Skip to content

bug(permissions): domain-by-reference to a not-yet-created group type aborts the entire plan — fresh-instance rehearsal impossible #69

Description

@2000game

Found during the eqrm-dev rehearsal (#23, 2026-07-10). The config (valid + full no-op on prod) declares ct.groupTypeRole({ key: "struktur_roles", groupType: "struktur", grants: [...] }). Against a FRESH instance (empty state; the group type is part of this run's create-set), ct plan --env dev aborts entirely:

✗ group_type_role "struktur_roles".domainId: references a resource created in the same run — apply it first, or use a numeric id.

Consequences:

  1. A read-only PLAN fails on a fresh env even though nothing is wrong — the create-set for 48 resources is never rendered. chore: bootstrap eqrm/ct-structure — adopt the real Equippers scaffold #23's dev-baseline acceptance ("plan --env dev shows the create-set") and feat: GitOps loop — plan on PR, gated apply, scheduled drift detection #24's plan.yml (plans BOTH envs on every PR; exit 1 = check failure) are both broken by design for any config that declares grants by reference.
  2. The suggested workaround (numeric id) cannot work cross-env: dev ids are assigned at create time, so a numeric domainId correct for prod is wrong for dev — the logical form is the only portable one.

Resources already solved this exact problem with pending refs (#20): the plan renders campusId: <campus:x (created this apply)> and apply re-resolves after the create (#46 fix wave). Permission domains should get the same treatment:

  • Plan: a domain referencing a same-run-created group type renders as a pending grant block (e.g. + grants on group_type_role <groupType:struktur (created this apply)>: N to grant) instead of aborting.
  • Apply: permission reconciliation for that domain runs after the group type is created, re-resolving the domainId from the fresh id (permissions already execute after resources — verify ordering and reuse the existing pending-ref re-resolution machinery).
  • The hard error should remain ONLY for genuinely unresolvable references (key not in config at all).

Acceptance: a config with resources + by-reference grants plans against an empty state without error (create-set + pending grants rendered, exit 2 with --detailed-exitcode); unit/e2e-tested with the #23 scenario (empty state, groupType created same run, grants by reference). No live instance in tests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions