Skip to content

[Docs] Clarify runtime sync rules for disabled profile chains - #20

Merged
slin1237 merged 1 commit into
mainfrom
codex/nightly-docs-a77307b88aac71fb
Oct 2, 2026
Merged

slin1237 merged 1 commit into
mainfrom
codex/nightly-docs-a77307b88aac71fb

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What this PR does

Does kubectl ome runtime sync work when the pinned runtime inherits from a disabled profile, and which chain states make it refuse?

Why we need it

Source change: ome-projects/ome@0167224

Commit 3 ([Bugfix] Harden CLI operations and document usage) deliberately changed the sync safety snapshot: pkg/cli/effective/runtime_sync_resolver.go removed the per-source IsDisabled() refusal from syncReadClient.Get, with the comment 'Profile ancestors are deliberately disabled; an enabled child can override that field. Check the merged runtime in prepareRuntimeSyncEvidence instead', and the same Get now refuses any chain runtime with a deletionTimestamp (runtime_sync_resolver.go:119). The merged-runtime check lives in pkg/cli/effective/runtime_sync.go:83 (live.Runtime.spec.IsDisabled() -> ErrRuntimeSyncEvidence, the 'action refused: managed runtime sync safety evidence is unavailable or inconsistent' message). The test TestRuntimeSyncAllowsDisabledProfileAncestorsWithEnabledLeaf in pkg/cli/effective/runtime_sync_test.go confirms a chain of disabled profiles with an enabled leaf syncs, while a disabled effective runtime still refuses. The sync preconditions in src/lib/content/reference/kubectl-ome/runtime.md say only 'The runtime isn't disabled, and its chain has at most five runtimes, none of them twice', without saying the disabled check applies to the merged live runtime, that disabled ancestors do not refuse, or that a deleting chain runtime refuses. This matters because concepts/runtimes/runtime-inheritance.md requires profiles to set disabled: true (the admission webhook enforces it for ome.io/runtime-profile), so a reader following the documented inheritance pattern cannot tell whether sync works for them. One independent concern: one precondition bullet in the sync section of one command page, sourced to this commit's behavior change.

Scope: cli-actions / runtime-sync-inherited-chain-rules. Other concerns are deferred.

How to test

  • Passed the documentation path and size guard (under 1000 added plus deleted lines; no file-count limit).
  • Passed an independent accuracy and single-concern review.
  • Passed git diff --check and website content/link tests, type checks, lint and production build.

Checklist

  • Every commit is signed off (git commit -s)
  • pnpm lint && pnpm check && pnpm test && pnpm build passes (run by the publisher on an isolated copy)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 84987ee6-8ab9-4f44-b7a4-450d5c15c96c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

Documentation maintenance: ready. Unsuccessful content rounds: 0/3. Operational attempts: 0/3.

Head: 32852dfeddd51b5b207884a767d8c1dfb5b03647; reviewed main: 40ff7deafa9a366fda6cc0cb9598dbef9b7fe515.

The diff rewrites one sync-precondition bullet in reference/kubectl-ome/runtime.md to say the disabled check applies to the merged Live view and that a deleting chain runtime refuses. Verified against the pinned OME checkout (bc1f94db, matching ome.ref): runtime_sync.go:83 refuses when the merged live spec IsDisabled(); the spec is inheritance-merged (runtimeselector/fetcher.go GetRuntime -> runtimeinheritance.Resolve*, strategic merge where the child's set fields win and Disabled is *bool omitempty, so an unset child inherits the ancestor's true and an explicit false overrides). runtime_sync_resolver.go deliberately omits a per-ancestor disabled check (comment at lines 139-141) and refuses any chain object with a deletionTimestamp at line 119, used for every chain read. TestRuntimeSyncAllowsDisabledProfileAncestorsWithEnabledLeaf confirms disabled profiles with an enabled leaf sync while a leaf with disabled unset or true refuses with ErrRuntimeSyncEvidence, and a "source deleting" case confirms the deletion refusal. The unchanged "at most five runtimes, none of them twice" clause matches RuntimeInheritMaxDepth=5 and the duplicate-chain check at runtime_sync.go:87-97. The profile link anchor exists and the edit follows the writing-docs style with no nav/redirect/code changes. Both bullets serve the single concern of which chain states make sync refuse, sourced to one commit's snapshot-rule change. No feedback threads exist in the context.

Workflow evidence

Human review threads and CODEOWNER approval remain under repository policy.

@slin1237
slin1237 merged commit 38c6d4d into main Oct 2, 2026
2 checks passed
@slin1237
slin1237 deleted the codex/nightly-docs-a77307b88aac71fb branch October 2, 2026 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant