* Docs(KEP): add KEP for Cluster Infrastructure Abstraction
Introduce new CRDs for managing cluster infrastructure with OAM patterns:
- Cluster: First-class cluster representation with inventory and health
- ClusterPlane: Composable infrastructure layers with team ownership
- ClusterBlueprint: Composition of planes into complete cluster specs
- ClusterRollout: Emergency/manual rollout overrides
- ClusterRolloutStrategy: Wave-based progressive rollout across fleet
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): Reduce duplication of concepts
- Removed go code in lieu of explanations
- Added command references
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): Add shared infrastructure plane semantics to ClusterPlane
Introduces plane-level scope model for multi cluster shared infrastructure
This enables cenarios where multiple clusters that share common infra without
complex ownership semantics. Shared planes are created once on management cluster
and their outputs are consumed by per-cluster planes via input bindings
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): Make cluster-gateway optional and isolate to backward compatibility appendix
- Remove cluster-gateway from main architecture, connectivity options, and controller flow
- Simplify Cluster CRD to 3 self-sufficient connectivity methods: inline, secretRef, cloudProvider
- Move cluster-gateway backward compatibility to dedicated Appendix A
- Fix internal contradictions and add GitOps integration section (Flux, ArgoCD)
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): add hub bootstrap prerequisites and fleet scaling guidance
- Add Prerequisites section: hub cluster must be bootstrapped externally
(Terraform/eksctl/cloud console) before KubeVela manages spoke clusters
- Add hub-spoke architecture diagram and bootstrap sequence
- Add Fleet Scale Controls: sharding, rate limiting for 50-1000+ clusters
- Clarify KubeVela orchestrates composition/rollout, delegates provisioning
to Crossplane/CAPI/tf-controller/KRO (user's choice)
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): Adds documentation for deletion and the order using
garbage collection policy
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): Consolidate definition CRDs and fix lifecycle consistency
Reuse existing KubeVela definition CRDs with scope annotation instead
of introducing new PlaneComponentDefinition/PlaneTraitDefinition CRDs.
Fix postCreate references to reflect validation/smoke-test purpose
rather than cluster infrastructure. Remove stale mode:infrastructure
references and resolve status phase inconsistencies across examples.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): Fix broken TOC anchors and minor text fixes
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): recast core model to spoke-reconciled lifecycle
Rework the Cluster Infrastructure KEP core model so the spoke is
self-sufficient:
- Introduce SpokeCluster as the hub-side fleet handle and blueprint
dispatcher (kubectl get spokeclusters).
- Recast Cluster as the spoke-side, self-reconciling object that
vela-cluster-core builds from the dispatched ClusterBlueprint and keeps
converged locally.
- Replace status push-back with hub-initiated, on-demand reads, so hub
downtime never stops spoke reconciliation.
- Reframe the lifecycle phases to infraProvisioning (hub),
planeProvisioning (spoke), and healthValidation (hub/both).
- Update The Approach, CRDs Introduced, What Lives Where, the controller
ownership/reconciliation/responsibilities sections, the migration path,
and the table of contents.
Downstream sections (the Cluster spec catalog, provision/adopt CLI,
rollouts, health, and use cases) still describe the prior hub-centric flow
and are flagged inline for a follow-up.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): generalize SpokeCluster credential model and record connectivity decisions
Make credential a discriminated union keyed by auth method: a directly supplied kubeconfig and cloud-native identity per provider (aws, azure, gcp), with provider-scoped auth modes so invalid combinations cannot be expressed.
Record cluster-gateway as the connectivity substrate, with an agent-based alternative such as Open Cluster Management for fleets the hub cannot route to.
Note per-provider workload identity for hub-to-spoke auth (AWS uses EKS Pod Identity, with IRSA as an alternative).
Clarify mode as the seam between connect (attach to an existing cluster) and provision (create when absent).
Note SpokeCluster as a hub-role object that a sub-hub also holds for its own children in a tree topology.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): clarify spoke-local reconciliation in the Approach bullet
Reword 'whether or not the hub is reachable' so it reads that reconciliation runs entirely on the spoke and never calls back to the hub, matching the no status push-back principle. Reword 'reconciles its blueprint into every cluster plane' to 'applies its blueprint by provisioning each ClusterPlane the blueprint declares.' Addresses review feedback on the Approach section.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): unify vela-cluster-core placement in What Lives Where
Replace the separate hub-controllers and spoke-engine rows with one vela-cluster-core row that runs on every cluster in the fleet. Hub-role and spoke-role controllers are activated by the CRs a cluster holds, so any cluster can act as hub, spoke, or both in the tree topology. Addresses review feedback on whether vela-cluster-core runs on the hub as well as the spokes.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): rename design principles 1-3 per review
Rename Principle 1 to Self-Sufficient, Principle 2 to Central Intent, Local Truth, and Principle 3 to One-Way Reconciliation Boundary, keeping each description. The earlier names for 2 and 3 read as descriptions rather than principle names. Addresses review feedback.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): add spoke-reconciled clusterInit lifecycle phase
Introduce clusterInit between infraProvisioning and planeProvisioning. It is spoke-reconciled: vela-cluster-core installs the foundational layer the planes depend on (Kubernetes controllers, operators, Helm charts, base CRDs) before planeProvisioning. infraProvisioning stays hub-side and ensures vela-cluster-core is running on the spoke first.
Also drop the numbered phase labels in the lifecycle block so adding a phase no longer forces renumbering; phases are referenced by name. Updates the Approach bullet, TOC, heading, SpokeCluster example, and deletion order. Addresses review feedback on init/bootstrap blueprints and splitting infraProvisioning.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): cover hub-reconciled infraProvisioning in the reconcile algorithm
The hub SpokeClusterController algorithm now reconciles spec.infraProvisioning.blueprintRef on the hub against cloud APIs (consuming shared outputs when another SpokeCluster already reconciled it) before any dispatch, then dispatches the spoke-reconciled blueprints (clusterInit, then the main blueprint). Adds the matching responsibility to the controller matrix. Addresses review feedback on the reconcile algorithm.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): carry infraProvisioning, patches, maintenance, pulled health on SpokeCluster
The hub SpokeCluster example now shows infraProvisioning.blueprintRef (hub-reconciled cloud infra), patches and maintenance (homed on the hub object), and status.health pulled from the spoke on demand. First step of splitting hub-side concerns onto SpokeCluster and leaving the spoke Cluster as the self-representation.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): make the spoke Cluster the self-representation
Trim the Cluster spec to the spoke-reconciled phases (clusterInit, planeProvisioning, healthValidation) driven by the dispatched blueprint. Hub-facing fields (credential, desired blueprintRef, patches, rolloutStrategyRef, maintenance) now live on SpokeCluster; cluster-level policies fold into the blueprint. Drop hub-facing status from Cluster: connectionStatus, the maintenance window state, and the Connected condition. Rewrite the field note and Key Design Decisions to match.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): align front-matter diagram, install steps, and What Lives Where with SpokeCluster
Architecture diagram: ClusterController becomes SpokeClusterController; the hub CRD box notes Cluster is spoke-resident and lists SpokeCluster (one per spoke). Bootstrap step installs vela-cluster-core and its reconcilers and applies the SpokeCluster CRD. What Lives Where: provisioning controllers are needed for infraProvisioning. Provisioning Flexibility: the SpokeCluster's infraProvisioning delegates cluster creation.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): migrate ClusterPlane section to the SpokeCluster model
Hub fleet object becomes SpokeCluster; ClusterController becomes SpokeClusterController (hub) or vela-cluster-core (spoke reconciliation). preCreate -> infraProvisioning, postCreate -> healthValidation, and the deletion cascade becomes healthValidation, planeProvisioning, clusterInit, infraProvisioning. GitOps is reframed as hub-dispatches / spoke-reconciles. The nested shared-pattern, GitOps-flow, and deletion-cascade ASCII boxes are converted to clean text, and the shared-infra example is now a SpokeCluster using the discriminated credential union.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): migrate Blueprint, Rollout, RolloutStrategy, Scale, Maintenance to SpokeCluster
Fleet object becomes SpokeCluster (blueprint-reference, sharding, and maintenance examples). Rollout gating targets SpokeClusterController dispatch rather than a hub ClusterController; the applied blueprint status is reconciled by vela-cluster-core on the spoke. Fix push-vs-pull wording (spoke state is pulled by the hub, not written to it), move maintenance window state onto SpokeCluster.status, and convert the rollout relationship ASCII box to clean text.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): fix execution model, broken anchor, and re-split the Lifecycle Phases example
Rewrite the Component Execution Model to the four phases with the correct reconcile locations (only infraProvisioning on the hub; clusterInit/planeProvisioning/healthValidation reconciled by vela-cluster-core on the spoke) and fix the broken cross-link to the renamed Lifecycle Phases heading. Re-split the Lifecycle Phases YAML into a hub SpokeCluster (infraProvisioning + dispatched blueprintRef) and a spoke Cluster (clusterInit, planeProvisioning, healthValidation), and correct the phase text so healthValidation is spoke-run/hub-pulled and provisioning happens in infraProvisioning.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): finish Lifecycle Management migration (modes, examples, provisioning, decommission)
Convert the Cluster Modes diagram to clean text with the four-phase flow. Rename the mode 1/2/3 and decommission examples from kind: Cluster to kind: SpokeCluster (the hub fleet object). Fix ClusterController to SpokeClusterController in the adopt intro, the IAM comment, and the provisioning-integration steps (hub dispatches, spoke reconciles). Rename the remaining preCreate references in the decommission section to infraProvisioning.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): state the pull boundary in Health and repoint Drift refs to SpokeCluster
Make explicit that health is local truth on the spoke Cluster (aggregated by vela-cluster-core); the hub reads it on demand and mirrors a snapshot on SpokeCluster.status.health, never by push. Retitle the Health Status section as the spoke Cluster and note the pulled hub mirror, and clarify that rollout wave progression reads the pulled SpokeCluster.status.health. Point ClusterDriftException and ClusterDriftReport clusterRef at the hub SpokeCluster, derived from the spoke's local status.drift.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): split API Reference into SpokeCluster + Cluster and migrate the Use Cases
Split the API Reference Cluster field table into SpokeCluster (hub: mode, credential union, infraProvisioning, dispatched blueprintRef, rolloutStrategyRef, patches, maintenance; status connection/dispatchedRevision/clusterInfo/pulled health/provisioning/adoption/maintenance) and Cluster (spoke: clusterInit/planeProvisioning/healthValidation; status blueprint/planes/health/drift/conditions/resources/history). Migrate Use Case 2 and Use Case 5: kind: Cluster to SpokeCluster, preCreate to infraProvisioning, and reframe the onboarding comment as hub-dispatches, spoke-reconciles.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): final consistency sweep (Appendix A, runtime-state comments, API consumers)
Rename the backward-compatibility cluster-gateway example to kind: SpokeCluster; qualify the ClusterPlane/ClusterBlueprint runtime-state comments as the spoke Cluster's status.planes reconciled by vela-cluster-core; label ClusterPlane status.consumers entries as SpokeClusters. Doc-wide: no preCreate/postCreate/ClusterController remain, the only kind: Cluster left are the three spoke self-representation examples, code fences are balanced, and TOC anchors resolve.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
---------
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
Co-authored-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Docs(KEP): Go SDK for X-Definition Authoring (defkit)
Introduces KEP proposal for defkit, a Go SDK that enables platform
engineers to author X-Definitions using native Go code instead of CUE.
Key proposed features:
- Fluent builder API for Component, Trait, Policy, and WorkflowStep definitions
- Transparent Go-to-CUE compilation
- IDE support with autocomplete and type checking
- Schema-agnostic resource construction
- Collection operations (map, filter, dedupe)
- Composable health and status expressions
- Addon integration with godef/ folder support
- Module dependencies for definition sharing via go get
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(KEP): Examples and minor api changes given in the document
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(KEP): align defkit examples
- Fix golang version in CI
- Fix variable declaration in example for testing
- Add Is() comparison method to status check
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): add security considerations section
- Add goal #7 for secure code execution model
- Add Security Considerations section covering:
- Code execution model (compile-time only, not runtime)
- Security benefits over CUE (static analysis, dependency scanning)
- Threat model with mitigations
Addresses PR feedback about code execution safety.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): add module versioning and definition placement sections
- Add Module Versioning section explaining git-based version derivation
- Add Definition Placement section covering:
- Motivation for placement constraints in multi-cluster environments
- Fluent API for placement (RunOn, NotRunOn, label conditions)
- Logical combinators (And, Or, Not)
- Module-level placement defaults
- Placement evaluation logic
- CLI experience for managing cluster labels
- Add Module Hooks section for lifecycle callbacks
- Minor fixes and clarifications throughout
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): add module hooks and update addon integration sections
- Add Module Hooks section covering:
- Use cases (CRD installation, setup scripts, post-install samples)
- Hook configuration in module.yaml (pre-apply, post-apply)
- Hook types (path for manifests, script for shell scripts)
- waitFor field with condition names and CUE expressions
- CLI usage (--skip-hooks, --dry-run)
- Update Addon Integration section with implementation details:
- godef/ folder structure with module.yaml
- CLI flags (--godef, --components, --traits, --policies, --workflowsteps)
- Conflict detection and --override-definitions flag
- Development workflow
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): address PR review comments and clarify placement labels
- Fix misleading "Sandboxed Compilation" claim (cubic-ai feedback) -
renamed to "Isolated Compilation" and clarified that security relies
on trust model, not technical sandboxing
- Fix inconsistent apiVersion in module hooks example (defkit.oam.dev/v1
→ core.oam.dev/v1beta1)
- Clarify that placement uses vela-cluster-identity ConfigMap directly,
not the vela cluster labels command (which is planned for future)
- Add --stats flag to apply-module CLI documentation
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(KEP): fix API documentation
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add core fluent API types for Go-based definitions
Introduce the defkit package providing a fluent Go API for defining
KubeVela X-Definitions (components, traits, policies, workflow steps).
Core types added:
- types.go: Value, Condition, Param interfaces
- base.go: Base definition types and interfaces
- param.go: Parameter builders (String, Int, Bool, Array, Map, Struct, Enum)
- expr.go: Expression builders for conditions and comparisons
- resource.go: Resource operations (Set, SetIf, Spread)
- context.go: KubeVela context references (appName, namespace, etc.)
- test_context.go: Test utilities for definition validation
This enables writing type-safe Go definitions that compile to CUE.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add collection operations and helper builders
Add fluent API for array/collection transformations:
- CollectionOp with Filter, Map, Pick, Wrap, Dedupe operations
- From() and Each() entry points for collection pipelines
- FieldRef, FieldEquals, FieldMap for field-level operations
- MultiSource for complex multi-array comprehensions
- Add helper builders for template variables
- Add value transformation utilities
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add CUE code generator
Implement CUEGenerator that transforms Go definitions into CUE code
Added helper methods and writers for conversion
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add status and health policy builders
Add fluent builders for customStatus and healthPolicy CUE generation
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add definition type builders
Add fluent builders for all four KubeVela X-Definition types:
- ComponentDefinition
- TraitDefinition
- PolicyDefinition
- WorkflowStepDefinition
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(goloader): add Go module loader for definitions
- Definition interface and registry for runtime discovery
- Discover and parse Go-based definition files
- Compile Go definitions to CUE at runtime
- Module environment for batch processing
- Parallel generation for better performance
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(cli): add vela def commands for Go-based definitions
- init-module: scaffold a new Go definition module
- apply-module: compile and apply definitions to cluster
- list-module: show definitions in a module
- validate-module: validate definitions without applying
- Also support the cue commands for xdefintions for go code
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add testing utilities and matchers
- CUE comparison matchers for Ginkgo/Gomega tests
- Test helpers for definition validation
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add patch container helpers for container mod operations
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(cli): update the go module to 1.23.8 for defkit init-module command
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Refactor: Add grouped help output for vela def command
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add definition placement for cluster-aware deployments
Enable definitions to specify which clusters they should run on based on
cluster identity labels stored in a well-known ConfigMap.
Also derives module version from git tags and improves init-module to
create directories from --name flag.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add RunOn/NotRunOn fluent API for placement constraints
Add placement methods to all definition builders allowing definitions
to specify cluster eligibility using the placement package's fluent API.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Docs(defkit): add commented placement example to module.yaml template
Show users the placement syntax in generated module.yaml without
setting actual values.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add module-level placement support
Add placement constraints at the module level in module.yaml that
apply to all definitions unless overridden at definition level.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add CLI placement enforcement in apply-module
Add placement constraint checking to `vela def apply-module` command.
Definitions are skipped if cluster labels don't match module placement.
- Add --ignore-placement flag to bypass placement checks
- Display placement status during apply with clear skip reasons
- Track placement-skipped count in summary output
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(defkit): show all flags in subcommand help output
Fix custom help function to properly display flags for def subcommands
like init-module and apply-module instead of only showing parent flags.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(defkit): apply name prefix to definitions in apply-module
The --prefix flag was not being applied to definition names. The prefix
was set in module loader metadata but not used when creating Kubernetes
objects from parsed CUE.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Chore(defkit): align module command help with standard vela pattern
Remove argument placeholders from command Use field to align with
other vela commands (addon, cluster, workflow). Arguments are shown
in examples and individual --help output instead of the listing.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(goloader): use json.Unmarshal for go mod download output
The downloadGoModule function parses JSON output from 'go mod download -json'
but was incorrectly using yaml.Unmarshal with json struct tags. The yaml.v3
library ignores json tags, resulting in empty field values.
This would cause remote Go module loading (e.g., github.com/foo/bar@v1.0.0)
to fail with "go mod download did not return a directory" because result.Dir
would be empty.
Fix: Use json.Unmarshal instead since the data is JSON from the Go toolchain.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(goloader): use semver for MinVelaVersion comparison
String comparison of version numbers is incorrect for cases like
"v1.10.0" > "v1.9.0" which returns false due to lexicographic ordering.
Use the Masterminds/semver library (already a dependency) for proper
semantic version comparison in ValidateModule().
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(placement): validate operator in module placement conditions
Add validation to catch invalid placement operators at module load time
instead of silently failing at runtime evaluation.
- Add Operator.IsValid() method to check for valid operators
- Add ValidOperators() helper function
- Add validatePlacementConditions() in ValidateModule()
- Provides clear error message with valid operator list
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(cli): validate conflict strategy in apply-module
Invalid --conflict values like "invalid" were silently accepted and
would fall through the switch statement, behaving like "overwrite".
Add ConflictStrategy.IsValid() method and validation at flag parsing
to provide clear error message for invalid values.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(placement): support definition-level placement constraints
Previously only module-level placement was enforced. Now individual
definitions can specify their own placement constraints that override
module defaults.
Changes:
- Add Placement field to DefinitionInfo and DefinitionPlacement types
- Add GetPlacement/HasPlacement to Definition interface
- Update registry ToJSON to include placement in output
- Update goloader to capture definition placement from registry
- Update CLI apply-module to use GetEffectivePlacement() for combining
module-level and definition-level placement
- Add comprehensive tests for definition placement
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Chore(defkit): remove dead PatchTemplate code
PatchTemplate, PatchOp, SetPatchOp, and SetIfPatchOp were defined but
never used anywhere in the codebase. The PatchResource type already
provides the same functionality and is the one actually being used
through Template.Patch().
Removed:
- PatchTemplate struct and its methods (ToCue, SetIf, Set)
- PatchOp interface
- SetPatchOp struct and its ToCue method
- SetIfPatchOp struct and its ToCue method
- NewPatchTemplate constructor
This cleanup reduces maintenance burden without affecting any
functionality.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(cli): pass actual VelaVersion to validate-module command
The help text for `vela def validate-module` promised to check
minVelaVersion requirements but ValidateModule() was called with
an empty string, causing the check to be silently skipped.
Now passes velaversion.VelaVersion so modules specifying a minimum
KubeVela version will be properly validated against the current CLI
version.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): implement WithDetails() and FromTyped() APIs
WithDetails():
- Adds WithDetails(message, details...) method to StatusBuilder
- Allows adding structured key-value details alongside status messages
- Uses existing StatusDetail and statusWithDetailsExpr infrastructure
- Example: s.WithDetails(s.Format("Ready: %v", ...), s.Detail("endpoint", ...))
FromTyped():
- Converts typed Kubernetes objects (runtime.Object) to Resource
- Provides compile-time type safety for building resources
- Requires TypeMeta to be set on the object
- Includes MustFromTyped() variant that panics on error
- Example: defkit.FromTyped(&appsv1.Deployment{...})
Both APIs were documented in the KEP but not implemented.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Style(defkit): apply gofmt formatting
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(defkit): fix remote module download with @latest version
When downloading a Go module without an explicit version, always append
@latest to ensure go mod download fetches from the remote repository
instead of skipping the download.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(defkit): support running def commands from any directory
Previously, module commands like `vela def list-module` only worked
when run from within the kubevela repository. Now they work from any
directory by honoring replace directives in the source module's go.mod.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): generate doc.go files in init-module
Create doc.go files with package documentation in each definition
directory (components, traits, policies, workflowsteps). This ensures
go mod tidy works correctly by making each directory a valid Go package,
and provides helpful examples for users creating new definitions.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(defkit): deduplicate definitions from overlapping directory scans
The module loader scans both conventional directories (components/,
traits/, etc.) and the root directory. Since DiscoverDefinitions uses
recursive filepath.Walk, files in subdirectories were found twice.
Added file tracking to skip already-processed files.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(defkit): validate placement constraints and fix GOWORK interference
Add validation for conflicting placement constraints at registration time.
Definitions with logically impossible placement (e.g., same condition in
both RunOn and NotRunOn) now fail fast with a clear error message.
Also fix placement loading when parent directories contain go.work files
by setting GOWORK=off when running the registry generator.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add parameter schema constraints and runtime condition methods
Extend the parameter fluent API with comprehensive validation and
conditional logic support:
- Schema constraints for input validation (Min/Max, Pattern, MinLen/MaxLen, MinItems/MaxItems)
- Runtime conditions for template logic (In, Contains, Matches, StartsWith/EndsWith, Len*, IsEmpty/IsNotEmpty, HasKey, IsFalse)
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(defkit): add waitFor support with CUE expressions for module hooks
Add the ability to specify custom readiness conditions for module hooks
using the new `waitFor` field. This allows users to define precise
conditions for when resources should be considered ready.
The waitFor field supports two formats:
- Simple condition name (e.g., "Ready", "Established") - checks
status.conditions for the named condition with status "True"
- CUE expression (e.g., "status.replicas == status.readyReplicas") -
evaluated against the full resource for flexible readiness checks
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(addon): add godef support for Go-based definitions in addons
Add support for a godef/ folder in addons that allows writing definitions
in Go instead of CUE. When an addon is enabled, Go definitions are
automatically compiled to CUE and deployed alongside traditional CUE
definitions.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: lint issues and make reviewable
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: lint and build failure
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: lint and ci errors
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: golangci-lint errors for defkit package
- Use standard library errors (errors.Is/As) instead of pkg/errors
- Fix ineffassign issues by scoping variables correctly
- Add nolint comments for intentional nilerr, makezero patterns
- Combine chained appends in addon init.go
- Add gosec nolint for CLI file operations and permissions
- Increase gocyclo threshold to 35, nolint complex CLI commands
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: kubectl installation with retry and fallback version in github actions
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix(ci): hardcode kubectl version to avoid flaky CDN endpoint
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Chore: improve test coverage for codecov
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Chore: add more tests for codecov and CI to pass
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: ci failure on style
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: OperatorNotEquals to fail closed with empty values
Change NotEquals operator to return false when Values slice is empty,
matching the fail-closed behavior of Equals operator. This prevents
silent widening of placement eligibility when a malformed constraint
is created.
Following Kubernetes label selector semantics where In/NotIn operators
require non-empty values, we apply a fail-closed approach for safety
in placement decisions.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: OpenArrayParam field shadowing and remove redundant GetName()
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: path traversal vulnerability in Go definition scaffolding
Validate Go definition names before using them in file paths to prevent
creation of files outside the addon directory. Unsanitized names could
contain path traversal segments (e.g., "../../../etc/passwd") allowing
arbitrary file writes.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: unescaped string interpolation in health_expr CUE generation
Use %q format verb in formatValue() to properly escape quotes and
special characters when generating CUE strings. Update fieldContainsExpr
to use formatValue() instead of raw string interpolation.
This prevents invalid CUE when substring values contain quotes or
backslashes.
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: Guard against typed nil in Gomega matchers to prevent panic
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: Guard against malformed bracket path in parseBracketAccess
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: incomplete AppRevision test to actually verify resolution
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Fix: apply fail-closed behavior to NotIn with empty values
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Doc: Added note about RawCUE and some alignment style
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
---------
Signed-off-by: Anoop Gopalakrishnan <anoop2811@aol.in>
* Feat(KEP): Nested Definition Rendering (Compositions)
Signed-off-by: Brian Kane <briankane1@gmail.com>
* Feat(KEP) #6990 - Nested Definition Rendering (Compositions) - Minor Updates
Signed-off-by: Brian Kane <briankane1@gmail.com>
---------
Signed-off-by: Brian Kane <briankane1@gmail.com>
Signed-off-by: zhengq2006 <zhengq200618@cmbchina.com>
workflow substep develop
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>
Feat: support step group with substep in the workflow
Signed-off-by: Qiang Zheng <zhengq20018@cmbchina.com>