Skip to content

S7.B: emit Progressing Condition on every ClawSandbox status path - #73

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-conditions-ssa-leader-b
Apr 29, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-conditions-ssa-leader-b

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

S7.B — Conditions matrix Progressing emission

Sub-slice 2 of the S7 craftsmanship train (S7.A landed in #72).

Closes the Progressing Condition gap in the three ClawSandbox status-patch builders that did not already match the overlay path's full Conditions matrix:

Status path Before After
running [Ready=True, RuntimeReady=True] [Ready=True, **Progressing=False/Reconciled**, RuntimeReady=True]
degraded [Degraded=True, Ready=False] [Degraded=True, Ready=False, **Progressing=False/<reason>**]
runtime-unsupported [Degraded=True, Ready=False, RuntimeReady=False] [Degraded=True, Ready=False, RuntimeReady=False, **Progressing=False/AdapterMissing**]
overlay (already correct) [Ready, Progressing, Degraded, Suspended, RuntimeReady] unchanged

After this slice, kubectl wait --for=condition=Progressing=False resolves consistently across all paths.

Upgrade safety

running_status_matches and runtime_unsupported_status_matches extended to verify the new condition. New regression test running_status_matches_returns_false_when_progressing_missing proves a pre-S7.B status (Ready+RuntimeReady only) is treated as stale and back-filled on the first reconcile after controller upgrade.

Out of scope

  • Mid-reconcile Progressing=True step emissions — deferred to S7.B.2 (would add a status-write per reconcile step and churn resourceVersion).
  • Step-reason vocabulary (STEP_NAMESPACE etc.) — ships with mid-reconcile emission.
  • Other reconcilers — already emit Progressing on happy paths (verified by source survey).

Tests

  • Controller: 328 → 329 (+1). Clippy -D warnings clean. cargo fmt --check clean.

Audit

docs/security-audits/2026-04-29-phase2-conditions-progressing.md (sign-offs included).

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

Close the Progressing Condition gap in the running, degraded, and
runtime-unsupported status-patch builders. Pre-S7.B these paths
emitted [Ready, RuntimeReady] or [Degraded, Ready] only, while the
overlay path (S8) already emitted the full four-condition matrix.
After this slice, kubectl wait --for=condition=Progressing=False
resolves consistently across all four paths.

Idempotency guards extended to verify Progressing=False so a pre-S7.B
status is treated as stale and back-filled on the next reconcile
after controller upgrade, rather than being short-circuited as a
no-op (new regression test:
running_status_matches_returns_false_when_progressing_missing).

Mid-reconcile Progressing=True step emissions (Namespace -> SA ->
FedCred -> NetworkPolicy -> ConfigMap -> Deployment -> Service)
deferred to S7.B.2 — would add a status-write per step and churn
resourceVersion. The current sub-slice keeps the change metadata-only.

- controller/src/status/mod.rs: extend three patch builders + two
  idempotency guards; +1 regression test
- 328 -> 329 controller bin tests (all green; clippy + fmt clean)
- docs/security-audits/2026-04-29-phase2-conditions-progressing.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit cde3a3d into dev Apr 29, 2026
12 of 13 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-conditions-ssa-leader-b branch April 29, 2026 06:03
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
Close the Progressing Condition gap in the running, degraded, and
runtime-unsupported status-patch builders. Pre-S7.B these paths
emitted [Ready, RuntimeReady] or [Degraded, Ready] only, while the
overlay path (S8) already emitted the full four-condition matrix.
After this slice, kubectl wait --for=condition=Progressing=False
resolves consistently across all four paths.

Idempotency guards extended to verify Progressing=False so a pre-S7.B
status is treated as stale and back-filled on the next reconcile
after controller upgrade, rather than being short-circuited as a
no-op (new regression test:
running_status_matches_returns_false_when_progressing_missing).

Mid-reconcile Progressing=True step emissions (Namespace -> SA ->
FedCred -> NetworkPolicy -> ConfigMap -> Deployment -> Service)
deferred to S7.B.2 — would add a status-write per step and churn
resourceVersion. The current sub-slice keeps the change metadata-only.

- controller/src/status/mod.rs: extend three patch builders + two
  idempotency guards; +1 regression test
- 328 -> 329 controller bin tests (all green; clippy + fmt clean)
- docs/security-audits/2026-04-29-phase2-conditions-progressing.md

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant