• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

opendefensecloud / artifact-conduit / 35337656786
86%

Build:
DEFAULT BRANCH: main
Ran 18 Sep 2026 11:12AM UTC
Jobs 1
Files 16
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

18 Sep 2026 11:02AM UTC coverage: 85.818% (+0.3%) from 85.504%
35337656786

push

github

web-flow
feat: report endpoint status and probe target connectivity (#482)

## What
`Endpoint` status extended by validity plus an active connection test,
populated by a controller and exposed through the `endpoints/status`
subresource.
Closes #442 

## Why
`EndpointStatus` was an empty struct with no subresource, so a consumer
had no way to tell a good Endpoint from a bad one until an Order failed.
Probe now answers the status question before an Order is ever placed.

## Testing
- `make test`: added new unit and integration (envtest) tests
- Manual, against local dev-cluster, using `examples/endpoint-status/` —
all eight demo Endpoints reach their expected verdict, including SSRF
refusal of `0.0.0.0` and a real Bearer-token rejection from `ghcr.io`

## Notes for reviewers
**API.** `EndpointStatus` gains `conditions`, `observedGeneration`,
`lastProbeTime`. Additive; the struct was empty. Printer columns
`READY`/`MESSAGE` are derived from the conditions at table-conversion
time, status deliberately stores no `phase`/`message` field, so there is
one source of truth.

**RBAC.** New rule for `endpoints/status` (`get;update;patch`). The base
`endpoints` rule is unchanged at `get;list;watch` — the reconciler's
only write is `Status().Update()`.

**New watches.** The controller watches `Secret` cluster-wide (to
re-probe on credential rotation) and
`ArtifactType`/`ClusterArtifactType` (so an unknown type clears itself
when the type appears). The Secret watch means the manager caches
Secrets it can read; narrowable with a label selector if that becomes a
memory concern.

**Security.** The controller-manager now reads a Secret's
`username`/`password` and sends them to a URL chosen by whoever wrote
the Endpoint. **`create` on `endpoints` must therefore be authorized as
if it were `get` on Secrets in the same namespace.** ARC previously only
ever passed Secret *names* into workflow parameters and never read their
contents. The probe refuses loopback, link-local and unspec... (continued)

496 of 577 new or added lines in 5 files covered. (85.96%)

1543 of 1798 relevant lines covered (85.82%)

2135.29 hits per line

Uncovered Changes

Lines Coverage ∆ File
36
85.94
pkg/controller/endpoint_controller.go
18
84.62
pkg/endpointprobe/auth.go
14
88.8
pkg/endpointprobe/probe.go
7
94.4
-5.6% pkg/metrics/collector.go
6
88.24
pkg/endpointprobe/dial.go
Jobs
ID Job ID Ran Files Coverage
1 35337656786.1 18 Sep 2026 11:12AM UTC 16
85.82
GitHub Action Run
Source Files on build 35337656786
  • Tree
  • List 16
  • Changed 2
  • Source Changed 1
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35337656786
  • 2f27cefa on github
  • Prev Build on main (#35066725735)
  • Next Build on main (#35592011123)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc