expand nested Kanidm entitlement groups (#166) #167
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!167
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/166-nested-group-expansion"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Fixes #166. The entitlement taxonomy (ADR 0016) nests a tier group INTO the ent_* groups it grants (
ent_lfs.member=[tier_pro], etc.) and relies on transitive memberOf. The reconciler'smembers()read.attrs.member— direct members only — soent_lfsresolved to the stringtier_pro, never its persons, and every tier_pro user matched no entitlement and fell through to the fail-closedparticipantgroup (#125): Pro seats got zero quota, no org-create, no Actions. Surfaced live during the #125 apply (alexanderkjall→ participant despite renovate cap 100 = tier_pro).Fix:
members()recurses into any member that is itself a group (via akd_codegroup-vs-person probe), with a cycle guard; pipefail propagates a Kanidm read error through the sort so the never-strip-on-failure contract holds.Verified: mocked-topology unit test — nested (
ent_lfs → alice,bob), mixed direct+nested (ent_orgs → alice,bob,carol), cycle (no hang), direct. Rendered +bash -n+ ansible-lint clean.⚠️ Touches
gitborg-reconciler.sh.j2(members() region) — #37 touches the org-loop region of the same file; whichever merges second rebases. After apply, verify a tier_pro user resolves tolfs=lfs-pro org_create=true actions=true(dry-run + journal).