Skip to content

Replace apiserver runtime - #176

Merged
anoop2811 merged 10 commits into
oam-dev:masterfrom
roguepikachu:replace-apiserver-runtime
Oct 5, 2026
Merged

anoop2811 merged 10 commits into
oam-dev:masterfrom
roguepikachu:replace-apiserver-runtime

Conversation

@roguepikachu

@roguepikachu roguepikachu commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by cubic

Replaces the sigs.k8s.io/apiserver-runtime framework with canonical k8s.io/apiserver, so the apiserver bootstraps directly and can move to k8s 1.35. This bumps the toolchain to go 1.25.13, k8s.io/apiserver v0.35.6, regenerates the CRD, OpenAPI, and clientset artifacts, and adds tests for the new storage and loopback wiring, with codecov ignores narrowed to generated files.

Refactors

  • cmd/apiserver now builds the aggregated apiserver on RecommendedOptions/GenericAPIServer; resource/resourcerest interfaces are replaced with canonical k8s.io/apiserver/pkg/registry/rest interfaces.
  • Proxy and health subresources get parent storage through direct injection instead of context lookup, backed by the new pkg/util/loopback package; loopback helper tests are stabilized for concurrent bootstrap.
  • The RESTClient in clustergateway_expansion.go is rebuilt with the public constructor instead of copying the rest.RESTClient struct.
  • Aligns the controller-tools module version with the pinned controller-gen v0.17.3.
  • Codecov uploads are now non-blocking so the check won't fail in forks.

Bug Fixes

Written for commit 284a2e9. Summary will update on new commits.

Review in cubic

…iserver

Drops the dependency on the externally-maintained kmodules/apiserver-runtime
fork of the stale kubernetes-sigs/apiserver-runtime. cmd/apiserver/main.go
now builds the aggregated apiserver directly on k8s.io/apiserver's
RecommendedOptions/RecommendedConfig/GenericAPIServer, since ClusterGateway
and VirtualCluster already implement the canonical rest.Getter/Lister
interfaces themselves and never relied on the framework's storage
generation. Subresource dispatch (proxy, health) is rewired from
context-based parent-storage lookup to direct field/singleton injection,
and resourcerest/resource.* interfaces are swapped for their canonical
k8s.io/apiserver/pkg/registry/rest equivalents.

Bundled with the k8s 1.35 bump (go 1.25.12, k8s.io/apiserver v0.35.6) since
unblocking that bump was the reason for this replacement, including the
OpenAPI definitions regen and go vet copylocks fix needed for v0.35.6's
OpenAPI/SSA machinery.

Signed-off-by: anish bista <anishbista053@gmail.com>
The apiserver-runtime replacement commit bumped go.mod to go 1.25.12 /
k8s.io/apiserver v0.35.6 but missed the surrounding build/CI surface:
Dockerfiles still built with golang:1.23 (would have failed the module's
go directive), and CI still pinned Go 1.23, kind v0.29.0, node v1.31.9,
and kubebuilder-assets 1.31.x. Also regenerates the
clustergatewayconfigurations CRD with controller-gen v0.17.3 to match the
version now pinned in the Makefile.

Signed-off-by: anish bista <anishbista053@gmail.com>
The canonical bootstrap dropped apiserver-runtime's
compatibility.DefaultComponentGlobalsRegistry.AddFlags call, which used to
register --feature-gates transparently. Both the Helm chart and the OCM
addon controller pass --feature-gates=HealthinessCheck=true,SecretCache=true
to the gateway container, so without this flag registered the process failed
cobra flag parsing and crashed on startup — which is why the APIService
never became Available in CI (oam-dev#173).

Bind it directly to utilfeature.DefaultMutableFeatureGate, the same gate
pkg/featuregates and the rest of the codebase already read from.

Verified locally: built the image, ran it against a live kind cluster's
API server with the exact flags the Helm chart passes (--secure-port,
--secret-namespace, --feature-gates, delegated auth via kubeconfig) — it
now starts cleanly, serves /healthz, and correctly enforces RBAC on the
API path.

Signed-off-by: anish bista <anishbista053@gmail.com>
Signed-off-by: anish bista <anishbista053@gmail.com>
Signed-off-by: anish bista <anishbista053@gmail.com>
Signed-off-by: anish bista <anishbista053@gmail.com>
Signed-off-by: roguepikachu <roguepikachu@users.noreply.github.com>
@roguepikachu
roguepikachu force-pushed the replace-apiserver-runtime branch from 0fea160 to ea8e7f1 Compare October 5, 2026 06:15
@roguepikachu

roguepikachu commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed against the latest diff

This PR moves logic across many files. Ultrareviews find 2.4x more serious bugs than standard reviews. Comment @cubic-dev-ai ultrareview to run one.

Fix all with cubic | Re-trigger cubic

Comment thread pkg/util/loopback/loopback_test.go Outdated
Comment thread codecov.yml
Signed-off-by: roguepikachu <roguepikachu@users.noreply.github.com>
Signed-off-by: roguepikachu <roguepikachu@users.noreply.github.com>
Signed-off-by: roguepikachu <roguepikachu@users.noreply.github.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 1 file (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Fix all with cubic | Re-trigger cubic

Comment thread .github/workflows/ci.yaml
Comment thread .github/workflows/ci.yaml

@jerrinfrancis jerrinfrancis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@anoop2811
anoop2811 merged commit 8ff085a into oam-dev:master Oct 5, 2026
6 checks passed
roguepikachu added a commit to roguepikachu/cluster-gateway that referenced this pull request Oct 6, 2026
client-gen v0.35.6 to v0.37.1 and controller-gen/controller-tools v0.17.3 to v0.22.0, keeping the go.mod controller-tools version aligned with the Makefile pin as oam-dev#176 did. Regenerates the clientset (Discovery() now returns discovery.DiscoveryInterfaces, matching client-go 0.37) and the CRD, with the chart copy kept in sync.

Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants