Skip to content

feat: a domain input for T Cloud Public scope (ENG-821) - #4

Merged
Adam Tauber (asciimoo) merged 1 commit into
mainfrom
adamtauber/eng-821-simulation-github-action-a-domain-input-and-the-customer
Sep 16, 2026
Merged

Adam Tauber (asciimoo) merged 1 commit into
mainfrom
adamtauber/eng-821-simulation-github-action-a-domain-input-and-the-customer

Conversation

@asciimoo

@asciimoo Adam Tauber (asciimoo) commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Part 1 of 3 for ENG-821. The other two are the onboarding section in plugin-tcloudpublic and the CLI's environment-variable suggestion in linro-simulator.

The problem

The action forwards scope flags one-to-one — account, region, project, stack-export — and had no domain. An OTC simulation from CI could reach --domain only through extra-args, which this action's own comment reserves for "flags added to the CLI after an action release, not the normal way to reach anything listed below".

And the input alone would not have been enough. Verified on main:

Surface Mentions --domain / OTC?
this README No. Documented account, region, project; no OTC anywhere
plugin-tcloudpublic/onboarding.md No. Never mentioned simulation at all
linro-simulator/AGENTS.md Yes — a maintainer document, not a customer one
CLI --help and the failure message Yes — the only customer-facing surface there was

So a customer discovered the requirement by hitting a failed submission. Better than a silent wrong scope (ENG-819), but "discoverable only by failing" is not documentation.

What is here

  • domain input → INPUT_DOMAIN → --domain, in the same if [ -n … ] form as its siblings (the && form would make an unset trailing input the script's exit status under set -e — the comment above that block explains it).
  • README: a domain row, the recovery-path table, and a worked example.
  • A note on framing. An earlier revision of the ticket read as though CI scope were a new OTC problem. It is not — the usual split is plan vs preview, not provider, and a missing value errors for AWS and GCP too. What is genuinely weaker for OTC is the number of recovery paths on a plan:
Value Recovery paths
AWS region plan-wide, a per-resource hint, then region
AWS account an assume_role role ARN, stack-export, then account
GCP project a constant project in the google provider block, then project
OTC domain a constant domain_id/domain_name in the provider block, then domain. That is all.

Both AWS and OTC lose the provider-block value when it comes from the environment (AWS_REGION, OS_DOMAIN_NAME, commonly repo secrets in CI). AWS has two other paths; OTC has none.

  • The byte-for-byte warning, which is the part no tooling can check. A connector's domain scope holds whatever the customer typed — the 32-hex id or the account name — and Linro never rewrites one into the other (settled in ENG-857). A simulation passing the other spelling composes rows that shadow nothing: every simulated resource lands beside its live twin, the diff shows everything as new, and nothing errors. So: read the value off the connector rather than retyping it.

Not in scope

allow-mock-domain as an input (mirroring allow-mock-account only if asked); stack-export scope recovery stays AWS-only.

Verification

action.yml parses; the action's own CI check that every declared input is wired and every used input declared passes locally (undeclared: [], unwired: []). The shell change is the existing if [ -n "$INPUT_X" ]; then args+=(--x "$INPUT_X"); fi line with a new name — shellcheck runs on it in CI.

Note the flag is inert today: --domain only does anything once linro-simulator links plugin-tcloudpublic (ENG-820), which is why this blocks that one rather than trailing it — shipping OTC simulation while CI cannot pass a domain means the first thing a customer tries fails on a flag they cannot reach.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added an optional domain input for T Cloud Public simulations.
    • Domains can be specified using either a 32-character hexadecimal ID or an account name.
    • Simulation scoping now requires the domain value to exactly match the configured connector value.
  • Documentation

    • Clarified preview requirements, provider-value precedence, environment-variable limitations, and literal domain matching behavior.

The action forwarded account, region, project and stack-export one-to-one and
had no `domain`, so an OTC simulation from CI could only reach `--domain`
through `extra-args` — which this action's own comment reserves for flags added
to the CLI after a release, not for a first-class scope value.

And the input alone would not have been enough: nothing customer-facing said
the value exists. The README documented account/region/project and no OTC at
all, so a customer discovered the requirement by hitting a failed submission.

The README now carries the input, the recovery-path table that explains why OTC
needs it more often than AWS needs `account` (one path before the flag, against
three for AWS region and three for AWS account — and only a value WRITTEN in
the provider block reaches the plan, so `OS_DOMAIN_NAME` in the job environment
carries nothing), and the one thing the tooling cannot check: the value is
compared byte for byte against the connector's, case not folded and name not
resolved to id, because a mismatch produces a run that succeeds, shadows
nothing, and describes a world that does not exist.

Not in scope: `allow-mock-domain` as an input.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 5b30bb21-3251-4f59-b8fd-baad81d53eca

📥 Commits

Reviewing files that changed from the base of the PR and between 0d19308 and cca7e13.

📒 Files selected for processing (2)
  • README.md
  • action.yml

Included review availability: Your plan provides up to 5 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

The action adds an optional domain input for T Cloud Public simulations. It documents accepted domain values and scope behavior, then forwards non-empty values to linro-simulator simulate.

Changes

T Cloud Public domain scoping

Layer / File(s) Summary
Domain input contract and scope guidance
action.yml, README.md
The action accepts a 32-hex domain ID or account name. Documentation covers exact connector matching, preview requirements, provider-value precedence, and environment-variable limitations.
Simulator domain forwarding
action.yml
The action maps domain to INPUT_DOMAIN and adds --domain to the simulator command when the value is non-empty.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to cca7e

The optional domain input is reported as consistently declared, mapped, and conditionally forwarded, with no identified merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding a domain input for T Cloud Public scope. The issue reference is relevant and does not obscure the change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Warning

Git: CodeRabbit could not clone the repository, so clone-backed analysis was skipped and this review may be incomplete. Verify repository clone access, such as SSH credentials, before requesting another full review. If clone access is intentionally unavailable, use path_filters to narrow the review scope.


Comment @coderabbitai help to get the list of available commands.

@asciimoo
Adam Tauber (asciimoo) marked this pull request as ready for review September 16, 2026 09:54
@asciimoo
Adam Tauber (asciimoo) merged commit 342ef73 into main Sep 16, 2026
7 checks passed
@asciimoo
Adam Tauber (asciimoo) deleted the adamtauber/eng-821-simulation-github-action-a-domain-input-and-the-customer branch September 16, 2026 09:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant