Repository navigation
feat: Add managed user bootstrap and local Launch testing - #401
Open
danielpanzella wants to merge 2 commits into
Open
danielpanzella wants to merge 2 commits into
danielpanzella wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Local Launch testing currently requires manual user creation and API-key setup. This change adds an optional Tilt workflow that waits for the W&B CR to report Ready, creates one user for both human login and Launch, saves their credentials, and disables the built-in local account so browser login no longer enters first-user setup.
The operator gains a default-off
spec.wandb.enableGlobalAdminAPIKeyflag. Server manifests can bind features to boolean CR fields, gate generated secrets and environment variables, and generate a per-deployment hex key for the API and Gorilla migrations. Bound features take their value from the CR field instead ofspec.wandb.features.Migration input tracking reruns affected jobs when the key is enabled, disabled, or rotated, and API readiness waits for the corresponding rollout. Existing security-profile behavior is preserved: profile-only changes do not restart completed migrations. The testing manifest wires the key into the API and Gorilla migration job.
The Launch integration includes a pinned agent chart/image, namespace-scoped setup and cleanup, credential display with CI suppression, documentation, and a smoke test that records a metric and verifies an artifact round trip. Login passwords are displayed only after successful password authentication; adopting an existing API key discards any unverified saved password, and a separately supplied password is validated before being saved as verified. No core server changes are required.
Validation:
make testpasses, including migration security-profile and global-admin lifecycle tests.bash -n.kind-operatorcovered initial bootstrap, enable/disable/re-enable, credential reuse, local-account cleanup, human login, and a Launch metric/artifact smoke run. These live checks preceded the merge from main; the merged code was validated by the tests above.make lintreports five existing staticcheck findings in unchanged code (three capitalized error strings and two deprecatedValueOrSecret.Nameuses).Compatibility: upgrade the operator and CRDs before using a manifest with feature bindings. The bootstrap and Launch workflow is opt-in; the Launch test profile targets Kind/Kubernetes.