Share one Temporal ClusterConnection - #1197
Merged
Merged
Conversation
order and checkout each carried an identical namespaced Connection to the same frontend. Worker Controller 1.10 added ClusterConnection, so one cluster-wide temporal-mop (configs/temporal) replaces both, and the WorkerDeployments reference it through connectionRef.objectRef. make validate now checks that reference and rejects a namespaced Connection beside a worker. The community catalog's WorkerDeployment schema predates objectRef and rejects the new reference, so the two CRs validate against vendored schemas generated from the pinned CRDs chart, made strict the way the catalog's generator does.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The owner asked for this adoption, which Worker Controller 1.10+ makes possible (#1194). The
orderandcheckoutnamespaces each carried an identical namespacedConnectiontemporal-mop, pointing at the same frontend. A single cluster-scopedClusterConnectiontemporal-mopnow replaces both.ClusterConnectiontemporal-mop(hostPort: temporal-frontend.temporal.svc.cluster.local:7233), applied bytemporal-config-local, whichapps-localalready dependsOnkubernetes/infra/configs/temporal/clusterconnection.yaml,kustomization.yamlconnectionRef.objectRef {apiGroup: temporal.io, kind: ClusterConnection, name: temporal-mop}; the namespacedConnections are deletedkubernetes/apps/{order,checkout}-worker.yamlmake validateguard now requires the ref to name the ClusterConnection and rejects a namespacedConnectionbeside a workerscripts/flux-validate.shWorkerDeploymentandClusterConnection, generated from the pinned CRDs chart 0.31.0 and read before the datree catalog. The catalog's copy predatesobjectRefand rejected the correct reference (additional properties 'objectRef' not allowed).generate.pyaddsadditionalProperties: falsethe way the catalog's generator does, plus regeneration stepsscripts/kubeconform-schemas/docs/api/temporal.md,docs/platform/{setup,application-delivery}.mdRFC-0020 note: once Temporal gets mTLS, the client Secret still has to live in each worker namespace, because a pod mounts only its own Secrets. A
ClusterConnectionremoves the duplicated address, not the per-namespace credential. This is recorded in the manifest header.Negative checks (local)
connectionRef.objectRef.nmaefailsmake validate(strict vendored schema).Connectionappended toorder-worker.yamlfails withexpected a WorkerDeployment and no namespaced Connection.Verified on Kind (branch overlay via
make flux-push)ClusterConnection temporal-mopwas created and carries thetemporal.io/delete-protectionfinalizer.Connections were pruned.kubectl get connections.temporal.io -Areturns no resources, so no finalizer was left behind.ConnectionHealthy=True, Ready=True, RolloutComplete=True.2.10.2-8d45/0.13.2-f678, and the same Deployments are 1/1. The connection ref is not part of the pod template.make e2e-saga GATE=kind: SG.1–SG.4 PASS.make validatepasses.