labels

package
v0.22.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: Apache-2.0 Imports: 1 Imported by: 0

Documentation

Overview

Package labels provides shared Kubernetes label constants used by both the validator (pkg/validator) and the snapshot agent (pkg/k8s/agent), so neither has to import the other to agree on label keys and values.

Index

Constants

View Source
const (
	Name      = "app.kubernetes.io/name"
	Component = "app.kubernetes.io/component"
	ManagedBy = "app.kubernetes.io/managed-by"
)

Standard Kubernetes label keys.

View Source
const (
	// ValueAICR is the shared app name.
	ValueAICR = "aicr"

	// ValueSnapshotAgent identifies snapshot-agent-owned resources.
	ValueSnapshotAgent = "snapshot-agent"

	// ValueAgentRBAC identifies the NON-run-scoped Role, RoleBinding,
	// ClusterRole and ClusterRoleBinding that
	// `aicr snapshot --add-roles-to-service-account` renders as manifests
	// for an operator-supplied ServiceAccount. aicr applies none of them;
	// the operator does. Objects carrying this value are deliberately
	// outside every run's lifecycle: they carry no RunID label, never
	// enter a run's created-set, and are never deleted by run cleanup.
	// Teardown is the operator's `kubectl delete -f`.
	ValueAgentRBAC = "agent-rbac"
)

Common label values.

View Source
const InvocationID = header.Domain + "/invocation-id"

InvocationID identifies the single in-process invocation — one snapshot-agent Deployer — that created an object, as distinct from the run it belongs to.

It exists because RunID cannot answer "did I create this?". RunID is public, caller-settable SDK surface, and sharing one across invocations is a designed scenario: `aicr validate` hands the same ID to its live-capture agent and to its validator Jobs, and e2e/chainsaw runs pin a value on purpose. Two invocations sharing a RunID therefore stamp byte-identical Name/ManagedBy/Component/RunID labels, so that set proves membership in a run but never authorship by one invocation.

The value is generated inside the Deployer with runid.Generate() and is reachable through no configuration field, so a second invocation cannot reproduce it even when it reuses the RunID verbatim. Cleanup requires it before adopting an object whose creation it never had confirmed.

View Source
const RunID = header.Domain + "/run-id"

RunID scopes every resource to the run that created it.

Variables

This section is empty.

Functions

This section is empty.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL