Skip to content

🤖 docs: complete the CoderTemplateTest how-to - #213

Merged
ThomasK33 merged 4 commits into
mainfrom
feat/template-test-18-howto
Oct 3, 2026
Merged

ThomasK33 merged 4 commits into
mainfrom
feat/template-test-18-howto

Conversation

@ThomasK33

@ThomasK33 ThomasK33 commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Summary

Plan PR 8b of the CoderTemplateTest stack (Refs #152): the complete how-to, troubleshooting, the sample, and the upgrade note from the #210 assessment. This is the last planned PR. The plan tags a release only after PR 8 lands.

Based on main. #211 and #212 landed, and I rebased this PR onto main (head 7be4853a). Its own diff is byte-identical to the reviewed diff of 5d4d5669, so the commit SHAs in the review sections below are the pre-rebase ones.

What

  1. docs/how-to/test-templates.md keeps all the existing notes (🤖 Use the internal Coder URL for provisioner keys and the aggregated API when TLS is on #198 TLS facts, TTL scope, more than 100 builds, tester keys, retain and allowRetain, dormant tester) and adds:
    • a reasons section: waiting reasons, failure reasons, and WorkspaceDeleted reasons, each with what to do. I took them all from the controller code.
    • a ResourceQuota example that caps tests per namespace with count/codertemplatetests.coder.com, because each test is a real workspace,
    • a nightly CronJob that creates a test with generateName and a TTL, with a Role that grants only create.
  2. docs/how-to/troubleshooting.md adds three sections:
  3. Sample config/samples/coder_v1alpha1_codertemplatetest.yaml, with prerequisites in comments like the other samples. I checked it with a server-side dry-run create in envtest: the CRD accepted it and rejected a copy with two version fields.
  4. README: the operator-kinds row now lists CoderTemplateTest.
  5. Upgrade note (🤖 feat: activate the CoderTemplateTest controller #210 assessment) in docs/how-to/deploy-controller.md: apply config/crd/bases/ and config/rbac/ from the new version before or together with the new image. The operator watches every kind it reconciles, so a missing CoderTemplateTest CRD stops the manager from starting.

Known limits

  • The CronJob example uses the image placeholder <an image with sh and kubectl>.
  • The how-to examples use the template default.docker. The sample uses coder.docker, because the default organization in the Kind E2E is coder.

Review round 1 (fixed in 6d0133d, rebased as a5742ac)

This PR is rebased onto the new head of #212, so the CI docs-quality 404 for the tree/main/config/gitops link is gone.

  1. The last-resort finalizer patch removed the whole finalizer list. It now removes only coder.com/template-test-cleanup, guarded by a JSON Patch test operation.
  2. A missing or empty operator token Secret is now under OperatorAccessNotReady, as the controller reports it.
  3. Readiness claims now say every top-level agent. The controller does not check devcontainer sub-agents.

Review round 2 (fixed in d824e17, rebased as b13b884)

This branch is rebased onto the round 3 head of #212.

  1. NoAgents now says that the workspace has no top-level agents, and that devcontainer sub-agents do not count. The sample comment says "every top-level agent".
  2. The nightly CronJob sets backoffLimit: 0. A retry after a lost create response would make a second test, and a second workspace, because of generateName.

Review round 3 (fixed in 1b6f302)

  1. WorkspaceNameConflict now sends readers to the WorkspaceDeleted condition. NotCreated (an existing workspace before the create, or HTTP 409) means that the test never created a workspace and releases its finalizer by itself. Only OwnershipUnknown points to the escape hatch.
  2. Troubleshooting now says that the first reconcile only adds the finalizer and the next one writes the status, and shows how to tell the cases apart.

Validation

All on the pushed tree, with exit 0 each:

  • make verify-vendor, make test, make test-integration, make build, make lint
  • make codegen, make manifests, make docs-reference (no diff afterwards)
  • go test -race ./internal/controller/...
  • make docs-check, plus CI's markdownlint-cli2 and cspell versions

Line count

Hand-written: 6 files changed, 247 insertions(+), 3 deletions(-) (no generated or vendored files).


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T17:08:27.424211Z 7be4853 Manual request
🔒 Security Review ✅ Completed 2026-10-03T17:09:03.493603Z 7be4853 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 247f28e3f1

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 247f28e3f1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/how-to/troubleshooting.md Outdated
Comment thread docs/how-to/test-templates.md Outdated
Comment thread docs/how-to/test-templates.md Outdated
@ThomasK33
ThomasK33 force-pushed the feat/template-test-18-howto branch from 247f28e to 6d0133d Compare October 3, 2026 15:53
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 6d0133d0b2

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6d0133d0b2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/how-to/test-templates.md Outdated
Comment thread docs/how-to/test-templates.md
@ThomasK33
ThomasK33 force-pushed the feat/template-test-18-howto branch from 6d0133d to d824e17 Compare October 3, 2026 16:09
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: d824e17e4a

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

- **A test stuck as `ControlPlaneUnavailable` or `CoderUnavailable`.** Coder is unreachable, so the finalizer stays and the controller retries every 60 s. To release the test, remove the finalizer by hand, or use `retain` as described below. Either way, check Coder for a workspace named `status.workspaceName` and delete it there.

P2 Badge Delete the test before removing its finalizer

When this escape hatch is used on a finished test that has not first been marked for deletion, removing the finalizer does not release it: Reconcile sees a final test whose cleanup is incomplete and immediately adds coder.com/template-test-cleanup again (internal/controller/codertemplatetest_controller.go:157-165). Tell the administrator to issue kubectl delete first and remove the finalizer only after the object has a deletion timestamp; otherwise the documented recovery step is undone by the controller.

AGENTS.md reference: AGENTS.md:L110-L111

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/how-to/test-templates.md Outdated
Comment thread docs/how-to/troubleshooting.md Outdated
@ThomasK33
ThomasK33 force-pushed the feat/template-test-18-howto branch from d824e17 to 1b6f302 Compare October 3, 2026 16:25
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: 1b6f3026ee

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 1b6f3026ee

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@ThomasK33
ThomasK33 force-pushed the feat/template-test-17-gitops-docs branch from 6ca50f4 to 2bf0d5f Compare October 3, 2026 16:33
@ThomasK33
ThomasK33 force-pushed the feat/template-test-18-howto branch 2 times, most recently from b13d9c4 to 5d4d566 Compare October 3, 2026 16:40
Base automatically changed from feat/template-test-17-gitops-docs to main October 3, 2026 17:03
Expand the CoderTemplateTest how-to with a "Read the result" section
that lists every status.reason the controller sets (waiting, failure,
and WorkspaceDeleted condition reasons) with what to do, a ResourceQuota
example to cap test count, and a nightly CronJob with the RBAC it needs.
The existing notes on the tester, retain, TTL, keys, builds, and TLS
stay as they were.

Add troubleshooting entries for a test that stays Pending, a test that
does not finish deleting (finalizer), and a namespace stuck Terminating
because of the aggregated API LIST bug (#209). Add a sample manifest
(validated with a server-side dry run against the CRD in envtest) and
list CoderTemplateTest among the operator kinds in the README.

Refs #152

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_

Change-Id: I0af2782b45a458869b2a1840611682a600cf06a3
The last-resort patch in troubleshooting now removes only coder.com/template-test-cleanup, guarded by a JSON Patch test operation, instead of the whole finalizer list. A missing or empty operator token Secret is listed under OperatorAccessNotReady, as the controller reports it. Readiness claims now say top-level agents, because the controller skips devcontainer sub-agents.

Refs #152

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_

Change-Id: I4cef0bfae938870169b3f18b00b1607662ee8584
NoAgents means that the workspace has no top-level agents: the controller ignores devcontainer sub-agents, so the row and the sample now ask for a top-level agent. The nightly CronJob sets backoffLimit 0, because a retry after a lost create response makes a second test with generateName.

Refs #152

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_

Change-Id: I1a43ba8c48730e461c27b9120cc77f7aee236ee9
…the first reconcile

WorkspaceNameConflict has two outcomes. With WorkspaceDeleted NotCreated, the test never created a workspace and releases its finalizer by itself, so the workspace belongs to someone else. Only OwnershipUnknown needs the escape hatch. The troubleshooting page now says that the first reconcile only adds the finalizer and the next one writes the status, and shows how to tell the two cases apart.

Refs #152

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_

Change-Id: I4c6ec127bba9a3b078a6729d469518b626f92124
@ThomasK33
ThomasK33 force-pushed the feat/template-test-18-howto branch from 5d4d566 to 7be4853 Compare October 3, 2026 17:05
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 7be4853ae3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 7be4853ae3

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@ThomasK33
ThomasK33 added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 8afd850 Oct 3, 2026
13 checks passed
@ThomasK33
ThomasK33 deleted the feat/template-test-18-howto branch October 3, 2026 17:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant