Repository navigation
Require atespace and actor names of at least 26 bytes - #2396
Open
Taahir Ahmed (ahmedtd) wants to merge 1 commit into
Open
Taahir Ahmed (ahmedtd) wants to merge 1 commit into
Taahir Ahmed (ahmedtd) wants to merge 1 commit into
Conversation
Taahir Ahmed (ahmedtd)
force-pushed
the
name-length-checks
branch
from
October 9, 2026 07:10
4d18cbb to
ef9a951
Compare
CreateAtespace and CreateActor now reject names shorter than 26 bytes, enough to hold 128 random bits in base-32. This pushes callers toward random names, which are hard to squat on and are not reused once a resource is deleted (for example, when an actor's name is referenced from GCP Cloud IAM). No format is enforced, so a readable prefix is still allowed. The check applies only on create: existing resources with shorter names can still be read, updated, and deleted. The reserved ate-golden atespace, which the template reconciler creates itself, is exempt. resources.NewRandomName builds such names from crypto/rand.Text, and the in-tree tests, benchmarks, and e2e suites use it for the actors they create. The demo, e2e fixture, and benchmark atespaces get fixed long names, decoupled from the k8s namespaces holding their worker pools: ate-setup waits on pool Deployments through a new steps.DeploymentRef, and e2e fixtures map between the two with e2e.FixtureAtespace and e2e.FixtureNamespace. Docs and examples now use generated names.
Taahir Ahmed (ahmedtd)
force-pushed
the
name-length-checks
branch
from
October 9, 2026 07:13
ef9a951 to
84cc8b3
Compare
Taahir Ahmed (ahmedtd)
requested review from
Julian Gutierrez Oschmann (juli4n) and
Tim Hockin (thockin)
October 9, 2026 07:16
Collaborator
Author
|
This is a doozy since it kills every short name in the tree and adds the validation in one step. I'd focus on reviewing the validation logic, since all the other changes are just to make tests, demos, and benchmarks work with the new minimum length. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CreateAtespace and CreateActor now reject names shorter than 26 bytes (128 bits in base32). We can't use declarative validation because the special ate-golden namespace still needs to work.
resources.NewRandomName builds such names from crypto/rand.Text, and everything in-tree that could be converted to it has been. Some demos, and e2e tests use fixed long names, and will need deeper rework to randomly generate their names.
Docs and examples now use generated names.
Fixes #1900
Breaking change
Atespaces and actor names now must be at least 26 characters long. You are strongly suggested to use random (or at least partially-random) names, such as a UUID or the output of crypto/rand.Text().