[Docs] Clarify runtime sync rules for disabled profile chains - #20
Conversation
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Documentation maintenance: ready. Unsuccessful content rounds: 0/3. Operational attempts: 0/3. Head: The diff rewrites one sync-precondition bullet in reference/kubectl-ome/runtime.md to say the disabled check applies to the merged Live view and that a deleting chain runtime refuses. Verified against the pinned OME checkout (bc1f94db, matching ome.ref): runtime_sync.go:83 refuses when the merged live spec IsDisabled(); the spec is inheritance-merged (runtimeselector/fetcher.go GetRuntime -> runtimeinheritance.Resolve*, strategic merge where the child's set fields win and Disabled is *bool omitempty, so an unset child inherits the ancestor's true and an explicit false overrides). runtime_sync_resolver.go deliberately omits a per-ancestor disabled check (comment at lines 139-141) and refuses any chain object with a deletionTimestamp at line 119, used for every chain read. TestRuntimeSyncAllowsDisabledProfileAncestorsWithEnabledLeaf confirms disabled profiles with an enabled leaf sync while a leaf with disabled unset or true refuses with ErrRuntimeSyncEvidence, and a "source deleting" case confirms the deletion refusal. The unchanged "at most five runtimes, none of them twice" clause matches RuntimeInheritMaxDepth=5 and the duplicate-chain check at runtime_sync.go:87-97. The profile link anchor exists and the edit follows the writing-docs style with no nav/redirect/code changes. Both bullets serve the single concern of which chain states make sync refuse, sourced to one commit's snapshot-rule change. No feedback threads exist in the context. Human review threads and CODEOWNER approval remain under repository policy. |
What this PR does
Does kubectl ome runtime sync work when the pinned runtime inherits from a disabled profile, and which chain states make it refuse?
Why we need it
Source change: ome-projects/ome@0167224
Commit 3 ([Bugfix] Harden CLI operations and document usage) deliberately changed the sync safety snapshot: pkg/cli/effective/runtime_sync_resolver.go removed the per-source IsDisabled() refusal from syncReadClient.Get, with the comment 'Profile ancestors are deliberately disabled; an enabled child can override that field. Check the merged runtime in prepareRuntimeSyncEvidence instead', and the same Get now refuses any chain runtime with a deletionTimestamp (runtime_sync_resolver.go:119). The merged-runtime check lives in pkg/cli/effective/runtime_sync.go:83 (live.Runtime.spec.IsDisabled() -> ErrRuntimeSyncEvidence, the 'action refused: managed runtime sync safety evidence is unavailable or inconsistent' message). The test TestRuntimeSyncAllowsDisabledProfileAncestorsWithEnabledLeaf in pkg/cli/effective/runtime_sync_test.go confirms a chain of disabled profiles with an enabled leaf syncs, while a disabled effective runtime still refuses. The sync preconditions in src/lib/content/reference/kubectl-ome/runtime.md say only 'The runtime isn't disabled, and its chain has at most five runtimes, none of them twice', without saying the disabled check applies to the merged live runtime, that disabled ancestors do not refuse, or that a deleting chain runtime refuses. This matters because concepts/runtimes/runtime-inheritance.md requires profiles to set disabled: true (the admission webhook enforces it for ome.io/runtime-profile), so a reader following the documented inheritance pattern cannot tell whether sync works for them. One independent concern: one precondition bullet in the sync section of one command page, sourced to this commit's behavior change.
Scope: cli-actions / runtime-sync-inherited-chain-rules. Other concerns are deferred.
How to test
git diff --checkand website content/link tests, type checks, lint and production build.Checklist
git commit -s)pnpm lint && pnpm check && pnpm test && pnpm buildpasses (run by the publisher on an isolated copy)