Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
280 commits
Select commit Hold shift + click to select a range
05c9a62
Let Radar Cloud tiers read CNPG FailoverQuorums and Leases
nadaverell Sep 29, 2026
47bb97a
Show CNPG trends from Prometheus and measured fleet lag
nadaverell Sep 29, 2026
559aa21
Register restore with the operation tracker, add Backup/ObjectStore r…
nadaverell Sep 29, 2026
094bfa7
Merge CNPG Prometheus history, fleet lag and interval-scoped logs/act…
nadaverell Sep 29, 2026
aee7f62
Quote restore manifests for YAML 1.1, keep Secret names in report spe…
nadaverell Sep 29, 2026
215a2a7
Merge feature/cnpg-actions-runtime into CNPG restore, report and oper…
nadaverell Sep 29, 2026
afbc530
Merge CNPG restore completion, report bundle and operator diagnosis
nadaverell Sep 29, 2026
604c116
Ask the kubeconfig identity for CNPG grants in local mode
nadaverell Sep 30, 2026
66a16aa
Answer the local permission review in the CNPG runtime test server
nadaverell Sep 30, 2026
0e75a1d
Read the previous container run for CNPG interval logs
nadaverell Sep 30, 2026
2895ebe
Say in plain words why CNPG runtime reads failed in transit
nadaverell Sep 30, 2026
fa2d016
Judge whether the CNPG operator is reconciling and guard writes on it
nadaverell Sep 30, 2026
b26caa3
Flag stale CNPG status on the fleet, cluster pages and action dialogs
nadaverell Sep 30, 2026
1255a73
Stop CNPG Sessions and Storage from asserting what was not measured
nadaverell Sep 30, 2026
853a780
Tag Pod timeline rows by the state the change produced
nadaverell Sep 30, 2026
9889d0c
Do not report a slow namespace switch as failed when it was applied
nadaverell Sep 30, 2026
72ca325
Label no CNPG operator Pod leader while its lease has expired
nadaverell Sep 30, 2026
6e3907a
Keep the CNPG Runtime section on Back and explain disabled actions
nadaverell Sep 30, 2026
b040bda
Keep every Runtime section for callers without pods/proxy and label o…
nadaverell Sep 30, 2026
927f7f5
Show a Pooler's Scheduled badge as neutral: status counts scheduled P…
nadaverell Sep 30, 2026
353c720
Keep the CNPG trend range and selected interval in the URL
nadaverell Sep 30, 2026
fa3375d
Raise sustained replication lag in the CNPG fleet's Needs attention
nadaverell Sep 30, 2026
fc25055
Describe the CNPG workspace's writes and sustained-lag rule in the docs
nadaverell Sep 30, 2026
f07a042
Send subresources in their own SelfSubjectAccessReview field
nadaverell Sep 30, 2026
aeba261
Redact sensitive env values in the CNPG report's Cluster and Pooler m…
nadaverell Sep 30, 2026
5aa5499
Stop following CNPG operations Radar cannot observe, and pause pollin…
nadaverell Sep 30, 2026
1276735
Complete a followed restore on a ready primary even without access to…
nadaverell Sep 30, 2026
9feeba2
Treat timeouts and lost connections as unknown write outcomes, and ti…
nadaverell Sep 30, 2026
53d3f9b
Say when fleet disk usage could not be read instead of showing it as …
nadaverell Sep 30, 2026
a782bb2
Keep the return label when clearing a trend interval, and animate the…
nadaverell Sep 30, 2026
e2f07f8
Re-verify the instance before each destroy step and report partial ou…
nadaverell Sep 30, 2026
6b4a738
Hold PVC usage and CNPG history to one cluster identity over the char…
nadaverell Sep 30, 2026
f1fc4a4
Redact SQL from every PostgreSQL log format in the CNPG report
nadaverell Sep 30, 2026
e430598
Compare streaming standbys against spec.instances, not the Pods still…
nadaverell Sep 30, 2026
8fcbdc4
Keep an unresolved operator watch scope unknown instead of all namesp…
nadaverell Sep 30, 2026
f3d8054
Require evidence before a fence or switchover counts as completed
nadaverell Sep 30, 2026
41517f6
Say when a CNPG refresh failed over cached data
nadaverell Sep 30, 2026
32fca56
Never pin metric queries to labels that are not proven cluster identity
nadaverell Sep 30, 2026
5f11b43
Redact extended-protocol log messages whatever the statement name
nadaverell Sep 30, 2026
ca73167
Require a fenced instance to destroy it, and lift the fence afterwards
nadaverell Sep 30, 2026
8bae581
Certify tracked CNPG operations only from fresh, affirmative evidence
nadaverell Sep 30, 2026
6dd663d
Check every destroy grant before the first write, and leave a recreat…
nadaverell Sep 30, 2026
92e9295
Never claim a fenced instance's PostgreSQL stopped: CloudNativePG rep…
nadaverell Sep 30, 2026
0dd9c45
Order the CNPG fleet by urgency: worst problem, then problem count
nadaverell Sep 30, 2026
2582432
Show a running CNPG base backup to a joining instance on the Cluster …
nadaverell Sep 30, 2026
cae338b
Show multixact ID age and extensions with updates in CNPG runtime
nadaverell Sep 30, 2026
7bfa8ef
Add a Connect section to the CNPG Cluster overview
nadaverell Sep 30, 2026
3475024
gofmt the CNPG runtime metric facts
nadaverell Sep 30, 2026
c31e9ca
Read CNPG backup schedules in plain language and edit them
nadaverell Sep 30, 2026
d848977
Trace each CNPG Subscription to its publication, slot and failover po…
nadaverell Sep 30, 2026
685833b
List schedule editing among the CNPG workspace's writes
nadaverell Sep 30, 2026
26d757b
Parse CNPG schedules with robfig/cron v1, the parser the operator uses
nadaverell Sep 30, 2026
c309186
Word a CNPG schedule's day fields with robfig/cron v1's AND/OR rule
nadaverell Sep 30, 2026
1cd0f85
Require HA replication slots for a CNPG logical slot to survive failover
nadaverell Sep 30, 2026
9858dc7
Keep an incomplete CNPG status report's unread lists unknown, not empty
nadaverell Sep 30, 2026
457f1bd
Keep a capped or stale publisher slot reading from reading as current
nadaverell Sep 30, 2026
e84cfcf
Say a Publication is unknown when its namespace's Publications are un…
nadaverell Sep 30, 2026
5bbb214
Stop calling the CNPG -r Service read-only in Connect
nadaverell Sep 30, 2026
d9dab19
Expose CNPG per-database counters and checkpoint counters in runtime …
nadaverell Sep 30, 2026
4d3d3e0
Pick the instance behind CNPG Sessions and Transactions, and show che…
nadaverell Sep 30, 2026
054c251
Show CNPG per-database health under Runtime > Transactions
nadaverell Sep 30, 2026
ed1c732
Chart more CNPG trends without Prometheus from the page's own samples
nadaverell Sep 30, 2026
d52b41e
Carry the CNPG exporter's generation time, Pod UIDs and sessions by s…
nadaverell Sep 30, 2026
67bf1e2
Take CNPG sampled rates per exporter run and per primary, and chart s…
nadaverell Sep 30, 2026
0beb0ab
Keep sampled lock waits when an instance's session counts are missing
nadaverell Sep 30, 2026
ad027cb
Require a sample in every minute of the window before calling CNPG la…
nadaverell Sep 30, 2026
057815c
Claim only recorded samples for sustained CNPG lag, from a standby re…
nadaverell Sep 30, 2026
44198d6
Let a low lag sample from any scrape job of a standby disqualify sust…
nadaverell Sep 30, 2026
5747c3a
Word CNPG instance manager and exporter error answers as plain sentences
nadaverell Sep 30, 2026
0398bf4
Say what a CNPG HA fact cannot show when Radar has no cached copy
nadaverell Sep 30, 2026
1ad83bb
Give Prometheus discovery failures one coherent sentence, once per fact
nadaverell Sep 30, 2026
c9bd1b3
Rate the CNPG Replication chip's lag with the Replication fact's scale
nadaverell Sep 30, 2026
e7e78f6
Lead a CNPG standby card with a paused replay
nadaverell Sep 30, 2026
1227929
Say why CNPG instance-manager facts are missing instead of "runtime a…
nadaverell Sep 30, 2026
aa43fa0
Stop CNPG Trends waiting for samples the caller can never take
nadaverell Sep 30, 2026
cd65dba
Drive CNPG Sessions from one instance picker and show one connections…
nadaverell Sep 30, 2026
53e54dc
Keep the CNPG fleet's Logs and Open buttons inside their column
nadaverell Sep 30, 2026
f7f7c06
Show Prometheus transaction rates on the CNPG Transactions card
nadaverell Sep 30, 2026
6c73db9
Say unknown parts of a CNPG logical replication path in words
nadaverell Sep 30, 2026
81a97da
Show an incomplete CNPG action form as a quiet hint, not an alert
nadaverell Sep 30, 2026
a4bd5e3
Name the streaming standbys and the lag on a lagging CNPG Replication…
nadaverell Sep 30, 2026
5293880
Keep every CNPG cluster menu item on its own row
nadaverell Sep 30, 2026
1653c1c
Gate CNPG Restore to a new cluster on create clusters
nadaverell Sep 30, 2026
287b407
Gate the CNPG restore dialog on create clusters however it is opened
nadaverell Sep 30, 2026
6524c85
Name the refused step when Prometheus port-forwarding is forbidden
nadaverell Sep 30, 2026
b4ee449
Read PostgreSQL's own errors before transport hints, and keep their d…
nadaverell Sep 30, 2026
b9d6639
Let a missing CNPG standby never hide a severe replay lag
nadaverell Sep 30, 2026
83a1f35
Tie CNPG Sessions to the picked Pod and keep Transactions rates honest
nadaverell Sep 30, 2026
98f5061
Name relayed PostgreSQL failures from an allowlist, and only for the …
nadaverell Sep 30, 2026
767314e
Keep a lockMode create dialog strict create after a partial create
nadaverell Sep 30, 2026
b894350
Show CNPG connection headroom once in Sessions
nadaverell Sep 30, 2026
8818644
Name the instance manager or exporter only when the relayed body says so
nadaverell Sep 30, 2026
5bb322d
Label the CNPG fleet table's namespace, row status and instance pills
nadaverell Sep 30, 2026
213c7e4
Open a CNPG cluster's other problems in place and make health chips n…
nadaverell Sep 30, 2026
25b6a5b
Hand a restored CNPG cluster off with a Next steps checklist
nadaverell Sep 30, 2026
e7b5557
Count only WAL archiving as done in a restored cluster's backup step
nadaverell Sep 30, 2026
9b1267b
Tighten the CNPG summary's in-page navigation, chip names and backup …
nadaverell Sep 30, 2026
6ee2c3e
Lead CNPG problem lists with the cause and word Pod reasons as sentences
nadaverell Sep 30, 2026
e4cc751
Drop the "(label)" suffix from CNPG instance roles
nadaverell Sep 30, 2026
011905f
Say what the CNPG WAL-held-by-slots figure is
nadaverell Sep 30, 2026
dc22721
Show CNPG transaction and multixact ID ages as readable counts
nadaverell Sep 30, 2026
e6f2b8f
Show counts, not a percentage, for a handful of CNPG checkpoints
nadaverell Sep 30, 2026
113fb3a
Say once that CNPG instance CPU and memory are not measured
nadaverell Sep 30, 2026
58861fe
Stop repeating the CNPG Storage & WAL notice under every volume
nadaverell Sep 30, 2026
7eeea74
Say once per cluster when no CNPG declaration records a GitOps source
nadaverell Sep 30, 2026
def5115
Head CNPG condition problems with a plain title, the operator's text …
nadaverell Sep 30, 2026
5b1f6ce
Keep the CNPG Replication cell short when lag is unknown
nadaverell Sep 30, 2026
e4f28dd
Show the CNPG operator leader as its Pod name
nadaverell Sep 30, 2026
413721c
Read CNPG WAL archiving as "Failing" with its message on hover
nadaverell Sep 30, 2026
5919359
Word CNPG backup schedules in plain language on Protection and the su…
nadaverell Sep 30, 2026
6003363
Word expired CNPG certificates and unproven missing backups honestly
nadaverell Sep 30, 2026
f731798
Say the metrics API is missing only when no CNPG instance has metrics
nadaverell Sep 30, 2026
69cd3de
Test that CNPG schedule readings follow ScheduledBackup access
nadaverell Sep 30, 2026
b5dfe85
Word missing CNPG instance metrics and certificate issues without ove…
nadaverell Sep 30, 2026
21a96a2
Fit the CNPG fleet table in a laptop-width content area again
nadaverell Oct 1, 2026
e574e73
Make the CNPG connections figure read as connections in use
nadaverell Oct 1, 2026
0fccd90
Hide the CNPG checkpoint share below ten checkpoints
nadaverell Oct 1, 2026
8b5ad8d
Caption the CNPG transaction rates with their source directly beneath
nadaverell Oct 1, 2026
a8518b5
Use one binary byte formatter across CNPG Storage & WAL
nadaverell Oct 1, 2026
0cde8cc
Read common CNPG schedule shapes naturally
nadaverell Oct 1, 2026
f966d36
Read failing CNPG WAL archiving as "Failing for 2d"
nadaverell Oct 1, 2026
69b27f8
Wrap CNPG backup destinations only at slashes
nadaverell Oct 1, 2026
8f60f4c
Word CNPG history's cluster-matching notes plainly
nadaverell Oct 1, 2026
c6b9aab
Say why CNPG history and used space lack Prometheus in one sentence, …
nadaverell Oct 1, 2026
0ca9fce
Word cluster-wide CNPG grants without nested parentheses
nadaverell Oct 1, 2026
8641b22
Word a CNPG instance's restart as past, not ongoing
nadaverell Oct 1, 2026
3351efd
Keep the CNPG declarations' GitOps-source note in a neutral tone
nadaverell Oct 1, 2026
aaa2966
Keep a CNPG logical path's arrows with the hop they point to
nadaverell Oct 1, 2026
a5ee754
Word CNPG pooler pressure so it wraps only between its two figures
nadaverell Oct 1, 2026
9bb103d
Word the CNPG sustained-lag problem plainly
nadaverell Oct 1, 2026
e470dbb
Scope the CNPG sustained-lag problem to the samples Prometheus recorded
nadaverell Oct 1, 2026
ae212a7
Fit the CNPG fleet table at a 1280px window and bound its instance pills
nadaverell Oct 1, 2026
5898d83
Keep each CNPG path segment whole so URLs wrap only after "/"
nadaverell Oct 1, 2026
c14dcc8
Describe CNPG schedules only as the operator's parser runs them
nadaverell Oct 1, 2026
2e647c1
Collapse CNPG backups that failed the same way into one problem
nadaverell Oct 1, 2026
688db47
Name the schedule in words in the CNPG missed-backup issue
nadaverell Oct 1, 2026
c1dc2be
Document the reworded CNPG missed-backup issue
nadaverell Oct 1, 2026
4279dae
Explain template0's empty CNPG database statistics on hover
nadaverell Oct 1, 2026
55db3c2
Note a lagging CNPG switchover candidate under its own row
nadaverell Oct 1, 2026
a0ec87e
Show a missing CNPG operator grant as one unit
nadaverell Oct 1, 2026
7221f5e
Word a denied CNPG Storage & WAL source like the others
nadaverell Oct 1, 2026
b87f63f
Read every CNPG replay lag with one formatter
nadaverell Oct 1, 2026
b4f61ba
Keep CNPG fleet cells short and names whole at a 1280px window
nadaverell Oct 1, 2026
6113218
Keep CNPG ObjectStore names on one line on the Protection page
nadaverell Oct 1, 2026
9b7cfc4
Count a CNPG cluster's newest failed Backup once
nadaverell Oct 1, 2026
388d424
Make the CNPG sustained-lag detail conditional on the lag persisting
nadaverell Oct 1, 2026
624a3b6
Base CNPG switchover's catch-up warning on the WAL backlog, not repla…
nadaverell Oct 1, 2026
90e1b66
Default the CNPG switchover to the standby with the least WAL to replay
nadaverell Oct 1, 2026
681a9bb
Order a CNPG cluster's failed Backups by the Backups' own times
nadaverell Oct 1, 2026
38924b0
Stop guessing why a CNPG database statistic is missing
nadaverell Oct 1, 2026
999e70d
Keep CNPG sustained-lag wording sample-scoped in the fleet, and tight…
nadaverell Oct 1, 2026
cade926
Re-pick the CNPG switchover default when runtime data arrives
nadaverell Oct 1, 2026
c32dff7
Read CNPG operator status apart from the caller's request, and say wh…
nadaverell Oct 1, 2026
e917e70
Let CNPG destination text wrap and keep ObjectStore names whole
nadaverell Oct 1, 2026
2024ceb
Keep CNPG action button labels on one line
nadaverell Oct 1, 2026
ec66fe6
Run a shared CNPG runtime read detached from the caller that started it
nadaverell Oct 1, 2026
2981d72
Keep the CNPG runtime read cap when callers leave, and never memoize …
nadaverell Oct 1, 2026
89d9a3f
Start no CNPG runtime read for a cancelled caller, and detect timeout…
nadaverell Oct 1, 2026
ea74b49
Recognize the apiserver proxy's relayed transport timeouts as timeouts
nadaverell Oct 1, 2026
78bc772
Read the restore dialog's copied resources as requests and limits
nadaverell Oct 1, 2026
2f0557c
Label a CNPG Pooler's pause row by its state, not as "Paused"
nadaverell Oct 1, 2026
e9e034c
Name where a CNPG problem comes from and link it to the Issues page
nadaverell Oct 1, 2026
7d03799
Say when the namespace filter hides an Issues subject instead of "non…
nadaverell Oct 1, 2026
487d8d3
Keep the default Overview for resources without a CNPG summary
nadaverell Oct 1, 2026
86d9b57
Label each CNPG problem's origin by what its detector actually reads
nadaverell Oct 1, 2026
f6e3f80
Answer an Issues subject link from the per-resource lookup
nadaverell Oct 1, 2026
100c08c
Gate per-resource issues on getting the subject's kind
nadaverell Oct 1, 2026
f9b6b9c
Describe only the subject on a narrowed Issues page, and keep it fresh
nadaverell Oct 1, 2026
437df8c
Honour named grants, scoped informers and the list gate on subject is…
nadaverell Oct 1, 2026
f41bc7c
Count withheld cluster-scoped issues by resolved group, only on request
nadaverell Oct 1, 2026
76482a4
Bind backup target, read jq ignore rules and fix replica and Issues l…
nadaverell Oct 2, 2026
83714f8
Merge feature/cnpg-workspace (with main) into feature/cnpg-actions-ru…
nadaverell Oct 2, 2026
7113a90
Fix hook dependencies and an unused test helper caught by CI checks
nadaverell Oct 2, 2026
3443844
Bind the cluster's backup target only when the backup inherits it
nadaverell Oct 2, 2026
85d5e7e
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 2, 2026
f61e577
Say what a disconnected standby is missing, and warn before a doomed …
nadaverell Oct 3, 2026
d90d10e
Detect replica clusters exactly like the operator, and space the WAL …
nadaverell Oct 3, 2026
4a5a644
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
89e6837
Qualify Prometheus findings matched by name, and keep lower bounds ou…
nadaverell Oct 3, 2026
32deb2c
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
0ab6b5f
Compare a disconnected standby's position only on the primary's timeline
nadaverell Oct 3, 2026
4e0763e
Qualify disk findings matched by claim name, and judge an instance on…
nadaverell Oct 3, 2026
ecdd279
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
3ee643d
Type the optional disk fact in the attribution test
nadaverell Oct 3, 2026
37c05b2
Give the Trends volume chart its own attribution note
nadaverell Oct 3, 2026
02c42b8
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
dbe6740
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
908e43b
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
eb9cce1
Claim a fenced instance stopped only when its instance manager says so
nadaverell Oct 3, 2026
d4fab1b
Describe why psql is unavailable on a fenced instance without claimin…
nadaverell Oct 3, 2026
29018b2
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 3, 2026
a6e9f2f
Fold the cluster Overview to what needs a look, and move Connect to t…
nadaverell Oct 3, 2026
d322b39
Name unread facts in the folded summaries, and keep Connect to one di…
nadaverell Oct 3, 2026
269de85
Open Connect from a URL request without keeping it in the URL
nadaverell Oct 3, 2026
a7c6bef
Answer a Connect request once, whichever button sees it first
nadaverell Oct 3, 2026
aabc70f
Read an empty instance list as a gap, and let a remounted Connect but…
nadaverell Oct 3, 2026
6cfb825
Share the workspace building blocks extracted from the CloudNativePG …
nadaverell Oct 4, 2026
2bd2d73
Merge remote-tracking branch 'origin/feature/cnpg-workspace' into fea…
nadaverell Oct 4, 2026
23608cc
Judge a scheduled run missed only from backups that were read
nadaverell Oct 4, 2026
c551ed2
Merge branch 'feature/cnpg-workspace' into feature/cnpg-actions-runtime
nadaverell Oct 4, 2026
1bb7ab5
CloudNativePG: WAL receiver and inactive slot evidence in the fleet; …
nadaverell Oct 4, 2026
3fa921d
CloudNativePG: task-shaped Cluster page and one assessment for every …
nadaverell Oct 4, 2026
0665b6e
CloudNativePG: raise only sustained receiver loss; live reads clear w…
nadaverell Oct 4, 2026
4b68f29
Detail tabs stay on one line at laptop widths
nadaverell Oct 4, 2026
1760fcb
CloudNativePG: clear warnings only on evidence; restore from the Back…
nadaverell Oct 4, 2026
f77ef5f
CloudNativePG: repair paths for archiving, retained WAL and plugin fa…
nadaverell Oct 4, 2026
c5692cd
docs: CloudNativePG repair paths, evidence rules and Operator current…
nadaverell Oct 4, 2026
64a726d
CloudNativePG: archiving repair shows the operator's message, opens t…
nadaverell Oct 4, 2026
84cdcf1
CloudNativePG: status dots line up with the first line of their text
nadaverell Oct 4, 2026
2bc8a67
CloudNativePG: Operator says ready right now, not ready, for a compon…
nadaverell Oct 4, 2026
64f9c55
CloudNativePG: blocked phases say the operator retries; archive repai…
nadaverell Oct 4, 2026
c5038c0
CloudNativePG: end the quoted phase reason with a period
nadaverell Oct 4, 2026
f41519d
CloudNativePG: a fresh recovery base must begin after the last WAL th…
nadaverell Oct 4, 2026
b0b8f85
CloudNativePG: a backup without a readable beginWal is unverified, no…
nadaverell Oct 4, 2026
349ccfb
CloudNativePG: archiving reads as resumed only after a failure the in…
nadaverell Oct 4, 2026
7cd7c57
CloudNativePG: restore checks, parameters in effect, and a Reachabili…
nadaverell Oct 4, 2026
846ebd2
CloudNativePG: pin search_path for every diagnostic SQL; keep the nam…
nadaverell Oct 4, 2026
5bf61c9
CloudNativePG: an empty parameters read is a read; no instance Pod is…
nadaverell Oct 4, 2026
a4e1a45
CloudNativePG: a replica's join Job does not hide the restore checks
nadaverell Oct 4, 2026
e9ab450
CloudNativePG: one title line for location, name and status; a tighte…
nadaverell Oct 4, 2026
36a0c81
Detail header: actions wrap before the title line is squeezed, not ag…
nadaverell Oct 4, 2026
a03b8df
CloudNativePG: every crumb names the view; the kind badge is left out…
nadaverell Oct 4, 2026
40ea6b8
CloudNativePG: a chart names the instances it has no line for; a cold…
nadaverell Oct 5, 2026
185f96d
CloudNativePG: the crumb is the only way back; declarations grouped b…
nadaverell Oct 5, 2026
2f86988
Resources sidebar: a filter keeps a category's matching workspace views
nadaverell Oct 5, 2026
914fe28
CloudNativePG: the Cluster kind's list is the Clusters view
nadaverell Oct 5, 2026
8c91107
CloudNativePG: Cluster create starts from a valid spec; kind route ti…
nadaverell Oct 5, 2026
99e8421
docs(cnpg): Create opens on a minimal Cluster
nadaverell Oct 5, 2026
6319855
CloudNativePG: even card padding, baseline-aligned facts, honest empt…
nadaverell Oct 5, 2026
f524b5d
CloudNativePG: an unread instance count claims no single instance
nadaverell Oct 5, 2026
8943fa3
CloudNativePG: health on the tabs; a Cluster's own Job Pods name the …
nadaverell Oct 5, 2026
90fbaaa
CloudNativePG: a marked tab says why; no restore without a source
nadaverell Oct 5, 2026
39177bb
CloudNativePG: values say what Radar actually knows
nadaverell Oct 5, 2026
ac0b730
CloudNativePG: refresh refreshes, stale reads say so, restore checks …
nadaverell Oct 5, 2026
9376035
CloudNativePG: a Configuration tab built for the Cluster, cards on it…
nadaverell Oct 5, 2026
70513a8
CloudNativePG: the Cluster page states no more than it read
nadaverell Oct 5, 2026
50dfafb
CloudNativePG: backups, actions and Connect show what blocks and what…
nadaverell Oct 5, 2026
d3494c7
CloudNativePG: one plain story across backups, the summary and the tabs
nadaverell Oct 5, 2026
b748800
CloudNativePG: Configuration, Pooler, drawers and logs read plainly a…
nadaverell Oct 5, 2026
bcfef1b
CloudNativePG: the Cluster tabs say each fact once, exactly
nadaverell Oct 6, 2026
6e7a761
CloudNativePG: the fleet, drawers, dialogs and Connect say what to do
nadaverell Oct 6, 2026
29583b2
CloudNativePG: last fixes from the final screen check
nadaverell Oct 6, 2026
e68fa22
CloudNativePG: Connect names the kubeconfig context; unmodeled backup…
nadaverell Oct 6, 2026
113bd54
CloudNativePG: a barman-cloud backup's destination comes from its Clu…
nadaverell Oct 6, 2026
55b9060
CloudNativePG: schedules no longer affect the restore assessment
nadaverell Oct 6, 2026
8800398
refactor: consolidate CNPG domain rules and host boundaries
nadaverell Oct 6, 2026
a974d3d
Extract CNPG orchestration and compose integration hosts
nadaverell Oct 6, 2026
788d9cc
Preserve CNPG creation intent and restore drafts
nadaverell Oct 6, 2026
17ac2f0
Complete guided CNPG setup, recovery targets and operation handoff
nadaverell Oct 7, 2026
f10f684
Verify existing Barman plugins enable WAL archiving without a false n…
nadaverell Oct 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
14 changes: 14 additions & 0 deletions .design-sync/previews/AlertBanner.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -49,3 +49,17 @@ export function CustomIcon() {
</div>
)
}

export function WithAction() {
return (
<div style={wrap}>
<AlertBanner
variant="warning"
title="The operator is not reconciling: status below may be stale"
message="The operator Deployment has no ready Pod."
action={<button type="button" className="text-xs font-medium text-accent-text hover:underline">Open Operator →</button>}
className="px-3 py-2"
/>
</div>
)
}
6 changes: 4 additions & 2 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ Not everything is in this file. The following files contain critical details tha
| Adding or modifying **HTTP endpoints** | `internal/server/server.go` — all routes are defined here — **plus** the handler's doc comments (why the route is gated the way it is lives there; copy the gate of the closest sibling only after reading it) and the integration's section in [docs/integrations.md](docs/integrations.md) |
| Adding or modifying **CLI flags** | `cmd/explorer/main.go` — flag definitions and defaults |
| Adding a **new CRD integration** (renderer, topology, discovery) | [docs/INTEGRATION_GUIDE.md](docs/INTEGRATION_GUIDE.md) — full checklist with collision gotchas |
| Building a **workspace integration** (several related CRDs with their own screens, like `/cnpg` or `/capacity`) | [docs/INTEGRATION_GUIDE.md](docs/INTEGRATION_GUIDE.md#3-workspace-integrations) — the shared server, UI and action pieces to import, and what is not shared yet; [DESIGN.md](DESIGN.md#unknown-partial-and-denied-values) — how unknown, partial and denied values read |
| Working on the **CloudNativePG workspace** (`/cnpg`) | [docs/cnpg.md](docs/cnpg.md) — destinations, navigation (drawer trail, return label, `ctx` guard) and the certainty table: which source each fact comes from and what it reads when unknown. Data from `/api/cnpg/workspace` (per-kind coverage); derivations in `packages/k8s-ui/src/components/cnpg/workspace.ts` + `relations.ts`; screens in `web/src/components/cnpg/` |
| Working on **local per-cluster integration settings** (Metrics, Argo CD, Cost in `~/.radar/clusters.json`) | [docs/configuration.md](docs/configuration.md#local-integration-connections) — store `internal/config/profiles.go`, resolve/update `internal/connections`, activation `internal/connectionruntime`, routes `GET/PUT /api/integrations/connections`. In local mode the older `PUT /api/integrations/{prometheus,argocd,cost}` return 409 |
| Working on **GitOps** (Argo CD / Flux detail pages, operations, Terminating lifecycle, drift, per-resource health, remote destinations) | [docs/gitops.md](docs/gitops.md) — detail-page tabs, operation semantics, the Terminating severity ramp, nested navigation, single-cluster scope. Engine in `pkg/gitops/`, handlers `internal/server/gitops_handlers.go` |
Expand Down Expand Up @@ -108,7 +109,7 @@ After `make <name>-demo`, run `kubectl config use-context kind-radar-<name>-demo
| GitOps | `make gitops-demo` | Argo CD / Flux UI. `-drift` induces live OutOfSync |
| Kyverno | `make kyverno-demo` | Policy renderers, report-family selection, admission attribution. Scenarios `openreports` / `modern-only` |
| Velero | `make velero-demo` | Backup/restore surfaces — all 13 Backup phases at once. `-live` for states the controller actually produced |
| CloudNativePG | `make cnpg-demo` | CNPG renderers/badges. `-live` for real failovers; fixtures have strict ordering constraints |
| CloudNativePG | `make cnpg-demo` | CNPG renderers/badges. `-live` for real failovers; `-runtime` adds real backups/restore, load, lock chain + Prometheus; fixtures have strict ordering constraints |
| Beyla | `make beyla-demo` | `internal/traffic/beyla.go` — which labels exist depends on Beyla config, not code. Modes `attrs` / `no-network` |
| Cilium | `make cilium-demo` | `internal/traffic/hubble.go` — every Hubble connection lane. Modes `tls` / `netpol` / `install-radar` |
| Kubecost | `make kubecost-demo` | Kubecost 3 current costs — real allocation/assets, local port-forward and in-cluster Service DNS. Modes `query` / `install-radar` / `radar-smoke` |
Expand Down Expand Up @@ -139,6 +140,7 @@ After `make <name>-demo`, run `kubectl config use-context kind-radar-<name>-demo
- Helm: `/api/helm/releases/...`
- Workloads: `/api/workloads/{kind}/{ns}/{name}/...` (logs, restart, scale, revisions, rollback, images, history). `revisions`/`rollback` accept Deployment, StatefulSet, DaemonSet and **Rollout**, gated by `rollbackableWorkloadKinds` in `server.go`; `images` accepts the same four through a separate map, `workloadImageRoots` in `pkg/k8score/workload_images.go` (a new kind needs both), uses compare-and-swap JSON Patch, and follows a Rollout's `workloadRef`. `history` is the workload's own timeline and never includes sibling workloads — scope rules live in `workload_history.go` and `pkg/timeline`'s `ResourceScope`
- Argo Rollouts: `/api/rollouts/{ns}/{name}/{abort,retry,promote,promote-full,skip-step}` (POST) + `/capabilities` (GET); rollback/history deliberately live on the `/workloads` routes. The status verbs patch the `rollouts/status` subresource, so capabilities SAR `rollouts` **and** `rollouts/status` separately — `patch rollouts` does not imply `patch rollouts/status`. Promotion waits for the controller to observe the current pod template, so `promote-full` can return **503** (`ErrControllerNotCaughtUp`) and is safe to retry; for a `workloadRef` Rollout the caller must be able to `get` the referenced workload. Engine `pkg/rollouts`, handlers `internal/server/rollouts_handlers.go`
- GitOps write evidence: `POST /api/gitops/write-evidence` `{kind, group, namespace, name, paths[], owner?}` reads the target (and its GitOps owner) directly as the caller and returns, per field path, whether it appears in last-applied, which field managers own it, and whether an ignore rule covers it, plus the owner's sync policy — never raw managedFields/last-applied. Classification into none/info/may-revert/will-revert is the pure `evaluateGitOpsWriteGuard` in k8s-ui (`utils/gitops-write-guard.ts`); every write dialog shows it via `GitOpsWriteWarning` + `web/src/hooks/useGitOpsWriteGuard.ts`. Copy never promises a change won't be reverted.
- GitOps controller actions: `/api/argo/applications/...` (sync, refresh, terminate, suspend, resume, rollback, selective-sync), `/api/flux/{kind}/...` (reconcile, suspend, resume, sync-with-source)
- Argo CD API integration: `PUT /api/integrations/argocd` (non-local config only — local mode uses `/api/integrations/connections`; URL/token, probe-before-persist, token preserved across GET-redaction round-trips); `/api/argo/applications/{ns}/{name}/resource-diff` (Git-rendered desired vs live via argocd-server managed-resources; dual RBAC gate + structural Secret redaction; see docs/gitops.md)
- GitOps detail data: `/api/gitops/{tree,insights,destination}/{kind}/{ns}/{name}`. `destination` says where a remote Application or `spec.kubeConfig` Flux object deploys; the object and any kubeconfig Secret are read as the caller, and full server URLs never leave the server
Expand All @@ -153,7 +155,7 @@ After `make <name>-demo`, run `kubectl config use-context kind-radar-<name>-demo
- RBAC reverse-lookup: `/api/rbac/subject/{kind}/{namespace}/{name}` (ServiceAccount, plus `usedByPods`) and `/api/rbac/subject/{kind}/{name}` (User/Group) — direct + group-inherited bindings and flattened effective rules; `/api/rbac/role/{kind}/{namespace}/{name}` (`_` for a ClusterRole's namespace) — the bindings that reference it; `/api/rbac/namespace/{namespace}` — backs the Namespace RBAC section (group-only ClusterRoleBindings deliberately excluded); `/api/rbac/whoami` — `SelfSubjectRulesReview` pass-through. All gate on `list rolebindings` AND `list clusterrolebindings`: **403 when either is denied, never a silent partial view**
- Policy (Kyverno): `/api/policy/resource/{kind}/{ns}/{name}` (one resource's findings), `/api/policy/policies/{policy}` (every resource one policy recorded an outcome for). Report families are authorized **per subject scope** (`policyreports` cluster-wide ≠ `clusterpolicyreports`); findings from an unreadable family are dropped from lists AND counts, with the withheld count reported; `counts` describe the cluster while subject lists are capped and view-filtered. `/api/policy/policies/{policy}/queued` reads Kyverno's `UpdateRequest`s cluster-wide, gated on `list updaterequests`
- Velero: `/api/velero/backupstoragelocations/{ns}/{name}/backups` (what a location holds; gated on `list backups`); `POST /api/velero/{backups|restores}/{ns}/{name}/messages` (a run's warnings/errors via a `DownloadRequest` — impersonated; needs a running Velero controller and object storage reachable from Radar, and reports which one failed)
- CloudNativePG: `/api/cnpg/...` — the workspace, operator, catalog reverse-lookups, Cluster logs and activity. Routes, gates and coverage states are listed in [docs/cnpg.md](docs/cnpg.md#api); each is gated on the caller's own access, and a partial answer says what it withheld
- CloudNativePG: `/api/cnpg/...` — the workspace, operator status and diagnosis, catalog reverse-lookups, and per Cluster: runtime, storage, HA facts, history, logs, activity, sessions, restore, report bundle and actions (plus Pooler and ScheduledBackup actions). Routes, gates and coverage states are listed in [docs/cnpg.md](docs/cnpg.md#api); each is gated on the caller's own access, a partial answer says what it withheld, and every write binds the facts the user reviewed

## Key Patterns

Expand Down
12 changes: 12 additions & 0 deletions DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,7 @@ Standard Tailwind type scale. No custom sizes or tracking. Use Tailwind utilitie
| `.btn-brand` | Primary CTAs — brand-colored bg, white text, 10px radius |
| `.btn-brand-muted` | Secondary brand actions — dimmed brand bg, white text |
| `.btn-brand-toggle` | Toggle buttons — 50% brand bg, primary text |
| `.btn-secondary` | Secondary actions beside a `.btn-brand` — bordered surface bg, primary text, 10px radius |

Hover/disabled states are built into the classes. For non-brand buttons, use shadcn/ui `<Button>` variants.

Expand Down Expand Up @@ -172,6 +173,17 @@ Use CSS classes from `components.css` for status cells in table rows:
| `.border-r-subtle` | Right border |
| `.border-t-subtle` | Top border |

### Unknown, partial and denied values
Radar shows only what the cluster reports, and says where it came from. These rules apply to every surface that reads several sources at once (workspace integrations such as Capacity and CloudNativePG, multi-source detail pages):

- **Unavailable ≠ zero.** A value Radar could not read (no access, not installed, not cached, the request failed) renders as unread, naming why — never as `0`, "none" or a healthy colour. A missing grant is named exactly (`GrantText`, `formatGrant`).
- **Partial ≠ exact.** A count or total over data read only in part is a lower bound: `≥N` (`CertaintyGlyph`, `SidebarCategoryDestination.countLowerBound`), and a zero over partial data is unknown, not none.
- **Unread is listed, not left out.** A summary line names what it could not read ("not read: Pods, zones"); a combined tone is never calmer than a part that was not read (`worseTone` ranks `unknown` above `healthy`).
- **Recorded ≠ observed.** A value copied from a status field, an annotation or a declaration says so; a value matched to its subject by name rather than by identity says that too.
- **Facts keep their rows.** `FactRow` renders the unread text in place; never hide a row because its value is missing (unlike `Property`, which hides empty values).

The shared pieces live in `packages/k8s-ui/src/components/facts/` (facts, certainty, GitOps manager), `components/problems/` (problems with their sources), `components/ui/FoldSection.tsx` (section headings and folded sections) and `web/src/components/workspace/` (workspace screen layout and tables); each integration's own doc lists which source each value comes from and how it reads when unknown.

## 5. Layout Principles

### Spacing
Expand Down
11 changes: 11 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -278,6 +278,16 @@ cnpg-demo-status:
cnpg-demo-live:
./scripts/cnpg-demo.sh live

# Runtime fixtures on the EXISTING CNPG demo cluster (operator thawed if frozen):
# MinIO + real plugin WAL archiving and backups, a restored cluster, a Pooler,
# pgbench load, a blocked lock chain and a Prometheus Radar auto-discovers.
# `./scripts/cnpg-demo.sh runtime-lag on|off` induces replica lag.
cnpg-demo-runtime:
./scripts/cnpg-demo.sh runtime

cnpg-demo-runtime-down:
./scripts/cnpg-demo.sh runtime-down

# Grafana Beyla on kind: eBPF loaded, a minimal Prometheus scraping it, and two
# conversations to observe. Which labels Beyla exports depends on configuration —
# dst_port and transport are off by default, direction is on and doubles every
Expand Down Expand Up @@ -523,6 +533,7 @@ help:
@echo " make rollouts-demo - Argo Rollouts progression fixtures"
@echo " make cnpg-demo - Frozen CNPG rendering fixtures"
@echo " make cnpg-demo-live - CNPG fixtures with the operator running"
@echo " make cnpg-demo-runtime - CNPG runtime: backups/restore, load, locks, Prometheus"
@echo " make velero-demo - Velero fixtures, all 13 backup phases at once"
@echo " make velero-demo-live - Velero with real object storage; states produced by the controller"
@echo " make beyla-demo - Grafana Beyla eBPF traffic fixtures"
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -362,7 +362,7 @@ View TLS certificate details and expiry dates across all namespaces — catch ex

### GitOps

Monitor, diagnose, and manage FluxCD and ArgoCD resources from a dedicated GitOps workspace.
Monitor, diagnose, and manage FluxCD and ArgoCD resources in one place.

<p align="center">
<img src="docs/screenshots/gitops-view.png" alt="GitOps fleet view" width="800">
Expand Down Expand Up @@ -548,7 +548,7 @@ Upgrade impact also gets list-only access to CSIStorageCapacities, FlowSchemas,
| **Strimzi** | [KafkaConnector failure evidence](docs/integrations.md#strimzi-kafka-connectors) (connector/task status) |
| **Velero** | Backup, Restore, Schedule, BackupStorageLocation, VolumeSnapshotLocation |
| **External Secrets** | ExternalSecret, ClusterExternalSecret, SecretStore, ClusterSecretStore |
| **CloudNativePG** | Cluster, Backup, ScheduledBackup, Pooler, Database, Publication, Subscription, ImageCatalog, ClusterImageCatalog, ObjectStore — plus a [workspace](docs/cnpg.md) for fleet, protection and declaration triage |
| **CloudNativePG** | Cluster, Backup, ScheduledBackup, Pooler, Database, Publication, Subscription, ImageCatalog, ClusterImageCatalog, ObjectStore — plus [dedicated views](docs/cnpg.md) for fleet, protection and declaration triage |
| **Crossplane** | Managed Resources (any provider), Composite Resources, Claims, Provider, ProviderConfig, Function, Configuration, Composition, CompositionRevision, XRD |
| **Kyverno** | Policy, ClusterPolicy, PolicyReport, ClusterPolicyReport |
| **Sealed Secrets** | SealedSecret |
Expand Down
2 changes: 1 addition & 1 deletion deploy/helm/radar/files/integration-read-baseline.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -613,7 +613,7 @@ entries:
reason: "Includes spec.externalClusters[].connectionParameters; inline connection settings (potentially passwords) are intentionally visible, like Helm values."
source: "https://cloudnative-pg.io/docs/1.28/logical_replication/"
- group: "postgresql.cnpg.io"
resources: ["backups","databases","imagecatalogs","poolers","publications","scheduledbackups","subscriptions"]
resources: ["backups","databaseroles","databases","failoverquorums","imagecatalogs","poolers","publications","scheduledbackups","subscriptions"]
scope: Namespaced
collection: "cloudnativePg"
decision: grant
Expand Down
8 changes: 8 additions & 0 deletions deploy/helm/radar/templates/cloud-rbac-cluster-read.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,11 @@ bindings to the radar:* groups — deliberately NOT via `aggregate-to-view` labe
which would widen the shared built-in `view`/`edit` roles cluster-wide for every
other subject bound to them (mirrors the radar-helm add-on pattern).

Leases are namespaced but read here like infrastructure: they carry only a
holder identity and renew times (controller leader election, node heartbeats,
CloudNativePG primary election). `edit` and `admin` already include them, so
only the viewer tier gains anything.

No Secrets and no RBAC objects here — those stay gated behind the tier roles
(view excludes Secrets; RBAC visibility is rbac.viewRBAC) so this is a pure
infrastructure-read widening.
Expand Down Expand Up @@ -69,6 +74,9 @@ rules:
- apiGroups: ["scheduling.k8s.io"]
resources: ["priorityclasses"]
verbs: ["get", "list", "watch"]
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["get", "list", "watch"]
- apiGroups: ["certificates.k8s.io"]
resources: ["clustertrustbundles"]
verbs: ["get", "list", "watch"]
Expand Down
6 changes: 6 additions & 0 deletions deploy/helm/radar/tests/cloud_rbac_cluster_read_test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,12 @@ tests:
apiGroups: ["scheduling.k8s.io"]
resources: ["priorityclasses"]
verbs: ["get", "list", "watch"]
- contains:
path: rules
content:
apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["get", "list", "watch"]
- contains:
path: rules
content:
Expand Down
Loading