You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Found during the eqrm-dev rehearsal (#23, 2026-07-10). The config (valid + full no-op on prod) declares ct.groupTypeRole({ key: "struktur_roles", groupType: "struktur", grants: [...] }). Against a FRESH instance (empty state; the group type is part of this run's create-set), ct plan --env dev aborts entirely:
✗ group_type_role "struktur_roles".domainId: references a resource created in the same run — apply it first, or use a numeric id.
The suggested workaround (numeric id) cannot work cross-env: dev ids are assigned at create time, so a numeric domainId correct for prod is wrong for dev — the logical form is the only portable one.
Resources already solved this exact problem with pending refs (#20): the plan renders campusId: <campus:x (created this apply)> and apply re-resolves after the create (#46 fix wave). Permission domains should get the same treatment:
Plan: a domain referencing a same-run-created group type renders as a pending grant block (e.g. + grants on group_type_role <groupType:struktur (created this apply)>: N to grant) instead of aborting.
Apply: permission reconciliation for that domain runs after the group type is created, re-resolving the domainId from the fresh id (permissions already execute after resources — verify ordering and reuse the existing pending-ref re-resolution machinery).
The hard error should remain ONLY for genuinely unresolvable references (key not in config at all).
Acceptance: a config with resources + by-reference grants plans against an empty state without error (create-set + pending grants rendered, exit 2 with --detailed-exitcode); unit/e2e-tested with the #23 scenario (empty state, groupType created same run, grants by reference). No live instance in tests.
Found during the eqrm-dev rehearsal (#23, 2026-07-10). The config (valid + full no-op on prod) declares
ct.groupTypeRole({ key: "struktur_roles", groupType: "struktur", grants: [...] }). Against a FRESH instance (empty state; the group type is part of this run's create-set),ct plan --env devaborts entirely:✗ group_type_role "struktur_roles".domainId: references a resource created in the same run — apply it first, or use a numeric id.Consequences:
Resources already solved this exact problem with pending refs (#20): the plan renders
campusId: <campus:x (created this apply)>and apply re-resolves after the create (#46 fix wave). Permission domains should get the same treatment:+ grants on group_type_role <groupType:struktur (created this apply)>: N to grant) instead of aborting.Acceptance: a config with resources + by-reference grants plans against an empty state without error (create-set + pending grants rendered, exit 2 with --detailed-exitcode); unit/e2e-tested with the #23 scenario (empty state, groupType created same run, grants by reference). No live instance in tests.