Skip to content

feat: Add managed user bootstrap and local Launch testing - #401

Open
danielpanzella wants to merge 2 commits into
mainfrom
danielpanzella/launch-agent-bootstrap
Open

danielpanzella wants to merge 2 commits into
mainfrom
danielpanzella/launch-agent-bootstrap

Conversation

@danielpanzella

@danielpanzella danielpanzella commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Local Launch testing currently requires manual user creation and API-key setup. This change adds an optional Tilt workflow that waits for the W&B CR to report Ready, creates one user for both human login and Launch, saves their credentials, and disables the built-in local account so browser login no longer enters first-user setup.

The operator gains a default-off spec.wandb.enableGlobalAdminAPIKey flag. Server manifests can bind features to boolean CR fields, gate generated secrets and environment variables, and generate a per-deployment hex key for the API and Gorilla migrations. Bound features take their value from the CR field instead of spec.wandb.features.

Migration input tracking reruns affected jobs when the key is enabled, disabled, or rotated, and API readiness waits for the corresponding rollout. Existing security-profile behavior is preserved: profile-only changes do not restart completed migrations. The testing manifest wires the key into the API and Gorilla migration job.

The Launch integration includes a pinned agent chart/image, namespace-scoped setup and cleanup, credential display with CI suppression, documentation, and a smoke test that records a metric and verifies an artifact round trip. Login passwords are displayed only after successful password authentication; adopting an existing API key discards any unverified saved password, and a separately supplied password is validated before being saved as verified. No core server changes are required.

Validation:

  • make test passes, including migration security-profile and global-admin lifecycle tests.
  • All 54 Python helper tests pass, including failed-signup/API-key adoption and password verification regressions; cleanup script passes bash -n.
  • Live validation on kind-operator covered initial bootstrap, enable/disable/re-enable, credential reuse, local-account cleanup, human login, and a Launch metric/artifact smoke run. These live checks preceded the merge from main; the merged code was validated by the tests above.
  • make lint reports five existing staticcheck findings in unchanged code (three capitalized error strings and two deprecated ValueOrSecret.Name uses).

Compatibility: upgrade the operator and CRDs before using a manifest with feature bindings. The bootstrap and Launch workflow is opt-in; the Launch test profile targets Kind/Kubernetes.

@danielpanzella
danielpanzella requested a review from a team as a code owner October 8, 2026 19:32
devin-ai-integration[bot]

This comment was marked as resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant