Skip to content

deps: bump k8s.io/apimachinery from 0.30.2 to 0.33.1 - #3

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/k8s.io/apimachinery-0.33.1
Closed

deps: bump k8s.io/apimachinery from 0.30.2 to 0.33.1#3
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/k8s.io/apimachinery-0.33.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 7, 2025

Copy link
Copy Markdown
Contributor

Bumps k8s.io/apimachinery from 0.30.2 to 0.33.1.

Commits
  • 173776a Merge pull request #131708tigrato/automated-cherry-pick-of-#131702
  • a3d1fde fix: fixes a possible panic in NewYAMLToJSONDecoder
  • 955939f bump etcd 3.5.21 sdk
  • e8a77bd Merge pull request #130910 from googs1025/fix/datarace
  • 7e8c77e Merge pull request #130906 from serathius/streaming-validation
  • 27fd396 flake: fix data race for func TestBackoff_Step
  • 8bcc6f1 Update kube-openapi and integrate streaming tags validation
  • 6ce776c Merge pull request #130857 from thockin/kk_small_vg_diffs
  • f2c94d6 Comment on origin and JSON schema
  • b63ba07 Use origin in validateFalse's own test
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot @github

dependabot Bot commented on behalf of github Jun 7, 2025

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automerge, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s.io/apimachinery-0.33.1 branch from 81f2c50 to c68e805 Compare June 8, 2025 05:48
Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.30.2 to 0.33.1.
- [Commits](kubernetes/apimachinery@v0.30.2...v0.33.1)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.33.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s.io/apimachinery-0.33.1 branch from c68e805 to 87b8b16 Compare June 11, 2025 05:54
@dependabot @github

dependabot Bot commented on behalf of github Jun 11, 2025

Copy link
Copy Markdown
Contributor Author

Looks like k8s.io/apimachinery is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 11, 2025
@dependabot
dependabot Bot deleted the dependabot/go_modules/k8s.io/apimachinery-0.33.1 branch June 11, 2025 06:35
jingle2008 added a commit that referenced this pull request May 17, 2026
#1 (cli/get): runGet was hard-coding "console" / "" log options,
   ignoring log_format/log_level from config and flags. Call the
   same logOptionsFromViper() the TUI path uses so `log_format:
   json` actually produces JSON logs in get.

#3 (terraform/getVariableDefaults): silently dropped any variable
   whose default expression can't evaluate with a nil context
   (functions, var/local/data refs). Add a Debugw entry so users
   tracing unresolved refs can see the default existed but couldn't
   be reduced.

#4 (cli/validateGetConfig): the --kubeconfig empty-string check was
   effectively dead because the persistent flag default populates
   it from ~/.kube/config. Stat the file when the category requires
   it (BaseModel/GpuNode/DAC) so we fail fast with a clear message
   instead of a deep client-go error.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 17, 2026
#1 (go.mod/go.sum): `go mod tidy` moved
   github.com/modelcontextprotocol/go-sdk out of the //indirect block.
   It's a direct import from internal/mcp/server.go.

#2 (internal/mcp/server.go:Run): document blocking semantics, EOF /
   ctx-cancel exit conditions, and the single-shot constraint
   (a second Run on the same Server reuses the SDK's session list).

#3 (internal/cli): extract validateLoaderConfig out of validateGetConfig
   so runMCP shares the four-field env check. Both surfaces now report
   "missing required setting(s): ..." with consistent wording. Kept
   the kubeconfig stat in validateGetConfig — only get needs it.

#4 (internal/cli/output/output.go): document FlattenWithKey's
   collision rule. If T's JSON encoding contains a field named
   groupField, the map key wins and the original value is silently
   overwritten. Currently safe (pool/tenant/model don't collide with
   any pkg/models tag), but locked in writing for future-proofing.

#5 (internal/cli/output/output_test.go): add direct tests for
   FlattenWithKey covering nil/empty maps, single entry, sort
   stability across multiple groups, omitempty respected, and the
   collision-overwrite contract from #4.

Outstanding from the latest review: an in-memory MCP integration
test for the JSON-RPC framing path (#6). Coming next in a separate
commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 18, 2026
Review item #3: three of seven MCP mutation handlers had 0% execution
coverage on the confirm=true path (handleRebootNode, handleScaleGpuPool,
handleDeleteDAC). Only the cordon variants were exercised.

To test scale_gpu_pool cleanly without a fake k8s + OCI pipeline,
introduce mcp-level resolver seams (mcpResolveGpuNodeFn,
mcpResolveGpuPoolFn) that default to internal/resolve. Tests swap
them for stub functions; production still routes through the
shared resolver. The lookup-and-enrich chain itself remains covered
once in internal/resolve.

Four new tests:
  - RebootTool ConfirmTrueExecutes (with --ocid bypass)
  - ScaleGpuPoolTool ConfirmTrueExecutes (resolver stub returns
    a populated pool; IncreasePoolSize receives it)
  - ScaleGpuPoolTool ResolverError (returns IsError)
  - DeleteDACTool ConfirmTrueExecutes (DAC stub passed through)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 18, 2026
Addresses the second round of review feedback.

Important #1 — env_override is now an explicit opt-in:

  - New config field MutationEnvOverrideAllowed (default false) with
    matching --mutation_env_override_allowed persistent flag.
  - effectiveMutationEnv applies the agent's envOverride only when
    the operator opted in; otherwise the override is silently dropped
    AND audit-logged at info, preserving "operator's startup-env
    choice caps blast radius" as the safety story.
  - When the override IS applied AND deviates from startup, an
    info-level "level=warn" audit line records the deviation for
    SIEM visibility.
  - Tool descriptions now honestly describe the trade-off via a
    central mutationToolFooter constant. The previous "parity with
    list_*" framing understated the security cost; the new shape
    keeps the parity benefit (multi-realm operators can opt in)
    without the silent capability expansion.

Important #2 — failed-phase event name unified:
  - Both CLI mutate.go and MCP mutations.go now emit Errorw with
    event="mutation", phase="failed". Aggregators filtering on a
    single `phase` discriminator now capture all four states
    (begin / done / failed / refused).

Important #3 — env_override propagation coverage:
  - TestIntegration_MutationTool_IgnoresEnvOverride_WhenDisallowed:
    default config drops the agent's env_realm/env_region.
  - TestIntegration_MutationTool_HonorsEnvOverride_WhenAllowed:
    flag-set config honors override (renamed from prior test).
  - TestIntegration_MutationTool_PropagatesEnvOverride:
    reboot/terminate/scale all assert env reaches BOTH the resolver
    seam and the action seam — the hops where a future refactor
    could accidentally drop the override.

Minors:
  - #4: gofmt double blank line in mutate.go (mutations_test.go and
    tools.go also picked up trailing-whitespace fixes from the same
    pass).
  - #5: mutationToolFooter centralizes the env-override clause so
    drift across the seven descriptions is not possible.
  - #7: drop the resolveNodeForOCIAction / resolveGpuPoolForOCIAction
    methods — they were pure passthroughs after the prior commit. The
    handlers now call mcpResolveGpuNodeFn / mcpResolveGpuPoolFn
    directly.

newTestPair now accepts a variadic config-mutator option so tests
that need to flip the flag don't have to fork the helper.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 20, 2026
Three Important + three Minor follow-ups from the post-commit review:

Important #1 — MCP integration test for enrichment failure:
- New TestIntegration_NotifiesOnGpuPoolEnrichmentFailure (and a tiny
  fixedGpuPoolsLoader helper) drives list_gpu_pools against a
  non-empty stub loader with KubeConfig pointed at a missing file.
  Asserts: tool call succeeds (IsError=false), Terraform-derived pool
  still rendered with placeholder status, enrichment warning appears
  in BOTH the StructuredContent.warnings envelope AND as a
  notifications/message frame. Was a real coverage gap — previous
  partial-load integration test returned nil pools, taking
  EnrichGpuPools's empty-slice fast-path.

Important #2 — GpuPool JSON shape pin-test:
- New TestWriteSlice_GpuPool_JSONShape asserts every key on the
  rendered object uses the lowercase JSON tags introduced in v0.3.0
  (name / shape / actualSize / status / capacityType / …) and that no
  capitalized struct-field name leaks. The CHANGELOG claimed
  shape-unchanged; this test backs that claim.

Important #3 — Structured log for enrichment failures:
- EnrichGpuPools now emits a logger.Infow line at each failure point
  with `step=compartment_id|populate` plus the error, matching the
  Infow pattern resolve.GpuPool already uses for partial-load.
  Long-running MCP servers degrade visibly in logs instead of only
  via tool output. Logger interface has no Warnw — using Infow stays
  consistent with the existing partial-load log shape.

Minor #4 — CHANGELOG calls out the NONEXIST status:
- A Terraform-defined pool that hasn't been applied yet now shows
  `status: "NONEXIST"` after enrichment (the literal value
  PopulateGpuPools writes when OCI returns 200 but excludes the pool
  from its result). Same as TUI behavior; just wasn't documented for
  CLI/MCP consumers.

Minor #7 — CHANGELOG calls out the offline-experience change:
- `toolkit get gpupool` was previously offline-capable; one K8s
  lookup attempt is now made before any output renders. Added a
  sentence explaining the new latency on no-auth hosts.

Minor #8 — CLI warning prefix symmetry:
- Partial-Terraform failures previously printed `warning: <err>`;
  enrichment failures print `warning: gpu pool enrichment
  incomplete: <err>`. Both are now prefixed by their step
  (`warning: load gpu pools: ...` vs `warning: gpu pool enrichment
  incomplete: ...`) so a reader can tell at a glance which one fired.

Skipped from the review's Minor list:
- #5 (string→error return type for EnrichGpuPools) — pure style call,
  current shape reads cleanly at both call sites; defer to a future
  pass if/when call sites grow.
- #6 (categorized warnings field) — would require restructuring the
  warnings array into typed entries (Terraform vs enrichment). Bigger
  surface change than this review warrants.

Verified: go test ./..., make fmt-check, make goimports-check,
golangci-lint run ./... all green.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 24, 2026
Code-review follow-up to the four-commit ImportedModel feature
(02fdba7 .. 2c1090e). All review feedback addressed:

Important #1 — MCP description claimed a `source` field that was
dropped in 0d194ae. Replaced with the orthogonality guidance the Go
doc and CHANGELOG now use. Agents planning JSON paths against the
tool description will no longer be misled.

Important #2 — CHANGELOG was missing the silent BaseModel filter
change (02fdba7). Added a `### Changed` entry explicit about the
count delta — `toolkit get basemodel -o json | jq length` returns
fewer items on clusters with tenant-scoped CBMs. Points readers at
the new `importedmodel` category to recover the full set.

Important #3 — Confirmed via inventory of pkg/models that
ImportedModel is the only category with both Namespace and TenantID
(DAC, LimitTenancyOverride, ConsolePropertyTenancyOverride each
have TenantID alone). Adopting the DAC pattern: TenantID is the OCI
tenant identifier (from `tenancy-id` label, populated on any source
that carries the label); Namespace is the K8s scope (the
authoritative source-kind indicator). They're orthogonal facets,
not synonyms. Loader behavior unchanged — only documentation flips,
in three places:

  - pkg/models/imported_model.go: expanded doc-comment with the
    "orthogonal facets" framing and explicit consumer guidance
    ("which K8s scope" vs "which OCI tenant").
  - internal/mcp/tools.go (list_imported_models description): same
    clarification, replacing the stale `source` mention.
  - CHANGELOG: same framing, with the DAC-pattern reference.

Important #4 — Added a deliberate comment in LoadImportedModels
explaining the all-or-nothing semantics vs. the LoadGpuPools
partial-error idiom. The two sources here are conceptually one
catalog; a half-loaded result is more confusing than an explicit
error, and the cross-GVR RBAC asymmetry (namespaced `basemodels`
vs cluster-scoped `clusterbasemodels`) is the realistic failure
mode the comment calls out.

Minor #5 — TestList_ImportedModels_FlatShape doc-comment said the
test asserts `source` is present; corrected to reflect that the
test now asserts `source` is absent (the post-0d194ae contract).

Skipped from the review's Minor list:
- #6 (lint suppression placement) — pre-existing, no change.
- #7 (split routeLoadingDataMsg following the routeList* pattern) —
  could land in a follow-up if the next addition pushes the message
  count above the cyclop ceiling again; not urgent at 10.
- #8 (ResetScopedData consistency) — already correct.
- #9 (StorageURI placement on BaseModel vs ImportedModel) — already
  the right call, no change.
- #10 (CLI table readability) — passed review.

Verified: go test ./..., make fmt-check, make goimports-check,
golangci-lint run ./... all green.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 24, 2026
Review follow-ups for 74723fd:

Important #1 — Harmonize the orphan-tenant sentinel across DAC and
ImportedModel. DAC's V1/V2 extractors previously branched on
hasLabels and defaulted to the literal "missing" — different from
the "UNKNOWN_TENANCY" sentinel ImportedModel and tenantIDFromLabels
already use for the labels-present-but-no-tenancy-id case.
tenantIDFromLabels(nil) already returns "UNKNOWN_TENANCY", so
calling it unconditionally collapses the two sentinels into one
and matches the policy the user picked ("same convention as DAC").
The dead-`hasLabels` variables are tagged with `_ = hasLabels` to
keep the surrounding signatures unchanged.

As a follow-on, the now-redundant tenantIDFromUnstructured wrapper
in imported_model.go is inlined — its only purpose was to bridge
the "labels absent" case, which tenantIDFromLabels(labels) handles
identically. One less abstraction, one less typo surface.

Important #2 — TestSetImportedModelMap added, mirroring
TestSetDedicatedAIClusterMap line-for-line. Covers both the
matched-by-suffix path (re-keys to Tenant.Name, sets Owner pointer)
and the unmatched path (key passes through, Owner stays nil). A
small generic `keys[V any]` helper feeds the diagnostic Errorf
message.

Important #3 — TestResetScopedData now seeds ImportedModelMap and
asserts it's nil after Reset. Production code (dataset.go:78)
already resets it; this test pins the contract so a future drop
of the reset line fails fast.

Important #4 — CHANGELOG TUI column claim corrected to the
shipped order: Name, Tenant, Namespace, Display Name, Version,
DAC Shape, Flags, Status. The previous text described an
in-development layout that didn't match the final headers.go
definition. Also added a sentence on the CLI/TUI tenant-column
asymmetry (CLI shows raw OCID, TUI shows resolved Tenant.Name
via SetImportedModelMap) — same as DAC's behavior, but never
documented before.

Skipped from the review's Minor list (filed for follow-up):
- #5 (UNKNOWN_TENANCY as a `const`): three sites now share the
  same literal via tenantIDFromLabels; extracting a const is a
  micro-cleanup that's strictly post-release.
- #7 (suffix-match bug in SetXxxMap): pre-existing in DAC, not
  introduced by this work — separate fix.

Verified: go test ./..., make fmt-check, make goimports-check,
golangci-lint run ./... all green.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request Jun 23, 2026
…save

Resolves seven review findings across the TUI/CLI/config layers; each fix
is covered by a test that fails before the change.

- DAC delete (dac_actions.go): guard nil OpcRequestId in the delete error
  path via a new derefOr helper, and reject a nil work-request id in
  waitForWorkRequest instead of dereferencing/polling it; skip endpoint
  summaries with a nil DedicatedAiClusterId rather than panicking the whole
  deletion. [findings #2, #3]
- GPU pool enrichment (gpu_node_actions.go): skip instance-pool summaries
  missing DisplayName/Id/Size (extracted applyInstancePoolSummaries) so a
  partial OCI response can't crash get/list/scale. [finding #5]
- Lazy loading (model.go): add GPUWorkload to lazyLoadedCategories so
  `toolkit -c gpuworkload` issues the category load on direct startup. A
  contract test now asserts every kube-backed category is lazy-loaded.
  [finding #4]
- DAC delete timeout (model_state.go, update_list_ops.go): run the
  multi-minute deletion under a new uncapped longOpCtx instead of the 30s
  opCtx, so its own internal timeout governs. [finding #6]
- Atomic metadata save (metadata_save.go): writeFileAtomic writes a temp
  file, fsyncs, then renames, so an interrupted write can't corrupt the
  existing file. [finding #8]
- stderr sink (redirect_stderr_unix.go): 0644 -> 0600 to keep captured
  auth-plugin output and panic stacks private. [finding #7]

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request Jun 23, 2026
Approved design for review findings #3 (silent category drift) and #5
(overlapping load-message paths), scoped to drift-guards rather than a
structural descriptor rewrite:

- Collapse the dual load-path: trim handleDataMsg to its live foundational-load
  and refresh-signal roles, removing the dead per-category cases now served only
  by the typed *LoadedMsg handlers.
- Add per-package drift-guard tests across all partial dispatch planes (domain,
  tui, keys) so a future category that misses a plane fails a test instead of
  drifting silently. Predicate invariants where a domain truth exists,
  behavior-probes for switches, account-for-all tables for genuine UI choices.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request Jun 23, 2026
Category drift-guards + load-path consolidation (review findings #3, #5):
collapse handleDataMsg to its live roles and add drift-guard tests across the
tui/domain/keys dispatch planes so a future category that misses a plane fails
a test instead of drifting silently.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants