classify nested Kanidm groups by the group list, not HTTP status (#166 hotfix) #172
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!172
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/166-group-classification"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Hotfix for a regression in #167 (the nested-group expansion, merged as #167). Applied to prod already (kofish was zero-quota'd — see below); this PR brings main in line with what's running.
Bug: #167 classified a
memberentry as group-vs-person by whetherGET /api/v1/admin/.../v1/group/<name>returned 2xx (group) or 404 (person). But Kanidm returns HTTP 200 for a person too (with nogroupclass). So every person was misclassified as a group and expanded to nothing → all tier resolution collapsed to the fail-closedparticipantgroup:kofishdropped from lfs-xl → participant (zero quota)alexanderkjallstayed participant; the wholetier_procohort lost lfs-pro / org-create / actions.Fix: fetch the authoritative group-name set once from
GET /v1/groupand classify a member as a nested group iff its name is in that set; everything else is a person. Abort on a failed group-list read (never strip entitlements on a transient error). Removes the unreliablekd_code2xx/404 probe.Verified on prod after apply (reconciler run 14:41:47Z):
Plus a mocked-topology logic test (nested/direct/participant) and ansible-lint clean. Refs #166.