Sweeps the references that carry no runtime coupling, and fixes one that
turned out to be a real bug rather than stale branding.
Docker network: sentry_default -> cairnobs_default across 23 runbook and
test-header `docker run` commands. Compose derives the network from the
directory name, so this lands together with renaming the working copy to
cairnobs/ -- the two are only correct as one change.
Stale references corrected: four Dockerfile "repo root (sentry/)"
headers; .env pointing at the long-renamed deploy/helm/sentry/ chart;
five Helm comments describing the topic as sentry.logs.raw when all four
code paths have defaulted to cairnobs.logs.raw for some time; an
absolute /home/john/Projects/sentry/ path in the operator's package doc,
now repo-relative; the hand-written Tenant CRD description in both of
its identical copies, whose Go source already said Cairn OBS.
Migration 0043 repoints the default tenant's data source. 0026 seeded it
with ('sentry', '/var/lib/sentry-search') to match what
api/internal/config then defaulted to; the rebrand later moved those
defaults to "cairnobs" and /var/lib/cairnobs-search without moving the
already-applied row, leaving the default tenant naming a ClickHouse
database nothing writes to. Scoped to the exact stale values so it is a
no-op on any deployment that set them deliberately. 0026's comment is
annotated as superseded; its applied SQL is untouched.
Deliberately not included: the gRPC wire packages (sentry.logs.v1,
sentry.agent.v1) and proto/sentry/ import paths, which cannot change
without a lockstep agent/server upgrade; the Helm chart's
sentry_metadata database and sentry role, which need a real Postgres
migration on existing deployments; and the compliance audit records in
docs/compliance/, which are a dated historical record.
go build, go vet, and go test pass for ingest and deploy/operator.
deploy/operator
A small controller-runtime Operator managing one CRD: Tenant
(cairnobs.io/v1alpha1). See internal/controller/tenant_controller.go's
doc comment for exactly what it reconciles and -- just as importantly --
what it deliberately doesn't (no ClickHouse calls, no Tantivy filesystem
access, no enterprise/internal/rbacstore wiring; those are
enterprise/internal/tenantprovision, still unbuilt).
Not kubebuilder-scaffolded
No kubebuilder/controller-gen binary was available in this
environment, so this package is hand-written rather than generated:
api/v1alpha1/zz_generated.deepcopy.go-- normallycontroller-gen objectoutput; hand-written here, covered byapi/v1alpha1/api_test.go's round-trip tests (mutate a copy, assert the original is untouched -- exactly the class of bug a hand-writtenDeepCopyis prone to).config/crd/cairnobs.io_tenants.yaml-- normallycontroller-gen crdoutput from the+kubebuilder:validation:*markers onapi/v1alpha1/tenant_types.go; hand-written here and only as strong as keeping the two in sync by hand. Validated by strict-unmarshaling it into the realk8s.io/apiextensions-apiserverGo type (see/deploy/README.md's verification section) -- catches YAML/structural mistakes, not a drift between the CRD's field descriptions and the Go doc comments.+kubebuilder:rbacmarkers oninternal/controller/tenant_controller.goare present as documentation/intent (matching kubebuilder convention) but were never run throughcontroller-gen rbac-- the actual ClusterRole is hand-written in/deploy/helm/cairnobs/templates/tenant-operator.yaml, kept in sync with those markers by hand, same caveat as the CRD above.
Layout
api/v1alpha1/ Tenant, TenantSpec, TenantStatus -- the CRD's Go types
internal/controller/ TenantReconciler -- see its doc comment
cmd/tenant-operator/ main.go -- manager setup, matches every other
service's cmd/<name>/main.go convention in this repo
config/crd/ hand-written CRD YAML (see above)
Building & testing
go build ./...
go vet ./...
go test ./...
Tests use sigs.k8s.io/controller-runtime/pkg/client/fake, not
envtest -- envtest needs a real kube-apiserver/etcd binary pair
(setup-envtest) not available in this environment. The fake client
exercises real reconcile logic (object CRUD, owner references, status
writes) but not anything a real apiserver does for you (admission,
garbage collection, watch-triggered re-reconciliation) -- see
internal/controller/tenant_controller_test.go's doc comment.
docker build -f Dockerfile -t cairnobs-tenant-operator . # context is deploy/operator/, not the repo root
Not verified in this session -- see /deploy/README.md.
Trying it against a real cluster
kubectl apply -f config/crd/cairnobs.io_tenants.yaml
kubectl apply -f - <<'EOF'
apiVersion: cairnobs.io/v1alpha1
kind: Tenant
metadata:
name: acme
spec:
displayName: "Acme Corp"
EOF
kubectl get tenant acme -o yaml # status.phase should reach Active
kubectl get secret cairnobs-tenant-acme-clickhouse -o yaml