feat(clusters): enforce PayloadSchedulable condition for workerless clusters - #2198
Merged
Merged
Conversation
…nstant On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
….mode On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
…e gating On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
4 tasks
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The bootstrap controller currently forces spec.mode back to Default when the workerless annotation is absent, which can unintentionally override an explicitly set Workerless mode and undermine the safety behavior.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds an explicit “workerless” cluster mode to prevent deploying plugin workloads onto clusters that cannot schedule them (e.g., Gardener etcd-only shoots), by driving cluster conditions and gating plugin reconciliation on those conditions.
Changes:
- Introduces
ClusterSpec.Mode(Default/Workerless) and exposes it via the Cluster CRD. - Updates cluster reconciliation phases to (a) remove
AllNodesReady/Status.Nodesfor workerless clusters and (b) setPayloadSchedulable=Falsewith a workerless-specific reason. - Updates plugin reconciliation (
initClientGetter) to block Helm release creation when the target cluster’sPayloadSchedulableisFalse, and adds unit tests for the new gating behavior.
File summaries
| File | Description |
|---|---|
api/v1alpha1/cluster_types.go |
Adds ClusterMode enum, spec.mode, and WorkerlessClusterReason. |
charts/manager/crds/greenhouse.sap_clusters.yaml |
Extends CRD schema with spec.mode (enum + default). |
api/well_known.go |
Adds greenhouse.sap/workerless annotation constant for secrets. |
internal/controller/cluster/bootstrap_controller.go |
Sets cluster.spec.mode based on the secret annotation. |
internal/controller/cluster/phases/ensure_nodes_ready.go |
Skips node readiness condition/status for workerless clusters. |
internal/controller/cluster/phases/ensure_workload_schedulable.go |
Forces PayloadSchedulable=False for workerless clusters. |
internal/controller/cluster/phases/phases_test.go |
Adds unit tests for workerless phase behavior. |
internal/controller/plugin/util.go |
Blocks client init / Helm release creation when PayloadSchedulable=False. |
internal/controller/plugin/util_test.go |
Adds unit tests for the new PayloadSchedulable gating. |
api/v1alpha1/plugin_types.go |
Adds ClusterPayloadNotSchedulableReason for plugin condition reporting. |
pkg/mocks/mock_Reconciler.go |
Import alias adjustment for controller-runtime in generated mocks. |
Review details
Files not reviewed (1)
- pkg/mocks/mock_Reconciler.go: Generated file
- Files reviewed: 12/13 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
…use it once On-behalf-of: @SAP krzysztof.zagorski@sap.com Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
abhijith-darshan
approved these changes
Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Introduces
ClusterMode(Default/Workerless) to the Cluster API and wires it through the cluster and plugin controllers to prevent Helm releases from being deployed to clusters that cannot schedule workloads.When a Cluster secret has the
greenhouse.sap/workerlessannotation, the bootstrap controller setsspec.mode=Workerlesson the Cluster. The cluster controller then setsPayloadSchedulable=Falseon that cluster and skips theAllNodesReadycondition, since workerless clusters have no worker nodes. Finally, the plugin controller checksPayloadSchedulablebefore deploying a Helm release and blocks deployment if it isFalse.The
greenhouse.sap/workerlessannotation on the Cluster secret is set by shoot-grafter in cloudoperators/shoot-grafter#79.What type of PR is this? (check all applicable)
Related Tickets & Documents
Added tests?
Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration
Added to documentation?
Checklist