Skip to content

Greenfield: Implement direct KRM types, CRD, and identity for WebSecurityScannerScanConfig - #13640

Open
lovelace-coder-bot wants to merge 1 commit into
GoogleCloudPlatform:masterfrom
lovelace-coder-bot:issue-10318-1790896780
Open

lovelace-coder-bot wants to merge 1 commit into
GoogleCloudPlatform:masterfrom
lovelace-coder-bot:issue-10318-1790896780

Conversation

@lovelace-coder-bot

Copy link
Copy Markdown
Collaborator

Description

This PR implements direct KRM types, CRD, and IdentityV2 for the greenfield resource WebSecurityScannerScanConfig (websecurityscanner.cnrm.cloud.google.com/v1alpha1).

Key Changes

  1. KRM Types:
    • Added WebSecurityScannerScanConfig CRD types and WebSecurityScannerScanConfigObservedState in apis/websecurityscanner/v1alpha1/websecurityscannerscanconfig_types.go.
    • Moved ScanConfig_Authentication_CustomAccount and ScanConfig_Authentication_GoogleAccount into manual types to handle Password using *refsv1beta1secret.Legacy for secret reference support and sensitive data compliance.
    • Configured managedScan under ObservedState as it is an output-only field.
  2. Identity:
    • Implemented WebSecurityScannerScanConfigIdentity for URL template projects/{project}/scanConfigs/{scan_config} in apis/websecurityscanner/v1alpha1/websecurityscannerscanconfig_identity.go.
    • Added unit tests in apis/websecurityscanner/v1alpha1/websecurityscannerscanconfig_identity_test.go.
  3. Scaffolding:
    • Created apis/websecurityscanner/generate.sh.
    • Generated CRD YAML manifests, supported GVKs, and deepcopy functions.
  4. Journal:
    • Added learning and design notes to .gemini/journals/websecurityscanner.md.

Fixes #10318

NONE

Triggered by .agents/greenfield-direct-new-resource-types.md


This PR was generated by the overseer,priority/medium,area/direct,step/gen-types,greenfield,chore/ai,overseer/review agent (powered by the gemini-3.7-flash model).

@google-oss-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign justinsb for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@argus-watcher-bot

Copy link
Copy Markdown
Collaborator

🤖 AI Factory started investigating CI check failures for this pull request.

Note: We recommend waiting for the 'ready-for-human' label before leaving review comments. Comments added while the system is actively working may be associated with outdated commits once a new commit is pushed, causing them to be ignored.

@lovelace-coder-bot

Copy link
Copy Markdown
Collaborator Author

Investigating unit-tests-operator failure

Run: 36954747533
Name: unit-tests-operator
Cause: Test Failure
Details: The operator golden test TestGoldenConfigConnector/simple failed because operator/pkg/controllers/configconnector/testdata/golden/simple/_expected.yaml was missing the newly generated RBAC rules for the websecurityscanner.cnrm.cloud.google.com API group.
Action Taken: Regenerated operator golden test fixtures with WRITE_GOLDEN_OUTPUT=1 ./dev/ci/presubmits/unit-tests-operator, verified tests pass locally, amended the commit, and pushed the update to the PR branch.

(This report was generated by overseer)

@argus-watcher-bot

Copy link
Copy Markdown
Collaborator

🤖 AI Factory started reviewing this pull request in a sandbox.

@reviewbot-robot reviewbot-robot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

KCC Auto-Review Results

  • Trigger criteria matched: Yes
  • API Version Check: Pass - apis/websecurityscanner/v1alpha1/, v1alpha1 used in CRD manifests.
  • Go Type Pointers: Pass - All scalar primitive fields in spec and manual types use pointer types (*string, *bool, *int32), while collections are non-pointer slices.
  • Completeness & Heuristics: Pass - 100% field coverage against google.cloud.websecurityscanner.v1.ScanConfig. Output-only managed_scan is correctly placed under ObservedState.
  • 1:1 Kind to Proto Mapping: Pass - WebSecurityScannerScanConfig maps 1:1 to ScanConfig.
  • References/Identity: Pass - ProjectRef references the parent project, Password fields use *refsv1beta1secret.Legacy, and IdentityV2 implementation follows canonical gcpurls.Template.
  • Exception Files: Pass - Only tests/apichecks/testdata/exceptions/alpha-missingfields.txt is updated.

Detailed Findings / Actions Required:

  1. Update copyright year to 2026 in apis/websecurityscanner/v1alpha1/doc.go and apis/websecurityscanner/v1alpha1/groupversion_info.go.
Comment thread apis/websecurityscanner/v1alpha1/doc.go Outdated
@@ -0,0 +1,16 @@
// Copyright 2025 Google LLC

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copyright year for newly added files should be 2026 (// Copyright 2026 Google LLC).

@@ -0,0 +1,33 @@
// Copyright 2025 Google LLC

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copyright year for newly added files should be 2026 (// Copyright 2026 Google LLC).

@argus-watcher-bot

Copy link
Copy Markdown
Collaborator

🤖 AI Factory started addressing review feedback for this pull request.

…rityScannerScanConfig

Implement the initial KRM types, CRD generation script, and IdentityV2 for
WebSecurityScannerScanConfig (websecurityscanner.cnrm.cloud.google.com/v1alpha1).

Issue: 10318
@lovelace-coder-bot

Copy link
Copy Markdown
Collaborator Author

Addressed review feedback:

  • Updated the copyright header year to 2026 in apis/websecurityscanner/v1alpha1/doc.go and apis/websecurityscanner/v1alpha1/groupversion_info.go.
  • Validated generated files and operator unit tests pass cleanly.

(This comment was generated by overseer)

@argus-watcher-bot

Copy link
Copy Markdown
Collaborator

🤖 AI Factory started investigating CI check failures for this pull request.

Note: We recommend waiting for the 'ready-for-human' label before leaving review comments. Comments added while the system is actively working may be associated with outdated commits once a new commit is pushed, causing them to be ignored.

@lovelace-coder-bot

Copy link
Copy Markdown
Collaborator Author

Investigating tests-e2e-direct-iam failure

Run: 36968573606
Name: tests-e2e-direct-iam
Cause: Flake
Details: The job failed with fork/exec /home/runner/work/k8s-config-connector/k8s-config-connector/.build/envtest-bin/etcd: text file busy during envtest control plane startup in pkg/test/resourcefixture/testdata/basic/iam/v1beta1/iamserviceaccount/iamserviceaccount. This is a transient concurrency flake when initializing envtest control planes in parallel and is unrelated to the changes in this PR.
Action Taken: Triggered a rerun of the failed workflow job with gh run rerun 36968573606 --failed.

(This report was generated by overseer)

@argus-watcher-bot

Copy link
Copy Markdown
Collaborator

🤖 AI Factory started reviewing this pull request in a sandbox.

@reviewbot-robot reviewbot-robot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

KCC Auto-Review Results

  • Trigger criteria matched: Yes
  • API Version Check: Pass - Resource types placed under apis/websecurityscanner/v1alpha1/ and CRD version is v1alpha1.
  • Go Type Pointers: Pass - All scalar primitive fields in Go types are defined as pointers.
  • Completeness & Heuristics: Pass - 100% field coverage against google.cloud.websecurityscanner.v1.ScanConfig. Output-only managed_scan is correctly placed in ObservedState, and sensitive password fields properly use *refsv1beta1secret.Legacy.
  • 1:1 Kind to Proto Mapping: Pass - WebSecurityScannerScanConfig maps 1:1 to proto message google.cloud.websecurityscanner.v1.ScanConfig.
  • References/Identity: Pass - Resource correctly implements IdentityV2, ProjectRef, and external URL format projects/{project}/scanConfigs/{scan_config}.
  • Exception Files: Pass - Only tests/apichecks/testdata/exceptions/alpha-missingfields.txt was modified.

Detailed Findings / Actions Required:

None. The changes satisfy all review criteria for Greenfield new types.

@argus-watcher-bot

Copy link
Copy Markdown
Collaborator

🤖 AI Factory started addressing review feedback for this pull request.

@lovelace-coder-bot

Copy link
Copy Markdown
Collaborator Author

All review criteria are satisfied and all CI checks are passing cleanly. Ready for reviewer/owner approval.

(This comment was generated by overseer)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment