Files
cairnobs/deploy/operator
jcoffey-dev 7a86008062 Complete the low-risk half of the Sentry -> Cairn OBS rebrand
Sweeps the references that carry no runtime coupling, and fixes one that
turned out to be a real bug rather than stale branding.

Docker network: sentry_default -> cairnobs_default across 23 runbook and
test-header `docker run` commands. Compose derives the network from the
directory name, so this lands together with renaming the working copy to
cairnobs/ -- the two are only correct as one change.

Stale references corrected: four Dockerfile "repo root (sentry/)"
headers; .env pointing at the long-renamed deploy/helm/sentry/ chart;
five Helm comments describing the topic as sentry.logs.raw when all four
code paths have defaulted to cairnobs.logs.raw for some time; an
absolute /home/john/Projects/sentry/ path in the operator's package doc,
now repo-relative; the hand-written Tenant CRD description in both of
its identical copies, whose Go source already said Cairn OBS.

Migration 0043 repoints the default tenant's data source. 0026 seeded it
with ('sentry', '/var/lib/sentry-search') to match what
api/internal/config then defaulted to; the rebrand later moved those
defaults to "cairnobs" and /var/lib/cairnobs-search without moving the
already-applied row, leaving the default tenant naming a ClickHouse
database nothing writes to. Scoped to the exact stale values so it is a
no-op on any deployment that set them deliberately. 0026's comment is
annotated as superseded; its applied SQL is untouched.

Deliberately not included: the gRPC wire packages (sentry.logs.v1,
sentry.agent.v1) and proto/sentry/ import paths, which cannot change
without a lockstep agent/server upgrade; the Helm chart's
sentry_metadata database and sentry role, which need a real Postgres
migration on existing deployments; and the compliance audit records in
docs/compliance/, which are a dated historical record.

go build, go vet, and go test pass for ingest and deploy/operator.
2026-08-22 18:39:25 -07:00
..
2026-08-21 20:53:32 -07:00
2026-08-21 20:53:32 -07:00
2026-08-21 20:53:32 -07:00

deploy/operator

A small controller-runtime Operator managing one CRD: Tenant (cairnobs.io/v1alpha1). See internal/controller/tenant_controller.go's doc comment for exactly what it reconciles and -- just as importantly -- what it deliberately doesn't (no ClickHouse calls, no Tantivy filesystem access, no enterprise/internal/rbacstore wiring; those are enterprise/internal/tenantprovision, still unbuilt).

Not kubebuilder-scaffolded

No kubebuilder/controller-gen binary was available in this environment, so this package is hand-written rather than generated:

  • api/v1alpha1/zz_generated.deepcopy.go -- normally controller-gen object output; hand-written here, covered by api/v1alpha1/api_test.go's round-trip tests (mutate a copy, assert the original is untouched -- exactly the class of bug a hand-written DeepCopy is prone to).
  • config/crd/cairnobs.io_tenants.yaml -- normally controller-gen crd output from the +kubebuilder:validation:* markers on api/v1alpha1/tenant_types.go; hand-written here and only as strong as keeping the two in sync by hand. Validated by strict-unmarshaling it into the real k8s.io/apiextensions-apiserver Go type (see /deploy/README.md's verification section) -- catches YAML/structural mistakes, not a drift between the CRD's field descriptions and the Go doc comments.
  • +kubebuilder:rbac markers on internal/controller/tenant_controller.go are present as documentation/intent (matching kubebuilder convention) but were never run through controller-gen rbac -- the actual ClusterRole is hand-written in /deploy/helm/cairnobs/templates/tenant-operator.yaml, kept in sync with those markers by hand, same caveat as the CRD above.

Layout

api/v1alpha1/          Tenant, TenantSpec, TenantStatus -- the CRD's Go types
internal/controller/    TenantReconciler -- see its doc comment
cmd/tenant-operator/     main.go -- manager setup, matches every other
                         service's cmd/<name>/main.go convention in this repo
config/crd/               hand-written CRD YAML (see above)

Building & testing

go build ./...
go vet ./...
go test ./...

Tests use sigs.k8s.io/controller-runtime/pkg/client/fake, not envtest -- envtest needs a real kube-apiserver/etcd binary pair (setup-envtest) not available in this environment. The fake client exercises real reconcile logic (object CRUD, owner references, status writes) but not anything a real apiserver does for you (admission, garbage collection, watch-triggered re-reconciliation) -- see internal/controller/tenant_controller_test.go's doc comment.

docker build -f Dockerfile -t cairnobs-tenant-operator .   # context is deploy/operator/, not the repo root

Not verified in this session -- see /deploy/README.md.

Trying it against a real cluster

kubectl apply -f config/crd/cairnobs.io_tenants.yaml
kubectl apply -f - <<'EOF'
apiVersion: cairnobs.io/v1alpha1
kind: Tenant
metadata:
  name: acme
spec:
  displayName: "Acme Corp"
EOF
kubectl get tenant acme -o yaml   # status.phase should reach Active
kubectl get secret cairnobs-tenant-acme-clickhouse -o yaml