Repository navigation
feat: observe installed Zitadel instances through native references - #32
Merged
Merged
Conversation
Replace the discovery Job and metadata ConfigMap with a read-only Instance using a consumer-owned ProviderConfig. Expose its typed name reference and require current-generation successful observation for readiness. BREAKING CHANGE: enabled instanceDiscovery requires providerConfigRef; the Job transport fields are removed. Discovery remains disabled by default, and instanceId status remains available after successful observation. Signed-off-by: Patrick Lee Scott <pat@patscott.io>
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (13)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Patrick Lee Scott <pat@patscott.io>
Published Crossplane PackageThe following Crossplane package was published as part of this PR: Package: ghcr.io/hops-ops/auth-stack:pr-32-1d56a922fc6b94d10a458e461d9c4f8338a1b103 |
patrickleet
marked this pull request as ready for review
October 6, 2026 05:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AuthStack currently learns an installed Zitadel instance ID through a one-shot Python Job and a ConfigMap. Consumers then copy that ID into domain resources. This creates extra RBAC and lifecycle/retry wiring for metadata that provider-upjet-zitadel v0.3.0 can now observe directly.
This replaces the Job, ConfigMap, ServiceAccount and RBAC with a read-only namespaced
Instanceand an orderingUsage. Helm continues to own the installed service and database. The observer reads credentials and transport settings from an existing ProviderConfig; secrets never pass through composition templates or XR status.For example, a platform stack installs Zitadel once and separate preview namespaces register trusted domains. Those namespaces can now reference the installed instance by resource name instead of copying its numeric ID:
After successful observation, status includes the existing
instanceIdand the additiveinstanceRef: {name: identity-instance, namespace: platform}. A consumer can use:The provider also supports
instanceIdSelector; name references are the simplest default. The ProviderConfig must target this installation, since AuthStack cannot establish ownership of an arbitrary external endpoint. For first install, wait for Helm to generate the PAT, publish it using PushSecret, establish the ProviderConfig through ESO, and then wait for AuthStack. Waiting for AuthStack before creating the observer credentials would introduce a dependency cycle.Compatibility:
internalURL,allowInsecureHTTP,caCertSecretRefandimagewithproviderConfigRef, and configure transport there. Enabled old configurations without the new reference are rejected. The package now requires provider-upjet-zitadel >=v0.3.0; coordinate an existing provider pin before upgrading.status.instanceIdis preserved;status.instanceRefis additive. Failed, stale or deleting observations clear the published metadata and explicitly make AuthStack Not Ready, even if the managed resource retains an older Ready condition. The observer continues rendering through those failures.Validation:
CI at
d83edde: all 16 validation cases, composition tests, native-observation tests and the existing E2E job passed in run 37067598051. Preview-package publication is still running.To repeat the configuration checks:
make test python3 -m pip install PyYAML==6.0.3 make test-security make validate:allFor a live trial, start the local control plane with
hops local up, retain a working Zitadel installation and its ProviderConfig, then install this checkout withhops config install --path /path/to/auth-stack --context kind-hops --cluster-provider kind --docker-provider dory. Upgrade the local Zitadel provider to v0.3.0 before enabling observation. The example above shows the changed fields; keep your existing installation/bootstrap spec.