Skip to content

controlplane: default actionsLeasor.enabled=true (v2-actions switch-over) - #481

Merged
aviator-app[bot] merged 1 commit into
mainfrom
mike/actionsleasor-enabled-default
Jul 16, 2026
Merged

aviator-app[bot] merged 1 commit into
mainfrom
mike/actionsleasor-enabled-default

Conversation

@mhotan

@mhotan mhotan commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Flips the actionsLeasor.enabled controlplane chart default false → true, per the switch-over timeline documented in charts/controlplane/values.yaml. With the default on, every selfhosted control plane routes its own UNION_ORG through the v2 actions service and stops depending on the legacy queue engine for eager/fan-out flows.

This is the "chart default flips to enabled: true" step of the 2026-07-31 milestone. The queue + executor template removal (the other half of that milestone) is intentionally not in this PR. The paired dataplane default (operator.apiKey.enabled) is split into its own PR: #482.

Behavior change

For any deployment that does not set actionsLeasor.enabled explicitly, the executions configmap now renders:

  • useActionsServiceForOrgs: [<UNION_ORG>] (was []) — the deployment's own org routes to the v2 actions service.
  • rejectLegacySDKVersions: true (was false) — CreateRun from SDK < 2.0.4 is hard-rejected.

The rejectLegacySDKVersions flip is the real blast radius: an env still on a sub-2.0.4 SDK will hard-fail CreateRun. Opt out with actionsLeasor.enabled: false.

The actions / leasor / scylla stack templates already rendered unconditionally, so there is no deployment/stack churn — the routing-config injection is the only functional delta.

Note on timing

The values.yaml timeline schedules this flip for 2026-07-31; this lands it ahead of that date deliberately. Merging is a conscious call by the switch-over owner.

Test Plan

  • Rebased onto latest main; make generate-expected + make test (helm-test + kubeconform) — green.
  • 6 controlplane snapshots change: the two routing keys above. The no-auth, external-authz, and aws.billing-enable fixtures gain global.UNION_ORG: test-org (they previously omitted it, so the default-on flag rendered an empty org); those snapshots now reflect a real single-tenant deployment.

Rollback

Revert this PR (actionsLeasor.enabled: true → false) and regenerate snapshots. State is reversible; no data migration.

@aviator-app

aviator-app Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Current Aviator status

Aviator will automatically update this comment as the status of the PR changes.
Comment /aviator refresh to force Aviator to re-examine your PR (or learn about other /aviator commands).

This PR was merged using Aviator (commit f62fa4d).


See the real-time status of this PR on the Aviator webapp.
Use the Aviator Chrome Extension to see the status of your PR within GitHub.

@mhotan

mhotan commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

/aviator merge

@aviator-app

aviator-app Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Aviator has accepted the merge request. It will enter the queue when all of the required status checks have passed. Aviator will update the sticky status comment as the pull request moves through the queue.

@mhotan mhotan changed the title controlplane: default actionsLeasor.enabled=true (v2-actions switch-over) helm-charts: default v2-actions execution on (controlplane actionsLeasor + dataplane operator apiKey) Jul 16, 2026
…ver)

Flip the actionsLeasor.enabled chart default false->true per the
2026-07-31 switch-over documented in values.yaml. Every selfhosted CP now
routes its own UNION_ORG through the v2 actions service and rejects
sub-2.0.4 SDK CreateRun (rejectLegacySDKVersions=true). Envs still on a
legacy SDK set actionsLeasor.enabled=false explicitly.

Also set global.UNION_ORG=test-org in the no-auth, external-authz, and
aws.billing-enable fixtures (they omitted it, so the default-on flag
rendered useActionsServiceForOrgs with an empty org); their snapshots now
reflect a real single-tenant deployment.

Rebased onto latest main. The dataplane operator.apiKey default moved to
its own PR (#482).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@mhotan
mhotan force-pushed the mike/actionsleasor-enabled-default branch from 517e174 to d218cbf Compare July 16, 2026 21:25
@mhotan mhotan changed the title helm-charts: default v2-actions execution on (controlplane actionsLeasor + dataplane operator apiKey) controlplane: default actionsLeasor.enabled=true (v2-actions switch-over) Jul 16, 2026
@aviator-app
aviator-app Bot merged commit f62fa4d into main Jul 16, 2026
6 checks passed
@aviator-app
aviator-app Bot deleted the mike/actionsleasor-enabled-default branch July 16, 2026 21:59
aviator-app Bot pushed a commit that referenced this pull request Sep 16, 2026
…rap) (#482)

## Overview

Flips the dataplane chart default `config.operator.apiKey.enabled: false → true`. With it on, the operator mints the `EAGER_API_KEY` on the control plane and writes it to the task-pod secret store, so the union-pod-webhook can inject it into task pods. Nothing mints the key without this, and it is **required for v2/actions (eager) execution** — see [cloud#17056 review](unionai/cloud#17056 (comment)). Under v2 every deployment runs eager/actions workloads, so this belongs on by default.

Split out of #481 as an isolated change so the controlplane `actionsLeasor` default and this dataplane default land independently.

## Behavior change

The operator configmap now renders the `apiKey` block (`enabled: true`). The prereq `proxy.secretManager.enabled` is already the chart default (`true`), so no dataplane loses functionality. A dataplane that must opt out sets `config.operator.apiKey.enabled: false`.

No deployments are added or removed — the operator already rendered unconditionally; the delta is the configmap block plus the operator deployment's recomputed `configChecksum`.

## Control-plane dependency (selfhosted)

The dataplane bootstrap only *requests* the key — the **control plane** must be able to mint `EAGER_API_KEY`. Normally the identity service mints it by registering an OAuth client on the IdP. If the control plane can't self-register clients (common with selfhosted Okta/Entra), operators must first seed pre-created OAuth client credentials via the controlplane chart's `identity.apiKeyOverrides` (system key `EAGER_API_KEY`), or the mint fails. Deployments where the CP can self-register need no action.

## Release notes

`RELEASE.md` gains an `## Unreleased` entry documenting the flipped default and this control-plane dependency, with the explicit selfhosted guidance above.

## Test Plan

- `make generate-expected` + `make test` (helm-test + kubeconform) — green.
- 32 dataplane snapshots regenerated against current `main`; delta limited to the `apiKey: {enabled: true}` block and the recomputed `configChecksum`.

## Rollback

Revert this PR (`enabled: true → false`) and regenerate snapshots. State is reversible; no data migration.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants