Skip to content

Implement Limit controller - #868

Open
chenwng wants to merge 12 commits into
k-orc:mainfrom
chenwng:limit-controller
Open

Implement Limit controller#868
chenwng wants to merge 12 commits into
k-orc:mainfrom
chenwng:limit-controller

Conversation

@chenwng

@chenwng chenwng commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

This PR implements the controller for Limit in Keystone.

Region is not included in the spec as it is not available in ORC yet.

As Limit depends on RegisteredLimit which hasn't been merged yet, a setup deployment is used in e2e test cases to create required RegisteredLimits and remove them when tearing down cases. The deployment is also used to disable created Domains to facilitate the deletion of them.

Close #851

chenwng added 9 commits July 28, 2026 11:40
go run ./cmd/scaffold-controller -interactive=false \
    -kind=Limit \
    -gophercloud-client=NewIdentityV3 \
    -gophercloud-module=github.com/gophercloud/gophercloud/v2/openstack/identity/v3/limits \
    -gophercloud-type=Limit \
    -openstack-json-object=limit \
    -available-polling-period=0 \
    -deleting-polling-period=0 \
    -required-create-dependency=Service \
    -optional-create-dependency=Project \
    -optional-create-dependency=Domain \
    -import-dependency=Service \
    -import-dependency=Project \
    -import-dependency=Domain
@github-actions github-actions Bot added the semver:major Breaking change label Jul 28, 2026
@chenwng
chenwng force-pushed the limit-controller branch from c416088 to e556212 Compare July 28, 2026 14:22
Update generated resources to reflect the addition of description in Limit spec
Update the OLM bundle
@chenwng
chenwng force-pushed the limit-controller branch from e556212 to 0b8d70e Compare July 29, 2026 11:06
Comment thread internal/controllers/limit/actuator.go Outdated
Comment thread internal/controllers/limit/actuator.go Outdated

@dlaw4608 dlaw4608 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey Winston, great job on the PR!! , I left a few comments after a quick first look, I am looking into it more but just to show you what I found so far WDYT?

Comment thread internal/controllers/limit/actuator.go Outdated
Comment thread internal/controllers/limit/actuator.go Outdated
Comment thread internal/controllers/limit/tests/utils/main.go Outdated
Fix parameters in dependencies in Limit actuator
Fix default name in test utils
@chenwng

chenwng commented Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

Thanks @dlaw4608 for the review. I will fix them. At the same time, I am also trying to figure out the CI failures.

@chenwng
chenwng force-pushed the limit-controller branch from 0b8d70e to b41c2e4 Compare July 29, 2026 13:53
@chenwng

chenwng commented Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

After further debugging, I found two issues in the CI e2e failures.

  • The adhoc setup/teardown pod takes too long time to complete creating registered limit, and the long backoff of limit controller makes test cases unable to complete in time. Using prebuilt image will solve this issue, but this will bring in an image to build/maintain. So I will wait for the merge of registered limit controller and take advantage of it.
  • Keystone API list limit returns empty even though limits have been created successfully in OpenStack versions flamingo (stable/2025.2) and epoxy (stable/2025.1), and listing with limit id does return the limit. No such an issue was found in version gazpacho (stable/2026.1). Here is the test result in my local env with version flamingo.

Limits can be created successfully.

NAMESPACE   NAME                                               ID                                 AVAILABLE   RESOURCE             LIMIT   POLICY    MESSAGE
default     limit.openstack.k-orc.cloud/limit-import-error-1   578222e588f74fb4921d5d561c88b560   True        limit-import-error   50      managed   OpenStack resource is up to date
default     limit.openstack.k-orc.cloud/limit-import-error-2   aab77ebf7ce7447d85d12cac91526dcc   True        limit-import-error   60      managed   OpenStack resource is up to date

openstack limit list returns nothing. However, openstack limit show limit-id returns the limit correctly.

$openstack limit list 


$openstack limit show 578222e588f74fb4921d5d561c88b560 
+----------------+-----------------------------------------------------------------+
| Field          | Value                                                           |
+----------------+-----------------------------------------------------------------+
| description    | Limit from "import error" test for project-limit-import-error-1 |
| domain_id      | None                                                            |
| id             | 578222e588f74fb4921d5d561c88b560                                |
| project_id     | ab9e509176894c408707611de07fb88c                                |
| region_id      | None                                                            |
| resource_limit | 50                                                              |
| resource_name  | limit-import-error                                              |
| service_id     | 5924b6f0c7c840faa46450ff73b1a1a2                                |
+----------------+-----------------------------------------------------------------+

$openstack limit show aab77ebf7ce7447d85d12cac91526dcc
+----------------+-----------------------------------------------------------------+
| Field          | Value                                                           |
+----------------+-----------------------------------------------------------------+
| description    | Limit from "import error" test for project-limit-import-error-2 |
| domain_id      | None                                                            |
| id             | aab77ebf7ce7447d85d12cac91526dcc                                |
| project_id     | 562d74e5088941068fd04c4e93da32e5                                |
| region_id      | None                                                            |
| resource_limit | 60                                                              |
| resource_name  | limit-import-error                                              |
| service_id     | 5924b6f0c7c840faa46450ff73b1a1a2                                |
+----------------+-----------------------------------------------------------------+

This makes all limit import related test cases unable to pass in flamingo and epoxy envs.

…to Keystone API issue

Use prebuilt image to avoid slow creation of registered limits
@chenwng
chenwng force-pushed the limit-controller branch from 3540f8b to 60bb5b3 Compare July 30, 2026 19:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:major Breaking change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Limits Controller

2 participants