Skip to content

feat(control-plane): tenant provision orchestration with reliable deprovision - #7544

Closed
jsdevninja wants to merge 2 commits into
JSONbored:mainfrom
jsdevninja:fix/control-plane-deprovision-without-handles
Closed

feat(control-plane): tenant provision orchestration with reliable deprovision#7544
jsdevninja wants to merge 2 commits into
JSONbored:mainfrom
jsdevninja:fix/control-plane-deprovision-without-handles

Conversation

@jsdevninja

Copy link
Copy Markdown
Contributor

Summary

  • Bootstrap control-plane/ with product-agnostic provisionTenant() / deprovisionTenant() behind an injectable TenantProvisioningDriver and fake/in-memory driver (no live Cloudflare/Postgres SDKs).
  • Secrets injection uses a #7174-shaped TenantSecretBroker seam.
  • Fix from closed feat(control-plane): add tenant provision orchestration with fake driver #7539: deprovisionTenant always calls revokeSecrets / destroyDatabase / destroyContainer — when provisioned handles are omitted, IDs are left undefined so the driver tears down by tenant (lost-handle / restart safe). Regression tests assert the driver is actually invoked and live resources are removed.

Closes #7524

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:build
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

N/A — control-plane orchestration library only; no visible UI.

Notes

Made with Cursor

jsdevninja and others added 2 commits July 20, 2026 16:27
@jsdevninja
jsdevninja requested a review from JSONbored as a code owner July 20, 2026 21:28
@codecov

codecov Bot commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.47%. Comparing base (37e7f86) to head (14e765f).
⚠️ Report is 2 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #7544   +/-   ##
=======================================
  Coverage   88.47%   88.47%           
=======================================
  Files         720      720           
  Lines       75733    75733           
  Branches    22547    22548    +1     
=======================================
  Hits        67008    67008           
  Misses       7679     7679           
  Partials     1046     1046           
Flag Coverage Δ
shard-1 33.03% <ø> (-0.01%) ⬇️
shard-2 36.85% <ø> (ø)
shard-3 25.66% <ø> (ø)
shard-4 38.88% <ø> (ø)
shard-5 34.21% <ø> (ø)
shard-6 36.22% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/config/loopover-repo-focus-manifest.ts 100.00% <ø> (ø)

@jsdevninja

Copy link
Copy Markdown
Contributor Author

Superseded by #7543, which already merged #7524 into main.

Rebase onto current upstream/main conflicts because both PRs added a control-plane/ package. Upstream's deprovisionTenant already always calls revokeSecretsdropDatabasedestroyContainer (no optional provisioned handle gate), so the #7539 defect does not exist in the merged code.

Closing this PR rather than force-resolving a duplicate package on top of the merged implementation.

@jsdevninja jsdevninja closed this Jul 20, 2026
@jsdevninja jsdevninja reopened this Jul 20, 2026
@jsdevninja
jsdevninja marked this pull request as draft July 20, 2026 21:40
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 20, 2026
@loopover-orb

loopover-orb Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Caution

🛑 LoopOver review result - reject/close recommended

Review updated: 2026-07-20 21:42:27 UTC

21 files · 1 blocker · CI green · dirty

🛑 Suggested Action - Reject/Close

  • AI review already in progress for this PR head: Another LoopOver pass is already running the AI review for this exact PR head. This pass is skipping to avoid a duplicate LLM call.

Review summary
AI review is already running for this PR head in another LoopOver pass. LoopOver is holding this PR for manual review until that pass completes.

Nits — 1 non-blocking
  • AI review already in progress for this PR head — The gate is held for a human reviewer rather than passed automatically; it re-evaluates once the in-flight review completes or on the next update.

Why this is blocked

  • No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.
📋 Copy for AI agents — paste into your coding agent
Fix the following blocker(s) from this PR review:

1. No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.

Decision drivers

  • ❌ Code review — 1 blocker (No AI review summary)
  • ❌ Gate result — Blocking (Repo-configured hard blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #7539, #7524
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (2 linked issues).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 201 registered-repo PR(s), 125 merged, 38 issue(s).
Contributor context ✅ Confirmed Gittensor contributor jsdevninja; Gittensor profile; 201 PR(s), 38 issue(s).
Improvement ✅ Minor risk: clean · value: minor
Review context
  • Author: jsdevninja
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: not available
  • Official Gittensor activity: 201 PR(s), 38 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Keep the PR focused and include validation evidence before maintainer review.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb

loopover-orb Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

LoopOver is closing this pull request on the maintainer's behalf (conflicts with the base branch — resolve and open a fresh PR; No linked issue detected). This is an automated maintenance action — to pursue this change, please open a new pull request with the issues resolved. Closed PRs may be analyzed later to improve review accuracy, but they are not automatically reopened or re-reviewed.

@loopover-orb loopover-orb Bot closed this Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(control-plane): provisionTenant()/deprovisionTenant() orchestration behind an injectable driver interface (fake driver only)

1 participant