Repository navigation
S7.B: emit Progressing Condition on every ClawSandbox status path - #73
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoApr 29, 2026
Merged
Conversation
Close the Progressing Condition gap in the running, degraded, and runtime-unsupported status-patch builders. Pre-S7.B these paths emitted [Ready, RuntimeReady] or [Degraded, Ready] only, while the overlay path (S8) already emitted the full four-condition matrix. After this slice, kubectl wait --for=condition=Progressing=False resolves consistently across all four paths. Idempotency guards extended to verify Progressing=False so a pre-S7.B status is treated as stale and back-filled on the next reconcile after controller upgrade, rather than being short-circuited as a no-op (new regression test: running_status_matches_returns_false_when_progressing_missing). Mid-reconcile Progressing=True step emissions (Namespace -> SA -> FedCred -> NetworkPolicy -> ConfigMap -> Deployment -> Service) deferred to S7.B.2 — would add a status-write per step and churn resourceVersion. The current sub-slice keeps the change metadata-only. - controller/src/status/mod.rs: extend three patch builders + two idempotency guards; +1 regression test - 328 -> 329 controller bin tests (all green; clippy + fmt clean) - docs/security-audits/2026-04-29-phase2-conditions-progressing.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
phase2-conditions-ssa-leader-b
branch
April 29, 2026 06:03
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
Close the Progressing Condition gap in the running, degraded, and runtime-unsupported status-patch builders. Pre-S7.B these paths emitted [Ready, RuntimeReady] or [Degraded, Ready] only, while the overlay path (S8) already emitted the full four-condition matrix. After this slice, kubectl wait --for=condition=Progressing=False resolves consistently across all four paths. Idempotency guards extended to verify Progressing=False so a pre-S7.B status is treated as stale and back-filled on the next reconcile after controller upgrade, rather than being short-circuited as a no-op (new regression test: running_status_matches_returns_false_when_progressing_missing). Mid-reconcile Progressing=True step emissions (Namespace -> SA -> FedCred -> NetworkPolicy -> ConfigMap -> Deployment -> Service) deferred to S7.B.2 — would add a status-write per step and churn resourceVersion. The current sub-slice keeps the change metadata-only. - controller/src/status/mod.rs: extend three patch builders + two idempotency guards; +1 regression test - 328 -> 329 controller bin tests (all green; clippy + fmt clean) - docs/security-audits/2026-04-29-phase2-conditions-progressing.md Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
S7.B — Conditions matrix
ProgressingemissionSub-slice 2 of the S7 craftsmanship train (S7.A landed in #72).
Closes the
ProgressingCondition gap in the threeClawSandboxstatus-patch builders that did not already match the overlay path's full Conditions matrix:[Ready=True, RuntimeReady=True][Ready=True, **Progressing=False/Reconciled**, RuntimeReady=True][Degraded=True, Ready=False][Degraded=True, Ready=False, **Progressing=False/<reason>**][Degraded=True, Ready=False, RuntimeReady=False][Degraded=True, Ready=False, RuntimeReady=False, **Progressing=False/AdapterMissing**][Ready, Progressing, Degraded, Suspended, RuntimeReady]After this slice,
kubectl wait --for=condition=Progressing=Falseresolves consistently across all paths.Upgrade safety
running_status_matchesandruntime_unsupported_status_matchesextended to verify the new condition. New regression testrunning_status_matches_returns_false_when_progressing_missingproves a pre-S7.B status (Ready+RuntimeReady only) is treated as stale and back-filled on the first reconcile after controller upgrade.Out of scope
Progressing=Truestep emissions — deferred to S7.B.2 (would add a status-write per reconcile step and churn resourceVersion).STEP_NAMESPACEetc.) — ships with mid-reconcile emission.Progressingon happy paths (verified by source survey).Tests
-D warningsclean.cargo fmt --checkclean.Audit
docs/security-audits/2026-04-29-phase2-conditions-progressing.md(sign-offs included).Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com