Repository navigation
Fix three errors that prevent the template from applying - #2
Merged
Merged
Conversation
An ApplicationInstance's spec.policyRef accepts only Topic, Connector and Subject policies (allowedApplicationInstancePolicies in console-plus), so naming an ApplicationGroup policy there fails the apply outright: Could not apply resource ApplicationInstance/payments-dev: Policy with name 'appgroup-restrictions' has ApplicationGroup but only [Connector, Topic, Subject] are allowed Both instances hit this, so apply-platform.yml could never have succeeded as shipped. Application spec.policyRef has no kind restriction, and a policy attached there covers every instance. Verified against Console 1.47.1: the applications now apply cleanly, and appgroup-restrictions still rejects an ApplicationGroup with direct members and prod write permissions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two copy-paste errors found while verifying the policyRef fix against a live Console. platform/clusters/prod/kafka-prod.yml declared metadata.name: kafka-dev. Since apply-clusters.yml applies platform/clusters/<instance>/ with that instance's environment secrets, running it for prod would not create a prod cluster — it would repoint the existing dev cluster at the prod bootstrap servers and prod credentials. applications/payments/prod/topics.yml referenced cluster "my-kafka-cluster", which matches no KafkaCluster and not the prod ApplicationInstance. Applying it failed with "Cluster my-kafka-cluster not found"; with the reference corrected the topic applies. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
chuck-alt-delete
had a problem deploying
to
payments-prod
September 14, 2026 21:19 — with
GitHub Actions
Failure
chuck-alt-delete
had a problem deploying
to
kafka-prod
September 14, 2026 21:19 — with
GitHub Actions
Failure
The policyRef placement is covered in the README. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
chuck-alt-delete
had a problem deploying
to
payments-prod
September 14, 2026 21:19 — with
GitHub Actions
Failure
chuck-alt-delete
had a problem deploying
to
kafka-prod
September 14, 2026 21:19 — with
GitHub Actions
Failure
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three defects found by applying this repo's
platform/andapplications/directories against a live Console 1.47.1. The first one blocksapply-platform.ymlentirely.1.
appgroup-restrictionscannot attach to an ApplicationInstanceAn ApplicationInstance's
spec.policyRefaccepts onlyTopic,ConnectorandSubjectpolicies (allowedApplicationInstancePoliciesin console-plus). Naming anApplicationGrouppolicy there fails the apply:Both instances hit this, so
apply-platform.ymlcould not have succeeded as shipped.Application.spec.policyRefhas no kind restriction, and a policy attached there covers every instance — soappgroup-restrictionsmoves toapplication.yml.2. The prod KafkaCluster is named
kafka-devplatform/clusters/prod/kafka-prod.ymldeclaredmetadata.name: kafka-dev. Becauseapply-clusters.ymlappliesplatform/clusters/<instance>/with that instance's environment secrets, running it for prod would not create a prod cluster — it would repoint the existing dev cluster at the prod bootstrap servers and prod credentials.3. Prod topics reference a cluster that doesn't exist
applications/payments/prod/topics.ymlreferencedcluster: "my-kafka-cluster", matching no KafkaCluster and not the prod ApplicationInstance:Verification
Applied against Console 1.47.1 with stand-in
kafka-dev/kafka-prodclusters:platform/groups/,platform/policies/,platform/applications/payments/all apply cleanlyappgroup-restrictionsstill enforces from the Application level — an ApplicationGroup with direct members and prod write access is rejected on both rulesapplications/payments/{dev,prod}/apply cleanlyThe README gains a short note on where each policy kind attaches, since the constraint isn't documented anywhere and the mistake is easy to repeat.
Commits are separable: the blocking fix is first, the two copy-paste fixes second.
🤖 Generated with Claude Code