Skip to content

DocumentAIProcessor: Migrate KMSCryptoKeyRef to kmsv1beta1 and normalize references #13612

Description

@anhdle-sso

Overview

Migrate KMS key reference(s) from the legacy unstructured refs.KMSCryptoKeyRef (apis/refs/v1beta1.KMSCryptoKeyRef) to the typed kmsv1beta1.KMSCryptoKeyRef (apis/kms/v1beta1.KMSCryptoKeyRef), and ensure common.NormalizeReferences is called during controller reconciliation.


Problem Description

  1. Missing refs.Ref interface implementation:
    The current API definition in apis/documentai/v1alpha1/documentaiprocessor_types.go uses *refs.KMSCryptoKeyRef for spec.kmsKeyRef. This legacy reference type does not implement the refs.Ref interface and cannot be automatically resolved by KCC's reference normalization mechanism.

  2. Missing reference normalization in controller:
    In pkg/controller/direct/documentai/documentaiprocessor_controller.go, AdapterForObject does not invoke common.NormalizeReferences(ctx, reader, obj, nil). As a result, references configured via name or namespace (instead of explicit external string) are not resolved to their canonical GCP external format before constructing desired GCP API protos, leading to reconciliation errors or diff discrepancies.


Proposed Changes

  1. Update API Types:

  2. Update Direct Controller:

  3. Regenerate Code & CRDs:

    • Run dev/tasks/generate-types-and-mappers (and make fmt).
  4. Testing:

    • Verify existing tests pass and add/update test cases referencing KMS keys to ensure reference resolution works as expected.

Affected Files & Fields

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions