fix(issues): correlate missing admission webhook services - #1391
Open
nadaverell wants to merge 1 commit into
Open
fix(issues): correlate missing admission webhook services#1391nadaverell wants to merge 1 commit into
nadaverell wants to merge 1 commit into
Conversation
nadaverell
added a commit
that referenced
this pull request
Aug 9, 2026
## Summary - detect Gateways that reference a missing GatewayClass after a two-minute reconciliation grace - detect HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute parentRefs that target a missing Gateway - require authoritative cluster or exact-namespace informer coverage before asserting absence - preserve unrelated Gateway controller conditions while deduplicating exact structural echoes, including Envoy Gateway PortNotFound - apply the same authority check to KEDA Rollout scaleTargetRefs so partial caches cannot produce false missing-target issues ## Validation - `make build` - `make test` - `make tsc` - `go test ./internal/issues ./internal/k8s` - `go test ./...` from `pkg/k8score/` - live EKS smoke on `radar-test-nonprod`: grace suppression, both findings present, target creation recovery, and fixture cleanup - Playwright Issues-page smoke with both findings rendered and zero console errors - visual-test skipped: no UI delta ## Stack - stacked on #1391 - #1391 is stacked on #1390 Linear: RAD-346 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Changes live issue detection for Gateway networking and dynamic-cache “absence” semantics; incorrect authority or dedupe could hide real problems or briefly miss issues during informer sync, but behavior is heavily tested and biased toward silence when coverage is incomplete. > > **Overview** > Extends **Gateway API missing-reference detection** beyond route backend Services: after a **2-minute grace**, it flags **Gateways** with a non-existent `spec.gatewayClassName` and **routes** (`HTTPRoute`, `GRPCRoute`, `TCPRoute`, `TLSRoute`) whose `parentRefs` point at a **missing Gateway** (same- or cross-namespace). **Backend Service / port / ReferenceGrant** checks still require the Service lister; **topology** checks (class + parent) run even when Services aren’t available. > > **Issue taxonomy** maps `Missing GatewayClass` to **gateway_not_ready** and `Missing Gateway parent` to **gateway_route_invalid**; user-facing catalog copy is updated accordingly. > > **Dedupe** no longer drops every `ResolvedRefs:*` condition when any structural missing-ref exists on the route. It only hides **matching** controller echoes (e.g. backend missing → `BackendNotFound` / `PortNotFound`; ReferenceGrant → `RefNotPermitted`). A **missing parent** structural row does **not** suppress unrelated `ResolvedRefs` conditions. > > **Dynamic cache authority**: new `HasWatchedInSyncedNamespace` returns “missing” only when the relevant informer has **synced** for that namespace (including during informer scope replacement). **KEDA `Rollout` scaleTargetRefs** use the same rule so partial watches don’t emit false **missing scaleTargetRef** issues. Initial add-event suppression is renamed/clarified so it isn’t confused with sync authority. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 93ee479. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
nadaverell
added a commit
that referenced
this pull request
Aug 9, 2026
## Summary - detect Gateways that reference a missing GatewayClass after a two-minute reconciliation grace - detect HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute parentRefs that target a missing Gateway - require authoritative cluster or exact-namespace informer coverage before asserting absence - preserve unrelated Gateway controller conditions while deduplicating exact structural echoes, including Envoy Gateway PortNotFound - apply the same authority check to KEDA Rollout scaleTargetRefs so partial caches cannot produce false missing-target issues ## Validation - `make build` - `make test` - `make tsc` - `go test ./internal/issues ./internal/k8s` - `go test ./...