Skip to content

dataplane: default operator.apiKey.enabled=true (eager API key bootstrap) - #482

Merged
aviator-app[bot] merged 2 commits into
mainfrom
mike/dataplane-operator-apikey-default
Sep 16, 2026
Merged

aviator-app[bot] merged 2 commits into
mainfrom
mike/dataplane-operator-apikey-default

Conversation

@mhotan

@mhotan mhotan commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Flips the dataplane chart default config.operator.apiKey.enabled: false → true. With it on, the operator mints the EAGER_API_KEY on the control plane and writes it to the task-pod secret store, so the union-pod-webhook can inject it into task pods. Nothing mints the key without this, and it is required for v2/actions (eager) execution — see cloud#17056 review. Under v2 every deployment runs eager/actions workloads, so this belongs on by default.

Split out of #481 as an isolated change so the controlplane actionsLeasor default and this dataplane default land independently.

Behavior change

The operator configmap now renders the apiKey block (enabled: true). The prereq proxy.secretManager.enabled is already the chart default (true), so no dataplane loses functionality. A dataplane that must opt out sets config.operator.apiKey.enabled: false.

No deployments are added or removed — the operator already rendered unconditionally; the delta is the configmap block plus the operator deployment's recomputed configChecksum.

Control-plane dependency (selfhosted)

The dataplane bootstrap only requests the key — the control plane must be able to mint EAGER_API_KEY. Normally the identity service mints it by registering an OAuth client on the IdP. If the control plane can't self-register clients (common with selfhosted Okta/Entra), operators must first seed pre-created OAuth client credentials via the controlplane chart's identity.apiKeyOverrides (system key EAGER_API_KEY), or the mint fails. Deployments where the CP can self-register need no action.

Release notes

RELEASE.md gains an ## Unreleased entry documenting the flipped default and this control-plane dependency, with the explicit selfhosted guidance above.

Test Plan

  • make generate-expected + make test (helm-test + kubeconform) — green.
  • 32 dataplane snapshots regenerated against current main; delta limited to the apiKey: {enabled: true} block and the recomputed configChecksum.

Rollback

Revert this PR (enabled: true → false) and regenerate snapshots. State is reversible; no data migration.

@aviator-app

aviator-app Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Current Aviator status

Aviator will automatically update this comment as the status of the PR changes.
Comment /aviator refresh to force Aviator to re-examine your PR (or learn about other /aviator commands).

This PR was merged using Aviator (commit 16bc253).


See the real-time status of this PR on the Aviator webapp.
Use the Aviator Chrome Extension to see the status of your PR within GitHub.

mhotan added a commit that referenced this pull request Jul 16, 2026
…ver)

Flip the actionsLeasor.enabled chart default false->true per the
2026-07-31 switch-over documented in values.yaml. Every selfhosted CP now
routes its own UNION_ORG through the v2 actions service and rejects
sub-2.0.4 SDK CreateRun (rejectLegacySDKVersions=true). Envs still on a
legacy SDK set actionsLeasor.enabled=false explicitly.

Also set global.UNION_ORG=test-org in the no-auth, external-authz, and
aws.billing-enable fixtures (they omitted it, so the default-on flag
rendered useActionsServiceForOrgs with an empty org); their snapshots now
reflect a real single-tenant deployment.

Rebased onto latest main. The dataplane operator.apiKey default moved to
its own PR (#482).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
aviator-app Bot pushed a commit that referenced this pull request Jul 16, 2026
…ver) (#481)

## Overview

Flips the `actionsLeasor.enabled` controlplane chart default `false → true`, per the switch-over timeline documented in `charts/controlplane/values.yaml`. With the default on, every selfhosted control plane routes its own `UNION_ORG` through the v2 actions service and stops depending on the legacy queue engine for eager/fan-out flows.

This is the "chart default flips to `enabled: true`" step of the **2026-07-31** milestone. The queue + executor template removal (the other half of that milestone) is intentionally **not** in this PR. The paired dataplane default (`operator.apiKey.enabled`) is split into its own PR: #482.

## Behavior change

For any deployment that does not set `actionsLeasor.enabled` explicitly, the `executions` configmap now renders:
- `useActionsServiceForOrgs: [<UNION_ORG>]` (was `[]`) — the deployment's own org routes to the v2 actions service.
- `rejectLegacySDKVersions: true` (was `false`) — **CreateRun from SDK < 2.0.4 is hard-rejected.**

The `rejectLegacySDKVersions` flip is the real blast radius: an env still on a sub-2.0.4 SDK will hard-fail CreateRun. Opt out with `actionsLeasor.enabled: false`.

The actions / leasor / scylla stack templates already rendered unconditionally, so there is **no** deployment/stack churn — the routing-config injection is the only functional delta.

## Note on timing

The values.yaml timeline schedules this flip for **2026-07-31**; this lands it ahead of that date deliberately. Merging is a conscious call by the switch-over owner.

## Test Plan

- Rebased onto latest `main`; `make generate-expected` + `make test` (helm-test + kubeconform) — green.
- 6 controlplane snapshots change: the two routing keys above. The `no-auth`, `external-authz`, and `aws.billing-enable` fixtures gain `global.UNION_ORG: test-org` (they previously omitted it, so the default-on flag rendered an empty org); those snapshots now reflect a real single-tenant deployment.

## Rollback

Revert this PR (`actionsLeasor.enabled: true → false`) and regenerate snapshots. State is reversible; no data migration.
@mhotan
mhotan force-pushed the mike/dataplane-operator-apikey-default branch from b7c69c8 to 73ca20a Compare September 16, 2026 20:48
@mhotan
mhotan deployed to helm-charts-ci September 16, 2026 21:07 — with GitHub Actions Active
config.operator.apiKey.enabled now defaults to true. The dataplane
operator mints EAGER_API_KEY on the control plane and writes it to the
task-pod secret store so eager/actions (v2) tasks can call back to the
control plane. Under v2 every deployment runs eager/actions workloads,
so this should be on. It relies on the proxy secret manager, which is
already on by default.

RELEASE.md documents the flipped default and the real dependency: the
control plane must be able to mint EAGER_API_KEY. If the CP can't
self-register OAuth clients on its IdP (selfhosted Okta/Entra), operators
must first seed the credentials via the controlplane chart's
identity.apiKeyOverrides (EAGER_API_KEY), else the bootstrap fails.

Regenerated dataplane snapshots (apiKey block now renders in the operator
configmap; configChecksum annotations updated).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Signed-off-by: Michael Hotan <mike@union.ai>
@mhotan
mhotan force-pushed the mike/dataplane-operator-apikey-default branch from 73ca20a to bda34e1 Compare September 16, 2026 22:03
@mhotan
mhotan deployed to helm-charts-ci September 16, 2026 22:04 — with GitHub Actions Active
@mhotan

mhotan commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

/aviator merge

@aviator-app

aviator-app Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Aviator has accepted the merge request. It will enter the queue when all of the required status checks have passed. Aviator will update the sticky status comment as the pull request moves through the queue.

@aviator-app
aviator-app Bot deployed to helm-charts-ci September 16, 2026 23:28 Active
@aviator-app
aviator-app Bot merged commit 16bc253 into main Sep 16, 2026
11 checks passed
@aviator-app
aviator-app Bot deleted the mike/dataplane-operator-apikey-default branch September 16, 2026 23:29
aviator-app Bot pushed a commit that referenced this pull request Sep 18, 2026
## Overview

Lowers the `uvolMountBroker` default CPU request from `500m` to `30m`, matching unionai/cloud#18499, which makes the same change to the operator chart that Union-managed (BYOC) dataplanes run.

The broker is a DaemonSet at `system-node-critical`, so its request comes off each node's allocatable, and a request a task pod cannot fit around **preempts** that task pod rather than queueing behind it. Two managed customers sizing task pods to their node's full allocatable CPU have now been bitten by the 500m default — one lost 184 running pods to preemption, the other could not schedule at all. Selfmanaged and selfhosted clusters run this chart and have exactly the same exposure.

The request is not a cap: there is deliberately no CPU limit, so the broker still bursts to whatever the node has idle. 500m bought a *guaranteed* share under contention. At the measured 60us of broker CPU per open with 8 volumes active, 30m guarantees ~500 opens/s against 500m's ~8,300 — far above what any cluster serving volumes through the CSI driver does today. A cluster that outgrows it should raise the value explicitly, and the rationale comment now says so.

## Test Plan

- `./tests/run.sh generate` with the CI-pinned helm 4.2.0, then `make test` — exit 0. The only snapshot movement is the one line in `tests/generated/dataplane.uvol-broker.yaml`.
- Committed with `--no-verify`: the local `trailing-whitespace` and `end-of-file-fixer` hooks want to rewrite lines this PR does not touch (three pre-existing trailing-whitespace lines already on `main`, and the trailing blank line the snapshot generator itself emits — stripping it would break `make test`). Neither hook runs in CI; `.github/workflows/checks.yaml` only mirrors the ruff hooks, and there is no Python here.
- No `Chart.yaml` bump: per `charts/CONVENTIONS.md` a `version:` bump requires a matching `RELEASE.md` section, and recent values changes (#585, #594, #482, #588) all land unversioned, picked up by the next release commit.

## Rollout

Picked up by ArgoCD on the next sync of each selfmanaged/selfhosted dataplane. `maxUnavailable: 25%` means brokers restart a quarter of nodes at a time; a task pod mounting a Volume during its node's restart window would fail `NodePublish`. The per-node effect is a 470m *reduction* in requested CPU, so it frees capacity rather than consuming it.

## Rollback

Revert the commit; the broker returns to 500m. A cluster needing the old value sooner can set `uvolMountBroker.resources.requests.cpu` in its env overlay in the cloud repo.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

This branch was successfully deployed

1 active deployment
helm-charts-ci — eec6bc38 Deployed Sep 16, 2026 by aviator-app[bot] via selfmanaged-dp/k3d #289
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants