Repository navigation
feat(racer): add controller and ClusterCache API - #869
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The deployment prerequisites omit the Kubernetes token capability required for bearer authentication, causing supported-looking older clusters to reject bootstrap requests.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds the standalone Racer controller, ClusterVolume API, wire protocol, deployment assets, packaging, and CI coverage.
Changes:
- Adds validated Racer wire contracts, canonical publications, deltas, membership, and keyrings.
- Adds ClusterVolume APIs and secure standalone Kubernetes deployment manifests.
- Adds controller build, test, envtest, image, and release automation.
| File | Description |
|---|---|
Makefile |
Adds Racer build, test, generation, and rendering targets. |
internal/racer/wire/vectors_test.go |
Tests shared wire vectors. |
internal/racer/wire/types.go |
Defines and validates wire types. |
internal/racer/wire/token_validation_test.go |
Tests strict token validation. |
internal/racer/wire/testdata/site-vectors.json |
Adds Site transition vectors. |
internal/racer/wire/testdata/rejections.json |
Adds rejection fixtures. |
internal/racer/wire/testdata/publication.json |
Adds publication fixture. |
internal/racer/wire/testdata/membership.json |
Adds membership fixture. |
internal/racer/wire/testdata/hashes.json |
Adds canonical hash fixture. |
internal/racer/wire/testdata/delta.json |
Adds delta fixture. |
internal/racer/wire/testdata/content.json |
Adds canonical content fixture. |
internal/racer/wire/testdata/bundle.json |
Adds keyring fixture. |
internal/racer/wire/testdata/bootstrap-response.json |
Adds bootstrap response fixture. |
internal/racer/wire/testdata/bootstrap-request.json |
Adds bootstrap request fixture. |
internal/racer/wire/site_vectors_test.go |
Tests shared Site vectors. |
internal/racer/wire/site_test.go |
Tests Site validation and deltas. |
internal/racer/wire/rdma_nics_test.go |
Tests RDMA NIC contracts. |
internal/racer/wire/delta_test.go |
Tests delta application. |
internal/racer/wire/codec.go |
Implements bounded strict codecs. |
internal/racer/wire/codec_test.go |
Tests bundle encoding and redaction. |
internal/racer/wire/canonical.go |
Implements canonicalization, hashes, and deltas. |
internal/racer/wire/canonical_test.go |
Tests canonical state ownership and bounds. |
internal/racer/wire/bootstrap_test.go |
Tests bootstrap size boundaries. |
internal/racer/wire/adversarial_test.go |
Adds malformed-input and fuzz coverage. |
internal/racer/volume_test.go |
Tests ClusterVolume reconciliation and admission. |
internal/racer/members/membership.go |
Builds membership and cache catalogs. |
internal/racer/members/membership_test.go |
Tests membership recovery and selection. |
images/racer-controller/Containerfile |
Packages the controller image. |
deploy/racer/security_test.go |
Tests rendered security controls. |
deploy/racer/rendered/.gitignore |
Excludes rendered manifests. |
deploy/racer/render_test.go |
Tests rendered deployment contracts. |
deploy/racer/README.md |
Documents standalone installation. |
deploy/racer/rbac.yaml.tmpl |
Defines controller RBAC. |
deploy/racer/installation.yaml.tmpl |
Defines installation state marker. |
deploy/racer/image_test.go |
Tests image metadata wiring. |
deploy/racer/embed.go |
Embeds rendered templates and CRDs. |
deploy/racer/embed_test.go |
Tests embedded manifest behavior. |
deploy/racer/dataplane-config.yaml.tmpl |
Supplies retained dataplane defaults. |
deploy/racer/create-restriction.yaml.tmpl |
Restricts runtime object creation. |
deploy/racer/crd/racer.unbounded-cloud.io_clustervolumes.yaml |
Defines the ClusterVolume CRD. |
deploy/racer/controller.yaml.tmpl |
Deploys controller replicas and Service. |
deploy/racer/config.yaml.tmpl |
Configures controller runtime settings. |
deploy/racer/bootstrap-trust.yaml.tmpl |
Optionally provisions bootstrap trust. |
cmd/racer-controller/README.md |
Documents controller operation. |
cmd/racer-controller/main.go |
Adds the controller entry point. |
cmd/racer-controller/main_test.go |
Tests CLI and startup logging. |
api/racer/v1alpha1/zz_generated.deepcopy.go |
Adds generated deep-copy methods. |
api/racer/v1alpha1/register.go |
Registers Racer API types. |
api/racer/v1alpha1/groupversion_info.go |
Configures API generation. |
api/racer/v1alpha1/clustervolume_types.go |
Defines ClusterVolume types. |
.github/workflows/release.yaml |
Publishes the controller image. |
.github/workflows/nightly.yaml |
Adds nightly image builds. |
.github/workflows/ci.yaml |
Adds Racer envtest CI. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
fceb746 to
bc52d94
Compare
Philip Lombardi (plombardi89)
left a comment
There was a problem hiding this comment.
Review at bc52d94, based on reading the non-test Go code, deploy templates, and build/CI changes (not run locally). Inline comments cover bugs first, then simplification candidates.
Bugs / correctness (highest impact first)
- Request cancellation during issuance withdraws trust for the whole replica (
authority/authentication.go). - 32 silent TCP connections block every new TLS handshake for 30s (
server/transport.go). - Every publication aborts in-flight snapshot writes; lagging clients may never complete a full download under churn (
authority/publications.go). - Conflicts requeue at 10ms with no backoff, and a stale-cache Node patch conflict restarts the whole publish (
reconcilers.go). - The default
installation.yamlrender cannot be applied to a new or existing install (installation.yaml.tmpl). - Delta selection matches content hash but not sequence (
authority/publications.go).
Simplification candidates
- Unstaged initialization protocol and compatibility code for formats that no earlier version in this repo produced.
- Operator-only code with no non-test caller in this PR (workload builder,
deploy/racer/embed.go, dataplane templates). - Code duplicated between
internal/racer,authority, andserver;frozenConfig; test-only reimplementation of the reconcilers shaping production code. - Write authorization via
context.Contexttype assertions. - Custom TLS listener and certificate reloader.
Nits (no inline anchor)
controller.go:190caches every ConfigMap in the namespace, though only two are watched. A field selector like the Secret one would do.controller.go:181-182:LeaderElectionID/LeaderElectionNamespaceare unused onceLeaderElectionResourceLockInterfaceis set (controller.go:145-149).- Config parse errors wrap a wire protocol code, so operators see messages like
RACER_PEER_PORT: invalid_request(controller.go:244,287,305). controller.yaml.tmpl: 3 replicas with no PodDisruptionBudget or anti-affinity.wire/codec.go:78-119(diff too large to comment inline):DecodeAdmittedMemberaccepts a legacyrailsrecord shape. See themembership.gocomment.
Questions
- Do any installs outside this repo depend on the unstaged protocol or the older annotation/record formats? If not, removing them is the largest simplification available.
- Is revoking in-flight snapshot writes on every publication a security requirement? If so, what is the plan for clients that fall behind in large clusters?



Adds the Racer control plane: the metadata-only ClusterCache CRD, membership APIs, and encryption key generation and rotation.