.go Outdated
Comment thread internal/database/migrations/47_add_builtin_tenants_test.go Outdated
Comment thread it/it_builtin_tenants_test.go
@jhernand
jhernand force-pushed the add_builtin_tenants branch from 4eb465c to d476bea Compare May 27, 2026 19:23

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
.github/workflows/check-pull-request.yaml (2)

55-62: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Missing explicit permissions block violates least-privilege principle.

The workflow uses default GITHUB_TOKEN permissions, which grant broad read-write access to repository contents, issues, pull requests, and other scopes. These jobs only require read access to checkout code and potentially read cache.

Risk severity: Major
Impact: If the workflow or its dependencies are compromised (e.g., through supply chain attack or malicious PR exploit), an attacker gains unnecessary write permissions, allowing them to push commits, create releases, modify issues/PRs, or exfiltrate secrets from other jobs.

Add a top-level permissions block to enforce least privilege across all jobs. As per coding guidelines, CI/CD workflows must minimize GITHUB_TOKEN permissions.

🔒 Proposed fix to add least-privilege permissions

Add this block after line 21 (after the on: trigger section):

     branches:
     - main
 
+permissions:
+  contents: read
+
 jobs:

This restricts all jobs to read-only access. Jobs that need additional permissions can override at the job level.

Also applies to: 74-90, 92-108

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/check-pull-request.yaml around lines 55 - 62, Add a
top-level permissions block to the workflow to enforce least-privilege for
GITHUB_TOKEN (e.g., set permissions: contents: read, actions: read, checks: read
as appropriate) so all jobs including the run-unit-tests job default to
read-only access; if specific jobs require extra scopes, override the
permissions at the job level (such as within the run-unit-tests job) rather than
relying on broad default permissions. Ensure the new permissions block is placed
at the top level of the YAML (after the on: trigger) so it applies globally and
only loosen permissions per-job when explicitly necessary.

28-30: 🧹 Nitpick | 🔵 Trivial | 🏗️ Heavy lift

Actions should be pinned by full SHA commit, not by tag.

Multiple actions use mutable tag references (e.g., @v6, @v7, @v3.0.1) instead of immutable SHA pins. Tags can be moved or deleted, allowing attackers to substitute malicious code if an action's repository is compromised.

Risk severity: Major
Impact: Supply chain attack vector. If an upstream action repository is compromised, attackers can repoint tags to malicious commits, executing arbitrary code in your CI with GITHUB_TOKEN permissions.

Pin actions by their full commit SHA (e.g., actions/checkout@0123456789abcdef...) to ensure immutable references. As per coding guidelines, CI/CD workflows must pin actions by SHA, not tag.

Example transformation:

# Before (vulnerable to tag repointing)
- uses: actions/checkout@v6

# After (pinned to immutable SHA)
- uses: actions/checkout@a1b2c3d4e5f6... # v6

You can use tools like pin-github-action or Dependabot to automate SHA pinning and updates.

Also applies to: 36-36, 46-47, 59-59, 68-70, 78-78, 86-86, 96-96, 104-104

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/check-pull-request.yaml around lines 28 - 30, Replace all
mutable action tags with immutable commit SHAs: update each occurrence of
actions/checkout@v6, actions/setup-python@v6, pre-commit/action@v3.0.1 (and the
other listed action usages) to use the corresponding full commit SHA for that
release (e.g., actions/checkout@<full-sha> # v6), keeping the human-readable tag
as a comment; ensure every occurrence referenced in the review (the multiple
lines mentioned) is changed so no actions use tag references anymore.
♻️ Duplicate comments (1)
it/it_builtin_tenants_test.go (1)

36-41: 🧹 Nitpick | 🔵 Trivial | ⚡ Quick win

Add defensive nil check for response before dereferencing.

The client.Get call returns response, err and the code checks err, then immediately calls response.GetObject() without verifying response != nil. While the gRPC contract implies err == nil guarantees response != nil, the List test on line 55 already includes this defensive check (Expect(response).ToNot(BeNil())), creating an inconsistency.

Risk: If a gRPC implementation bug violates the contract and returns (nil, nil), the test will panic on nil dereference. Severity: minor defensive gap.

🛡️ Proposed fix to match List test pattern
 response, err := client.Get(ctx, privatev1.OrganizationsGetRequest_builder{
     Id: id,
 }.Build())
 Expect(err).ToNot(HaveOccurred())
+Expect(response).ToNot(BeNil())
 object := response.GetObject()
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@it/it_builtin_tenants_test.go` around lines 36 - 41, The test calls
client.Get and checks err but then dereferences response via
response.GetObject() without ensuring response != nil; add a defensive
Expect(response).ToNot(BeNil()) immediately after
Expect(err).ToNot(HaveOccurred()) (matching the List test pattern) before
calling response.GetObject() to prevent a nil dereference if a (nil, nil) gRPC
response occurs.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@it/it_builtin_tenants_test.go`:
- Around line 48-49: Replace the hardcoded tenant ID strings in the test Entry
calls with the auth package constants to ensure consistency with the migration
tests: change the Entry("System", "system") and Entry("Shared", "shared") usages
to use auth.SystemTenant and auth.SharedTenant respectively (refer to the Entry
calls in it_builtin_tenants_test.go) and update any related assertions or
iterations to reference those constants as well.

---

Outside diff comments:
In @.github/workflows/check-pull-request.yaml:
- Around line 55-62: Add a top-level permissions block to the workflow to
enforce least-privilege for GITHUB_TOKEN (e.g., set permissions: contents: read,
actions: read, checks: read as appropriate) so all jobs including the
run-unit-tests job default to read-only access; if specific jobs require extra
scopes, override the permissions at the job level (such as within the
run-unit-tests job) rather than relying on broad default permissions. Ensure the
new permissions block is placed at the top level of the YAML (after the on:
trigger) so it applies globally and only loosen permissions per-job when
explicitly necessary.
- Around line 28-30: Replace all mutable action tags with immutable commit SHAs:
update each occurrence of actions/checkout@v6, actions/setup-python@v6,
pre-commit/action@v3.0.1 (and the other listed action usages) to use the
corresponding full commit SHA for that release (e.g.,
actions/checkout@<full-sha> # v6), keeping the human-readable tag as a comment;
ensure every occurrence referenced in the review (the multiple lines mentioned)
is changed so no actions use tag references anymore.

---

Duplicate comments:
In `@it/it_builtin_tenants_test.go`:
- Around line 36-41: The test calls client.Get and checks err but then
dereferences response via response.GetObject() without ensuring response != nil;
add a defensive Expect(response).ToNot(BeNil()) immediately after
Expect(err).ToNot(HaveOccurred()) (matching the List test pattern) before
calling response.GetObject() to prevent a nil dereference if a (nil, nil) gRPC
response occurs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 53068a9e-69ed-459a-b0a4-33be73adffb9

📥 Commits

Reviewing files that changed from the base of the PR and between 4eb465c and d476bea.

📒 Files selected for processing (13)
  • .github/workflows/check-pull-request.yaml
  • internal/database/migrations/39_move_hub_fields_to_spec_test.go
  • internal/database/migrations/40_rename_tenants_to_tenant_test.go
  • internal/database/migrations/41_rename_creators_to_creator_test.go
  • internal/database/migrations/42_singular_tenant_and_creator_in_public_ip_attachments_tables_test.go
  • internal/database/migrations/43_drop_leases_tables_test.go
  • internal/database/migrations/44_add_public_ip_attachments_unique_indexes_test.go
  • internal/database/migrations/45_fix_tables_test.go
  • internal/database/migrations/46_add_immutable_column_trigger_test.go
  • internal/database/migrations/47_add_builtin_tenants.up.sql
  • internal/database/migrations/47_add_builtin_tenants_test.go
  • internal/database/migrations/migrations_suite_test.go
  • it/it_builtin_tenants_test.go

Comment thread it/it_builtin_tenants_test.go Outdated
@jhernand
jhernand force-pushed the add_builtin_tenants branch from d476bea to e4cb77c Compare May 27, 2026 19:38

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
internal/database/migrations/44_add_public_ip_attachments_unique_indexes_test.go (1)

24-31: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Use UUIDv7 fixture IDs for public_ip / compute_instance values (minor severity, contract-drift risk).

Using slug-style IDs (pip-1, ci-1) in these changed migration fixtures weakens parity with production ID formats and can mask failures if stricter ID validation is introduced.

Suggested fixture pattern update
- err := insert(ctx, "a1", "pip-1", "ci-1")
+ err := insert(ctx, "a1", "019728a4-3f5c-7def-8abc-1234567890ab", "019728a4-3f5c-7e01-8abc-1234567890ab")

- err = insert(ctx, "a2", "pip-1", "ci-2")
+ err = insert(ctx, "a2", "019728a4-3f5c-7def-8abc-1234567890ab", "019728a4-3f5c-7e02-8abc-1234567890ab")

Based on learnings: In this repository, resource IDs (including PublicIP and ComputeInstance in test fixtures) should use UUIDv7-format strings.

Also applies to: 43-45, 50-51, 55-56, 61-62, 66-67, 74-75, 79-80, 87-88, 92-93, 98-99

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@internal/database/migrations/44_add_public_ip_attachments_unique_indexes_test.go`
around lines 24 - 31, Update the test fixture values to use UUIDv7-format IDs
instead of slug-style IDs in the insert helper: inside the insert function (and
its call sites) replace test values passed as publicIP and computeInstance
(currently like "pip-1"/"ci-1") with UUIDv7-like strings (e.g., 16-byte
timestamp-prefixed UUIDs used elsewhere in tests) so fixtures mirror production
ID format; apply the same change to all related test cases referenced (the other
migration tests mentioned) to keep parity with production ID formats and avoid
contract drift.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/check-pull-request.yaml:
- Line 62: Add an explicit least-privilege permissions block for the workflow or
for the specific job that runs the tests (the job invoking "ginkgo run --timeout
1h -r internal"), setting GITHUB_TOKEN permissions only to the minimal scopes
required (e.g., contents: read and any other specific read-only scopes your
tests need) and remove reliance on default broad scopes; if any step needs extra
privileges, grant them only on that job by adding a job-level permissions stanza
for GITHUB_TOKEN with the narrower scopes.

---

Outside diff comments:
In
`@internal/database/migrations/44_add_public_ip_attachments_unique_indexes_test.go`:
- Around line 24-31: Update the test fixture values to use UUIDv7-format IDs
instead of slug-style IDs in the insert helper: inside the insert function (and
its call sites) replace test values passed as publicIP and computeInstance
(currently like "pip-1"/"ci-1") with UUIDv7-like strings (e.g., 16-byte
timestamp-prefixed UUIDs used elsewhere in tests) so fixtures mirror production
ID format; apply the same change to all related test cases referenced (the other
migration tests mentioned) to keep parity with production ID formats and avoid
contract drift.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: c41b8c1f-7ccf-45a1-9b70-1e649ef0578e

📥 Commits

Reviewing files that changed from the base of the PR and between d476bea and e4cb77c.

📒 Files selected for processing (13)
  • .github/workflows/check-pull-request.yaml
  • internal/database/migrations/39_move_hub_fields_to_spec_test.go
  • internal/database/migrations/40_rename_tenants_to_tenant_test.go
  • internal/database/migrations/41_rename_creators_to_creator_test.go
  • internal/database/migrations/42_singular_tenant_and_creator_in_public_ip_attachments_tables_test.go
  • internal/database/migrations/43_drop_leases_tables_test.go
  • internal/database/migrations/44_add_public_ip_attachments_unique_indexes_test.go
  • internal/database/migrations/45_fix_tables_test.go
  • internal/database/migrations/46_add_immutable_column_trigger_test.go
  • internal/database/migrations/47_add_builtin_tenants.up.sql
  • internal/database/migrations/47_add_builtin_tenants_test.go
  • internal/database/migrations/migrations_suite_test.go
  • it/it_builtin_tenants_test.go

Comment thread .github/workflows/check-pull-request.yaml
This is a preparatory step towards making the tenant field mandatory and
enforcing that every tenant references an existing organization via a
database foreign key constraint. For that to work the `system` and
`shared` tenants, which are already used by convention throughout the
codebase, must exist as rows in the `organizations` table.

Migration 46 inserts both organizations with matching `id`, `name`, and
`tenant` columns (e.g. `system`/`system`/`system`) and their status set
to `ORGANIZATION_STATE_SYNCED` since they are always operational and do
not require IDP reconciliation.

The list tests in `organizations_server_test.go` and
`private_organizations_server_test.go` are updated to filter by name so
they remain deterministic now that the table is no longer empty at test
start.

A migration test verifies the rows are created correctly, and an
integration test confirms both organizations are retrievable through the
private gRPC API.

Signed-off-by: Juan Hernandez <juan.hernandez@redhat.com>
Assisted-by: Cursor
@jhernand
jhernand force-pushed the add_builtin_tenants branch from e4cb77c to 889af76 Compare May 27, 2026 20:59
@jhernand
jhernand merged commit c23f884 into osac-project:main May 28, 2026
12 of 13 checks passed
@jhernand
jhernand deleted the add_builtin_tenants branch May 28, 2026 05:35
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants