feat: a domain input for T Cloud Public scope (ENG-821) - #4
Conversation
The action forwarded account, region, project and stack-export one-to-one and had no `domain`, so an OTC simulation from CI could only reach `--domain` through `extra-args` — which this action's own comment reserves for flags added to the CLI after a release, not for a first-class scope value. And the input alone would not have been enough: nothing customer-facing said the value exists. The README documented account/region/project and no OTC at all, so a customer discovered the requirement by hitting a failed submission. The README now carries the input, the recovery-path table that explains why OTC needs it more often than AWS needs `account` (one path before the flag, against three for AWS region and three for AWS account — and only a value WRITTEN in the provider block reaches the plan, so `OS_DOMAIN_NAME` in the job environment carries nothing), and the one thing the tooling cannot check: the value is compared byte for byte against the connector's, case not folded and name not resolved to id, because a mismatch produces a run that succeeds, shadows nothing, and describes a world that does not exist. Not in scope: `allow-mock-domain` as an input. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 5 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe action adds an optional ChangesT Cloud Public domain scoping
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The optional domain input is reported as consistently declared, mapped, and conditionally forwarded, with no identified merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Warning Git: CodeRabbit could not clone the repository, so clone-backed analysis was skipped and this review may be incomplete. Verify repository clone access, such as SSH credentials, before requesting another full review. If clone access is intentionally unavailable, use Comment |
Part 1 of 3 for ENG-821. The other two are the onboarding section in plugin-tcloudpublic and the CLI's environment-variable suggestion in linro-simulator.
The problem
The action forwards scope flags one-to-one —
account,region,project,stack-export— and had nodomain. An OTC simulation from CI could reach--domainonly throughextra-args, which this action's own comment reserves for "flags added to the CLI after an action release, not the normal way to reach anything listed below".And the input alone would not have been enough. Verified on
main:--domain/ OTC?account,region,project; no OTC anywhereplugin-tcloudpublic/onboarding.mdlinro-simulator/AGENTS.md--helpand the failure messageSo a customer discovered the requirement by hitting a failed submission. Better than a silent wrong scope (ENG-819), but "discoverable only by failing" is not documentation.
What is here
domaininput →INPUT_DOMAIN→--domain, in the sameif [ -n … ]form as its siblings (the&&form would make an unset trailing input the script's exit status underset -e— the comment above that block explains it).domainrow, the recovery-path table, and a worked example.regionassume_rolerole ARN,stack-export, thenaccountprojectin the google provider block, thenprojectdomain_id/domain_namein the provider block, thendomain. That is all.Both AWS and OTC lose the provider-block value when it comes from the environment (
AWS_REGION,OS_DOMAIN_NAME, commonly repo secrets in CI). AWS has two other paths; OTC has none.domainscope holds whatever the customer typed — the 32-hex id or the account name — and Linro never rewrites one into the other (settled in ENG-857). A simulation passing the other spelling composes rows that shadow nothing: every simulated resource lands beside its live twin, the diff shows everything as new, and nothing errors. So: read the value off the connector rather than retyping it.Not in scope
allow-mock-domainas an input (mirroringallow-mock-accountonly if asked);stack-exportscope recovery stays AWS-only.Verification
action.ymlparses; the action's own CI check that every declared input is wired and every used input declared passes locally (undeclared: [],unwired: []). The shell change is the existingif [ -n "$INPUT_X" ]; then args+=(--x "$INPUT_X"); filine with a new name — shellcheck runs on it in CI.Note the flag is inert today:
--domainonly does anything once linro-simulator links plugin-tcloudpublic (ENG-820), which is why this blocks that one rather than trailing it — shipping OTC simulation while CI cannot pass a domain means the first thing a customer tries fails on a flag they cannot reach.🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Documentation