Skip to main content

GATEWAY_API_KEY_PARENT_REFS

Constant GATEWAY_API_KEY_PARENT_REFS 

Source
pub const GATEWAY_API_KEY_PARENT_REFS: &str = "parentRefs";
Expand description

Canonical K8s Gateway API HTTPRoute parent-Gateway-binding container- axis key every gateway_routes-emitted HTTPRoute document mounts its per-route parent-Gateway [{name}] list under (spec.parentRefs[]). Pairs with the sibling GATEWAY_API_KIND_HTTP_ROUTE (1adccc0) + GATEWAY_API_KIND_GATEWAY (fb4639c) — the Gateway API v1 CRD schema pins the per-HTTPRoute parent-Gateway identity through the spec.parentRefs[] container axis (each entry names the parent Gateway the route attaches to; the sibling hostnames + rules container axes carry the per-route host-match + per-rule L7-dispatch halves under the same spec block), so drift on the parent-Gateway- binding axis is exactly as load-bearing as drift on the per-HTTPRoute kind discriminator axis it accompanies (the K8s apiserver-side Gateway API CRD schema validator drops any spec block whose parent- binding container axis carries an unrecognized key — a "parentRef" / "parents" / "parentGateways" typo silently emits an HTTPRoute whose parent-Gateway attachment the Gateway API implementation’s per-HTTPRoute reconcile loop no-ops entirely: the route lands unattached to any Gateway, and every external :entrada flow the HTTPRoute was authored to accept drops at the Gateway API implementation’s per-Gateway HTTP-listener fan-in with no field naming the parent-Gateway-binding-axis-drift root cause).

The single source of truth the rendered Aplicacao Gateway-API-side ingress bundle’s per-HTTPRoute parent-Gateway-binding-axis-naming reaches for:

  • the rendered HTTPRoute document’s spec.parentRefs[] axis (caixa-mesh/src/lib.rs:1389 — the gateway_routes per-Aplicacao HTTPRoute’s r_spec.insert("parentRefs", …) call).

The parent-Gateway-binding axis names the same Gateway-API- implementation-side per-HTTPRoute route→Gateway attachment container as the sibling GATEWAY_API_KIND_HTTP_ROUTE + GATEWAY_API_KIND_GATEWAY CRD kind discriminators the pair declares together, and must move together on any future Gateway API rebrand (an upstream Gateway API v2 rename of the parent-binding axis from parentRefs to parents / parentGateways / attachedTo, coordinated with the upstream SIG-Network Gateway API deprecation cycle). Until this lift landed the axis carried an inline parentRefs literal at the one production-code occurrence in caixa-mesh/src/lib.rs:1389 (the gateway_routes r_spec.insert("parentRefs", …) call) — the single load-bearing Gateway-API-CRD-parentRefs-axis-key occurrence, drift-prone by construction. A drift on the production site to "parentRef" / "parents" / "parentGateways" would have surfaced as a Gateway- API-implementation-side schema validator drop at apply time (the affected HTTPRoute’s parent-Gateway-binding axis the CRD schema validator recognizes as unknown), with every external :entrada flow the HTTPRoute was authored to accept dropping at the Gateway API implementation’s per-Gateway HTTP-listener fan-in with no field naming the parent-Gateway-binding-drift root cause.

The PRIME DIRECTIVE duplication-budget rule (THEORY.md §I.3.5, “every recurring shape becomes a generator before it becomes a pattern; every pattern becomes a library before it becomes duplicated code. The duplication budget is zero.”) promotes the constant to a typed substrate-side &'static str on the same trajectory the CILIUM_KEY_PORTS (1087693) / CILIUM_KEY_FROM_ENDPOINTS (ecfa557) / CILIUM_KEY_INGRESS (0400a9b) / CILIUM_KEY_ENDPOINT_SELECTOR (7088789) / CILIUM_KEY_TO_PORTS (c8d9cbf) / KUBE_KEY_RULES (a205eb3) / GATEWAY_API_KIND_HTTP_ROUTE (1adccc0) / GATEWAY_API_KIND_GATEWAY (fb4639c) lifts established on the sibling canonical-Cilium-CNP-body-axis / canonical-Gateway-API-CRD-kind-discriminator surfaces — pivots the per-CNP-body-axis lift discipline onto the sibling per-HTTPRoute- body-axis surface, beginning the per-Gateway-API-HTTPRoute-body-axis canonical-string-pin set (parentRefs, hostnames) the M3 Aplicacao mesh renderer’s external :entrada ingress contract rests on across the Gateway API HTTPRoute-side per-route body-shape. The render-side consumer now threads the same &'static str through its r_spec.insert(…) call so a future Gateway API rebrand on the parent-Gateway-binding axis (or an upstream SIG-Network Gateway API v2 rename to a per-CRD sibling name) lands in one place; every future renderer that reaches for the canonical per-HTTPRoute parent- Gateway-binding axis (the future M4 mesh.pleme.io/v1alpha1/Aplicacao CR materializer’s per-Aplicacao HTTPRoute fan-out, a future per-edge TCPRoute / TLSRoute / GRPCRoute renderer for non-HTTP :entrada edges whose per-route parent-Gateway-binding nests under the same axis convention, a future per-Aplicacao ReferenceGrant renderer whose cross-namespace parent-Gateway attachment binds against this same axis) inherits the same value by construction with no opportunity for per-renderer drift.

Same “the typed constant lives in one place” discipline the CILIUM_KEY_PORTS (1087693) / CILIUM_KEY_FROM_ENDPOINTS (ecfa557) / CILIUM_KEY_INGRESS (0400a9b) / CILIUM_KEY_ENDPOINT_SELECTOR (7088789) / CILIUM_KEY_TO_PORTS (c8d9cbf) / KUBE_KEY_RULES (a205eb3) / GATEWAY_API_KIND_HTTP_ROUTE (1adccc0) / GATEWAY_API_KIND_GATEWAY (fb4639c) lifts apply on the peer canonical-Gateway-API-HTTPRoute-body-axis surface.