Skip to content

feat(recipepack): [stack 1/3: default k8s recipe pack] sync and embed the pinned Kubernetes recipe pack - #13248

Open
nithyatsu wants to merge 4 commits into
mainfrom
nithyatsu-k8s-pack-sync
Open

nithyatsu wants to merge 4 commits into
mainfrom
nithyatsu-k8s-pack-sync

Conversation

@nithyatsu

@nithyatsu nithyatsu commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Stack 1/3 for the default Kubernetes recipe pack plan (#13225).

  • make sync-resource-types (and update-recipe-packs, update-resource-types-and-recipe-packs) now compiles recipe-packs/kubernetes/default.bicep at the pinned recipePacks ref into deploy/manifest/recipe-packs/kubernetes/default.json. The script requires the Bicep version in build/tools.yaml and strips metadata._generator. Other packs are still only verified.
  • The JSON is embedded. pkg/defaults.DefaultKubernetesRecipePack() decodes the pack's properties into the generated RecipePackProperties (2025-08-01-preview), so every recipe field the API defines (kind, source, parameters, plainHttp, outputs) passes through without code changes. Extension imports and other template content are ignored.
  • The load fails, rather than dropping data, on: fields the models don't know, read-only fields, a different recipe pack API version, an unsupported kind, a source without a tag or with a digest, and ARM expressions anywhere in a recipe.
  • CI installs Bicep, and the drift check now covers deploy/manifest/recipe-packs/.

rad does not use the loader yet; that is stack 2/3.

Note

Rebased onto #13254, which pins the kubernetes pack to recipe-pack/kubernetes/v0.3.0 (fc1b667). make sync-resource-types at that pin produces the committed default.json with no diff.

Reason for change

rad hard-codes the default Kubernetes recipe list in Go. This vendors the pinned contrib pack so rad can build from it instead.

Part of #11959

How to test

  • make test-sync-resource-types: passed (new tests cover a missing default.bicep, a wrong Bicep version, a pin move recompiling the JSON, non-vendored packs not copied, and --update-recipe-packs ordering)
  • go test ./pkg/defaults/... ./deploy/manifest/...: passed
  • go vet ./pkg/defaults/... ./deploy/manifest/...: passed
  • shellcheck --rcfile .github/linters/.shellcheckrc and shfmt -i 4 -ci -d on both scripts: no new findings
  • make sync-resource-types at the v0.3.0 pin: no diff (manifests and default.json unchanged)

File change summary

File Summary of change
build/scripts/sync-resource-types.sh Compile vendored packs (VENDORED_RECIPE_PACKS=kubernetes) with the pinned Bicep version; --update-recipe-packs now recompiles them
build/scripts/test-sync-resource-types.sh Tests for pack compile, version check, pin move and mode ordering
build/resource-types.mk Pass BICEP_VERSION; update comments and target help
deploy/manifest/defaults.yaml Comment: kubernetes pack is compiled and embedded
deploy/manifest/recipe-packs/kubernetes/default.json Compiled Kubernetes recipe pack
deploy/manifest/embed.go Embed default.json; add KubernetesRecipePackPath
pkg/defaults/recipepack.go Loader, DefaultKubernetesRecipePack() and RecipeSourceRepository()
pkg/defaults/recipepack_test.go Loader tests (embedded pack checked without a hard-coded type list)
pkg/defaults/defaults.go Load the pack at init; package doc
.github/workflows/verify-resource-types-manifest.yaml Install Bicep; drift check covers recipe-packs/; trigger on build/tools.yaml
.github/workflows/update-resource-types.yaml Install Bicep for the bot job; PR body mentions the pack

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files  ± 0    460 suites  ±0   15m 46s ⏱️ + 2m 56s
7 282 tests +26  7 280 ✅ +26  2 💤 ±0  0 ❌ ±0 
8 761 runs  +26  8 759 ✅ +26  2 💤 ±0  0 ❌ ±0 

Results for commit 9681bc4. ± Comparison against base commit e900bbb.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 89.21569% with 11 lines in your changes missing coverage. Please review.
✅ Project coverage is 60.44%. Comparing base (e900bbb) to head (9681bc4).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
pkg/defaults/recipepack.go 89.10% 11 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main   #13248      +/-   ##
==========================================
+ Coverage   60.38%   60.44%   +0.06%     
==========================================
  Files         774      775       +1     
  Lines       45682    45784     +102     
==========================================
+ Hits        27583    27673      +90     
- Misses      18099    18111      +12     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

make sync-resource-types and update-recipe-packs now compile
recipe-packs/kubernetes/default.bicep at the pinned recipePacks ref to
deploy/manifest/recipe-packs/kubernetes/default.json with the Bicep
version from build/tools.yaml. The file is embedded, and pkg/defaults
exposes its recipes through DefaultKubernetesRecipes.

CI installs Bicep and includes the compiled pack in the drift check.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
@nithyatsu
nithyatsu force-pushed the nithyatsu-k8s-pack-sync branch from 30e5320 to 5af95ef Compare October 8, 2026 23:37
@nithyatsu
nithyatsu marked this pull request as ready for review October 8, 2026 23:38
Copilot AI balanced review requested due to automatic review settings October 8, 2026 23:38
@nithyatsu
nithyatsu requested review from a team as code owners October 8, 2026 23:38
@github-actions github-actions Bot added the pr:waiting-for-review A reviewer owns the next action; required approval is pending or unverifiable label Oct 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The loader’s shallow copy and top-level-only validation mishandle valid nested recipe parameters.

2 open findings
What changed in this PR

This first stack change vendors and embeds the pinned Kubernetes recipe pack for later use by rad.

Changes:

  • Compiles pinned recipe-pack Bicep into embedded JSON.
  • Adds a Go loader and tests for recipe metadata.
  • Extends CI drift checks and update automation.
File Description
pkg/​defaults/​recipepack.go Adds recipe-pack parsing and access.
pkg/​defaults/​recipepack_test.go Tests parsing and copy behavior.
pkg/​defaults/​defaults.go Loads recipes during initialization.
deploy/​manifest/​recipe-packs/​kubernetes/​default.json Vendors compiled Kubernetes recipes.
deploy/​manifest/​embed.go Embeds the compiled pack.
deploy/​manifest/​defaults.yaml Documents pack vendoring.
build/​scripts/​test-sync-resource-types.sh Tests recipe-pack synchronization.
build/​scripts/​sync-resource-types.sh Compiles pinned recipe packs.
build/​resource-types.mk Passes Bicep configuration to sync targets.
.github/​workflows/​verify-resource-types-manifest.yaml Verifies recipe-pack drift.
.github/​workflows/​update-resource-types.yaml Installs Bicep for automated updates.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/defaults/recipepack.go Outdated
Comment thread pkg/defaults/recipepack.go Outdated
nithyatsu and others added 2 commits October 8, 2026 17:29
…odels

DefaultKubernetesRecipePack returns the pack's RecipePackProperties as
authored, so every recipe field the API defines (such as parameters and
plainHttp) reaches rad without code changes. Fields the models don't know,
read-only fields, a different API version, unsupported kinds and ARM
expressions anywhere in a recipe fail the load instead of being dropped.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
… test

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
@nithyatsu nithyatsu added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Oct 9, 2026
… ST1012

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
@radius-functional-tests

radius-functional-tests Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref 9681bc4
Unique ID funce62fe90dbc
Image tag pr-funce62fe90dbc
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-funce62fe90dbc
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-funce62fe90dbc
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-funce62fe90dbc
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-funce62fe90dbc
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-funce62fe90dbc
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

}
}

return json.Marshal(&properties)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Decode ARM-escaped literal strings before returning the properties

This function reads recipe-pack JSON produced by Bicep. The pinned compiler adds an extra [ to literal strings that begin with [: a Bicep-authored recipe parameter of [literal] becomes [[literal] in the compiled JSON. json.Marshal(&properties) preserves that encoding, so the loader returns a different parameter value from the one authored in Bicep. The same problem affects strings inside objects and arrays.

After rejecting ARM expressions, recursively remove exactly one leading [ from escaped literal strings. Update the valid-input test that currently expects [[literal], and add nested cases and a literal with two leading brackets to verify that decoding happens only once.

Comment thread build/resource-types.mk

.PHONY: sync-resource-types
sync-resource-types: ## Copy manifest files from the per-namespace refs pinned in defaults.yaml
sync-resource-types: ## Copy manifest files and compile the kubernetes recipe pack from the refs pinned in defaults.yaml

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Document the new Bicep prerequisite and generated pack file (non-blocking)

make sync-resource-types now compiles the pinned Kubernetes pack's default.bicep into deploy/manifest/recipe-packs/kubernetes/default.json, so contributors running the command also need the pinned Bicep executable on PATH. Please update docs/contributing/contributing-code/contributing-code-shell-and-make/README.md to include make install-bicep, the required PATH setup, and committing regenerated default.json when changing the contrib pin. This makes the compiler prerequisite and the generated file explicit in the documented update workflow.

@github-actions github-actions Bot added pr:waiting-for-author The author needs to address human review feedback or human-endorsed inline feedback and removed pr:waiting-for-review A reviewer owns the next action; required approval is pending or unverifiable labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work pr:waiting-for-author The author needs to address human review feedback or human-endorsed inline feedback

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants