feat(binjovi): grant the legacy reads ex-mcp needs to be a working project #678
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/ex-mcp-bindings"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
The seanfarm half of making
sean/ex-mcpa working Binjovi project. Pairs with binjovi PR #1658, which adds the bindings themselves. Without this, none of them work.Why a grant is needed for objects that do not exist
Binjovi proves the legacy Kubernetes CR is absent before it takes ownership (
ServiceLegacyClient.legacy_state/2). Without the name in the Role the scoped read returns 403 — denied, indistinguishable from present — and the gate refuses. With it the read returns 404, which is absent and actionable.This repo's own guard already says exactly that:
The pinned counts in
tests/binjovi-service-handoff.shandtests/binjovi-active-webhook-handoff.shmove with them, and both now assert theex-mcpnames by hand, as the fleet already does.Worth noting for whoever hits this next: four other guards call the webhook one as a sub-check, so a single stale
38failed five guards at once with no output of their own. The trail isbash -x, not the summary.No
forgejorepositoriesentry, deliberately.ForgejoRepository/ex-mcpis live and owned by forgejo-operator, so that gate refuses by design. A grant there would look like coverage and do nothing.Also: what the mirror does not cover
gitmirrors/ex-mcp.yamlnow records it.branchFilteris an allowlist, so the first sync pruned three branches from codeberg. Two are redundant —feat/optional-cowboyandclaude/issue-pr-feedback-hyl8jnpoint at commits already on mirrored refs. The third is upstream's owncursor/azm-5-track-cowlib-cve-…, which I confirmed is present atgithub.com/azmaveth/ex_mcprather than assuming it.So a ref diff against codeberg is expected to be non-empty here, and widening the filter would be worse: every named branch must exist, so an upstream branch that disappears fails the whole push atomically and stops the backup.
It also records that
syncOnCommitfires on a commit, sotrunkandmain— created before the mirror — needed one manualpush_mirrors-sync.Verification
Full
tests/check.shgreen.https://claude.ai/code/session_01XdBRc9CHgFhAxCyHbdVtt6