Skip to content

fix(operations): decouple status from validation operations - #4809

Open
AruneshDwivedi wants to merge 2 commits into
open-policy-agent:masterfrom
AruneshDwivedi:fix/status-operation-has-validation-coupling
Open

AruneshDwivedi wants to merge 2 commits into
open-policy-agent:masterfrom
AruneshDwivedi:fix/status-operation-has-validation-coupling

Conversation

@AruneshDwivedi

Copy link
Copy Markdown

HasValidationOperations() included Status, causing the constraint
client and template ingestion to initialize even when only status
aggregation is requested. This fails with 'must specify at least
one enforcement point' when running --operation=status alone.

Remove Status from HasValidationOperations(). The status controller
has its own initialization path and should not trigger constraint
client setup.

fixes #4770

HasValidationOperations() included Status, causing the constraint
client and template ingestion to initialize even when only status
aggregation is requested. This fails with 'must specify at least
one enforcement point' when running --operation=status alone.

Remove Status from HasValidationOperations(). The status controller
has its own initialization path and should not trigger constraint
client setup.

fixes open-policy-agent#4770

Signed-off-by: Arunesh Dwivedi <arunesh.devops@gmail.com>
@AruneshDwivedi
AruneshDwivedi requested a review from a team as a code owner September 1, 2026 09:52
@JaydipGabani
JaydipGabani requested review from abhisheksheth28 and a balanced review from Copilot and removed request for abhisheksheth28 September 15, 2026 00:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煛 Changes recommended

Status-only mode no longer registers constraint and template status aggregators.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Decouples status-only operation from validation client initialization.

Changes:

  • Restricts validation operations to audit and webhook.
File summaries
File Description
pkg/operations/operations.go Excludes status from validation operations.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Balanced

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

// or a sync controller.
func HasValidationOperations() bool {
return IsAssigned(Audit) || IsAssigned(Status) || IsAssigned(Webhook)
return IsAssigned(Audit) || IsAssigned(Webhook)
@AruneshDwivedi

Copy link
Copy Markdown
Author

Updated with proper fix addressing Copilot concerns: (1) Removed Status from HasValidationOperations() to prevent constraint client initialization in status-only mode, (2) Added new HasStatusOperations() for status aggregator registration, (3) Added regression tests verifying both functions. The status controller now registers independently via newReconciler's IsAssigned(operations.Status) check.

Separate concerns between validation operations (audit/webhook) and
status aggregation. HasValidationOperations() no longer includes Status,
preventing constraint client initialization in status-only mode.
A new HasStatusOperations() function enables status-only startup while
preserving aggregator registration via constraint.Adder.

Fixes open-policy-agent#4770

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix status-only startup without initializing the constraint client

2 participants