` from `pkg/k8score/` - live EKS smoke on `radar-test-nonprod`: grace suppression, both findings present, target creation recovery, and fixture cleanup - Playwright Issues-page smoke with both findings rendered and zero console errors - visual-test skipped: no UI delta ## Stack - stacked on #1391 - #1391 is stacked on #1390 Linear: RAD-346 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Changes live issue detection for Gateway networking and dynamic-cache “absence” semantics; incorrect authority or dedupe could hide real problems or briefly miss issues during informer sync, but behavior is heavily tested and biased toward silence when coverage is incomplete. > > **Overview** > Extends **Gateway API missing-reference detection** beyond route backend Services: after a **2-minute grace**, it flags **Gateways** with a non-existent `spec.gatewayClassName` and **routes** (`HTTPRoute`, `GRPCRoute`, `TCPRoute`, `TLSRoute`) whose `parentRefs` point at a **missing Gateway** (same- or cross-namespace). **Backend Service / port / ReferenceGrant** checks still require the Service lister; **topology** checks (class + parent) run even when Services aren’t available. > > **Issue taxonomy** maps `Missing GatewayClass` to **gateway_not_ready** and `Missing Gateway parent` to **gateway_route_invalid**; user-facing catalog copy is updated accordingly. > > **Dedupe** no longer drops every `ResolvedRefs:*` condition when any structural missing-ref exists on the route. It only hides **matching** controller echoes (e.g. backend missing → `BackendNotFound` / `PortNotFound`; ReferenceGrant → `RefNotPermitted`). A **missing parent** structural row does **not** suppress unrelated `ResolvedRefs` conditions. > > **Dynamic cache authority**: new `HasWatchedInSyncedNamespace` returns “missing” only when the relevant informer has **synced** for that namespace (including during informer scope replacement). **KEDA `Rollout` scaleTargetRefs** use the same rule so partial watches don’t emit false **missing scaleTargetRef** issues. Initial add-event suppression is renamed/clarified so it isn’t confused with sync authority. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 93ee479. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
nadaverell
force-pushed
the
fix/rad-346-webhook-missing-service
branch
from
August 9, 2026 13:03
2da1e04 to
3588d3d
Compare
nadaverell
force-pushed
the
fix/rad-346-onset-provenance
branch
from
August 9, 2026 13:03
a2fce69 to
e2c2e3d
Compare
nadaverell
force-pushed
the
fix/rad-346-webhook-missing-service
branch
2 times, most recently
from
August 10, 2026 00:24
dc1547c to
572085b
Compare
nadaverell
force-pushed
the
fix/rad-346-webhook-missing-service
branch
from
August 10, 2026 00:29
572085b to
e5161cd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
failurePolicysemanticsValidation
make buildmake testgo test ./internal/k8s ./internal/issues -count=1radar-test-nonprod: reproduced the exactservice not foundFailedCreateevent, verified the configuration-to-workload incident edge in API and UI, installed a TLS webhook backend, and verified both workload recovery and issue disappearanceStacked on #1390; retarget to
mainafter that PR lands.RAD-346
Note
Medium Risk
Changes admission webhook incident correlation and parsing of API-server failure messages; incorrect matching could mis-parent workloads or miss real outages, though ambiguity guards and broad tests limit exposure.
Overview
Extends admission webhook failure handling beyond no ready endpoints to
service not foundAPI errors, using strict parsing of webhook name and in-cluster Service URL so scheduling failures classify asWebhookUnavailable.Missing webhook backend detections now use shared
MissingWebhookBackendReasonandWebhookBackendFingerprintso each configuration root is keyed to an exact backend Service identity. Diagnostic enrichment treats those missing-ref webhook configuration issues as roots (no synthetic Service row), resolves webhooks viaAdmissionWebhookRefsForConfiguration, and links blocked workloads only when the parsed failure matchesfailurePolicy=Fail, webhook name, service identity, and failure kind (missing service vs no endpoints).Existing Service-backend webhook correlation is tightened the same way:
ParseAdmissionWebhookBackendFailurereplaces the no-endpoints-only parser, and incident edges require an exact webhook reference match rather than service name alone.Reviewed by Cursor Bugbot for commit e5161cd. Bugbot is set up for automated code reviews on this repo. Configure here.