Commit 5bb11f0
feat: Tier 3 cross-pollination - PaperclipClusterDefaults + PaperclipSelfConfig CRDs + Tailscale sidecar (#68)
* feat(clusterdefaults): add cluster-scoped PaperclipClusterDefaults CRD
Add a cluster-scoped singleton (name must be "cluster") that supplies
org-wide defaults merged into every Instance at reconcile time. The merge
happens in-memory only; the user's stored spec in etcd is never overwritten
and per-instance fields always win.
Defaults cover image, storage class, database mode, observability, networking
Service type, and shared env vars (merged by Name, instance entries win). The
Instance reconciler fetches the singleton, applies ApplyClusterDefaults before
rendering owned resources, and watches the singleton to re-reconcile Instances.
A dedicated PaperclipClusterDefaults controller validates the singleton name
and surfaces a Ready/InvalidName condition. Also wires the cross-cutting
generated artifacts (manifests, deepcopy, chart CRDs, RBAC, samples, docs) and
adds the spec fields and controller registration shared by the Tier 3 work.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(selfconfig): add agent-driven PaperclipSelfConfig CRD applied via SSA
Add a namespaced PaperclipSelfConfig CRD that lets the Paperclip app request
changes to its own parent Instance (addPlugins/removePlugins, patchConfig,
addEnvVars/removeEnvVars). Requests are gated by the parent Instance's
spec.selfConfigure allowlist (enabled + allowedActions) and a set of protected
config keys and protected env vars so an agent cannot touch auth, secrets,
database, or operator-managed env.
Approved changes are applied to the Instance via Server-Side Apply with a
dedicated field manager ("paperclip-selfconfig") so GitOps controllers do not
flap over the agent-owned fields. The controller records audit events, sets a
terminal Pending/Applied/Failed/Denied phase, owns the request via an owner
reference, and TTL-reaps completed requests after one hour.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(tailscale): add ephemeral Tailscale sidecar that Serves the app
Add spec.tailscale (enabled, mode=serve|funnel, image, authKey.secretRef,
hostname) and an ephemeral userspace Tailscale sidecar that Serves the
Paperclip app (port 3100) over the tailnet via TS_SERVE_CONFIG. The node runs
with --ephemeral so it is removed from the tailnet when the pod is deleted, and
the sidecar runs with a read-only root filesystem and all capabilities dropped.
The serve config is rendered into a managed ConfigMap and mounted into the
sidecar; funnel mode additionally sets AllowFunnel. The Instance reconciler
provisions the ConfigMap (surfacing a TailscaleReady condition) and the
NetworkPolicy gains STUN (3478/udp) and WireGuard (41641/udp) egress when
Tailscale is enabled (443/tcp for DERP/control is already allowed).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 97b9d0f commit 5bb11f0
38 files changed
Lines changed: 4665 additions & 2 deletions
File tree
- api/v1alpha1
- charts/paperclip-operator/templates
- crds
- cmd
- config
- crd
- bases
- rbac
- samples
- docs
- internal
- controller
- resources
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
23 | 41 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
76 | 81 | | |
77 | 82 | | |
78 | 83 | | |
| |||
135 | 140 | | |
136 | 141 | | |
137 | 142 | | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
138 | 148 | | |
139 | 149 | | |
140 | 150 | | |
| |||
582 | 592 | | |
583 | 593 | | |
584 | 594 | | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
585 | 661 | | |
586 | 662 | | |
587 | 663 | | |
| |||
0 commit comments