Greenfield: Implement direct KRM types, CRD, and identity for WebSecurityScannerScanConfig - #13640
lovelace-coder-bot wants to merge 1 commit into
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
🤖 AI Factory started investigating CI check failures for this pull request. Note: We recommend waiting for the 'ready-for-human' label before leaving review comments. Comments added while the system is actively working may be associated with outdated commits once a new commit is pushed, causing them to be ignored. |
fb907a4 to
2d40d99
Compare
Investigating unit-tests-operator failureRun: 36954747533 (This report was generated by overseer) |
|
🤖 AI Factory started reviewing this pull request in a sandbox. |
reviewbot-robot
left a comment
There was a problem hiding this comment.
KCC Auto-Review Results
- Trigger criteria matched: Yes
- API Version Check: Pass -
apis/websecurityscanner/v1alpha1/,v1alpha1used in CRD manifests. - Go Type Pointers: Pass - All scalar primitive fields in spec and manual types use pointer types (
*string,*bool,*int32), while collections are non-pointer slices. - Completeness & Heuristics: Pass - 100% field coverage against
google.cloud.websecurityscanner.v1.ScanConfig. Output-onlymanaged_scanis correctly placed underObservedState. - 1:1 Kind to Proto Mapping: Pass -
WebSecurityScannerScanConfigmaps 1:1 toScanConfig. - References/Identity: Pass -
ProjectRefreferences the parent project,Passwordfields use*refsv1beta1secret.Legacy, andIdentityV2implementation follows canonicalgcpurls.Template. - Exception Files: Pass - Only
tests/apichecks/testdata/exceptions/alpha-missingfields.txtis updated.
Detailed Findings / Actions Required:
- Update copyright year to
2026inapis/websecurityscanner/v1alpha1/doc.goandapis/websecurityscanner/v1alpha1/groupversion_info.go.
| @@ -0,0 +1,16 @@ | |||
| // Copyright 2025 Google LLC | |||
There was a problem hiding this comment.
Copyright year for newly added files should be 2026 (// Copyright 2026 Google LLC).
| @@ -0,0 +1,33 @@ | |||
| // Copyright 2025 Google LLC | |||
There was a problem hiding this comment.
Copyright year for newly added files should be 2026 (// Copyright 2026 Google LLC).
|
🤖 AI Factory started addressing review feedback for this pull request. |
…rityScannerScanConfig Implement the initial KRM types, CRD generation script, and IdentityV2 for WebSecurityScannerScanConfig (websecurityscanner.cnrm.cloud.google.com/v1alpha1). Issue: 10318
2d40d99 to
a872a2f
Compare
|
Addressed review feedback:
(This comment was generated by overseer) |
|
🤖 AI Factory started investigating CI check failures for this pull request. Note: We recommend waiting for the 'ready-for-human' label before leaving review comments. Comments added while the system is actively working may be associated with outdated commits once a new commit is pushed, causing them to be ignored. |
Investigating tests-e2e-direct-iam failureRun: 36968573606 (This report was generated by overseer) |
|
🤖 AI Factory started reviewing this pull request in a sandbox. |
reviewbot-robot
left a comment
There was a problem hiding this comment.
KCC Auto-Review Results
- Trigger criteria matched: Yes
- API Version Check: Pass - Resource types placed under
apis/websecurityscanner/v1alpha1/and CRD version isv1alpha1. - Go Type Pointers: Pass - All scalar primitive fields in Go types are defined as pointers.
- Completeness & Heuristics: Pass - 100% field coverage against
google.cloud.websecurityscanner.v1.ScanConfig. Output-onlymanaged_scanis correctly placed inObservedState, and sensitive password fields properly use*refsv1beta1secret.Legacy. - 1:1 Kind to Proto Mapping: Pass -
WebSecurityScannerScanConfigmaps 1:1 to proto messagegoogle.cloud.websecurityscanner.v1.ScanConfig. - References/Identity: Pass - Resource correctly implements
IdentityV2,ProjectRef, and external URL formatprojects/{project}/scanConfigs/{scan_config}. - Exception Files: Pass - Only
tests/apichecks/testdata/exceptions/alpha-missingfields.txtwas modified.
Detailed Findings / Actions Required:
None. The changes satisfy all review criteria for Greenfield new types.
|
🤖 AI Factory started addressing review feedback for this pull request. |
|
All review criteria are satisfied and all CI checks are passing cleanly. Ready for reviewer/owner approval. (This comment was generated by overseer) |
Description
This PR implements direct KRM types, CRD, and IdentityV2 for the greenfield resource
WebSecurityScannerScanConfig(websecurityscanner.cnrm.cloud.google.com/v1alpha1).Key Changes
WebSecurityScannerScanConfigCRD types andWebSecurityScannerScanConfigObservedStateinapis/websecurityscanner/v1alpha1/websecurityscannerscanconfig_types.go.ScanConfig_Authentication_CustomAccountandScanConfig_Authentication_GoogleAccountinto manual types to handlePasswordusing*refsv1beta1secret.Legacyfor secret reference support and sensitive data compliance.managedScanunderObservedStateas it is an output-only field.WebSecurityScannerScanConfigIdentityfor URL templateprojects/{project}/scanConfigs/{scan_config}inapis/websecurityscanner/v1alpha1/websecurityscannerscanconfig_identity.go.apis/websecurityscanner/v1alpha1/websecurityscannerscanconfig_identity_test.go.apis/websecurityscanner/generate.sh..gemini/journals/websecurityscanner.md.Fixes #10318
Triggered by .agents/greenfield-direct-new-resource-types.md
This PR was generated by the overseer,priority/medium,area/direct,step/gen-types,greenfield,chore/ai,overseer/review agent (powered by the gemini-3.7-flash model).