Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
nerdalert
force-pushed
the
feat/deny-all-overlay
branch
from
October 3, 2026 02:07
664c74b to
75e9e78
Compare
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
3 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When the last eligible provider is withdrawn, AGN must publish a new no-route decision instead of leaving an older, permissive route in service. This PR makes an empty candidate set an authoritative, versioned routing state and connects that state to the supported running gateway paths.
This is the shared prerequisite in #258 for provider-gateway path health (#20) and sovereignty-zone enforcement (#78). Those policies are not implemented here.
Routing behavior
existing_onlyalso remains distinct from withdrawal; it can serve an existing session but cannot accept a new one.Breaking change and release dependency
🟥 On hold for the next release: this PR requires Praxis AI #1539 to merge, a compatible AI image to be published, and the Grid chart default to be updated before this Grid change merges or ships. Grid now publishes a valid empty overlay whenever the last eligible provider is withdrawn; there is no compatibility opt-in. The current chart-default AI 0.4.0 image rejects that snapshot.
This is a prerelease compatibility change. Every consumer of a Grid-managed overlay must be upgraded and rolled out with empty-snapshot support. Deployments using generated
GatewayRef.consumerConfigmust also mount the versioned overlay at/etc/praxis/routing/routing-overlay.jsonand roll out the new generated config, which now reads live candidates from that file instead of embedding them in startup YAML. The next release must qualify the paired AI and Grid images together; do not deploy this Grid change with the old chart-default image.Consumer paths
intelligent_routewithoverlay_filecandidates: []. Candidate revisions hot-reload; invalid revisions retain the last valid snapshot.GatewayRef.consumerConfigpraxis.yamlsupplies filter and endpoint plumbing, while the same watched overlay supplies live candidates. Candidate-only withdrawal hot-reloads. Changes to listeners, filter chains, endpoints, or TLS still require the consumer owner to reload or roll out its configuration.grid-gatewayGatewayRef.providerHopEndpointsis independent ofconsumerConfig; the gateway verifies those declared hops against its configured mTLS backends. Ambiguous same-named verified/plaintext backends fail startup.Manual static
intelligent_route.candidatesare not a runtime-withdrawal path.Qualification
The provider-traffic Kind qualification passed 9/9 scenarios on the source snapshot preceding the final gateway trust-validation change:
The static-weighted regression passed all three 60-request distribution phases on that snapshot.
Static checks
make lint, gateway-workspace strict Clippy, andgit diff --checkpass on this branch.References
Scope note
Admission-time schema tightening for
GatewayRef.providerHopEndpointsmay be more than this initial no-route change needs. The controller already rejects invalid nonempty hop declarations. The optional CRD validation work is preserved on nerdalert/grid:review/provider-hop-admission-validation for separate review if the API contract calls for it.