lahirujayathilake opened a new pull request, #487:
URL: https://github.com/apache/airavata-custos/pull/487

   Adds a POSIX username allocator under `pkg/posix`, switches AMIE account 
provisioning to use it, and introduces the COmanage Identity-Provisioner 
connector. The connector listens on `ComputeClusterUserCreateEvent` and ensures 
each user has a CoPerson, a per-user CoGroup, and a UnixClusterAccount in a 
COmanage Registry.
   
   ## Changes
   
   - **`pkg/posix`** - `BuildBase` derives a POSIX username from the user's 
name, normalises to ASCII, and stays within the 32-char POSIX login cap. Empty 
first + last name returns `ErrUnbuildableUsername` instead of a silent 
placeholder.
   - **AMIE handler** - temp posix username generator removed. 
`request_account_create` and `request_project_create` (PI provisioning) now go 
through a single `allocateAndCreateClusterUser` helper that retries on 
collisions against the new `(compute_cluster_id, local_username)` UNIQUE.
   - **COmanage Identity-Provisioner connector** - 
`connectors/COmanage/Identity-Provisioner/`. HTTP client with 5xx retry, Core 
API + REST wrappers, orchestrator that invokes the services end-to-end 
(lookup-or-create CoPerson, store comanage_id, per-user CoGroup, Identifiers, 
group membership, UnixCluster bind, UnixClusterAccount PUT). Idempotent on 
re-run.
   - **Connector loader** - `internal/connectors/loader.go` registers the new 
connector. If the seven required env vars are missing, the loader skips 
registration silently.
   
   ## Audit events added
   
   | Event type                        | Side     | When                        
                     |
   
|-----------------------------------|----------|--------------------------------------------------|
   | `PosixUsernameTruncated`          | AMIE     | Name longer than POSIX cap  
                     |
   | `PosixUsernameUnbuildable`        | AMIE     | First + last name both 
empty after normalisation |
   | `PosixUsernameAllocatorExhausted` | AMIE     | All collision suffixes used 
                     |
   | `ComanageCoPersonCreated`         | COmanage | A new CoPerson was POSTed   
                     |
   | `ComanageClusterAccountAttached`  | COmanage | Sequence completed          
                     |
   | `ComanageProvisioningFailed`      | COmanage | Any step errored, with 
`step=` and `err=`        |
   
   ## Configuration
   
   Required env vars (loader skips silently if any is missing):
   
   ```
   COMANAGE_REGISTRY_URL
   COMANAGE_CO_ID
   COMANAGE_API_USER
   COMANAGE_API_KEY
   COMANAGE_PERSON_ID_TYPE
   COMANAGE_UNIX_CLUSTER_ID
   CUSTOS_CLUSTER_ID
   ```
   
   See `connectors/COmanage/Identity-Provisioner/README.md` and 
`config.example.yaml` for the full list including optional attrs.
   
   ## Source of truth
   
   Custos owns the user records. CoPerson and UnixClusterAccount records for 
users provisioned by this connector **must not be edited directly** in 
COmanage. There is no drift reconciliation.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to