Skip to content

Initial user stanza support & architecture review - #7

Open
navaneeth-dev wants to merge 19 commits into
mainfrom
feat/users
Open

navaneeth-dev wants to merge 19 commits into
mainfrom
feat/users

Conversation

@navaneeth-dev

Copy link
Copy Markdown
Collaborator

Summary

  • add the bt Cobra CLI for converting cloud-config YAML to Butane YAML
  • support the initial Cluster API worker users subset: name, password hash, GECOS, home directory, shell, and SSH authorized keys
  • reject unsupported or malformed input instead of silently producing a partial conversion
  • preserve cloud-init's default locked-password behavior
  • document the supported fields and current limitations
  • Added GitHub Actions CI for unit testing, will add QEMU tests soon

Testing

  • validated generated output with Butane v0.29.0 in strict mode
  • booted Flatcar Stable under QEMU/KVM and verified SSH login, GECOS, custom home directory, shell, locked password, and authorized key provisioning

Signed-off-by: Navaneeth <me@rizexor.com>
Signed-off-by: Navaneeth <me@rizexor.com>
Signed-off-by: Navaneeth <me@rizexor.com>
Signed-off-by: Navaneeth <me@rizexor.com>
Signed-off-by: Navaneeth <me@rizexor.com>
Signed-off-by: Navaneeth <me@rizexor.com>
Signed-off-by: Navaneeth <me@rizexor.com>
@navaneeth-dev navaneeth-dev self-assigned this Sep 17, 2026
@navaneeth-dev
navaneeth-dev requested a review from a team as a code owner September 17, 2026 14:41
@navaneeth-dev
navaneeth-dev requested review from elmiko and tormath1 and a lite review from Copilot September 17, 2026 14:41

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are cohesive, well-tested with clear rejection semantics, and CI is in place to enforce build/vet/test for the new CLI and transpiler logic.

Pull request overview

Adds an initial bt CLI and a strict cloud-config → Butane transpiler focused on the Cluster API worker users subset, with validation and unit tests, aligning with the repo’s goal of a minimal but correct conversion path for Cluster API provisioning.

Changes:

  • Introduce a Cobra-based bt CLI that reads cloud-config from a file or stdin and writes Butane YAML to stdout or an output file (atomic write).
  • Implement strict transpilation for the supported users subset, rejecting unsupported fields, YAML aliases/anchors, multiple documents, and missing #cloud-config headers, and validating the generated Butane via butane.TranslateBytes.
  • Add unit tests plus fixture documentation and GitHub Actions CI for build/vet/test.
File summaries
File Description
README.md Documents bt usage, supported users fields, and current limitations.
main.go Adds the bt Cobra CLI, input handling, and atomic output writing.
main_test.go Tests CLI stdin→stdout behavior and output file permissions.
internal/transpile/transpile.go Implements strict parsing/validation and Butane generation + validation.
internal/transpile/users.go Parses and validates the supported users fields and maps them to Butane passwd.users.
internal/transpile/transpile_test.go Adds fixture-driven unit tests for success and rejection cases.
internal/transpile/testdata/README.md Documents the provenance and purpose of fixtures.
internal/transpile/testdata/cluster-api-supported-user.yaml Success fixture covering supported users fields.
internal/transpile/testdata/cluster-api-groups.yaml Rejection fixture for groups-related fields.
internal/transpile/testdata/cluster-api-deferred-fields.yaml Rejection fixture for deferred/unsupported account-policy fields.
go.mod Introduces module definition and dependencies.
go.sum Adds dependency checksums.
.github/workflows/ci.yml Adds CI workflow to build, vet, and test on push/PR.
Review details
  • Files reviewed: 12/13 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

The standalone Butane module is deprecated. Use the public Butane
packages shipped in Ignition v2.27.0 and raise the Go version to the
dependency's required Go 1.25.

Signed-off-by: Navaneeth <me@rizexor.com>
Copilot AI review requested due to automatic review settings September 17, 2026 15:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The Jinja template rejection logic can be bypassed when the directive appears after #cloud-config, contradicting the documented “rejected” behavior.

Review details

Suppressed comments (1)

Previously missed (1) — in code that hasn't changed since the last review.

internal/transpile/transpile.go:104

  • validateCloudConfigHeader() returns as soon as it sees #cloud-config, so a ## template: jinja line that appears after the header would not be rejected even though the README states Jinja templates are rejected. This can lead to silently accepting templated configs depending on directive placement.
  • Files reviewed: 12/13 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@elmiko elmiko left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think this is looking nice for an initial configuration. i have a question about the combined error return from the Transpile function.

also, i'm curious if you plan to make a test file for the users.go, or will it be tested through the transpile_test.go ?

Comment thread transpile.go
Represent validation failures as typed problems so callers can inspect
paths and source locations without parsing the human-readable error
message.

Signed-off-by: Navaneeth <me@rizexor.com>
@navaneeth-dev

Copy link
Copy Markdown
Collaborator Author

Refactored to users_test.go and future stanzas will also be done like this.

Keep document-level checks in transpile_test.go and group user-specific
behavior in users_test.go while preserving the public Transpile test seam.

Signed-off-by: Navaneeth <me@rizexor.com>
@navaneeth-dev

Copy link
Copy Markdown
Collaborator Author

Is there a public Go lib to validate Butane? Currently using https://pkg.go.dev/github.com/coreos/ignition but last update is 2 years back?

Copilot AI review requested due to automatic review settings September 18, 2026 14:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Signed-off-by: Navaneeth <me@rizexor.com>
Update the shared fixture helper after testdata was renamed to testcases so
users tests resolve the existing fixture files again.

Signed-off-by: Navaneeth <me@rizexor.com>
Copilot AI review requested due to automatic review settings September 18, 2026 14:43

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@elmiko

elmiko commented Sep 18, 2026

Copy link
Copy Markdown
Collaborator

Is there a public Go lib to validate Butane? Currently using https://pkg.go.dev/github.com/coreos/ignition but last update is 2 years back?

that's a good question, i'm not sure. perhaps @tormath1 knows?

@elmiko elmiko left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think this is looking good, no further comments from my side.

/lgtm

@tormath1

tormath1 commented Sep 21, 2026 •

Copy link
Copy Markdown

Is there a public Go lib to validate Butane? Currently using https://pkg.go.dev/github.com/coreos/ignition but last update is 2 years back?

Given the very recent merge of Butane into Ignition (https://github.com/coreos/ignition/pull/2235/changes#diff-fe44f09c4d5977b5f5eaea29170b6a0748819c9d02271746a20d81a5f3efca17R18), I think the best way to proceed is to import the module as:

 "github.com/coreos/ignition/v2/butane/config"

As you actually did, you need to add 'v2' suffix to your link to get the current doc: https://pkg.go.dev/github.com/coreos/ignition/v2

@tormath1 tormath1 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, it looks good for a first iteration. :)

Comment thread transpile.go
Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/workflows/ci.yml
Comment thread internal/transpile/transpile.go Outdated
Comment thread internal/transpile/transpile.go Outdated
Comment thread internal/transpile/transpile.go Outdated
Comment thread internal/transpile/transpile.go Outdated
Comment thread internal/transpile/users.go Outdated
Co-authored-by: Mathieu Tortuyaux <mathieu.tortuyaux@gmail.com>
Signed-off-by: Navaneeth Rao <me@rizexor.com>
Copilot AI review requested due to automatic review settings September 23, 2026 13:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Co-authored-by: Mathieu Tortuyaux <mathieu.tortuyaux@gmail.com>
Signed-off-by: Navaneeth Rao <me@rizexor.com>
Copilot AI review requested due to automatic review settings September 23, 2026 13:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Move the library from internal/transpile to the module root so Cluster API
and other consumers can import it. Move the bt executable to cmd/bt and
keep fixtures with the root package tests.

Signed-off-by: Navaneeth <me@rizexor.com>
Use Go 1.27 for local builds and CI through the version declared in
go.mod.

Signed-off-by: Navaneeth <me@rizexor.com>
Build output with the Ignition v2 Flatcar and passwd types. Use the YAML
zero-value omission option to avoid emitting unsupported empty sections.

Signed-off-by: Navaneeth <me@rizexor.com>
Inspect only the first input line because Jinja, cloud-config, and invalid
input exhaust the supported header states. Cover a leading blank line as
an invalid header.

Signed-off-by: Navaneeth <me@rizexor.com>
Check dependency sources into vendor and force CI build, vet, and test
commands to use them without downloading modules.

Signed-off-by: Navaneeth <me@rizexor.com>
Copilot AI review requested due to automatic review settings September 23, 2026 16:11

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@navaneeth-dev

Copy link
Copy Markdown
Collaborator Author

Done

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants