Repository navigation
Resolve KEDA GCP credential Secret references from the provider schema - #2011
nadaverell wants to merge 3 commits into
Conversation
PR Summary by QodoResolve KEDA GCP credential Secret references from the provider schema
AI Description
Diagram
High-Level Assessment
Files changed (4)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can route each severity your way: inline, summary, both, or drop |
KEDA GCP Secret Manager credentials are nested under
credentials.clientSecret.valueFrom.secretKeyRef. Radar's audit adapter and authentication drawer read a shallow field that does not exist in the provider contract, so they miss the credential Secret. Read the actual nested name/key and link namespaced TriggerAuthentication credentials to the correct Secret.ClusterTriggerAuthentication credential names remain visible as plain text: its operator credential namespace is not available in this drawer. Apply that same scope rule to its direct Secret references rather than navigating to a fictional cluster-scoped Secret. Resolving the operator namespace is a separate change. No Secret values, key existence, cloud authentication, graph edges or Diagnose expansion are claimed.
Scope: existing supported KEDA config-reference extraction for the unused-ConfigMap/Secret audit, plus shared authentication drawers and package consumers after normal updates. This corrects an existing relationship rather than adding a new generic reference parser. The KEDA v2.21 GCP provider contract is the source of the field path.
Validation: complete internal audit suite and three drawer interaction/schema cases pass; type check, production frontend/embed/backend build and full root
make testpass. Actual isolated-kind browser navigation reaches the correct namespaced empty Secret. A live MCP audit counterfactual flags that Secret as unused after removing only the nested credential reference, then clears the finding when the reference is restored. The fixture has no credential values or KEDA controller, and does not prove cloud authentication. The settled capture was inspected.Note
Low Risk
Corrects config-reference paths and UI linking for KEDA auth resources; no changes to authentication, secret values, or cluster credential namespace resolution.
Overview
Aligns KEDA GCP Secret Manager credential tracking with the provider schema: both the audit TriggerAuthentication config-ref extractor and KedaTriggerAuthRenderer now read
credentials.clientSecret.valueFrom.secretKeyRef(name/key) instead of a non-existent shallowclientSecret.name, so unused-Secret audit and the drawer surface the real credential Secret.The drawer links namespaced credential and
secretTargetRefSecrets viaResourceLink; without a resource namespace (e.g. ClusterTriggerAuthentication), those names stay plain text so navigation does not target invented cluster-scoped Secrets. A regression test ensures the old shallow GCP shape is ignored.Reviewed by Cursor Bugbot for commit 88d0855. Bugbot is set up for automated code reviews on this repo. Configure here.