fix(control-plane): product-scope TenantRegistry keys (#8024) - #8029
Conversation
Key registry storage and HTTP conflict/delete lookups by
${product}:${name} so same-named ORB and AMS tenants stay independent.
Co-authored-by: Cursor <cursoragent@cursor.com>
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
|
Tip ✅ LoopOver review result - approve/merge recommendedReview updated: 2026-07-22 17:23:59 UTC
Review summary Nits — 3 non-blocking
Decision drivers
Context & advisory signals — never blocks the verdict
Linked issue satisfactionAddressed Review context
Contributor next steps
Signal definitions
🧪 Chat with LoopOverAsk LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.
Full command reference: https://loopover.ai/docs/loopover-commands 🧪 Experimental — new and may change. 🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed 💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →. Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.
|
Summary
TenantRegistry(fake + KV) keyed records by tenant name alone, so provisioning ORBacmethen AMSacmehit a false409, and deprovisioning one overwrote the other's inventory row.${product}:${name}(same ascontainer-driver.ts'sinstanceNameFor).DELETE /v1/tenants/:namerequires?product=;GET /v1/tenantsstill lists every product.Closes #8024
Scope
type(scope): short summaryConventional Commit format, for examplefix(api): restore profile access checks.CONTRIBUTING.mdand does not reintroduce GitHub Pages, VitePress,site/, orCNAME.Closes #123) — a linked open issue is required for every contributor PR.Validation
git diff --checknpm run actionlintnpm run typechecknpm run test:coveragelocally;codecov/patchrequires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.npm run test:workersnpm run build:mcpnpm run test:mcp-packnpm run ui:openapi:checknpm run ui:lintnpm run ui:typechecknpm run ui:buildnpm audit --audit-level=moderateIf any required check was skipped, explain why:
npm --prefix control-plane test(98 pass) andnpm run control-plane:coverage—tenant-registry.tsandhttp-app.tsat 100% lines/branches. Root vitest/UI/MCP gates do not covercontrol-plane/src/**.Safety
UI Evidencesection below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.UI Evidence
N/A — control-plane registry/HTTP keying only; no UI.
Notes
control-plane/src/container-driver.tsinstanceNameFor/test/container-driver.test.tsproduct-scoped key test.DELETEnow requires?product=so the composite key can be resolved. MinerdestroyTenantstill omits product (follow-up if needed).