classify nested Kanidm groups by the group list, not HTTP status (#166 hotfix) #172

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/166-group-classification in i main 2026-07-20 14:46:55 +00:00
Ägare

Hotfix for a regression in #167 (the nested-group expansion, merged as #167). Applied to prod already (kofish was zero-quota'd — see below); this PR brings main in line with what's running.

Bug: #167 classified a member entry as group-vs-person by whether GET /api/v1/admin/.../v1/group/<name> returned 2xx (group) or 404 (person). But Kanidm returns HTTP 200 for a person too (with no group class). So every person was misclassified as a group and expanded to nothing → all tier resolution collapsed to the fail-closed participant group:

  • kofish dropped from lfs-xl → participant (zero quota)
  • alexanderkjall stayed participant; the whole tier_pro cohort lost lfs-pro / org-create / actions.

Fix: fetch the authoritative group-name set once from GET /v1/group and classify a member as a nested group iff its name is in that set; everything else is a person. Abort on a failed group-list read (never strip entitlements on a transient error). Removes the unreliable kd_code 2xx/404 probe.

Verified on prod after apply (reconciler run 14:41:47Z):

alexanderkjall: lfs=lfs-pro  org_create=true actions=true (cap 100)   # tier_pro → ent_lfs
kofish:         lfs=lfs-xl   org_create=true actions=true (cap 100)   # ent_lfs_large
supernaut:      lfs=org-unlimited                                     # exempt

Plus a mocked-topology logic test (nested/direct/participant) and ansible-lint clean. Refs #166.

**Hotfix for a regression in #167** (the nested-group expansion, merged as #167). Applied to prod already (kofish was zero-quota'd — see below); this PR brings main in line with what's running. **Bug:** #167 classified a `member` entry as group-vs-person by whether `GET /api/v1/admin/.../v1/group/<name>` returned 2xx (group) or 404 (person). But **Kanidm returns HTTP 200 for a person too** (with no `group` class). So every person was misclassified as a group and expanded to nothing → all tier resolution collapsed to the fail-closed `participant` group: - `kofish` dropped from **lfs-xl → participant (zero quota)** - `alexanderkjall` stayed participant; the whole `tier_pro` cohort lost lfs-pro / org-create / actions. **Fix:** fetch the authoritative group-name set once from `GET /v1/group` and classify a member as a nested group iff its name is in that set; everything else is a person. Abort on a failed group-list read (never strip entitlements on a transient error). Removes the unreliable `kd_code` 2xx/404 probe. **Verified on prod after apply** (reconciler run 14:41:47Z): ``` alexanderkjall: lfs=lfs-pro org_create=true actions=true (cap 100) # tier_pro → ent_lfs kofish: lfs=lfs-xl org_create=true actions=true (cap 100) # ent_lfs_large supernaut: lfs=org-unlimited # exempt ``` Plus a mocked-topology logic test (nested/direct/participant) and ansible-lint clean. Refs #166.
supernaut lade till 1 incheckning 2026-07-20 14:43:34 +00:00
fix(reconciler): classify nested groups by the Kanidm group list, not HTTP status (#166)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m27s
2b5cab427a
The #166 fix used GET /v1/group/<name> returning 2xx to mean "group" and 404
to mean "person". But Kanidm returns HTTP 200 for a PERSON too (with no group
class), so every person was misclassified as a group and expanded to nothing —
regressing ALL tier resolution to the fail-closed participant group (e.g. kofish
dropped from lfs-xl to zero quota; tier_pro users lost lfs-pro/org-create/actions).

Fetch the authoritative group-name set once from GET /v1/group and classify a
member as a nested group iff its name is in that set; everything else is a
person. Abort on a failed group-list read (never strip on a transient error).
Verified against the live topology: ent_lfs → {kofish,supernaut,alexanderkjall}
via tier_pro, ent_lfs_large → {kofish}. Refs #166.
supernaut sammanfogade incheckning ba6ec8a1d9 till main 2026-07-20 14:46:55 +00:00
supernaut tog bort grenen fix/166-group-classification 2026-07-20 14:46:56 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!172
Ingen beskrivning angiven.