Repository navigation
R8 post-merge battery fixes: rollout order, pre-R8 producer marker, anchor check - #56
Merged
Merged
Conversation
The 'roll in any order' justification claimed the scoped envelope was stamped on every admission route, contradicting the per-resource-route drain requirement. State the real reason (admission stays disabled for the cutover), narrow the stamping claim to gateway routes, and document the image-before-chart ordering constraint plus the unstripped pass-through of legacy headers after the cutover. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…-only 503 parseTrustedRateLimits builds the org/owner name and value arrays once and derives the anchorless-scoped check from them (no duplicated 8-field list). The no-policy branch returns errNoTrustedRateLimitPolicy; the proxy call site adds a log-only WARN (legacy_envelope_present=true) when the raw request still carries the removed legacy quota headers. Response status and body are unchanged and the legacy names never feed a trust or limit decision. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tays on default lane Rename TestLegacyOnlyQuotaHeadersFailClosed to TestLegacyQuotaHeadersAreIgnored and add the anchored cases that would fail if legacy headers were read (zero caps, malformed values). Add TestLegacyOnlyQuotaHeadersLogPreR8ProducerMarker and TestUnmappedOrgStaysOnDefaultLaneDynamoHints. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
After R8, X-Saturn-Owner-Id is the only anchor for the quota policy, and admission also requires X-Saturn-Org-Id. A configured PHOEBE_TRUSTED_HEADERS that omits either now logs an ERROR at startup naming the header and the 503 consequence. The list is still installed as written and phoebe does not exit. Tests: TestLoadTrustedHeadersErrorsWhenOwnerOrOrgAnchorMissing, TestLoadTrustedHeadersNoErrorForPinnedList. The fallback no-regression test's doc comment now records that R8 removed five headers the pre-gate parser read. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Pre-R8 phoebe replicas still parse the legacy envelope, so the edge must keep blanking the five legacy names (strip-only, not trusted) until every replica runs the R8 image. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…r-56 # Conflicts: # internal/identity/trusted_headers_test.go
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Post-merge battery fixes for phoebe #55 (R8 hard cut of the five legacy quota headers), run
wf_9d5ad211-fb2(Tier 2, 1 round, gate green: build, vet, gofmt, golangci-lint,go test -race, integration and admission-integration suites).docs/shared-tier-admission.md: the R8 rollout section said the components "can roll in any order". That is wrong in one case: if the saturn-k8s chart that drops the legacy names fromtrustedHeaders(and therefore from the Traefik strip middleware) rolls before every phoebe replica runs the R8 image, and admission is enabled, a pre-R8 replica accepts a client-forged legacy envelope on a request with noX-Saturn-Owner-Id. The doc now states the order: every phoebe replica on the R8 image first (or admission kept off for the whole cutover), then the chart.PHOEBE_TRUSTED_HEADERSthat omits the owner or org anchor.Contracts
admission.enabled: falsethroughout. Admission is off by default (R12), so the current state is not exposed.https://claude.ai/code/session_01JR59LERE7vBqUT9cga5Kvq