Skip to content

Share one Temporal ClusterConnection - #1197

Merged
duynhne merged 1 commit into
mainfrom
feat/temporal-clusterconnection
Oct 2, 2026
Merged

duynhne merged 1 commit into
mainfrom
feat/temporal-clusterconnection

Conversation

@duynhne

@duynhne duynhne commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

What

The owner asked for this adoption, which Worker Controller 1.10+ makes possible (#1194). The order and checkout namespaces each carried an identical namespaced Connection temporal-mop, pointing at the same frontend. A single cluster-scoped ClusterConnection temporal-mop now replaces both.

Change Where
New ClusterConnection temporal-mop (hostPort: temporal-frontend.temporal.svc.cluster.local:7233), applied by temporal-config-local, which apps-local already dependsOn kubernetes/infra/configs/temporal/clusterconnection.yaml, kustomization.yaml
Both WorkerDeployments: connectionRef.objectRef {apiGroup: temporal.io, kind: ClusterConnection, name: temporal-mop}; the namespaced Connections are deleted kubernetes/apps/{order,checkout}-worker.yaml
The make validate guard now requires the ref to name the ClusterConnection and rejects a namespaced Connection beside a worker scripts/flux-validate.sh
Vendored kubeconform schemas for WorkerDeployment and ClusterConnection, generated from the pinned CRDs chart 0.31.0 and read before the datree catalog. The catalog's copy predates objectRef and rejected the correct reference (additional properties 'objectRef' not allowed). generate.py adds additionalProperties: false the way the catalog's generator does, plus regeneration steps scripts/kubeconform-schemas/
Docs and CHANGELOG (Feature → Temporal) docs/api/temporal.md, docs/platform/{setup,application-delivery}.md

RFC-0020 note: once Temporal gets mTLS, the client Secret still has to live in each worker namespace, because a pod mounts only its own Secrets. A ClusterConnection removes the duplicated address, not the per-namespace credential. This is recorded in the manifest header.

Negative checks (local)

  • A misspelt connectionRef.objectRef.nmae fails make validate (strict vendored schema).
  • A namespaced Connection appended to order-worker.yaml fails with expected a WorkerDeployment and no namespaced Connection.

Verified on Kind (branch overlay via make flux-push)

  • ClusterConnection temporal-mop was created and carries the temporal.io/delete-protection finalizer.
  • Both old Connections were pruned. kubectl get connections.temporal.io -A returns no resources, so no finalizer was left behind.
  • Both WorkerDeployments are ConnectionHealthy=True, Ready=True, RolloutComplete=True.
  • No new version was minted: the current builds are still 2.10.2-8d45 / 0.13.2-f678, and the same Deployments are 1/1. The connection ref is not part of the pod template.
  • Both ScaledObjects are Ready.
  • make e2e-saga GATE=kind: SG.1–SG.4 PASS.

make validate passes.

order and checkout each carried an identical namespaced Connection to
the same frontend. Worker Controller 1.10 added ClusterConnection, so
one cluster-wide temporal-mop (configs/temporal) replaces both, and
the WorkerDeployments reference it through connectionRef.objectRef.

make validate now checks that reference and rejects a namespaced
Connection beside a worker. The community catalog's WorkerDeployment
schema predates objectRef and rejects the new reference, so the two
CRs validate against vendored schemas generated from the pinned CRDs
chart, made strict the way the catalog's generator does.
@duynhne
duynhne requested a review from duyhenryer as a code owner October 2, 2026 10:10
@duynhne
duynhne merged commit d55ba88 into main Oct 2, 2026
7 checks passed
@duynhne
duynhne deleted the feat/temporal-clusterconnection branch October 2, 2026 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant