Repository navigation
controlplane: default actionsLeasor.enabled=true (v2-actions switch-over) - #481
Merged
Merged
Conversation
Contributor
Current Aviator status
This PR was merged using Aviator (commit f62fa4d).
See the real-time status of this PR on the
Aviator webapp.
Use the Aviator Chrome Extension
to see the status of your PR within GitHub.
|
Contributor
Author
|
/aviator merge |
Contributor
|
Aviator has accepted the merge request. It will enter the queue when all of the required status checks have passed. Aviator will update the sticky status comment as the pull request moves through the queue. |
…ver) Flip the actionsLeasor.enabled chart default false->true per the 2026-07-31 switch-over documented in values.yaml. Every selfhosted CP now routes its own UNION_ORG through the v2 actions service and rejects sub-2.0.4 SDK CreateRun (rejectLegacySDKVersions=true). Envs still on a legacy SDK set actionsLeasor.enabled=false explicitly. Also set global.UNION_ORG=test-org in the no-auth, external-authz, and aws.billing-enable fixtures (they omitted it, so the default-on flag rendered useActionsServiceForOrgs with an empty org); their snapshots now reflect a real single-tenant deployment. Rebased onto latest main. The dataplane operator.apiKey default moved to its own PR (#482). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
mhotan
force-pushed
the
mike/actionsleasor-enabled-default
branch
from
July 16, 2026 21:25
517e174 to
d218cbf
Compare
wild-endeavor
approved these changes
Jul 16, 2026
aviator-app Bot
pushed a commit
that referenced
this pull request
Sep 16, 2026
…rap) (#482) ## Overview Flips the dataplane chart default `config.operator.apiKey.enabled: false → true`. With it on, the operator mints the `EAGER_API_KEY` on the control plane and writes it to the task-pod secret store, so the union-pod-webhook can inject it into task pods. Nothing mints the key without this, and it is **required for v2/actions (eager) execution** — see [cloud#17056 review](unionai/cloud#17056 (comment)). Under v2 every deployment runs eager/actions workloads, so this belongs on by default. Split out of #481 as an isolated change so the controlplane `actionsLeasor` default and this dataplane default land independently. ## Behavior change The operator configmap now renders the `apiKey` block (`enabled: true`). The prereq `proxy.secretManager.enabled` is already the chart default (`true`), so no dataplane loses functionality. A dataplane that must opt out sets `config.operator.apiKey.enabled: false`. No deployments are added or removed — the operator already rendered unconditionally; the delta is the configmap block plus the operator deployment's recomputed `configChecksum`. ## Control-plane dependency (selfhosted) The dataplane bootstrap only *requests* the key — the **control plane** must be able to mint `EAGER_API_KEY`. Normally the identity service mints it by registering an OAuth client on the IdP. If the control plane can't self-register clients (common with selfhosted Okta/Entra), operators must first seed pre-created OAuth client credentials via the controlplane chart's `identity.apiKeyOverrides` (system key `EAGER_API_KEY`), or the mint fails. Deployments where the CP can self-register need no action. ## Release notes `RELEASE.md` gains an `## Unreleased` entry documenting the flipped default and this control-plane dependency, with the explicit selfhosted guidance above. ## Test Plan - `make generate-expected` + `make test` (helm-test + kubeconform) — green. - 32 dataplane snapshots regenerated against current `main`; delta limited to the `apiKey: {enabled: true}` block and the recomputed `configChecksum`. ## Rollback Revert this PR (`enabled: true → false`) and regenerate snapshots. State is reversible; no data migration.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
Flips the
actionsLeasor.enabledcontrolplane chart defaultfalse → true, per the switch-over timeline documented incharts/controlplane/values.yaml. With the default on, every selfhosted control plane routes its ownUNION_ORGthrough the v2 actions service and stops depending on the legacy queue engine for eager/fan-out flows.This is the "chart default flips to
enabled: true" step of the 2026-07-31 milestone. The queue + executor template removal (the other half of that milestone) is intentionally not in this PR. The paired dataplane default (operator.apiKey.enabled) is split into its own PR: #482.Behavior change
For any deployment that does not set
actionsLeasor.enabledexplicitly, theexecutionsconfigmap now renders:useActionsServiceForOrgs: [<UNION_ORG>](was[]) — the deployment's own org routes to the v2 actions service.rejectLegacySDKVersions: true(wasfalse) — CreateRun from SDK < 2.0.4 is hard-rejected.The
rejectLegacySDKVersionsflip is the real blast radius: an env still on a sub-2.0.4 SDK will hard-fail CreateRun. Opt out withactionsLeasor.enabled: false.The actions / leasor / scylla stack templates already rendered unconditionally, so there is no deployment/stack churn — the routing-config injection is the only functional delta.
Note on timing
The values.yaml timeline schedules this flip for 2026-07-31; this lands it ahead of that date deliberately. Merging is a conscious call by the switch-over owner.
Test Plan
main;make generate-expected+make test(helm-test + kubeconform) — green.no-auth,external-authz, andaws.billing-enablefixtures gainglobal.UNION_ORG: test-org(they previously omitted it, so the default-on flag rendered an empty org); those snapshots now reflect a real single-tenant deployment.Rollback
Revert this PR (
actionsLeasor.enabled: true → false) and regenerate snapshots. State is reversible; no data migration.