• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

opendefensecloud / solution-arsenal / 37796593255
79%

Build:
DEFAULT BRANCH: main
Ran 08 Oct 2026 03:17PM UTC
Jobs 1
Files 94
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

08 Oct 2026 02:56PM UTC coverage: 78.574% (+0.02%) from 78.558%
37796593255

push

github

web-flow
docs(adr): settle cross-namespace RegistryBinding semantics (#845)

## What
Settles the cross-namespace RegistryBinding semantics in the ADRs before
the controller changes land. Docs only.

- ADR-012 Pattern 4: how the Target controller collects cross-ns
RegistryBindings, Registry always resolved in the binding's own ns, what
a cross-ns binding provides, `Granted` condition
- ADR-010: render-time step 3 matches the actual behavior (strict vs
relaxed, identical pull secrets merged, differing ones conflict),
Registry scope question resolved
- ADR-009: open questions on cross-ns bindings, Registry scope and
status conditions resolved

Part of #565.

## Why
Open question from #565 (originally #567, closed as duplicate): may a
RegistryBinding reference a Registry in another namespace? Answer is no:
`registryRef` stays a `LocalObjectReference`. The provider keeps
RegistryBinding + Registry in its own ns and targets the user's Target
via a ReferenceGrant (Pattern 4). No API change, and `ClusterRegistry`
stays deferred.

ADR-010 step 3 said "exactly one binding must match", but the code
merges bindings with the same `targetPullSecretName` and only fails on
differing ones (`target_controller.go:1340`). Once bindings can come
from several namespaces the identical case gets more likely (provider
and tenant binding the same mirror), so the ADR now follows the code
instead of the other way round.

One thing worth calling out: a cross-ns binding only contributes the
pull secret name for the target cluster. SolAr still reads private
components with a Registry in the Target's ns
(`resolveComponentSource`), because the render Job can't mount a Secret
from another ns.

## Testing
Docs only, no behavior change. `mkdocs` not available locally, no links
added or changed.

## Notes for reviewers
The implementation follows in separate PRs: same-ns
`targetRef.namespace` fix, requeue on Registry changes, cross-ns
collection (closes #565), `Granted` condition on RegistryBindin... (continued)

5079 of 6464 relevant lines covered (78.57%)

25.85 hits per line

Coverage Regressions

Lines Coverage ∆ File
2
71.88
-3.13% pkg/controller/registrybinding_controller.go
Jobs
ID Job ID Ran Files Coverage
1 37796593255.1 08 Oct 2026 03:17PM UTC 94
78.57
GitHub Action Run
Source Files on build 37796593255
  • Tree
  • List 94
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #37796593255
  • d998efda on github
  • Prev Build on main (#37751911677)
  • Next Build on main (#37900056597)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc