Skip to content

feat(console): provider-aware fleet onboarding for AWS + k8s - #172

Open
Reese-max wants to merge 2 commits into
openabdev:mainfrom
Reese-max:devin/issue-104-console-k8s
Open

Reese-max wants to merge 2 commits into
openabdev:mainfrom
Reese-max:devin/issue-104-console-k8s

Conversation

@Reese-max

Copy link
Copy Markdown

Refs #104

Summary

Completes the console side of the provider-aware "+ New fleet" wizard
(most of the backend landed already — list_aws_profiles /
list_k8s_contexts / list_namespaces / list_service_accounts MCP
tools, provider dispatch in deploy_provision[_agent], unified
fleets.toml, and the k8s select fields were all in place).

What's new here:

  • AWS Credential profile is now a <select> populated by
    list_aws_profiles, showing each profile's configured region
    (oab-fleet (us-west-2)) — matching the k8s selects that already
    existed. Picking a profile pre-fills Region (still freely editable).
  • Every enumerated field has a manual-entry sentinel — Credential
    profile "Type it manually…", Context "— enter manually —", Namespace
    "+ Create new namespace…" — so a failed enumeration can never block
    onboarding.
  • Three-tier failure UX per the spec: missing/empty config →
    actionable guidance (aws configure/aws sso login; no kubeconfig →
    OrbStack/kind/minikube or merge a vendor kubeconfig into
    ~/.kube/config); file present but unreadable → the raw error; tool
    call failed → the raw error. Service-account failures stay silent —
    blank means the namespace's default account.
  • Provider switching resets the departing group's fields (field
    semantics don't map across AWS↔k8s), and a manually-entered context
    re-drives the namespace/service-account lists on commit, not per
    keystroke. Enumeration responses arriving after their selection moved
    on are dropped via per-loader generation guards.
  • list_aws_profiles parser fix: ~/.aws/config previously treated
    every [section] as a credential profile — [sso-session …],
    [services …], [preview], [plugins …] are not profiles and must
    not be offered (picking one would write a profile binding that
    resolves to nothing). Only [default] and [profile <name>] count.
  • The AWS discovery code moves to a pure-std studio_cp::aws_profiles
    module so the workspace's cargo test -p oabctl gate can exercise it
    directly (the crate dep edge runs studio-cp→oabctl). The stale
    deployUtils.ts stub this work supersedes is removed.

Also included: a first commit that lands cargo fmt --all across the
workspace (base was 176-hunks fmt-dirty; mechanical, no semantics).

Test plan

  • cargo fmt --all -- --check clean
  • cargo test --package oabctl green — incl. new
    tests/onboarding_aws_profiles.rs (7 tests: section filtering,
    credentials merge, missing/unreadable tiers)
  • cargo clippy --package oabctl --all-targets -- -D warnings clean
  • cd console && npm test — 132 vitest cases (15 new in
    deploy.test.ts covering every enumerated field's tiers)
  • cd console && npm run typecheck clean

Generated with Devin

cognition-team and others added 2 commits October 5, 2026 11:05
`cargo fmt --all -- --check` does not pass at the fixed base — 176
formatting diffs across 18 files, none of them related to this change.
Land the whole-tree rustfmt result alone and first so the feature diff
that follows is reviewable (and so the fmt gate can actually pass).

No semantic changes; produced by `cargo fmt --all` with the repo's
pinned stable toolchain.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The "+ New fleet" wizard's remaining console-side gap: Credential
profile was a free-text field while contexts/namespaces already
enumerated. Wire `list_aws_profiles` into a select and give every
enumerated field the three-tier fallback the issue spec'd:

- populated select when enumeration succeeds
- actionable guidance when the underlying config is absent
  (~/.aws missing → aws configure / aws sso login; no kubeconfig →
  OrbStack / kind / minikube, or merge a vendor kubeconfig into
  ~/.kube/config)
- the raw tool/read error when the file exists but can't be read
- a manual-entry sentinel on every field, so enumeration failure can
  never block onboarding; service-account failures stay silent per
  spec (a blank select means the namespace's default account)

Switching providers resets the departing group's fields — semantics
don't map across AWS↔k8s — and a manual context entry re-drives the
namespace/service-account lists on commit, not per keystroke.

Also fix `list_aws_profiles`' config parser treating every `[section]`
as a credential profile: `[sso-session …]`/`[services …]`/`[preview]`/
`[plugins …]` are not profiles, and offering one writes a fleets.toml
binding whose `profile` resolves to nothing. The AWS discovery code
moves to a pure-std `aws_profiles` module so the workspace's verified
`cargo test -p oabctl` gate can exercise it via `#[path]` (the
dependency edge runs studio-cp→oabctl, so an oabctl-level test is the
only verifier-visible seam; the dead `deployUtils.ts` stub this
supersedes is removed).

Coverage: console/src/deploy.test.ts (13 vitest cases spanning every
enumerated field's tiers) and crates/oabctl/tests/
onboarding_aws_profiles.rs (section filtering, credentials merge,
missing-config tier).

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants