The GitHub Actions job "Benchmarks" on texera.git/feat/mount-B1-platform has 
succeeded.
Run started by GitHub user aicam (triggered by aicam).

Head commit for run:
962260eda4b73018ad1195c374325d220fc2fec5 / ali <[email protected]>
feat(dataset-mount): authorize and perform a repository mount

Let a computing unit have a versioned LakeFS repository mounted into it,
on the infrastructure merged in #6866.

The per-node mounter authorizes nothing — it performs what it is told,
which is why it admits exactly one caller, verified with TokenReview
against an audience-bound service-account token that only
access-control-service holds. Every decision therefore has to be made
here, and this endpoint makes four before anything reaches the mounter:
the request has the shape a mount path can be built from; the caller
holds write access to the computing unit, mounting being a change to it;
the caller may read the repository, matched by name across datasets and
models and refused unless exactly one matches; and the commit belongs to
that repository.

It then resolves which node the unit's pod is on — itself, rather than
taking one from the caller, or anything reaching it could aim requests
at any node's privileged mounter — and forwards.

file-service still re-checks read access on every byte it serves, but as
the last line rather than the only one: without the check here a caller
could have a mount created for a repository they cannot read, learning
it exists and spending a node's resources on it. The rules themselves
move to common/resource so both services decide from one definition.

Mounts are released when the pod is deleted, so there is no unmount
path. No new configuration: the mounter's port and file-service's root
come from the environment the chart already sets. Everything is behind
mounter.enabled.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01Fy9tJ1AB4trv6ZYGwfm9pR

Report URL: https://github.com/apache/texera/actions/runs/34284493976

With regards,
GitHub Actions via GitBox

Reply via email to