Conversation
…e cluster security seed Adds HAServerPlugin.connectClusterAndReportSeed, overridden by RaftHAPlugin to join and then ask the leader for the seed outcome. ServerControlPlane.connectCluster now consumes that report instead of issuing its own seed request, so there is still exactly one seed request per connect cluster (#7834). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Tick the box to add this pull request to the merge queue (same as
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
🟢 Coverage 100.00% diff coverage · -5.91% coverage variation
Metric Results Coverage variation ✅ -5.91% coverage variation Diff coverage ✅ 100.00% diff coverage Coverage variation details
Coverable lines Covered lines Coverage Common ancestor commit (6abf36d) 205851 174151 84.60% Head commit (4e00cd7) 238451 (+32600) 187643 (+13492) 78.69% (-5.91%) Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch:
<coverage of head commit> - <coverage of common ancestor commit>Diff coverage details
Coverable lines Covered lines Diff coverage Pull request (#8845) 10 10 100.00% Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified:
<covered lines added or modified>/<coverable lines added or modified> * 100%
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe HA plugin API now exposes an optional security-seed report for cluster connections. The Raft implementation joins before reporting seed results. The control plane consumes a plugin report when available and uses its existing seed path when the plugin provides none. ChangesCluster seed reporting
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant ServerControlPlane
participant HAServerPlugin
participant RaftHAPlugin
ServerControlPlane->>HAServerPlugin: connectClusterAndReportSeed(serverAddress)
HAServerPlugin->>RaftHAPlugin: dispatch reporting method
RaftHAPlugin->>RaftHAPlugin: connectCluster(serverAddress)
RaftHAPlugin->>RaftHAPlugin: request admission seed report
RaftHAPlugin-->>ServerControlPlane: return optional seed report
ServerControlPlane->>ServerControlPlane: use report or run fallback seed path
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The reporting API preserves membership failure behavior and avoids duplicate seeding while retaining compatibility fallback. No actionable merge-blocking risk remains on the supplied evidence. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The reviewed change improves visibility into incomplete security synchronization without granting new membership authority. Existing administrative access checks remain in place, legacy implementations retain their fallback behavior, and security-seed failures remain distinguishable from failed joins. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Review of #8845 (connectClusterAndReportSeed)Overall: a small, well-scoped change that follows the existing Correctness (looks good)
Minor issues / suggestions
Performance / security
Process
Nice work, and the completeness table in the description makes the review easy. |
…oin and UOE-mapping tests Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Review of #8845 (connectClusterAndReportSeed)I found nothing that blocks the merge. The change follows the Correctness
Suggestions (non-blocking)
Performance / securityThere is no hot-path impact. This is a control-plane call with the same bounded seed wait as TestsThe coverage is good. It includes the single-seed ordering, a failed join not being seeded (against both the stub and the production |
…port, if/else over ternary, javadoc on who logs Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Review of #8845 Overall this is a clean, well-scoped change. The new What I checked
Suggestions (non-blocking)
The diff follows CLAUDE.md for style: LGTM once you have decided on suggestion 1. |
…ortSeed Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Review of #8845Overall this is a clean, well-scoped change. It mirrors the existing What looks good
Points worth a look
Security / performanceNo new security surface. The only cost is the bounded seed wait for embedders who switch to the new method, and that is documented. No hot-path or allocation concerns. CISeveral checks (build-and-package, Analyze, lint) were not green when I looked. Please confirm they pass before merging. Nothing here blocks the merge; points 1 and 2 are the ones I would consider addressing. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8845 +/- ##
=========================================
Coverage 76.34% 76.34%
- Complexity 3779 3780 +1
=========================================
Files 2102 2102
Lines 205851 205857 +6
Branches 43375 43376 +1
=========================================
+ Hits 157159 157167 +8
+ Misses 31742 31741 -1
+ Partials 16950 16949 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Closes #8077
The embedded
HAServerPlugin.connectCluster(String)API joined a server with no way for the caller to learn that the leader's security seed left a document uncommitted. This addsHAServerPlugin.connectClusterAndReportSeed(String)(theconnect clustercounterpart of #7820'saddPeerAndReportSeed) and moves the report down into the plugin, as the issue proposed:RaftHAPluginoverrides it to run the join and then ask the leader for the seed outcome (sameseedReportForAdmissionasaddPeerAndReportSeed, so it never throws after the join and reports an unknown outcome as all three documents).ServerControlPlane.connectClusternow calls the new method and uses its report, so both wire transports still make exactly one seed request perconnect cluster(#7834).The interface default joins through
connectClusterand returns an emptyOptional, which means "this implementation leaves the seed to its caller", the same conventionseedSecurityStateForAdmissionuses. In that caseServerControlPlaneruns the seed it always ran (leader-side viaseedSecurityStateForAdmission, or locally), so an HA implementation written before this change behaves exactly as before. The voidconnectClusterstays the membership change alone.Completeness
Invariant: every admission entry point that changes membership can hand its caller the residual seed failure, with one seed request per admission.
connect cluster(PostServerCommandHandler->ServerControlPlane)failedSeedsConnectCluster(ArcadeDbGrpcAdminService->ServerControlPlane)UNAVAILABLEHAServerPlugin.connectClusterAndReportSeed(Raft)HAServerPlugin.connectCluster(void)ServerControlPlanefallback, as beforeIssue7532ConnectClusterReportsSeedFailureTestCoverage
RaftHAPlugin.connectClusterAndReportSeed:Issue8077EmbeddedConnectClusterSeedReportTest(report, clean join, ordering + single seed request, failed join not seeded, seed IOException / unchecked failure never fails the join).ServerControlPlane.connectClusterconsuming the report:Issue8077ConnectClusterConsumesPluginSeedReportTest(plugin report used, no second seed either leader-side or local; default plugin still gets the leader seed; interface default contract; no-runtime-membership still a precondition refusal).Known gaps: None.
Test plan
mvn test -pl server,ha-raft -Dtest='Issue8077*Test,Issue7532ConnectClusterReportsSeedFailureTest,Issue7401ServerControlPlaneConnectClusterTest,Issue7834SeedStaysUnconditionalTest,Issue7521SecuritySeedRetryTest,Issue7820EmbeddedAddPeerSeedReportTest,Issue7515SelfJoinRefusedTest,Issue4837DoubleLeaveTest,Issue7559SecurityPreconditionOnFollowerTest'- 75 tests greenmvn verify -pl ha-raft,server -DskipITs=false -Dit.test='Issue7401ConnectClusterJoinsPeerIT,Issue7532ConnectClusterHttpSeedFailureIT,Issue7400ConnectClusterHttpIT,Issue7514UnreachablePeerFailsFastIT'- 10 ITs green (live Raft join throughServerControlPlane->connectClusterAndReportSeed)Adversarial pass
No subagent tool was available in this run, so the pass was done as a self-review against the issue body:
ServerControlPlaneonly falls back to its own seed when the plugin returns an emptyOptional, which Raft never does; asserted byaPluginThatReportsItsOwnSeedIsNotSeededAgain.seedReportForAdmissioncatches everyRuntimeException, so a UOE can only come from the join; asserted byanUncheckedFailureWhileSeedingStillDoesNotFailTheJoin.Review cycles
connectClusterfailing (no seed); test that a reporting plugin's UOE still maps toOperationNotAvailableException; field alignmentif/elseinstead of the ternary; javadoc says the report is returned, not loggedDeferred items
seedReportForAdmissionlogs and returns all three documents, thenServerControlPlanelogs the non-empty report. The control-plane line is the one an HTTP or gRPC operator relies on for every non-empty report, and the plugin cannot tell its caller which kind of non-empty report it produced.addPeeralready has the same double line. Logging in one place only would need a richer return type than this fix is worth.server.getHA().connectClusterAndReportSeed(...)(cycle 3): skipped.Issue7401ConnectClusterJoinsPeerITalready drives the Raft override throughServerControlPlaneon a real cluster.connectClusterandconnectClusterAndReportSeedonRaftHAPlugin(cycle 3): skipped as a nit.RaftHAPlugin.connectClusterAndReportSeedfor a caller that drops the result (this would double the log on the control-plane path); (3) AssertJcontains(List.of())instead ofisPresent()/get()inaCleanJoinReportsAPresentEmptyList; (4) trim the javadoc; (5) the bot said CI checks were still pending when it looked.Final state: max-cycles-reached (4/4). No blocking findings. Every review said nothing blocks the merge.
🤖 Generated with Claude Code