Scenario contract enforcement: build-time guards + single-sourced CM name
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- bash, go, kubernetes
- Domain
- build-system, cli, devops, infrastructure, testing-qa
Research direction
Start with the Layer 1 tests added in sei-k8s-controller#339, the wrapper bash, and the files under scenarios/. Read how the current envsubst inputs and scenario YAML are wired, then determine whether Layer 2 shape (a) or (b) is selected before designing the validation work. Done means the chosen CM-name approach is migrated, scenario validation exists, and the stated CI and pre-apply checks run.
Written by the indexing model from the issue text.
Description
Problem
The seitask workstream has surfaced a recurring failure pattern: contract drift between the seitask binary's internal helpers (`WorkflowVarsName`, scheme registration, downward-API env contract) and the scenario YAML / RBAC layer that has to mirror them manually. Each of the last four PRs (sei-protocol/sei-k8s-controller#334, #337, #339, plus the in-flight #339 build-time tests) addressed a different facet of the same shape: an internal helper has a convention, the scenario author has to mirror it manually in YAML, no test catches the drift, the bug surfaces only at first cluster fire ~10 minutes into the run.
Platform-engineer (cross-review on #339):
"The scenario YAML is the integration contract between three things (the runtime binary, the chaos-mesh CR shape, the wrapper's envsubst inputs) and none of them validate it. Each bug surfaced at first cluster fire."
Impact
- Slow feedback loop. Each contract bug costs ~10–30 min of manual-fire + investigation + fix-PR + image rebuild + SCENARIO_REF bump + re-fire. We've done this loop four times in the last hour to get the harness past keygen.
- Compounds with scenario count. Adding a second/third scenario will repeat the contract surface from scratch. Without enforcement, each new scenario brings its own #337-class bugs.
- Build-time enforcement is cheap. Two narrow tests added in sei-protocol/sei-k8s-controller#339 already catch the two highest-frequency classes (scheme registration + CM-name drift) at `go test`. There's more we could enforce; this issue tracks the broader pattern.
Proposed approach
Three reinforcing layers, deferred-ranked by effort:
Layer 1 (already partially in #339): unit tests for internal contracts
- ✅ Scheme round-trip test for every typed CR provision-snd / keygen / upload-report constructs
- ✅ CM-name validation for scenario YAMLs that opt in
- ⏳ RBAC vs kubebuilder-marker reconciliation — defer; un-defer when we hit a third RBAC-class bug
Layer 2: single-source the CM name across YAML + binary
Two candidate shapes (both reviewers raised independently):
(a) Wrapper exports `SEI_WORKFLOW_VARS_CM=workflow-vars-${WORKFLOW_NAME}` env var; scenarios reference `$SEI_WORKFLOW_VARS_CM` via envsubst allow-list. Single string-builder lives in the wrapper bash. No new templating dependency.
(b) Render-time template helper `{{ workflowVarsCM }}` exposed in a scenario template engine. Aligns with how the runner subcommand already templates SeiNodeTask CRs and how provision-snd templates SND specs. Requires a scenario rendering engine the wrapper invokes (vs current envsubst).
Platform-engineer recommends (a) as the MVP; kubernetes-specialist recommends (b) longer-term. Both eliminate the manual-mirror failure mode.
Layer 3 (longer-term): `seitask scenario validate` subcommand
A schema-validator subcommand that:
- Parses scenario YAML
- Checks every `configMapRef.name` matches `WorkflowVarsName(metadataName)`
- Checks every `--var=KEY=...` flag matches a documented input on the target subcommand
- Checks every `$(VAR)` reference has a producer step earlier in the Serial
- Run pre-commit (Husky/lefthook), in CI, and pre-apply in the wrapper
Catches more bugs than Layer 1 unit tests because it has access to the full scenario semantics (DAG ordering, var producer/consumer matching), not just the YAML structure.
Source: platform-engineer cross-review on sei-protocol/sei-k8s-controller#339.
Relevant experts
- platform-engineer — owns the wrapper bash + envsubst contract; (a) lives entirely in their territory
- kubernetes-specialist — owns the operator-pattern alignment for (b); also the rbac-marker reconciliation in Layer 1
- product-engineer — should weigh in on which Layer 2 shape fits the longer-term scenario authoring DX
Acceptance criteria
This issue resolves when:
- Layer 1 partially done (scheme + CM-name tests in #339)
- Layer 1 RBAC reconciliation test added (when justified)
- Layer 2: pick (a) or (b) and migrate release-test + future scenarios to it
- Layer 3: `seitask scenario validate` subcommand exists, runs in sei-k8s-controller CI on every PR that touches `scenarios/`, runs pre-apply in the wrapper
Out of scope
- Workflow engine swap (sei-protocol/sei-k8s-controller#332 tracks longer-term Argo evaluation)
- Status-check shared template library (sei-protocol/sei-k8s-controller#330)
- Chaos-mesh fail-fast (sei-protocol/sei-k8s-controller#340)
References
- sei-protocol/sei-k8s-controller#334 — first contract bug class (downward-API UID assumption)
- sei-protocol/sei-k8s-controller#337 — second (CM name mismatch)
- sei-protocol/sei-k8s-controller#339 — third (scheme + RBAC) + Layer 1 partial implementation
- Memory: `feedback_prototype_first.md` survey-checkpoint pattern (this issue's recurrence count, 4, justifies hardening)
🤖 Generated with Claude Code
- Dominant language
- Go
- Stars
- 1
- Forks
- 2
- Avg merge
- 2h 29m
- Merged PRs (30d)
- 56
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from sei-protocol/sei-k8s-controller
-
Difficulty 5/5 Over a week Newbie friendliness 32/100
-
Difficulty 5/5 Over a week Newbie friendliness 32/100
sei-protocol/sei-k8s-controller#457 · 2 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
-
Difficulty 3/5 1-2 days Newbie friendliness 65/100
All issues in sei-protocol/sei-k8s-controller
Similar issues
-
optimization optimization:agents-md-curator
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
githubnext/gh-aw-cao#13143 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
blinklabs-io/bursa#904 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
yanet-platform/ipfw-go#129 ·
-
bug confmap/provider/googlesecretmanagerprovider needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
open-telemetry/opentelemetry-collector-contrib#51273 · 2 comments ·
-
bug: AI Gateway client filter lists "Unknown" twice when NULL and literal Unknown clients coexist Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 90/100