Skip to content

feat(clusters): enforce PayloadSchedulable condition for workerless clusters - #2198

Merged
Zaggy21 merged 27 commits into
mainfrom
feat/enforce-payloadschedulable-condition-check
Sep 18, 2026
Merged

Zaggy21 merged 27 commits into
mainfrom
feat/enforce-payloadschedulable-condition-check

Conversation

@Zaggy21

@Zaggy21 Zaggy21 commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Description

Introduces ClusterMode (Default/Workerless) to the Cluster API and wires it through the cluster and plugin controllers to prevent Helm releases from being deployed to clusters that cannot schedule workloads.

When a Cluster secret has the greenhouse.sap/workerless annotation, the bootstrap controller sets spec.mode=Workerless on the Cluster. The cluster controller then sets PayloadSchedulable=False on that cluster and skips the AllNodesReady condition, since workerless clusters have no worker nodes. Finally, the plugin controller checks PayloadSchedulable before deploying a Helm release and blocks deployment if it is False.

The greenhouse.sap/workerless annotation on the Cluster secret is set by shoot-grafter in cloudoperators/shoot-grafter#79.

What type of PR is this? (check all applicable)

  • 🍕 Feature
  • 🐛 Bug Fix
  • 📝 Documentation Update
  • 🎨 Style
  • 🧑‍💻 Code Refactor
  • 🔥 Performance Improvements
  • ✅ Test
  • 🤖 Build
  • 🔁 CI
  • 📦 Chore (Release)
  • ⏩ Revert

Related Tickets & Documents

Added tests?

  • 👍 yes
  • 🙅 no, because they aren't needed
  • 🙋 no, because I need help
  • Separate ticket for tests # (issue/pr)

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration

Added to documentation?

  • 📜 README.md
  • 🤝 Documentation pages updated
  • 🙅 no documentation needed
  • (if applicable) generated OpenAPI docs for CRD changes

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • My changes generate no new warnings
  • New and existing unit tests pass locally with my changes

…nstant

On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
….mode

On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
…e gating

On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
Copilot AI lite review requested due to automatic review settings September 7, 2026 22:06
@Zaggy21
Zaggy21 requested a review from a team as a code owner September 7, 2026 22:06
@Zaggy21 Zaggy21 linked an issue Sep 7, 2026 that may be closed by this pull request
4 tasks
@Zaggy21 Zaggy21 changed the title feat(cluster): enforce PayloadSchedulable condition for workerless clusters feat(clusters): enforce PayloadSchedulable condition for workerless clusters Sep 7, 2026
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The bootstrap controller currently forces spec.mode back to Default when the workerless annotation is absent, which can unintentionally override an explicitly set Workerless mode and undermine the safety behavior.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds an explicit “workerless” cluster mode to prevent deploying plugin workloads onto clusters that cannot schedule them (e.g., Gardener etcd-only shoots), by driving cluster conditions and gating plugin reconciliation on those conditions.

Changes:

  • Introduces ClusterSpec.Mode (Default / Workerless) and exposes it via the Cluster CRD.
  • Updates cluster reconciliation phases to (a) remove AllNodesReady/Status.Nodes for workerless clusters and (b) set PayloadSchedulable=False with a workerless-specific reason.
  • Updates plugin reconciliation (initClientGetter) to block Helm release creation when the target cluster’s PayloadSchedulable is False, and adds unit tests for the new gating behavior.
File summaries
File Description
api/v1alpha1/cluster_types.go Adds ClusterMode enum, spec.mode, and WorkerlessClusterReason.
charts/manager/crds/greenhouse.sap_clusters.yaml Extends CRD schema with spec.mode (enum + default).
api/well_known.go Adds greenhouse.sap/workerless annotation constant for secrets.
internal/controller/cluster/bootstrap_controller.go Sets cluster.spec.mode based on the secret annotation.
internal/controller/cluster/phases/ensure_nodes_ready.go Skips node readiness condition/status for workerless clusters.
internal/controller/cluster/phases/ensure_workload_schedulable.go Forces PayloadSchedulable=False for workerless clusters.
internal/controller/cluster/phases/phases_test.go Adds unit tests for workerless phase behavior.
internal/controller/plugin/util.go Blocks client init / Helm release creation when PayloadSchedulable=False.
internal/controller/plugin/util_test.go Adds unit tests for the new PayloadSchedulable gating.
api/v1alpha1/plugin_types.go Adds ClusterPayloadNotSchedulableReason for plugin condition reporting.
pkg/mocks/mock_Reconciler.go Import alias adjustment for controller-runtime in generated mocks.
Review details

Files not reviewed (1)

  • pkg/mocks/mock_Reconciler.go: Generated file
  • Files reviewed: 12/13 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/controller/cluster/bootstrap_controller.go Outdated
Comment thread api/v1alpha1/cluster_types.go Outdated
Comment thread api/v1alpha1/cluster_types.go Outdated
Comment thread api/well_known.go Outdated
Comment thread api/well_known.go Outdated
Comment thread api/well_known.go Outdated
Comment thread internal/controller/cluster/bootstrap_controller.go Outdated
Comment thread internal/controller/cluster/phases/phases_test.go Outdated
Comment thread pkg/mocks/mock_Reconciler.go Outdated
Zaggy21 and others added 2 commits September 8, 2026 16:26
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
Comment thread internal/controller/cluster/phases/phases_test.go
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
Comment thread internal/controller/cluster/phases/phases_test.go Outdated
Comment thread internal/controller/plugin/util_test.go Outdated
Zaggy21 and others added 5 commits September 15, 2026 22:54
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
…use it once

On-behalf-of: @SAP krzysztof.zagorski@sap.com
Signed-off-by: Zaggy21 <k.zaggy@gmail.com>
@Zaggy21
Zaggy21 merged commit cdde51b into main Sep 18, 2026
28 checks passed
@Zaggy21
Zaggy21 deleted the feat/enforce-payloadschedulable-condition-check branch September 18, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core-apis documentation Improvements or additions to documentation feature helm-charts size/L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FEAT] - Enforce PayloadSchedulable condition check in Plugin controller

4 participants