Skip to content

Fix three errors that prevent the template from applying - #2

Merged
chuck-alt-delete merged 3 commits into
mainfrom
feat/fix-appgroup-policyref
Sep 14, 2026
Merged

chuck-alt-delete merged 3 commits into
mainfrom
feat/fix-appgroup-policyref

Conversation

@chuck-alt-delete

Copy link
Copy Markdown
Collaborator

Three defects found by applying this repo's platform/ and applications/ directories against a live Console 1.47.1. The first one blocks apply-platform.yml entirely.

1. appgroup-restrictions cannot attach to an ApplicationInstance

An ApplicationInstance's spec.policyRef accepts only Topic, Connector and Subject policies (allowedApplicationInstancePolicies in console-plus). Naming an ApplicationGroup policy there fails the apply:

Could not apply resource ApplicationInstance/payments-dev: Policy with name
'appgroup-restrictions' has ApplicationGroup but only [Connector, Topic, Subject] are allowed

Both instances hit this, so apply-platform.yml could not have succeeded as shipped.

Application.spec.policyRef has no kind restriction, and a policy attached there covers every instance — so appgroup-restrictions moves to application.yml.

2. The prod KafkaCluster is named kafka-dev

platform/clusters/prod/kafka-prod.yml declared metadata.name: kafka-dev. Because apply-clusters.yml applies platform/clusters/<instance>/ with that instance's environment secrets, running it for prod would not create a prod cluster — it would repoint the existing dev cluster at the prod bootstrap servers and prod credentials.

3. Prod topics reference a cluster that doesn't exist

applications/payments/prod/topics.yml referenced cluster: "my-kafka-cluster", matching no KafkaCluster and not the prod ApplicationInstance:

Could not apply resource Topic/payments.transactions: Cluster my-kafka-cluster not found

Verification

Applied against Console 1.47.1 with stand-in kafka-dev / kafka-prod clusters:

  • platform/groups/, platform/policies/, platform/applications/payments/ all apply cleanly
  • appgroup-restrictions still enforces from the Application level — an ApplicationGroup with direct members and prod write access is rejected on both rules
  • applications/payments/{dev,prod}/ apply cleanly

The README gains a short note on where each policy kind attaches, since the constraint isn't documented anywhere and the mistake is easy to repeat.

Commits are separable: the blocking fix is first, the two copy-paste fixes second.

🤖 Generated with Claude Code

chuck-alt-delete and others added 2 commits September 14, 2026 14:14
An ApplicationInstance's spec.policyRef accepts only Topic, Connector and
Subject policies (allowedApplicationInstancePolicies in console-plus), so
naming an ApplicationGroup policy there fails the apply outright:

  Could not apply resource ApplicationInstance/payments-dev: Policy with
  name 'appgroup-restrictions' has ApplicationGroup but only
  [Connector, Topic, Subject] are allowed

Both instances hit this, so apply-platform.yml could never have succeeded
as shipped. Application spec.policyRef has no kind restriction, and a
policy attached there covers every instance.

Verified against Console 1.47.1: the applications now apply cleanly, and
appgroup-restrictions still rejects an ApplicationGroup with direct
members and prod write permissions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two copy-paste errors found while verifying the policyRef fix against a
live Console.

platform/clusters/prod/kafka-prod.yml declared metadata.name: kafka-dev.
Since apply-clusters.yml applies platform/clusters/<instance>/ with that
instance's environment secrets, running it for prod would not create a
prod cluster — it would repoint the existing dev cluster at the prod
bootstrap servers and prod credentials.

applications/payments/prod/topics.yml referenced cluster
"my-kafka-cluster", which matches no KafkaCluster and not the prod
ApplicationInstance. Applying it failed with "Cluster my-kafka-cluster
not found"; with the reference corrected the topic applies.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The policyRef placement is covered in the README.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@chuck-alt-delete
chuck-alt-delete merged commit 0ac048b into main Sep 14, 2026
2 of 4 checks passed
@chuck-alt-delete
chuck-alt-delete deleted the feat/fix-appgroup-policyref branch September 14, 2026 21:22

This branch had an error being deployed

2 failed deployments
kafka-prod — bde29457 Deployed Sep 14, 2026 by chuck-alt-delete via apply #3
payments-prod — bde29457 Deployed Sep 14, 2026 by chuck-alt-delete via apply #6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant