🤖 docs: complete the CoderTemplateTest how-to - #213
Conversation
|
@codex security review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 247f28e3f1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
247f28e to
6d0133d
Compare
|
@codex review |
|
@codex security review |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6d0133d0b2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
6d0133d to
d824e17
Compare
|
@codex review |
|
@codex security review |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
coder-k8s/docs/how-to/test-templates.md
Line 216 in d824e17
When this escape hatch is used on a finished test that has not first been marked for deletion, removing the finalizer does not release it: Reconcile sees a final test whose cleanup is incomplete and immediately adds coder.com/template-test-cleanup again (internal/controller/codertemplatetest_controller.go:157-165). Tell the administrator to issue kubectl delete first and remove the finalizer only after the object has a deletion timestamp; otherwise the documented recovery step is undone by the controller.
AGENTS.md reference: AGENTS.md:L110-L111
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
d824e17 to
1b6f302
Compare
|
@codex review |
|
@codex security review |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
6ca50f4 to
2bf0d5f
Compare
b13d9c4 to
5d4d566
Compare
Expand the CoderTemplateTest how-to with a "Read the result" section that lists every status.reason the controller sets (waiting, failure, and WorkspaceDeleted condition reasons) with what to do, a ResourceQuota example to cap test count, and a nightly CronJob with the RBAC it needs. The existing notes on the tester, retain, TTL, keys, builds, and TLS stay as they were. Add troubleshooting entries for a test that stays Pending, a test that does not finish deleting (finalizer), and a namespace stuck Terminating because of the aggregated API LIST bug (#209). Add a sample manifest (validated with a server-side dry run against the CRD in envtest) and list CoderTemplateTest among the operator kinds in the README. Refs #152 Signed-off-by: Thomas Kosiewski <tk@coder.com> --- _Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_ Change-Id: I0af2782b45a458869b2a1840611682a600cf06a3
The last-resort patch in troubleshooting now removes only coder.com/template-test-cleanup, guarded by a JSON Patch test operation, instead of the whole finalizer list. A missing or empty operator token Secret is listed under OperatorAccessNotReady, as the controller reports it. Readiness claims now say top-level agents, because the controller skips devcontainer sub-agents. Refs #152 Signed-off-by: Thomas Kosiewski <tk@coder.com> --- _Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_ Change-Id: I4cef0bfae938870169b3f18b00b1607662ee8584
NoAgents means that the workspace has no top-level agents: the controller ignores devcontainer sub-agents, so the row and the sample now ask for a top-level agent. The nightly CronJob sets backoffLimit 0, because a retry after a lost create response makes a second test with generateName. Refs #152 Signed-off-by: Thomas Kosiewski <tk@coder.com> --- _Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_ Change-Id: I1a43ba8c48730e461c27b9120cc77f7aee236ee9
…the first reconcile WorkspaceNameConflict has two outcomes. With WorkspaceDeleted NotCreated, the test never created a workspace and releases its finalizer by itself, so the workspace belongs to someone else. Only OwnershipUnknown needs the escape hatch. The troubleshooting page now says that the first reconcile only adds the finalizer and the next one writes the status, and shows how to tell the two cases apart. Refs #152 Signed-off-by: Thomas Kosiewski <tk@coder.com> --- _Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_ Change-Id: I4c6ec127bba9a3b078a6729d469518b626f92124
5d4d566 to
7be4853
Compare
|
@codex review |
|
@codex security review |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Summary
Plan PR 8b of the
CoderTemplateTeststack (Refs #152): the complete how-to, troubleshooting, the sample, and the upgrade note from the #210 assessment. This is the last planned PR. The plan tags a release only after PR 8 lands.Based on
main. #211 and #212 landed, and I rebased this PR ontomain(head7be4853a). Its own diff is byte-identical to the reviewed diff of5d4d5669, so the commit SHAs in the review sections below are the pre-rebase ones.What
docs/how-to/test-templates.mdkeeps all the existing notes (🤖 Use the internal Coder URL for provisioner keys and the aggregated API when TLS is on #198 TLS facts, TTL scope, more than 100 builds, tester keys,retainandallowRetain, dormant tester) and adds:WorkspaceDeletedreasons, each with what to do. I took them all from the controller code.ResourceQuotaexample that caps tests per namespace withcount/codertemplatetests.coder.com, because each test is a real workspace,CronJobthat creates a test withgenerateNameand a TTL, with a Role that grants onlycreate.docs/how-to/troubleshooting.mdadds three sections:Pending,coder.com/template-test-cleanup),Terminating, the aggregated API bug 🤖 Namespace deletion hangs: the aggregated API answers LIST with 503 when the namespace has no control plane #209.config/samples/coder_v1alpha1_codertemplatetest.yaml, with prerequisites in comments like the other samples. I checked it with a server-side dry-run create in envtest: the CRD accepted it and rejected a copy with two version fields.CoderTemplateTest.docs/how-to/deploy-controller.md: applyconfig/crd/bases/andconfig/rbac/from the new version before or together with the new image. The operator watches every kind it reconciles, so a missingCoderTemplateTestCRD stops the manager from starting.Known limits
<an image with sh and kubectl>.default.docker. The sample usescoder.docker, because the default organization in the Kind E2E iscoder.Review round 1 (fixed in 6d0133d, rebased as a5742ac)
This PR is rebased onto the new head of #212, so the CI
docs-quality404 for thetree/main/config/gitopslink is gone.coder.com/template-test-cleanup, guarded by a JSON Patchtestoperation.OperatorAccessNotReady, as the controller reports it.Review round 2 (fixed in d824e17, rebased as b13b884)
This branch is rebased onto the round 3 head of #212.
NoAgentsnow says that the workspace has no top-level agents, and that devcontainer sub-agents do not count. The sample comment says "every top-level agent".backoffLimit: 0. A retry after a lost create response would make a second test, and a second workspace, because ofgenerateName.Review round 3 (fixed in 1b6f302)
WorkspaceNameConflictnow sends readers to theWorkspaceDeletedcondition.NotCreated(an existing workspace before the create, or HTTP 409) means that the test never created a workspace and releases its finalizer by itself. OnlyOwnershipUnknownpoints to the escape hatch.Validation
All on the pushed tree, with exit 0 each:
make verify-vendor,make test,make test-integration,make build,make lintmake codegen,make manifests,make docs-reference(no diff afterwards)go test -race ./internal/controller/...make docs-check, plus CI'smarkdownlint-cli2andcspellversionsLine count
Hand-written: 6 files changed, 247 insertions(+), 3 deletions(-) (no generated or vendored files).
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high