Skip to content

feat(racer): add controller and ClusterCache API - #869

Merged
Jordan Olshevski (jveski) merged 25 commits into
mainfrom
pr/racer-controller
Oct 7, 2026
Merged

Jordan Olshevski (jveski) merged 25 commits into
mainfrom
pr/racer-controller

Conversation

@jveski

@jveski Jordan Olshevski (jveski) commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Adds the Racer control plane: the metadata-only ClusterCache CRD, membership APIs, and encryption key generation and rotation.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The deployment prerequisites omit the Kubernetes token capability required for bearer authentication, causing supported-looking older clusters to reject bootstrap requests.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Adds the standalone Racer controller, ClusterVolume API, wire protocol, deployment assets, packaging, and CI coverage.

Changes:

  • Adds validated Racer wire contracts, canonical publications, deltas, membership, and keyrings.
  • Adds ClusterVolume APIs and secure standalone Kubernetes deployment manifests.
  • Adds controller build, test, envtest, image, and release automation.
File Description
Makefile Adds Racer build, test, generation, and rendering targets.
internal/​racer/​wire/​vectors_test.go Tests shared wire vectors.
internal/​racer/​wire/​types.go Defines and validates wire types.
internal/​racer/​wire/​token_validation_test.go Tests strict token validation.
internal/​racer/​wire/​testdata/​site-vectors.json Adds Site transition vectors.
internal/​racer/​wire/​testdata/​rejections.json Adds rejection fixtures.
internal/​racer/​wire/​testdata/​publication.json Adds publication fixture.
internal/​racer/​wire/​testdata/​membership.json Adds membership fixture.
internal/​racer/​wire/​testdata/​hashes.json Adds canonical hash fixture.
internal/​racer/​wire/​testdata/​delta.json Adds delta fixture.
internal/​racer/​wire/​testdata/​content.json Adds canonical content fixture.
internal/​racer/​wire/​testdata/​bundle.json Adds keyring fixture.
internal/​racer/​wire/​testdata/​bootstrap-response.json Adds bootstrap response fixture.
internal/​racer/​wire/​testdata/​bootstrap-request.json Adds bootstrap request fixture.
internal/​racer/​wire/​site_vectors_test.go Tests shared Site vectors.
internal/​racer/​wire/​site_test.go Tests Site validation and deltas.
internal/​racer/​wire/​rdma_nics_test.go Tests RDMA NIC contracts.
internal/​racer/​wire/​delta_test.go Tests delta application.
internal/​racer/​wire/​codec.go Implements bounded strict codecs.
internal/​racer/​wire/​codec_test.go Tests bundle encoding and redaction.
internal/​racer/​wire/​canonical.go Implements canonicalization, hashes, and deltas.
internal/​racer/​wire/​canonical_test.go Tests canonical state ownership and bounds.
internal/​racer/​wire/​bootstrap_test.go Tests bootstrap size boundaries.
internal/​racer/​wire/​adversarial_test.go Adds malformed-input and fuzz coverage.
internal/​racer/​volume_test.go Tests ClusterVolume reconciliation and admission.
internal/​racer/​members/​membership.go Builds membership and cache catalogs.
internal/​racer/​members/​membership_test.go Tests membership recovery and selection.
images/​racer-controller/​Containerfile Packages the controller image.
deploy/​racer/​security_test.go Tests rendered security controls.
deploy/​racer/​rendered/​.gitignore Excludes rendered manifests.
deploy/​racer/​render_test.go Tests rendered deployment contracts.
deploy/​racer/​README.md Documents standalone installation.
deploy/​racer/​rbac.yaml.tmpl Defines controller RBAC.
deploy/​racer/​installation.yaml.tmpl Defines installation state marker.
deploy/​racer/​image_test.go Tests image metadata wiring.
deploy/​racer/​embed.go Embeds rendered templates and CRDs.
deploy/​racer/​embed_test.go Tests embedded manifest behavior.
deploy/​racer/​dataplane-config.yaml.tmpl Supplies retained dataplane defaults.
deploy/​racer/​create-restriction.yaml.tmpl Restricts runtime object creation.
deploy/​racer/​crd/​racer.unbounded-cloud.io_clustervolumes.yaml Defines the ClusterVolume CRD.
deploy/​racer/​controller.yaml.tmpl Deploys controller replicas and Service.
deploy/​racer/​config.yaml.tmpl Configures controller runtime settings.
deploy/​racer/​bootstrap-trust.yaml.tmpl Optionally provisions bootstrap trust.
cmd/​racer-controller/​README.md Documents controller operation.
cmd/​racer-controller/​main.go Adds the controller entry point.
cmd/​racer-controller/​main_test.go Tests CLI and startup logging.
api/​racer/​v1alpha1/​zz_generated.deepcopy.go Adds generated deep-copy methods.
api/​racer/​v1alpha1/​register.go Registers Racer API types.
api/​racer/​v1alpha1/​groupversion_info.go Configures API generation.
api/​racer/​v1alpha1/​clustervolume_types.go Defines ClusterVolume types.
.github/​workflows/​release.yaml Publishes the controller image.
.github/​workflows/​nightly.yaml Adds nightly image builds.
.github/​workflows/​ci.yaml Adds Racer envtest CI.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread deploy/racer/README.md Outdated
@jveski
Jordan Olshevski (jveski) requested a balanced review from Copilot October 6, 2026 19:44
@jveski
Jordan Olshevski (jveski) marked this pull request as ready for review October 6, 2026 19:45
@jveski
Jordan Olshevski (jveski) requested a review from a team October 6, 2026 19:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The broad security-sensitive protocol, credential, durable-state, and deployment surface warrants final human review.

Review effort: Balanced
Findings: None

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The broad security-sensitive control-plane, credential, replication, and recovery changes warrant final human review.

0 open findings

🧠 Review effort: Balanced

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review at bc52d94, based on reading the non-test Go code, deploy templates, and build/CI changes (not run locally). Inline comments cover bugs first, then simplification candidates.

Bugs / correctness (highest impact first)

  1. Request cancellation during issuance withdraws trust for the whole replica (authority/authentication.go).
  2. 32 silent TCP connections block every new TLS handshake for 30s (server/transport.go).
  3. Every publication aborts in-flight snapshot writes; lagging clients may never complete a full download under churn (authority/publications.go).
  4. Conflicts requeue at 10ms with no backoff, and a stale-cache Node patch conflict restarts the whole publish (reconcilers.go).
  5. The default installation.yaml render cannot be applied to a new or existing install (installation.yaml.tmpl).
  6. Delta selection matches content hash but not sequence (authority/publications.go).

Simplification candidates

  • Unstaged initialization protocol and compatibility code for formats that no earlier version in this repo produced.
  • Operator-only code with no non-test caller in this PR (workload builder, deploy/racer/embed.go, dataplane templates).
  • Code duplicated between internal/racer, authority, and server; frozenConfig; test-only reimplementation of the reconcilers shaping production code.
  • Write authorization via context.Context type assertions.
  • Custom TLS listener and certificate reloader.

Nits (no inline anchor)

  • controller.go:190 caches every ConfigMap in the namespace, though only two are watched. A field selector like the Secret one would do.
  • controller.go:181-182: LeaderElectionID/LeaderElectionNamespace are unused once LeaderElectionResourceLockInterface is set (controller.go:145-149).
  • Config parse errors wrap a wire protocol code, so operators see messages like RACER_PEER_PORT: invalid_request (controller.go:244,287,305).
  • controller.yaml.tmpl: 3 replicas with no PodDisruptionBudget or anti-affinity.
  • wire/codec.go:78-119 (diff too large to comment inline): DecodeAdmittedMember accepts a legacy rails record shape. See the membership.go comment.

Questions

  • Do any installs outside this repo depend on the unstaged protocol or the older annotation/record formats? If not, removing them is the largest simplification available.
  • Is revoking in-flight snapshot writes on every publication a security requirement? If so, what is the plan for clients that fall behind in large clusters?

Comment thread internal/racer/authority/authentication.go Outdated
Comment thread internal/racer/server/transport.go Outdated
Comment thread internal/racer/authority/publications.go Outdated
Comment thread internal/racer/reconcilers.go Outdated
Comment thread internal/racer/reconcilers.go Outdated
Comment thread internal/racer/controller.go Outdated
Comment thread internal/racer/authority/credentials.go
Comment thread internal/racer/authority/authority.go Outdated
Comment thread internal/racer/server/transport.go Outdated
Comment thread internal/racer/authority/authentication.go Outdated
@jveski
Jordan Olshevski (jveski) requested a balanced review from Copilot October 7, 2026 18:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A failing metrics assertion, unexecuted deployment envtests, and unrestricted cluster-wide Node patch access must be addressed.

2 open findings
2 resolved since last review

🧠 Review effort: Balanced

Comment thread deploy/racer/rbac.yaml.tmpl Outdated
Comment thread Makefile Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A metrics test has a guaranteed failing assertion, and the security-critical runtime admission policy lacks API-server execution coverage.

2 open findings
1 resolved since last review

🧠 Review effort: Balanced

Comment thread deploy/racer/create-restriction.yaml.tmpl Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

A metrics assertion guarantees test failure, and workload URL validation accepts malformed empty-port endpoints.

2 open findings

🧠 Review effort: Balanced

@jveski Jordan Olshevski (jveski) changed the title feat(racer): add controller and ClusterVolume API feat(racer): add controller and ClusterCache API Oct 7, 2026
@jveski
Jordan Olshevski (jveski) requested a balanced review from Copilot October 7, 2026 21:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The extensive authentication, cryptographic state, admission-policy, replication, and durable-recovery changes require final human security and operational review.

2 open findings

🧠 Review effort: Balanced

@jveski
Jordan Olshevski (jveski) added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit 7367ce7 Oct 7, 2026
41 checks passed
@jveski
Jordan Olshevski (jveski) deleted the pr/racer-controller branch October 7, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants