Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

OSAC-1571: add template_parameters field to BareMetalInstance API - #762

Merged
openshift-merge-bot[bot] merged 3 commits into
osac-project:mainfrom
mennyaboush:feat/OSAC-1571
Jun 29, 2026
Merged

openshift-merge-bot[bot] merged 3 commits into
osac-project:mainfrom
mennyaboush:feat/OSAC-1571

Conversation

@mennyaboush

@mennyaboush mennyaboush commented Jun 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add template_parameters (map<string, google.protobuf.Any>) to BareMetalInstanceSpec in both public and private APIs, allowing tenants to pass custom parameters to the provisioning template at instance creation time
  • Add BareMetalInstanceTemplateParameterDefinition and parameters field to BareMetalInstanceTemplate for server-side parameter validation
  • Validate template_parameters against template definitions on Create, apply defaults for optional parameters, enforce immutability on Update
  • Reconciler merges user-provided template_parameters into the CR's templateParameters JSON alongside system parameters (sshPublicKey, userDataSecret), with system params overriding user values for security

Dependencies

  • Depends on OSAC-1550 merging first (renames sshKey → sshPublicKey in reconciler). Reconciler tests assert sshPublicKey key name.

Companion PR

Test plan

  • buf lint passes
  • go build ./... passes
  • gofmt -s -w . — no formatting issues
  • ginkgo run internal/utils — 57 tests pass (1 new adapter test)
  • ginkgo run internal/servers — 1042 tests pass (7 new template_parameters tests)
  • ginkgo run internal/controllers/baremetalinstance — 40 tests pass (3 new reconciler tests)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added support for customizable bare-metal instance template parameters, including required/optional fields, typed Any values, and default values derived from templates.
    • Template parameters can now be provided at instance creation and are validated against the selected template and its parameter definitions.
  • Bug Fixes

    • System-generated parameters are now merged reliably with user-provided values, with system values taking precedence when keys overlap.
    • Template parameters are enforced as immutable after creation.
  • Tests

    • Added end-to-end coverage for creation, defaults, validation errors, and immutability (including update-mask behavior).

@openshift-ci-robot

openshift-ci-robot commented Jun 24, 2026 •

Copy link
Copy Markdown

@mennyaboush: This pull request references OSAC-1571 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Add template_parameters (map<string, google.protobuf.Any>) to BareMetalInstanceSpec in both public and private APIs, allowing tenants to pass custom parameters to the provisioning template at instance creation time
  • Add BareMetalInstanceTemplateParameterDefinition and parameters field to BareMetalInstanceTemplate for server-side parameter validation
  • Validate template_parameters against template definitions on Create, apply defaults for optional parameters, enforce immutability on Update
  • Reconciler merges user-provided template_parameters into the CR's templateParameters JSON alongside system parameters (sshPublicKey, userDataSecret), with system params overriding user values for security

Dependencies

  • Depends on OSAC-1550 merging first (renames sshKey → sshPublicKey in reconciler). Reconciler tests assert sshPublicKey key name.

Companion PR

Test plan

  • buf lint passes
  • go build ./... passes
  • gofmt -s -w . — no formatting issues
  • ginkgo run internal/utils — 57 tests pass (1 new adapter test)
  • ginkgo run internal/servers — 1042 tests pass (7 new template_parameters tests)
  • ginkgo run internal/controllers/baremetalinstance — 40 tests pass (3 new reconciler tests)

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from eliorerz and rgolangh June 24, 2026 12:26
@coderabbitai

coderabbitai Bot commented Jun 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@mennyaboush, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 50 minutes and 24 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 04f5f29b-3e47-4b42-a4de-024895fff5fe

📥 Commits

Reviewing files that changed from the base of the PR and between b5c5473 and 604b5bb.

📒 Files selected for processing (1)
  • internal/servers/private_baremetal_instances_server_test.go

Walkthrough

Adds immutable template_parameters on BareMetalInstanceSpec and parameter definitions on BareMetalInstanceTemplate. The private server now validates and applies template parameters on create and rejects changes on update. The reconciler merges user parameters with generated fields into the hub CR.

Changes

BareMetalInstance template_parameters end-to-end

Layer / File(s) Summary
Proto schema: template_parameters and parameter definitions
proto/public/osac/public/v1/baremetal_instance_type.proto, proto/public/osac/public/v1/baremetal_instance_template_type.proto, proto/private/osac/private/v1/baremetal_instance_type.proto, proto/private/osac/private/v1/baremetal_instance_template_type.proto
Both public and private BareMetalInstanceSpec messages gain an immutable map<string, google.protobuf.Any> template_parameters field. Both BareMetalInstanceTemplate messages gain a repeated parameters field and the new BareMetalInstanceTemplateParameterDefinition message.
Template parameter adapter and validation utility
internal/utils/template_parameters.go, internal/utils/template_parameters_test.go
Adds BareMetalInstanceTemplateAdapter and ValidateBareMetalInstanceTemplateParameters, with tests covering validation and default processing for bare-metal templates.
Private server: template validation and immutability
internal/servers/private_baremetal_instances_server.go
Adds templatesDao, validates and applies template parameters during create, and rejects PATCH updates that change spec.template_parameters.
Private server: template_parameters integration tests
internal/servers/private_baremetal_instances_server_test.go
Adds helpers for template-backed catalog items and behavior tests for creation, defaults, validation failures, catalog/template interactions, and PATCH immutability.
Reconciler: merge user template_parameters into hub CR
internal/controllers/baremetalinstance/baremetalinstance_reconciler_function.go, internal/controllers/baremetalinstance/baremetalinstance_reconciler_function_test.go
mutateBMI now loads user template_parameters into a map[string]any, merges system-generated keys, and tests cover propagation, merge behavior, and override precedence.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant PrivateBareMetalInstancesServer
  participant templatesDao
  participant Reconciler

  Client->>PrivateBareMetalInstancesServer: CreateBareMetalInstance(spec.template_parameters)
  PrivateBareMetalInstancesServer->>templatesDao: Get(templateId)
  templatesDao-->>PrivateBareMetalInstancesServer: BareMetalInstanceTemplate
  PrivateBareMetalInstancesServer->>PrivateBareMetalInstancesServer: validateAndApplyTemplateParameters()
  PrivateBareMetalInstancesServer-->>Client: created instance

  Client->>PrivateBareMetalInstancesServer: UpdateBareMetalInstance(mask includes template_parameters)
  PrivateBareMetalInstancesServer->>PrivateBareMetalInstancesServer: validateImmutability()
  PrivateBareMetalInstancesServer-->>Client: InvalidArgument if changed

  Reconciler->>Reconciler: mutateBMI()
  Reconciler->>Reconciler: ConvertTemplateParametersToJSON()
  Reconciler->>Reconciler: merge sshPublicKey and userDataSecret
  Reconciler-->>Reconciler: marshal hub CR TemplateParameters
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

Suggested reviewers

  • carbonin
  • adriengentil
  • jhernand

Poem

Tiny params in a JSON sea,
Wrapped in Any so they may be free.
Defaults bloom, and immutables stay,
The reconciler folds them into the day.
Templates speak, the CR listens well,
Typed little spells that pass the validation bell.

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately captures the core API addition of template_parameters on BareMetalInstance.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets found in changed files; scans showed only public SSH key test fixtures and no private keys, tokens, passwords, or embedded credentials.
No-Weak-Crypto ✅ Passed PASS: The PR’s touched files contain no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB or crypto imports; only an unrelated existing HmacSHA1 in Keycloak config appears.
No-Injection-Vectors ✅ Passed No unsafe sinks were added: no shell/eval/pickle/yaml/innerHTML calls, and the only user-influenced filter is quoted then translated via CEL→SQL.
Container-Privileges ✅ Passed No privileged:true, hostPID/Network/IPC, SYS_ADMIN, runAsUser:0, or allowPrivilegeEscalation:true found; manifests use runAsNonRoot and drop ALL.
No-Sensitive-Data-In-Logs ✅ Passed No added logs expose secrets/PII; new template-parameter paths return errors and never log parameter values.
Ai-Attribution ✅ Passed PASS: AI use is acknowledged and HEAD includes Assisted-by: Claude Code <noreply@anthropic.com>; no Co-Authored-By found.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread internal/servers/private_baremetal_instances_server_test.go Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@internal/controllers/baremetalinstance/baremetalinstance_reconciler_function.go`:
- Around line 523-525: The parameter name used in the BareMetalInstance
reconciler is outdated: update the ssh key assignment in the BareMetalInstance
reconciliation path to use the renamed system parameter key expected by the
template. In the code that builds params from
t.bareMetalInstance.GetSpec().HasSshPublicKey(), replace the old sshKey entry
with sshPublicKey so the server-managed key is propagated correctly and can
override any user-supplied template_parameters value under that name.

In `@internal/servers/private_baremetal_instances_server.go`:
- Around line 262-269: The validateAndApplyTemplateParameters method currently
returns early when templateID is empty, which allows spec.template_parameters to
slip through unvalidated. Update this path to reject any non-empty
bmi.GetSpec().GetTemplateParameters() when no template is available, and keep
the existing parameter validation/defaulting flow only for cases where
templateID is set. Use validateAndApplyTemplateParameters and providedParams as
the key locations for the fix.

In `@internal/utils/template_parameters_test.go`:
- Around line 241-261: Add test coverage for the bare metal default-application
path in the template parameter tests: the current
BareMetalInstanceTemplateAdapter validation only checks
ValidateTemplateParameters, so it can miss regressions in
ProcessTemplateParametersWithDefaults. Extend the existing bare metal test suite
to cover ProcessTemplateParametersWithDefaults using BareMetalInstanceTemplate
and BareMetalInstanceTemplateParameterDefinition.Default, asserting that a
missing parameter is populated from the default before validation continues.

In `@proto/public/osac/public/v1/baremetal_instance_type.proto`:
- Around line 62-63: The ProtoJSON documentation link in the comment is written
with reversed Markdown syntax, so it will not render correctly in generated
docs. Update the comment near baremetal_instance_type.proto to use standard link
text formatting, and apply the same fix to the copied comment blocks in the
matching private/template proto definitions so the documentation stays
consistent across all occurrences.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: dd9dafae-1c77-43ad-ad27-5d0e8a0de28c

📥 Commits

Reviewing files that changed from the base of the PR and between c520207 and 28591fd.

⛔ Files ignored due to path filters (8)
  • internal/api/osac/private/v1/baremetal_instance_template_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/baremetal_instance_template_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/baremetal_instance_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/baremetal_instance_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/baremetal_instance_template_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/baremetal_instance_template_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/baremetal_instance_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/baremetal_instance_type_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (10)
  • internal/controllers/baremetalinstance/baremetalinstance_reconciler_function.go
  • internal/controllers/baremetalinstance/baremetalinstance_reconciler_function_test.go
  • internal/servers/private_baremetal_instances_server.go
  • internal/servers/private_baremetal_instances_server_test.go
  • internal/utils/template_parameters.go
  • internal/utils/template_parameters_test.go
  • proto/private/osac/private/v1/baremetal_instance_template_type.proto
  • proto/private/osac/private/v1/baremetal_instance_type.proto
  • proto/public/osac/public/v1/baremetal_instance_template_type.proto
  • proto/public/osac/public/v1/baremetal_instance_type.proto

Comment thread internal/servers/private_baremetal_instances_server.go Outdated
Comment thread internal/utils/template_parameters_test.go
Comment thread proto/public/osac/public/v1/baremetal_instance_type.proto Outdated
Signed-off-by: Menny Aboush <maboush@redhat.com>
Assisted-by: Claude Code <noreply@anthropic.com>
@osac-project osac-project deleted a comment from coderabbitai Bot Jun 28, 2026
@mennyaboush
mennyaboush requested a review from adriengentil June 28, 2026 10:21
MENNY ABOUSH added 2 commits June 28, 2026 14:54
Address PR review feedback from adriengentil: add tests covering
CatalogItem field_definitions alongside template_parameters.

Signed-off-by: Menny Aboush <maboush@redhat.com>
Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: MENNY ABOUSH <maboush@maboush-thinkpadt14gen5.raanaii.csb>
Signed-off-by: Menny Aboush <maboush@redhat.com>
Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: MENNY ABOUSH <maboush@maboush-thinkpadt14gen5.raanaii.csb>
@openshift-ci

openshift-ci Bot commented Jun 29, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: adriengentil, mennyaboush

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit cf8d45f into osac-project:main Jun 29, 2026
14 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants