caixa_mesh/lib.rs
1//! caixa-mesh — typed renderer that emits cluster mesh primitives
2//! from an `:kind Aplicacao` caixa.
3//!
4//! See `theory/MESH-COMPOSITION.md` for the design frame: a typed
5//! Aplicacao composes Servicos into a graph with WIT-typed contracts,
6//! mesh policies, and explicit placement. caixa-mesh is the renderer
7//! that turns that typed graph into the cluster-side primitives:
8//!
9//! 1. **programs.yaml fan-out** — one entry per `:membros`,
10//! consumed by lareira-fleet-programs (V0; this crate)
11//! 2. **Cilium NetworkPolicy** — one per distinct `:contratos`
12//! `(:de, :para)` pair, identity-based L7 allow-list (M3.x next)
13//! 3. **Gateway + HTTPRoute** — one per `:entrada`, K8s Gateway API
14//! external ingress (M3.x next)
15//!
16//! Same `caixa-<target>` naming convention as [`caixa_helm`] +
17//! [`caixa_flux`]: a typed renderer that takes a typed Caixa and emits
18//! the canonical source for `<target>`.
19//!
20//! V0 contract:
21//!
22//! ```rust,ignore
23//! use caixa_core::Caixa;
24//! use caixa_mesh::programs_for_aplicacao;
25//!
26//! let aplicacao: Caixa = Caixa::from_lisp(src)?;
27//! let entries: Vec<serde_yaml::Value> = programs_for_aplicacao(&aplicacao)?;
28//! // → one entry per :membros, suitable for fan-out into the
29//! // cluster's lareira-fleet-programs HelmRelease.
30//! ```
31
32#![allow(clippy::module_name_repetitions)]
33
34use std::collections::BTreeMap;
35
36use caixa_core::{
37 Caixa, CaixaKind, FLEET_PROGRAMS_KEY_APLICACAO, FLEET_PROGRAMS_KEY_NAME,
38 FLEET_PROGRAMS_KEY_VERSAO, GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME,
39 GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT, GATEWAY_API_KEY_NAME, LABEL_APLICACAO, LABEL_CONTRATO,
40 M3_KEY_PLACEMENT, MappingExt, SequenceExt, WitContract, WitTarget, aplicacao::AplicacaoSpec,
41 kube_resource_skeleton, label_selector, pleme_program_in_aplicacao_selector,
42 pleme_program_selector, single_field_overlay,
43};
44use thiserror::Error;
45
46/// Errors caixa-mesh can raise.
47#[derive(Debug, Error)]
48pub enum Error {
49 /// The caixa's `:kind` doesn't match what `caixa-mesh` targets
50 /// (this renderer only emits the per-Aplicacao mesh artifact set
51 /// — programs.yaml fan-out + Cilium NetworkPolicies + Gateway/
52 /// HTTPRoute — for `:kind Aplicacao`). Lifted from a prior
53 /// `NotAnAplicacao(CaixaKind)` arm to wrap [`caixa_core::KindMismatch`]
54 /// so the diagnostic names the offending caixa's `:nome` (not
55 /// just its kind), shared verbatim with `caixa-helm` and
56 /// `caixa-flux`.
57 #[error("{0}")]
58 NotAnAplicacao(#[from] caixa_core::KindMismatch),
59 #[error("aplicacao typed shape violation: {0}")]
60 InvalidAplicacao(#[from] caixa_core::AplicacaoError),
61 #[error("yaml: {0}")]
62 Yaml(#[from] serde_yaml::Error),
63}
64
65/// Render one `programs.yaml` entry per `:membros` in the Aplicacao.
66///
67/// Each entry is a typed [`serde_yaml::Value::Mapping`] suitable for
68/// upserting into a `lareira-fleet-programs` HelmRelease's
69/// `spec.values.programs[]` (the same shape `caixa-flux::programs_yaml_entry`
70/// emits for individual Servico caixas).
71///
72/// V0 caveats:
73/// - The member entry has only `name` + `versao` + a passthrough
74/// `aplicacao` annotation linking it back to the parent Aplicacao.
75/// Resolving each member's full ComputeUnit (module.source,
76/// trigger, capabilities) is the resolver's job at deploy time —
77/// the resolver fetches each member's caixa.lisp from git, calls
78/// `caixa-flux::programs_yaml_entry` on it, then merges with the
79/// Aplicacao-level `politicas` overrides.
80/// - Mesh-level concerns (Cilium NetworkPolicy, Gateway) are
81/// deferred to follow-up rendering verbs in this crate (M3.x).
82pub fn programs_for_aplicacao(caixa: &Caixa) -> Result<Vec<serde_yaml::Value>, Error> {
83 // Route the entry gate through the canonical [`typed_view`] entry
84 // point so every per-Aplicacao renderer in this crate
85 // (`programs_for_aplicacao`, `cilium_network_policies`,
86 // `gateway_routes`) shares one `require_kind + aplicacao_view +
87 // AplicacaoSpec::validate` cascade. Prior to this lift
88 // `programs_for_aplicacao` re-inlined the three-arm gate while its
89 // two sibling renderers reached for `typed_view`; the drift risk
90 // was structural — a future entry-gate widening (e.g. a per-
91 // Aplicacao capability-audit prelude, a `:placement`-aware
92 // pre-render normalization, the M4 CR materializer's admission-
93 // webhook floor) would have to be threaded through both call sites
94 // in lockstep or one renderer would silently diverge from the
95 // other on which shapes it accepted at emit time. Peer with the
96 // sibling `typed_view` consumers on the same one-entry-gate
97 // discipline (a4ba8ec `require_v0_servico_shape` lifted the
98 // `require_kind(Servico) + require_single_servico` compound entry-
99 // gate across `caixa-helm` + `caixa-flux`; this lift closes the
100 // matching two-caller drift surface on `caixa-mesh`'s per-
101 // Aplicacao entry-gate).
102 let spec = typed_view(caixa)?;
103
104 // `:placement` overlay — surfaces the typed Aplicacao-level
105 // distribution strategy + cluster list (validated upstream by
106 // [`AplicacaoSpec::validate_placement`]: non-empty `:clusters`,
107 // unique entries, `Sharded` carries `:shard-key`) onto every
108 // emitted programs.yaml entry under the canonical
109 // [`M3_KEY_PLACEMENT`] key. Until this wiring landed the typed
110 // `:placement` slot was inert past validate() — `AplicacaoSpec`
111 // refused empty/duplicate clusters, missing shard-keys, and
112 // empty affinity hints (the c7c7799 + 4bb3f3d + 2d71a9a +
113 // c4213a4 typed-shape lifts), but the rendered programs.yaml
114 // entries carried only `name + versao + aplicacao`, so the
115 // lareira-fleet-programs aggregator and the future M4
116 // cross-cluster fanout / `app-operator` reconciler had no way
117 // to scope each entry by its parent Aplicacao's distribution
118 // strategy.
119 //
120 // Wiring it through turns MESH-COMPOSITION §III.4 ("the
121 // application graph is a compile-time typed value … rendered
122 // through to whatever runtime layer makes sense") + §V
123 // ("cross-cluster federation: `:placement :replicated
124 // :clusters (\"rio\" \"mar\")` deploys the Aplicacao to every
125 // named cluster") from a typed-author-side promise into a
126 // typed-renderer-side artifact: each cluster's local
127 // lareira-fleet-programs HelmRelease can filter
128 // `programs[]` by `placement.clusters.contains(<self>)`,
129 // dispatch on `placement.estrategia`, and (for `Sharded`)
130 // route by `placement.shardKey`. Same trajectory as the
131 // 5f477a6 / 23b7f00 / 878bf81 `:politicas` axis overlays:
132 // typed slot → cluster artifact in one wiring step, no new
133 // primitive needed.
134 //
135 // The serialized fragment uses the [`Placement`] struct's
136 // serde shape verbatim — `estrategia` + `clusters` always
137 // present (validated non-empty), `affinity` + `shardKey`
138 // present iff `Some` (skip_serializing_if). One entry per
139 // member carries the same placement block; redundant in
140 // bytes, but each programs.yaml entry is self-describing for
141 // the aggregator (which has no Aplicacao-level context),
142 // mirroring the existing `aplicacao:` annotation's per-entry
143 // emission.
144 // Route the per-Aplicacao `:placement` composite-serialization seed
145 // through the lifted [`caixa_core::AplicacaoSpec::placement`] outer
146 // accessor rather than the raw `&spec.placement` field access — every
147 // downstream per-`programs[]` entry's placement-block annotation now
148 // keys off the substrate-primitive typed dispatch on the outer
149 // composition altitude, sibling to the paired peer
150 // [`caixa_core::AplicacaoSpec::politicas`] (534dc21) outer-composite-
151 // reference accessor the per-CNP mTLS-overlay + HTTPRoute
152 // timeout/retry-overlay emitters below already route through. The
153 // accessor's `&Placement` return borrows the same backing composite
154 // the raw field access borrows from, so the serialization byte-string
155 // is byte-for-byte identical (validated by the peer
156 // `aplicacao_spec_placement_returns_placement_ref_byte_equal_across_permutations`
157 // reference-identity pin).
158 let placement_value = serde_yaml::to_value(spec.placement())?;
159
160 let mut out = Vec::with_capacity(spec.membros().len());
161 for m in spec.membros() {
162 let mut entry = serde_yaml::Mapping::new();
163 // Route the per-`:membros` entry-`name:` byte-string through the
164 // typed [`Membro::nome`] accessor rather than the raw `.caixa`
165 // field access — the last un-lifted `.caixa.clone()` copy of the
166 // read path on the per-`:membros` member-caixa `:nome` axis, and
167 // the sibling `String`-carry site to the five `&str`-read sites
168 // the peer 4a32abf lift already routed through the accessor.
169 // Prior to this lift the emit-side `String`-carry path was the
170 // solitary consumer bypassing the typed dispatch, so a future
171 // extension of the `:membros :caixa` axis to a richer author
172 // surface (a per-cluster alias table, an M4 namespace-qualified
173 // rewrite, a `:membros :nome-suffix` overlay) that lands on the
174 // accessor would silently disagree with the emitted programs.yaml
175 // `name:` — the drift-detection pins below key off this equality
176 // to catch the regression at caixa-mesh build time.
177 entry.insert_string(FLEET_PROGRAMS_KEY_NAME, m.nome().to_string());
178 // Per-`:membros` version-constraint annotation — flows the
179 // Membro's `:versao` (the M3 Aplicacao's per-member semver /
180 // range constraint) through the canonical
181 // [`caixa_core::FLEET_PROGRAMS_KEY_VERSAO`] axis-key the
182 // substrate operator's per-`:membros` resolver reads to fetch
183 // each member's caixa.lisp release. See the const's doc-comment
184 // for the fourth-of-four per-entry fleet-programs values-schema
185 // axis-key single-sourcing arc — with this lift landed every
186 // per-entry axis (name + versao + aplicacao + placement) lives
187 // in exactly one `&'static str` across the emitter here + every
188 // downstream aggregator/resolver call site. Routes through the
189 // typed [`Membro::versao_requirement`] accessor (a40b0e3) rather
190 // than the raw `.versao` field — same converging-`String`-carry-
191 // path discipline the sibling [`FLEET_PROGRAMS_KEY_NAME`] emit
192 // above applies on the peer per-`:membros` member-caixa `:nome`
193 // axis.
194 entry.insert_string(
195 FLEET_PROGRAMS_KEY_VERSAO,
196 m.versao_requirement().to_string(),
197 );
198 // Annotate with the parent Aplicacao's nome so the operator
199 // knows which graph this member belongs to. Consumes the
200 // lifted [`caixa_core::FLEET_PROGRAMS_KEY_APLICACAO`] axis-key
201 // — see its doc-comment for why the per-entry parent-graph-
202 // annotation-key axis lives in one canonical const across
203 // the emitter here + the readback probe below.
204 entry.insert_string(FLEET_PROGRAMS_KEY_APLICACAO, caixa.nome().to_string());
205 // M3 `:placement` overlay — see the per-call rationale
206 // above. Cloned per entry so each programs.yaml row is
207 // self-describing for downstream filters that have no
208 // Aplicacao-level context.
209 entry.insert_str_key(M3_KEY_PLACEMENT, placement_value.clone());
210 out.push_mapping(entry);
211 }
212 Ok(out)
213}
214
215/// Compose a single typed view of the entire Aplicacao for downstream
216/// renderers (Cilium, Gateway, observability). Convenience wrapper that
217/// routes the compound `require_kind + aplicacao_view + validate`
218/// cascade through the canonical substrate primitive
219/// [`caixa_core::require_aplicacao_view`], sibling to the
220/// per-Servico [`caixa_core::require_v0_servico_shape`] compound entry
221/// gate every `caixa-helm` / `caixa-flux` renderer already routes
222/// through. The wrapper stays for turbofish elision at this crate's
223/// three call sites (`programs_for_aplicacao` /
224/// `cilium_network_policies` / `gateway_routes`), matching the shape
225/// the sibling `caixa-flux` / `caixa-helm` renderers read the compound
226/// V0-Servico gate as, and every future per-Aplicacao consumer
227/// (`caixa-tatara`'s spec-consuming validate arm when it lands, the
228/// deferred `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's
229/// admission webhook) gets the compound three-arm gate for free with
230/// one call rather than re-inlining the cascade — same discipline the
231/// peer [`caixa_core::require_v0_servico_shape`] lift closed on the
232/// per-Servico renderer axis.
233pub fn typed_view(caixa: &Caixa) -> Result<AplicacaoSpec, Error> {
234 caixa_core::require_aplicacao_view::<Error>(caixa)
235}
236
237/// Default namespace for emitted cluster objects when the Aplicacao
238/// doesn't pin one. Re-export of the canonical
239/// [`caixa_core::DEFAULT_NAMESPACE`] so the namespace string lives in
240/// exactly one place across every renderer — caixa-mesh's programs
241/// fan-out / CiliumNetworkPolicy / Gateway / HTTPRoute emitters and
242/// caixa-flux's programs.yaml / GitRepository / HelmRelease /
243/// Kustomization emitters now consult the same `&'static str`, so a
244/// future per-cluster-namespace rebrand is a one-line edit on the
245/// canonical [`caixa_core::DEFAULT_NAMESPACE`] declaration, not a
246/// coordinated rewrite across this crate, caixa-flux, and every
247/// future per-target renderer the substrate adds. The prior local
248/// `pub const` declaration explicitly acknowledged the duplication
249/// ("Mirrors `caixa_flux::DEFAULT_NAMESPACE`"); this re-export
250/// closes the drift footgun structurally — a future rebrand on one
251/// side without a coordinated edit on the other would otherwise have
252/// silently emitted Servicos into one namespace and their Aplicacao's
253/// NetworkPolicies / Gateways / HTTPRoutes into a drifted one, with
254/// the apply-time symptom (CiliumNetworkPolicy `endpointSelector`
255/// matches no pods, every L7 contrato flow silently drops) far from
256/// the rebrand commit's source.
257pub use caixa_core::DEFAULT_NAMESPACE;
258
259/// Canonical K8s Gateway API CRD `apiVersion` every `gateway_routes`-
260/// emitted `Gateway` / `HTTPRoute` document declares. Re-export of the
261/// canonical [`caixa_core::GATEWAY_API_API_VERSION`] so the
262/// Gateway-API-conformant CRD-group/version string lives in exactly
263/// one place across every caixa renderer — caixa-mesh's
264/// `gateway_routes` Gateway + HTTPRoute emitters (the two production-
265/// code sites the prior inline literal sat at,
266/// caixa-mesh/src/lib.rs:455, 496) and every future per-edge
267/// `TCPRoute` / `TLSRoute` / `GRPCRoute` emitter the M3.x absorption-
268/// roadmap acknowledges now consult the same `&'static str`, so a
269/// future K8s Gateway API GA promotion (the upstream SIG-Network
270/// roadmap names per-CRD-group / per-version migration once the v1
271/// GA branch matures) is a one-line edit on the canonical
272/// [`caixa_core::GATEWAY_API_API_VERSION`] declaration, not a
273/// coordinated rewrite across this crate's two `kube_resource_skeleton`
274/// call sites + every future per-target renderer the substrate adds.
275/// The prior inline literals would have let a Gateway-API GA bump on
276/// one axis without a coordinated edit on the other silently emit a
277/// `Gateway` / `HTTPRoute` pair pointing at distinct CRD versions —
278/// apply-side: the `Gateway` and `HTTPRoute` land in two distinct
279/// apiserver-side CRD registrations, the per-route attached-policy
280/// resolution pipeline never binds, every external `:entrada` flow
281/// drops at the gateway with no field naming the version-drift root
282/// cause. Peer to the [`DEFAULT_NAMESPACE`] re-export on the sibling
283/// canonical-load-bearing-string axis — extends the discipline onto
284/// the canonical-K8s-Gateway-API-CRD-axis surface.
285pub use caixa_core::GATEWAY_API_API_VERSION;
286
287/// Canonical Cilium CRD `apiVersion` every `cilium_network_policies`-
288/// emitted `CiliumNetworkPolicy` document declares. Re-export of the
289/// canonical [`caixa_core::CILIUM_API_VERSION`] so the Cilium-CRD-
290/// group/version string lives in exactly one place across every caixa
291/// renderer — caixa-mesh's `cilium_network_policies` per-`(:de, :para)`
292/// CiliumNetworkPolicy emitter (the single production-code site the
293/// prior inline literal sat at, caixa-mesh/src/lib.rs:326) and every
294/// future per-policy `CiliumClusterwideNetworkPolicy` /
295/// `CiliumLocalRedirectPolicy` emitter the M3.x absorption roadmap
296/// acknowledges now consult the same `&'static str`, so a future
297/// Cilium-CRD-group/version promotion (the upstream Cilium roadmap
298/// names per-CRD-group / per-version migration once the
299/// `cilium.io/v3` branch lands) is a one-line edit on the canonical
300/// [`caixa_core::CILIUM_API_VERSION`] declaration, not a coordinated
301/// rewrite across this crate's `kube_resource_skeleton` call site +
302/// every future per-target renderer the substrate adds. The prior
303/// inline literal would have let a Cilium-CRD bump on one axis without
304/// a coordinated edit on the matching in-file
305/// `cilium_policy_carries_canonical_kube_skeleton` test fixture pin
306/// (caixa-mesh/src/lib.rs:1560) silently emit a `CiliumNetworkPolicy`
307/// whose top-level apiVersion drifts off the lifted-test-fixture pin —
308/// apply-side: the policy lands in a stale apiserver-side CRD-version
309/// registration the Cilium operator no longer watches, every
310/// `(:de, :para)` intra-mesh L4 contract drops at the eBPF data plane
311/// with no field naming the version-drift root cause. Peer to the
312/// [`GATEWAY_API_API_VERSION`] re-export on the sibling
313/// canonical-K8s-Gateway-API-CRD-axis — extends the discipline onto
314/// the canonical-Cilium-CRD-axis surface.
315pub use caixa_core::CILIUM_API_VERSION;
316
317/// Canonical Cilium CRD `kind` discriminator every
318/// `cilium_network_policies`-emitted `CiliumNetworkPolicy` document
319/// declares at its top-level [`caixa_core::KUBE_KEY_KIND`] axis.
320/// Re-export of the canonical [`caixa_core::CILIUM_KIND_NETWORK_POLICY`]
321/// so the Cilium-operator-side CRD `kind` discriminator string lives in
322/// exactly one place across every caixa renderer — caixa-mesh's
323/// `cilium_network_policies` per-`(:de, :para)` CiliumNetworkPolicy
324/// emitter (the single production-code site the prior inline
325/// `"CiliumNetworkPolicy"` literal sat at,
326/// caixa-mesh/src/lib.rs:382 — the `kube_resource_skeleton` kind
327/// argument) and every future per-Cilium-side renderer the M3.x
328/// absorption roadmap acknowledges now consult the same `&'static
329/// str`, so a future Cilium-CRD rebrand (e.g. an upstream rename to
330/// `CiliumNetworkPolicyV2`) is a one-line edit on the canonical
331/// [`caixa_core::CILIUM_KIND_NETWORK_POLICY`] declaration, not a
332/// coordinated rewrite across this crate's `kube_resource_skeleton`
333/// call site + every future per-target renderer the substrate adds.
334/// The prior inline literal would have let a Cilium-CRD bump on the
335/// kind axis without a coordinated edit on the matching in-file
336/// `cilium_policy_carries_canonical_kube_skeleton` test fixture pin
337/// silently emit a `CiliumNetworkPolicy` whose top-level kind drifts
338/// off the lifted-test-fixture pin — apply-side: the policy lands
339/// outside the Cilium-operator-side CRD registration, every
340/// `(:de, :para)` intra-mesh L4/L7 contract drops at the eBPF data
341/// plane with no field naming the kind-drift root cause. Peer to the
342/// [`CILIUM_API_VERSION`] re-export on the sibling
343/// canonical-Cilium-CRD-apiVersion-axis — extends the discipline from
344/// the apiVersion half of the `(apiVersion, kind)` CRD-lookup tuple
345/// onto the kind half, completing the per-Cilium-CRD
346/// kind+apiVersion re-export pair this crate's `cilium_network_policies`
347/// renderer's eBPF data-plane contract rests on.
348pub use caixa_core::CILIUM_KIND_NETWORK_POLICY;
349
350/// Canonical Cilium `CiliumNetworkPolicy` per-ingress-rule port-set
351/// container-axis key every `cilium_network_policies`-emitted CNP
352/// document mounts its per-ingress-rule `[{ports: […], rules: {…}}]`
353/// list under (`spec.ingress[].toPorts[]`). Re-export of the canonical
354/// [`caixa_core::CILIUM_KEY_TO_PORTS`] so the Cilium-operator-side
355/// per-CNP L4/L7-dispatch container-key string lives in exactly one
356/// place across every caixa renderer — caixa-mesh's
357/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
358/// emitter (the `ingress_rule.insert("toPorts", …)` call the prior
359/// inline `"toPorts"` literal sat at) and every future per-Cilium-side
360/// renderer the M3.x absorption roadmap acknowledges now consult the
361/// same `&'static str`, so a future Cilium-CRD rebrand on the port-set
362/// container axis (unlikely on the CRD's stable `cilium.io/v2` slot,
363/// but the coordination point the prior [`KUBE_KEY_RULES`] +
364/// [`CILIUM_KIND_NETWORK_POLICY`] + [`CILIUM_API_VERSION`] re-exports
365/// anchor on the sibling per-CNP-dispatch-axis surface) lands in one
366/// place. The prior inline literal split across the one production
367/// emitter and six test-fixture navigation sites (2 CNP presence /
368/// absence pins, 1 fan-in-per-pair invariant pin, 1 mTLS-overlay
369/// nesting pin — via the pair of `contains_key` + `.get` navigations,
370/// 1 L4-fallback port pin) would have let a Cilium-CRD port-set-
371/// container rebrand or a per-emitter typo (`"toport"` / `"toPort"` /
372/// `"targetPorts"`) at any one site silently emit a per-ingress-rule
373/// entry whose port-set container the Cilium CRD schema validator
374/// drops as unknown; every intra-mesh `:contratos` flow the affected
375/// CNP was authored to allow drops at the eBPF data plane's default-
376/// deny gate with no field naming the container-drift root cause, and
377/// on the test-fixture side the drift silently masks the emission-side
378/// pin (`.get("toPorts")` returns `None` under both the drifted
379/// emitter and the drifted probe — the `cilium_pubsub_contracts_skip_\
380/// l7_rules` absence pin's downstream `to_ports.get("rules").is_none()`
381/// assertion succeeds vacuously because `to_ports` is itself `None`).
382/// Peer to the [`caixa_core::KUBE_KEY_RULES`] re-export on the sibling
383/// canonical-per-CNP-dispatch-axis surface — completes the per-CNP
384/// L4/L7-dispatch-container `(toPorts, rules)` re-export pair this
385/// crate's `cilium_network_policies` renderer's eBPF data-plane
386/// contract rests on.
387pub use caixa_core::CILIUM_KEY_TO_PORTS;
388
389/// Canonical Cilium `CiliumNetworkPolicy` per-CNP-body destination-
390/// identity selector-axis key every `cilium_network_policies`-emitted
391/// CNP document mounts its L3-target `LabelSelector` under
392/// (`spec.endpointSelector`). Re-export of the canonical
393/// [`caixa_core::CILIUM_KEY_ENDPOINT_SELECTOR`] so the Cilium-operator-
394/// side per-CNP destination-identity-axis string lives in exactly one
395/// place across every caixa renderer — caixa-mesh's
396/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
397/// emitter (the `policy_spec.insert("endpointSelector", …)` call the
398/// prior inline `"endpointSelector"` literal sat at) and every future
399/// per-Cilium-side renderer the M3.x absorption roadmap acknowledges
400/// now consult the same `&'static str`, so a future Cilium-CRD rebrand
401/// on the destination-identity axis (unlikely on the CRD's stable
402/// `cilium.io/v2` slot, but the coordination point the prior
403/// [`CILIUM_KEY_TO_PORTS`] + [`caixa_core::KUBE_KEY_RULES`] +
404/// [`CILIUM_KIND_NETWORK_POLICY`] + [`CILIUM_API_VERSION`] re-exports
405/// anchor on the sibling per-CNP-body axis surface) lands in one place.
406/// The prior inline literal split across the one production emitter and
407/// two test-fixture navigation sites (destination-`endpointSelector`
408/// retrieval whose downstream navigation chains ride through the same
409/// axis-key) would have let a Cilium-CRD destination-identity axis
410/// rebrand or a per-emitter typo (`"endpointselector"` /
411/// `"endpointSelectors"` / `"endpoints"`) at any one site silently emit
412/// a CNP whose destination-identity axis the Cilium CRD schema
413/// validator drops as unknown; the policy binds against no destination
414/// pods and every intra-mesh `:contratos` flow the affected CNP was
415/// authored to allow drops at the eBPF data plane's default-deny gate
416/// with no field naming the destination-identity-drift root cause, and
417/// on the test-fixture side the drift silently masks the emission-side
418/// pin (`.get("endpointSelector")` returns `None` under both the
419/// drifted emitter and the drifted probe — the downstream
420/// `.and_then(|s| s.get("matchLabels"))` chain short-circuits vacuously
421/// because the outer selector-lookup is itself `None`). Peer to the
422/// [`CILIUM_KEY_TO_PORTS`] re-export on the sibling canonical-per-CNP-
423/// body-axis surface — extends the per-CNP-body re-export set from the
424/// per-ingress-rule port-set container axis (the L4 dispatch container
425/// half of the `(endpointSelector, ingress → toPorts → rules)` L3/L4/
426/// L7-triad) onto the destination-identity axis half, completing the
427/// per-CNP L3-target-selector re-export the M3 Aplicacao mesh
428/// renderer's eBPF data-plane contract rests on.
429pub use caixa_core::CILIUM_KEY_ENDPOINT_SELECTOR;
430
431/// Canonical Cilium `CiliumNetworkPolicy` per-CNP-body traffic-direction
432/// container-axis key every `cilium_network_policies`-emitted CNP
433/// document mounts its permitted-inbound-per-`(:de, :para)` ingress-rule
434/// list under (`spec.ingress[]`). Re-export of the canonical
435/// [`caixa_core::CILIUM_KEY_INGRESS`] so the Cilium-operator-side per-
436/// CNP inbound-traffic-dispatch container-key string lives in exactly
437/// one place across every caixa renderer — caixa-mesh's
438/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
439/// emitter (the `policy_spec.insert("ingress", …)` call the prior
440/// inline `"ingress"` literal sat at) and every future per-Cilium-side
441/// renderer the M3.x absorption roadmap acknowledges now consult the
442/// same `&'static str`, so a future Cilium-CRD rebrand on the traffic-
443/// direction axis (unlikely on the CRD's stable `cilium.io/v2` slot,
444/// but the coordination point the prior [`CILIUM_KEY_ENDPOINT_SELECTOR`]
445/// + [`CILIUM_KEY_TO_PORTS`] + [`caixa_core::KUBE_KEY_RULES`] +
446/// [`CILIUM_KIND_NETWORK_POLICY`] + [`CILIUM_API_VERSION`] re-exports
447/// anchor on the sibling per-CNP-body axis surface) lands in one place.
448/// The prior inline literal split across the one production emitter and
449/// eight test-fixture navigation sites (whose downstream navigation
450/// chains — `fromEndpoints`, `toPorts`, `authentication` — ride through
451/// the same axis-key) would have let a Cilium-CRD traffic-direction
452/// axis rebrand or a per-emitter typo (`"Ingress"` / `"ingressRules"` /
453/// `"inbound"`) at any one site silently emit a CNP whose ingress-rule
454/// list the Cilium CRD schema validator drops as unknown; the policy
455/// binds against the destination workload but admits no ingress
456/// traffic, and every intra-mesh `:contratos` flow the affected CNP was
457/// authored to allow drops at the eBPF data plane's default-deny gate
458/// with no field naming the traffic-direction-drift root cause, and on
459/// the test-fixture side the drift silently masks the emission-side
460/// pin (`.get("ingress")` returns `None` under both the drifted emitter
461/// and the drifted probe — every downstream `.and_then(|i|
462/// i.as_sequence())` chain short-circuits vacuously because the outer
463/// traffic-direction-lookup is itself `None`, and every per-CNP
464/// downstream navigation — `fromEndpoints`, `toPorts`, `authentication`
465/// — rides through the same short-circuited outer axis-lookup with no
466/// field naming the drift root cause). Peer to the
467/// [`CILIUM_KEY_ENDPOINT_SELECTOR`] + [`CILIUM_KEY_TO_PORTS`] re-exports
468/// on the sibling canonical-per-CNP-body-axis surface — completes the
469/// per-CNP L3/L4/L7-triad
470/// `(endpointSelector, ingress → toPorts → rules)` re-export this
471/// crate's `cilium_network_policies` renderer's eBPF data-plane
472/// contract rests on by lifting the traffic-direction axis that
473/// structurally separates the destination-identity axis from the port-
474/// set-container axis nested beneath it.
475pub use caixa_core::CILIUM_KEY_INGRESS;
476
477/// Canonical Cilium `CiliumNetworkPolicy` per-ingress-rule identity-
478/// source selector-list axis key every `cilium_network_policies`-emitted
479/// CNP document mounts its permitted-source `LabelSelector` list under
480/// (`spec.ingress[].fromEndpoints[]`). Re-export of the canonical
481/// [`caixa_core::CILIUM_KEY_FROM_ENDPOINTS`] so the Cilium-operator-side
482/// per-ingress-rule identity-source axis-key string lives in exactly one
483/// place across every caixa renderer — caixa-mesh's
484/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
485/// emitter (the `ingress_rule.insert("fromEndpoints", …)` call the prior
486/// inline `"fromEndpoints"` literal sat at) and every future per-
487/// Cilium-side renderer the M3.x absorption roadmap acknowledges now
488/// consult the same `&'static str`, so a future Cilium-CRD rebrand on
489/// the identity-source axis (unlikely on the CRD's stable `cilium.io/v2`
490/// slot, but the coordination point the prior [`CILIUM_KEY_ENDPOINT_SELECTOR`]
491/// + [`CILIUM_KEY_INGRESS`] + [`CILIUM_KEY_TO_PORTS`] +
492/// [`caixa_core::KUBE_KEY_RULES`] + [`CILIUM_KIND_NETWORK_POLICY`] +
493/// [`CILIUM_API_VERSION`] re-exports anchor on the sibling per-CNP-body
494/// axis surface) lands in one place. The prior inline literal split
495/// across the one production emitter and four test-fixture navigation
496/// sites (whose downstream navigation chains — `.as_sequence()`,
497/// `.first()`, `.get(KUBE_KEY_MATCH_LABELS)` — ride through the same
498/// axis-key) would have let a Cilium-CRD identity-source axis rebrand
499/// or a per-emitter typo (`"fromendpoints"` / `"fromEndPoint"` /
500/// `"sourceEndpoints"`) at any one site silently emit a CNP whose per-
501/// ingress-rule identity-source selector list the Cilium CRD schema
502/// validator drops as unknown; the ingress rule admits no source pods,
503/// and every intra-mesh `:contratos` flow the affected CNP was authored
504/// to allow drops at the eBPF data plane's default-deny gate with no
505/// field naming the identity-source-drift root cause, and on the test-
506/// fixture side the drift silently masks the emission-side pin
507/// (`.get("fromEndpoints")` returns `None` under both the drifted
508/// emitter and the drifted probe — every downstream navigation short-
509/// circuits vacuously because the outer identity-source-lookup is
510/// itself `None`). Peer to the [`CILIUM_KEY_ENDPOINT_SELECTOR`] +
511/// [`CILIUM_KEY_INGRESS`] + [`CILIUM_KEY_TO_PORTS`] re-exports on the
512/// sibling canonical-per-CNP-body-axis surface — completes the per-CNP
513/// identity-pair `(endpointSelector, fromEndpoints)` re-export this
514/// crate's `cilium_network_policies` renderer's eBPF data-plane
515/// contract rests on by lifting the identity-source axis structurally
516/// paired with the destination-identity axis under the Cilium-operator-
517/// side per-CNP SPIFFE-identity-bound access-control contract.
518pub use caixa_core::CILIUM_KEY_FROM_ENDPOINTS;
519
520/// Canonical Cilium `CiliumNetworkPolicy` per-`toPorts[]`-entry L4
521/// port-tuple-list-container axis key every `cilium_network_policies`-
522/// emitted CNP document mounts its per-port-set `[{port, protocol}]`
523/// list under (`spec.ingress[].toPorts[].ports[]`). Re-export of the
524/// canonical [`caixa_core::CILIUM_KEY_PORTS`] so the Cilium-operator-
525/// side per-`toPorts[]`-entry L4-port-tuple-list-container-axis-key
526/// string lives in exactly one place across every caixa renderer —
527/// caixa-mesh's `cilium_network_policies` per-`(:de, :para)`
528/// `CiliumNetworkPolicy` emitter (the `to_port.insert("ports", …)` call
529/// the prior inline `"ports"` literal sat at) and every future per-
530/// Cilium-side renderer the M3.x absorption roadmap acknowledges now
531/// consult the same `&'static str`, so a future Cilium-CRD rebrand on
532/// the L4 port-tuple-list-container axis (unlikely on the CRD's stable
533/// `cilium.io/v2` slot, but the coordination point the prior
534/// [`CILIUM_KEY_FROM_ENDPOINTS`] + [`CILIUM_KEY_ENDPOINT_SELECTOR`] +
535/// [`CILIUM_KEY_INGRESS`] + [`CILIUM_KEY_TO_PORTS`] +
536/// [`caixa_core::KUBE_KEY_RULES`] + [`CILIUM_KIND_NETWORK_POLICY`] +
537/// [`CILIUM_API_VERSION`] re-exports anchor on the sibling per-CNP-body
538/// axis surface) lands in one place. The prior inline literal split
539/// across the one production emitter and two test-fixture navigation
540/// sites (`cilium_pubsub_contracts_skip_l7_rules` — the
541/// `to_ports.get("ports").is_some()` presence pin the L4-yes-L7-no
542/// separation invariant hinges on;
543/// `cnp_l4_fallback_port_reflects_default_servico_port` — the
544/// `.and_then(|tp| tp.get("ports"))` navigation whose downstream
545/// `.and_then(|s| s.first()).and_then(|p| p.get("port"))` chain reads
546/// the per-port-set L4 port-tuple value the `DEFAULT_SERVICO_PORT`
547/// fallback pins) would have let a Cilium-CRD L4 port-tuple-list-
548/// container axis rebrand or a per-emitter typo (`"port"` /
549/// `"portList"` / `"L4Ports"`) at any one site silently emit a per-
550/// `toPorts[]` entry whose L4 port-tuple-list-container axis the Cilium
551/// CRD schema validator drops as unknown; the port-set admits no
552/// `(port, protocol)` tuple, and every intra-mesh `:contratos` flow the
553/// affected CNP was authored to allow drops at the eBPF data plane's
554/// default-deny gate with no field naming the L4-port-tuple-list-
555/// container-drift root cause, and on the test-fixture side the drift
556/// silently masks the emission-side pin (`.get("ports")` returns `None`
557/// under both the drifted emitter and the drifted probe — every
558/// downstream navigation short-circuits vacuously because the outer L4-
559/// port-tuple-list-container-lookup is itself `None`). Peer to the
560/// [`CILIUM_KEY_TO_PORTS`] re-export on the sibling canonical-per-CNP-
561/// dispatch-axis surface — nests the per-port-set L4 port-tuple-list-
562/// container axis structurally beneath the sibling
563/// [`CILIUM_KEY_TO_PORTS`] port-set-container axis, extending the per-
564/// CNP L3/L4/L7-triad
565/// `(endpointSelector, ingress → toPorts → ports / rules)` re-export
566/// with the L4-half's port-tuple-list-container axis this crate's
567/// `cilium_network_policies` renderer's eBPF data-plane L4-allow
568/// contract rests on.
569pub use caixa_core::CILIUM_KEY_PORTS;
570
571/// Canonical Cilium `CiliumNetworkPolicy` per-ingress-rule mutual-auth
572/// policy body-axis key every `cilium_network_policies`-emitted CNP
573/// document mounts its per-rule mTLS enforcement block under
574/// (`spec.ingress[].authentication`). Re-export of the canonical
575/// [`caixa_core::CILIUM_KEY_AUTHENTICATION`] so the Cilium-operator-
576/// side per-ingress-rule mutual-auth-axis-key string lives in exactly
577/// one place across every caixa renderer — caixa-mesh's
578/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
579/// emitter (the `ingress_rule.insert("authentication", …)` call in
580/// the `:politicas :mtls-required` overlay emit gate the prior inline
581/// `"authentication"` literal sat at) and every future per-Cilium-
582/// side renderer the M3.x absorption roadmap acknowledges now consult
583/// the same `&'static str`, so a future Cilium-CRD rebrand on the
584/// per-ingress-rule mutual-auth axis (unlikely on the CRD's stable
585/// `cilium.io/v2` slot, but the coordination point the prior
586/// [`CILIUM_KEY_PORTS`] + [`CILIUM_KEY_FROM_ENDPOINTS`] +
587/// [`CILIUM_KEY_ENDPOINT_SELECTOR`] + [`CILIUM_KEY_INGRESS`] +
588/// [`CILIUM_KEY_TO_PORTS`] + [`caixa_core::KUBE_KEY_RULES`] +
589/// [`CILIUM_KIND_NETWORK_POLICY`] + [`CILIUM_API_VERSION`] re-exports
590/// anchor on the sibling per-CNP-body axis surface) lands in one
591/// place. The prior inline literal split across the one production
592/// emitter and nine test-fixture navigation sites (the presence pin
593/// under the `:mtls-required t` overlay, the absence pin under the
594/// `:mtls-required` unset semantic, the explicit-`false`-emits-
595/// disabled-mode pin under the `Some(false)` arm, the fan-out pin
596/// across multiple contratos, the rule-level-not-nested position pin
597/// with two nested-under-`fromEndpoints[]` and nested-under-
598/// `toPorts[]` negative-navigation guards, the pubsub-carry-overlay-
599/// too shape pin, and the yaml-string-scalar `mode`-value pin) would
600/// have let a Cilium-CRD mutual-auth-axis rebrand or a per-emitter
601/// typo (`"auth"` / `"mutualAuth"` / `"mtls"` / `"authPolicy"`) at
602/// any one site silently emit a per-`ingress[]` entry whose mutual-
603/// auth-axis the Cilium CRD schema validator drops as unknown; the
604/// ingress rule falls back to the cluster-default authentication
605/// mode and every intra-mesh `:contratos` flow the CNP was authored
606/// to protect with per-edge SPIFFE-identity-bound mutual-auth
607/// silently bypasses the mTLS handshake at the Cilium data-plane's
608/// default-authentication mode with no field naming the mutual-
609/// auth-axis-drift root cause. On the test-fixture side the drift
610/// silently masks the emission-side pin
611/// (`.get("authentication")` returns `None` under both the drifted
612/// emitter and the drifted probe — every downstream
613/// `.and_then(|a| a.get("mode"))` chain short-circuits vacuously
614/// because the outer mutual-auth-body-lookup is itself `None`). Peer
615/// to the [`CILIUM_KEY_FROM_ENDPOINTS`] + [`CILIUM_KEY_TO_PORTS`]
616/// re-exports on the sibling per-ingress-rule-body-axis surfaces —
617/// completes the per-ingress-rule-body triple
618/// `(fromEndpoints, toPorts, authentication)` this crate's
619/// `cilium_network_policies` renderer's SPIFFE-identity-bound per-
620/// edge mTLS contract rests on.
621pub use caixa_core::CILIUM_KEY_AUTHENTICATION;
622
623/// Canonical Cilium `CiliumNetworkPolicy` per-`ingress[].authentication`
624/// block mTLS-mode-discriminator leaf-scalar-axis key every
625/// `cilium_network_policies`-emitted CNP document mounts its per-rule
626/// mutual-auth mode leaf under (`spec.ingress[].authentication.mode`).
627/// Re-export of the canonical [`caixa_core::CILIUM_KEY_MODE`] so the
628/// Cilium-operator-side per-ingress-rule mutual-auth-mode-discriminator
629/// leaf-axis key string lives in exactly one place across every caixa
630/// renderer — caixa-mesh's `cilium_network_policies` per-`(:de, :para)`
631/// `CiliumNetworkPolicy` emitter (the single-field-overlay call in the
632/// `:politicas :mtls-required` overlay emit gate the prior inline
633/// `"mode"` literal sat at) and every future per-Cilium-side renderer
634/// the M3.x absorption roadmap acknowledges now consult the same
635/// `&'static str`, so a future Cilium-CRD rebrand on the per-
636/// authentication-block mode-discriminator leaf-axis (unlikely on the
637/// CRD's stable `cilium.io/v2` slot, but the coordination point the
638/// prior [`CILIUM_KEY_AUTHENTICATION`] re-export anchors on the parent
639/// per-ingress-rule mutual-auth-body-axis) lands in one place. The
640/// prior inline literal split across the one production emitter site
641/// and five test-fixture navigation sites (the presence pin under the
642/// `:mtls-required t` overlay, the explicit-`false`-emits-disabled-
643/// mode pin under the `Some(false)` arm, the fan-out pin across
644/// multiple contratos, the pubsub-carry-overlay-too shape pin, and the
645/// yaml-string-scalar `mode`-value pin) would have let a Cilium-CRD
646/// mutual-auth-mode-leaf rebrand or a per-emitter typo (`"policy"` /
647/// `"authMode"` / `"handshakeMode"`) at any one site silently emit a
648/// per-`ingress[]` entry whose mutual-auth-block mode-discriminator-
649/// leaf-axis the Cilium CRD schema validator drops as unknown; the
650/// ingress rule falls back to the cluster-default authentication mode
651/// and every intra-mesh `:contratos` flow the CNP was authored to
652/// protect with per-edge SPIFFE-identity-bound mutual-auth silently
653/// bypasses the mTLS handshake at the Cilium data-plane's default-
654/// authentication mode with no field naming the mutual-auth-mode-
655/// leaf-axis-drift root cause. On the test-fixture side the drift
656/// silently masks the emission-side pin (`.get("mode")` returns `None`
657/// under both the drifted-key emitter and the drifted-key probe —
658/// every downstream `.and_then(|v| v.as_str())` chain short-circuits
659/// vacuously because the outer mode-leaf-lookup is itself `None`).
660/// Peer to the [`CILIUM_KEY_AUTHENTICATION`] re-export on the parent
661/// per-ingress-rule mutual-auth-body-axis surface — completes the
662/// per-rule mutual-auth `(authentication → mode)` body/leaf axis
663/// re-export pair this crate's `cilium_network_policies` renderer's
664/// SPIFFE-identity-bound per-edge mTLS enforcement contract rests on.
665pub use caixa_core::CILIUM_KEY_MODE;
666
667/// Canonical Cilium `CiliumNetworkPolicy` `MutualAuthenticationMode` OpenAPI
668/// schema enum's `required` mTLS-mandatory per-`ingress[].authentication.mode`
669/// scalar-value every `cilium_network_policies`-emitted CNP document declares
670/// under the `:mtls-required t` affirmative arm of the typed `:politicas
671/// :mtls-required` tristate. Re-export of the canonical
672/// [`caixa_core::CILIUM_AUTH_MODE_REQUIRED`] so the Cilium-agent-side per-rule
673/// mutual-auth-mandatory scalar-value string lives in exactly one place across
674/// every caixa renderer — caixa-mesh's `cilium_network_policies` per-`(:de,
675/// :para)` `CiliumNetworkPolicy` emitter (the single-field-overlay closure's
676/// `if required { … }` affirmative arm the prior inline `"required"` literal
677/// sat at, plus the presence / fan-out / pubsub-carry-overlay-too test-fixture
678/// probes that pin the emitted value under the `:mtls-required t` shape) and
679/// every future per-Cilium-side renderer the M3.x absorption roadmap
680/// acknowledges now consult the same `&'static str`. Peer to the sibling
681/// [`CILIUM_AUTH_MODE_DISABLED`] re-export on the explicit-opt-out arm of the
682/// same tristate — completes the per-authn-block `(mode → {required,
683/// disabled})` author-reachable-scalar-value-pair re-export pair this crate's
684/// `cilium_network_policies` renderer's SPIFFE-identity-bound per-edge mTLS
685/// enforcement + explicit-opt-out contract rests on.
686pub use caixa_core::CILIUM_AUTH_MODE_REQUIRED;
687
688/// Canonical Cilium `CiliumNetworkPolicy` `MutualAuthenticationMode` OpenAPI
689/// schema enum's `disabled` mTLS-skipped per-`ingress[].authentication.mode`
690/// scalar-value every `cilium_network_policies`-emitted CNP document declares
691/// under the explicit `Some(false)` opt-out arm of the typed `:politicas
692/// :mtls-required` tristate (distinct from the `None` slot-absent arm the
693/// renderer maps to omit-the-block-entirely). Re-export of the canonical
694/// [`caixa_core::CILIUM_AUTH_MODE_DISABLED`] so the Cilium-agent-side per-rule
695/// mutual-auth-skipped scalar-value string lives in exactly one place across
696/// every caixa renderer — caixa-mesh's `cilium_network_policies` per-`(:de,
697/// :para)` `CiliumNetworkPolicy` emitter (the single-field-overlay closure's
698/// `else { … }` opt-out arm the prior inline `"disabled"` literal sat at,
699/// plus the `cnp_explicit_mtls_required_false_emits_disabled_mode` test-
700/// fixture probe that pins the emitted value under the explicit-opt-out
701/// shape) and every future per-Cilium-side renderer the M3.x absorption
702/// roadmap acknowledges now consult the same `&'static str`. Peer to the
703/// sibling [`CILIUM_AUTH_MODE_REQUIRED`] re-export on the affirmative arm of
704/// the same tristate.
705pub use caixa_core::CILIUM_AUTH_MODE_DISABLED;
706
707/// Canonical `bool → &'static str` bijection projection every consumer of the
708/// Cilium `CiliumNetworkPolicy` `MutualAuthenticationMode` OpenAPI schema
709/// enum's closed-set author-reachable scalar-value pair
710/// ([`CILIUM_AUTH_MODE_REQUIRED`] / [`CILIUM_AUTH_MODE_DISABLED`]) consults
711/// so the per-tristate-arm dispatch — `Some(true)` (mTLS handshake
712/// mandatory) → [`CILIUM_AUTH_MODE_REQUIRED`], `Some(false)` (mTLS handshake
713/// skipped, explicit opt-out) → [`CILIUM_AUTH_MODE_DISABLED`] — lives in
714/// exactly one place. Re-export of the canonical
715/// [`caixa_core::cilium_auth_mode`] so a future Cilium CNP
716/// `MutualAuthenticationMode` enum rebrand (either arm's scalar-value or
717/// the per-arm dispatch shape) lands at the two consts + one projection
718/// body rather than at scattered per-emitter inline closure bodies.
719/// Consumed by the `cilium_network_policies` per-`(:de, :para)` emitter's
720/// `single_field_overlay(spec.politicas.mtls_required, CILIUM_KEY_MODE,
721/// |required| serde_yaml::Value::String(cilium_auth_mode(required).into()))`
722/// closure body the prior inline `if required { CILIUM_AUTH_MODE_REQUIRED }
723/// else { CILIUM_AUTH_MODE_DISABLED }` per-arm dispatch sat at (plus the
724/// caixa-core in-file `single_field_overlay_threads_typed_value_through_
725/// closure` generic-helper pin that mirrors the production overlay's
726/// shape letter-for-letter and now threads through the same projection).
727/// Peer to the [`CILIUM_AUTH_MODE_REQUIRED`] / [`CILIUM_AUTH_MODE_DISABLED`]
728/// re-export pair the two arms of the same enum land on — completes the
729/// canonical `(closed-set-CRD-schema-enum-value pair, per-typed-arm
730/// dispatch projection)` compound re-export triple this crate's
731/// `cilium_network_policies` renderer's SPIFFE-identity-bound per-edge
732/// mTLS enforcement + explicit-opt-out contract rests on.
733pub use caixa_core::cilium_auth_mode;
734
735/// Canonical M3 `:contratos` edge-direction separator byte-string every
736/// caixa-mesh emitter that encodes a typed edge as a K8s-name-shaped
737/// scalar reads from — the per-`(:de, :para)`
738/// [`LABEL_CONTRATO`] value threaded through
739/// [`contrato_edge_label`] and the per-`(:de, :para)`
740/// `CiliumNetworkPolicy` `metadata.name` threaded through
741/// [`cilium_network_policy_name`]. Re-export of the canonical
742/// [`caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR`] so the load-bearing
743/// `-to-` byte-string lives in exactly one place across every caixa
744/// renderer — caixa-mesh's `cilium_network_policies` per-`(:de, :para)`
745/// group (the two writer sites the prior inline `format!` literals
746/// sat at) and every future per-target renderer that encodes a typed
747/// M3 edge as a K8s-name-shaped scalar. A future edge-encoding rebrand
748/// (`-to-` → `->` for compactness, `-to-` → `_to_` to reserve `-` for
749/// embedded DNS-1123-label boundaries, an edge-direction-arrow
750/// migration to UTF-8 shapes) lands at the canonical
751/// [`caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR`] declaration, not at
752/// this crate's per-group writer sites. Peer with the
753/// [`contrato_edge_label`] / [`cilium_network_policy_name`] composer
754/// re-exports that consume this const — together the three items
755/// close the canonical per-`(:de, :para)` CNP identity pair
756/// `(metadata.labels.pleme.pleme.io/contrato, metadata.name)` onto
757/// one shared edge-encoding source of truth.
758pub use caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR;
759
760/// Canonical M3 `:contratos` edge label value composer — the
761/// `<de>-to-<para>` K8s-name-shaped scalar every per-`(:de, :para)`
762/// `CiliumNetworkPolicy` document carries at its
763/// `metadata.labels.pleme.pleme.io/contrato` axis. Re-export of the
764/// canonical [`caixa_core::contrato_edge_label`] composer so the
765/// per-CNP `LABEL_CONTRATO`-value construction lives in exactly one
766/// place across every caixa renderer. Reads from the lifted
767/// [`CONTRATO_EDGE_LABEL_SEPARATOR`] byte-string so a future
768/// edge-encoding rebrand lands at one canonical composition. Peer of
769/// [`cilium_network_policy_name`] on the sibling per-CNP
770/// `metadata.name` composition axis — the two composers close the
771/// canonical `(LABEL_CONTRATO-value, metadata.name)` per-CNP identity
772/// pair on one shared edge-encoding source of truth
773/// ([`CONTRATO_EDGE_LABEL_SEPARATOR`]).
774pub use caixa_core::contrato_edge_label;
775
776/// Canonical per-`(:de, :para)` `CiliumNetworkPolicy` `metadata.name`
777/// composer — the `<aplicacao>-<de>-to-<para>` K8s-name-shaped
778/// scalar every caixa-mesh `cilium_network_policies` emitter mounts
779/// its per-edge CNP under. Re-export of the canonical
780/// [`caixa_core::cilium_network_policy_name`] composer so the per-CNP
781/// name construction lives in exactly one place across every caixa
782/// renderer. Composes on the lifted [`contrato_edge_label`] helper so
783/// the two writer-side axes — the CNP
784/// `metadata.labels.pleme.pleme.io/contrato` value and the CNP
785/// `metadata.name` — share one canonical edge-encoding source of
786/// truth ([`CONTRATO_EDGE_LABEL_SEPARATOR`]). Peer of
787/// [`contrato_edge_label`] on the parent-composition axis — the two
788/// writer-side composers close the canonical
789/// `(LABEL_CONTRATO-value, metadata.name)` per-CNP identity pair so a
790/// future edge-encoding rebrand or a per-emitter typo can't silently
791/// split the two axes at emit time and orphan every operator-side
792/// grep-by-label query at apply time far from the source caixa.lisp.
793pub use caixa_core::cilium_network_policy_name;
794
795/// Canonical per-`:entrada` `HTTPRoute` `metadata.name` composer —
796/// the `<aplicacao>-<para>` K8s-name-shaped scalar every caixa-mesh
797/// `gateway_routes` emitter mounts its per-`:entrada` HTTPRoute
798/// under. Re-export of the canonical
799/// [`caixa_core::gateway_api_http_route_name`] composer so the
800/// per-HTTPRoute name construction lives in exactly one place across
801/// every caixa renderer. Peer of the sibling
802/// [`cilium_network_policy_name`] composer on the per-Aplicacao
803/// per-CR K8s-name-shaped-identity-scalar axis: the CNP-name composer
804/// carries the per-`(:de, :para)` L4/L7 policy CR name and this
805/// composer carries the per-`:entrada` L7 route CR name — both share
806/// the same "aplicacao-prefixed sub-identity" discipline (an
807/// aplicacao-prefix joined to a per-CR sub-axis by a canonical `-`
808/// separator) so a future substrate-side per-Aplicacao Gateway API
809/// axis extension (`GRPCRoute` on grpc-shaped `:contratos` payloads,
810/// `TCPRoute` on l4-only tcp payloads, per-`:entrada` `HTTPRouteFilter`
811/// / `BackendTLSPolicy` overlays) reaches the shared naming
812/// discipline through this composer's peer-shape by construction.
813///
814/// Until this lift landed the HTTPRoute `metadata.name` axis sat as a
815/// verbatim inline `format!("{}-{}", caixa.nome, entrada.para)` at
816/// the [`gateway_routes`] emitter (with an in-file test-side probe
817/// pinning the expected `checkout-cart` byte-shape by verbatim
818/// literal), and any future name-encoding rebrand on this axis would
819/// have had to be threaded through both sites in lockstep or the
820/// HTTPRoute `metadata.name` silently split from the operator-side
821/// grep-by-name / `kubectl get httproute -n tatara-system
822/// <aplicacao>-<para>` lookup encoding at apply time far from the
823/// source caixa.lisp. See
824/// [`caixa_core::gateway_api_http_route_name`] for the full lift
825/// rationale.
826pub use caixa_core::gateway_api_http_route_name;
827
828/// Canonical M3 [`caixa_core::aplicacao::PlacementStrategy::SingleNode`]
829/// variant discriminator scalar-value the `Serialize` derive on the
830/// un-`rename`d enum emits under [`caixa_core::M3_PLACEMENT_KEY_ESTRATEGIA`] on every
831/// `programs_for_aplicacao`-emitted programs.yaml entry authored with
832/// `:placement (:estrategia SingleNode …)`. Re-export of the canonical
833/// [`caixa_core::M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE`] so the OTP-style
834/// single-cluster-takeover distribution-strategy scalar lives in exactly
835/// one place across every caixa renderer and every caixa-mesh test-fixture
836/// probe that dispatches on the strategy string. Peer to the sibling
837/// [`M3_PLACEMENT_ESTRATEGIA_REPLICATED`] / [`M3_PLACEMENT_ESTRATEGIA_SHARDED`]
838/// re-exports on the other two arms of the same closed enum surface —
839/// together the three constants name every author-reachable arm of the
840/// M3 distribution-strategy discriminator.
841pub use caixa_core::M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE;
842
843/// Canonical M3 [`caixa_core::aplicacao::PlacementStrategy::Replicated`]
844/// variant discriminator scalar-value the `Serialize` derive on the
845/// un-`rename`d enum emits under [`caixa_core::M3_PLACEMENT_KEY_ESTRATEGIA`] on every
846/// `programs_for_aplicacao`-emitted programs.yaml entry authored with
847/// `:placement (:estrategia Replicated …)` (and — because the enum's
848/// `default()` is `Replicated` — every programs.yaml entry authored
849/// without an explicit `:estrategia` slot). Re-export of the canonical
850/// [`caixa_core::M3_PLACEMENT_ESTRATEGIA_REPLICATED`]. The
851/// `programs_entry_placement_carries_strategy` test-fixture probe pins
852/// the emitted value against this re-export so a future variant rename
853/// or `rename_all` attribute at the aplicacao module reaches the caixa-
854/// mesh probe by construction rather than silently rebranding the
855/// substrate's default distribution posture. Peer to the sibling
856/// [`M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE`] / [`M3_PLACEMENT_ESTRATEGIA_SHARDED`]
857/// re-exports on the other two arms of the same closed enum surface.
858pub use caixa_core::M3_PLACEMENT_ESTRATEGIA_REPLICATED;
859
860/// Canonical M3 [`caixa_core::aplicacao::PlacementStrategy::Sharded`]
861/// variant discriminator scalar-value the `Serialize` derive on the
862/// un-`rename`d enum emits under [`caixa_core::M3_PLACEMENT_KEY_ESTRATEGIA`] on every
863/// `programs_for_aplicacao`-emitted programs.yaml entry authored with
864/// `:placement (:estrategia Sharded :shard-key …)` — the one arm on
865/// which the sibling [`caixa_core::M3_PLACEMENT_KEY_SHARD_KEY`] sub-block is
866/// required (`AplicacaoSpec::validate_placement` gates
867/// `shard_key.is_some() == matches!(estrategia, Sharded)` as a
868/// structural partition of every validated Placement). Re-export of the
869/// canonical [`caixa_core::M3_PLACEMENT_ESTRATEGIA_SHARDED`]. The
870/// `programs_entry_placement_carries_shard_key_when_sharded` test-fixture
871/// probe pins the emitted value against this re-export so a future
872/// variant rename or `rename_all` attribute at the aplicacao module
873/// reaches the caixa-mesh probe by construction rather than silently
874/// collapsing the hash-keyed distribution back onto the aggregator's
875/// default. Peer to the sibling [`M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE`] /
876/// [`M3_PLACEMENT_ESTRATEGIA_REPLICATED`] re-exports on the other two
877/// arms of the same closed enum surface.
878pub use caixa_core::M3_PLACEMENT_ESTRATEGIA_SHARDED;
879
880/// Canonical Cilium `CiliumNetworkPolicy` per-`ingress[].toPorts[].rules`
881/// L7-HTTP-rule-list-discriminator container-axis key every
882/// `cilium_network_policies`-emitted CNP document mounts its per-
883/// `toPorts[]` entry L7 URL-path-prefix predicate list under
884/// (`spec.ingress[].toPorts[].rules.http`). Re-export of the canonical
885/// [`caixa_core::CILIUM_KEY_HTTP`] so the Cilium-CRD per-`toPorts[]` L7-
886/// HTTP-rule-list-discriminator container-axis key string lives in exactly
887/// one place across every caixa renderer — caixa-mesh's
888/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
889/// emitter (the single production-code site the prior inline `"http"`
890/// literal sat at, the `rules.insert("http", …)` call in the
891/// `WitTarget::Http` L7 introspection emit branch) and every future
892/// per-Cilium-side renderer the M3.x absorption roadmap acknowledges now
893/// consult the same `&'static str`, so a future Cilium-CRD rebrand on the
894/// per-`toPorts[]` L7-HTTP-rule-list-discriminator axis (unlikely on the
895/// CRD's stable `cilium.io/v2` slot, but the coordination point the
896/// sibling [`CILIUM_KEY_AUTHENTICATION`] / [`CILIUM_KEY_MODE`] re-exports
897/// anchor on the parent per-ingress-rule mutual-auth body/leaf axis pair)
898/// lands in one place. The prior inline literal split across the one
899/// production emitter site and two test-fixture navigation sites (the L7
900/// fan-in path-capture pin across the multi-edge group, the per-HTTP-
901/// contract L7-path presence pin) would have let a Cilium-CRD L7-HTTP-
902/// rule-list-discriminator rebrand or a per-emitter typo (`"HTTP"` /
903/// `"Http"` / `"httpRules"` / `"httpMatch"`) at any one site silently
904/// emit a per-`toPorts[]` entry whose L7-HTTP-rule-list-discriminator
905/// key the Cilium CRD schema validator drops as unknown; the per-
906/// `toPorts[]` entry falls back to L4-only enforcement — no L7 URL-
907/// path predicate is applied — silently admitting every HTTP-method /
908/// URL-path combination the ingress rule was authored to filter to the
909/// exact path prefix set the typed `:contratos` graph names at the L7
910/// introspection axis, with no field naming the L7-HTTP-rule-list-
911/// discriminator-drift root cause. On the test-fixture side the drift
912/// silently masks the emission-side pin (`.get("http")` returns `None`
913/// under both the drifted-key emitter and the drifted-key probe —
914/// every downstream `.and_then(|h| h.as_sequence())` chain short-
915/// circuits vacuously because the outer L7-HTTP-rule-list-lookup is
916/// itself `None`). Peer to the [`CILIUM_KEY_MODE`] /
917/// [`CILIUM_KEY_AUTHENTICATION`] re-exports on the sibling per-
918/// ingress-rule mutual-auth body/leaf axis pair — completes the per-
919/// `toPorts[]` L7-introspection `(rules → http)` container/protocol-
920/// discriminator axis re-export pair this crate's
921/// `cilium_network_policies` renderer's HTTP-shaped-`:contratos` URL-
922/// path-prefix-filtering L7-enforcement contract rests on.
923pub use caixa_core::CILIUM_KEY_HTTP;
924
925/// Canonical Cilium `CiliumNetworkPolicy` per-`ingress[].toPorts[].rules.http[]`
926/// per-HTTP-rule URL-path-predicate leaf-scalar-axis key every
927/// `cilium_network_policies`-emitted CNP document mounts its per-HTTP-rule
928/// URL-path-prefix predicate scalar under
929/// (`spec.ingress[].toPorts[].rules.http[].path`). Re-export of the canonical
930/// [`caixa_core::CILIUM_KEY_PATH`] so the Cilium-CRD per-`rules.http[]`
931/// URL-path-predicate leaf-axis key string lives in exactly one place across
932/// every caixa renderer — caixa-mesh's `cilium_network_policies` per-`(:de,
933/// :para)` `CiliumNetworkPolicy` emitter (the single production-code site
934/// the prior inline `"path"` literal sat at, the `http_rule.insert("path", …)`
935/// call in the `WitTarget::Http` L7 introspection emit branch) and every
936/// future per-Cilium-side renderer the M3.x absorption roadmap acknowledges
937/// now consult the same `&'static str`, so a future Cilium-CRD rebrand on
938/// the per-`rules.http[]` URL-path-predicate leaf-axis (unlikely on the
939/// CRD's stable `cilium.io/v2` slot, but the coordination point the sibling
940/// [`CILIUM_KEY_HTTP`] re-export anchors on the parent per-`toPorts[]`
941/// L7-HTTP-rule-list-discriminator container-axis it nests inside) lands in
942/// one place. The prior inline literal split across the one production
943/// emitter site and one test-fixture navigation site (the per-HTTP-rule
944/// URL-path-predicate presence-and-value pin on the aplicacao fixture's
945/// cart→catalog HTTP-shaped `:contratos` edge) would have let a Cilium-CRD
946/// per-HTTP-rule URL-path-predicate rebrand or a per-emitter typo (`"Path"`
947/// / `"pathPrefix"` / `"regex"` / `"urlPath"` / `"pathMatch"`) at any one
948/// site silently emit a per-`rules.http[]` entry whose URL-path-predicate
949/// leaf-axis key the Cilium CRD schema validator drops as unknown; the
950/// per-`rules.http[]` entry falls back to a match-any-URL-path predicate —
951/// the per-`toPorts[]` L7 rule admits every URL path on the destination
952/// port silently, bypassing the URL-path-prefix predicate the typed
953/// `:contratos` HTTP-shaped edge's `:endpoint` slot names at the L7
954/// introspection axis, with no field naming the URL-path-predicate-leaf-
955/// axis-drift root cause. On the test-fixture side the drift silently
956/// masks the emission-side pin (`.get("path")` returns `None` under both
957/// the drifted-key emitter and the drifted-key probe — every downstream
958/// `.and_then(|v| v.as_str())` chain short-circuits vacuously because the
959/// outer per-HTTP-rule URL-path-lookup is itself `None`). Peer to the
960/// [`CILIUM_KEY_HTTP`] re-export on the parent per-`toPorts[]` L7-HTTP-
961/// rule-list-discriminator container-axis it nests inside — completes the
962/// per-`toPorts[]` L7-introspection `(rules → http → path)` container /
963/// protocol-discriminator / URL-path-predicate axis triple re-export chain
964/// this crate's `cilium_network_policies` renderer's HTTP-shaped-
965/// `:contratos` URL-path-prefix-filtering L7-enforcement contract rests on.
966/// Distinct from the sibling K8s-Gateway-API-side [`GATEWAY_API_KEY_PATH`]
967/// per-`HTTPRouteMatch` path-matcher container-axis re-export: both re-
968/// exports carry the same underlying `"path"` string but name distinct
969/// schema axes on distinct CRD groups (the Cilium-side leaf on the
970/// `cilium.io/v2` `CiliumNetworkPolicy` CRD's per-`rules.http[]` entry,
971/// the Gateway-API-side container on the `gateway.networking.k8s.io/v1`
972/// `HTTPRoute` CRD's `spec.rules[].matches[]` entry), so the sibling
973/// `pub use` declarations stay independent for the same axis-independence
974/// reason the sibling [`CILIUM_KIND_NETWORK_POLICY`] /
975/// [`GATEWAY_API_KIND_GATEWAY`] / [`GATEWAY_API_KIND_HTTP_ROUTE`] kind-
976/// discriminator re-exports stay independent across the two CRD groups.
977/// The axis-independence discipline lives at the rustc symbol-name
978/// axis (the two `pub use caixa_core::CILIUM_KEY_PATH` /
979/// `pub use caixa_core::GATEWAY_API_KEY_PATH` symbol re-exports a
980/// future rebrand of one leaves the other structurally untouched under)
981/// rather than the runtime-address axis — Rust's `&'static str` interner
982/// coalesces identical byte-sequences onto one storage allocation at
983/// codegen time, so the per-axis re-export identity pin against the
984/// canonical caixa-core declaration on each axis is what actually
985/// forbids a sibling local `pub const` from drifting, not a cross-axis
986/// pointer-inequality assertion.
987pub use caixa_core::CILIUM_KEY_PATH;
988
989/// Canonical K8s Gateway API CRD `kind` discriminator every
990/// `gateway_routes`-emitted `Gateway` document declares at its top-level
991/// [`caixa_core::KUBE_KEY_KIND`] axis. Re-export of the canonical
992/// [`caixa_core::GATEWAY_API_KIND_GATEWAY`] so the Gateway-API-conformant
993/// CRD `kind` discriminator string lives in exactly one place across
994/// every caixa renderer — caixa-mesh's `gateway_routes` per-Aplicacao
995/// `Gateway` emitter (the single production-code site the prior inline
996/// `"Gateway"` literal sat at, caixa-mesh/src/lib.rs:578 — the
997/// `kube_resource_skeleton` kind argument) and every future per-
998/// Gateway-API-side renderer the M3.x absorption roadmap acknowledges
999/// now consult the same `&'static str`, so a future Gateway-API rebrand
1000/// (e.g. an upstream rename to `GatewayV1` post-GA) is a one-line edit
1001/// on the canonical [`caixa_core::GATEWAY_API_KIND_GATEWAY`] declaration,
1002/// not a coordinated rewrite across this crate's `kube_resource_skeleton`
1003/// call site + every future per-target renderer the substrate adds.
1004/// The prior inline literal would have let a Gateway-API kind rebrand
1005/// on the caixa-mesh side without a coordinated edit on the matching
1006/// in-file `gateway_carries_canonical_kube_skeleton_without_labels` /
1007/// `render_all_includes_every_artifact_kind` test fixture pins silently
1008/// emit a `Gateway` whose top-level kind drifts off the lifted-test-
1009/// fixture pins — apply-side: the Gateway lands outside the apiserver-
1010/// side CRD registration, every external `:entrada` flow drops at the
1011/// gateway-class-controller's reconcile loop with no field naming the
1012/// kind-drift root cause. Peer to the [`GATEWAY_API_API_VERSION`]
1013/// re-export on the sibling canonical-Gateway-API-CRD-apiVersion-axis —
1014/// extends the discipline from the apiVersion half of the
1015/// `(apiVersion, kind)` CRD-lookup tuple onto the kind half on the
1016/// same Gateway-API-CRD-axis, beginning the per-Gateway-API-CRD
1017/// kind+apiVersion re-export pair this crate's `gateway_routes`
1018/// renderer's external `:entrada` ingress contract rests on. Peer to
1019/// the [`CILIUM_KIND_NETWORK_POLICY`] re-export on the sibling
1020/// canonical-Cilium-CRD-kind-discriminator surface.
1021pub use caixa_core::GATEWAY_API_KIND_GATEWAY;
1022
1023/// Canonical K8s Gateway API CRD `kind` discriminator every
1024/// `gateway_routes`-emitted `HTTPRoute` document declares at its
1025/// top-level [`caixa_core::KUBE_KEY_KIND`] axis. Re-export of the
1026/// canonical [`caixa_core::GATEWAY_API_KIND_HTTP_ROUTE`] so the
1027/// Gateway-API-conformant CRD `kind` discriminator string lives in
1028/// exactly one place across every caixa renderer — caixa-mesh's
1029/// `gateway_routes` per-Aplicacao `HTTPRoute` emitter (the single
1030/// production-code site the prior inline `"HTTPRoute"` literal sat at,
1031/// caixa-mesh/src/lib.rs:663 — the `kube_resource_skeleton` kind
1032/// argument) and every future per-Gateway-API-side renderer the M3.x
1033/// absorption roadmap acknowledges now consult the same `&'static str`,
1034/// so a future Gateway-API rebrand (e.g. an upstream rename to
1035/// `HTTPRouteV1` post-GA) is a one-line edit on the canonical
1036/// [`caixa_core::GATEWAY_API_KIND_HTTP_ROUTE`] declaration, not a
1037/// coordinated rewrite across this crate's `kube_resource_skeleton`
1038/// call site + every future per-target renderer the substrate adds.
1039/// The prior inline literal would have let a Gateway-API kind rebrand
1040/// on the caixa-mesh side without a coordinated edit on the matching
1041/// in-file `httproute_carries_canonical_kube_skeleton_without_labels`
1042/// / `render_all_includes_every_artifact_kind` test fixture pins
1043/// silently emit an `HTTPRoute` whose top-level kind drifts off the
1044/// lifted-test-fixture pins — apply-side: the HTTPRoute lands outside
1045/// the apiserver-side CRD registration, every external `:entrada` flow
1046/// drops at the gateway-class-controller's reconcile loop with no
1047/// field naming the kind-drift root cause. Peer to the
1048/// [`GATEWAY_API_KIND_GATEWAY`] re-export on the sibling canonical-
1049/// Gateway-API-CRD-`kind`-discriminator surface — completes the
1050/// per-Gateway-API-CRD `kind`-axis re-export pair this crate's
1051/// `gateway_routes` renderer's external `:entrada` ingress contract
1052/// rests on across the `(Gateway, HTTPRoute)` pair the renderer emits
1053/// together.
1054pub use caixa_core::GATEWAY_API_KIND_HTTP_ROUTE;
1055
1056/// Canonical K8s Gateway API v1 `ProtocolType` OpenAPI schema enum's
1057/// `HTTP` listener-protocol scalar value every `gateway_routes`-emitted
1058/// `Gateway` document's first (and V0-only) listener declares under its
1059/// [`caixa_core::KUBE_KEY_PROTOCOL`] axis. Re-export of the canonical
1060/// [`caixa_core::GATEWAY_API_PROTOCOL_HTTP`] so the Gateway-API-
1061/// implementation-side per-listener L7-parser-selection scalar value
1062/// lives in exactly one place across every caixa renderer — caixa-mesh's
1063/// `gateway_routes` per-`:entrada` `Gateway` emitter (the single
1064/// production-code site the prior inline `"HTTP".into()` literal sat at,
1065/// caixa-mesh/src/lib.rs:2123 — the per-listener `KUBE_KEY_PROTOCOL`
1066/// scalar-value emit) and every future per-Gateway-API-side renderer the
1067/// M3.x absorption roadmap acknowledges now consult the same
1068/// `&'static str`, so a future Gateway API `ProtocolType` enum rebrand
1069/// (e.g. an upstream rename to `HTTP/1.1` / `HTTP/2` per the SIG-Network
1070/// per-version-scope proposal) is a one-line edit on the canonical
1071/// [`caixa_core::GATEWAY_API_PROTOCOL_HTTP`] declaration, not a
1072/// coordinated rewrite across this crate's `gateway_routes` renderer's
1073/// per-listener `KUBE_KEY_PROTOCOL`-scalar-value emit + the matching
1074/// in-file `gateway_listener_carries_aplicacao_host` test's
1075/// `assert_eq!(…, Some("HTTP"))` listener-protocol-value pin + every
1076/// future per-Gateway-API-side renderer the substrate adds. The prior
1077/// inline literal would have let a Gateway-API `ProtocolType` rebrand
1078/// on the caixa-mesh side without a coordinated edit on the matching
1079/// in-file test pin silently emit a `Gateway` whose listener-protocol
1080/// scalar drifts off the lifted-test-fixture pin — apply-side: the
1081/// gateway-class-controller's per-listener bind loop rejects the
1082/// `Gateway` at admission (the K8s Gateway API v1 `ProtocolType` OpenAPI
1083/// schema enum admits the closed set `{"HTTP", "HTTPS", "TCP", "TLS",
1084/// "UDP"}` verbatim), and every external `:entrada` HTTP flow drops at
1085/// the gateway-class-controller's admission gate with no field naming
1086/// the listener-protocol-drift root cause. Peer to the
1087/// [`GATEWAY_API_KIND_GATEWAY`] + [`GATEWAY_API_KIND_HTTP_ROUTE`]
1088/// re-exports on the sibling canonical-Gateway-API-CRD-`kind`-
1089/// discriminator surface + the [`DEFAULT_GATEWAY_CLASS_NAME`] re-export
1090/// on the sibling Gateway-controller-binding-scalar-value axis —
1091/// extends the Gateway-API-CRD-`kind`-value + Gateway-controller-
1092/// binding-value re-export set onto the sibling per-Gateway
1093/// `spec.listeners[].protocol` listener-protocol-scalar-value axis the
1094/// same `gateway_routes` renderer's external `:entrada` ingress contract
1095/// carries under the shared `Gateway` body.
1096pub use caixa_core::GATEWAY_API_PROTOCOL_HTTP;
1097
1098/// Canonical K8s Gateway API v1 `PathMatchType` OpenAPI schema enum's
1099/// `PathPrefix` per-`HTTPRouteMatch` path-selection-predicate discriminator
1100/// value every `gateway_routes`-emitted `HTTPRoute` per-rule `matches[]`
1101/// entry declares under its per-match `spec.rules[].matches[].path.type`
1102/// scalar axis. Re-export of the canonical
1103/// [`caixa_core::GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] so the Gateway-
1104/// API-implementation-side per-`HTTPRouteMatch` request-path-selection-
1105/// predicate discriminator scalar value lives in exactly one place across
1106/// every caixa renderer — caixa-mesh's `gateway_routes` per-Aplicacao
1107/// `HTTPRoute` emitter (the single production-code site the prior inline
1108/// `"PathPrefix".into()` literal sat at, caixa-mesh/src/lib.rs — the
1109/// per-match `path_match.insert("type", "PathPrefix")` scalar-value emit)
1110/// and every future per-Gateway-API-side renderer the M3.x absorption
1111/// roadmap acknowledges now consult the same `&'static str`, so a future
1112/// Gateway API `PathMatchType` enum rebrand (e.g. an upstream rename to
1113/// `Prefix` / `PathPrefixMatch` per the SIG-Network per-version-scope
1114/// proposal) is a one-line edit on the canonical
1115/// [`caixa_core::GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] declaration,
1116/// not a coordinated rewrite across this crate's `gateway_routes`
1117/// renderer's per-match `path_match.insert` scalar-value emit + every
1118/// future per-Gateway-API-side renderer the substrate adds. The prior
1119/// inline literal at the one production emitter site would have let a
1120/// Gateway-API `PathMatchType` rebrand on the caixa-mesh side without a
1121/// coordinated caixa-core edit silently emit an `HTTPRoute` whose per-
1122/// match path-selection-predicate scalar drifts off the canonical
1123/// [`caixa_core::GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] value —
1124/// apply-side: the K8s apiserver-side Gateway API v1 `PathMatchType`
1125/// OpenAPI schema enum admits the closed set
1126/// `{"Exact", "PathPrefix", "RegularExpression"}` verbatim, so any
1127/// drifted value lands the emitted `HTTPRoute` outside the enum's
1128/// admitted set and every external `:entrada` path-filtered flow drops
1129/// at the gateway-class-controller's admission gate with no field naming
1130/// the path-match-type-drift root cause. Peer to the
1131/// [`GATEWAY_API_PROTOCOL_HTTP`] re-export on the sibling per-Gateway-
1132/// listener L7-parser-selection scalar-value axis — extends the
1133/// canonical-Gateway-API-v1-OpenAPI-schema-enum-value single-sourcing
1134/// re-export discipline the `ProtocolType.HTTP` re-export established
1135/// onto the sibling `PathMatchType.PathPrefix` per-`HTTPRouteMatch`
1136/// path-selection-predicate discriminator the same `gateway_routes`
1137/// external `:entrada` ingress emitter carries under the shared
1138/// `HTTPRoute` body.
1139pub use caixa_core::GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX;
1140
1141/// Canonical K8s Gateway API `HTTPRoute` parent-Gateway-binding container-
1142/// axis key every `gateway_routes`-emitted `HTTPRoute` document mounts
1143/// its per-route parent-Gateway `[{name}]` attachment list under
1144/// (`spec.parentRefs[]`). Re-export of the canonical
1145/// [`caixa_core::GATEWAY_API_KEY_PARENT_REFS`] so the Gateway-API-
1146/// implementation-side per-HTTPRoute parent-Gateway-binding-container-
1147/// axis-key string lives in exactly one place across every caixa
1148/// renderer — caixa-mesh's `gateway_routes` per-Aplicacao `HTTPRoute`
1149/// emitter (the `r_spec.insert("parentRefs", …)` call the prior inline
1150/// `"parentRefs"` literal sat at, caixa-mesh/src/lib.rs:1389) and every
1151/// future per-Gateway-API-side renderer the M3.x absorption roadmap
1152/// acknowledges now consult the same `&'static str`, so a future
1153/// Gateway API rebrand on the parent-Gateway-binding axis (an upstream
1154/// Gateway API v2 rename to `parents` / `parentGateways` / `attachedTo`,
1155/// coordinated with the upstream SIG-Network Gateway API deprecation
1156/// cycle) is a one-line edit on the canonical
1157/// [`caixa_core::GATEWAY_API_KEY_PARENT_REFS`] declaration, not a
1158/// coordinated rewrite across this crate's `gateway_routes` renderer +
1159/// every future per-target renderer the substrate adds. The prior
1160/// inline literal at the one production emitter site would have let a
1161/// Gateway-API-CRD parent-Gateway-binding-axis rebrand or a per-
1162/// emitter typo (`"parentRef"` / `"parents"` / `"parentGateways"`)
1163/// silently emit an `HTTPRoute` whose parent-Gateway-binding axis the
1164/// Gateway API CRD schema validator drops as unknown — the route lands
1165/// unattached to any Gateway, and every external `:entrada` flow the
1166/// HTTPRoute was authored to accept drops at the Gateway API
1167/// implementation's per-Gateway HTTP-listener fan-in with no field
1168/// naming the parent-Gateway-binding-drift root cause. Peer to the
1169/// [`GATEWAY_API_KIND_HTTP_ROUTE`] + [`GATEWAY_API_KIND_GATEWAY`]
1170/// re-exports on the sibling canonical-Gateway-API-CRD-`kind`-
1171/// discriminator surface — pivots this crate's per-CNP-body-axis
1172/// re-export discipline onto the sibling per-HTTPRoute-body-axis
1173/// surface, beginning the per-Gateway-API-HTTPRoute-body-axis
1174/// canonical-string re-export set (`parentRefs`, future `hostnames`)
1175/// this crate's `gateway_routes` renderer's external `:entrada`
1176/// ingress contract rests on across the Gateway API HTTPRoute-side
1177/// per-route body-shape.
1178pub use caixa_core::GATEWAY_API_KEY_PARENT_REFS;
1179
1180/// Canonical K8s Gateway API `HTTPRoute` per-`spec.parentRefs[]` entry
1181/// listener-selector sub-axis key every `gateway_routes`-emitted
1182/// `HTTPRoute` document mounts under each parent-Gateway attachment
1183/// (`spec.parentRefs[].sectionName`). Re-export of the canonical
1184/// [`caixa_core::GATEWAY_API_KEY_SECTION_NAME`] so the Gateway-API-
1185/// implementation-side per-parentRef listener-selector-sub-axis-key
1186/// string lives in exactly one place across every caixa renderer —
1187/// caixa-mesh's `gateway_routes` per-Aplicacao `HTTPRoute` emitter
1188/// (the per-parentRef `parent_ref.insert(<KEY>, …)` call whose paired
1189/// [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] `&'static str` value
1190/// binds the emitted route to the same listener the parent Gateway's
1191/// sole `listener.insert(GATEWAY_API_KEY_NAME, …)` call names) and
1192/// every future per-Gateway-API-side renderer the M3.x absorption
1193/// roadmap acknowledges now consult the same `&'static str`, so a
1194/// future Gateway API rebrand on the per-parentRef listener-selector
1195/// sub-axis (an upstream Gateway API v2 rename to `listenerName` /
1196/// `listener` / `attachTo`, coordinated with the upstream SIG-Network
1197/// Gateway API deprecation cycle) is a one-line edit on the canonical
1198/// [`caixa_core::GATEWAY_API_KEY_SECTION_NAME`] declaration, not a
1199/// coordinated rewrite across this crate's `gateway_routes` renderer
1200/// + every future per-target renderer the substrate adds.
1201///
1202/// The per-parentRef listener-selector sub-axis binds the emitted
1203/// `HTTPRoute` to exactly one listener on its parent Gateway (the
1204/// paired [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] byte-string names
1205/// the sole HTTP listener the substrate emits today). Omitting the
1206/// selector attaches the route to *every* listener on the parent
1207/// Gateway — the Gateway API v1 default fan-out that silently doubles
1208/// route emission once the substrate ships a second listener under
1209/// the HTTPS-by-default trajectory the peer
1210/// [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] docstring forecasts.
1211/// Pinning the selector by construction closes that drift footgun
1212/// structurally: the listener-name emitter and the sectionName
1213/// selector move as a single unit through one lifted `&'static str`,
1214/// so a substrate-side rebrand of the canonical listener-name
1215/// identifier reaches both sites at construction time.
1216///
1217/// Peer to the [`GATEWAY_API_KEY_PARENT_REFS`] re-export on the
1218/// sibling canonical-Gateway-API-HTTPRoute-body-axis surface — nests
1219/// the per-Gateway-API-HTTPRoute-body-axis canonical-string re-export
1220/// set (`parentRefs`, `backendRefs`, future `hostnames`) one level
1221/// deeper onto the per-parentRef listener-selector sub-axis this
1222/// crate's `gateway_routes` renderer's external `:entrada` ingress
1223/// contract now rests on across the Gateway API HTTPRoute-side per-
1224/// parentRef body-shape.
1225pub use caixa_core::GATEWAY_API_KEY_SECTION_NAME;
1226
1227/// Canonical K8s Gateway API `HTTPRoute` per-rule backend-destination
1228/// container-axis key every `gateway_routes`-emitted `HTTPRoute` per-
1229/// rule block mounts its `[{name, port}]` backend fan-out list under
1230/// (`spec.rules[].backendRefs[]`). Re-export of the canonical
1231/// [`caixa_core::GATEWAY_API_KEY_BACKEND_REFS`] so the Gateway-API-
1232/// implementation-side per-rule backend-destination-container-axis-key
1233/// string lives in exactly one place across every caixa renderer —
1234/// caixa-mesh's `gateway_routes` per-Aplicacao `HTTPRoute` emitter
1235/// (the `rule.insert("backendRefs", …)` call the prior inline
1236/// `"backendRefs"` literal sat at, caixa-mesh/src/lib.rs:1414) and
1237/// every future per-Gateway-API-side renderer the M3.x absorption
1238/// roadmap acknowledges now consult the same `&'static str`, so a
1239/// future Gateway API rebrand on the per-rule backend-destination axis
1240/// (an upstream Gateway API v2 rename to `backends` / `forwardTo` /
1241/// `to`, coordinated with the upstream SIG-Network Gateway API
1242/// deprecation cycle) is a one-line edit on the canonical
1243/// [`caixa_core::GATEWAY_API_KEY_BACKEND_REFS`] declaration, not a
1244/// coordinated rewrite across this crate's `gateway_routes` renderer +
1245/// every future per-target renderer the substrate adds. The prior
1246/// inline literal at the one production emitter site + two test-side
1247/// fixture pins (`httproute_routes_to_entrada_para`'s
1248/// `.get("backendRefs")` navigation, `httproute_rule_keys_pin_overlay_position`'s
1249/// `contains_key("backendRefs")` presence pin) would have let a
1250/// Gateway-API-CRD per-rule backend-destination-axis rebrand or a per-
1251/// emitter typo (`"backendRef"` / `"backends"` / `"forwardTo"`)
1252/// silently emit an `HTTPRoute` whose per-rule backend-destination axis
1253/// the Gateway API CRD schema validator drops as unknown — no backend
1254/// is picked at the per-rule L7 dispatch, and every external `:entrada`
1255/// request the rule was authored to route drops at the gateway-class-
1256/// controller's per-rule reconcile with no field naming the backend-
1257/// destination-drift root cause. A drift on the test-fixture side
1258/// silently masks the emission-side pin (`.get("backendRefs")` returns
1259/// `None` under both the drifted-key emitter and the drifted-key probe
1260/// — the downstream `.and_then(|b| b.as_sequence())` /
1261/// `.and_then(|s| s.first())` chain short-circuits vacuously because
1262/// the outer per-rule backend-destination lookup is itself `None`).
1263/// Peer to the [`GATEWAY_API_KEY_PARENT_REFS`] re-export on the
1264/// sibling canonical-Gateway-API-HTTPRoute-body-axis surface — extends
1265/// the per-Gateway-API-HTTPRoute-body-axis canonical-string re-export
1266/// set (`parentRefs`, `backendRefs`, future `hostnames`) this crate's
1267/// `gateway_routes` renderer's external `:entrada` ingress contract
1268/// rests on across the Gateway API HTTPRoute-side per-route body-
1269/// shape.
1270pub use caixa_core::GATEWAY_API_KEY_BACKEND_REFS;
1271
1272/// Canonical K8s Gateway API `HTTPRoute` per-rule route-match container-
1273/// axis key every `gateway_routes`-emitted `HTTPRoute` per-rule block
1274/// mounts its per-rule `[{path: {type, value}}]` route-match fan-out
1275/// list under (`spec.rules[].matches[]`). Re-export of the canonical
1276/// [`caixa_core::GATEWAY_API_KEY_MATCHES`] so the Gateway-API-
1277/// implementation-side per-rule route-match-container-axis-key string
1278/// lives in exactly one place across every caixa renderer —
1279/// caixa-mesh's `gateway_routes` per-Aplicacao `HTTPRoute` emitter
1280/// (the `rule.insert("matches", …)` call the prior inline `"matches"`
1281/// literal sat at, seeded from the Aplicacao's `:entrada :paths`
1282/// slot) and every future per-Gateway-API-side renderer the M3.x
1283/// absorption roadmap acknowledges now consult the same `&'static
1284/// str`, so a future Gateway API rebrand on the per-rule route-match
1285/// axis (an upstream Gateway API v2 rename to `match` /
1286/// `routeMatches` / `predicates`, coordinated with the upstream SIG-
1287/// Network Gateway API deprecation cycle) is a one-line edit on the
1288/// canonical [`caixa_core::GATEWAY_API_KEY_MATCHES`] declaration, not
1289/// a coordinated rewrite across this crate's `gateway_routes`
1290/// renderer + every future per-target renderer the substrate adds.
1291/// The prior inline literal at the one production emitter site + one
1292/// test-side fixture pin (`httproute_rule_keys_pin_overlay_position`'s
1293/// `contains_key("matches")` presence pin) would have let a Gateway-
1294/// API-CRD per-rule route-match-axis rebrand or a per-emitter typo
1295/// (`"match"` / `"routeMatches"` / `"predicates"`) silently emit an
1296/// `HTTPRoute` whose per-rule request-selection axis the Gateway API
1297/// CRD schema validator drops as unknown — the per-rule predicate
1298/// degrades to the wildcard match at the gateway-class-controller's
1299/// per-rule reconcile, the rule matches every request unconditionally,
1300/// and every external `:entrada` path filter the rule was authored
1301/// to enforce drops with no field naming the route-match-drift root
1302/// cause. A drift on the test-fixture side silently masks the
1303/// emission-side pin (`contains_key("matches")` returns `false` under
1304/// both the drifted-key emitter and the drifted-key probe). Peer to
1305/// the [`GATEWAY_API_KEY_BACKEND_REFS`] / [`GATEWAY_API_KEY_PARENT_REFS`]
1306/// re-exports on the sibling canonical-Gateway-API-HTTPRoute-body-
1307/// axis surface — completes the per-rule top-level-axis re-export
1308/// set (`matches`, `backendRefs`, `timeouts`, `retry`) the
1309/// `httproute_rule_keys_pin_overlay_position` pin binds against, so
1310/// every one of the four per-rule top-level axes now threads a
1311/// lifted `&'static str` apiece.
1312pub use caixa_core::GATEWAY_API_KEY_MATCHES;
1313
1314/// Canonical K8s Gateway API `HTTPRoute` per-`HTTPRouteMatch` path-matcher
1315/// container-axis key every `gateway_routes`-emitted `HTTPRoute` per-rule
1316/// `matches[]` entry mounts its per-match `{type, value}` path-selection
1317/// predicate under (`spec.rules[].matches[].path`). Re-export of the
1318/// canonical [`caixa_core::GATEWAY_API_KEY_PATH`] so the Gateway-API-
1319/// implementation-side per-`HTTPRouteMatch` path-matcher-container-axis-
1320/// key string lives in exactly one place across every caixa renderer —
1321/// caixa-mesh's `gateway_routes` per-Aplicacao `HTTPRoute` emitter (the
1322/// per-match `match_entry.insert("path", …)` call the prior inline
1323/// `"path"` literal sat at, seeded from the Aplicacao's `:entrada :paths`
1324/// slot) and every future per-Gateway-API-side renderer the M3.x
1325/// absorption roadmap acknowledges now consult the same `&'static str`,
1326/// so a future Gateway API rebrand on the per-`HTTPRouteMatch` path-
1327/// matcher axis (an upstream Gateway API v2 rename to `pathMatch` /
1328/// `prefix` / `url`, coordinated with the upstream SIG-Network Gateway
1329/// API deprecation cycle) is a one-line edit on the canonical
1330/// [`caixa_core::GATEWAY_API_KEY_PATH`] declaration, not a coordinated
1331/// rewrite across this crate's `gateway_routes` renderer + every future
1332/// per-target renderer the substrate adds. The prior inline literal at
1333/// the one production emitter site would have let a Gateway-API-CRD
1334/// per-`HTTPRouteMatch` path-matcher-axis rebrand or a per-emitter typo
1335/// (`"pathMatch"` / `"prefix"` / `"url"`) silently emit an `HTTPRoute`
1336/// whose per-match path-selection axis the Gateway API CRD schema
1337/// validator drops as unknown — the per-match path predicate degrades
1338/// to the wildcard match at the gateway-class-controller's per-rule
1339/// reconcile, the rule matches every request path unconditionally, and
1340/// every external `:entrada` path filter the rule was authored to
1341/// enforce drops with no field naming the path-matcher-drift root
1342/// cause. Peer to the [`GATEWAY_API_KEY_MATCHES`] /
1343/// [`GATEWAY_API_KEY_BACKEND_REFS`] / [`GATEWAY_API_KEY_PARENT_REFS`]
1344/// re-exports on the sibling canonical-Gateway-API-HTTPRoute-body-
1345/// axis surface — nests the per-Gateway-API-HTTPRoute-per-rule-body-
1346/// axis canonical-string re-export set (`matches`, `backendRefs`,
1347/// `timeouts`, `retry`) one level deeper onto the per-`HTTPRouteMatch`
1348/// body-axis surface this crate's `gateway_routes` renderer's external
1349/// `:entrada` ingress contract rests on across the Gateway API
1350/// HTTPRoute-side per-match body-shape.
1351pub use caixa_core::GATEWAY_API_KEY_PATH;
1352
1353/// Canonical K8s Gateway API v1 `HTTPPathMatch` scalar-payload axis key
1354/// every `gateway_routes`-emitted `HTTPRoute` per-match `path` block
1355/// mounts its per-match request-path-selection scalar payload under
1356/// (`spec.rules[].matches[].path.value`). Re-export of the canonical
1357/// [`caixa_core::GATEWAY_API_KEY_VALUE`] so the Gateway-API-
1358/// implementation-side per-`HTTPPathMatch` scalar-payload-axis-key
1359/// string lives in exactly one place across every caixa renderer —
1360/// caixa-mesh's `gateway_routes` per-Aplicacao `HTTPRoute` emitter
1361/// (the per-match `path_match.insert("value", …)` call the prior
1362/// inline `"value"` literal sat at, seeded from the Aplicacao's
1363/// `:entrada :paths` slot) and every future per-Gateway-API-side
1364/// renderer the M3.x absorption roadmap acknowledges now consult the
1365/// same `&'static str`, so a future Gateway API rebrand on the
1366/// per-`HTTPPathMatch` scalar-payload axis (an upstream Gateway API
1367/// v2 rename to `path` / `pattern` / `expression`, coordinated with
1368/// the upstream SIG-Network Gateway API deprecation cycle) is a
1369/// one-line edit on the canonical
1370/// [`caixa_core::GATEWAY_API_KEY_VALUE`] declaration, not a
1371/// coordinated rewrite across this crate's `gateway_routes` renderer
1372/// + every future per-target renderer the substrate adds. The prior
1373/// inline literal at the one production emitter site would have let
1374/// a Gateway-API-CRD per-`HTTPPathMatch`-`value`-axis rebrand or a
1375/// per-emitter typo (`"path"` / `"pattern"` / `"expression"`)
1376/// silently emit an `HTTPRoute` whose per-match request-path scalar
1377/// the Gateway API CRD schema validator drops as unknown — the
1378/// per-match path predicate degrades to the wildcard match at the
1379/// gateway-class-controller's per-rule reconcile, the rule matches
1380/// every request path unconditionally, and every external `:entrada`
1381/// path filter the rule was authored to enforce drops with no field
1382/// naming the `HTTPPathMatch`-scalar-payload-drift root cause. Peer
1383/// to the [`GATEWAY_API_KEY_PATH`] re-export on the sibling
1384/// canonical-Gateway-API-HTTPRoute-per-`HTTPRouteMatch`-body-axis
1385/// surface — nests the per-Gateway-API-HTTPRoute-per-match-body-axis
1386/// canonical-string re-export set (`path` container-axis, `value`
1387/// scalar-payload key) one level deeper onto the per-`HTTPPathMatch`
1388/// body-axis surface this crate's `gateway_routes` renderer's
1389/// external `:entrada` ingress contract rests on across the Gateway
1390/// API HTTPRoute-side per-match body-shape.
1391pub use caixa_core::GATEWAY_API_KEY_VALUE;
1392
1393/// Canonical K8s Gateway API `Gateway` per-listener-set container-axis
1394/// key every `gateway_routes`-emitted `Gateway` document mounts its per-
1395/// Gateway `[{name, port, protocol, hostname}]` L7-listener fan-out
1396/// list under (`spec.listeners[]`). Re-export of the canonical
1397/// [`caixa_core::GATEWAY_API_KEY_LISTENERS`] so the Gateway-API-
1398/// implementation-side per-Gateway L7-listener-set-container-axis-key
1399/// string lives in exactly one place across every caixa renderer —
1400/// caixa-mesh's `gateway_routes` per-Aplicacao `Gateway` emitter (the
1401/// `g_spec.insert("listeners", …)` call the prior inline `"listeners"`
1402/// literal sat at) and every future per-Gateway-API-side renderer the
1403/// M3.x absorption roadmap acknowledges now consult the same
1404/// `&'static str`, so a future Gateway API rebrand on the per-Gateway
1405/// L7-listener-set axis (an upstream Gateway API v2 rename to
1406/// `servers` / `endpoints` / `bindings`, coordinated with the upstream
1407/// SIG-Network Gateway API deprecation cycle) is a one-line edit on
1408/// the canonical [`caixa_core::GATEWAY_API_KEY_LISTENERS`] declaration,
1409/// not a coordinated rewrite across this crate's `gateway_routes`
1410/// renderer + every future per-target renderer the substrate adds. The
1411/// prior inline literal at the one production emitter site + one test-
1412/// side fixture pin (`gateway_listener_carries_aplicacao_host`'s
1413/// `.get("listeners")` navigation) would have let a Gateway-API-CRD
1414/// per-Gateway L7-listener-set-axis rebrand or a per-emitter typo
1415/// (`"listener"` / `"listen"` / `"servers"`) silently emit a `Gateway`
1416/// whose L7-listener-set axis the Gateway API CRD schema validator
1417/// drops as unknown — no listener is opened, and every external
1418/// `:entrada` flow the Gateway was authored to accept drops at the
1419/// gateway-class-controller's per-Gateway reconcile with no field
1420/// naming the L7-listener-set-drift root cause. A drift on the test-
1421/// fixture side silently masks the emission-side pin (`.get("listeners")`
1422/// returns `None` under both the drifted-key emitter and the drifted-
1423/// key probe — the downstream `.and_then(|l| l.as_sequence())` /
1424/// `.and_then(|s| s.first())` chain short-circuits vacuously because
1425/// the outer per-Gateway L7-listener-set lookup is itself `None`).
1426/// Peer to the [`GATEWAY_API_KEY_PARENT_REFS`] +
1427/// [`GATEWAY_API_KEY_BACKEND_REFS`] re-exports on the sibling
1428/// canonical-Gateway-API-HTTPRoute-body-axis surface — extends the
1429/// per-Gateway-API-CRD-body-axis canonical-string re-export set
1430/// (`parentRefs`, `backendRefs`, `listeners`, future `hostnames`) this
1431/// crate's `gateway_routes` renderer's external `:entrada` ingress
1432/// contract rests on across the Gateway API CRD-side body-shape.
1433pub use caixa_core::GATEWAY_API_KEY_LISTENERS;
1434
1435/// Canonical K8s Gateway API `Gateway` per-listener DNS-host-discriminator
1436/// axis key every `gateway_routes`-emitted `Gateway` document mounts each
1437/// listener's virtual-host filter under (`spec.listeners[].hostname`). Re-
1438/// export of the canonical [`caixa_core::GATEWAY_API_KEY_HOSTNAME`] so the
1439/// Gateway-API-implementation-side per-listener DNS-host-discriminator-
1440/// axis-key string lives in exactly one place across every caixa renderer
1441/// — caixa-mesh's `gateway_routes` per-Aplicacao `Gateway` emitter (the
1442/// per-listener `listener.insert("hostname", …)` call the prior inline
1443/// `"hostname"` literal sat at, seeded from the Aplicacao's `:entrada
1444/// :host` slot) and every future per-Gateway-API-side renderer the M3.x
1445/// absorption roadmap acknowledges now consult the same `&'static str`,
1446/// so a future Gateway API rebrand on the per-listener DNS-host
1447/// discriminator axis (an upstream Gateway API v2 rename to `host` /
1448/// `vhost` / `serverName`, coordinated with the upstream SIG-Network
1449/// Gateway API deprecation cycle) is a one-line edit on the canonical
1450/// [`caixa_core::GATEWAY_API_KEY_HOSTNAME`] declaration, not a
1451/// coordinated rewrite across this crate's `gateway_routes` renderer +
1452/// every future per-target renderer the substrate adds. The prior inline
1453/// literal at the one production emitter site + one test-side fixture
1454/// pin (`gateway_listener_carries_aplicacao_host`'s `.get("hostname")`
1455/// navigation) would have let a Gateway-API-CRD per-listener DNS-host-
1456/// discriminator-axis rebrand or a per-emitter typo (`"host"` /
1457/// `"vhost"` / `"serverName"`) silently emit a `Gateway` whose per-
1458/// listener virtual-host filter axis the Gateway API CRD schema
1459/// validator drops as unknown — the listener accepts traffic on the
1460/// wildcard host rather than the typed `:entrada :host` the Aplicacao
1461/// author declared, and every external `:entrada` flow the listener was
1462/// authored to accept lands on the wrong virtual-host filter with no
1463/// field naming the DNS-host-discriminator-drift root cause. A drift on
1464/// the test-fixture side silently masks the emission-side pin
1465/// (`.get("hostname")` returns `None` under both the drifted-key emitter
1466/// and the drifted-key probe — the downstream `.and_then(|h| h.as_str())`
1467/// chain short-circuits vacuously because the outer per-listener DNS-
1468/// host discriminator lookup is itself `None`). Peer to the
1469/// [`GATEWAY_API_KEY_LISTENERS`] +
1470/// [`GATEWAY_API_KEY_PARENT_REFS`] +
1471/// [`GATEWAY_API_KEY_BACKEND_REFS`] re-exports on the sibling
1472/// canonical-Gateway-API-CRD-body-axis surface — nests the per-Gateway-
1473/// API-CRD-body-axis canonical-string re-export set one level deeper
1474/// onto the per-listener body-axis surface (`parentRefs`, `backendRefs`,
1475/// `listeners`, `hostname`, future `hostnames`) this crate's
1476/// `gateway_routes` renderer's external `:entrada` ingress contract
1477/// rests on across the Gateway API CRD-side body-shape.
1478pub use caixa_core::GATEWAY_API_KEY_HOSTNAME;
1479
1480/// Canonical K8s Gateway API `HTTPRoute` spec-level DNS-host-filter axis
1481/// key every `gateway_routes`-emitted `HTTPRoute` document mounts the
1482/// route's per-route virtual-host filter list under (`spec.hostnames[]`).
1483/// The plural sibling of [`GATEWAY_API_KEY_HOSTNAME`] — same
1484/// Gateway-API-CRD DNS-host-discriminator convention nested one level up
1485/// on the sibling `HTTPRoute` per-route body-axis surface, distinct
1486/// spelling (`hostnames` — plural — is the `HTTPRoute` spec-level filter
1487/// list; the singular `hostname` axis it pairs against is the per-
1488/// `Gateway`-listener virtual-host discriminator). Re-export of the
1489/// canonical [`caixa_core::GATEWAY_API_KEY_HOSTNAMES`] so the Gateway-
1490/// API-implementation-side per-route DNS-host-filter-axis-key string
1491/// lives in exactly one place across every caixa renderer — caixa-mesh's
1492/// `gateway_routes` per-Aplicacao `HTTPRoute` emitter (the spec-level
1493/// `r_spec.insert("hostnames", …)` call the prior inline `"hostnames"`
1494/// literal sat at, seeded from the Aplicacao's `:entrada :host` slot as
1495/// a single-element sequence) and every future per-Gateway-API-side
1496/// renderer the M3.x absorption roadmap acknowledges now consult the
1497/// same `&'static str`, so a future Gateway API rebrand on the per-route
1498/// DNS-host filter axis (an upstream Gateway API v2 rename to `hosts` /
1499/// `vhosts` / `serverNames`, coordinated with the upstream SIG-Network
1500/// Gateway API deprecation cycle) is a one-line edit on the canonical
1501/// [`caixa_core::GATEWAY_API_KEY_HOSTNAMES`] declaration, not a
1502/// coordinated rewrite across this crate's `gateway_routes` renderer +
1503/// every future per-target renderer the substrate adds. The prior inline
1504/// literal at the one production emitter site would have let a Gateway-
1505/// API-CRD per-route DNS-host-filter-axis rebrand or a per-emitter typo
1506/// (`"hosts"` / `"vhosts"` / `"serverNames"`) silently emit an
1507/// `HTTPRoute` whose per-route virtual-host filter axis the Gateway API
1508/// CRD schema validator drops as unknown — the route accepts traffic on
1509/// every host the parent Gateway's listener accepts rather than the
1510/// typed `:entrada :host` the Aplicacao author declared, and every
1511/// external `:entrada` flow the route was authored to accept lands on
1512/// the wildcard virtual-host filter with no field naming the DNS-host-
1513/// filter-drift root cause. Peer to the
1514/// [`GATEWAY_API_KEY_HOSTNAME`] +
1515/// [`GATEWAY_API_KEY_LISTENERS`] +
1516/// [`GATEWAY_API_KEY_PARENT_REFS`] +
1517/// [`GATEWAY_API_KEY_BACKEND_REFS`] re-exports on the sibling
1518/// canonical-Gateway-API-CRD-body-axis surface — closes the per-Gateway-
1519/// API-CRD `HTTPRoute` per-route body-axis re-export pair across the
1520/// singular / plural DNS-host discriminator surface (`hostname` at the
1521/// parent-Gateway per-listener discriminator + `hostnames` at the child
1522/// HTTPRoute per-route filter list), so both halves of the DNS-host-
1523/// discriminator convention across the `(Gateway, HTTPRoute)` pair this
1524/// crate's `gateway_routes` renderer's external `:entrada` ingress
1525/// contract emits together now carry one lifted canonical `&'static str`
1526/// re-export apiece.
1527pub use caixa_core::GATEWAY_API_KEY_HOSTNAMES;
1528
1529/// Canonical K8s CR top-level `spec` key. Re-export of the canonical
1530/// [`caixa_core::KUBE_KEY_SPEC`] so the per-kind body key lives in
1531/// exactly one place across every caixa renderer — caixa-mesh's
1532/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
1533/// emitter (the `endpointSelector` + `ingress` block under spec),
1534/// caixa-mesh's `gateway_routes` `Gateway` + `HTTPRoute` emitter (the
1535/// `listeners` / `rules` / `parentRefs` / `hostnames` block under
1536/// spec), and every future per-target renderer that materializes a CR
1537/// (the M4 `mesh.pleme.io/v1alpha1/Aplicacao` materializer's
1538/// per-policy spec block, the future per-Servico `ComputeUnit` schema
1539/// reroute) consults the same `&'static str`. The prior inline
1540/// `"spec".into()` literals at the three production-code call sites
1541/// in this crate would have let a typo / camelCase drift on any one
1542/// of the three sites silently emit a CR with no recognizable spec
1543/// (the apiserver-side CRD schema validator drops the malformed
1544/// document at apply time, naming the unrecognized key but not the
1545/// source-side renderer call site). Peer to the
1546/// [`GATEWAY_API_API_VERSION`] / [`CILIUM_API_VERSION`] re-exports on
1547/// the sibling canonical-K8s-API-axis surfaces.
1548pub use caixa_core::KUBE_KEY_SPEC;
1549
1550/// Canonical K8s Gateway API `GatewayClass` name every
1551/// `gateway_routes`-emitted `Gateway` document declares at its
1552/// `spec.gatewayClassName` axis. Re-export of the canonical
1553/// [`caixa_core::DEFAULT_GATEWAY_CLASS_NAME`] so the substrate's chosen
1554/// Gateway API controller-discriminator lives in exactly one place
1555/// across every caixa renderer — caixa-mesh's `gateway_routes`
1556/// per-`:entrada` `Gateway` emitter (the single production-code site
1557/// the prior inline `"cilium".into()` literal sat at — the
1558/// `spec.gatewayClassName` field of the emitted `Gateway`'s `spec`
1559/// block) and every future per-Aplicacao materializer the M3.x + M4
1560/// absorption roadmap acknowledges (the future
1561/// `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's `Gateway`
1562/// synthesis, a future per-cluster / per-edge `Gateway` renderer for
1563/// non-HTTP `:entrada` shapes) now consult the same `&'static str`,
1564/// so a future substrate-side Gateway API controller migration
1565/// (Cilium → Envoy Gateway / Istio Gateway or any per-edition
1566/// Gateway API v1.x GA controller variant the SIG-Network roadmap
1567/// names) is a one-line edit on the canonical
1568/// [`caixa_core::DEFAULT_GATEWAY_CLASS_NAME`] declaration, not a
1569/// coordinated rewrite across this crate's `gateway_routes` call site
1570/// + every future per-target renderer the substrate adds.
1571///
1572/// The prior inline literal would have let a substrate-side controller
1573/// migration on the caixa-mesh side without a coordinated edit on the
1574/// matching in-file `gateway_gateway_class_name_uses_lifted_default_gateway_class_name`
1575/// test fixture pin silently emit a `Gateway` whose
1576/// `spec.gatewayClassName` referenced a `GatewayClass` no controller
1577/// reconciles — apply-side: the `Gateway` sits at `Programmed: False`
1578/// with every attached `HTTPRoute` unbound, every external `:entrada`
1579/// flow drops at the ingress with no field naming the controller-
1580/// drift root cause. And splitting the controller across renderers
1581/// would silently reintroduce the two-data-planes drift the mesh
1582/// composition "one identity layer, one data plane" invariant
1583/// (MESH-COMPOSITION.md §V) closes — the emitted `Gateway`'s
1584/// controller and the sibling `CiliumNetworkPolicy`'s controller
1585/// would land in distinct reconcilers, and the intra-mesh
1586/// identity-aware policy stops matching the ingress-side traffic at
1587/// the eBPF data plane. Peer to the [`DEFAULT_NAMESPACE`] re-export
1588/// on the sibling canonical-substrate-default-resource-name axis —
1589/// extends the discipline onto the canonical-Gateway-API-controller-
1590/// choice axis surface.
1591pub use caixa_core::DEFAULT_GATEWAY_CLASS_NAME;
1592
1593/// Canonical K8s Gateway API `Gateway` per-Gateway controller-binding
1594/// scalar-axis key every `gateway_routes`-emitted `Gateway` document
1595/// mounts its per-Gateway `GatewayClass.metadata.name` reference
1596/// under (`spec.gatewayClassName`). Re-export of the canonical
1597/// [`caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME`] so the
1598/// Gateway-API-implementation-side per-Gateway controller-binding
1599/// scalar-axis-key string lives in exactly one place across every
1600/// caixa renderer — caixa-mesh's `gateway_routes` per-Aplicacao
1601/// `Gateway` emitter (the `g_spec.insert("gatewayClassName", …)` call
1602/// the prior inline `"gatewayClassName"` literal sat at) and every
1603/// future per-Gateway-API-side renderer the M3.x absorption roadmap
1604/// acknowledges now consult the same `&'static str`, so a future
1605/// Gateway API rebrand on the per-Gateway controller-binding scalar
1606/// axis (an upstream Gateway API v2 rename to `className` /
1607/// `gatewayClassRef`, coordinated with the upstream SIG-Network
1608/// Gateway API deprecation cycle) is a one-line edit on the canonical
1609/// [`caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME`] declaration,
1610/// not a coordinated rewrite across this crate's `gateway_routes`
1611/// renderer + every future per-target renderer the substrate adds.
1612/// The prior inline literal at the one production emitter site + one
1613/// test-side fixture pin
1614/// (`gateway_gateway_class_name_uses_lifted_default_gateway_class_name`'s
1615/// `.get("gatewayClassName")` navigation) would have let a Gateway-
1616/// API-CRD per-Gateway controller-binding-axis rebrand or a per-
1617/// emitter typo (`"gatewayClass"` / `"className"` /
1618/// `"gatewayClassRef"`) silently emit a `Gateway` whose controller-
1619/// binding scalar-axis the Gateway API CRD schema validator drops as
1620/// unknown — no `GatewayClass` is resolved, no `controllerName` is
1621/// looked up, and every external `:entrada` flow the Gateway was
1622/// authored to accept drops at the gateway-class-controller's per-
1623/// Gateway reconcile with no field naming the controller-binding-
1624/// drift root cause. A drift on the test-fixture side silently masks
1625/// the emission-side pin (`.get("gatewayClassName")` returns `None`
1626/// under both the drifted-key emitter and the drifted-key probe —
1627/// the downstream `.and_then(|c| c.as_str())` chain short-circuits
1628/// vacuously because the outer per-Gateway controller-binding lookup
1629/// is itself `None`). Peer to the [`GATEWAY_API_KEY_LISTENERS`] +
1630/// [`GATEWAY_API_KEY_HOSTNAME`] re-exports on the sibling canonical-
1631/// Gateway-API-CRD-per-Gateway-body-axis surface. Sibling of the
1632/// peer [`DEFAULT_GATEWAY_CLASS_NAME`] re-export on the canonical-
1633/// Gateway-API-`(key, value)`-pair-lift surface this re-export
1634/// closes the KEY half of.
1635pub use caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME;
1636
1637/// Canonical K8s CR top-level `metadata` key. Re-export of the canonical
1638/// [`caixa_core::KUBE_KEY_METADATA`] so the per-kind metadata block key
1639/// lives in exactly one place across every caixa renderer — caixa-mesh's
1640/// `cilium_network_policies` per-`(:de, :para)` `CiliumNetworkPolicy`
1641/// emitter (the `metadata.{name, namespace, labels}` block every policy
1642/// carries) and `gateway_routes` `Gateway` + `HTTPRoute` emitter (the
1643/// `metadata.{name, namespace}` block each doc carries) now consult the
1644/// same `&'static str` as the peer caixa-flux renderer's
1645/// `KUBE_KEY_METADATA` re-export. The prior inline `"metadata"`
1646/// literals at every drift-detection / policy-traversal test-side site
1647/// in this crate would have let a typo on any one site (e.g. `"Metadata"`,
1648/// `"meta-data"`, `"medadata"`) silently miss the per-CNP / per-Gateway
1649/// / per-HTTPRoute metadata retrieval — the equality assertion would
1650/// then compare `None` against `Some("checkout")` rather than the
1651/// expected label value; the lift routes every K8s-CR-top-level-
1652/// metadata-axis retrieval through the same `&'static str` so drift
1653/// between any two sites becomes a single-edit fix at the caixa-core
1654/// const definition. Same shape as the [`KUBE_KEY_SPEC`] re-export on
1655/// the sibling K8s-CR top-level-spec-axis.
1656pub use caixa_core::KUBE_KEY_METADATA;
1657
1658/// Canonical K8s CR top-level `kind` discriminator key. Re-export of the
1659/// canonical [`caixa_core::KUBE_KEY_KIND`] so the per-CR-kind-axis
1660/// retrieval key lives in exactly one place across every caixa renderer
1661/// — caixa-mesh's `cilium_network_policies` + `gateway_routes` +
1662/// `render_all` test-side `(:kind, :apiVersion)` CRD-lookup-tuple
1663/// traversal predicates (every `docs.iter().find(|d| d.get("kind")…)` +
1664/// `for p in &policies { p.get("kind")… }` filter that separates the
1665/// rendered `Gateway` / `HTTPRoute` / `CiliumNetworkPolicy` documents
1666/// inside the multi-doc sequence the `gateway_routes` / `render_all`
1667/// emitters return) now consult the same `&'static str` as the peer
1668/// caixa-core-side `kube_resource_skeleton` production emitter (which
1669/// already inserts [`KUBE_KEY_KIND`] under caixa-core/src/render.rs:7181
1670/// on the [`caixa_core::KUBE_KEY_API_VERSION`] + [`KUBE_KEY_KIND`]
1671/// axis pair every rendered CR carries). The prior inline `"kind"`
1672/// literals at every drift-detection / policy-traversal / render-
1673/// determinism test-side site in this crate would have let a typo on
1674/// any one site (e.g. `"Kind"`, `"kinds"`, `"knid"`) silently miss the
1675/// per-CR kind-axis retrieval — the equality assertion would then
1676/// compare `None` against `Some("CiliumNetworkPolicy")` / `Some("Gateway")`
1677/// / `Some("HTTPRoute")` rather than the expected kind discriminator,
1678/// and the `docs.iter().find(|d| d.get(…) == Some(…))` predicate would
1679/// silently miss the per-kind document inside the multi-doc sequence
1680/// (the `.expect("Gateway present")` unwrap that names the offending
1681/// axis would fire instead of the intended assertion, masking the true
1682/// drift). The lift routes every K8s-CR-top-level-kind-axis retrieval
1683/// through the same `&'static str` so drift between any two sites
1684/// becomes a single-edit fix at the caixa-core const definition. Same
1685/// shape as the [`KUBE_KEY_SPEC`] + [`KUBE_KEY_METADATA`] re-exports on
1686/// the sibling K8s-CR top-level-spec / top-level-metadata axes —
1687/// completes the per-K8s-CR top-level `(apiVersion, kind, metadata,
1688/// spec)` axis re-export set on the `kind` half, which every downstream
1689/// `docs.iter().find(|d| d.get(KUBE_KEY_KIND)…)` predicate the multi-doc
1690/// `render_all` sequence-consumer needs to distinguish the emitted
1691/// `Cilium` / `Gateway` / `HTTPRoute` documents by rests on.
1692pub use caixa_core::KUBE_KEY_KIND;
1693
1694/// Canonical K8s CR top-level `apiVersion` key. Re-export of the
1695/// canonical [`caixa_core::KUBE_KEY_API_VERSION`] so the per-CR-
1696/// apiVersion-axis retrieval key lives in exactly one place across
1697/// every caixa renderer — caixa-mesh's `cilium_network_policies` +
1698/// `gateway_routes` test-side `(:kind, :apiVersion)` CRD-lookup-tuple
1699/// pins (every `p.get("apiVersion")` / `gateway.get("apiVersion")` /
1700/// `route.get("apiVersion")` retrieval that traverses the multi-doc
1701/// sequence the `gateway_routes` / `cilium_network_policies` emitters
1702/// return to assert the top-level `apiVersion` axis on each per-CNP /
1703/// per-`Gateway` / per-`HTTPRoute` document binds to the lifted
1704/// [`CILIUM_API_VERSION`] / [`GATEWAY_API_API_VERSION`] CRD-group/
1705/// version) now consult the same `&'static str` as the peer
1706/// caixa-core-side `kube_resource_skeleton` production emitter (which
1707/// already inserts [`KUBE_KEY_API_VERSION`] under
1708/// caixa-core/src/render.rs:7177 on the [`KUBE_KEY_API_VERSION`] +
1709/// [`KUBE_KEY_KIND`] axis pair every rendered CR carries). The prior
1710/// inline `"apiVersion"` literals at every drift-detection / CRD-
1711/// group-version pin test-side site in this crate would have let a
1712/// typo on any one site (e.g. `"ApiVersion"`, `"api-version"`,
1713/// `"apiVerison"`) silently miss the per-CR apiVersion retrieval —
1714/// the equality assertion would then compare `None` against
1715/// `Some("cilium.io/v2")` / `Some("gateway.networking.k8s.io/v1")`
1716/// rather than the expected CRD-group/version string, masking the
1717/// true sibling [`CILIUM_API_VERSION`] / [`GATEWAY_API_API_VERSION`]
1718/// axis drift. The lift routes every K8s-CR-top-level-apiVersion-
1719/// axis retrieval through the same `&'static str` so drift between
1720/// any two sites becomes a single-edit fix at the caixa-core const
1721/// definition. Same shape as the [`KUBE_KEY_SPEC`] + [`KUBE_KEY_METADATA`]
1722/// + [`KUBE_KEY_KIND`] re-exports on the sibling K8s-CR top-level-
1723/// spec / top-level-metadata / top-level-kind axes — completes the
1724/// per-K8s-CR top-level `(apiVersion, kind, metadata, spec)` axis
1725/// re-export quartet on the `apiVersion` half, which every drift-
1726/// detection pin on the sibling controller-triplet-CRD-group/
1727/// version axis (`CILIUM_API_VERSION` for Cilium, `GATEWAY_API_API_VERSION`
1728/// for Gateway API `Gateway` + `HTTPRoute`) rests on. Peer to
1729/// `caixa_flux::KUBE_KEY_API_VERSION` (e0555d6) on the sibling
1730/// renderer crate — extends the discipline from the Flux v2
1731/// controller-triplet drift-detection pins onto the Cilium + Gateway
1732/// API controller-pair drift-detection pins in this crate.
1733pub use caixa_core::KUBE_KEY_API_VERSION;
1734
1735/// Canonical K8s CR `metadata.namespace` nested-axis key. Re-export of
1736/// the canonical [`caixa_core::KUBE_KEY_NAMESPACE`] so the per-CR
1737/// namespace-axis retrieval key lives in exactly one place across
1738/// every caixa renderer — caixa-mesh's `cilium_policy_carries_canonical_kube_skeleton`
1739/// / `gateway_carries_canonical_kube_skeleton_without_labels` /
1740/// `cilium_policy_metadata_block_iterates_alphabetically` test-side
1741/// `metadata.namespace` retrievals + alphabetical-iteration determinism
1742/// pin (the three inline `"namespace"` sites this crate's rendered
1743/// multi-doc mesh bundle's per-CR `metadata.{name, namespace, labels}`
1744/// / `metadata.{name, namespace}` block traversal navigates) now
1745/// consult the same `&'static str` as the peer caixa-core-side
1746/// `kube_resource_skeleton` production emitter (which already inserts
1747/// [`KUBE_KEY_NAMESPACE`] under caixa-core/src/render.rs:9019 on the
1748/// per-CR metadata block every rendered mesh bundle document carries).
1749/// The prior inline `"namespace"` literals at every drift-detection
1750/// / render-determinism test-side site in this crate would have let a
1751/// typo on any one site (e.g. `"Namespace"`, `"name space"`, the
1752/// canonical transposition `"namesapce"`) silently miss the per-CR
1753/// metadata.namespace retrieval — the equality assertion would then
1754/// compare `None` against `Some(DEFAULT_NAMESPACE)` rather than the
1755/// expected namespace value, masking the true sibling
1756/// [`DEFAULT_NAMESPACE`] axis drift; the alphabetical-iteration
1757/// determinism pin's `vec!["labels", "name", "namespace"]` fixture
1758/// would compare against the actually-iterated key sequence and fire
1759/// on the drifted-fixture rather than the true render-determinism
1760/// property. The lift routes every K8s-CR-metadata-namespace-axis
1761/// retrieval + fixture through the same `&'static str` so drift
1762/// between any two sites becomes a single-edit fix at the caixa-core
1763/// const definition. Peer to `caixa_flux::KUBE_KEY_NAMESPACE`
1764/// (44bebfe) on the sibling renderer crate — extends the discipline
1765/// from the Flux v2 controller-triplet + ComputeUnit-side
1766/// metadata.namespace drift-detection pins onto the Cilium + Gateway
1767/// API controller-pair metadata.namespace drift-detection pins in
1768/// this crate. Extends the per-K8s-CR top-level `(apiVersion, kind,
1769/// metadata, spec)` axis re-export quartet onto the load-bearing
1770/// nested `metadata.namespace` axis — the axis every rendered
1771/// `CiliumNetworkPolicy` / `Gateway` / `HTTPRoute` document binds to
1772/// on the deploy path (the Cilium operator's per-CNP
1773/// `endpointSelector` matches pods in this namespace; the
1774/// gateway-class-controller's per-`Gateway` listener attaches only to
1775/// HTTPRoutes in this namespace; every apiserver-side CR admission-
1776/// time schema validates against it) so exactly one canonical
1777/// byte-sequence must reach every rendered artifact.
1778pub use caixa_core::KUBE_KEY_NAMESPACE;
1779
1780/// Canonical K8s CR `metadata.labels` nested-axis key. Re-export of the
1781/// canonical [`caixa_core::KUBE_KEY_LABELS`] so the per-CR labels-axis
1782/// retrieval key lives in exactly one place across every caixa renderer
1783/// — caixa-mesh's `cilium_policy_metadata_labels_use_lifted_consts`
1784/// test-side retrieval of the per-CNP `metadata.labels` mapping (the
1785/// LABEL_APLICACAO + LABEL_CONTRATO drift-detection pin's entry point),
1786/// caixa-mesh's `cilium_policy_carries_canonical_kube_skeleton` +
1787/// `gateway_carries_canonical_kube_skeleton_without_labels` +
1788/// `httproute_carries_canonical_kube_skeleton_without_labels` per-CR
1789/// metadata-block `.get("labels")` probes (the presence-of-labels /
1790/// empty-labels-skip semantic pins on `CiliumNetworkPolicy` /
1791/// `Gateway` / `HTTPRoute`), and the
1792/// `cilium_policy_metadata_block_iterates_alphabetically` render-
1793/// determinism-contract fixture (the alphabetical-iteration `vec!["labels",
1794/// "name", KUBE_KEY_NAMESPACE]` fixture whose first entry the alphabetical-
1795/// key-ordering `metadata:` block emission pins). The prior five inline
1796/// `"labels"` literals at every drift-detection / render-determinism
1797/// test-side site in this crate would have let a typo on any one site
1798/// (e.g. `"Labels"`, `"lables"`, the canonical transposition `"lablels"`)
1799/// silently miss the per-CR metadata.labels retrieval — the
1800/// `.get("labels")` chain would then return `None` and the trailing
1801/// `.expect("policy metadata.labels mapping")` would panic with the
1802/// mapping-shape message, masking the true label-key drift, or the
1803/// presence-of-labels / empty-labels-skip semantic pins would compare
1804/// `Some(...)`/`None` under the wrong retrieval so the empty-labels-skip
1805/// contract's true drift never surfaces, or the alphabetical-iteration
1806/// render-determinism fixture would fire on the drifted-fixture rather
1807/// than the true render-determinism property. The lift routes every K8s-
1808/// CR-metadata-labels-axis retrieval + fixture through the same
1809/// `&'static str` so drift between any two sites becomes a single-edit
1810/// fix at the caixa-core const definition. Extends the per-K8s-CR
1811/// top-level `(apiVersion, kind, metadata, spec)` axis re-export
1812/// quartet + the load-bearing nested `metadata.namespace` axis onto
1813/// the load-bearing nested `metadata.labels` axis — the axis every
1814/// rendered `CiliumNetworkPolicy` document carries at the `pleme.pleme.io/
1815/// aplicacao` + `pleme.pleme.io/contrato` grouping key (the Hubble flow-
1816/// grouping / operator-policy-filter selection axis every consumer of
1817/// the rendered mesh bundle keys off) so exactly one canonical byte-
1818/// sequence must reach every rendered artifact.
1819pub use caixa_core::KUBE_KEY_LABELS;
1820
1821/// Canonical K8s CR `metadata.name` nested-axis key. Re-export of the
1822/// canonical [`caixa_core::KUBE_KEY_NAME`] so the per-CR name-axis
1823/// retrieval key lives in exactly one place across every caixa renderer
1824/// — caixa-mesh's `cilium_policy_carries_canonical_kube_skeleton` +
1825/// `gateway_carries_canonical_kube_skeleton_without_labels` +
1826/// `httproute_carries_canonical_kube_skeleton_without_labels` per-CR
1827/// metadata-block `.get("name")` retrievals (the presence + equality
1828/// pins on `CiliumNetworkPolicy` / `Gateway` / `HTTPRoute`), the six
1829/// per-CNP `metadata.name`-axis lookup navigations across the
1830/// `cilium_policy_metadata_names_span_all_edges` /
1831/// `cilium_fans_same_de_para_edges_into_one_policy` /
1832/// `cilium_http_contracts_emit_l7_rules` /
1833/// `cilium_pubsub_contracts_skip_l7_rules` /
1834/// `cnp_l4_fallback_port_routes_through_lifted_default_servico_port` /
1835/// `cilium_mtls_required_contract_emits_authentication_required`
1836/// test-side `policies.iter().find(|p| p.get(KUBE_KEY_METADATA)
1837/// .and_then(|m| m.get(KUBE_KEY_NAME)))` filters (the per-CNP
1838/// `<aplicacao>-<de>-to-<para>` metadata.name binding that names every
1839/// `CiliumNetworkPolicy` document the per-`(:de, :para)` fan-out emits),
1840/// and the `cilium_policy_metadata_block_iterates_alphabetically`
1841/// render-determinism-contract fixture (the alphabetical-iteration
1842/// `vec![KUBE_KEY_LABELS, "name", KUBE_KEY_NAMESPACE]` fixture whose
1843/// middle entry the alphabetical-key-ordering `metadata:` block
1844/// emission pins). The prior ten inline `"name"` literals at every
1845/// drift-detection / per-CNP-lookup / render-determinism test-side site
1846/// in this crate would have let a typo on any one site (e.g. `"Name"`,
1847/// `"nmae"`, the canonical transposition `"naem"`) silently miss the
1848/// per-CR metadata.name retrieval — the `.get("name")` chain would then
1849/// return `None` under the presence pin so the true metadata-name-axis
1850/// drift never surfaces, or compare `Some(<other>)` against the
1851/// expected caixa name/route name under the equality pins so the
1852/// caixa-nome → metadata-name binding's true drift is masked, or slip
1853/// past the per-CNP metadata.name filter under the six per-`(:de, :para)`
1854/// lookup navigations so the true policy-identity → edge-shape binding
1855/// under fan-in / L7-emission / L4-fallback / mTLS-authentication drift
1856/// never surfaces (each `.find(|p| p.get(KUBE_KEY_METADATA)
1857/// .and_then(|m| m.get("name")))` chain would silently return
1858/// `.unwrap()`-panicking `None` on the first per-CNP lookup or match
1859/// the wrong policy under the equality-comparison filter, masking the
1860/// true fan-in / L7-rule / L4-port / mTLS-authentication mode
1861/// property), or trip the alphabetical-iteration determinism fixture
1862/// against the drifted-fixture rather than the true render-determinism
1863/// property. The lift routes every K8s-CR-metadata-name-axis retrieval
1864/// + fixture through the same `&'static str` so drift between any two
1865/// sites becomes a single-edit fix at the caixa-core const definition.
1866/// Completes the K8s-CR metadata-block axis triplet `(name, namespace, labels)`
1867/// under a single canonical `caixa-core::KUBE_KEY_*` re-export shape
1868/// in this crate — the peer `KUBE_KEY_NAMESPACE` (ae34889) and
1869/// `KUBE_KEY_LABELS` (aa2d105) sweeps established the discipline; this
1870/// lift extends it onto the last remaining metadata-nested axis. The
1871/// per-K8s-CR top-level `(apiVersion, kind, metadata, spec)` axis
1872/// re-export quartet + the load-bearing nested `metadata.namespace` +
1873/// `metadata.labels` axes now extend onto the load-bearing nested
1874/// `metadata.name` axis — the axis every rendered `CiliumNetworkPolicy`
1875/// / `Gateway` / `HTTPRoute` document binds to on the deploy path (the
1876/// apiserver's CR admission-time schema keys the object identity off
1877/// it; every `kubectl get`/GC/finalizer navigates the same key; the
1878/// Cilium operator's per-CNP status-update path and the gateway-class-
1879/// controller's per-`Gateway` listener-attach navigate the same axis)
1880/// so exactly one canonical byte-sequence must reach every rendered
1881/// artifact.
1882pub use caixa_core::KUBE_KEY_NAME;
1883
1884/// Canonical K8s `LabelSelector.matchLabels` nested-axis key. Re-export
1885/// of the canonical [`caixa_core::KUBE_KEY_MATCH_LABELS`] so the per-CR
1886/// selector-axis retrieval key lives in exactly one place across every
1887/// caixa renderer — caixa-mesh's `cilium_policies_are_identity_based`
1888/// (the `endpointSelector.matchLabels` presence pin + the
1889/// `ingress[0].fromEndpoints[0].matchLabels` two-axis-selector pin
1890/// that check the `pleme.pleme.io/program` + `pleme.pleme.io/aplicacao`
1891/// identity keys the Cilium data plane matches on), the
1892/// `cilium_endpoint_selector_is_program_only` destination-selector-axis
1893/// pin (single-axis `LABEL_PROGRAM`-only selector — the
1894/// destination-`endpointSelector.matchLabels` retrieval whose
1895/// `selector.len() == 1` assertion pins the program-only semantic the
1896/// canonical `pleme_program_selector` helper emits), and the
1897/// `cilium_from_endpoints_carries_aplicacao_scoped_selector` source-
1898/// selector-axis pin (two-axis `LABEL_PROGRAM` + `LABEL_APLICACAO`
1899/// selector — the source-`fromEndpoints[0].matchLabels` retrieval
1900/// whose `from.len() == 2` assertion pins the
1901/// program-in-Aplicacao-scoped semantic the canonical
1902/// `pleme_program_in_aplicacao_selector` helper emits, guarding the
1903/// safety property that a same-named program in a different
1904/// Aplicacao cannot satisfy the policy's ingress rule) now consult
1905/// the same `&'static str` as the peer caixa-core-side
1906/// `label_selector` production emitter (which already inserts
1907/// [`KUBE_KEY_MATCH_LABELS`] under caixa-core/src/render.rs:7112 on
1908/// every `{matchLabels: <mapping>}` envelope the typed selector
1909/// helpers emit). The prior four inline `"matchLabels"` literals at
1910/// every drift-detection / selector-axis test-side site in this
1911/// crate would have let a typo on any one site (e.g. `"MatchLabels"`,
1912/// `"match_labels"`, `"match-labels"`, the canonical camelCase-drift
1913/// `"matchlabels"` — the K8s apiserver's OpenAPI v3 schema property
1914/// name is strict camelCase `matchLabels`) silently miss the per-CR
1915/// selector-mapping retrieval — the `.get("matchLabels")` chain
1916/// would then return `None` under the presence pin so the true
1917/// selector-axis drift never surfaces, or the surrounding
1918/// `.expect("endpointSelector.matchLabels mapping")` /
1919/// `.expect("fromEndpoints[0].matchLabels mapping")` panic-message
1920/// tag would fire with the mapping-shape message rather than the
1921/// true selector-key drift, or the `selector.len() == 1` /
1922/// `from.len() == 2` axis-count assertion would compare against the
1923/// wrong retrieval so the destination-program-only / source-program-
1924/// in-Aplicacao selector-shape contract's true drift is masked. The
1925/// lift routes every K8s-`LabelSelector.matchLabels`-axis retrieval
1926/// through the same `&'static str` so drift between any two sites
1927/// becomes a single-edit fix at the caixa-core const definition.
1928/// Extends the per-K8s-CR top-level `(apiVersion, kind, metadata,
1929/// spec)` axis re-export quartet + the load-bearing nested
1930/// `metadata.{name, namespace, labels}` triplet onto the load-bearing
1931/// nested `LabelSelector.matchLabels` axis — the equality-projection
1932/// axis every rendered `CiliumNetworkPolicy` document carries at both
1933/// `spec.endpointSelector.matchLabels` (the destination-identity
1934/// selector the Cilium data plane matches pod-identity keys against)
1935/// and `spec.ingress[*].fromEndpoints[*].matchLabels` (the source-
1936/// identity selector the same data plane checks on the admitted-
1937/// source side). Peer to the sibling load-bearing nested
1938/// `LabelSelector.matchLabels` axis re-exports every downstream
1939/// consumer of the rendered mesh bundle keys off (the Cilium
1940/// operator's per-CNP `endpointSelector` and per-ingress-rule
1941/// `fromEndpoints` navigate the same K8s-`LabelSelector`-schema
1942/// projection).
1943pub use caixa_core::KUBE_KEY_MATCH_LABELS;
1944
1945/// Canonical K8s CR `rules` collection-axis key. Re-export of the
1946/// canonical [`caixa_core::KUBE_KEY_RULES`] so the per-CR rule-list
1947/// container key lives in exactly one place across every caixa
1948/// renderer — this crate's two production-code emitters
1949/// (`cilium_network_policies`'s per-`toPorts[]` `rules:` L7 rule-list
1950/// mapping the Cilium data plane dispatches HTTP / Kafka / DNS L7
1951/// rules under, `gateway_routes`'s `HTTPRoute` `spec.rules[]` sequence
1952/// the gateway-class-controller dispatches per-rule `matches[]` +
1953/// `backendRefs[]` + timeouts / retries overlay under) and this crate's
1954/// five test-side rule-list traversal sites (the
1955/// `httproute_carries_paths_from_http_endpoints` `.get("rules")` under
1956/// `toPorts[]` L7-path-content pin, the `cilium_l7_rules_are_http_only`
1957/// `.get("rules")` under `toPorts[]` L7-http-only-shape pin, the
1958/// `cilium_pubsub_contracts_skip_l7_rules` `to_ports.get("rules").is_none()`
1959/// pubsub-contracts-carry-no-L7-rules absence pin, the
1960/// `gateway_emits_gateway_plus_httproute_pair` `.get("rules")` under
1961/// `spec` HTTPRoute-backendRefs-shape pin, and the `httproute_rules`
1962/// test-fixture helper `.get("rules")` under `spec` HTTPRoute-rule-
1963/// sequence retrieval every downstream policy-timeout / retries /
1964/// mtls / rate-limit determinism pin reaches through) now consult the
1965/// same `&'static str` as the peer caixa-core-side const definition.
1966///
1967/// The prior inline `"rules"` literals at the two production emitter
1968/// sites + five test-side retrieval sites in this crate would have let
1969/// a typo on any one site (e.g. `"Rules"`, `"rule"`, `"ruleset"`, the
1970/// canonical `HTTPRoute.spec.rules` vs Cilium `toPorts[].rules` cross-
1971/// context transposition where a maintainer replaces one axis's key
1972/// with the other's spelling mid-edit) silently miss the per-CR rule-
1973/// list retrieval — the presence pin's `.expect("HTTPRoute spec.rules
1974/// sequence")` panic-message tag would fire against the mapping-shape
1975/// message rather than the true rule-list-key drift, or the
1976/// `is_none()` absence pin (`cilium_pubsub_contracts_skip_l7_rules`)
1977/// would fire on the drifted retrieval so the L7-rules-absent-on-
1978/// pubsub-contracts contract's true drift is masked. On the production
1979/// side, a drift to `"Rules"` at either emitter site would silently
1980/// emit a CR whose rule-list container the apiserver-side CRD schema
1981/// validator drops as unrecognized at apply time (the Cilium operator's
1982/// per-CNP L7 dispatch pass would silently no-op every rule on the
1983/// affected `toPorts[]`; the gateway-class-controller's per-HTTPRoute
1984/// rule-dispatch pass would silently no-op every match/backend rule on
1985/// the affected route) with no field naming the rule-list-key-drift
1986/// root cause. The lift routes every K8s-CR-rules-axis retrieval +
1987/// emission through the same `&'static str` so drift between any two
1988/// sites becomes a single-edit fix at the caixa-core const definition.
1989///
1990/// Same shape as the [`KUBE_KEY_MATCH_LABELS`] re-export on the
1991/// sibling nested-selector-projection axis — extends the per-K8s-CR
1992/// top-level `(apiVersion, kind, metadata, spec)` axis re-export
1993/// quartet + the load-bearing nested `metadata.{name, namespace,
1994/// labels}` triplet + the load-bearing nested
1995/// `LabelSelector.matchLabels` selector-projection axis onto the
1996/// load-bearing nested `spec.rules[]` / `toPorts[].rules`
1997/// rule-list-container axis every downstream L7-policy /
1998/// HTTPRoute-rule-dispatch consumer of the rendered mesh bundle keys
1999/// off. Peer to the sibling load-bearing K8s-CR-schema-axis re-exports
2000/// every downstream apiserver-side CRD-schema-validator navigates the
2001/// same rule-list container axis on (the Cilium operator's per-CNP
2002/// L7 dispatch pass under `spec.ingress[].toPorts[].rules.http[]`, the
2003/// gateway-class-controller's per-HTTPRoute rule-dispatch pass under
2004/// `spec.rules[].matches[]` + `spec.rules[].backendRefs[]`).
2005pub use caixa_core::KUBE_KEY_RULES;
2006
2007/// Canonical K8s CR L4-port scalar-axis key. Re-export of the
2008/// canonical [`caixa_core::KUBE_KEY_PORT`] so the per-CR L4-port
2009/// scalar field name lives in exactly one place across every caixa
2010/// renderer — this crate's three production-code emission sites
2011/// (`cilium_network_policies`'s per-`toPorts[].ports[]` port-tuple
2012/// `port:` scalar the Cilium data plane's per-tuple bpf policy
2013/// dispatch loop compares against the observed TCP/UDP L4 header
2014/// port value, `gateway_routes`'s per-`Gateway` per-listener
2015/// `spec.listeners[].port` scalar the gateway-class-controller's
2016/// per-listener bind loop opens the listener socket on,
2017/// `gateway_routes`'s per-`HTTPRoute` per-rule
2018/// `spec.rules[].backendRefs[].port` scalar the gateway-class-
2019/// controller's per-rule backend-dispatch loop forwards the matched
2020/// request to on the resolved Service / ExternalName backend) and
2021/// this crate's two test-side L4-port traversal sites (the
2022/// `cilium_l4_ports_default_to_servico_port` `.get("port")` under
2023/// `toPorts[].ports[]` L7-fallback-port-content pin threading through
2024/// [`DEFAULT_SERVICO_PORT`], the `gateway_emits_gateway_plus_httproute_pair`
2025/// `.get("port")` under `backendRefs[]` HTTPRoute-backend-port-content
2026/// pin) now consult the same `&'static str` as the peer caixa-core-side
2027/// const definition.
2028///
2029/// The prior inline `"port"` literals at the three production
2030/// emitter sites + two test-side retrieval sites in this crate would
2031/// have let a typo on any one site (e.g. `"Port"`, `"portNumber"`,
2032/// `"portValue"`, the canonical K8s port-value axis vs the K8s
2033/// Service `targetPort` L4-forwarding-destination axis cross-context
2034/// transposition where a maintainer replaces the port-value axis's
2035/// key with the forwarding-destination axis's spelling mid-edit)
2036/// silently miss the per-CR L4-port retrieval or emit a malformed CR
2037/// whose port field the apiserver-side CRD schema validator drops as
2038/// unrecognized at apply time — the Cilium operator's per-CNP L4
2039/// per-tuple bpf policy dispatch loop would silently accept every
2040/// L4 packet on the drifted `toPorts[].ports[]` entry regardless of
2041/// port match (bpf policy no-op on unrecognized port field), the
2042/// gateway-class-controller's per-listener bind loop would silently
2043/// fall back to a null listener socket (no bind, no L7 traffic
2044/// admitted), and the gateway-class-controller's per-rule backend-
2045/// dispatch loop would silently fall back to the K8s Service's
2046/// default target port (which may bind a different Servico's L4
2047/// port, silently routing traffic to the wrong backend) with no
2048/// field naming the L4-port-key-drift root cause. The lift routes
2049/// every K8s-CR-L4-port-scalar-axis retrieval + emission through the
2050/// same `&'static str` so drift between any two sites becomes a
2051/// single-edit fix at the caixa-core const definition.
2052///
2053/// Same shape as the [`KUBE_KEY_RULES`] re-export on the sibling
2054/// nested-rule-list-container axis — extends the per-K8s-CR top-
2055/// level `(apiVersion, kind, metadata, spec)` axis re-export quartet
2056/// + the load-bearing nested `metadata.{name, namespace, labels}`
2057/// triplet + the load-bearing nested `LabelSelector.matchLabels`
2058/// selector-projection axis + the load-bearing nested `spec.rules[]`
2059/// / `toPorts[].rules` rule-list-container axis onto the load-
2060/// bearing nested L4-port-scalar axis every downstream bpf-policy-
2061/// dispatch / gateway-listener-bind / gateway-backend-dispatch
2062/// consumer of the rendered mesh bundle keys off. Peer to the
2063/// sibling load-bearing K8s-CR-schema-axis re-exports every
2064/// downstream apiserver-side CRD-schema-validator navigates the same
2065/// L4-port scalar axis on (the Cilium operator's per-CNP L4 dispatch
2066/// pass under `spec.ingress[].toPorts[].ports[].port`, the gateway-
2067/// class-controller's per-Gateway per-listener bind pass under
2068/// `spec.listeners[].port`, the gateway-class-controller's per-
2069/// HTTPRoute per-rule backend-dispatch pass under
2070/// `spec.rules[].backendRefs[].port`).
2071pub use caixa_core::KUBE_KEY_PORT;
2072
2073/// Canonical K8s CR L4/L7 protocol scalar-discriminator-axis key.
2074/// Re-export of the canonical [`caixa_core::KUBE_KEY_PROTOCOL`] so
2075/// the per-CR protocol scalar-discriminator field name lives in
2076/// exactly one place across every caixa renderer — this crate's two
2077/// production-code emission sites (`cilium_network_policies`'s
2078/// per-`toPorts[].ports[]` port-tuple `protocol:` scalar the Cilium
2079/// data plane's per-tuple bpf policy dispatch loop compares against
2080/// the observed L4 header protocol before applying the port match,
2081/// `gateway_routes`'s per-`Gateway` per-listener
2082/// `spec.listeners[].protocol` scalar the gateway-class-controller's
2083/// per-listener bind loop selects the L7 parser + TLS termination
2084/// strategy from) and this crate's one test-side protocol-scalar
2085/// traversal site (the `gateway_emits_gateway_plus_httproute_pair`
2086/// `.get("protocol")` retrieval on the emitted `Gateway`'s first
2087/// listener pinning the canonical `HTTP` listener-protocol content)
2088/// now consult the same `&'static str` as the peer caixa-core-side
2089/// const definition.
2090///
2091/// The prior inline `"protocol"` literals at the two production
2092/// emitter sites + one test-side retrieval site in this crate would
2093/// have let a typo on any one site (e.g. `"Protocol"`, `"proto"`,
2094/// `"transportProtocol"`) silently miss the per-CR protocol
2095/// discrimination or emit a malformed CR whose protocol field the
2096/// apiserver-side CRD schema validator drops as unrecognized at
2097/// apply time — the Cilium data plane's per-tuple bpf policy
2098/// dispatch loop would silently fall back to the CRD default
2099/// protocol `ANY` (admitting UDP traffic through a TCP-only rule
2100/// with no diagnostic), the gateway-class-controller's per-listener
2101/// bind loop would silently fail listener validation on a required
2102/// protocol field (rejecting the entire `Gateway` object at
2103/// admission time, no L7 traffic admitted, with the error message
2104/// naming the missing field rather than the drifted key that caused
2105/// the omission), and the test-side pin's `assert_eq!(…, Some("HTTP"))`
2106/// would silently unwrap to `None` under the drifted retrieval. The
2107/// lift routes every K8s-CR-protocol-scalar-axis retrieval + emission
2108/// through the same `&'static str` so drift between any two sites
2109/// becomes a single-edit fix at the caixa-core const definition.
2110///
2111/// Same shape as the [`KUBE_KEY_PORT`] re-export on the sibling
2112/// L4-port-scalar axis — extends the per-K8s-CR top-level
2113/// `(apiVersion, kind, metadata, spec)` axis re-export quartet +
2114/// the load-bearing nested `metadata.{name, namespace, labels}`
2115/// triplet + the load-bearing nested `LabelSelector.matchLabels`
2116/// selector-projection axis + the load-bearing nested `spec.rules[]`
2117/// / `toPorts[].rules` rule-list-container axis + the load-bearing
2118/// nested L4-port-scalar axis onto the load-bearing nested
2119/// L4/L7-protocol-scalar-discriminator axis every downstream bpf-
2120/// policy-dispatch / gateway-listener-bind consumer of the rendered
2121/// mesh bundle keys off before it can commit to a port match or a
2122/// listener parser. Peer to the sibling load-bearing K8s-CR-schema-
2123/// axis re-exports every downstream apiserver-side CRD-schema-
2124/// validator navigates the same protocol scalar axis on (the Cilium
2125/// operator's per-CNP L4 dispatch pass under
2126/// `spec.ingress[].toPorts[].ports[].protocol`, the gateway-class-
2127/// controller's per-Gateway per-listener bind pass under
2128/// `spec.listeners[].protocol`).
2129pub use caixa_core::KUBE_KEY_PROTOCOL;
2130
2131/// Canonical K8s CR discriminated-union `type` scalar-discriminator-
2132/// axis key. Re-export of the canonical [`caixa_core::KUBE_KEY_TYPE`]
2133/// so the per-CR discriminated-union type scalar-discriminator field
2134/// name lives in exactly one place across every caixa renderer — this
2135/// crate's one production-code emission site (`gateway_routes`'s per-
2136/// rule per-`HTTPRouteMatch` `spec.rules[].matches[].path.type` scalar
2137/// the gateway-class-controller's per-rule L7 dispatch pass selects
2138/// the path-match strategy from) and this crate's test-side traversal
2139/// sites navigating the rendered `HTTPRoute`'s per-match path-selection-
2140/// predicate discriminator now consult the same `&'static str` as the
2141/// peer caixa-core-side const definition. Pairs with the sibling
2142/// [`GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] re-export on the per-
2143/// `HTTPRouteMatch` path-selection-predicate discriminator scalar-VALUE
2144/// axis the discriminator scalar-KEY here holds under, closing the
2145/// per-`HTTPRouteMatch` path-selection-predicate `(type key →
2146/// PathPrefix value)` scalar-key/scalar-value discriminator axis pair
2147/// this crate's `gateway_routes` renderer's external `:entrada` per-
2148/// path L7-filtering ingress contract rests on — the same shape the
2149/// sibling [`KUBE_KEY_PROTOCOL`] key + [`KUBE_PROTOCOL_TCP`] /
2150/// [`GATEWAY_API_PROTOCOL_HTTP`] value pair already carries on the
2151/// L4/L7-protocol scalar-discriminator surface.
2152///
2153/// The prior inline `"type"` literal at the one production emitter
2154/// site (`path_match.insert("type", …)` in `gateway_routes`) would
2155/// have let a typo (`"Type"` / `"kind"` / `"discriminator"` /
2156/// `"predicate"`) silently emit an `HTTPRoute` whose per-match path-
2157/// selection-predicate discriminator scalar-key the Gateway API v1
2158/// `HTTPPathMatch` OpenAPI schema validator drops as unknown at
2159/// apply time — the per-match entry falls back to the schema-side
2160/// default path-match-strategy, silently admitting every URL-path
2161/// prefix the ingress rule was authored to filter to the exact
2162/// predicate the typed `:entrada :paths` slot names at the request-
2163/// path-selection axis, and every external `:entrada` path-filtered
2164/// flow drops at the gateway-class-controller's admission gate with
2165/// no field naming the discriminator-scalar-key-drift root cause.
2166/// The lift routes every K8s-CR-discriminated-union-type-scalar-key
2167/// retrieval + emission through the same `&'static str` so drift
2168/// between any two sites becomes a single-edit fix at the caixa-core
2169/// const definition.
2170///
2171/// Same shape as the [`KUBE_KEY_PROTOCOL`] / [`KUBE_KEY_PORT`] re-
2172/// exports on the sibling L4/L7-protocol + L4-port scalar-axis
2173/// surfaces — extends the per-K8s-CR top-level
2174/// `(apiVersion, kind, metadata, spec)` axis re-export quartet + the
2175/// load-bearing nested `metadata.{name, namespace, labels}` triplet
2176/// + the load-bearing nested `LabelSelector.matchLabels` selector-
2177/// projection axis + the load-bearing nested `spec.rules[]` /
2178/// `toPorts[].rules` rule-list-container axis + the load-bearing
2179/// nested L4-port-scalar axis + the load-bearing nested L4/L7-
2180/// protocol-scalar-discriminator axis onto the load-bearing nested
2181/// K8s-discriminated-union-type-scalar-discriminator axis every
2182/// downstream apiserver-side OpenAPI-schema-validator / gateway-
2183/// class-controller consumer of the rendered mesh bundle keys off
2184/// before it can commit to a per-match request-path-selection
2185/// predicate.
2186pub use caixa_core::KUBE_KEY_TYPE;
2187
2188/// Canonical K8s core `Protocol` OpenAPI schema enum's `TCP` L4-transport-
2189/// protocol scalar value every `cilium_network_policies`-emitted
2190/// `CiliumNetworkPolicy` document's per-`spec.ingress[].toPorts[].ports[]`
2191/// port-tuple declares under its per-tuple [`caixa_core::KUBE_KEY_PROTOCOL`]
2192/// axis. Re-export of the canonical [`caixa_core::KUBE_PROTOCOL_TCP`] so
2193/// the K8s-core-`Protocol`-enum-side per-port-tuple L4-transport-selection
2194/// scalar value lives in exactly one place across every caixa renderer —
2195/// caixa-mesh's `cilium_network_policies` per-`(:de, :para)` CNP emitter
2196/// (the single production-code site the prior inline `"TCP".into()`
2197/// literal sat at, caixa-mesh/src/lib.rs — the per-`toPorts[].ports[]`
2198/// port-tuple `KUBE_KEY_PROTOCOL` scalar-value emit) and every future
2199/// per-Cilium-CNP-side / K8s-core-`Protocol`-side renderer the M3.x
2200/// absorption roadmap acknowledges now consult the same `&'static str`,
2201/// so a future K8s core `Protocol` enum rebrand (e.g. the `KEP-3675 QUIC
2202/// transport` proposal's `"QUIC"` addition to the enum, coordinated with
2203/// the upstream SIG-Network per-version deprecation cycle) is a one-line
2204/// edit on the canonical [`caixa_core::KUBE_PROTOCOL_TCP`] declaration,
2205/// not a coordinated rewrite across this crate's `cilium_network_policies`
2206/// renderer's per-port-tuple `KUBE_KEY_PROTOCOL`-scalar-value emit + every
2207/// future per-Cilium-CNP-side renderer the substrate adds. The prior
2208/// inline literal would have let a K8s core `Protocol` rebrand on the
2209/// caixa-mesh side without a coordinated edit silently emit a
2210/// `CiliumNetworkPolicy` whose per-`toPorts[].ports[]` port-tuple
2211/// L4-transport-protocol scalar drifts off the K8s core `Protocol` enum's
2212/// admitted closed set — apply-side: the Cilium operator's per-CNP L4
2213/// dispatch pass rejects the object at admission (the K8s core `Protocol`
2214/// OpenAPI schema enum admits the closed set `{"TCP", "UDP", "SCTP"}`
2215/// verbatim), and every intra-mesh `:contratos` L4-tuple-gated flow drops
2216/// at the Cilium operator's admission gate with no field naming the L4-
2217/// transport-protocol-drift root cause; worse — because the `protocol`
2218/// scalar carries a schema-side default of `TCP` on the K8s core
2219/// `Protocol` enum, a silently-elided drift on the emit lands a
2220/// `CiliumNetworkPolicy` whose ingress rule falls back to the default
2221/// L4-transport-protocol and every port-match on a non-default transport
2222/// silently misses at the eBPF data plane's per-tuple dispatch. Peer to
2223/// the [`GATEWAY_API_PROTOCOL_HTTP`] +
2224/// [`GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] re-exports on the sibling
2225/// canonical-Gateway-API-v1-OpenAPI-schema-enum-value surface — extends
2226/// the Gateway-API-v1-OpenAPI-schema-enum-value re-export pair onto the
2227/// sibling K8s-core-`Protocol`-OpenAPI-schema-enum-value axis the same
2228/// `cilium_network_policies` renderer's intra-mesh L4-tuple-gating
2229/// contract carries under the shared `CiliumNetworkPolicy` body.
2230pub use caixa_core::KUBE_PROTOCOL_TCP;
2231
2232/// Canonical K8s Gateway API `HTTPRoute` per-rule request-timeout-policy
2233/// body-axis key. Re-export of the canonical
2234/// [`caixa_core::GATEWAY_API_KEY_TIMEOUTS`] so the per-rule request-
2235/// timeout-policy field name lives in exactly one place across every
2236/// caixa renderer — this crate's one production emitter site
2237/// (`gateway_routes`'s per-`HTTPRoute` per-rule
2238/// `spec.rules[].timeouts` insert the Aplicacao's typed
2239/// `:politicas :timeout` overlay lands under, the sub-shape the
2240/// Gateway API v1 CRD schema pins as `HTTPRouteTimeouts` and whose
2241/// `request` scalar the Gateway-API-implementation-side per-rule
2242/// request-dispatch loop compares each accepted request's wall-clock
2243/// elapsed time against before cancelling the in-flight backend call)
2244/// and this crate's eight test-side per-rule timeout-policy traversal
2245/// sites (the `httproute_carries_politicas_timeout_on_every_rule` /
2246/// `httproute_omits_timeouts_when_politicas_timeout_unset` /
2247/// `httproute_timeout_renders_every_rule_independently` /
2248/// `httproute_timeout_uses_canonical_kube_duration_format` /
2249/// `httproute_timeout_renders_minute_window_canonically` /
2250/// `httproute_rule_keys_pin_overlay_position` /
2251/// `httproute_timeouts_and_retry_coexist_independently`
2252/// pins asserting the overlay's presence, absence, canonical-duration-
2253/// format contract, per-rule fan-out under multi-`:entrada :paths`,
2254/// and independent-axis coexistence with the sibling `retry` per-
2255/// rule retry-policy axis) now consult the same `&'static str` as the
2256/// peer caixa-core-side const definition.
2257///
2258/// The prior inline `"timeouts"` literals at the one production
2259/// emitter site + eight test-side retrieval sites in this crate would
2260/// have let a typo on any one site (e.g. `"timeout"` (singular) /
2261/// `"timeoutPolicy"` / `"deadlines"`) silently miss the per-rule
2262/// request-timeout policy or emit a malformed `HTTPRoute` whose per-
2263/// rule request-timeout-policy field the apiserver-side Gateway API
2264/// CRD schema validator drops as unrecognized at apply time — the
2265/// Gateway API implementation's per-rule request-dispatch loop would
2266/// silently no-op the per-rule wall-clock deadline (the "no infinite
2267/// blocking" guarantee MESH-COMPOSITION.md §V mandates for every
2268/// rendered per-`:politicas` mesh-composition edge silently regresses
2269/// to the pre-overlay unbounded-request semantic, and every external
2270/// `:entrada` flow the route was authored to bound by the typed
2271/// `:politicas :timeout` slot runs to whatever backend deadline the
2272/// resolved backend's downstream infrastructure picks with no field
2273/// naming the per-rule-timeout-policy-drift root cause), and the test-
2274/// side pins' `.expect("rule must carry timeouts mapping when
2275/// :politicas :timeout is set")` panic-message tags would fire against
2276/// the presence-shape message rather than naming the true per-rule-
2277/// timeout-policy-key drift, the `.get("timeouts").and_then(|t|
2278/// t.get("request"))` navigators would silently unwrap to `None`
2279/// under the drifted retrieval. The lift routes every per-rule
2280/// timeout-policy-axis retrieval + emission through the same
2281/// `&'static str` so drift between any two sites becomes a single-
2282/// edit fix at the caixa-core const definition.
2283///
2284/// Same shape as the [`GATEWAY_API_KEY_HOSTNAMES`] /
2285/// [`GATEWAY_API_KEY_HOSTNAME`] / [`GATEWAY_API_KEY_LISTENERS`] /
2286/// [`GATEWAY_API_KEY_PARENT_REFS`] / [`GATEWAY_API_KEY_BACKEND_REFS`]
2287/// re-exports on the sibling per-Gateway-API-CRD-body-axis surface —
2288/// extends the per-Gateway-API-`HTTPRoute` per-rule body-axis re-export
2289/// set (`backendRefs`) onto the load-bearing per-rule request-timeout-
2290/// policy axis every downstream Gateway-API-implementation-side per-
2291/// rule request-dispatch loop keys off before it can commit to a per-
2292/// request wall-clock deadline. Peer to the sibling load-bearing K8s-
2293/// CR-schema-axis re-exports every downstream apiserver-side CRD-
2294/// schema-validator navigates the same per-rule request-timeout-policy
2295/// axis on (the gateway-class-controller's per-HTTPRoute per-rule
2296/// request-dispatch pass under `spec.rules[].timeouts.request`).
2297pub use caixa_core::GATEWAY_API_KEY_TIMEOUTS;
2298
2299/// Canonical K8s Gateway API `HTTPRoute` per-rule retry-policy body-axis
2300/// key. Re-export of the canonical [`caixa_core::GATEWAY_API_KEY_RETRY`]
2301/// so the per-rule retry-policy field name lives in exactly one place
2302/// across every caixa renderer — this crate's one production emitter
2303/// site (`gateway_routes`'s per-`HTTPRoute` per-rule
2304/// `spec.rules[].retry` insert the Aplicacao's typed `:politicas
2305/// :retries` overlay lands under, the sub-shape the Gateway API v1 CRD
2306/// schema pins as `HTTPRouteRetry` and whose `attempts` scalar the
2307/// Gateway-API-implementation-side per-rule request-dispatch loop
2308/// compares each failed attempt count against before giving up on the
2309/// in-flight backend call) and this crate's eight test-side per-rule
2310/// retry-policy traversal sites (the
2311/// `httproute_rule_keys_pin_overlay_position` rule-level top-key-set
2312/// pin, the `httproute_carries_politicas_retries_on_every_rule`
2313/// presence pin, the `httproute_omits_retry_when_politicas_retries_unset`
2314/// absence pin, the `httproute_retry_renders_every_rule_independently`
2315/// per-rule fan-out pin under multi-`:entrada :paths`, the
2316/// `httproute_retry_round_trips_typed_attempt_count` typed-`u32`-round-
2317/// trip pin, the `httproute_retry_attempts_serialized_as_yaml_number`
2318/// YAML integer-scalar-kind pin, and two
2319/// `httproute_timeouts_and_retry_coexist_independently` presence-only +
2320/// absence-only pins pinning independent-axis coexistence with the
2321/// sibling `timeouts` per-rule request-timeout-policy axis) now consult
2322/// the same `&'static str` as the peer caixa-core-side const definition.
2323///
2324/// The prior inline `"retry"` literals at the one production emitter
2325/// site + eight test-side retrieval sites in this crate would have let a
2326/// typo on any one site (e.g. `"retries"` (plural) / `"retryPolicy"` /
2327/// `"budget"`) silently miss the per-rule retry policy or emit a
2328/// malformed `HTTPRoute` whose per-rule retry-policy field the
2329/// apiserver-side Gateway API CRD schema validator drops as unrecognized
2330/// at apply time — the Gateway API implementation's per-rule request-
2331/// dispatch loop would silently no-op the per-rule retry budget (the
2332/// "no infinite retrying without bound" guarantee MESH-COMPOSITION.md §V
2333/// mandates for every rendered per-`:politicas` mesh-composition edge
2334/// silently regresses to the pre-overlay unbounded-retry semantic, and
2335/// every external `:entrada` flow the route was authored to cap by the
2336/// typed `:politicas :retries` slot runs to whatever retry policy the
2337/// resolved backend's downstream infrastructure picks with no field
2338/// naming the per-rule-retry-policy-drift root cause), and the test-
2339/// side pins' `.expect("rule must carry retry mapping when :politicas
2340/// :retries is set")` panic-message tags would fire against the
2341/// presence-shape message rather than naming the true per-rule-retry-
2342/// policy-key drift, the `.get("retry").and_then(|r| r.get("attempts"))`
2343/// navigators would silently unwrap to `None` under the drifted
2344/// retrieval. The lift routes every per-rule retry-policy-axis
2345/// retrieval + emission through the same `&'static str` so drift
2346/// between any two sites becomes a single-edit fix at the caixa-core
2347/// const definition.
2348///
2349/// Same shape as the [`GATEWAY_API_KEY_TIMEOUTS`] /
2350/// [`GATEWAY_API_KEY_HOSTNAMES`] / [`GATEWAY_API_KEY_HOSTNAME`] /
2351/// [`GATEWAY_API_KEY_LISTENERS`] / [`GATEWAY_API_KEY_PARENT_REFS`] /
2352/// [`GATEWAY_API_KEY_BACKEND_REFS`] re-exports on the sibling per-
2353/// Gateway-API-CRD-body-axis surface — closes the per-Gateway-API-
2354/// `HTTPRoute`-per-rule `:politicas` overlay axis re-export pair
2355/// (`timeouts` for `:politicas :timeout`, `retry` for `:politicas
2356/// :retries`) both MESH-COMPOSITION.md §V "no infinite blocking / no
2357/// infinite retrying" guarantees rest on. Peer to the sibling load-
2358/// bearing K8s-CR-schema-axis re-exports every downstream apiserver-
2359/// side CRD-schema-validator navigates the same per-rule retry-policy
2360/// axis on (the gateway-class-controller's per-HTTPRoute per-rule
2361/// request-dispatch pass under `spec.rules[].retry.attempts`).
2362pub use caixa_core::GATEWAY_API_KEY_RETRY;
2363
2364/// Canonical K8s Gateway API `HTTPRoute` per-rule retry-policy
2365/// `attempts` leaf scalar-key. Re-export of the canonical
2366/// [`caixa_core::GATEWAY_API_KEY_ATTEMPTS`] so the per-rule retry-
2367/// attempts leaf key lives in exactly one place across every caixa
2368/// renderer — this crate's one production emitter site
2369/// (`gateway_routes`'s per-`HTTPRoute` per-rule
2370/// `single_field_overlay(spec.politicas.retries, …)` call that seeds
2371/// the typed `u32` attempt count into the sibling
2372/// [`GATEWAY_API_KEY_RETRY`] container axis under
2373/// `spec.rules[].retry.attempts`, the leaf the Gateway API v1 CRD
2374/// schema pins as `HTTPRouteRetry.attempts` and whose scalar value
2375/// the Gateway-API-implementation-side per-rule request-dispatch
2376/// loop compares each failed backend attempt count against before
2377/// giving up on the in-flight backend call) and this crate's five
2378/// test-side per-rule retry-attempts traversal sites (the
2379/// `httproute_carries_politicas_retries_on_every_rule` typed-`u64`-
2380/// value pin, the `httproute_retry_renders_every_rule_independently`
2381/// per-rule fan-out attempt-count pin under multi-`:entrada :paths`,
2382/// the `httproute_retry_round_trips_typed_attempt_count` typed-`u32`-
2383/// round-trip pin, the `httproute_retry_attempts_serialized_as_yaml_number`
2384/// YAML integer-scalar-kind pin, and the retries-only arm of
2385/// `httproute_timeouts_and_retry_coexist_independently` pinning the
2386/// leaf attempt count survives when only the sibling `:retries` slot
2387/// is set) now consult the same `&'static str` as the peer caixa-core-
2388/// side const definition.
2389///
2390/// The prior inline `"attempts"` literals at the one production
2391/// emitter site + five test-side retrieval sites in this crate would
2392/// have let a typo on any one site (e.g. `"attempt"` (singular) /
2393/// `"count"` / `"tries"` / `"maxAttempts"`) silently drop the per-rule
2394/// retry attempt count or emit a malformed `HTTPRoute` whose per-rule
2395/// retry-attempts leaf the apiserver-side Gateway API CRD schema
2396/// validator drops as unrecognized at apply time — the Gateway API
2397/// implementation's per-rule request-dispatch loop would silently
2398/// parse the retry sub-shape as an empty `HTTPRouteRetry` with the
2399/// typed `u32` attempt count discarded (the "no infinite retrying
2400/// without bound" guarantee MESH-COMPOSITION.md §V mandates for
2401/// every rendered per-`:politicas` mesh-composition edge silently
2402/// regresses to the pre-overlay unbounded-retry semantic, and every
2403/// external `:entrada` flow the route was authored to cap by the
2404/// typed `:politicas :retries` slot runs to whatever retry policy
2405/// the resolved backend's downstream infrastructure picks with no
2406/// field naming the per-rule-retry-attempts-leaf-key-drift root
2407/// cause), and the test-side navigators' `.and_then(|r|
2408/// r.get("attempts"))` chains would silently unwrap to `None` under
2409/// the drifted retrieval. The lift routes every per-rule retry-
2410/// attempts-leaf retrieval + emission through the same `&'static str`
2411/// so drift between any two sites becomes a single-edit fix at the
2412/// caixa-core const definition.
2413///
2414/// Same shape as the [`GATEWAY_API_KEY_RETRY`] /
2415/// [`GATEWAY_API_KEY_TIMEOUTS`] / [`GATEWAY_API_KEY_HOSTNAMES`] /
2416/// [`GATEWAY_API_KEY_HOSTNAME`] / [`GATEWAY_API_KEY_LISTENERS`] /
2417/// [`GATEWAY_API_KEY_PARENT_REFS`] / [`GATEWAY_API_KEY_BACKEND_REFS`]
2418/// re-exports on the sibling per-Gateway-API-CRD-body-axis surface —
2419/// closes the parent-leaf axis pair (`retry` container + `attempts`
2420/// leaf) the K8s Gateway API v1 `HTTPRouteRetry` sub-shape pins under
2421/// `HTTPRoute.spec.rules[].retry.attempts`, one nesting level deeper
2422/// than the parent per-rule retry-policy container axis (`retry`).
2423/// Peer to the sibling load-bearing K8s-CR-schema-axis re-exports
2424/// every downstream apiserver-side CRD-schema-validator navigates the
2425/// same per-rule retry-attempts leaf on (the gateway-class-
2426/// controller's per-HTTPRoute per-rule request-dispatch pass under
2427/// `spec.rules[].retry.attempts`).
2428pub use caixa_core::GATEWAY_API_KEY_ATTEMPTS;
2429
2430/// Canonical K8s Gateway API `HTTPRoute` per-rule request-timeout-policy
2431/// `request` leaf scalar-key. Re-export of the canonical
2432/// [`caixa_core::GATEWAY_API_KEY_REQUEST`] so the per-rule request-
2433/// deadline leaf key lives in exactly one place across every caixa
2434/// renderer — this crate's one production emitter site
2435/// (`gateway_routes`'s per-`HTTPRoute` per-rule
2436/// `single_field_overlay(spec.politicas.timeout, …)` call that seeds
2437/// the typed `Duration` request-deadline string into the sibling
2438/// [`GATEWAY_API_KEY_TIMEOUTS`] container axis under
2439/// `spec.rules[].timeouts.request`, the leaf the Gateway API v1 CRD
2440/// schema pins as `HTTPRouteTimeouts.request` and whose scalar value
2441/// the Gateway-API-implementation-side per-rule request-dispatch loop
2442/// commits to as the per-request wall-clock deadline every inbound
2443/// request is bounded against before the resolved backend even sees
2444/// the call) and this crate's five test-side per-rule request-
2445/// deadline traversal sites (the
2446/// `httproute_carries_politicas_timeout_on_every_rule` typed-`&str`-
2447/// value pin, the `httproute_timeout_renders_every_rule_independently`
2448/// per-rule fan-out request-deadline pin under multi-`:entrada :paths`,
2449/// the `httproute_timeout_uses_canonical_kube_duration_format` typed-
2450/// `Duration`-round-trip pin, the
2451/// `httproute_timeout_renders_minute_window_canonically` canonical-
2452/// minute-form pin, and the timeout-only arm of
2453/// `httproute_timeouts_and_retry_coexist_independently` pinning the
2454/// leaf request-deadline survives when only the sibling `:timeout`
2455/// slot is set) now consult the same `&'static str` as the peer
2456/// caixa-core-side const definition.
2457///
2458/// The prior inline `"request"` literals at the one production emitter
2459/// site + five test-side retrieval sites in this crate would have let a
2460/// typo on any one site (e.g. `"deadline"` / `"requestTimeout"` /
2461/// `"timeout"` / `"upstreamRequest"`) silently drop the per-rule
2462/// request deadline or emit a malformed `HTTPRoute` whose per-rule
2463/// request-deadline leaf the apiserver-side Gateway API CRD schema
2464/// validator drops as unrecognized at apply time — the Gateway API
2465/// implementation's per-rule request-dispatch loop would silently parse
2466/// the timeouts sub-shape as an empty `HTTPRouteTimeouts` with the
2467/// typed `Duration` request-deadline discarded (the "no infinite
2468/// blocking" guarantee MESH-COMPOSITION.md §V mandates for every
2469/// rendered per-`:politicas` mesh-composition edge silently regresses
2470/// to the pre-overlay unbounded-blocking semantic, and every external
2471/// `:entrada` flow the route was authored to cap by the typed
2472/// `:politicas :timeout` slot runs to whatever request-deadline the
2473/// resolved backend's downstream infrastructure picks with no field
2474/// naming the per-rule-request-deadline-leaf-key-drift root cause),
2475/// and the test-side navigators' `.and_then(|t| t.get("request"))`
2476/// chains would silently unwrap to `None` under the drifted retrieval.
2477/// The lift routes every per-rule request-deadline-leaf retrieval +
2478/// emission through the same `&'static str` so drift between any two
2479/// sites becomes a single-edit fix at the caixa-core const definition.
2480///
2481/// Same shape as the [`GATEWAY_API_KEY_ATTEMPTS`] /
2482/// [`GATEWAY_API_KEY_RETRY`] / [`GATEWAY_API_KEY_TIMEOUTS`] /
2483/// [`GATEWAY_API_KEY_HOSTNAMES`] / [`GATEWAY_API_KEY_HOSTNAME`] /
2484/// [`GATEWAY_API_KEY_LISTENERS`] / [`GATEWAY_API_KEY_PARENT_REFS`] /
2485/// [`GATEWAY_API_KEY_BACKEND_REFS`] re-exports on the sibling per-
2486/// Gateway-API-CRD-body-axis surface — closes the second parent-leaf
2487/// axis pair (`timeouts` container + `request` leaf) the K8s Gateway
2488/// API v1 `HTTPRouteTimeouts` sub-shape pins under
2489/// `HTTPRoute.spec.rules[].timeouts.request`, sibling to the parent-
2490/// leaf pair (`retry` container + `attempts` leaf) closed in the
2491/// immediately-preceding [`GATEWAY_API_KEY_ATTEMPTS`] lift (e2e136b).
2492/// Both MESH-COMPOSITION.md §V "no infinite blocking / no infinite
2493/// retrying" guarantees now rest on typed lifts at both container-axis
2494/// and leaf-scalar-axis nesting levels. Peer to the sibling load-
2495/// bearing K8s-CR-schema-axis re-exports every downstream apiserver-
2496/// side CRD-schema-validator navigates the same per-rule request-
2497/// deadline leaf on (the gateway-class-controller's per-HTTPRoute
2498/// per-rule request-dispatch pass under
2499/// `spec.rules[].timeouts.request`).
2500pub use caixa_core::GATEWAY_API_KEY_REQUEST;
2501
2502// ── Cilium NetworkPolicy emission ──────────────────────────────────────
2503
2504/// Render one [`CiliumNetworkPolicy`-shaped][cnp] YAML per distinct
2505/// `(:de, :para)` pair across `:contratos`. The policy whitelists the
2506/// `:de → :para` flow at L4 (every contract); HTTP contracts add L7
2507/// rules (path) keyed by the `:wit` shape.
2508///
2509/// A CiliumNetworkPolicy's identity is its destination (`endpointSelector`)
2510/// plus its admitted source (`fromEndpoints`), so the `(:de, :para)`
2511/// pair is the policy's `metadata.name` axis — `<aplicacao>-<de>-to-<para>`.
2512/// [`AplicacaoSpec::validate`] deliberately permits multiple typed edges
2513/// between the same ordered pair (cart→catalog at `/products` *and*
2514/// `/search`, an HTTP edge alongside a NATS edge — distinct identity keys
2515/// via differing payloads, see `caixa_core::aplicacao` validate), so the
2516/// renderer fans those in: each edge in a `(:de, :para)` group contributes
2517/// one `ingress[0].toPorts[]` entry to the *single* policy for that pair.
2518/// Emitting one policy per raw contrato instead would name two objects
2519/// `<aplicacao>-<de>-to-<para>` identically and collide at `kubectl apply`
2520/// time, far from the source caixa.lisp.
2521///
2522/// Every emitted policy is identity-based — `endpointSelector` matches
2523/// pleme labels (`pleme.pleme.io/program: <:para>`) injected by the
2524/// fleet-programs aggregator, and `fromEndpoints` requires the same
2525/// label on the source. Identity = caixa nome + Aplicacao annotation
2526/// (no IP-based reasoning required).
2527///
2528/// V0 emits a typed YAML mapping; the operator (Cilium control plane)
2529/// validates against the official schema.
2530///
2531/// [cnp]: https://docs.cilium.io/en/stable/security/policy/index.html
2532pub fn cilium_network_policies(caixa: &Caixa) -> Result<Vec<serde_yaml::Value>, Error> {
2533 let spec = typed_view(caixa)?;
2534 let namespace = DEFAULT_NAMESPACE; // operators scope per-cluster manifests
2535 // `:politicas :mtls-required` overlay — when the typed slot
2536 // carries a value it surfaces as a per-ingress-rule
2537 // `authentication: { mode: <mode> }` block on every emitted
2538 // CiliumNetworkPolicy, the canonical Cilium per-rule mutual-
2539 // authentication shape:
2540 // https://docs.cilium.io/en/stable/network/servicemesh/mutual-authentication/
2541 //
2542 // Same trajectory as the `:timeout`/`:retries` overlays in
2543 // [`gateway_routes`]: until this landed the typed
2544 // `:mtls-required` slot was inert past
2545 // [`AplicacaoSpec::validate`] — the slot round-tripped through
2546 // serde and read non-empty for `MeshPolicy::is_empty`, but no
2547 // caixa-side renderer surfaced it as a cluster artifact. Wiring
2548 // it through the CiliumNetworkPolicy renderer turns the
2549 // MESH-COMPOSITION §V CSE invariant ("every Aplicacao declares
2550 // `:politicas :mtls-required t` — no plaintext intra-mesh") from
2551 // a validate-time gate into a runtime-enforced contract: Cilium's
2552 // identity-aware data plane refuses every ingress edge that
2553 // doesn't carry a peer SPIFFE-identity-bound mTLS handshake, so
2554 // a same-namespace pod that doesn't satisfy the typed identity
2555 // contract can't satisfy the rule even from inside the cluster.
2556 //
2557 // The author-facing `:mtls-required` slot is a `Option<bool>`
2558 // tristate (Some(true) | Some(false) | None) — the explicit
2559 // Some(false) opt-out reads non-empty for `MeshPolicy::is_empty`
2560 // (the author *named* the axis, the renderer needs to honor that
2561 // vs. fall back to the cluster default). The two non-None arms
2562 // map to the two valid Cilium authentication modes:
2563 // - Some(true) → `mode: "required"` (mTLS handshake mandatory)
2564 // - Some(false) → `mode: "disabled"` (mTLS handshake skipped —
2565 // explicit opt-out, e.g. for a debug edge)
2566 // - None → omit the block entirely (cluster default
2567 // applies — typically "disabled" cluster-wide).
2568 // Single-axis overlay built once per renderer call and cloned into
2569 // each ingress rule. Same lifted-typed-primitive shape the
2570 // gateway_routes overlays (timeout, retry) consume — see
2571 // [`caixa_core::render::single_field_overlay`].
2572 // Route the `:politicas :mtls-required` mTLS-enforcement-toggle
2573 // read through the typed [`caixa_core::MeshPolicy::mtls_required`]
2574 // accessor rather than the raw `spec.politicas.mtls_required` field
2575 // access — one of the two open-coded field-access sites on the
2576 // per-`:politicas` `:mtls-required` axis the accessor lift now
2577 // owns (peer of the [`caixa_core::MeshPolicy::is_empty`] arm that
2578 // already routes through the same dispatch). The accessor returns
2579 // `Option<bool>` by copy (bool is `Copy`), so
2580 // [`single_field_overlay`]'s first parameter accepts the narrower
2581 // owned Option verbatim without a re-allocation or a `.clone()`.
2582 // Route the outer `:politicas` composite-reference read through
2583 // the lifted [`caixa_core::AplicacaoSpec::politicas`] outer accessor
2584 // rather than the raw `spec.politicas` field access — the outer
2585 // composite-reference axis now dispatches on the substrate
2586 // primitive, and the per-axis `mtls_required()` inner-accessor
2587 // dispatch chains onto the returned `&MeshPolicy` reference verbatim.
2588 let mtls_overlay = single_field_overlay(
2589 spec.politicas().mtls_required(),
2590 CILIUM_KEY_MODE,
2591 |required| serde_yaml::Value::String(cilium_auth_mode(required).into()),
2592 );
2593 // Fan typed edges into per-`(:de, :para)` groups — the policy
2594 // identity axis. A `BTreeMap` keyed by the pair gives deterministic
2595 // policy order independent of `:contratos` declaration order
2596 // (THEORY.md §V.2.7 render determinism), and collapses the
2597 // validate-permitted "same caller-callee pair, different payload"
2598 // contratos (cart→catalog at `/products` and `/search`) onto the
2599 // single CiliumNetworkPolicy whose `metadata.name` they'd otherwise
2600 // collide on. Insertion preserves source order within each group, so
2601 // the per-edge `toPorts[]` entries appear in the author's declared
2602 // order.
2603 let mut groups: BTreeMap<(&str, &str), Vec<&WitContract>> = BTreeMap::new();
2604 for c in spec.contratos() {
2605 groups
2606 .entry((c.source(), c.destination()))
2607 .or_default()
2608 .push(c);
2609 }
2610
2611 let mut out = Vec::with_capacity(groups.len());
2612 for ((de, para), edges) in &groups {
2613 // Policy's own labels — `aplicacao` (which graph) and
2614 // `contrato` (which typed edge pair). Keys come from
2615 // caixa_core::render so a future label-namespace rebrand is a
2616 // one-line edit, not a search-and-replace across renderers.
2617 // The per-`(:de, :para)` [`LABEL_CONTRATO`] value + the
2618 // per-CNP `metadata.name` now compose on the lifted
2619 // [`contrato_edge_label`] / [`cilium_network_policy_name`]
2620 // helpers (which route through the canonical
2621 // [`caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR`] `"-to-"`
2622 // byte-string) so a future edge-encoding rebrand lands at one
2623 // const-edit and both writer sites pick up the new encoding
2624 // by construction. Prior to this lift the two sites carried
2625 // verbatim inline `format!("{de}-to-{para}")` +
2626 // `format!("{}-{}-to-{}", caixa.nome, de, para)` with no
2627 // compile-time link between them; a rebrand on either half
2628 // would have silently split the CNP `metadata.name` from its
2629 // own `metadata.labels.pleme.pleme.io/contrato` value,
2630 // orphaning every operator-side `kubectl get cnp -l
2631 // pleme.pleme.io/contrato=<de>-to-<para>` grep-by-label
2632 // query at apply time far from the source caixa.lisp.
2633 let mut labels = BTreeMap::new();
2634 labels.insert(LABEL_APLICACAO, caixa.nome().to_string());
2635 labels.insert(LABEL_CONTRATO, contrato_edge_label(de, para));
2636 // The apiVersion + kind + metadata.{name, namespace, labels}
2637 // skeleton comes from caixa_core::render::kube_resource_skeleton
2638 // — same lift as pleme_program_*_selector applied to the K8s-
2639 // resource axis. Caller adds spec below. The Cilium-CRD-group/
2640 // version string threads through the lifted
2641 // [`CILIUM_API_VERSION`] re-export so a future Cilium-CRD bump
2642 // lands on the canonical [`caixa_core::CILIUM_API_VERSION`]
2643 // declaration, not at this call site. The kind axis of the
2644 // `(apiVersion, kind)` CRD-lookup tuple now threads through the
2645 // matching [`CILIUM_KIND_NETWORK_POLICY`] re-export so a future
2646 // Cilium-CRD kind rebrand lands on the canonical
2647 // [`caixa_core::CILIUM_KIND_NETWORK_POLICY`] declaration too —
2648 // both halves of the tuple move as a unit through one lifted
2649 // const each, no per-renderer drift surface. The CNP
2650 // `metadata.name` axis now threads through the lifted
2651 // [`cilium_network_policy_name`] composer (peer with the
2652 // [`LABEL_CONTRATO`] value composer above) so the
2653 // per-CNP identity pair — `(metadata.labels.pleme.pleme.io/
2654 // contrato, metadata.name)` — shares one canonical
2655 // edge-encoding source of truth
2656 // ([`caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR`]).
2657 // The per-CNP `metadata.name` identity byte-string derives from
2658 // the parent-Caixa's `:nome` verbatim through the substrate-
2659 // canonical [`caixa_core::cilium_network_policy_name`] composer.
2660 // Routing the aplicacao-name arg through the typed
2661 // [`caixa_core::Caixa::nome`] accessor (`caixa.nome()`) rather
2662 // than the raw `&caixa.nome` `&String`-borrow of the underlying
2663 // field extends the "one typed dispatch on the substrate
2664 // primitive, thin projections at each consumer" discipline the
2665 // e6b7d97 [`caixa_core::Caixa::nome`] accessor lift opened onto
2666 // this per-CNP `metadata.name` axis — peer of the sibling 22461ef
2667 // caixa-helm non-`.clone()` raw-field-access converge on the
2668 // per-`lareira-<nome>` chart-directory identity composer.
2669 let mut policy = kube_resource_skeleton(
2670 CILIUM_API_VERSION,
2671 CILIUM_KIND_NETWORK_POLICY,
2672 &cilium_network_policy_name(caixa.nome(), de, para),
2673 namespace,
2674 labels,
2675 );
2676
2677 // spec.endpointSelector — match the destination Servico's
2678 // identity. Single-axis (program-only) selector; see
2679 // caixa_core::render::pleme_program_selector for the deliberate
2680 // intent / safety tradeoff vs. the in-aplicacao variant. The
2681 // `{matchLabels: <selector>}` envelope comes from
2682 // caixa_core::render::label_selector — same lift as
2683 // yaml_string_mapping / kube_resource_skeleton applied to the
2684 // K8s LabelSelector axis.
2685 let endpoint_selector = label_selector(pleme_program_selector(para));
2686
2687 // ingress[0]: from the source Servico, scoped to this
2688 // Aplicacao (so a same-named program in a different Aplicacao
2689 // can't satisfy the rule). Two-axis selector via the
2690 // canonical helper — call-site reads as intent, not as five
2691 // hand-written insert() calls. Wrapped in label_selector so
2692 // the `matchLabels` envelope is the typed primitive's
2693 // responsibility, not this site's.
2694 // The per-CNP ingress[0]-from-endpoint two-axis selector's
2695 // aplicacao-scope arg (the `LABEL_APLICACAO` value the emitted
2696 // selector matches against) reads the parent-Caixa's `:nome`
2697 // through the typed [`caixa_core::Caixa::nome`] accessor rather
2698 // than the raw `&caixa.nome` `&String`-borrow of the underlying
2699 // field — same converge as the peer per-CNP `metadata.name`
2700 // composer above, extended onto the sibling per-CNP ingress
2701 // selector's aplicacao-scope axis so the pair
2702 // `(metadata.name, ingress[0].from[].matchLabels
2703 // .pleme.pleme.io/aplicacao)` shares one typed dispatch on the
2704 // substrate primitive.
2705 let from_endpoint = label_selector(pleme_program_in_aplicacao_selector(de, caixa.nome()));
2706 let mut ingress_rule = serde_yaml::Mapping::new();
2707 ingress_rule.insert_sequence(CILIUM_KEY_FROM_ENDPOINTS, vec![from_endpoint]);
2708
2709 // One `toPorts[]` entry per typed edge in the group — Cilium
2710 // unions the L4/L7 rules across entries, so each edge keeps its
2711 // own L7 shape (an HTTP edge's path stays scoped to the HTTP
2712 // edge; a NATS/store edge stays L4-only) instead of leaking
2713 // across the shared destination port.
2714 let mut to_ports_seq = Vec::with_capacity(edges.len());
2715 for c in edges {
2716 // toPorts — wit-shape-aware. HTTP gets L7 rules; pubsub +
2717 // store get L4-only (Cilium can't introspect those protocols).
2718 let mut to_port = serde_yaml::Mapping::new();
2719 let mut port_entry = serde_yaml::Mapping::new();
2720 // The per-destination Servico TCP port every emitted CNP's
2721 // ingress[].toPorts[].ports[0].port axis reads now routes
2722 // through the canonical [`AplicacaoSpec::port_for_destination`]
2723 // typed dispatch (re-exported through the peer `typed_view`
2724 // path this call reaches through). Prior to this lift the
2725 // "if the typed `:entrada` block names this destination use
2726 // its author-declared `:port`, else fall back to the lifted
2727 // [`DEFAULT_SERVICO_PORT`] substrate-canonical port floor"
2728 // cascade lived inline here — the sole per-Aplicacao L4
2729 // fallback site with no typed method on the substrate
2730 // primitive that named the rule, so a future per-destination
2731 // port axis addition (a per-`:contratos` explicit `:port`
2732 // slot the M4 typed-edge registry adds, a per-`:membros`
2733 // `:port` overlay once heterogeneous per-Servico listener
2734 // ports land, a per-cluster override the operator pins
2735 // through a future `:placement :default-port` slot) would
2736 // have had to be threaded through this inline cascade and
2737 // every future per-Aplicacao renderer's inline copy in
2738 // lockstep or one consumer would silently disagree on which
2739 // port a given destination Servico's ingress lands at.
2740 // Lifting the resolution rule to a typed method on
2741 // `AplicacaoSpec` — peer with the sibling
2742 // [`AplicacaoSpec::validate`] / `AplicacaoSpec::detect_sync_cycles`
2743 // typed dispatches — means the M4
2744 // `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's
2745 // per-CNP L4 port resolver, the future per-edge policy
2746 // resolver's per-destination probe axis, and every
2747 // downstream test-fixture navigator asserting the L4
2748 // port floor read from one place.
2749 let port = spec.port_for_destination(c.destination());
2750 port_entry.insert_string(KUBE_KEY_PORT, port.to_string());
2751 port_entry.insert_string(KUBE_KEY_PROTOCOL, KUBE_PROTOCOL_TCP);
2752 to_port.insert_singleton_mapping_sequence(CILIUM_KEY_PORTS, port_entry);
2753
2754 // L7 introspection only fires for HTTP-shaped contracts; the
2755 // typed view (validated upstream by AplicacaoSpec::validate)
2756 // makes the "wit world ↔ payload field" link impossible to
2757 // get wrong silently. PubSub / Store / Capability edges stay
2758 // L4-only — Cilium can't introspect those protocols.
2759 if let WitTarget::Http { endpoint } = c.target().expect("validated by typed_view") {
2760 let mut http_rule = serde_yaml::Mapping::new();
2761 http_rule.insert_string(CILIUM_KEY_PATH, endpoint.to_string());
2762 let mut rules = serde_yaml::Mapping::new();
2763 rules.insert_singleton_mapping_sequence(CILIUM_KEY_HTTP, http_rule);
2764 to_port.insert_mapping(KUBE_KEY_RULES, rules);
2765 }
2766 to_ports_seq.push_mapping(to_port);
2767 }
2768 ingress_rule.insert_sequence(CILIUM_KEY_TO_PORTS, to_ports_seq);
2769 ingress_rule.insert_str_key_if_some(CILIUM_KEY_AUTHENTICATION, mtls_overlay.as_ref());
2770
2771 let mut policy_spec = serde_yaml::Mapping::new();
2772 policy_spec.insert_str_key(CILIUM_KEY_ENDPOINT_SELECTOR, endpoint_selector);
2773 policy_spec.insert_singleton_mapping_sequence(CILIUM_KEY_INGRESS, ingress_rule);
2774 policy.insert_mapping(KUBE_KEY_SPEC, policy_spec);
2775
2776 out.push_mapping(policy);
2777 }
2778 Ok(out)
2779}
2780
2781// ── K8s Gateway API emission ───────────────────────────────────────────
2782
2783/// Render the Gateway + HTTPRoute pair for `:entrada`, when set.
2784/// Returns an empty Vec when the Aplicacao has no external entry
2785/// point (internal-only meshes).
2786///
2787/// Output is two YAML documents:
2788///
2789/// - one `gateway.networking.k8s.io/v1 Gateway` named after the
2790/// Aplicacao, listening on the Aplicacao's host
2791/// - one `gateway.networking.k8s.io/v1 HTTPRoute` per declared
2792/// `:entrada :paths` entry (or one catch-all when paths is empty),
2793/// pointing at the destination Servico.
2794pub fn gateway_routes(caixa: &Caixa) -> Result<Vec<serde_yaml::Value>, Error> {
2795 let spec = typed_view(caixa)?;
2796 // Route the per-`:entrada` composite-reference read through the
2797 // lifted [`caixa_core::AplicacaoSpec::entrada`] accessor rather
2798 // than the raw `spec.entrada.as_ref()` field access — the
2799 // per-Aplicacao K8s Gateway API v1 Gateway + HTTPRoute emitter's
2800 // early-return partition now keys off the canonical read-side
2801 // surface every per-Aplicacao entrada consumer routes through,
2802 // peer of the sibling per-`:politicas` and per-`:placement`
2803 // outer-composite-reference migrations already routed through
2804 // [`caixa_core::AplicacaoSpec::politicas`] and
2805 // [`caixa_core::AplicacaoSpec::placement`].
2806 let entrada = match spec.entrada() {
2807 Some(e) => e,
2808 None => return Ok(Vec::new()),
2809 };
2810 let namespace = DEFAULT_NAMESPACE;
2811
2812 // Gateway — apiVersion + kind + metadata.{name, namespace} skeleton
2813 // comes from caixa_core::render::kube_resource_skeleton; caller adds
2814 // spec below. No metadata.labels on Gateway today (the gateway is
2815 // identified by its own name + namespace; per-Aplicacao label
2816 // grouping happens at the HTTPRoute / route-attached-policy axis).
2817 // The Gateway-API-CRD-group/version string threads through the
2818 // lifted [`GATEWAY_API_API_VERSION`] re-export so a future
2819 // Gateway-API bump lands on the canonical
2820 // [`caixa_core::GATEWAY_API_API_VERSION`] declaration, not at this
2821 // call site. The kind axis of the `(apiVersion, kind)` CRD-lookup
2822 // tuple now threads through the matching [`GATEWAY_API_KIND_GATEWAY`]
2823 // re-export so a future Gateway-API kind rebrand lands on the
2824 // canonical [`caixa_core::GATEWAY_API_KIND_GATEWAY`] declaration too
2825 // — both halves of the tuple move as a unit through one lifted const
2826 // each, no per-renderer drift surface.
2827 // The Gateway `metadata.name` identity byte-string derives from the
2828 // parent-Aplicacao Caixa's `:nome` verbatim (Gateway API v1 keys per-
2829 // Gateway resolution off this scalar, and the sibling HTTPRoute
2830 // `spec.parentRefs[0].name` below binds through it). Routing the
2831 // name arg through the typed [`caixa_core::Caixa::nome`] accessor
2832 // (`caixa.nome()`) rather than the raw `&caixa.nome` `&String`-borrow
2833 // of the underlying field pins the pair `(Gateway metadata.name,
2834 // HTTPRoute spec.parentRefs[0].name)` onto one typed dispatch — the
2835 // parentRefs projection already read through [`caixa_core::Caixa::nome`]
2836 // ahead of this converge; this call closes the peer skeleton-name
2837 // arm so both halves of the parent-Aplicacao's Gateway identity
2838 // pair move as a unit on any future accessor extension.
2839 let mut gateway = kube_resource_skeleton(
2840 GATEWAY_API_API_VERSION,
2841 GATEWAY_API_KIND_GATEWAY,
2842 caixa.nome(),
2843 namespace,
2844 BTreeMap::new(),
2845 );
2846 let mut listener = serde_yaml::Mapping::new();
2847 // Per-listener name-discriminator scalar — reads from the lifted
2848 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] `&'static str` const so
2849 // a future substrate-side listener-name migration (`"http"` →
2850 // `"http-v1"` once multi-listener Gateways ship under the HTTPS-by-
2851 // default trajectory the sibling
2852 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] docstring names, an
2853 // operator-pinned override the future `:entrada :listener-name`
2854 // slot promotes) lands at the canonical
2855 // [`caixa_core::GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] declaration,
2856 // not at this call site. Peer with the sibling
2857 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] port-scalar consumer on
2858 // the immediately-following `listener.insert(KUBE_KEY_PORT, …)`
2859 // line — both per-listener substrate-canonical scalar-value axes
2860 // now route through their own lifted typed const, so a future
2861 // rebrand on either axis reaches its consumer by construction.
2862 // Downstream `HTTPRoute.spec.parentRefs[].sectionName` selectors
2863 // that attach to this Gateway's HTTP listener bind by the same
2864 // lifted byte-string, so a listener-name drift can't silently
2865 // orphan the route at attachment time.
2866 listener.insert_string(GATEWAY_API_KEY_NAME, GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME);
2867 // Per-listener HTTP-listener-port scalar — reads from the lifted
2868 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] `u16` const so a future
2869 // substrate-side external-Gateway port migration (`:80` → `:443`
2870 // once cert-manager-issued per-`:entrada :host` certificates land
2871 // and the external listener becomes HTTPS-by-default, matching the
2872 // mTLS-by-default trajectory [`DEFAULT_SERVICO_PORT`]'s docstring
2873 // names) lands at the canonical
2874 // [`caixa_core::GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] declaration,
2875 // not at this call site. Peer with the sibling
2876 // `DEFAULT_SERVICO_PORT` fallback in the `cilium_network_policies`
2877 // per-`(:de, :para)` L4 port resolver — both consumers of a
2878 // K8s-CRD-side `port:` axis now route through their own lifted
2879 // typed `u16` const, so a future rebrand on either axis reaches
2880 // its consumer by construction.
2881 listener.insert_number(KUBE_KEY_PORT, GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT);
2882 listener.insert_string(KUBE_KEY_PROTOCOL, GATEWAY_API_PROTOCOL_HTTP);
2883 // Substrate-canonical per-`:entrada` DNS-hostname singular
2884 // resolver — routes through the lifted
2885 // [`caixa_core::Entrada::hostname`] typed accessor on the
2886 // substrate primitive so the parent-Gateway per-listener
2887 // `hostname:` filter and the peer per-HTTPRoute plural
2888 // `spec.hostnames[]` filter list (see the sibling
2889 // [`caixa_core::Entrada::hostnames`] consumer below in this
2890 // same `gateway_routes` emitter) both key off exactly one
2891 // typed dispatch on the substrate primitive. Every future
2892 // Gateway-API-aware consumer (the M4 `mesh.pleme.io/v1alpha1/
2893 // Aplicacao` CR materializer's per-listener SNI fan-out, a
2894 // future per-cluster `:entrada :alt-hosts` overlay resolver
2895 // the operator pins through a `:placement`-scoped slot,
2896 // every future per-Aplicacao snapshot renderer) reads the
2897 // same typed dispatch, so a rebrand of the singular-plural
2898 // resolution shape lands at exactly one caixa-core edit and
2899 // reaches every consumer by construction. Peer of the
2900 // sibling [`caixa_core::Entrada::resolved_paths`] (1449891)
2901 // path-list resolver on the per-HTTPRoute per-rule path axis.
2902 listener.insert_string(GATEWAY_API_KEY_HOSTNAME, entrada.hostname().to_string());
2903 let mut g_spec = serde_yaml::Mapping::new();
2904 // `spec.gatewayClassName` binds the emitted `Gateway` to the
2905 // substrate's chosen K8s Gateway API controller — the same Cilium
2906 // eBPF-identity data plane the sibling `cilium_network_policies`
2907 // renderer emits `CiliumNetworkPolicy` documents against, closing
2908 // the mesh-composition "one identity layer, one data plane"
2909 // invariant (MESH-COMPOSITION.md §V). The controller-choice value
2910 // threads through the lifted [`DEFAULT_GATEWAY_CLASS_NAME`]
2911 // re-export so a future substrate-side controller migration
2912 // (Cilium → Envoy Gateway / Istio Gateway / any per-edition
2913 // Gateway API v1.x GA controller variant) lands at the canonical
2914 // [`caixa_core::DEFAULT_GATEWAY_CLASS_NAME`] declaration, not at
2915 // this call site — same discipline the [`DEFAULT_NAMESPACE`] /
2916 // [`GATEWAY_API_API_VERSION`] / [`GATEWAY_API_KIND_GATEWAY`]
2917 // lifts apply on the peer canonical-K8s-Gateway-API-axis surfaces.
2918 g_spec.insert_string(
2919 GATEWAY_API_KEY_GATEWAY_CLASS_NAME,
2920 DEFAULT_GATEWAY_CLASS_NAME,
2921 );
2922 g_spec.insert_singleton_mapping_sequence(GATEWAY_API_KEY_LISTENERS, listener);
2923 gateway.insert_mapping(KUBE_KEY_SPEC, g_spec);
2924
2925 // HTTPRoute — all paths route to the entrada.destination() Servico.
2926 // Same skeleton lift as Gateway above; caller adds spec. Both halves
2927 // of the `(apiVersion, kind)` CRD-lookup tuple now thread through
2928 // their matching lifted [`GATEWAY_API_API_VERSION`] +
2929 // [`GATEWAY_API_KIND_HTTP_ROUTE`] re-exports so a future Gateway-API
2930 // rebrand on either axis lands on the canonical
2931 // [`caixa_core::GATEWAY_API_KIND_HTTP_ROUTE`] declaration, not at
2932 // this call site — peer with the sibling Gateway skeleton above on
2933 // the canonical-Gateway-API-CRD-`kind`-discriminator surface. The
2934 // HTTPRoute `metadata.name` axis now threads through the lifted
2935 // [`gateway_api_http_route_name`] composer (peer of the
2936 // [`cilium_network_policy_name`] composer that carries the
2937 // sibling per-`(:de, :para)` CNP name on the shared
2938 // "aplicacao-prefixed sub-identity" discipline) so a future
2939 // per-Aplicacao Gateway API per-CR name-encoding rebrand lands at
2940 // one lifted composer and reaches this call site by construction.
2941 // The destination-Servico discriminator arg now routes through
2942 // the lifted [`caixa_core::Entrada::destination`] typed accessor
2943 // on the substrate primitive so the HTTPRoute `metadata.name`
2944 // discriminator and the peer per-rule `backendRefs[0].name` (see
2945 // the sibling consumer below in this same emitter) both key off
2946 // exactly one typed dispatch — a future extension of the `:entrada`
2947 // slot to a multi-destination author surface (weighted canary
2948 // backends, per-path override, an M4 `mesh.pleme.io/v1alpha1/
2949 // Aplicacao` CR materializer's admission-webhook that promotes the
2950 // scalar to a weighted list) reaches both consumers by construction
2951 // rather than by a coordinated inline-copy rewrite. Prior to this
2952 // lift the site inlined a verbatim `format!("{}-{}", caixa.nome,
2953 // entrada.para)` with no compile-time link to the peer CNP-name
2954 // composer's naming discipline; a rebrand would have had to be
2955 // threaded through this site and the in-file test-side
2956 // `httproute_carries_canonical_kube_skeleton_without_labels`
2957 // probe's `Some("checkout-cart")` byte-shape pin in lockstep or
2958 // the HTTPRoute `metadata.name` would have silently split from the
2959 // operator-side `kubectl get httproute -n tatara-system
2960 // <aplicacao>-<destination>` grep-by-name lookup encoding.
2961 // The HTTPRoute `metadata.name` identity byte-string derives from
2962 // the parent-Aplicacao Caixa's `:nome` verbatim through the
2963 // substrate-canonical [`caixa_core::gateway_api_http_route_name`]
2964 // composer. Routing the aplicacao-name arg through the typed
2965 // [`caixa_core::Caixa::nome`] accessor (`caixa.nome()`) rather than
2966 // the raw `&caixa.nome` `&String`-borrow of the underlying field
2967 // extends the same "one typed dispatch on the substrate primitive"
2968 // discipline onto the HTTPRoute-name axis every operator-side
2969 // `kubectl -n tatara-system get httproute <aplicacao>-<destination>`
2970 // grep-by-name lookup consults — peer of the sibling Gateway
2971 // `metadata.name` converge above and the co-resident CNP
2972 // `metadata.name` composer converge in [`cilium_network_policies`].
2973 let mut route = kube_resource_skeleton(
2974 GATEWAY_API_API_VERSION,
2975 GATEWAY_API_KIND_HTTP_ROUTE,
2976 &gateway_api_http_route_name(caixa.nome(), entrada.destination()),
2977 namespace,
2978 BTreeMap::new(),
2979 );
2980
2981 let mut parent_ref = serde_yaml::Mapping::new();
2982 parent_ref.insert_string(GATEWAY_API_KEY_NAME, caixa.nome().to_string());
2983 // Per-parentRef listener-selector sub-axis — pins the emitted
2984 // `HTTPRoute` to the parent Gateway's sole HTTP listener by name,
2985 // rather than accepting the Gateway API v1 default
2986 // attach-to-every-listener fan-out. Both halves of the substrate's
2987 // canonical per-listener identity pair — the Gateway's
2988 // `spec.listeners[].name` (emitted a few lines above through the
2989 // `listener.insert(GATEWAY_API_KEY_NAME, GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME)`
2990 // call) and the HTTPRoute's `spec.parentRefs[].sectionName` (this
2991 // call) — now thread through the same lifted
2992 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] `&'static str`
2993 // constant, so a substrate-side rebrand of the canonical listener-
2994 // name identifier (`"http" → "http-v1"` on the multi-listener
2995 // HTTPS-by-default trajectory the paired
2996 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] docstring forecasts,
2997 // a per-cluster override the future `:entrada :listener-name`
2998 // slot promotes) reaches both sites by construction.
2999 //
3000 // Until this line landed the emitter omitted the selector
3001 // entirely, silently accepting the Gateway API v1
3002 // attach-to-every-listener default: a future substrate-side
3003 // second listener under the same parent Gateway (the
3004 // cert-manager-issued per-`:entrada :host` HTTPS listener the
3005 // sibling `GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT` docstring
3006 // forecasts) would have silently doubled every route's dispatch
3007 // surface — every external `:entrada` request the route was
3008 // authored to accept on the substrate's canonical HTTP listener
3009 // would have accepted a matching request on the paired HTTPS
3010 // listener too, with the second-listener leak surfacing only in
3011 // per-request access logs (never in `kubectl describe httproute`
3012 // — the implicit fan-out reads as intended per the Gateway API v1
3013 // spec). Peer to the sibling `parent_ref.insert(GATEWAY_API_KEY_NAME,
3014 // …)` call on the same parent-Gateway attachment sub-container —
3015 // both per-parentRef sub-axes now name their target through the
3016 // canonical byte-string sourced from `caixa-core`, so a rebrand on
3017 // either axis reaches this consumer by construction.
3018 parent_ref.insert_string(
3019 GATEWAY_API_KEY_SECTION_NAME,
3020 GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME,
3021 );
3022
3023 // Substrate-canonical per-`:entrada` URL-path resolver — routes
3024 // through the lifted [`caixa_core::Entrada::resolved_paths`] typed
3025 // method on the substrate primitive so the "empty `:entrada :paths`
3026 // → single [`GATEWAY_API_DEFAULT_HTTP_ROUTE_PATH`] catch-all;
3027 // non-empty → each declared path verbatim" cascade lives at one
3028 // typed dispatch on `Entrada` rather than inline here. Every
3029 // future HTTPRoute-aware consumer (the M4 `mesh.pleme.io/v1alpha1/
3030 // Aplicacao` CR materializer's per-rule path-list emit site, a
3031 // future per-cluster `:entrada :default-path` overlay resolver
3032 // the operator pins through a `:placement`-scoped slot, every
3033 // future per-Aplicacao snapshot renderer) reads from the same
3034 // typed dispatch, so a rebrand of the catch-all shape (a
3035 // hypothetical Gateway API v2 `Exact ""` migration, an operator-
3036 // pinned override, a per-controller variant that treats `"/"` as
3037 // a literal prefix rather than the catch-all) lands at exactly
3038 // one caixa-core edit and reaches every consumer by construction.
3039 // Peer of the sibling [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] /
3040 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] lifts on the
3041 // per-Gateway per-listener substrate-canonical scalar-value axes.
3042 let paths: Vec<&str> = entrada.resolved_paths();
3043 // `:politicas :timeout` overlay — when the typed slot carries a
3044 // value it surfaces as a per-rule `timeouts: { request: <K8s
3045 // duration> }` block on every HTTPRoute rule, the canonical
3046 // Gateway API v1.x request-deadline shape:
3047 // https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts
3048 //
3049 // Until this overlay landed the typed `:politicas :timeout` slot
3050 // was inert at the cluster boundary — `AplicacaoSpec::validate`
3051 // refused zero values (PolicyTimeoutZero), but a non-zero timeout
3052 // never reached an emitted artifact. Wiring it through the
3053 // HTTPRoute renderer turns the MESH-COMPOSITION §V CSE invariant
3054 // ("every Aplicacao declares :politicas :timeout — no infinite
3055 // blocking") from a validate-time gate into a runtime-enforced
3056 // contract: the cluster's apiserver-side Gateway API parser will
3057 // refuse a malformed timeouts block, and the data plane (Envoy /
3058 // Cilium L7) will trip the per-call deadline at exactly the
3059 // configured duration.
3060 //
3061 // Duration → string formatting comes from the canonical
3062 // caixa_core::supervisor::duration_codec::render so a `30s`
3063 // typed-slot value renders to the same `"30s"` string K8s
3064 // tooling parses — no per-renderer ad-hoc duration formatting.
3065 let timeout_overlay =
3066 single_field_overlay(spec.politicas().timeout(), GATEWAY_API_KEY_REQUEST, |d| {
3067 serde_yaml::Value::String(caixa_core::supervisor::duration_codec::render(d))
3068 });
3069 // `:politicas :retries` overlay — when the typed slot carries a
3070 // value it surfaces as a per-rule `retry: { attempts: <N> }` block
3071 // on every HTTPRoute rule, the canonical Gateway API v1.2+
3072 // per-rule retry-policy shape:
3073 // https://gateway-api.sigs.k8s.io/api-types/httproute/#retry
3074 //
3075 // Same trajectory as the `:politicas :timeout` overlay above:
3076 // until this landed the typed `:retries` slot was inert past
3077 // [`AplicacaoSpec::validate`] (which refuses zero via
3078 // [`AplicacaoError::PolicyRetriesZero`]) — a non-zero attempt
3079 // count never reached an emitted artifact. Wiring it through the
3080 // HTTPRoute renderer turns the MESH-COMPOSITION §V CSE invariant
3081 // ("no infinite retrying without bound") into a runtime-enforced
3082 // contract: the cluster's data plane (Envoy / Cilium L7) caps
3083 // the retry budget at exactly the typed slot's value, so a
3084 // transient failure can't loop unbounded against a downstream.
3085 //
3086 // The overlay carries `attempts:` only — the typed slot is a
3087 // single-axis `Option<u32>`. Future axes the Gateway API exposes
3088 // (`codes:` for retryable status codes, `backoff:` for the
3089 // backoff window) are future `MeshPolicy` field additions + a
3090 // future `&& self.<axis>.is_none()` arm in
3091 // [`MeshPolicy::is_empty`] + a parallel arm here, not a
3092 // coordinated rewrite of this site.
3093 //
3094 // The retry cap projection routes through the substrate-canonical
3095 // per-`:politicas` [`caixa_core::MeshPolicy::retries`] typed
3096 // accessor (sibling of the peer per-`:politicas`
3097 // [`caixa_core::MeshPolicy::mtls_required`] accessor the CNP
3098 // `mtls_overlay` builder above keys off) — every downstream
3099 // consumer of the per-Aplicacao `:retries` axis reaches for
3100 // exactly one typed dispatch on the substrate primitive rather
3101 // than an open-coded `.retries` field access, so a future
3102 // extension of the axis (a per-`:contratos`-edge override overlay
3103 // the operator pins through a `:contratos :retries` slot the
3104 // MESH-COMPOSITION §III.2 #2 roadmap acknowledges, a per-cluster
3105 // retry-default overlay the M4 CR materializer resolves per-CR,
3106 // a promotion of the plain `u32` attempt-count to a richer
3107 // `{attempts, codes, backoff}` sub-block once the Gateway API
3108 // grows the peer `retry.codes` / `retry.backoff` axes) reaches
3109 // this consumer by construction.
3110 let retry_overlay = single_field_overlay(
3111 spec.politicas().retries(),
3112 GATEWAY_API_KEY_ATTEMPTS,
3113 |attempts| serde_yaml::Value::Number(attempts.into()),
3114 );
3115 let mut rules = Vec::with_capacity(paths.len());
3116 for path in paths {
3117 let mut path_match = serde_yaml::Mapping::new();
3118 path_match.insert_string(KUBE_KEY_TYPE, GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX);
3119 path_match.insert_string(GATEWAY_API_KEY_VALUE, path.to_string());
3120 let mut match_entry = serde_yaml::Mapping::new();
3121 match_entry.insert_mapping(GATEWAY_API_KEY_PATH, path_match);
3122 let mut backend_ref = serde_yaml::Mapping::new();
3123 // Substrate-canonical per-`:entrada` destination-Servico
3124 // scalar — routes through the lifted
3125 // [`caixa_core::Entrada::destination`] typed accessor on the
3126 // substrate primitive so the per-HTTPRoute per-rule
3127 // `backendRefs[0].name` axis and the peer HTTPRoute
3128 // `metadata.name` discriminator arg (see the sibling consumer
3129 // in the [`kube_resource_skeleton`] call above in this same
3130 // emitter) both key off exactly one typed dispatch. A future
3131 // extension of the `:entrada` slot to a multi-destination
3132 // author surface (weighted canary backends, per-path override,
3133 // an M4 `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's
3134 // admission-webhook that promotes the scalar to a weighted list)
3135 // reaches both consumers by construction rather than by a
3136 // coordinated inline-copy rewrite — Gateway API v1.x
3137 // conformance requires the HTTPRoute's `backendRefs[]` to
3138 // reach a K8s Service the parent Gateway has permission to
3139 // route to; drift between the `metadata.name` grep-by-name
3140 // encoding and the `backendRefs[]` service-name reach breaks
3141 // the operator-side `kubectl get httproute` lookup encoding
3142 // far from any single-site commit.
3143 backend_ref.insert_string(GATEWAY_API_KEY_NAME, entrada.destination().to_string());
3144 // Substrate-canonical per-destination L4 port scalar — routes
3145 // through the lifted [`caixa_core::AplicacaoSpec::port_for_destination`]
3146 // typed dispatch on the substrate primitive so the per-HTTPRoute
3147 // per-rule `backendRefs[0].port` axis and the peer per-`(:de, :para)`
3148 // `CiliumNetworkPolicy` `toPorts[0].ports[0].port` axis (see the
3149 // sibling consumer at `cilium_network_policies` earlier in this
3150 // module — the sole other per-Aplicacao renderer that reaches for
3151 // a per-destination Servico TCP port scalar) both key off exactly
3152 // one typed dispatch. Prior to this lift the site inlined a
3153 // verbatim `entrada.port` field access, with no compile-time link
3154 // to the peer CNP-side resolver dispatch's naming discipline; a
3155 // future per-destination port axis extension (a per-`:contratos`
3156 // explicit `:port` slot the M4 typed-edge registry adds, a per-
3157 // `:membros` `:port` overlay once heterogeneous per-Servico
3158 // listener ports land, a per-cluster override the operator pins
3159 // through a future `:placement :default-port` slot, the M4
3160 // `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's per-CR
3161 // admission-webhook floor) would have had to be threaded through
3162 // this inline field access and every future per-Aplicacao
3163 // renderer's inline copy in lockstep, or the HTTPRoute
3164 // `backendRefs[].port` would have silently split from the peer
3165 // CNP L4 whitelist port — Gateway API v1.x forwards the request
3166 // to the destination Servico's Service on the emitted `port:`,
3167 // while Cilium's per-L4 policy filter drops any flow whose
3168 // destination port doesn't match the CNP whitelist, so a two-
3169 // consumer split silently blackholes every external `:entrada`
3170 // flow at the eBPF data plane far from the source `caixa.lisp`
3171 // with no field naming the port-drift root cause in the
3172 // emitted YAML. Peer with the sibling `entrada.destination()`
3173 // consumer on the immediately-preceding `backend_ref.insert_
3174 // string(GATEWAY_API_KEY_NAME, …)` call — both per-`:entrada`
3175 // backendRef scalar axes now route through their own typed
3176 // dispatch on the substrate primitive, so a future rebrand on
3177 // either axis reaches this consumer by construction. Same
3178 // discipline the peer `cilium_network_policies` L4 port resolver
3179 // at caixa-mesh/src/lib.rs:2663 established (9ca4896) on the
3180 // sibling per-`(:de, :para)` CNP consumer.
3181 backend_ref.insert_number(
3182 KUBE_KEY_PORT,
3183 spec.port_for_destination(entrada.destination()),
3184 );
3185 let mut rule = serde_yaml::Mapping::new();
3186 rule.insert_singleton_mapping_sequence(GATEWAY_API_KEY_MATCHES, match_entry);
3187 rule.insert_singleton_mapping_sequence(GATEWAY_API_KEY_BACKEND_REFS, backend_ref);
3188 rule.insert_str_key_if_some(GATEWAY_API_KEY_TIMEOUTS, timeout_overlay.as_ref());
3189 rule.insert_str_key_if_some(GATEWAY_API_KEY_RETRY, retry_overlay.as_ref());
3190 rules.push_mapping(rule);
3191 }
3192
3193 let mut r_spec = serde_yaml::Mapping::new();
3194 r_spec.insert_singleton_mapping_sequence(GATEWAY_API_KEY_PARENT_REFS, parent_ref);
3195 // Substrate-canonical per-`:entrada` DNS-hostname plural
3196 // resolver — routes through the lifted
3197 // [`caixa_core::Entrada::hostnames`] typed accessor on the
3198 // substrate primitive so the per-HTTPRoute plural
3199 // `spec.hostnames[]` filter list and the peer parent-Gateway
3200 // per-listener singular `hostname:` filter (see the sibling
3201 // [`caixa_core::Entrada::hostname`] consumer above in this
3202 // same `gateway_routes` emitter) both key off exactly one
3203 // typed dispatch on the substrate primitive. The pair-
3204 // invariant `hostnames() == vec![hostname()]` pinned in
3205 // [`caixa_core::aplicacao::tests::hostnames_returns_singleton_of_hostname_accessor`]
3206 // keeps the two axes in lockstep by construction, so a
3207 // Gateway API v1.x `Accepted:False/NoMatchingParent` reject
3208 // at HTTPRoute-attach time (the parent Gateway's listener
3209 // hostname doesn't intersect the route's hostname filter
3210 // list) is a caixa-core-build-time failure rather than a
3211 // cluster-apply-time surprise. Peer of the sibling
3212 // [`caixa_core::Entrada::resolved_paths`] (1449891) path-list
3213 // resolver on the per-HTTPRoute per-rule path axis.
3214 r_spec.insert_sequence(
3215 GATEWAY_API_KEY_HOSTNAMES,
3216 entrada
3217 .hostnames()
3218 .into_iter()
3219 .map(|h| serde_yaml::Value::String(h.to_string()))
3220 .collect(),
3221 );
3222 r_spec.insert_sequence(KUBE_KEY_RULES, rules);
3223 route.insert_mapping(KUBE_KEY_SPEC, r_spec);
3224
3225 Ok(vec![
3226 serde_yaml::Value::Mapping(gateway),
3227 serde_yaml::Value::Mapping(route),
3228 ])
3229}
3230
3231/// One-shot bundle that renders every cluster artifact for an Aplicacao:
3232///
3233/// - programs.yaml entries (one per `:membros`)
3234/// - Cilium NetworkPolicies (one per `:contratos`)
3235/// - Gateway + HTTPRoute (when `:entrada` is set)
3236///
3237/// Returned as a flat `Vec<Value>` of YAML documents, suitable for
3238/// concatenation into a single multi-doc YAML file (the canonical
3239/// `feira app deploy` write target).
3240pub fn render_all(caixa: &Caixa) -> Result<Vec<serde_yaml::Value>, Error> {
3241 let mut out = Vec::new();
3242 out.extend(programs_for_aplicacao(caixa)?);
3243 out.extend(cilium_network_policies(caixa)?);
3244 out.extend(gateway_routes(caixa)?);
3245 Ok(out)
3246}
3247
3248#[cfg(test)]
3249mod tests {
3250 use super::*;
3251 use caixa_core::{
3252 Caixa, CaixaKind, DEFAULT_SERVICO_PORT, Entrada, GATEWAY_API_DEFAULT_HTTP_ROUTE_PATH,
3253 LABEL_PROGRAM, M3_PLACEMENT_KEY_AFFINITY, M3_PLACEMENT_KEY_CLUSTERS,
3254 M3_PLACEMENT_KEY_ESTRATEGIA, M3_PLACEMENT_KEY_SHARD_KEY, Membro, MeshPolicy, Placement,
3255 PlacementStrategy, WitContract, find_by_kind, kube_kind_is, kube_metadata_str_field,
3256 kube_root_str_field,
3257 };
3258 use std::time::Duration;
3259
3260 fn aplicacao_caixa() -> Caixa {
3261 Caixa {
3262 nome: "checkout".into(),
3263 versao: "0.1.0".into(),
3264 kind: CaixaKind::Aplicacao,
3265 edicao: Some("2026".into()),
3266 descricao: Some("Checkout flow.".into()),
3267 repositorio: Some("github:pleme-io/checkout".into()),
3268 licenca: Some("MIT".into()),
3269 autores: vec!["pleme-io".into()],
3270 etiquetas: vec!["checkout".into()],
3271 deps: vec![],
3272 deps_dev: vec![],
3273 exe: vec![],
3274 bibliotecas: vec![],
3275 servicos: vec![],
3276 limits: None,
3277 behavior: None,
3278 upgrade_from: vec![],
3279 estrategia: None,
3280 max_restarts: None,
3281 restart_window: None,
3282 children: vec![],
3283 membros: vec![
3284 Membro {
3285 caixa: "catalog".into(),
3286 versao: "^0.1".into(),
3287 },
3288 Membro {
3289 caixa: "cart".into(),
3290 versao: "^0.1".into(),
3291 },
3292 Membro {
3293 caixa: "payment".into(),
3294 versao: "^0.2".into(),
3295 },
3296 ],
3297 contratos: vec![
3298 WitContract {
3299 de: "cart".into(),
3300 para: "catalog".into(),
3301 wit: "wasi:http/proxy".into(),
3302 endpoint: Some("/products/:id".into()),
3303 subject: None,
3304 slot: None,
3305 },
3306 WitContract {
3307 de: "cart".into(),
3308 para: "payment".into(),
3309 wit: "wasi:http/proxy".into(),
3310 endpoint: Some("/charge".into()),
3311 subject: None,
3312 slot: None,
3313 },
3314 ],
3315 politicas: Some(MeshPolicy {
3316 timeout: Some(Duration::from_secs(30)),
3317 retries: Some(3),
3318 mtls_required: Some(true),
3319 ..Default::default()
3320 }),
3321 placement: Some(Placement {
3322 estrategia: PlacementStrategy::Replicated,
3323 clusters: vec!["rio".into(), "mar".into()],
3324 affinity: Some("data-locality".into()),
3325 shard_key: None,
3326 }),
3327 entrada: Some(Entrada {
3328 host: "checkout.quero.cloud".into(),
3329 para: "cart".into(),
3330 paths: vec!["/api/cart".into()],
3331 port: 8080,
3332 }),
3333 ci: None,
3334 }
3335 }
3336
3337 #[test]
3338 fn default_namespace_re_export_points_at_caixa_core_canonical() {
3339 // The renderer's `pub const DEFAULT_NAMESPACE` (with its prior
3340 // doc-comment explicitly acknowledging the duplication —
3341 // "Mirrors `caixa_flux::DEFAULT_NAMESPACE`") was lifted to a
3342 // re-export of [`caixa_core::DEFAULT_NAMESPACE`] so the
3343 // namespace string lives in exactly one place across every
3344 // caixa renderer. Pin the equality here so any local re-
3345 // introduction of a sibling `pub const DEFAULT_NAMESPACE: &str
3346 // = "…"` is a build-time test failure naming the offending
3347 // drift, not a silent apply-time symptom — the prior shape
3348 // would have let a rebrand on the caixa-flux side without a
3349 // coordinated caixa-mesh edit silently land Servicos at one
3350 // namespace and their Aplicacao's CiliumNetworkPolicy /
3351 // Gateway / HTTPRoute objects at the drifted other, with
3352 // every L7 contrato flow dropping at apply time because the
3353 // policy's `endpointSelector` matched no pods in its emit
3354 // namespace. Peer to
3355 // `caixa_flux::tests::default_namespace_re_export_points_at_caixa_core_canonical`
3356 // on the sibling renderer crate.
3357 caixa_core::assert_str_reexport_identity(
3358 "DEFAULT_NAMESPACE",
3359 DEFAULT_NAMESPACE,
3360 caixa_core::DEFAULT_NAMESPACE,
3361 );
3362 }
3363
3364 #[test]
3365 fn contrato_edge_label_separator_re_export_points_at_caixa_core_canonical() {
3366 // The renderer's `CONTRATO_EDGE_LABEL_SEPARATOR` was lifted from
3367 // two verbatim inline `format!("{de}-to-{para}")` +
3368 // `format!("{}-{}-to-{}", caixa.nome, de, para)` sites at the
3369 // `cilium_network_policies` per-`(:de, :para)` group's
3370 // [`LABEL_CONTRATO`] `labels.insert(...)` call and the peer
3371 // `kube_resource_skeleton` `name:` argument to a re-export of
3372 // [`caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR`] so the load-
3373 // bearing `-to-` byte-string lives in exactly one place across
3374 // every caixa renderer. Pin the equality + static-data identity
3375 // here so any local re-introduction of a sibling `pub const
3376 // CONTRATO_EDGE_LABEL_SEPARATOR: &str = "…"` (the canonical
3377 // drift footgun where a sibling local `pub const` could happen
3378 // to carry the same string at the source while pointing at a
3379 // different `&'static` allocation) is a build-time test failure
3380 // naming the offending drift, not a silent apply-time symptom —
3381 // the prior shape would have let an edge-encoding rebrand on
3382 // the caixa-mesh side without a coordinated caixa-core edit
3383 // silently split the CNP `metadata.name` from its own
3384 // `metadata.labels.pleme.pleme.io/contrato` value, orphaning
3385 // every operator-side `kubectl get cnp -l pleme.pleme.io/
3386 // contrato=<de>-to-<para>` grep-by-label query at apply time.
3387 // Peer to
3388 // [`default_namespace_re_export_points_at_caixa_core_canonical`]
3389 // on the sibling re-export axis.
3390 caixa_core::assert_str_reexport_identity(
3391 "CONTRATO_EDGE_LABEL_SEPARATOR",
3392 CONTRATO_EDGE_LABEL_SEPARATOR,
3393 caixa_core::CONTRATO_EDGE_LABEL_SEPARATOR,
3394 );
3395 }
3396
3397 #[test]
3398 fn contrato_edge_label_re_export_matches_caixa_core_canonical_output() {
3399 // The renderer's `contrato_edge_label` was lifted from the
3400 // verbatim inline `format!("{de}-to-{para}")` at the
3401 // `cilium_network_policies` per-`(:de, :para)` group's
3402 // [`LABEL_CONTRATO`] `labels.insert(...)` call to a re-export
3403 // of [`caixa_core::contrato_edge_label`]. Pin the output-shape
3404 // equality here on a representative fixture so any local re-
3405 // introduction of a sibling `pub fn contrato_edge_label(...)`
3406 // shadow at this crate is a build-time test failure. Both call
3407 // paths must resolve to the same canonical function through
3408 // `pub use`, so their outputs agree by construction.
3409 assert_eq!(
3410 contrato_edge_label("cart", "catalog"),
3411 caixa_core::contrato_edge_label("cart", "catalog"),
3412 );
3413 assert_eq!(contrato_edge_label("cart", "catalog"), "cart-to-catalog");
3414 }
3415
3416 #[test]
3417 fn cilium_network_policy_name_re_export_matches_caixa_core_canonical_output() {
3418 // The renderer's `cilium_network_policy_name` was lifted from
3419 // the verbatim inline `format!("{}-{}-to-{}", caixa.nome, de,
3420 // para)` at the `cilium_network_policies` per-`(:de, :para)`
3421 // group's `kube_resource_skeleton` `name:` argument to a re-
3422 // export of [`caixa_core::cilium_network_policy_name`]. Pin the
3423 // output-shape equality here on a representative fixture so any
3424 // local re-introduction of a sibling `pub fn
3425 // cilium_network_policy_name(...)` shadow at this crate is a
3426 // build-time test failure. Peer with
3427 // [`contrato_edge_label_re_export_matches_caixa_core_canonical_output`]
3428 // on the sibling composer axis — the CNP metadata.name
3429 // composes on [`contrato_edge_label`], so a drift on either
3430 // half would silently split the per-CNP identity pair
3431 // `(metadata.labels.pleme.pleme.io/contrato, metadata.name)`
3432 // at emit time.
3433 assert_eq!(
3434 cilium_network_policy_name("checkout", "cart", "catalog"),
3435 caixa_core::cilium_network_policy_name("checkout", "cart", "catalog"),
3436 );
3437 assert_eq!(
3438 cilium_network_policy_name("checkout", "cart", "catalog"),
3439 "checkout-cart-to-catalog",
3440 );
3441 }
3442
3443 #[test]
3444 fn cilium_network_policy_metadata_name_uses_lifted_composer() {
3445 // Composition pin: the CNP `metadata.name` emitted by
3446 // `cilium_network_policies` per `(:de, :para)` group must
3447 // byte-equal the output of the lifted
3448 // [`cilium_network_policy_name`] composer with the same
3449 // arguments — so a future refactor of the composer's internals
3450 // (edge-encoding rebrand, aplicacao-prefix reshape) reaches
3451 // the renderer through the one function-pointer edit, and any
3452 // rewrite of the inline `format!` at the emit site that
3453 // desynchronizes from the composer fires here at build-time
3454 // rather than silently splitting the two writer-side axes at
3455 // emit time. The fixture's two `:contratos` edges (cart→catalog
3456 // and cart→payment) exercise both edges of the per-`(:de,
3457 // :para)` groups the CNP emitter produces.
3458 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
3459 let names: Vec<String> = policies
3460 .iter()
3461 .map(|p| {
3462 kube_metadata_str_field(p, KUBE_KEY_NAME)
3463 .expect("policy metadata.name")
3464 .to_string()
3465 })
3466 .collect();
3467 assert!(
3468 names.contains(&cilium_network_policy_name("checkout", "cart", "catalog")),
3469 "CNP metadata.name for (cart, catalog) must match lifted composer output; \
3470 got names {names:?}",
3471 );
3472 assert!(
3473 names.contains(&cilium_network_policy_name("checkout", "cart", "payment")),
3474 "CNP metadata.name for (cart, payment) must match lifted composer output; \
3475 got names {names:?}",
3476 );
3477 }
3478
3479 #[test]
3480 fn cilium_network_policy_label_contrato_value_uses_lifted_composer() {
3481 // Composition pin: the CNP `metadata.labels.pleme.pleme.io/
3482 // contrato` value emitted by `cilium_network_policies` per
3483 // `(:de, :para)` group must byte-equal the output of the
3484 // lifted [`contrato_edge_label`] composer with the same
3485 // arguments — so a future refactor of the composer's internals
3486 // (edge-encoding rebrand) reaches the label emission through
3487 // one function-pointer edit, and any rewrite of the inline
3488 // `format!` at the emit site that desynchronizes from the
3489 // composer fires here at build-time rather than silently
3490 // orphaning every operator-side grep-by-label query at apply
3491 // time. Peer with
3492 // [`cilium_network_policy_metadata_name_uses_lifted_composer`]
3493 // on the sibling per-CNP identity-pair axis — the two pins
3494 // together close the drift surface between
3495 // `metadata.labels.pleme.pleme.io/contrato` and
3496 // `metadata.name` on the shared
3497 // [`CONTRATO_EDGE_LABEL_SEPARATOR`] byte-string.
3498 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
3499 let contrato_values: Vec<String> = policies
3500 .iter()
3501 .filter_map(|p| {
3502 p.get(KUBE_KEY_METADATA)
3503 .and_then(|m| m.get(KUBE_KEY_LABELS))
3504 .and_then(|l| l.get(LABEL_CONTRATO))
3505 .and_then(|v| v.as_str())
3506 .map(String::from)
3507 })
3508 .collect();
3509 assert!(
3510 contrato_values.contains(&contrato_edge_label("cart", "catalog")),
3511 "CNP LABEL_CONTRATO value for (cart, catalog) must match lifted composer output; \
3512 got values {contrato_values:?}",
3513 );
3514 assert!(
3515 contrato_values.contains(&contrato_edge_label("cart", "payment")),
3516 "CNP LABEL_CONTRATO value for (cart, payment) must match lifted composer output; \
3517 got values {contrato_values:?}",
3518 );
3519 }
3520
3521 #[test]
3522 fn gateway_api_http_route_name_re_export_matches_caixa_core_canonical_output() {
3523 // The renderer's `gateway_api_http_route_name` was lifted from
3524 // the verbatim inline `format!("{}-{}", caixa.nome,
3525 // entrada.para)` at the `gateway_routes`
3526 // `kube_resource_skeleton` `name:` argument to a re-export of
3527 // [`caixa_core::gateway_api_http_route_name`]. Pin the
3528 // output-shape equality here on a representative fixture so
3529 // any local re-introduction of a sibling `pub fn
3530 // gateway_api_http_route_name(...)` shadow at this crate is a
3531 // build-time test failure. Peer with
3532 // [`cilium_network_policy_name_re_export_matches_caixa_core_canonical_output`]
3533 // on the sibling per-Aplicacao per-CR K8s-name-shaped-identity-
3534 // scalar composer axis — the CNP-name composer carries the
3535 // per-`(:de, :para)` policy CR name and this composer carries
3536 // the per-`:entrada` route CR name.
3537 assert_eq!(
3538 gateway_api_http_route_name("checkout", "cart"),
3539 caixa_core::gateway_api_http_route_name("checkout", "cart"),
3540 );
3541 assert_eq!(
3542 gateway_api_http_route_name("checkout", "cart"),
3543 "checkout-cart",
3544 );
3545 }
3546
3547 #[test]
3548 fn gateway_api_http_route_metadata_name_uses_lifted_composer() {
3549 // Composition pin: the HTTPRoute `metadata.name` emitted by
3550 // `gateway_routes` must byte-equal the output of the lifted
3551 // [`gateway_api_http_route_name`] composer with the same
3552 // arguments — so a future refactor of the composer's internals
3553 // (per-Aplicacao Gateway API per-CR name-encoding rebrand)
3554 // reaches the renderer through one function-pointer edit, and
3555 // any rewrite of the inline `format!` at the emit site that
3556 // desynchronizes from the composer fires here at build-time
3557 // rather than silently splitting the emitted HTTPRoute
3558 // `metadata.name` from the operator-side `kubectl get
3559 // httproute -n tatara-system <aplicacao>-<para>` grep-by-name
3560 // lookup encoding. Peer to
3561 // [`cilium_network_policy_metadata_name_uses_lifted_composer`]
3562 // on the sibling per-CR K8s-name-shaped-identity-scalar
3563 // composer axis.
3564 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
3565 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
3566 assert_eq!(
3567 kube_metadata_str_field(route, KUBE_KEY_NAME),
3568 Some(gateway_api_http_route_name("checkout", "cart").as_str()),
3569 "HTTPRoute metadata.name must match lifted composer output",
3570 );
3571 }
3572
3573 #[test]
3574 fn gateway_api_api_version_re_export_points_at_caixa_core_canonical() {
3575 // The renderer's `GATEWAY_API_API_VERSION` was lifted from two
3576 // inline `"gateway.networking.k8s.io/v1"` literals at the two
3577 // `gateway_routes` `kube_resource_skeleton` call sites
3578 // (caixa-mesh/src/lib.rs:455, 496 — the `Gateway` + `HTTPRoute`
3579 // CRD-group/version axis pair) to a re-export of
3580 // [`caixa_core::GATEWAY_API_API_VERSION`] so the Gateway-API-
3581 // conformant CRD-group/version string lives in exactly one
3582 // place across every caixa renderer. Pin the equality + static-
3583 // data identity here so any local re-introduction of a sibling
3584 // `pub const GATEWAY_API_API_VERSION: &str = "…"` (the canonical
3585 // drift footgun where a sibling local `pub const` could happen
3586 // to carry the same string at the source while pointing at a
3587 // different `&'static` allocation) is a build-time test failure
3588 // naming the offending drift, not a silent apply-time symptom —
3589 // the prior shape would have let a Gateway-API GA bump on the
3590 // caixa-mesh side without a coordinated caixa-core edit silently
3591 // land Gateway / HTTPRoute objects at one CRD version and every
3592 // future per-target renderer's emitted `Gateway` / `HTTPRoute` /
3593 // `TCPRoute` / `TLSRoute` / `GRPCRoute` at the drifted other,
3594 // with every external `:entrada` flow dropping at apply time
3595 // because the per-route attached-policy pipeline never binds
3596 // across the version-drifted CRD-group/version pair. Peer to
3597 // [`default_namespace_re_export_points_at_caixa_core_canonical`]
3598 // on the sibling re-export axis.
3599 caixa_core::assert_str_reexport_identity(
3600 "GATEWAY_API_API_VERSION",
3601 GATEWAY_API_API_VERSION,
3602 caixa_core::GATEWAY_API_API_VERSION,
3603 );
3604 }
3605
3606 #[test]
3607 fn cilium_api_version_re_export_points_at_caixa_core_canonical() {
3608 // The renderer's `CILIUM_API_VERSION` was lifted from the inline
3609 // `"cilium.io/v2"` literal at the `cilium_network_policies`
3610 // `kube_resource_skeleton` call site (caixa-mesh/src/lib.rs:326 —
3611 // the per-`(:de, :para)` CiliumNetworkPolicy emit site) to a
3612 // re-export of [`caixa_core::CILIUM_API_VERSION`] so the
3613 // Cilium-CRD-group/version string lives in exactly one place
3614 // across every caixa renderer. Pin the equality + static-data
3615 // identity here so any local re-introduction of a sibling
3616 // `pub const CILIUM_API_VERSION: &str = "…"` (the canonical
3617 // drift footgun where a sibling local `pub const` could happen
3618 // to carry the same string at the source while pointing at a
3619 // different `&'static` allocation) is a build-time test failure
3620 // naming the offending drift, not a silent apply-time symptom —
3621 // the prior shape would have let a Cilium-CRD bump on the
3622 // caixa-mesh side without a coordinated caixa-core edit silently
3623 // land per-`(:de, :para)` CiliumNetworkPolicy objects at one CRD
3624 // version and every future per-target Cilium-side renderer's
3625 // emitted `CiliumClusterwideNetworkPolicy` /
3626 // `CiliumLocalRedirectPolicy` at the drifted other, with every
3627 // intra-mesh L4/L7 contrato flow dropping at apply time because
3628 // the per-policy attached-identity pipeline never binds across
3629 // the version-drifted CRD-group/version pair. Peer to
3630 // [`gateway_api_api_version_re_export_points_at_caixa_core_canonical`]
3631 // / [`default_namespace_re_export_points_at_caixa_core_canonical`]
3632 // on the sibling re-export axes.
3633 caixa_core::assert_str_reexport_identity(
3634 "CILIUM_API_VERSION",
3635 CILIUM_API_VERSION,
3636 caixa_core::CILIUM_API_VERSION,
3637 );
3638 }
3639
3640 #[test]
3641 fn kube_key_spec_re_export_points_at_caixa_core_canonical() {
3642 // The renderer's `KUBE_KEY_SPEC` was lifted from three inline
3643 // `"spec".into()` literals at the three K8s-CR top-level-spec
3644 // insertion sites (the `cilium_network_policies` per-`(:de,
3645 // :para)` `CiliumNetworkPolicy` skeleton, the `gateway_routes`
3646 // `Gateway` skeleton, the `gateway_routes` `HTTPRoute`
3647 // skeleton) to a re-export of [`caixa_core::KUBE_KEY_SPEC`] so
3648 // the canonical K8s-CR top-level spec-axis string lives in
3649 // exactly one place across every caixa renderer. Pin the
3650 // equality + static-data identity here so any local
3651 // re-introduction of a sibling `pub const KUBE_KEY_SPEC: &str
3652 // = "…"` (the canonical drift footgun where a sibling local
3653 // `pub const` could happen to carry the same string at the
3654 // source while pointing at a different `&'static` allocation)
3655 // is a build-time test failure naming the offending drift,
3656 // not a silent apply-time symptom. Peer to
3657 // [`gateway_api_api_version_re_export_points_at_caixa_core_canonical`]
3658 // / [`cilium_api_version_re_export_points_at_caixa_core_canonical`]
3659 // / [`default_namespace_re_export_points_at_caixa_core_canonical`]
3660 // on the sibling re-export axes.
3661 caixa_core::assert_str_reexport_identity(
3662 "KUBE_KEY_SPEC",
3663 KUBE_KEY_SPEC,
3664 caixa_core::KUBE_KEY_SPEC,
3665 );
3666 }
3667
3668 #[test]
3669 fn kube_key_metadata_re_export_points_at_caixa_core_canonical() {
3670 // The renderer's `KUBE_KEY_METADATA` was lifted from eleven
3671 // inline `"metadata"` literals at the test-side K8s-CR
3672 // top-level-metadata-axis retrieval calls that navigate into
3673 // the metadata block of each rendered `CiliumNetworkPolicy` /
3674 // `Gateway` / `HTTPRoute` doc (per-policy name / namespace /
3675 // labels / mapping-shape / alphabetical-iteration axes) to a
3676 // re-export of [`caixa_core::KUBE_KEY_METADATA`] so the
3677 // canonical K8s-CR top-level metadata-axis string lives in
3678 // exactly one place across every caixa renderer. Pin the
3679 // equality + static-data identity here so any local
3680 // re-introduction of a sibling `pub const KUBE_KEY_METADATA:
3681 // &str = "…"` (the canonical drift footgun where a sibling
3682 // local `pub const` could happen to carry the same string at
3683 // the source while pointing at a different `&'static`
3684 // allocation) is a build-time test failure naming the
3685 // offending drift. Peer to
3686 // [`kube_key_spec_re_export_points_at_caixa_core_canonical`]
3687 // on the sibling K8s-CR top-level-spec-axis re-export +
3688 // `caixa_flux::tests::kube_key_metadata_re_export_points_at_caixa_core_canonical`
3689 // on the sibling renderer crate.
3690 caixa_core::assert_str_reexport_identity(
3691 "KUBE_KEY_METADATA",
3692 KUBE_KEY_METADATA,
3693 caixa_core::KUBE_KEY_METADATA,
3694 );
3695 }
3696
3697 #[test]
3698 fn kube_key_kind_re_export_points_at_caixa_core_canonical() {
3699 // The renderer's `KUBE_KEY_KIND` was lifted from sixteen inline
3700 // `"kind"` literals at the test-side K8s-CR top-level-kind-axis
3701 // retrieval calls that navigate the multi-doc sequence the
3702 // `cilium_network_policies` / `gateway_routes` / `render_all`
3703 // emitters return to isolate the per-`(Gateway, HTTPRoute,
3704 // CiliumNetworkPolicy)` document (the `docs.iter().find(|d|
3705 // d.get("kind")…)` filter predicate + `for p in &policies {
3706 // p.get("kind")… }` iteration axes) to a re-export of
3707 // [`caixa_core::KUBE_KEY_KIND`] so the canonical K8s-CR
3708 // top-level kind-discriminator axis string lives in exactly one
3709 // place across every caixa renderer. Pin the equality +
3710 // static-data identity here so any local re-introduction of a
3711 // sibling `pub const KUBE_KEY_KIND: &str = "…"` (the canonical
3712 // drift footgun where a sibling local `pub const` could happen
3713 // to carry the same string at the source while pointing at a
3714 // different `&'static` allocation) is a build-time test
3715 // failure naming the offending drift, not a silent apply-time
3716 // symptom — the prior shape would have let a typo on any one
3717 // sibling `pub const` declaration silently miss the per-CR
3718 // kind retrieval so the multi-doc `.find(|d|
3719 // d.get(KUBE_KEY_KIND)…) == Some(…)` predicate the render-
3720 // determinism / kind-axis pins rest on would compare against
3721 // `None` and mask the true kind-axis drift under the trailing
3722 // `.expect("Gateway present")` panic. Peer to
3723 // [`kube_key_spec_re_export_points_at_caixa_core_canonical`] +
3724 // [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
3725 // on the sibling K8s-CR top-level-spec / top-level-metadata
3726 // axis re-exports — completes the per-K8s-CR top-level axis
3727 // re-export triple `(spec, metadata, kind)` the multi-doc
3728 // consumer patterns across this crate's test suite rest on.
3729 caixa_core::assert_str_reexport_identity(
3730 "KUBE_KEY_KIND",
3731 KUBE_KEY_KIND,
3732 caixa_core::KUBE_KEY_KIND,
3733 );
3734 }
3735
3736 #[test]
3737 fn kube_key_api_version_re_export_points_at_caixa_core_canonical() {
3738 // The renderer's `KUBE_KEY_API_VERSION` was lifted from six
3739 // inline `"apiVersion"` literals at the test-side K8s-CR
3740 // top-level-apiVersion-axis retrieval calls that navigate the
3741 // rendered multi-doc sequence the `cilium_network_policies` /
3742 // `gateway_routes` emitters return to isolate each per-`(CNP,
3743 // Gateway, HTTPRoute)` document's top-level-apiVersion axis and
3744 // pin it to the lifted [`CILIUM_API_VERSION`] /
3745 // [`GATEWAY_API_API_VERSION`] controller-pair CRD-group/version
3746 // constants (the two `cilium_network_policies_use_lifted_cilium_api_version`
3747 // + `gateway_routes_gateway_uses_lifted_gateway_api_api_version`
3748 // + `gateway_routes_httproute_uses_lifted_gateway_api_api_version`
3749 // lifted-uses pins plus the three sibling
3750 // `cilium_policy_carries_canonical_kube_skeleton` /
3751 // `gateway_carries_canonical_kube_skeleton_without_labels` /
3752 // `httproute_carries_canonical_kube_skeleton_without_labels`
3753 // canonical-string bridge-arm pins), to a re-export of
3754 // [`caixa_core::KUBE_KEY_API_VERSION`] so the canonical K8s-CR
3755 // top-level apiVersion-axis string lives in exactly one place
3756 // across every caixa renderer. Pin the equality + static-data
3757 // identity here so any local re-introduction of a sibling `pub
3758 // const KUBE_KEY_API_VERSION: &str = "…"` (the canonical drift
3759 // footgun where a sibling local `pub const` could happen to
3760 // carry the same string at the source while pointing at a
3761 // different `&'static` allocation) is a build-time test failure
3762 // naming the offending drift, not a silent apply-time symptom —
3763 // the prior shape would have let a typo on any one sibling
3764 // `pub const` declaration silently miss the per-CR apiVersion
3765 // retrieval so the drift-detection
3766 // `.get(KUBE_KEY_API_VERSION).and_then(|n| n.as_str()) == Some(…)`
3767 // predicate the sibling [`CILIUM_API_VERSION`] /
3768 // [`GATEWAY_API_API_VERSION`] re-export pins rest on would
3769 // compare against `None` under the trailing
3770 // `.expect("Gateway present")` / `.expect("HTTPRoute present")`
3771 // panic and mask the true sibling controller-pair
3772 // CRD-group/version axis drift. Peer to
3773 // [`kube_key_spec_re_export_points_at_caixa_core_canonical`] +
3774 // [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
3775 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
3776 // on the sibling K8s-CR top-level-spec / top-level-metadata /
3777 // top-level-kind axis re-exports — completes the per-K8s-CR
3778 // top-level `(apiVersion, kind, metadata, spec)` axis re-export
3779 // quartet every rendered multi-doc mesh bundle document
3780 // navigates. Peer to
3781 // `caixa_flux::tests::kube_key_api_version_re_export_points_at_caixa_core_canonical`
3782 // (e0555d6) on the sibling renderer crate — extends the
3783 // discipline from the Flux v2 controller-triplet drift-
3784 // detection pins onto the Cilium + Gateway API controller-pair
3785 // drift-detection pins in this crate.
3786 caixa_core::assert_str_reexport_identity(
3787 "KUBE_KEY_API_VERSION",
3788 KUBE_KEY_API_VERSION,
3789 caixa_core::KUBE_KEY_API_VERSION,
3790 );
3791 }
3792
3793 #[test]
3794 fn kube_key_namespace_re_export_points_at_caixa_core_canonical() {
3795 // The renderer's `KUBE_KEY_NAMESPACE` was lifted from three
3796 // inline `"namespace"` literals at the test-side K8s-CR
3797 // metadata.namespace-axis retrieval sites (the
3798 // `cilium_policy_carries_canonical_kube_skeleton` /
3799 // `gateway_carries_canonical_kube_skeleton_without_labels`
3800 // per-CR metadata.namespace equality pins and the
3801 // `cilium_policy_metadata_block_iterates_alphabetically`
3802 // render-determinism-contract fixture) to a re-export of
3803 // [`caixa_core::KUBE_KEY_NAMESPACE`] so the canonical K8s-CR
3804 // metadata.namespace-axis string lives in exactly one place
3805 // across every caixa renderer. Pin the equality + static-data
3806 // identity here so any local re-introduction of a sibling
3807 // `pub const KUBE_KEY_NAMESPACE: &str = "…"` (the canonical
3808 // drift footgun where a sibling local `pub const` could
3809 // happen to carry the same string at the source while
3810 // pointing at a different `&'static` allocation) is a
3811 // build-time test failure naming the offending drift, not a
3812 // silent apply-time symptom — the prior shape would have let
3813 // a typo on any one sibling `pub const` declaration silently
3814 // miss the per-CR metadata.namespace retrieval so the
3815 // `.get(KUBE_KEY_NAMESPACE).and_then(|n| n.as_str()) ==
3816 // Some(DEFAULT_NAMESPACE)` predicate the sibling
3817 // [`DEFAULT_NAMESPACE`] re-export pin rests on would compare
3818 // against `None` under the trailing `.expect("metadata
3819 // mapping")` panic and mask the true sibling default-
3820 // namespace-axis drift. Peer to
3821 // [`kube_key_spec_re_export_points_at_caixa_core_canonical`] +
3822 // [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
3823 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
3824 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
3825 // on the sibling K8s-CR top-level `(apiVersion, kind, metadata,
3826 // spec)` axis re-export quartet — extends the discipline onto
3827 // the load-bearing nested `metadata.namespace` axis every
3828 // rendered `CiliumNetworkPolicy` / `Gateway` / `HTTPRoute`
3829 // document binds to on the deploy path. Peer to
3830 // `caixa_flux::tests::kube_key_namespace_re_export_points_at_caixa_core_canonical`
3831 // (44bebfe) on the sibling renderer crate — extends the
3832 // discipline from the Flux v2 controller-triplet + ComputeUnit-
3833 // side metadata.namespace drift-detection pins onto the
3834 // Cilium + Gateway API controller-pair metadata.namespace
3835 // drift-detection pins in this crate.
3836 caixa_core::assert_str_reexport_identity(
3837 "KUBE_KEY_NAMESPACE",
3838 KUBE_KEY_NAMESPACE,
3839 caixa_core::KUBE_KEY_NAMESPACE,
3840 );
3841 }
3842
3843 #[test]
3844 fn kube_key_labels_re_export_points_at_caixa_core_canonical() {
3845 // The renderer's `KUBE_KEY_LABELS` was lifted from five inline
3846 // `"labels"` literals at the test-side K8s-CR metadata.labels-
3847 // axis retrieval sites (the `cilium_policy_metadata_labels_use_lifted_consts`
3848 // per-CNP metadata.labels retrieval entry point, the
3849 // `cilium_policy_carries_canonical_kube_skeleton` +
3850 // `gateway_carries_canonical_kube_skeleton_without_labels` +
3851 // `httproute_carries_canonical_kube_skeleton_without_labels`
3852 // presence-of-labels / empty-labels-skip semantic pins, and the
3853 // `cilium_policy_metadata_block_iterates_alphabetically`
3854 // render-determinism-contract fixture) to a re-export of
3855 // [`caixa_core::KUBE_KEY_LABELS`] so the canonical K8s-CR
3856 // metadata.labels-axis string lives in exactly one place
3857 // across every caixa renderer. Pin the equality + static-data
3858 // identity here so any local re-introduction of a sibling
3859 // `pub const KUBE_KEY_LABELS: &str = "…"` (the canonical drift
3860 // footgun where a sibling local `pub const` could happen to
3861 // carry the same string at the source while pointing at a
3862 // different `&'static` allocation) is a build-time test
3863 // failure naming the offending drift, not a silent apply-time
3864 // symptom — the prior shape would have let a typo on any one
3865 // sibling `pub const` declaration silently miss the per-CR
3866 // metadata.labels retrieval so the `.get(KUBE_KEY_LABELS)`
3867 // chain the LABEL_APLICACAO + LABEL_CONTRATO drift-detection
3868 // pin rests on would return `None` under the trailing
3869 // `.expect("policy metadata.labels mapping")` panic and mask
3870 // the true sibling label-key-axis drift, or the presence-of-
3871 // labels / empty-labels-skip semantic pins would compare
3872 // `Some(...)`/`None` against the wrong retrieval so the
3873 // empty-labels-skip contract's true drift never surfaces, or
3874 // the alphabetical-iteration render-determinism fixture would
3875 // fire on the drifted-fixture rather than the true render-
3876 // determinism property. Peer to
3877 // [`kube_key_spec_re_export_points_at_caixa_core_canonical`] +
3878 // [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
3879 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
3880 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
3881 // + [`kube_key_namespace_re_export_points_at_caixa_core_canonical`]
3882 // on the sibling K8s-CR top-level `(apiVersion, kind,
3883 // metadata, spec)` axis re-export quartet + the load-bearing
3884 // nested `metadata.namespace` axis re-export — extends the
3885 // discipline onto the load-bearing nested `metadata.labels`
3886 // axis every rendered `CiliumNetworkPolicy` document carries
3887 // at the `pleme.pleme.io/aplicacao` + `pleme.pleme.io/contrato`
3888 // grouping key.
3889 caixa_core::assert_str_reexport_identity(
3890 "KUBE_KEY_LABELS",
3891 KUBE_KEY_LABELS,
3892 caixa_core::KUBE_KEY_LABELS,
3893 );
3894 }
3895
3896 #[test]
3897 fn kube_key_name_re_export_points_at_caixa_core_canonical() {
3898 // The renderer's `KUBE_KEY_NAME` was lifted from four inline
3899 // `"name"` literals at the test-side K8s-CR metadata.name-axis
3900 // retrieval sites (the `cilium_policy_carries_canonical_kube_skeleton`
3901 // + `gateway_carries_canonical_kube_skeleton_without_labels` +
3902 // `httproute_carries_canonical_kube_skeleton_without_labels`
3903 // per-CR metadata.name presence + equality pins, and the
3904 // `cilium_policy_metadata_block_iterates_alphabetically`
3905 // render-determinism-contract fixture) to a re-export of
3906 // [`caixa_core::KUBE_KEY_NAME`] so the canonical K8s-CR
3907 // metadata.name-axis string lives in exactly one place across
3908 // every caixa renderer. Pin the equality + static-data identity
3909 // here so any local re-introduction of a sibling
3910 // `pub const KUBE_KEY_NAME: &str = "…"` (the canonical drift
3911 // footgun where a sibling local `pub const` could happen to
3912 // carry the same string at the source while pointing at a
3913 // different `&'static` allocation) is a build-time test failure
3914 // naming the offending drift, not a silent apply-time symptom
3915 // — the prior shape would have let a typo on any one sibling
3916 // `pub const` declaration silently miss the per-CR
3917 // metadata.name retrieval so the caixa-nome → metadata-name
3918 // binding's true drift is masked, or trip the alphabetical-
3919 // iteration determinism fixture against the drifted-fixture
3920 // rather than the true render-determinism property. Bridge-arm
3921 // peer to [`kube_key_spec_re_export_points_at_caixa_core_canonical`]
3922 // + [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
3923 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
3924 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
3925 // + [`kube_key_namespace_re_export_points_at_caixa_core_canonical`]
3926 // + [`kube_key_labels_re_export_points_at_caixa_core_canonical`]
3927 // — completes the K8s-CR metadata-block axis triplet `(name,
3928 // namespace, labels)` bridge-arm pin under a single canonical
3929 // `caixa-core::KUBE_KEY_*` re-export shape in this crate.
3930 caixa_core::assert_str_reexport_identity(
3931 "KUBE_KEY_NAME",
3932 KUBE_KEY_NAME,
3933 caixa_core::KUBE_KEY_NAME,
3934 );
3935 }
3936
3937 #[test]
3938 fn gateway_api_key_name_re_export_points_at_caixa_core_canonical() {
3939 // The renderer's `GATEWAY_API_KEY_NAME` was lifted from four
3940 // inline `"name"` literals at the Gateway API v1 per-child-
3941 // object name-reference-axis emission + retrieval sites (the
3942 // per-listener `listener.insert("name", …)`, the per-parentRef
3943 // `parent_ref.insert("name", …)`, and the per-backendRef
3944 // `backend_ref.insert("name", …)` calls in `gateway_routes`,
3945 // plus the in-file `httproute_routes_to_entrada_para` fixture's
3946 // per-backendRef `.get("name")` retrieval) to a re-export of
3947 // [`caixa_core::GATEWAY_API_KEY_NAME`] so the canonical
3948 // Gateway-API-v1-per-child-object name-reference-axis string
3949 // lives in exactly one place across every caixa renderer.
3950 //
3951 // Pin the equality + static-data identity here so any local
3952 // re-introduction of a sibling
3953 // `pub const GATEWAY_API_KEY_NAME: &str = "…"` (the canonical
3954 // drift footgun where a sibling local `pub const` could happen
3955 // to carry the same string at the source while pointing at a
3956 // different `&'static` allocation) is a build-time test
3957 // failure naming the offending drift, not a silent apply-time
3958 // symptom — the prior shape would have let a typo on any one
3959 // sibling `pub const` declaration silently miss the per-
3960 // listener / per-parentRef / per-backendRef name-reference
3961 // retrieval so the Aplicacao gateway bundle's true drift is
3962 // masked (the Gateway API implementation's per-listener
3963 // section identity resolves to nothing, the per-HTTPRoute
3964 // parent-Gateway attachment reconciles as unbound, or the
3965 // per-rule backend fan-out resolves no Service — all at
3966 // apply time, far from the source caixa.lisp with no field
3967 // naming the name-reference-axis drift).
3968 //
3969 // Byte-identical to [`KUBE_KEY_NAME`] today — both resolve to
3970 // the same three-byte `"name"` literal — but semantically
3971 // distinct: `KUBE_KEY_NAME` names the K8s CR canonical
3972 // `metadata.name` outer-level identity axis (every rendered
3973 // CR's own name), while `GATEWAY_API_KEY_NAME` names the
3974 // Gateway API v1 CRD schema's per-child-object name-reference
3975 // axis on `Listener` / `ParentReference` / `BackendObjectReference`
3976 // sub-schemas. Splitting the two lets each schema's future
3977 // rebrand land independently at its canonical const definition
3978 // — a future Gateway API v2 rename of the name-reference axis
3979 // to `target` / `ref` / `objectName` cannot coincidentally
3980 // rebrand the K8s CR canonical `metadata.name` axis, and vice
3981 // versa — the same discipline
3982 // [`caixa_core::FLEET_PROGRAMS_KEY_NAME`] establishes vs.
3983 // [`caixa_core::KUBE_KEY_NAME`] on the `lareira-fleet-programs`
3984 // values-schema per-entry name-axis.
3985 caixa_core::assert_str_reexport_identity(
3986 "GATEWAY_API_KEY_NAME",
3987 GATEWAY_API_KEY_NAME,
3988 caixa_core::GATEWAY_API_KEY_NAME,
3989 );
3990 // The re-export is byte-identical to `KUBE_KEY_NAME` today; pin
3991 // the value-equality so a future rebrand on either axis (the
3992 // K8s CR canonical `metadata.name` axis moving to a namespaced
3993 // key, or the Gateway API v1 per-child-object name-reference
3994 // axis moving to `target` / `ref` / `objectName`) surfaces here
3995 // as an explicit split rather than a silent coupling.
3996 assert_eq!(GATEWAY_API_KEY_NAME, "name");
3997 }
3998
3999 #[test]
4000 fn kube_key_match_labels_re_export_points_at_caixa_core_canonical() {
4001 // The renderer's `KUBE_KEY_MATCH_LABELS` was lifted from four
4002 // inline `"matchLabels"` literals at the test-side
4003 // K8s-`LabelSelector.matchLabels` retrieval sites (the
4004 // `cilium_policies_are_identity_based` destination-
4005 // `endpointSelector.matchLabels` presence pin +
4006 // source-`ingress[0].fromEndpoints[0].matchLabels` two-axis
4007 // pin, the `cilium_endpoint_selector_is_program_only`
4008 // destination-`endpointSelector.matchLabels` retrieval whose
4009 // `selector.len() == 1` assertion pins the program-only
4010 // semantic the canonical `pleme_program_selector` helper
4011 // emits, and the
4012 // `cilium_from_endpoints_carries_aplicacao_scoped_selector`
4013 // source-`fromEndpoints[0].matchLabels` retrieval whose
4014 // `from.len() == 2` assertion pins the program-in-Aplicacao-
4015 // scoped semantic the canonical
4016 // `pleme_program_in_aplicacao_selector` helper emits — the
4017 // safety property that a same-named program in a different
4018 // Aplicacao cannot satisfy the policy's ingress rule) to a
4019 // re-export of [`caixa_core::KUBE_KEY_MATCH_LABELS`] so the
4020 // canonical K8s-`LabelSelector.matchLabels`-axis string lives
4021 // in exactly one place across every caixa renderer. Pin the
4022 // equality + static-data identity here so any local
4023 // re-introduction of a sibling `pub const KUBE_KEY_MATCH_LABELS:
4024 // &str = "…"` (the canonical drift footgun where a sibling
4025 // local `pub const` could happen to carry the same string at
4026 // the source while pointing at a different `&'static`
4027 // allocation) is a build-time test failure naming the
4028 // offending drift, not a silent apply-time symptom — the
4029 // prior shape would have let a typo on any one sibling `pub
4030 // const` declaration silently miss the per-CR selector-
4031 // mapping retrieval so the destination-program-only /
4032 // source-program-in-Aplicacao selector-shape contract's true
4033 // drift is masked, or fire the trailing
4034 // `.expect("endpointSelector.matchLabels mapping")` /
4035 // `.expect("fromEndpoints[0].matchLabels mapping")` panic-
4036 // message tag with the mapping-shape message rather than the
4037 // true selector-key drift. Bridge-arm peer to
4038 // [`kube_key_spec_re_export_points_at_caixa_core_canonical`]
4039 // + [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
4040 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
4041 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
4042 // + [`kube_key_namespace_re_export_points_at_caixa_core_canonical`]
4043 // + [`kube_key_labels_re_export_points_at_caixa_core_canonical`]
4044 // + [`kube_key_name_re_export_points_at_caixa_core_canonical`]
4045 // — extends the K8s-CR top-level `(apiVersion, kind,
4046 // metadata, spec)` axis re-export quartet + the load-bearing
4047 // nested `metadata.{name, namespace, labels}` triplet bridge-
4048 // arm pin under a single canonical `caixa-core::KUBE_KEY_*`
4049 // re-export shape in this crate onto the load-bearing nested
4050 // `LabelSelector.matchLabels` axis every rendered
4051 // `CiliumNetworkPolicy` document carries at both
4052 // `spec.endpointSelector.matchLabels` (the destination-
4053 // identity selector the Cilium data plane matches pod-
4054 // identity keys against) and
4055 // `spec.ingress[*].fromEndpoints[*].matchLabels` (the source-
4056 // identity selector the same data plane checks on the
4057 // admitted-source side).
4058 caixa_core::assert_str_reexport_identity(
4059 "KUBE_KEY_MATCH_LABELS",
4060 KUBE_KEY_MATCH_LABELS,
4061 caixa_core::KUBE_KEY_MATCH_LABELS,
4062 );
4063 }
4064
4065 #[test]
4066 fn kube_key_rules_re_export_points_at_caixa_core_canonical() {
4067 // The renderer's `KUBE_KEY_RULES` was lifted from seven inline
4068 // `"rules"` literals — two production emitter sites
4069 // (`cilium_network_policies`'s per-`toPorts[]` L7 `rules:`
4070 // mapping the Cilium data plane dispatches HTTP / Kafka / DNS
4071 // L7 rules under, `gateway_routes`'s `HTTPRoute` `spec.rules[]`
4072 // sequence the gateway-class-controller dispatches per-rule
4073 // `matches[]` + `backendRefs[]` + timeouts / retries overlay
4074 // under) and five test-side rule-list traversal sites (the
4075 // `httproute_carries_paths_from_http_endpoints` /
4076 // `cilium_l7_rules_are_http_only` L7-rule-content pins under
4077 // `toPorts[]`, the `cilium_pubsub_contracts_skip_l7_rules`
4078 // absence pin whose `.is_none()` guards the pubsub-contracts-
4079 // carry-no-L7-rules contract, the
4080 // `gateway_emits_gateway_plus_httproute_pair` HTTPRoute-
4081 // backendRefs-shape pin under `spec`, and the `httproute_rules`
4082 // test-fixture helper the downstream policy-timeout / retries
4083 // / mtls / rate-limit determinism pins reach through) — to a
4084 // re-export of [`caixa_core::KUBE_KEY_RULES`] so the canonical
4085 // K8s-CR-`rules`-collection-axis string lives in exactly one
4086 // place across every caixa renderer. Pin the equality + static-
4087 // data identity here so any local re-introduction of a sibling
4088 // `pub const KUBE_KEY_RULES: &str = "…"` (the canonical drift
4089 // footgun where a sibling local `pub const` could happen to
4090 // carry the same string at the source while pointing at a
4091 // different `&'static` allocation) is a build-time test failure
4092 // naming the offending drift, not a silent apply-time symptom
4093 // — the prior shape would have let a typo on any one sibling
4094 // `pub const` declaration silently miss the per-CR rule-list
4095 // retrieval so the L7-rules-absent-on-pubsub-contracts contract
4096 // (`cilium_pubsub_contracts_skip_l7_rules`), the
4097 // HTTPRoute-rule-sequence-under-spec contract (`httproute_rules`
4098 // fixture + every determinism pin downstream), and the L7-rule-
4099 // path-content contract
4100 // (`httproute_carries_paths_from_http_endpoints` /
4101 // `cilium_l7_rules_are_http_only`) true drift is masked, or
4102 // fire the trailing `.expect("HTTPRoute spec.rules sequence")`
4103 // panic-message tag with the sequence-shape message rather than
4104 // the true rule-list-key drift. Bridge-arm peer to
4105 // [`kube_key_match_labels_re_export_points_at_caixa_core_canonical`]
4106 // + [`kube_key_spec_re_export_points_at_caixa_core_canonical`]
4107 // + [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
4108 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
4109 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
4110 // + [`kube_key_namespace_re_export_points_at_caixa_core_canonical`]
4111 // + [`kube_key_labels_re_export_points_at_caixa_core_canonical`]
4112 // + [`kube_key_name_re_export_points_at_caixa_core_canonical`]
4113 // — extends the K8s-CR top-level `(apiVersion, kind, metadata,
4114 // spec)` axis re-export quartet + the load-bearing nested
4115 // `metadata.{name, namespace, labels}` triplet + the load-
4116 // bearing nested `LabelSelector.matchLabels` selector-projection
4117 // axis under a single canonical `caixa-core::KUBE_KEY_*`
4118 // re-export shape in this crate onto the load-bearing nested
4119 // `spec.rules[]` / `toPorts[].rules` rule-list-container axis
4120 // every rendered `CiliumNetworkPolicy` L7 rule-list + every
4121 // rendered `HTTPRoute` rule-list carries.
4122 caixa_core::assert_str_reexport_identity(
4123 "KUBE_KEY_RULES",
4124 KUBE_KEY_RULES,
4125 caixa_core::KUBE_KEY_RULES,
4126 );
4127 }
4128
4129 #[test]
4130 fn kube_key_port_re_export_points_at_caixa_core_canonical() {
4131 // The renderer's `KUBE_KEY_PORT` was lifted from five inline
4132 // `"port"` literals — three production emitter sites
4133 // (`cilium_network_policies`'s per-`toPorts[].ports[]` port-tuple
4134 // `port:` scalar the Cilium data plane's per-tuple bpf policy
4135 // dispatch loop compares against the observed TCP/UDP L4 header
4136 // port value, `gateway_routes`'s per-`Gateway` per-listener
4137 // `spec.listeners[].port` scalar the gateway-class-controller's
4138 // per-listener bind loop opens the listener socket on,
4139 // `gateway_routes`'s per-`HTTPRoute` per-rule
4140 // `spec.rules[].backendRefs[].port` scalar the gateway-class-
4141 // controller's per-rule backend-dispatch loop forwards the
4142 // matched request to on the resolved Service / ExternalName
4143 // backend) and two test-side L4-port traversal sites (the
4144 // `gateway_emits_gateway_plus_httproute_pair` `.get("port")`
4145 // under `backendRefs[]` HTTPRoute-backend-port-content pin, the
4146 // `cilium_l4_ports_default_to_servico_port` `.get("port")` under
4147 // `toPorts[].ports[]` L7-fallback-port-content pin threading
4148 // through [`DEFAULT_SERVICO_PORT`]) — to a re-export of
4149 // [`caixa_core::KUBE_KEY_PORT`] so the canonical
4150 // K8s-CR-`port`-L4-scalar-axis string lives in exactly one place
4151 // across every caixa renderer. Pin the equality + static-data
4152 // identity here so any local re-introduction of a sibling `pub
4153 // const KUBE_KEY_PORT: &str = "…"` (the canonical drift footgun
4154 // where a sibling local `pub const` could happen to carry the
4155 // same string at the source while pointing at a different
4156 // `&'static` allocation) is a build-time test failure naming
4157 // the offending drift, not a silent apply-time symptom — the
4158 // prior shape would have let a typo on any one sibling `pub
4159 // const` declaration silently miss the per-CR L4-port
4160 // retrieval (the L7-fallback-port-content pin's
4161 // `.expect("toPorts[0].ports[0].port present")` panic-message
4162 // tag would fire against the sequence-shape message rather than
4163 // the true L4-port-key drift, the HTTPRoute-backend-port-content
4164 // pin's `assert_eq!(…, Some(8080))` would silently mask the
4165 // drift under the `None` unwrap-default), or silently emit a
4166 // malformed CR whose port field the apiserver-side CRD schema
4167 // validator drops as unrecognized at apply time. Bridge-arm
4168 // peer to
4169 // [`kube_key_rules_re_export_points_at_caixa_core_canonical`]
4170 // + [`kube_key_match_labels_re_export_points_at_caixa_core_canonical`]
4171 // + [`kube_key_spec_re_export_points_at_caixa_core_canonical`]
4172 // + [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
4173 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
4174 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
4175 // + [`kube_key_namespace_re_export_points_at_caixa_core_canonical`]
4176 // + [`kube_key_labels_re_export_points_at_caixa_core_canonical`]
4177 // + [`kube_key_name_re_export_points_at_caixa_core_canonical`]
4178 // — extends the K8s-CR top-level `(apiVersion, kind, metadata,
4179 // spec)` axis re-export quartet + the load-bearing nested
4180 // `metadata.{name, namespace, labels}` triplet + the load-
4181 // bearing nested `LabelSelector.matchLabels` selector-projection
4182 // axis + the load-bearing nested `spec.rules[]` /
4183 // `toPorts[].rules` rule-list-container axis under a single
4184 // canonical `caixa-core::KUBE_KEY_*` re-export shape in this
4185 // crate onto the load-bearing nested L4-port-scalar axis every
4186 // rendered `CiliumNetworkPolicy` per-`toPorts[].ports[]` port-
4187 // tuple + every rendered `Gateway` per-listener + every
4188 // rendered `HTTPRoute` per-`backendRefs[]` per-rule per-backend
4189 // carries.
4190 caixa_core::assert_str_reexport_identity(
4191 "KUBE_KEY_PORT",
4192 KUBE_KEY_PORT,
4193 caixa_core::KUBE_KEY_PORT,
4194 );
4195 }
4196
4197 #[test]
4198 fn kube_key_protocol_re_export_points_at_caixa_core_canonical() {
4199 // The renderer's `KUBE_KEY_PROTOCOL` was lifted from three
4200 // inline `"protocol"` literals — two production emitter sites
4201 // (`cilium_network_policies`'s per-`toPorts[].ports[]` port-
4202 // tuple `protocol:` scalar the Cilium data plane's per-tuple
4203 // bpf policy dispatch loop compares against the observed L4
4204 // header protocol before applying the port match,
4205 // `gateway_routes`'s per-`Gateway` per-listener
4206 // `spec.listeners[].protocol` scalar the gateway-class-
4207 // controller's per-listener bind loop selects the L7 parser
4208 // + TLS termination strategy from) and one test-side
4209 // protocol-scalar traversal site (the
4210 // `gateway_emits_gateway_plus_httproute_pair` `.get("protocol")`
4211 // retrieval on the emitted `Gateway`'s first listener pinning
4212 // the canonical `HTTP` listener-protocol content) — to a
4213 // re-export of [`caixa_core::KUBE_KEY_PROTOCOL`] so the
4214 // canonical K8s-CR-`protocol`-scalar-discriminator-axis
4215 // string lives in exactly one place across every caixa
4216 // renderer. Pin the equality + static-data identity here so
4217 // any local re-introduction of a sibling `pub const
4218 // KUBE_KEY_PROTOCOL: &str = "…"` (the canonical drift
4219 // footgun where a sibling local `pub const` could happen to
4220 // carry the same string at the source while pointing at a
4221 // different `&'static` allocation) is a build-time test
4222 // failure naming the offending drift, not a silent apply-time
4223 // symptom — the prior shape would have let a typo on any one
4224 // sibling `pub const` declaration silently miss the per-CR
4225 // protocol retrieval (the listener-protocol-content pin's
4226 // `assert_eq!(…, Some("HTTP"))` would silently mask the
4227 // drift under the `None` unwrap-default), or silently emit a
4228 // malformed CR whose protocol field the apiserver-side CRD
4229 // schema validator drops as unrecognized at apply time (the
4230 // Cilium data plane's per-tuple bpf policy dispatch loop
4231 // silently fall back to the CRD default protocol `ANY`,
4232 // admitting UDP traffic through a TCP-only rule; the
4233 // gateway-class-controller's per-listener bind loop silently
4234 // fail listener validation on a required protocol field,
4235 // rejecting the entire `Gateway` object at admission time,
4236 // no L7 traffic admitted). Bridge-arm peer to
4237 // [`kube_key_port_re_export_points_at_caixa_core_canonical`]
4238 // + [`kube_key_rules_re_export_points_at_caixa_core_canonical`]
4239 // + [`kube_key_match_labels_re_export_points_at_caixa_core_canonical`]
4240 // + [`kube_key_spec_re_export_points_at_caixa_core_canonical`]
4241 // + [`kube_key_metadata_re_export_points_at_caixa_core_canonical`]
4242 // + [`kube_key_kind_re_export_points_at_caixa_core_canonical`]
4243 // + [`kube_key_api_version_re_export_points_at_caixa_core_canonical`]
4244 // + [`kube_key_namespace_re_export_points_at_caixa_core_canonical`]
4245 // + [`kube_key_labels_re_export_points_at_caixa_core_canonical`]
4246 // + [`kube_key_name_re_export_points_at_caixa_core_canonical`]
4247 // — extends the K8s-CR top-level `(apiVersion, kind,
4248 // metadata, spec)` axis re-export quartet + the load-bearing
4249 // nested `metadata.{name, namespace, labels}` triplet + the
4250 // load-bearing nested `LabelSelector.matchLabels` selector-
4251 // projection axis + the load-bearing nested `spec.rules[]` /
4252 // `toPorts[].rules` rule-list-container axis + the load-
4253 // bearing nested L4-port-scalar axis under a single canonical
4254 // `caixa-core::KUBE_KEY_*` re-export shape in this crate onto
4255 // the load-bearing nested L4/L7-protocol-scalar-discriminator
4256 // axis every rendered `CiliumNetworkPolicy` per-
4257 // `toPorts[].ports[]` port-tuple + every rendered `Gateway`
4258 // per-listener carries.
4259 caixa_core::assert_str_reexport_identity(
4260 "KUBE_KEY_PROTOCOL",
4261 KUBE_KEY_PROTOCOL,
4262 caixa_core::KUBE_KEY_PROTOCOL,
4263 );
4264 }
4265
4266 #[test]
4267 fn kube_protocol_tcp_re_export_points_at_caixa_core_canonical() {
4268 // The renderer's `KUBE_PROTOCOL_TCP` was lifted from the single
4269 // inline `"TCP".into()` literal at the `cilium_network_policies`
4270 // per-`(:de, :para)` CNP `port_entry.insert(KUBE_KEY_PROTOCOL,
4271 // …)` call site (the per-`toPorts[].ports[]` port-tuple L4-
4272 // transport-protocol scalar-value emit the Cilium data plane's
4273 // per-tuple bpf policy dispatch loop compares against the
4274 // observed L4 header protocol before applying the port match)
4275 // to a re-export of [`caixa_core::KUBE_PROTOCOL_TCP`] so the
4276 // canonical K8s-core-`Protocol`-enum-value string lives in
4277 // exactly one place across every caixa renderer. Pin the
4278 // equality + static-data identity here so any local
4279 // re-introduction of a sibling `pub const KUBE_PROTOCOL_TCP:
4280 // &str = "…"` (the canonical drift footgun where a sibling
4281 // local `pub const` could happen to carry the same string at
4282 // the source while pointing at a different `&'static`
4283 // allocation) is a build-time test failure naming the offending
4284 // drift, not a silent apply-time symptom — the prior shape
4285 // would have let a K8s core `Protocol` rebrand on the caixa-
4286 // mesh side without a coordinated caixa-core edit silently
4287 // land per-`(:de, :para)` CiliumNetworkPolicy documents whose
4288 // per-`toPorts[].ports[]` port-tuple L4-transport-protocol
4289 // scalar the K8s core `Protocol` OpenAPI schema enum's
4290 // `{"TCP", "UDP", "SCTP"}` closed set rejects at apply time
4291 // (the Cilium operator's per-CNP L4 dispatch pass drops the
4292 // CNP under a non-self-locating
4293 // "spec.ingress[0].toPorts[0].ports[0].protocol: Unsupported
4294 // value" apiserver admission rejection); worse — because the
4295 // schema-side default is `TCP`, a silently-elided drift on
4296 // the value lands a CNP whose ingress rule falls back to the
4297 // default L4-transport-protocol and every port-match on a
4298 // non-default transport silently misses at the eBPF data
4299 // plane's per-tuple dispatch. Peer to
4300 // [`gateway_api_protocol_http_re_export_points_at_caixa_core_canonical`]
4301 // on the sibling canonical-Gateway-API-v1-OpenAPI-schema-enum-
4302 // value re-export surface — extends the Gateway-API-v1-
4303 // OpenAPI-schema-enum-value single-sourcing discipline onto
4304 // the sibling K8s-core `Protocol.TCP` per-port-tuple L4-
4305 // transport-protocol-discriminator the `cilium_network_policies`
4306 // intra-mesh L4-tuple-gating emitter carries under the shared
4307 // `CiliumNetworkPolicy` body.
4308 caixa_core::assert_str_reexport_identity(
4309 "KUBE_PROTOCOL_TCP",
4310 KUBE_PROTOCOL_TCP,
4311 caixa_core::KUBE_PROTOCOL_TCP,
4312 );
4313 }
4314
4315 #[test]
4316 fn cilium_port_tuple_carries_lifted_kube_protocol_tcp() {
4317 // Production-emit pin: traverse a rendered CNP's first
4318 // `spec.ingress[0].toPorts[0].ports[0]` port-tuple and assert
4319 // the `protocol:` scalar is the lifted `KUBE_PROTOCOL_TCP`
4320 // (`"TCP"`) verbatim — the load-bearing per-tuple L4-transport-
4321 // protocol discriminator the Cilium data plane's per-tuple
4322 // bpf policy dispatch loop compares against the observed L4
4323 // header protocol before applying the port match. Before the
4324 // lift the emitter carried an inline `"TCP".into()` literal
4325 // at the sole `port_entry.insert(KUBE_KEY_PROTOCOL, …)` call
4326 // site; a typo there (`"tcp"` / `"Tcp"` / `"TCP/IP"`) would
4327 // have silently landed the CNP outside the K8s core `Protocol`
4328 // OpenAPI schema enum's `{"TCP", "UDP", "SCTP"}` admitted set,
4329 // and worse — because the schema-side default is `TCP` — a
4330 // silently-elided drift would have fallen back to the default
4331 // L4-transport-protocol at admission, letting non-default-
4332 // transport port-matches silently miss at the eBPF data plane
4333 // with no field naming the drift root cause. Peer to
4334 // `gateway_listener_carries_aplicacao_host`'s
4335 // `assert_eq!(listener.get(KUBE_KEY_PROTOCOL)…, Some(GATEWAY_API_PROTOCOL_HTTP))`
4336 // per-listener L7-parser-selection scalar pin on the sibling
4337 // `Gateway.spec.listeners[].protocol` surface — extends the
4338 // per-listener L7-parser-selection scalar pin discipline onto
4339 // the sibling per-`toPorts[].ports[]` port-tuple L4-transport-
4340 // protocol scalar pin surface every `cilium_network_policies`
4341 // intra-mesh L4-tuple-gating emit carries under the shared
4342 // `CiliumNetworkPolicy` body.
4343 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
4344 let port_tuple = policies
4345 .first()
4346 .and_then(|p| p.get(KUBE_KEY_SPEC))
4347 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
4348 .and_then(|i| i.as_sequence())
4349 .and_then(|s| s.first())
4350 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
4351 .and_then(|p| p.as_sequence())
4352 .and_then(|s| s.first())
4353 .and_then(|tp| tp.get(CILIUM_KEY_PORTS))
4354 .and_then(|p| p.as_sequence())
4355 .and_then(|s| s.first())
4356 .expect("spec.ingress[0].toPorts[0].ports[0] port-tuple");
4357 assert_eq!(
4358 port_tuple.get(KUBE_KEY_PROTOCOL).and_then(|v| v.as_str()),
4359 Some(KUBE_PROTOCOL_TCP),
4360 "per-`toPorts[].ports[]` port-tuple `protocol:` scalar must be \
4361 the lifted `KUBE_PROTOCOL_TCP` (`\"TCP\"`) verbatim — the \
4362 load-bearing K8s core `Protocol` OpenAPI schema enum value \
4363 the Cilium data plane's per-tuple bpf policy dispatch loop \
4364 compares against the observed L4 header protocol"
4365 );
4366 }
4367
4368 #[test]
4369 fn gateway_api_key_timeouts_re_export_points_at_caixa_core_canonical() {
4370 // The renderer's `GATEWAY_API_KEY_TIMEOUTS` was lifted from nine
4371 // inline `"timeouts"` literals — one production emitter site
4372 // (`gateway_routes`'s per-`HTTPRoute` per-rule
4373 // `spec.rules[].timeouts` insert the Aplicacao's typed
4374 // `:politicas :timeout` overlay lands under, the sub-shape the
4375 // Gateway API v1 CRD schema pins as `HTTPRouteTimeouts` and
4376 // whose `request` scalar the Gateway-API-implementation-side
4377 // per-rule request-dispatch loop compares each accepted
4378 // request's wall-clock elapsed time against before cancelling
4379 // the in-flight backend call) and eight test-side per-rule
4380 // timeout-policy traversal sites (the
4381 // `httproute_carries_politicas_timeout_on_every_rule` presence
4382 // pin, the `httproute_omits_timeouts_when_politicas_timeout_unset`
4383 // absence pin, the `httproute_timeout_renders_every_rule_independently`
4384 // per-rule fan-out pin under multi-`:entrada :paths`, the
4385 // `httproute_timeout_uses_canonical_kube_duration_format`
4386 // `Duration::from_secs(90)`-round-trip canonical-form pin, the
4387 // `httproute_timeout_renders_minute_window_canonically`
4388 // 1-minute canonical-form pin, the
4389 // `httproute_rule_keys_pin_overlay_position` rule-level
4390 // top-key-set pin, and two `httproute_timeouts_and_retry_coexist_independently`
4391 // presence-only + absence-only pins pinning independent-axis
4392 // coexistence with the sibling `retry` per-rule retry-policy
4393 // axis) — to a re-export of
4394 // [`caixa_core::GATEWAY_API_KEY_TIMEOUTS`] so the canonical
4395 // K8s-Gateway-API-`HTTPRoute`-per-rule-request-timeout-policy-
4396 // body-axis string lives in exactly one place across every
4397 // caixa renderer. Pin the equality + static-data identity here
4398 // so any local re-introduction of a sibling `pub const
4399 // GATEWAY_API_KEY_TIMEOUTS: &str = "…"` (the canonical drift
4400 // footgun where a sibling local `pub const` could happen to
4401 // carry the same string at the source while pointing at a
4402 // different `&'static` allocation) is a build-time test failure
4403 // naming the offending drift, not a silent apply-time symptom —
4404 // the prior shape would have let a typo on any one sibling
4405 // `pub const` declaration silently miss the per-rule request-
4406 // timeout retrieval (the presence pin's `.expect("rule must
4407 // carry timeouts mapping when :politicas :timeout is set")`
4408 // panic-message tag would fire against the presence-shape
4409 // message rather than the true per-rule-timeout-policy-key
4410 // drift, the `.get("timeouts").and_then(|t| t.get("request"))`
4411 // navigators would silently unwrap to `None` under the drifted
4412 // retrieval), or silently emit a malformed `HTTPRoute` whose
4413 // per-rule request-timeout-policy field the apiserver-side
4414 // Gateway API CRD schema validator drops as unrecognized at
4415 // apply time (the Gateway API implementation's per-rule
4416 // request-dispatch loop silently no-ops the per-rule wall-
4417 // clock deadline, the "no infinite blocking" guarantee
4418 // MESH-COMPOSITION.md §V mandates for every rendered per-
4419 // `:politicas` mesh-composition edge silently regresses to the
4420 // pre-overlay unbounded-request semantic). Bridge-arm peer to
4421 // [`kube_key_protocol_re_export_points_at_caixa_core_canonical`]
4422 // + [`kube_key_port_re_export_points_at_caixa_core_canonical`]
4423 // + [`kube_key_rules_re_export_points_at_caixa_core_canonical`]
4424 // + [`gateway_api_key_hostnames_re_export_points_at_caixa_core_canonical`]
4425 // + [`gateway_api_key_hostname_re_export_points_at_caixa_core_canonical`]
4426 // + [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
4427 // + [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
4428 // + [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
4429 // — extends the per-Gateway-API-CRD-body-axis re-export set
4430 // onto the load-bearing per-rule request-timeout-policy axis
4431 // the M3 Aplicacao mesh renderer's per-`:politicas :timeout`
4432 // overlay lands under.
4433 caixa_core::assert_str_reexport_identity(
4434 "GATEWAY_API_KEY_TIMEOUTS",
4435 GATEWAY_API_KEY_TIMEOUTS,
4436 caixa_core::GATEWAY_API_KEY_TIMEOUTS,
4437 );
4438 }
4439
4440 #[test]
4441 fn gateway_api_key_retry_re_export_points_at_caixa_core_canonical() {
4442 // The renderer's `GATEWAY_API_KEY_RETRY` was lifted from nine
4443 // inline `"retry"` literals — one production emitter site
4444 // (`gateway_routes`'s per-`HTTPRoute` per-rule
4445 // `spec.rules[].retry` insert the Aplicacao's typed
4446 // `:politicas :retries` overlay lands under, the sub-shape the
4447 // Gateway API v1 CRD schema pins as `HTTPRouteRetry` and whose
4448 // `attempts` scalar the Gateway-API-implementation-side per-
4449 // rule request-dispatch loop compares each failed attempt count
4450 // against before giving up on the in-flight backend call) and
4451 // eight test-side per-rule retry-policy traversal sites (the
4452 // `httproute_rule_keys_pin_overlay_position` rule-level top-key-
4453 // set pin, the `httproute_carries_politicas_retries_on_every_rule`
4454 // presence pin, the `httproute_omits_retry_when_politicas_retries_unset`
4455 // absence pin, the `httproute_retry_renders_every_rule_independently`
4456 // per-rule fan-out pin under multi-`:entrada :paths`, the
4457 // `httproute_retry_round_trips_typed_attempt_count` typed-`u32`-
4458 // round-trip pin, the `httproute_retry_attempts_serialized_as_yaml_number`
4459 // YAML integer-scalar-kind pin, and two
4460 // `httproute_timeouts_and_retry_coexist_independently` presence-
4461 // only + absence-only pins pinning independent-axis coexistence
4462 // with the sibling `timeouts` per-rule request-timeout-policy
4463 // axis) — to a re-export of
4464 // [`caixa_core::GATEWAY_API_KEY_RETRY`] so the canonical
4465 // K8s-Gateway-API-`HTTPRoute`-per-rule-retry-policy-body-axis
4466 // string lives in exactly one place across every caixa
4467 // renderer. Pin the equality + static-data identity here so any
4468 // local re-introduction of a sibling `pub const
4469 // GATEWAY_API_KEY_RETRY: &str = "…"` (the canonical drift
4470 // footgun where a sibling local `pub const` could happen to
4471 // carry the same string at the source while pointing at a
4472 // different `&'static` allocation) is a build-time test failure
4473 // naming the offending drift, not a silent apply-time symptom —
4474 // the prior shape would have let a typo on any one sibling
4475 // `pub const` declaration silently miss the per-rule retry
4476 // retrieval (the presence pin's `.expect("rule must carry retry
4477 // mapping when :politicas :retries is set")` panic-message tag
4478 // would fire against the presence-shape message rather than the
4479 // true per-rule-retry-policy-key drift, the
4480 // `.get("retry").and_then(|r| r.get("attempts"))` navigators
4481 // would silently unwrap to `None` under the drifted retrieval),
4482 // or silently emit a malformed `HTTPRoute` whose per-rule
4483 // retry-policy field the apiserver-side Gateway API CRD schema
4484 // validator drops as unrecognized at apply time (the Gateway
4485 // API implementation's per-rule request-dispatch loop silently
4486 // no-ops the per-rule retry budget, the "no infinite retrying
4487 // without bound" guarantee MESH-COMPOSITION.md §V mandates for
4488 // every rendered per-`:politicas` mesh-composition edge
4489 // silently regresses to the pre-overlay unbounded-retry
4490 // semantic). Bridge-arm peer to
4491 // [`gateway_api_key_timeouts_re_export_points_at_caixa_core_canonical`]
4492 // + [`gateway_api_key_hostnames_re_export_points_at_caixa_core_canonical`]
4493 // + [`gateway_api_key_hostname_re_export_points_at_caixa_core_canonical`]
4494 // + [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
4495 // + [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
4496 // + [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
4497 // — closes the per-Gateway-API-`HTTPRoute`-per-rule `:politicas`
4498 // overlay axis re-export pair (`timeouts` for `:politicas
4499 // :timeout`, `retry` for `:politicas :retries`) both
4500 // MESH-COMPOSITION.md §V "no infinite blocking / no infinite
4501 // retrying" guarantees rest on.
4502 caixa_core::assert_str_reexport_identity(
4503 "GATEWAY_API_KEY_RETRY",
4504 GATEWAY_API_KEY_RETRY,
4505 caixa_core::GATEWAY_API_KEY_RETRY,
4506 );
4507 }
4508
4509 #[test]
4510 fn gateway_api_key_attempts_re_export_points_at_caixa_core_canonical() {
4511 // The renderer's `GATEWAY_API_KEY_ATTEMPTS` was lifted from six
4512 // inline `"attempts"` literals — one production emitter site
4513 // (`gateway_routes`'s per-`HTTPRoute` per-rule
4514 // `single_field_overlay(spec.politicas.retries, …)` call that
4515 // seeds the typed `u32` attempt count into the sibling
4516 // [`GATEWAY_API_KEY_RETRY`] container axis under
4517 // `spec.rules[].retry.attempts`, the leaf the Gateway API v1
4518 // CRD schema pins as `HTTPRouteRetry.attempts` and whose scalar
4519 // value the Gateway-API-implementation-side per-rule request-
4520 // dispatch loop compares each failed backend attempt count
4521 // against before giving up on the in-flight backend call) and
4522 // five test-side per-rule retry-attempts traversal sites (the
4523 // `httproute_carries_politicas_retries_on_every_rule` typed-
4524 // `u64`-value pin, the
4525 // `httproute_retry_renders_every_rule_independently` per-rule
4526 // fan-out attempt-count pin under multi-`:entrada :paths`, the
4527 // `httproute_retry_round_trips_typed_attempt_count` typed-`u32`-
4528 // round-trip pin, the
4529 // `httproute_retry_attempts_serialized_as_yaml_number` YAML
4530 // integer-scalar-kind pin, and the retries-only arm of
4531 // `httproute_timeouts_and_retry_coexist_independently` pinning
4532 // the leaf attempt count survives when only the sibling
4533 // `:retries` slot is set) — to a re-export of
4534 // [`caixa_core::GATEWAY_API_KEY_ATTEMPTS`] so the canonical K8s-
4535 // Gateway-API-`HTTPRoute`-per-rule-retry-policy-`attempts`-
4536 // leaf-scalar-key string lives in exactly one place across
4537 // every caixa renderer. Pin the equality + static-data identity
4538 // here so any local re-introduction of a sibling `pub const
4539 // GATEWAY_API_KEY_ATTEMPTS: &str = "…"` (the canonical drift
4540 // footgun where a sibling local `pub const` could happen to
4541 // carry the same string at the source while pointing at a
4542 // different `&'static` allocation) is a build-time test failure
4543 // naming the offending drift, not a silent apply-time symptom
4544 // — the prior shape would have let a typo on any one sibling
4545 // `pub const` declaration silently miss the per-rule retry-
4546 // attempts retrieval (the round-trip pins' `Some(3)` /
4547 // `Some(5)` / `Some(2)` equality tags would fire against the
4548 // `None` retrieval, silently masking the true per-rule-retry-
4549 // attempts-leaf-key drift), or silently emit a malformed
4550 // `HTTPRoute` whose per-rule retry sub-shape the apiserver-side
4551 // Gateway API CRD schema validator drops the leaf attempt count
4552 // from as unrecognized at apply time (the Gateway API
4553 // implementation's per-rule request-dispatch loop parses the
4554 // retry sub-shape as an empty `HTTPRouteRetry`, the "no
4555 // infinite retrying without bound" guarantee MESH-COMPOSITION.md
4556 // §V mandates for every rendered per-`:politicas` mesh-
4557 // composition edge silently regresses to the pre-overlay
4558 // unbounded-retry semantic). Bridge-arm peer to
4559 // [`gateway_api_key_retry_re_export_points_at_caixa_core_canonical`]
4560 // + [`gateway_api_key_timeouts_re_export_points_at_caixa_core_canonical`]
4561 // + [`gateway_api_key_hostnames_re_export_points_at_caixa_core_canonical`]
4562 // + [`gateway_api_key_hostname_re_export_points_at_caixa_core_canonical`]
4563 // + [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
4564 // + [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
4565 // + [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
4566 // — closes the parent-leaf axis pair (`retry` container +
4567 // `attempts` leaf) both MESH-COMPOSITION.md §V "no infinite
4568 // retrying" guarantees rest on, one nesting level deeper than
4569 // the parent per-rule retry-policy container axis (`retry`).
4570 caixa_core::assert_str_reexport_identity(
4571 "GATEWAY_API_KEY_ATTEMPTS",
4572 GATEWAY_API_KEY_ATTEMPTS,
4573 caixa_core::GATEWAY_API_KEY_ATTEMPTS,
4574 );
4575 }
4576
4577 #[test]
4578 fn gateway_api_key_request_re_export_points_at_caixa_core_canonical() {
4579 // The renderer's `GATEWAY_API_KEY_REQUEST` was lifted from six
4580 // inline `"request"` literals — one production emitter site
4581 // (`gateway_routes`'s per-`HTTPRoute` per-rule
4582 // `single_field_overlay(spec.politicas.timeout, …)` call that
4583 // seeds the typed `Duration` request-deadline string into the
4584 // sibling [`GATEWAY_API_KEY_TIMEOUTS`] container axis under
4585 // `spec.rules[].timeouts.request`, the leaf the Gateway API v1
4586 // CRD schema pins as `HTTPRouteTimeouts.request` and whose
4587 // scalar value the Gateway-API-implementation-side per-rule
4588 // request-dispatch loop commits to as the per-request wall-
4589 // clock deadline every inbound request is bounded against
4590 // before the resolved backend even sees the call) and five
4591 // test-side per-rule request-deadline traversal sites (the
4592 // `httproute_carries_politicas_timeout_on_every_rule` typed-
4593 // `&str`-value pin, the
4594 // `httproute_timeout_renders_every_rule_independently` per-rule
4595 // fan-out request-deadline pin under multi-`:entrada :paths`,
4596 // the `httproute_timeout_uses_canonical_kube_duration_format`
4597 // typed-`Duration`-round-trip pin, the
4598 // `httproute_timeout_renders_minute_window_canonically`
4599 // canonical-minute-form pin, and the timeout-only arm of
4600 // `httproute_timeouts_and_retry_coexist_independently` pinning
4601 // the leaf request-deadline survives when only the sibling
4602 // `:timeout` slot is set) — to a re-export of
4603 // [`caixa_core::GATEWAY_API_KEY_REQUEST`] so the canonical K8s-
4604 // Gateway-API-`HTTPRoute`-per-rule-request-timeout-policy-
4605 // `request`-leaf-scalar-key string lives in exactly one place
4606 // across every caixa renderer. Pin the equality + static-data
4607 // identity here so any local re-introduction of a sibling `pub
4608 // const GATEWAY_API_KEY_REQUEST: &str = "…"` (the canonical
4609 // drift footgun where a sibling local `pub const` could happen
4610 // to carry the same string at the source while pointing at a
4611 // different `&'static` allocation) is a build-time test failure
4612 // naming the offending drift, not a silent apply-time symptom
4613 // — the prior shape would have let a typo on any one sibling
4614 // `pub const` declaration silently miss the per-rule request-
4615 // deadline retrieval (the round-trip pins' `Some("30s")` /
4616 // `Some("90s")` / `Some("1m")` / `Some("15s")` equality tags
4617 // would fire against the `None` retrieval, silently masking
4618 // the true per-rule-request-deadline-leaf-key drift), or
4619 // silently emit a malformed `HTTPRoute` whose per-rule
4620 // timeouts sub-shape the apiserver-side Gateway API CRD schema
4621 // validator drops the leaf request-deadline from as
4622 // unrecognized at apply time (the Gateway API implementation's
4623 // per-rule request-dispatch loop parses the timeouts sub-shape
4624 // as an empty `HTTPRouteTimeouts`, the "no infinite blocking"
4625 // guarantee MESH-COMPOSITION.md §V mandates for every rendered
4626 // per-`:politicas` mesh-composition edge silently regresses to
4627 // the pre-overlay unbounded-blocking semantic). Bridge-arm peer
4628 // to
4629 // [`gateway_api_key_attempts_re_export_points_at_caixa_core_canonical`]
4630 // + [`gateway_api_key_retry_re_export_points_at_caixa_core_canonical`]
4631 // + [`gateway_api_key_timeouts_re_export_points_at_caixa_core_canonical`]
4632 // + [`gateway_api_key_hostnames_re_export_points_at_caixa_core_canonical`]
4633 // + [`gateway_api_key_hostname_re_export_points_at_caixa_core_canonical`]
4634 // + [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
4635 // + [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
4636 // + [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
4637 // — closes the second parent-leaf axis pair (`timeouts`
4638 // container + `request` leaf) both MESH-COMPOSITION.md §V "no
4639 // infinite blocking / no infinite retrying" guarantees rest
4640 // on, sibling to the parent-leaf pair (`retry` container +
4641 // `attempts` leaf) closed in the immediately-preceding
4642 // [`GATEWAY_API_KEY_ATTEMPTS`] bridge-arm.
4643 caixa_core::assert_str_reexport_identity(
4644 "GATEWAY_API_KEY_REQUEST",
4645 GATEWAY_API_KEY_REQUEST,
4646 caixa_core::GATEWAY_API_KEY_REQUEST,
4647 );
4648 }
4649
4650 #[test]
4651 fn cilium_kind_network_policy_re_export_points_at_caixa_core_canonical() {
4652 // The renderer's `CILIUM_KIND_NETWORK_POLICY` was lifted from
4653 // the inline `"CiliumNetworkPolicy"` literal at the
4654 // `cilium_network_policies` `kube_resource_skeleton` kind
4655 // argument (caixa-mesh/src/lib.rs:382 — the per-`(:de, :para)`
4656 // CiliumNetworkPolicy emit site) to a re-export of
4657 // [`caixa_core::CILIUM_KIND_NETWORK_POLICY`] so the
4658 // Cilium-CRD-`kind` discriminator string lives in exactly one
4659 // place across every caixa renderer. Pin the equality +
4660 // static-data identity here so any local re-introduction of a
4661 // sibling `pub const CILIUM_KIND_NETWORK_POLICY: &str = "…"`
4662 // (the canonical drift footgun where a sibling local `pub
4663 // const` could happen to carry the same string at the source
4664 // while pointing at a different `&'static` allocation) is a
4665 // build-time test failure naming the offending drift, not a
4666 // silent apply-time symptom — the prior shape would have let a
4667 // Cilium-CRD kind rebrand on the caixa-mesh side without a
4668 // coordinated caixa-core edit silently land per-`(:de, :para)`
4669 // CiliumNetworkPolicy objects at one CRD kind and every
4670 // future per-target Cilium-side renderer's emitted
4671 // `CiliumClusterwideNetworkPolicy` / `CiliumLocalRedirectPolicy`
4672 // at the drifted other, with every intra-mesh L4/L7 contrato
4673 // flow dropping at apply time because the per-policy
4674 // attached-identity pipeline never binds across the
4675 // kind-drifted CRD-discriminator pair. Peer to
4676 // [`cilium_api_version_re_export_points_at_caixa_core_canonical`]
4677 // on the sibling Cilium-CRD-apiVersion-re-export axis —
4678 // completes the per-Cilium-CRD kind+apiVersion re-export pair
4679 // this crate's `cilium_network_policies` renderer's eBPF
4680 // data-plane contract rests on.
4681 caixa_core::assert_str_reexport_identity(
4682 "CILIUM_KIND_NETWORK_POLICY",
4683 CILIUM_KIND_NETWORK_POLICY,
4684 caixa_core::CILIUM_KIND_NETWORK_POLICY,
4685 );
4686 }
4687
4688 #[test]
4689 fn cilium_key_to_ports_re_export_points_at_caixa_core_canonical() {
4690 // The renderer's `CILIUM_KEY_TO_PORTS` was lifted from the
4691 // inline `"toPorts"` literal at the `cilium_network_policies`
4692 // per-`(:de, :para)` `ingress_rule.insert("toPorts", …)` call
4693 // site + six test-side navigations
4694 // (`cilium_http_contracts_emit_l7_rules`,
4695 // `cilium_pubsub_contracts_skip_l7_rules`,
4696 // `cilium_multiple_edges_same_pair_fold_into_one_policy`,
4697 // `cnp_authentication_carries_mtls_overlay_at_ingress_rule_level`
4698 // — via the `contains_key` presence check + the paired
4699 // `.get(…).and_then(|t| t.as_sequence())` navigation both
4700 // consulting the same axis,
4701 // `cnp_l4_fallback_port_routes_through_lifted_default_servico_port`)
4702 // to a re-export of [`caixa_core::CILIUM_KEY_TO_PORTS`] so the
4703 // Cilium-CRD per-ingress-rule port-set container-key string
4704 // lives in exactly one place across every caixa renderer. Pin
4705 // the equality + static-data identity here so any local
4706 // re-introduction of a sibling `pub const CILIUM_KEY_TO_PORTS:
4707 // &str = "…"` (the canonical drift footgun where a sibling
4708 // local `pub const` could happen to carry the same string at
4709 // the source while pointing at a different `&'static`
4710 // allocation) is a build-time test failure naming the offending
4711 // drift, not a silent apply-time symptom — the prior shape
4712 // would have let a Cilium-CRD schema rebrand on the port-set
4713 // container axis without a coordinated caixa-core edit silently
4714 // land per-`(:de, :para)` CiliumNetworkPolicy documents whose
4715 // `spec.ingress[].toPorts[]` container the Cilium CRD schema
4716 // validator drops as unrecognized at apply time, with every
4717 // intra-mesh L4/L7 `:contratos` flow dropping at the eBPF data
4718 // plane's default-deny gate because the per-CNP L4-allow /
4719 // L7-dispatch pass never binds through the container-drifted
4720 // port-set-container axis. Peer to
4721 // [`kube_key_rules_re_export_points_at_caixa_core_canonical`]
4722 // on the sibling per-CNP-dispatch-container re-export axis —
4723 // completes the per-CNP L4/L7-dispatch-container
4724 // `(toPorts, rules)` re-export pair this crate's
4725 // `cilium_network_policies` renderer's eBPF data-plane contract
4726 // rests on. Peer to
4727 // [`cilium_kind_network_policy_re_export_points_at_caixa_core_canonical`]
4728 // + [`cilium_api_version_re_export_points_at_caixa_core_canonical`]
4729 // on the outer `(apiVersion, kind)` shell of the same per-CNP
4730 // CRD — extends the per-Cilium-CRD re-export set from the outer
4731 // shell down through the load-bearing
4732 // `spec.ingress[].toPorts[].rules` L4/L7-dispatch axis.
4733 caixa_core::assert_str_reexport_identity(
4734 "CILIUM_KEY_TO_PORTS",
4735 CILIUM_KEY_TO_PORTS,
4736 caixa_core::CILIUM_KEY_TO_PORTS,
4737 );
4738 }
4739
4740 #[test]
4741 fn cilium_key_endpoint_selector_re_export_points_at_caixa_core_canonical() {
4742 // The renderer's `CILIUM_KEY_ENDPOINT_SELECTOR` was lifted from
4743 // the inline `"endpointSelector"` literal at the
4744 // `cilium_network_policies` per-`(:de, :para)` CNP
4745 // `policy_spec.insert("endpointSelector", …)` call site plus
4746 // two test-side navigations
4747 // (`cilium_policies_are_identity_based`,
4748 // `cnp_endpoint_selector_carries_program_only_single_axis_shape`
4749 // — the pair of destination-`endpointSelector` retrievals whose
4750 // downstream `.and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))`
4751 // chains consult the same axis-key) to a re-export of
4752 // [`caixa_core::CILIUM_KEY_ENDPOINT_SELECTOR`] so the Cilium-CRD
4753 // per-CNP-body destination-identity axis-key string lives in
4754 // exactly one place across every caixa renderer. Pin the
4755 // equality + static-data identity here so any local
4756 // re-introduction of a sibling `pub const CILIUM_KEY_ENDPOINT_\
4757 // SELECTOR: &str = "…"` (the canonical drift footgun where a
4758 // sibling local `pub const` could happen to carry the same
4759 // string at the source while pointing at a different `&'static`
4760 // allocation) is a build-time test failure naming the offending
4761 // drift, not a silent apply-time symptom — the prior shape
4762 // would have let a Cilium-CRD schema rebrand on the
4763 // destination-identity axis without a coordinated caixa-core
4764 // edit silently land per-`(:de, :para)` CiliumNetworkPolicy
4765 // documents whose `spec.endpointSelector` axis the Cilium CRD
4766 // schema validator drops as unrecognized at apply time, with
4767 // the emitted policy binding against no destination pods and
4768 // every intra-mesh `:contratos` flow the affected CNP was
4769 // authored to allow dropping at the eBPF data plane's default-
4770 // deny gate because the per-CNP L3-target-selector pass never
4771 // resolves through the axis-drifted destination-identity key.
4772 // Peer to
4773 // [`cilium_key_to_ports_re_export_points_at_caixa_core_canonical`]
4774 // on the sibling per-CNP-body-axis re-export set — completes the
4775 // per-CNP L3/L4/L7-triad
4776 // `(endpointSelector, ingress → toPorts → rules)` re-export
4777 // this crate's `cilium_network_policies` renderer's eBPF data-
4778 // plane contract rests on. Peer to
4779 // [`cilium_kind_network_policy_re_export_points_at_caixa_core_canonical`]
4780 // + [`cilium_api_version_re_export_points_at_caixa_core_canonical`]
4781 // on the outer `(apiVersion, kind)` shell of the same per-CNP
4782 // CRD — extends the per-Cilium-CRD re-export set from the outer
4783 // shell down through the load-bearing `spec.endpointSelector`
4784 // L3-target-selector axis.
4785 caixa_core::assert_str_reexport_identity(
4786 "CILIUM_KEY_ENDPOINT_SELECTOR",
4787 CILIUM_KEY_ENDPOINT_SELECTOR,
4788 caixa_core::CILIUM_KEY_ENDPOINT_SELECTOR,
4789 );
4790 }
4791
4792 #[test]
4793 fn cilium_key_ingress_re_export_points_at_caixa_core_canonical() {
4794 // The renderer's `CILIUM_KEY_INGRESS` was lifted from the inline
4795 // `"ingress"` literal at the `cilium_network_policies`
4796 // per-`(:de, :para)` CNP `policy_spec.insert("ingress", …)`
4797 // call site plus eight test-side navigations
4798 // (`cilium_http_contracts_emit_l7_rules`,
4799 // `cilium_policies_are_identity_based`,
4800 // `cnp_from_endpoints_carries_program_plus_aplicacao_labels_two_axis_shape`,
4801 // `cilium_multiple_edges_same_pair_fold_into_one_policy`,
4802 // `cilium_pubsub_contracts_skip_l7_rules`,
4803 // `render_multi_doc_contains_expected_kinds`,
4804 // `cnp_authentication_carries_mtls_overlay_at_ingress_rule_level`,
4805 // `cnp_l4_fallback_port_routes_through_lifted_default_servico_port`
4806 // — the per-CNP navigation each of these tests consults to
4807 // reach the ingress-rule list before descending into the
4808 // `fromEndpoints` / `toPorts` / `authentication` axes) to a
4809 // re-export of [`caixa_core::CILIUM_KEY_INGRESS`] so the
4810 // Cilium-CRD per-CNP-body traffic-direction axis-key string
4811 // lives in exactly one place across every caixa renderer. Pin
4812 // the equality + static-data identity here so any local
4813 // re-introduction of a sibling `pub const CILIUM_KEY_INGRESS:
4814 // &str = "…"` (the canonical drift footgun where a sibling
4815 // local `pub const` could happen to carry the same string at
4816 // the source while pointing at a different `&'static`
4817 // allocation) is a build-time test failure naming the offending
4818 // drift, not a silent apply-time symptom — the prior shape
4819 // would have let a Cilium-CRD schema rebrand on the traffic-
4820 // direction axis without a coordinated caixa-core edit silently
4821 // land per-`(:de, :para)` CiliumNetworkPolicy documents whose
4822 // `spec.ingress[]` list the Cilium CRD schema validator drops
4823 // as unrecognized at apply time, with the emitted policy
4824 // binding against the destination workload but admitting no
4825 // ingress traffic and every intra-mesh `:contratos` flow the
4826 // affected CNP was authored to allow dropping at the eBPF data
4827 // plane's default-deny gate because the per-CNP L4/L7-dispatch
4828 // pass never resolves through the axis-drifted traffic-
4829 // direction key. Peer to
4830 // [`cilium_key_endpoint_selector_re_export_points_at_caixa_core_canonical`]
4831 // + [`cilium_key_to_ports_re_export_points_at_caixa_core_canonical`]
4832 // on the sibling per-CNP-body-axis re-export set — completes
4833 // the per-CNP L3/L4/L7-triad
4834 // `(endpointSelector, ingress → toPorts → rules)` re-export
4835 // this crate's `cilium_network_policies` renderer's eBPF data-
4836 // plane contract rests on by lifting the traffic-direction
4837 // axis that structurally separates the destination-identity
4838 // axis from the port-set-container axis nested beneath it.
4839 // Peer to
4840 // [`cilium_kind_network_policy_re_export_points_at_caixa_core_canonical`]
4841 // + [`cilium_api_version_re_export_points_at_caixa_core_canonical`]
4842 // on the outer `(apiVersion, kind)` shell of the same per-CNP
4843 // CRD — extends the per-Cilium-CRD re-export set from the outer
4844 // shell down through the load-bearing `spec.ingress[]` traffic-
4845 // direction axis.
4846 caixa_core::assert_str_reexport_identity(
4847 "CILIUM_KEY_INGRESS",
4848 CILIUM_KEY_INGRESS,
4849 caixa_core::CILIUM_KEY_INGRESS,
4850 );
4851 }
4852
4853 #[test]
4854 fn cilium_key_from_endpoints_re_export_points_at_caixa_core_canonical() {
4855 // The renderer's `CILIUM_KEY_FROM_ENDPOINTS` was lifted from the
4856 // inline `"fromEndpoints"` literal at the `cilium_network_policies`
4857 // per-`(:de, :para)` CNP `ingress_rule.insert("fromEndpoints", …)`
4858 // call site plus four test-side navigations
4859 // (`cnp_from_endpoints_carries_program_plus_aplicacao_labels_two_axis_shape`
4860 // — the `.and_then(|i| i.get("fromEndpoints"))` navigation whose
4861 // downstream `.and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))` chain
4862 // reaches the source `LabelSelector`,
4863 // `cilium_policies_are_identity_based` — the paired
4864 // `.and_then(|i| i.get("fromEndpoints"))` navigation whose
4865 // `.expect("fromEndpoints[0].matchLabels mapping")` pins the
4866 // two-axis-selector shape,
4867 // `cnp_authentication_carries_mtls_overlay_at_ingress_rule_level`
4868 // — via both the `contains_key` presence check + the paired
4869 // `.get(…).and_then(|f| f.as_sequence())` navigation consulting
4870 // the same axis) to a re-export of
4871 // [`caixa_core::CILIUM_KEY_FROM_ENDPOINTS`] so the Cilium-CRD
4872 // per-ingress-rule identity-source axis-key string lives in
4873 // exactly one place across every caixa renderer. Pin the
4874 // equality + static-data identity here so any local
4875 // re-introduction of a sibling `pub const CILIUM_KEY_FROM_\
4876 // ENDPOINTS: &str = "…"` (the canonical drift footgun where a
4877 // sibling local `pub const` could happen to carry the same
4878 // string at the source while pointing at a different `&'static`
4879 // allocation) is a build-time test failure naming the offending
4880 // drift, not a silent apply-time symptom — the prior shape
4881 // would have let a Cilium-CRD schema rebrand on the identity-
4882 // source axis without a coordinated caixa-core edit silently
4883 // land per-`(:de, :para)` CiliumNetworkPolicy documents whose
4884 // `spec.ingress[].fromEndpoints[]` list the Cilium CRD schema
4885 // validator drops as unrecognized at apply time, with the
4886 // emitted ingress rule admitting no source pods and every
4887 // intra-mesh `:contratos` flow the affected CNP was authored to
4888 // allow dropping at the eBPF data plane's default-deny gate
4889 // because the per-CNP identity-resolution pass never binds
4890 // through the axis-drifted identity-source key. Peer to
4891 // [`cilium_key_endpoint_selector_re_export_points_at_caixa_core_canonical`]
4892 // on the sibling per-CNP-body-axis re-export set — completes
4893 // the per-CNP identity-pair
4894 // `(endpointSelector, fromEndpoints)` re-export this crate's
4895 // `cilium_network_policies` renderer's eBPF data-plane contract
4896 // rests on by lifting the identity-source axis structurally
4897 // paired with the destination-identity axis under the Cilium-
4898 // operator-side per-CNP SPIFFE-identity-bound access-control
4899 // contract. Peer to
4900 // [`cilium_kind_network_policy_re_export_points_at_caixa_core_canonical`]
4901 // + [`cilium_api_version_re_export_points_at_caixa_core_canonical`]
4902 // on the outer `(apiVersion, kind)` shell of the same per-CNP
4903 // CRD — extends the per-Cilium-CRD re-export set from the outer
4904 // shell down through the load-bearing
4905 // `spec.ingress[].fromEndpoints[]` identity-source axis.
4906 caixa_core::assert_str_reexport_identity(
4907 "CILIUM_KEY_FROM_ENDPOINTS",
4908 CILIUM_KEY_FROM_ENDPOINTS,
4909 caixa_core::CILIUM_KEY_FROM_ENDPOINTS,
4910 );
4911 }
4912
4913 #[test]
4914 fn cilium_key_ports_re_export_points_at_caixa_core_canonical() {
4915 // The renderer's `CILIUM_KEY_PORTS` was lifted from the inline
4916 // `"ports"` literal at the `cilium_network_policies` per-
4917 // `(:de, :para)` CNP `to_port.insert("ports", …)` call site
4918 // (caixa-mesh/src/lib.rs:1081 — the per-`toPorts[]`-entry L4
4919 // port-tuple-list emitter) plus two test-side navigations
4920 // (`cilium_pubsub_contracts_skip_l7_rules` — the
4921 // `to_ports.get("ports").is_some()` presence pin the L4-yes-L7-
4922 // no separation invariant hinges on;
4923 // `cnp_l4_fallback_port_reflects_default_servico_port` — the
4924 // `.and_then(|tp| tp.get("ports"))` navigation whose downstream
4925 // `.and_then(|s| s.first()).and_then(|p| p.get("port"))` chain
4926 // reads the per-port-set L4 port-tuple value the
4927 // `DEFAULT_SERVICO_PORT` fallback pins) to a re-export of
4928 // [`caixa_core::CILIUM_KEY_PORTS`] so the Cilium-CRD per-
4929 // `toPorts[]`-entry L4-port-tuple-list-container-axis-key
4930 // string lives in exactly one place across every caixa
4931 // renderer. Pin the equality + static-data identity here so any
4932 // local re-introduction of a sibling `pub const CILIUM_KEY_\
4933 // PORTS: &str = "…"` (the canonical drift footgun where a
4934 // sibling local `pub const` could happen to carry the same
4935 // string at the source while pointing at a different `&'static`
4936 // allocation) is a build-time test failure naming the offending
4937 // drift, not a silent apply-time symptom — the prior shape
4938 // would have let a Cilium-CRD schema rebrand on the L4 port-
4939 // tuple-list-container axis without a coordinated caixa-core
4940 // edit silently land per-`(:de, :para)` CiliumNetworkPolicy
4941 // documents whose `spec.ingress[].toPorts[].ports[]` list the
4942 // Cilium CRD schema validator drops as unrecognized at apply
4943 // time, with the emitted per-port-set entry admitting no
4944 // `(port, protocol)` tuple and every intra-mesh `:contratos`
4945 // flow the affected CNP was authored to allow dropping at the
4946 // eBPF data plane's default-deny gate because the per-CNP L4-
4947 // allow eBPF-program-generation pass never sources through the
4948 // axis-drifted L4-port-tuple-list-container key. Peer to
4949 // [`cilium_key_to_ports_re_export_points_at_caixa_core_canonical`]
4950 // on the sibling per-CNP-dispatch-axis re-export set — nests
4951 // the per-port-set L4 port-tuple-list-container axis
4952 // structurally beneath the sibling per-ingress-rule port-set-
4953 // container axis it lives inside, extending the per-CNP
4954 // L3/L4/L7-triad
4955 // `(endpointSelector, ingress → toPorts → ports / rules)`
4956 // re-export with the L4-half's port-tuple-list-container axis
4957 // this crate's `cilium_network_policies` renderer's eBPF data-
4958 // plane L4-allow contract rests on.
4959 caixa_core::assert_str_reexport_identity(
4960 "CILIUM_KEY_PORTS",
4961 CILIUM_KEY_PORTS,
4962 caixa_core::CILIUM_KEY_PORTS,
4963 );
4964 }
4965
4966 #[test]
4967 fn cilium_key_authentication_re_export_points_at_caixa_core_canonical() {
4968 // The renderer's `CILIUM_KEY_AUTHENTICATION` was lifted from
4969 // the inline `"authentication"` literal at the
4970 // `cilium_network_policies` per-`(:de, :para)` CNP
4971 // `ingress_rule.insert("authentication", …)` call site (the
4972 // per-ingress-rule mutual-auth emit gate the `:politicas
4973 // :mtls-required` overlay lands under) plus nine test-side
4974 // navigations: the presence pin under `:mtls-required t`, the
4975 // absence pin under `:mtls-required` unset (default),
4976 // the explicit-`Some(false)`-emits-`"disabled"`-mode pin, the
4977 // per-policy-fan-out pin across multiple `:contratos`, the
4978 // rule-level-position pin (with two nested-inside-negative
4979 // guards under `fromEndpoints[]` and `toPorts[]`), the pubsub-
4980 // contracts-carry-overlay-too shape pin, and the yaml-string-
4981 // scalar `mode`-value pin — to a re-export of
4982 // [`caixa_core::CILIUM_KEY_AUTHENTICATION`] so the Cilium-CRD
4983 // per-ingress-rule mutual-auth-body-axis-key string lives in
4984 // exactly one place across every caixa renderer. Pin the
4985 // equality + static-data identity here so any local
4986 // re-introduction of a sibling `pub const CILIUM_KEY_\
4987 // AUTHENTICATION: &str = "…"` (the canonical drift footgun
4988 // where a sibling local `pub const` could happen to carry the
4989 // same string at the source while pointing at a different
4990 // `&'static` allocation) is a build-time test failure naming
4991 // the offending drift, not a silent apply-time symptom — the
4992 // prior shape would have let a Cilium-CRD schema rebrand on
4993 // the per-ingress-rule mutual-auth axis without a coordinated
4994 // caixa-core edit silently land per-`(:de, :para)`
4995 // CiliumNetworkPolicy documents whose
4996 // `spec.ingress[].authentication` block the Cilium CRD schema
4997 // validator drops as unrecognized at apply time; the emitted
4998 // per-ingress-rule mutual-auth block falls back to the
4999 // cluster-default authentication mode and every intra-mesh
5000 // `:contratos` flow the CNP was authored to protect with
5001 // per-edge SPIFFE-identity-bound mutual-auth silently
5002 // bypasses the mTLS handshake at the Cilium data-plane's
5003 // default-authentication mode. Peer to
5004 // [`cilium_key_from_endpoints_re_export_points_at_caixa_core_canonical`]
5005 // + [`cilium_key_to_ports_re_export_points_at_caixa_core_canonical`]
5006 // on the sibling per-ingress-rule-body-axis re-export set —
5007 // completes the per-ingress-rule-body triple
5008 // `(fromEndpoints, toPorts, authentication)` this crate's
5009 // `cilium_network_policies` renderer's SPIFFE-identity-bound
5010 // per-edge mTLS contract rests on.
5011 caixa_core::assert_str_reexport_identity(
5012 "CILIUM_KEY_AUTHENTICATION",
5013 CILIUM_KEY_AUTHENTICATION,
5014 caixa_core::CILIUM_KEY_AUTHENTICATION,
5015 );
5016 }
5017
5018 #[test]
5019 fn cilium_key_mode_re_export_points_at_caixa_core_canonical() {
5020 // The renderer's `CILIUM_KEY_MODE` was lifted from the inline
5021 // `"mode"` literal at the `cilium_network_policies` per-`(:de,
5022 // :para)` CNP `single_field_overlay(spec.politicas.mtls_required,
5023 // "mode", …)` call site (the per-rule mutual-auth-mode-leaf
5024 // emit gate the `:politicas :mtls-required` overlay lands
5025 // under, which the helper writes at the single leaf axis of
5026 // the per-rule authentication block) plus five test-side
5027 // navigations: the presence pin under `:mtls-required t`, the
5028 // explicit-`Some(false)`-emits-`"disabled"`-mode pin, the
5029 // per-policy-fan-out pin across multiple `:contratos`, the
5030 // pubsub-contracts-carry-overlay-too shape pin, and the
5031 // yaml-string-scalar `mode`-value pin — to a re-export of
5032 // [`caixa_core::CILIUM_KEY_MODE`] so the Cilium-CRD per-
5033 // authentication-block mode-discriminator leaf-axis key string
5034 // lives in exactly one place across every caixa renderer. Pin
5035 // the equality + static-data identity here so any local
5036 // re-introduction of a sibling `pub const CILIUM_KEY_MODE:
5037 // &str = "…"` (the canonical drift footgun where a sibling
5038 // local `pub const` could happen to carry the same string at
5039 // the source while pointing at a different `&'static`
5040 // allocation) is a build-time test failure naming the
5041 // offending drift, not a silent apply-time symptom — the prior
5042 // shape would have let a Cilium-CRD schema rebrand on the per-
5043 // authentication-block mode-discriminator leaf axis without a
5044 // coordinated caixa-core edit silently land per-`(:de, :para)`
5045 // CiliumNetworkPolicy documents whose per-`ingress[]` entry
5046 // mutual-auth block's mode-leaf-key the Cilium CRD schema
5047 // validator drops as unrecognized at apply time; the ingress
5048 // rule falls back to the cluster-default authentication mode
5049 // and every intra-mesh `:contratos` flow the CNP was authored
5050 // to protect with per-edge SPIFFE-identity-bound mutual-auth
5051 // silently bypasses the mTLS handshake at the Cilium data-
5052 // plane's default-authentication mode. Peer to
5053 // [`cilium_key_authentication_re_export_points_at_caixa_core_canonical`]
5054 // on the parent per-ingress-rule mutual-auth-body-axis re-
5055 // export surface — completes the per-rule mutual-auth
5056 // `(authentication → mode)` body/leaf axis re-export pair this
5057 // crate's `cilium_network_policies` renderer's SPIFFE-identity-
5058 // bound per-edge mTLS enforcement contract rests on.
5059 caixa_core::assert_str_reexport_identity(
5060 "CILIUM_KEY_MODE",
5061 CILIUM_KEY_MODE,
5062 caixa_core::CILIUM_KEY_MODE,
5063 );
5064 }
5065
5066 #[test]
5067 fn cilium_auth_mode_required_re_export_points_at_caixa_core_canonical() {
5068 // The renderer's `CILIUM_AUTH_MODE_REQUIRED` was lifted from the
5069 // inline `"required"` scalar-value at the `cilium_network_policies`
5070 // per-`(:de, :para)` CNP `single_field_overlay(spec.politicas.
5071 // mtls_required, CILIUM_KEY_MODE, |required| …)` closure's
5072 // `if required { … }` affirmative arm (the per-rule mutual-auth-
5073 // mode-discriminator leaf value the Cilium agent's per-rule
5074 // dispatch loop keys off to select the SPIFFE-identity-handshake-
5075 // mandatory enforcement policy) plus three test-side navigations —
5076 // the presence pin under `:mtls-required t`, the per-policy fan-
5077 // out pin across multiple `:contratos`, and the pubsub-carry-
5078 // overlay-too shape pin — to a re-export of
5079 // [`caixa_core::CILIUM_AUTH_MODE_REQUIRED`] so the Cilium-CRD per-
5080 // rule mutual-auth-mandatory scalar-value string lives in exactly
5081 // one place across every caixa renderer. Pin the equality +
5082 // static-data identity here so any local re-introduction of a
5083 // sibling `pub const CILIUM_AUTH_MODE_REQUIRED: &str = "…"` (the
5084 // canonical drift footgun where a sibling local `pub const` could
5085 // happen to carry the same string at the source while pointing at
5086 // a different `&'static` allocation) is a build-time test failure
5087 // naming the offending drift, not a silent apply-time symptom —
5088 // the prior shape would have let a Cilium CNP
5089 // `MutualAuthenticationMode` OpenAPI schema enum rebrand on the
5090 // mTLS-mandatory scalar value without a coordinated caixa-core
5091 // edit silently land per-`(:de, :para)` CiliumNetworkPolicy
5092 // documents whose per-`ingress[]` entry mutual-auth block's mode
5093 // value the Cilium-agent-side schema validator drops as
5094 // unrecognized at apply time; the author's mTLS-mandatory intent
5095 // silently collapses onto the cluster-default authentication mode
5096 // and every intra-mesh `:contratos` flow the CNP was authored to
5097 // protect with per-edge SPIFFE-identity-bound mutual-auth silently
5098 // bypasses the mTLS handshake at the Cilium data-plane's default-
5099 // authentication mode. Peer to
5100 // [`cilium_auth_mode_disabled_re_export_points_at_caixa_core_canonical`]
5101 // on the explicit-opt-out arm of the same
5102 // `MutualAuthenticationMode` enum + to
5103 // [`cilium_key_mode_re_export_points_at_caixa_core_canonical`] on
5104 // the parent per-authn-block mode-discriminator leaf-axis-key re-
5105 // export surface — completes the per-authn-block `(mode →
5106 // {required, disabled})` author-reachable-scalar-value-pair re-
5107 // export pair this crate's `cilium_network_policies` renderer's
5108 // SPIFFE-identity-bound per-edge mTLS enforcement contract rests
5109 // on across the affirmative arm of the `:politicas :mtls-required`
5110 // tristate.
5111 caixa_core::assert_str_reexport_identity(
5112 "CILIUM_AUTH_MODE_REQUIRED",
5113 CILIUM_AUTH_MODE_REQUIRED,
5114 caixa_core::CILIUM_AUTH_MODE_REQUIRED,
5115 );
5116 }
5117
5118 #[test]
5119 fn cilium_auth_mode_disabled_re_export_points_at_caixa_core_canonical() {
5120 // Peer to `cilium_auth_mode_required_re_export_points_at_caixa_
5121 // core_canonical` on the `Some(false)` explicit-opt-out arm of
5122 // the same `:politicas :mtls-required` tristate: the renderer's
5123 // `CILIUM_AUTH_MODE_DISABLED` was lifted from the inline
5124 // `"disabled"` scalar-value at the `cilium_network_policies` per-
5125 // `(:de, :para)` CNP `single_field_overlay(...)` closure's `else
5126 // { … }` opt-out arm plus one test-side navigation (the
5127 // `cnp_explicit_mtls_required_false_emits_disabled_mode` explicit-
5128 // opt-out probe) to a re-export of
5129 // [`caixa_core::CILIUM_AUTH_MODE_DISABLED`] so the Cilium-CRD per-
5130 // rule mutual-auth-skipped scalar-value string lives in exactly
5131 // one place across every caixa renderer. Pin the equality +
5132 // static-data identity here so any local re-introduction of a
5133 // sibling `pub const CILIUM_AUTH_MODE_DISABLED: &str = "…"` is a
5134 // build-time test failure naming the offending drift, not a
5135 // silent apply-time symptom — the prior shape would have let a
5136 // rebrand silently erase the author's explicit-opt-out intent at
5137 // the emit boundary. Peer to
5138 // [`cilium_auth_mode_required_re_export_points_at_caixa_core_canonical`]
5139 // — the two per-arm re-export pins together complete the per-
5140 // authn-block `(mode → {required, disabled})` author-reachable-
5141 // scalar-value-pair single-sourcing.
5142 caixa_core::assert_str_reexport_identity(
5143 "CILIUM_AUTH_MODE_DISABLED",
5144 CILIUM_AUTH_MODE_DISABLED,
5145 caixa_core::CILIUM_AUTH_MODE_DISABLED,
5146 );
5147 }
5148
5149 #[test]
5150 fn m3_placement_estrategia_single_node_re_export_points_at_caixa_core_canonical() {
5151 // The `M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE` re-export was lifted
5152 // from the (author-facing but not yet emit-referenced by this
5153 // crate) inline `"SingleNode"` scalar the
5154 // [`caixa_core::aplicacao::PlacementStrategy::SingleNode`] variant
5155 // serializes as under [`caixa_core::M3_PLACEMENT_KEY_ESTRATEGIA`].
5156 // Pin the equality + static-data identity here so any local re-
5157 // introduction of a sibling `pub const M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE:
5158 // &str = "…"` is a build-time test failure naming the offending
5159 // drift, not a silent apply-time symptom at the aggregator's
5160 // per-entry strategy dispatch or the operator's reconcile posture
5161 // — the prior shape would have let an aplicacao-side variant
5162 // rename or `#[serde(rename_all = …)]` attribute silently rebrand
5163 // the emitted scalar under one spelling while every caixa-mesh
5164 // probe still checked another. Peer to
5165 // [`m3_placement_estrategia_replicated_re_export_points_at_caixa_core_canonical`]
5166 // and
5167 // [`m3_placement_estrategia_sharded_re_export_points_at_caixa_core_canonical`]
5168 // on the other two arms of the same closed
5169 // [`caixa_core::aplicacao::PlacementStrategy`] enum surface — the
5170 // three per-arm pins together complete the per-strategy
5171 // discriminator scalar-value single-sourcing across the M3
5172 // distribution-strategy dispatch axis.
5173 caixa_core::assert_str_reexport_identity(
5174 "M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE",
5175 M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE,
5176 caixa_core::M3_PLACEMENT_ESTRATEGIA_SINGLE_NODE,
5177 );
5178 }
5179
5180 #[test]
5181 fn m3_placement_estrategia_replicated_re_export_points_at_caixa_core_canonical() {
5182 // Peer of `m3_placement_estrategia_single_node_re_export_points_at_caixa_core_canonical`
5183 // on the every-cluster-active-active arm of the same
5184 // [`caixa_core::aplicacao::PlacementStrategy`] enum — the arm the
5185 // enum's `default()` maps to, so drift here silently rebrands the
5186 // substrate's default distribution posture across every Aplicacao
5187 // that never declares the slot explicitly. This is the same
5188 // constant the `programs_entry_placement_carries_strategy` probe
5189 // dispatches on (the sweep lands here at the sole author-facing
5190 // consumption site the M3.x roadmap has today).
5191 caixa_core::assert_str_reexport_identity(
5192 "M3_PLACEMENT_ESTRATEGIA_REPLICATED",
5193 M3_PLACEMENT_ESTRATEGIA_REPLICATED,
5194 caixa_core::M3_PLACEMENT_ESTRATEGIA_REPLICATED,
5195 );
5196 }
5197
5198 #[test]
5199 fn m3_placement_estrategia_sharded_re_export_points_at_caixa_core_canonical() {
5200 // Peer of the SingleNode / Replicated pins on the hash-keyed-
5201 // across-clusters arm of the same
5202 // [`caixa_core::aplicacao::PlacementStrategy`] enum — the one arm
5203 // on which the sibling [`caixa_core::M3_PLACEMENT_KEY_SHARD_KEY`]
5204 // sub-block is required (`AplicacaoSpec::validate_placement`
5205 // gates `shard_key.is_some() == matches!(estrategia, Sharded)` as
5206 // a structural partition of every validated Placement). Drift
5207 // here silently collapses the hash-keyed distribution back onto
5208 // the aggregator's default (Replicated) and every sharded
5209 // workload's per-entity routing invariant vanishes at the data
5210 // plane. This is the same constant the
5211 // `programs_entry_placement_carries_shard_key_when_sharded` probe
5212 // dispatches on.
5213 caixa_core::assert_str_reexport_identity(
5214 "M3_PLACEMENT_ESTRATEGIA_SHARDED",
5215 M3_PLACEMENT_ESTRATEGIA_SHARDED,
5216 caixa_core::M3_PLACEMENT_ESTRATEGIA_SHARDED,
5217 );
5218 }
5219
5220 #[test]
5221 fn cilium_key_http_re_export_points_at_caixa_core_canonical() {
5222 // The renderer's `CILIUM_KEY_HTTP` was lifted from the inline
5223 // `"http"` literal at the `cilium_network_policies` per-`(:de,
5224 // :para)` CNP `rules.insert("http", …)` call site in the
5225 // `WitTarget::Http` L7 introspection emit branch (the per-
5226 // `toPorts[]` L7-HTTP-rule-list-discriminator container-axis
5227 // emit the Cilium data plane's per-`toPorts[]` L7 dispatch pass
5228 // reads to source the per-`toPorts[]` L7 URL-path-prefix
5229 // predicate list the ingress rule was authored to filter each
5230 // HTTP-shaped `:contratos` flow through) plus two test-side
5231 // navigations: the L7-fan-in path-capture pin across the multi-
5232 // edge group and the per-HTTP-contract L7-path presence pin —
5233 // to a re-export of [`caixa_core::CILIUM_KEY_HTTP`] so the
5234 // Cilium-CRD per-`toPorts[]` L7-HTTP-rule-list-discriminator
5235 // container-axis key string lives in exactly one place across
5236 // every caixa renderer. Pin the equality + static-data identity
5237 // here so any local re-introduction of a sibling `pub const
5238 // CILIUM_KEY_HTTP: &str = "…"` (the canonical drift footgun
5239 // where a sibling local `pub const` could happen to carry the
5240 // same string at the source while pointing at a different
5241 // `&'static` allocation) is a build-time test failure naming
5242 // the offending drift, not a silent apply-time symptom — the
5243 // prior shape would have let a Cilium-CRD schema rebrand on
5244 // the per-`toPorts[]` L7-HTTP-rule-list-discriminator axis
5245 // without a coordinated caixa-core edit silently land per-
5246 // `(:de, :para)` CiliumNetworkPolicy documents whose per-
5247 // `toPorts[]` entry L7-HTTP-rule-list-discriminator container-
5248 // axis key the Cilium CRD schema validator drops as
5249 // unrecognized at apply time; the per-`toPorts[]` entry falls
5250 // back to L4-only enforcement — no L7 URL-path predicate is
5251 // applied — silently admitting every HTTP-method / URL-path
5252 // combination the ingress rule was authored to filter to the
5253 // exact path prefix set the typed `:contratos` graph names at
5254 // the L7 introspection axis. Peer to
5255 // [`cilium_key_mode_re_export_points_at_caixa_core_canonical`] /
5256 // [`cilium_key_authentication_re_export_points_at_caixa_core_canonical`]
5257 // on the sibling per-ingress-rule mutual-auth body/leaf axis
5258 // re-export pair — completes the per-`toPorts[]` L7-
5259 // introspection `(rules → http)` container/protocol-
5260 // discriminator axis re-export pair this crate's
5261 // `cilium_network_policies` renderer's HTTP-shaped-`:contratos`
5262 // URL-path-prefix-filtering L7-enforcement contract rests on.
5263 caixa_core::assert_str_reexport_identity(
5264 "CILIUM_KEY_HTTP",
5265 CILIUM_KEY_HTTP,
5266 caixa_core::CILIUM_KEY_HTTP,
5267 );
5268 }
5269
5270 #[test]
5271 fn cilium_key_path_re_export_points_at_caixa_core_canonical() {
5272 // The renderer's `CILIUM_KEY_PATH` was lifted from the inline
5273 // `"path"` literal at the `cilium_network_policies` per-`(:de,
5274 // :para)` CNP `http_rule.insert("path", …)` call site in the
5275 // `WitTarget::Http` L7 introspection emit branch (the per-
5276 // `rules.http[]` URL-path-predicate leaf-scalar-axis emit the
5277 // Cilium data plane's per-HTTP-rule L7 dispatch pass reads to
5278 // source the per-HTTP-rule URL-path predicate scalar the ingress
5279 // rule was authored to filter each HTTP-shaped `:contratos`
5280 // flow through) plus one test-side navigation: the per-HTTP-
5281 // rule URL-path-predicate presence-and-value pin on the
5282 // aplicacao fixture's cart→catalog HTTP-shaped `:contratos`
5283 // edge — to a re-export of [`caixa_core::CILIUM_KEY_PATH`] so
5284 // the Cilium-CRD per-`rules.http[]` URL-path-predicate leaf-
5285 // axis key string lives in exactly one place across every
5286 // caixa renderer. Pin the equality + static-data identity here
5287 // so any local re-introduction of a sibling `pub const
5288 // CILIUM_KEY_PATH: &str = "…"` (the canonical drift footgun
5289 // where a sibling local `pub const` could happen to carry the
5290 // same string at the source while pointing at a different
5291 // `&'static` allocation) is a build-time test failure naming
5292 // the offending drift, not a silent apply-time symptom — the
5293 // prior shape would have let a Cilium-CRD schema rebrand on
5294 // the per-`rules.http[]` URL-path-predicate leaf-axis without
5295 // a coordinated caixa-core edit silently land per-`(:de, :para)`
5296 // CiliumNetworkPolicy documents whose per-`rules.http[]` entry
5297 // URL-path-predicate leaf-axis key the Cilium CRD schema
5298 // validator drops as unrecognized at apply time; the per-
5299 // `rules.http[]` entry falls back to a match-any-URL-path
5300 // predicate — the per-`toPorts[]` L7 rule admits every URL
5301 // path on the destination port silently, bypassing the URL-
5302 // path-prefix predicate the typed `:contratos` HTTP-shaped
5303 // edge's `:endpoint` slot names at the L7 introspection axis,
5304 // with no field naming the URL-path-predicate-leaf-axis-drift
5305 // root cause. Peer to
5306 // [`cilium_key_http_re_export_points_at_caixa_core_canonical`]
5307 // on the parent per-`toPorts[]` L7-HTTP-rule-list-
5308 // discriminator container-axis re-export — descends the per-
5309 // `toPorts[]` L7-introspection `(rules → http → path)`
5310 // container / protocol-discriminator / URL-path-predicate axis
5311 // re-export chain one leaf level beneath the parent
5312 // `CILIUM_KEY_HTTP` per-`toPorts[]` L7-HTTP-rule-list-
5313 // discriminator re-export it nests inside, completing the per-
5314 // `toPorts[]` L7-introspection `(rules → http → path)`
5315 // container / protocol-discriminator / URL-path-predicate axis
5316 // re-export triple this crate's `cilium_network_policies`
5317 // renderer's HTTP-shaped-`:contratos` URL-path-prefix-
5318 // filtering L7-enforcement contract rests on. Distinct from
5319 // the sibling K8s-Gateway-API-side
5320 // [`gateway_api_key_path_re_export_points_at_caixa_core_canonical`]
5321 // — both re-exports carry the same underlying `"path"` string
5322 // but name distinct schema axes on distinct CRD groups (the
5323 // Cilium-side leaf on the `cilium.io/v2` `CiliumNetworkPolicy`
5324 // CRD's per-`rules.http[]` entry, the Gateway-API-side
5325 // container on the `gateway.networking.k8s.io/v1` `HTTPRoute`
5326 // CRD's `spec.rules[].matches[]` entry), so this test asserts
5327 // pointer-identity against the Cilium-side canonical
5328 // declaration (not the Gateway-API-side canonical declaration
5329 // the sibling re-export test asserts against), pinning the
5330 // axis-independence discipline the two sibling re-exports rest
5331 // on against a future coalescing edit that would erase the
5332 // per-CRD-group distinction.
5333 caixa_core::assert_str_reexport_identity(
5334 "CILIUM_KEY_PATH",
5335 CILIUM_KEY_PATH,
5336 caixa_core::CILIUM_KEY_PATH,
5337 );
5338 }
5339
5340 #[test]
5341 fn cilium_key_path_and_gateway_api_key_path_stay_independent_axes() {
5342 // Axis-independence pin: the Cilium-CRD per-`rules.http[]`
5343 // URL-path-predicate leaf-axis (`CILIUM_KEY_PATH`) and the K8s
5344 // Gateway API v1 `HTTPRoute` per-`HTTPRouteMatch` path-matcher
5345 // container-axis (`GATEWAY_API_KEY_PATH`) spell the same
5346 // underlying `"path"` string but name distinct schema axes on
5347 // distinct CRD groups (the Cilium-side leaf on the
5348 // `cilium.io/v2` `CiliumNetworkPolicy` CRD, the Gateway-API-
5349 // side container on the `gateway.networking.k8s.io/v1`
5350 // `HTTPRoute` CRD). Rust's `&'static str` interner coalesces
5351 // identical byte-sequences onto one storage allocation at
5352 // codegen time, so a pointer-identity assertion against
5353 // `.as_ptr()` between the two constants can't distinguish
5354 // "sibling `pub const` declarations carrying identical bytes"
5355 // from "coalesced canonical declaration" at runtime — the
5356 // axis-independence discipline this test names lives at the
5357 // rustc symbol-name axis (two separate `pub const` symbols
5358 // whose bindings a future rebrand of one leaves the other
5359 // structurally untouched) rather than the runtime-address
5360 // axis. Pin equality of the string bytes (so a downstream
5361 // consumer that expects `"path"` at either axis gets it),
5362 // pin equality of each half against its own caixa-core
5363 // canonical declaration (so the sibling
5364 // [`cilium_key_path_re_export_points_at_caixa_core_canonical`]
5365 // / [`gateway_api_key_path_re_export_points_at_caixa_core_canonical`]
5366 // re-export identity pins remain the load-bearing per-axis
5367 // "no sibling local `pub const` drift" gate this test rests
5368 // on, not this test itself), and let the two distinct
5369 // `pub const CILIUM_KEY_PATH` / `pub const GATEWAY_API_KEY_PATH`
5370 // symbol declarations carry the per-CRD-group axis-
5371 // independence at the type-symbol level any future rustc
5372 // codegen the substrate consumes preserves by construction.
5373 // A future coalescing edit collapsing the two symbols onto
5374 // one canonical declaration in caixa-core (the axis-
5375 // coalescence regression this pin names) would surface at
5376 // the sibling per-axis re-export identity pins — the local
5377 // `CILIUM_KEY_PATH` re-export would begin pointing at the
5378 // Gateway-API-side canonical declaration (or vice-versa),
5379 // fingering the offending axis on the sibling test's failure
5380 // message — rather than at this cross-axis pointer-identity
5381 // pin. So this test asserts the weaker string-equality
5382 // property that any future rustc string-interner behavior
5383 // preserves, and defers the load-bearing per-axis
5384 // "no sibling local `pub const` drift" gate to the sibling
5385 // per-axis re-export identity pins.
5386 assert_eq!(CILIUM_KEY_PATH, GATEWAY_API_KEY_PATH);
5387 assert_eq!(CILIUM_KEY_PATH, caixa_core::CILIUM_KEY_PATH);
5388 assert_eq!(GATEWAY_API_KEY_PATH, caixa_core::GATEWAY_API_KEY_PATH);
5389 }
5390
5391 #[test]
5392 fn cilium_l7_rule_list_carries_lifted_cilium_key_http() {
5393 // Production-emit pin: traverse a rendered CNP's
5394 // `spec.ingress[0].toPorts[0].rules` L7-rule-list-container
5395 // block and assert the L7-HTTP-rule-list-discriminator entry
5396 // is keyed by the lifted `CILIUM_KEY_HTTP` (`"http"`) verbatim
5397 // — the load-bearing per-`toPorts[]` L7-HTTP-rule-list-
5398 // discriminator container-axis key the Cilium data plane's
5399 // per-`toPorts[]` L7 dispatch pass reads to source the per-
5400 // `toPorts[]` L7 URL-path-prefix predicate list before applying
5401 // the per-request URL-path predicate against the observed
5402 // HTTP request line. Before the lift the emitter carried an
5403 // inline `"http".into()` literal at the sole `rules.insert(…)`
5404 // call site in the `WitTarget::Http` L7 introspection emit
5405 // branch; a typo there (`"HTTP"` / `"Http"` / `"httpRules"`)
5406 // would have silently landed a per-`toPorts[]` entry whose
5407 // L7-HTTP-rule-list-discriminator key the Cilium CRD schema
5408 // validator drops as unknown at admission, and the per-
5409 // `toPorts[]` entry would have fallen back to L4-only
5410 // enforcement — no L7 URL-path predicate applied — silently
5411 // admitting every HTTP-method / URL-path combination the
5412 // ingress rule was authored to filter to the exact path prefix
5413 // set the typed `:contratos` graph names at the L7
5414 // introspection axis, with no field naming the L7-HTTP-rule-
5415 // list-discriminator-drift root cause. Peer to
5416 // `cilium_port_tuple_carries_lifted_kube_protocol_tcp`'s per-
5417 // `toPorts[].ports[]` L4-transport-protocol scalar pin on the
5418 // sibling per-`toPorts[]` L4-tuple surface — extends the per-
5419 // `toPorts[]` L4-tuple-scalar pin discipline onto the sibling
5420 // per-`toPorts[]` L7-rule-list-container-axis pin surface
5421 // every `cilium_network_policies` intra-mesh L7-URL-path-
5422 // predicate-gating emit carries under the shared
5423 // `CiliumNetworkPolicy` body.
5424 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
5425 let rules = policies
5426 .iter()
5427 .find_map(|p| {
5428 p.get(KUBE_KEY_SPEC)
5429 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
5430 .and_then(|i| i.as_sequence())
5431 .and_then(|s| s.first())
5432 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
5433 .and_then(|p| p.as_sequence())
5434 .and_then(|s| s.iter().find(|tp| tp.get(KUBE_KEY_RULES).is_some()))
5435 .and_then(|tp| tp.get(KUBE_KEY_RULES))
5436 })
5437 .expect(
5438 "at least one per-`toPorts[]` entry emits a `rules` \
5439 L7-rule-list-container block on the aplicacao fixture's \
5440 HTTP-shaped `:contratos` edges",
5441 );
5442 assert!(
5443 rules.get(CILIUM_KEY_HTTP).is_some(),
5444 "per-`toPorts[]` `rules` L7-rule-list-container must carry \
5445 the lifted `CILIUM_KEY_HTTP` (`\"http\"`) L7-HTTP-rule-list-\
5446 discriminator key verbatim — the load-bearing Cilium CRD \
5447 per-`toPorts[]` L7-HTTP-rule-list-discriminator container-\
5448 axis key the Cilium data plane's per-`toPorts[]` L7 dispatch \
5449 pass reads to source the per-`toPorts[]` L7 URL-path-prefix \
5450 predicate list, got rules = {rules:?}"
5451 );
5452 }
5453
5454 #[test]
5455 fn kube_key_type_re_export_points_at_caixa_core_canonical() {
5456 // The renderer's `KUBE_KEY_TYPE` was lifted from the inline
5457 // `"type"` literal at the `gateway_routes` per-`HTTPRouteMatch`
5458 // `path_match.insert("type", …)` call site (the sole production-
5459 // code site the prior literal sat at — the per-`HTTPRouteMatch`
5460 // path-selection-predicate discriminator scalar-key the
5461 // gateway-class-controller's per-rule L7 dispatch pass reads to
5462 // source the path-match strategy from the closed
5463 // `PathMatchType` OpenAPI schema enum's
5464 // `{Exact, PathPrefix, RegularExpression}` set) to a re-export
5465 // of [`caixa_core::KUBE_KEY_TYPE`] so the K8s-CR discriminated-
5466 // union type scalar-discriminator key string lives in exactly
5467 // one place across every caixa renderer. Pin the equality +
5468 // static-data identity here so any local re-introduction of a
5469 // sibling `pub const KUBE_KEY_TYPE: &str = "…"` (the canonical
5470 // drift footgun where a sibling local `pub const` could happen
5471 // to carry the same string at the source while pointing at a
5472 // different `&'static` allocation) is a build-time test failure
5473 // naming the offending drift, not a silent apply-time symptom —
5474 // the prior shape would have let a K8s API conventions rebrand
5475 // on the caixa-mesh side without a coordinated caixa-core edit
5476 // silently land per-Aplicacao `HTTPRoute` documents whose per-
5477 // `HTTPRouteMatch` path-selection-predicate discriminator
5478 // scalar-key the Gateway API v1 `HTTPPathMatch` OpenAPI schema
5479 // validator drops as unknown at apply time; the per-match entry
5480 // falls back to the schema-side default path-match-strategy,
5481 // silently admitting every URL-path prefix the ingress rule was
5482 // authored to filter to the exact predicate the typed `:entrada
5483 // :paths` slot names at the request-path-selection axis. Peer to
5484 // [`gateway_api_path_match_type_path_prefix_re_export_points_at_caixa_core_canonical`]
5485 // on the sibling per-`HTTPRouteMatch` path-selection-predicate
5486 // discriminator scalar-VALUE axis re-export — closes the per-
5487 // `HTTPRouteMatch` path-selection-predicate `(type key →
5488 // PathPrefix value)` scalar-key/scalar-value discriminator axis
5489 // pair this crate's `gateway_routes` renderer's external
5490 // `:entrada` per-path L7-filtering ingress contract rests on.
5491 caixa_core::assert_str_reexport_identity(
5492 "KUBE_KEY_TYPE",
5493 KUBE_KEY_TYPE,
5494 caixa_core::KUBE_KEY_TYPE,
5495 );
5496 }
5497
5498 #[test]
5499 fn httproute_path_match_carries_lifted_kube_key_type() {
5500 // Production-emit pin: traverse a rendered `HTTPRoute`'s per-
5501 // `HTTPRouteMatch` `spec.rules[].matches[].path` mapping and
5502 // assert the path-selection-predicate discriminator entry is
5503 // keyed by the lifted `KUBE_KEY_TYPE` (`"type"`) verbatim — the
5504 // load-bearing per-`HTTPRouteMatch` path-selection-predicate
5505 // discriminator scalar-key the gateway-class-controller's per-
5506 // rule L7 dispatch pass reads to source the path-match strategy
5507 // (the closed `PathMatchType` OpenAPI schema enum's `{Exact,
5508 // PathPrefix, RegularExpression}` set) before applying the per-
5509 // match request-path predicate against the observed HTTP request
5510 // line's `:path` pseudo-header. Before the lift the emitter
5511 // carried an inline `"type".into()` literal at the sole
5512 // `path_match.insert(…)` call site in the `gateway_routes` per-
5513 // path iteration; a typo there (`"Type"` / `"kind"` /
5514 // `"discriminator"` / `"predicate"`) would have silently landed
5515 // a per-match entry whose path-selection-predicate discriminator
5516 // scalar-key the Gateway API v1 `HTTPPathMatch` OpenAPI schema
5517 // validator drops as unknown at admission, and the per-match
5518 // entry would have fallen back to the schema-side default path-
5519 // match-strategy — silently admitting every URL-path prefix the
5520 // ingress rule was authored to filter to the exact predicate the
5521 // typed `:entrada :paths` slot names at the request-path-
5522 // selection axis, with no field naming the discriminator-scalar-
5523 // key-drift root cause. Peer to
5524 // `cilium_l7_rule_list_carries_lifted_cilium_key_http`'s per-
5525 // `toPorts[]` L7-HTTP-rule-list-discriminator container-axis
5526 // pin on the sibling per-`toPorts[]` L7-rule-list-container
5527 // surface — extends the per-CRD-body-axis lifted-uses pin
5528 // discipline onto the sibling per-`HTTPRouteMatch` path-
5529 // selection-predicate discriminator scalar-key axis every
5530 // `gateway_routes` external `:entrada` per-path L7-filtering
5531 // emit carries under the shared `HTTPRoute` body.
5532 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
5533 let rules = httproute_rules(&docs);
5534 assert!(
5535 !rules.is_empty(),
5536 "HTTPRoute must carry at least one rule the per-match path-\
5537 selection-predicate discriminator scalar-key nests under"
5538 );
5539 for rule in &rules {
5540 let matches = rule
5541 .get(caixa_core::GATEWAY_API_KEY_MATCHES)
5542 .and_then(|m| m.as_sequence())
5543 .expect("HTTPRoute per-rule spec.rules[].matches sequence");
5544 for m in matches {
5545 let path = m
5546 .get(caixa_core::GATEWAY_API_KEY_PATH)
5547 .and_then(|p| p.as_mapping())
5548 .expect(
5549 "HTTPRoute per-match spec.rules[].matches[].path must be \
5550 navigable through the lifted GATEWAY_API_KEY_PATH constant",
5551 );
5552 assert!(
5553 path.get(KUBE_KEY_TYPE).is_some(),
5554 "per-`HTTPRouteMatch` `path` block must carry \
5555 the lifted `KUBE_KEY_TYPE` (`\"type\"`) path-\
5556 selection-predicate discriminator scalar-key \
5557 verbatim — the load-bearing Gateway API v1 \
5558 HTTPPathMatch canonical discriminator-key axis \
5559 the gateway-class-controller's per-rule L7 \
5560 dispatch pass reads to source the path-match \
5561 strategy, got path = {path:?}"
5562 );
5563 }
5564 }
5565 }
5566
5567 #[test]
5568 fn gateway_api_kind_gateway_re_export_points_at_caixa_core_canonical() {
5569 // The renderer's `GATEWAY_API_KIND_GATEWAY` was lifted from the
5570 // inline `"Gateway"` literal at the `gateway_routes`
5571 // `kube_resource_skeleton` kind argument
5572 // (caixa-mesh/src/lib.rs:578 — the per-Aplicacao Gateway emit
5573 // site) to a re-export of [`caixa_core::GATEWAY_API_KIND_GATEWAY`]
5574 // so the Gateway-API-conformant CRD `kind` discriminator string
5575 // lives in exactly one place across every caixa renderer. Pin
5576 // the equality + static-data identity here so any local
5577 // re-introduction of a sibling
5578 // `pub const GATEWAY_API_KIND_GATEWAY: &str = "…"` (the canonical
5579 // drift footgun where a sibling local `pub const` could happen
5580 // to carry the same string at the source while pointing at a
5581 // different `&'static` allocation) is a build-time test failure
5582 // naming the offending drift, not a silent apply-time symptom —
5583 // the prior shape would have let a Gateway-API kind rebrand on
5584 // the caixa-mesh side without a coordinated caixa-core edit
5585 // silently land per-Aplicacao Gateway objects at one CRD kind
5586 // and every future per-target Gateway-API-side renderer's
5587 // emitted `GatewayClass` / `TCPRoute` / `TLSRoute` / `GRPCRoute`
5588 // at the drifted other, with every external `:entrada` flow
5589 // dropping at the gateway-class-controller's reconcile loop
5590 // because the per-route attached-policy pipeline never binds
5591 // across the kind-drifted CRD-discriminator pair. Peer to
5592 // [`gateway_api_api_version_re_export_points_at_caixa_core_canonical`]
5593 // on the sibling Gateway-API-CRD-apiVersion-re-export axis —
5594 // begins the per-Gateway-API-CRD kind+apiVersion re-export pair
5595 // this crate's `gateway_routes` renderer's external `:entrada`
5596 // ingress contract rests on. Peer to
5597 // [`cilium_kind_network_policy_re_export_points_at_caixa_core_canonical`]
5598 // on the sibling Cilium-CRD-kind-discriminator re-export axis.
5599 caixa_core::assert_str_reexport_identity(
5600 "GATEWAY_API_KIND_GATEWAY",
5601 GATEWAY_API_KIND_GATEWAY,
5602 caixa_core::GATEWAY_API_KIND_GATEWAY,
5603 );
5604 }
5605
5606 #[test]
5607 fn gateway_api_kind_http_route_re_export_points_at_caixa_core_canonical() {
5608 // The renderer's `GATEWAY_API_KIND_HTTP_ROUTE` was lifted from
5609 // the inline `"HTTPRoute"` literal at the `gateway_routes`
5610 // `kube_resource_skeleton` kind argument
5611 // (caixa-mesh/src/lib.rs:663 — the per-Aplicacao HTTPRoute emit
5612 // site) to a re-export of
5613 // [`caixa_core::GATEWAY_API_KIND_HTTP_ROUTE`] so the
5614 // Gateway-API-conformant CRD `kind` discriminator string lives
5615 // in exactly one place across every caixa renderer. Pin the
5616 // equality + static-data identity here so any local
5617 // re-introduction of a sibling
5618 // `pub const GATEWAY_API_KIND_HTTP_ROUTE: &str = "…"` (the
5619 // canonical drift footgun where a sibling local `pub const`
5620 // could happen to carry the same string at the source while
5621 // pointing at a different `&'static` allocation) is a
5622 // build-time test failure naming the offending drift, not a
5623 // silent apply-time symptom — the prior shape would have let a
5624 // Gateway-API kind rebrand on the caixa-mesh side without a
5625 // coordinated caixa-core edit silently land per-Aplicacao
5626 // HTTPRoute objects at one CRD kind and every future
5627 // per-target Gateway-API-side renderer's emitted `TCPRoute` /
5628 // `TLSRoute` / `GRPCRoute` at the drifted other, with every
5629 // external `:entrada` flow dropping at the
5630 // gateway-class-controller's reconcile loop because the
5631 // per-route attached-policy pipeline never binds across the
5632 // kind-drifted CRD-discriminator pair. Peer to
5633 // [`gateway_api_kind_gateway_re_export_points_at_caixa_core_canonical`]
5634 // on the sibling parent-Gateway-`kind`-discriminator re-export
5635 // axis — completes the per-Gateway-API-CRD `kind`-axis
5636 // re-export pair this crate's `gateway_routes` renderer's
5637 // external `:entrada` ingress contract rests on across the
5638 // `(Gateway, HTTPRoute)` pair the renderer emits together.
5639 caixa_core::assert_str_reexport_identity(
5640 "GATEWAY_API_KIND_HTTP_ROUTE",
5641 GATEWAY_API_KIND_HTTP_ROUTE,
5642 caixa_core::GATEWAY_API_KIND_HTTP_ROUTE,
5643 );
5644 }
5645
5646 #[test]
5647 fn gateway_api_protocol_http_re_export_points_at_caixa_core_canonical() {
5648 // The renderer's `GATEWAY_API_PROTOCOL_HTTP` was lifted from the
5649 // inline `"HTTP".into()` literal at the `gateway_routes`
5650 // per-`:entrada` `Gateway`'s per-listener `KUBE_KEY_PROTOCOL`
5651 // scalar-value emit (caixa-mesh/src/lib.rs:2165 — the sole
5652 // production-code call site the prior literal sat at) to a
5653 // re-export of [`caixa_core::GATEWAY_API_PROTOCOL_HTTP`] so the
5654 // Gateway-API-v1-`ProtocolType`-conformant HTTP listener-protocol
5655 // scalar value string lives in exactly one place across every
5656 // caixa renderer. Pin the equality + static-data identity here
5657 // so any local re-introduction of a sibling
5658 // `pub const GATEWAY_API_PROTOCOL_HTTP: &str = "…"` (the
5659 // canonical drift footgun where a sibling local `pub const`
5660 // could happen to carry the same string at the source while
5661 // pointing at a different `&'static` allocation) is a
5662 // build-time test failure naming the offending drift, not a
5663 // silent apply-time symptom — the prior shape would have let a
5664 // Gateway-API `ProtocolType` rebrand on the caixa-mesh side
5665 // without a coordinated caixa-core edit silently land per-
5666 // `:entrada` `Gateway` objects at one listener-protocol scalar
5667 // and every future per-Aplicacao multi-listener fan-out
5668 // renderer's emitted `Gateway` at the drifted other, with every
5669 // external `:entrada` HTTP flow dropping at the gateway-class-
5670 // controller's admission gate because the K8s Gateway API v1
5671 // `ProtocolType` OpenAPI schema enum only admits the closed set
5672 // `{"HTTP", "HTTPS", "TCP", "TLS", "UDP"}` verbatim. Peer to
5673 // [`gateway_api_kind_gateway_re_export_points_at_caixa_core_canonical`]
5674 // + [`gateway_api_kind_http_route_re_export_points_at_caixa_core_canonical`]
5675 // on the sibling per-Gateway-API-CRD-`kind`-discriminator
5676 // re-export pair + [`default_gateway_class_name_re_export_points_at_caixa_core_canonical`]
5677 // on the sibling Gateway-controller-binding-scalar-value axis —
5678 // extends the pair of `kind`-value + controller-binding-value
5679 // re-export drift pins across the `(Gateway, HTTPRoute)` pair
5680 // onto the sibling per-Gateway `spec.listeners[].protocol`
5681 // listener-protocol-scalar-value axis this crate's
5682 // `gateway_routes` renderer's external `:entrada` ingress
5683 // contract rests on.
5684 caixa_core::assert_str_reexport_identity(
5685 "GATEWAY_API_PROTOCOL_HTTP",
5686 GATEWAY_API_PROTOCOL_HTTP,
5687 caixa_core::GATEWAY_API_PROTOCOL_HTTP,
5688 );
5689 }
5690
5691 #[test]
5692 fn gateway_api_path_match_type_path_prefix_re_export_points_at_caixa_core_canonical() {
5693 // The renderer's `GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX` was
5694 // lifted from the inline `"PathPrefix".into()` literal at the
5695 // `gateway_routes` per-match `path_match.insert("type", …)`
5696 // per-`HTTPRouteMatch` path-selection-predicate scalar-value
5697 // emit (the sole production-code call site the prior literal
5698 // sat at) to a re-export of
5699 // [`caixa_core::GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] so
5700 // the Gateway-API-v1-`PathMatchType`-conformant per-match
5701 // request-path-selection-predicate discriminator scalar value
5702 // string lives in exactly one place across every caixa
5703 // renderer. Pin the equality + static-data identity here so any
5704 // local re-introduction of a sibling
5705 // `pub const GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX: &str =
5706 // "…"` (the canonical drift footgun where a sibling local
5707 // `pub const` could happen to carry the same string at the
5708 // source while pointing at a different `&'static` allocation)
5709 // is a build-time test failure naming the offending drift, not
5710 // a silent apply-time symptom — the prior shape would have let
5711 // a Gateway-API `PathMatchType` rebrand on the caixa-mesh side
5712 // without a coordinated caixa-core edit silently land per-
5713 // `:entrada` `HTTPRoute` objects at one path-selection-
5714 // predicate scalar and every future per-Aplicacao multi-
5715 // predicate fan-out renderer's emitted `HTTPRoute` at the
5716 // drifted other, with every external `:entrada` path-filtered
5717 // flow dropping at the gateway-class-controller's admission
5718 // gate because the K8s Gateway API v1 `PathMatchType` OpenAPI
5719 // schema enum only admits the closed set
5720 // `{"Exact", "PathPrefix", "RegularExpression"}` verbatim. Peer
5721 // to
5722 // [`gateway_api_protocol_http_re_export_points_at_caixa_core_canonical`]
5723 // on the sibling per-Gateway-listener L7-parser-selection
5724 // scalar-value re-export axis — extends the canonical-Gateway-
5725 // API-v1-OpenAPI-schema-enum-value re-export drift pin the
5726 // `ProtocolType.HTTP` re-export pin established onto the
5727 // sibling `PathMatchType.PathPrefix` per-`HTTPRouteMatch`
5728 // path-selection-predicate discriminator this crate's
5729 // `gateway_routes` renderer's external `:entrada` ingress
5730 // contract rests on under the shared `HTTPRoute` body.
5731 caixa_core::assert_str_reexport_identity(
5732 "GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX",
5733 GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX,
5734 caixa_core::GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX,
5735 );
5736 }
5737
5738 #[test]
5739 fn default_gateway_class_name_re_export_points_at_caixa_core_canonical() {
5740 // The renderer's `DEFAULT_GATEWAY_CLASS_NAME` was lifted from the
5741 // inline `"cilium".into()` literal at the `gateway_routes`
5742 // per-`:entrada` `Gateway` `spec.gatewayClassName` field to a
5743 // re-export of [`caixa_core::DEFAULT_GATEWAY_CLASS_NAME`] so the
5744 // substrate's chosen K8s Gateway API controller-discriminator
5745 // lives in exactly one place across every caixa renderer. Pin
5746 // the equality + static-data identity here so any local
5747 // re-introduction of a sibling
5748 // `pub const DEFAULT_GATEWAY_CLASS_NAME: &str = "…"` (the
5749 // canonical drift footgun where a sibling local `pub const`
5750 // could happen to carry the same string at the source while
5751 // pointing at a different `&'static` allocation) is a
5752 // build-time test failure naming the offending drift, not a
5753 // silent apply-time symptom — the prior shape would have let a
5754 // substrate-side Gateway API controller migration on the
5755 // caixa-mesh side without a coordinated caixa-core edit
5756 // silently land per-`:entrada` `Gateway` objects at one
5757 // `gatewayClassName` and every future per-Aplicacao
5758 // materializer's emitted `Gateway` at the drifted other, with
5759 // every external `:entrada` flow dropping at the
5760 // gateway-class-controller's reconcile loop because the
5761 // per-route attached-policy pipeline never binds across the
5762 // controller-drifted `spec.gatewayClassName` pair. And
5763 // splitting the Gateway controller across renderers would
5764 // silently reintroduce the two-data-planes drift the mesh
5765 // composition "one identity layer, one data plane" invariant
5766 // (MESH-COMPOSITION.md §V) closes — the emitted `Gateway`'s
5767 // controller and the sibling `CiliumNetworkPolicy`'s eBPF
5768 // reconciler would land in distinct data planes, and the
5769 // intra-mesh identity-aware policy would stop matching the
5770 // ingress-side traffic at the eBPF data plane. Peer to
5771 // [`default_namespace_re_export_points_at_caixa_core_canonical`]
5772 // on the sibling canonical-substrate-default-resource-name
5773 // re-export axis.
5774 caixa_core::assert_str_reexport_identity(
5775 "DEFAULT_GATEWAY_CLASS_NAME",
5776 DEFAULT_GATEWAY_CLASS_NAME,
5777 caixa_core::DEFAULT_GATEWAY_CLASS_NAME,
5778 );
5779 }
5780
5781 #[test]
5782 fn gateway_api_key_gateway_class_name_re_export_points_at_caixa_core_canonical() {
5783 // The renderer's `GATEWAY_API_KEY_GATEWAY_CLASS_NAME` was
5784 // lifted from the inline `"gatewayClassName"` literal at the
5785 // `gateway_routes` per-Aplicacao Gateway's
5786 // `g_spec.insert("gatewayClassName", …)` call site
5787 // (caixa-mesh/src/lib.rs:2060 — the sole per-production-code
5788 // controller-binding-scalar-axis-KEY emitter) to a re-export
5789 // of [`caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME`] so
5790 // the Gateway-API-CRD per-Gateway controller-binding-scalar-
5791 // axis-key string lives in exactly one place across every
5792 // caixa renderer. Pin the equality + static-data identity
5793 // here so any local re-introduction of a sibling
5794 // `pub const GATEWAY_API_KEY_GATEWAY_CLASS_NAME: &str = "…"`
5795 // (the canonical drift footgun where a sibling local
5796 // `pub const` could happen to carry the same string at the
5797 // source while pointing at a different `&'static` allocation)
5798 // is a build-time test failure naming the offending drift,
5799 // not a silent apply-time symptom — the prior shape would
5800 // have let a Gateway-API-CRD controller-binding-axis rebrand
5801 // on the caixa-mesh side without a coordinated caixa-core
5802 // edit silently land per-Aplicacao Gateway objects at one
5803 // controller-binding key and every future per-Aplicacao
5804 // materializer's emitted `Gateway` at the drifted other,
5805 // with every external `:entrada` flow dropping at the
5806 // gateway-class-controller's reconcile loop because the
5807 // per-Gateway `GatewayClass` lookup never binds across the
5808 // KEY-drifted controller-binding-axis pair. Peer to
5809 // [`default_gateway_class_name_re_export_points_at_caixa_core_canonical`]
5810 // on the sibling canonical-Gateway-API-`(key, value)`-pair-
5811 // lift re-export axis this pin closes the KEY half of, and
5812 // to
5813 // [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
5814 // on the sibling per-Gateway-body-axis re-export surface.
5815 caixa_core::assert_str_reexport_identity(
5816 "GATEWAY_API_KEY_GATEWAY_CLASS_NAME",
5817 GATEWAY_API_KEY_GATEWAY_CLASS_NAME,
5818 caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME,
5819 );
5820 }
5821
5822 #[test]
5823 fn gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical() {
5824 // The renderer's `GATEWAY_API_KEY_PARENT_REFS` was lifted from
5825 // the inline `"parentRefs"` literal at the `gateway_routes`
5826 // per-Aplicacao HTTPRoute's `r_spec.insert("parentRefs", …)`
5827 // call site (caixa-mesh/src/lib.rs:1389 — the sole per-
5828 // production-code parent-Gateway-binding-container-axis
5829 // emitter) to a re-export of
5830 // [`caixa_core::GATEWAY_API_KEY_PARENT_REFS`] so the
5831 // Gateway-API-CRD per-HTTPRoute parent-Gateway-binding-
5832 // container-axis-key string lives in exactly one place across
5833 // every caixa renderer. Pin the equality + static-data
5834 // identity here so any local re-introduction of a sibling
5835 // `pub const GATEWAY_API_KEY_PARENT_REFS: &str = "…"` (the
5836 // canonical drift footgun where a sibling local `pub const`
5837 // could happen to carry the same string at the source while
5838 // pointing at a different `&'static` allocation) is a
5839 // build-time test failure naming the offending drift, not a
5840 // silent apply-time symptom — the prior shape would have let a
5841 // Gateway-API-CRD parent-Gateway-binding-axis rebrand on the
5842 // caixa-mesh side without a coordinated caixa-core edit
5843 // silently land per-HTTPRoute parent-Gateway attachments at
5844 // the drifted axis; the route lands unattached, and every
5845 // external `:entrada` flow drops at the Gateway API
5846 // implementation's per-Gateway HTTP-listener fan-in with no
5847 // field naming the parent-Gateway-binding-drift root cause.
5848 // Peer to
5849 // [`cilium_key_ports_re_export_points_at_caixa_core_canonical`]
5850 // /
5851 // [`gateway_api_kind_http_route_re_export_points_at_caixa_core_canonical`]
5852 // /
5853 // [`gateway_api_kind_gateway_re_export_points_at_caixa_core_canonical`]
5854 // on the sibling canonical-K8s-CRD-body-axis re-export set —
5855 // begins the per-Gateway-API-HTTPRoute-body-axis re-export
5856 // identity-pin set (`parentRefs`, future `hostnames`) this
5857 // crate's `gateway_routes` renderer's external `:entrada`
5858 // ingress contract rests on across the Gateway API HTTPRoute-
5859 // side per-route body-shape.
5860 caixa_core::assert_str_reexport_identity(
5861 "GATEWAY_API_KEY_PARENT_REFS",
5862 GATEWAY_API_KEY_PARENT_REFS,
5863 caixa_core::GATEWAY_API_KEY_PARENT_REFS,
5864 );
5865 }
5866
5867 #[test]
5868 fn gateway_api_key_section_name_re_export_points_at_caixa_core_canonical() {
5869 // The renderer's `GATEWAY_API_KEY_SECTION_NAME` was lifted from
5870 // the (previously omitted) per-parentRef listener-selector sub-
5871 // axis at the `gateway_routes` per-Aplicacao HTTPRoute's
5872 // `parent_ref.insert(GATEWAY_API_KEY_SECTION_NAME,
5873 // GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME)` call site (the sole
5874 // per-production-code per-parentRef listener-selector-sub-axis
5875 // emitter) to a re-export of
5876 // [`caixa_core::GATEWAY_API_KEY_SECTION_NAME`] so the Gateway-
5877 // API-CRD per-HTTPRoute per-parentRef listener-selector-sub-
5878 // axis-key string lives in exactly one place across every caixa
5879 // renderer. Pin the equality + static-data identity here so any
5880 // local re-introduction of a sibling
5881 // `pub const GATEWAY_API_KEY_SECTION_NAME: &str = "…"` (the
5882 // canonical drift footgun where a sibling local `pub const`
5883 // could happen to carry the same string at the source while
5884 // pointing at a different `&'static` allocation) is a build-
5885 // time test failure naming the offending drift, not a silent
5886 // apply-time symptom — the prior shape (the selector omitted
5887 // entirely) would have let a Gateway-API-CRD per-parentRef
5888 // listener-selector-axis rebrand on the caixa-mesh side without
5889 // a coordinated caixa-core edit silently land per-HTTPRoute
5890 // parent-Gateway attachments at the drifted axis; the route
5891 // reverts to the Gateway API v1 attach-to-every-listener
5892 // default fan-out, silently doubling per-request dispatch
5893 // surface once a second listener lands on the parent Gateway
5894 // (the HTTPS-by-default trajectory the paired
5895 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] docstring
5896 // forecasts). Peer to
5897 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
5898 // on the sibling canonical-Gateway-API-HTTPRoute-body-axis re-
5899 // export identity-pin set — nests the per-Gateway-API-
5900 // HTTPRoute-body-axis re-export identity-pin set (`parentRefs`,
5901 // `backendRefs`, future `hostnames`) one level deeper onto the
5902 // per-parentRef listener-selector sub-axis this crate's
5903 // `gateway_routes` renderer's external `:entrada` ingress
5904 // contract now rests on across the Gateway API HTTPRoute-side
5905 // per-parentRef body-shape.
5906 caixa_core::assert_str_reexport_identity(
5907 "GATEWAY_API_KEY_SECTION_NAME",
5908 GATEWAY_API_KEY_SECTION_NAME,
5909 caixa_core::GATEWAY_API_KEY_SECTION_NAME,
5910 );
5911 // Pin the byte-shape too so a future Gateway API v2 rebrand of
5912 // the per-parentRef listener-selector sub-axis (an upstream
5913 // SIG-Network Gateway API v2 rename to `listenerName` /
5914 // `listener` / `attachTo`) surfaces here as an explicit
5915 // byte-shape drift rather than a silent per-consumer dispatch
5916 // miss at the K8s apiserver-side CRD schema validator.
5917 assert_eq!(GATEWAY_API_KEY_SECTION_NAME, "sectionName");
5918 }
5919
5920 #[test]
5921 fn gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical() {
5922 // The renderer's `GATEWAY_API_KEY_BACKEND_REFS` was lifted from
5923 // the inline `"backendRefs"` literal at the `gateway_routes`
5924 // per-Aplicacao HTTPRoute's per-rule
5925 // `rule.insert("backendRefs", …)` call site (the sole per-
5926 // production-code per-rule backend-destination-container-axis
5927 // emitter) plus the matching test-side fixture sites
5928 // (`httproute_routes_to_entrada_para`'s `.get("backendRefs")`
5929 // navigation + `httproute_rule_keys_pin_overlay_position`'s
5930 // `contains_key("backendRefs")` presence pin) to a re-export of
5931 // [`caixa_core::GATEWAY_API_KEY_BACKEND_REFS`] so the Gateway-
5932 // API-CRD per-HTTPRoute per-rule backend-destination-container-
5933 // axis-key string lives in exactly one place across every caixa
5934 // renderer. Pin the equality + static-data identity here so any
5935 // local re-introduction of a sibling
5936 // `pub const GATEWAY_API_KEY_BACKEND_REFS: &str = "…"` (the
5937 // canonical drift footgun where a sibling local `pub const`
5938 // could happen to carry the same string at the source while
5939 // pointing at a different `&'static` allocation) is a
5940 // build-time test failure naming the offending drift, not a
5941 // silent apply-time symptom — the prior shape would have let a
5942 // Gateway-API-CRD per-rule backend-destination-axis rebrand on
5943 // the caixa-mesh side without a coordinated caixa-core edit
5944 // silently land per-rule backend fan-outs at the drifted axis;
5945 // no backend is picked at the per-rule L7 dispatch, and every
5946 // external `:entrada` request drops at the gateway-class-
5947 // controller's per-rule reconcile with no field naming the
5948 // backend-destination-drift root cause. Peer to
5949 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
5950 // on the sibling canonical-Gateway-API-HTTPRoute-body-axis re-
5951 // export set — extends the per-Gateway-API-HTTPRoute-body-axis
5952 // re-export identity-pin set (`parentRefs`, `backendRefs`,
5953 // future `hostnames`) this crate's `gateway_routes` renderer's
5954 // external `:entrada` ingress contract rests on across the
5955 // Gateway API HTTPRoute-side per-route body-shape.
5956 caixa_core::assert_str_reexport_identity(
5957 "GATEWAY_API_KEY_BACKEND_REFS",
5958 GATEWAY_API_KEY_BACKEND_REFS,
5959 caixa_core::GATEWAY_API_KEY_BACKEND_REFS,
5960 );
5961 }
5962
5963 #[test]
5964 fn gateway_api_key_matches_re_export_points_at_caixa_core_canonical() {
5965 // The renderer's `GATEWAY_API_KEY_MATCHES` was lifted from the
5966 // inline `"matches"` literal at the `gateway_routes` per-
5967 // Aplicacao HTTPRoute's per-rule
5968 // `rule.insert("matches", …)` call site (the sole per-
5969 // production-code per-rule route-match-container-axis
5970 // emitter) plus the matching test-side fixture site
5971 // (`httproute_rule_keys_pin_overlay_position`'s
5972 // `contains_key("matches")` presence pin) to a re-export of
5973 // [`caixa_core::GATEWAY_API_KEY_MATCHES`] so the Gateway-API-
5974 // CRD per-HTTPRoute per-rule route-match-container-axis-key
5975 // string lives in exactly one place across every caixa
5976 // renderer. Pin the equality + static-data identity here so
5977 // any local re-introduction of a sibling
5978 // `pub const GATEWAY_API_KEY_MATCHES: &str = "…"` (the
5979 // canonical drift footgun where a sibling local `pub const`
5980 // could happen to carry the same string at the source while
5981 // pointing at a different `&'static` allocation) is a
5982 // build-time test failure naming the offending drift, not a
5983 // silent apply-time symptom — the prior shape would have let
5984 // a Gateway-API-CRD per-rule route-match-axis rebrand on the
5985 // caixa-mesh side without a coordinated caixa-core edit
5986 // silently land per-rule request-selection predicates at the
5987 // drifted axis; the per-rule predicate degrades to the
5988 // wildcard match, the rule matches every request
5989 // unconditionally, and every external `:entrada` path filter
5990 // drops with no field naming the route-match-drift root
5991 // cause. Peer to
5992 // [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
5993 // /
5994 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
5995 // on the sibling canonical-Gateway-API-HTTPRoute-body-axis
5996 // re-export identity-pin set — completes the per-rule top-
5997 // level-axis re-export identity-pin set (`matches`,
5998 // `backendRefs`, `timeouts`, `retry`) this crate's
5999 // `gateway_routes` renderer's external `:entrada` ingress
6000 // contract rests on across the Gateway API HTTPRoute per-
6001 // rule body-shape.
6002 caixa_core::assert_str_reexport_identity(
6003 "GATEWAY_API_KEY_MATCHES",
6004 GATEWAY_API_KEY_MATCHES,
6005 caixa_core::GATEWAY_API_KEY_MATCHES,
6006 );
6007 }
6008
6009 #[test]
6010 fn gateway_api_key_path_re_export_points_at_caixa_core_canonical() {
6011 // The renderer's `GATEWAY_API_KEY_PATH` was lifted from the
6012 // inline `"path"` literal at the `gateway_routes` per-
6013 // Aplicacao HTTPRoute's per-match
6014 // `match_entry.insert("path", …)` call site (the sole per-
6015 // production-code per-`HTTPRouteMatch` path-matcher-
6016 // container-axis emitter) to a re-export of
6017 // [`caixa_core::GATEWAY_API_KEY_PATH`] so the Gateway-API-CRD
6018 // per-`HTTPRouteMatch` path-matcher-container-axis-key string
6019 // lives in exactly one place across every caixa renderer.
6020 // Pin the equality + static-data identity here so any local
6021 // re-introduction of a sibling
6022 // `pub const GATEWAY_API_KEY_PATH: &str = "…"` (the canonical
6023 // drift footgun where a sibling local `pub const` could
6024 // happen to carry the same string at the source while pointing
6025 // at a different `&'static` allocation) is a build-time test
6026 // failure naming the offending drift, not a silent apply-time
6027 // symptom — the prior shape would have let a Gateway-API-CRD
6028 // per-`HTTPRouteMatch` path-matcher-axis rebrand on the
6029 // caixa-mesh side without a coordinated caixa-core edit
6030 // silently land per-match path-selection predicates at the
6031 // drifted axis; the per-match path predicate degrades to the
6032 // wildcard match, the rule matches every request path
6033 // unconditionally, and every external `:entrada` path filter
6034 // drops with no field naming the path-matcher-drift root
6035 // cause. Peer to
6036 // [`gateway_api_key_matches_re_export_points_at_caixa_core_canonical`]
6037 // /
6038 // [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
6039 // /
6040 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
6041 // on the sibling canonical-Gateway-API-HTTPRoute-body-axis
6042 // re-export identity-pin set — nests the per-Gateway-API-
6043 // HTTPRoute-per-rule-body-axis re-export identity-pin set
6044 // (`matches`, `backendRefs`, `timeouts`, `retry`) one level
6045 // deeper onto the per-`HTTPRouteMatch` body-axis surface this
6046 // crate's `gateway_routes` renderer's external `:entrada`
6047 // ingress contract rests on across the Gateway API HTTPRoute
6048 // per-match body-shape.
6049 caixa_core::assert_str_reexport_identity(
6050 "GATEWAY_API_KEY_PATH",
6051 GATEWAY_API_KEY_PATH,
6052 caixa_core::GATEWAY_API_KEY_PATH,
6053 );
6054 }
6055
6056 #[test]
6057 fn gateway_api_key_listeners_re_export_points_at_caixa_core_canonical() {
6058 // The renderer's `GATEWAY_API_KEY_LISTENERS` was lifted from the
6059 // inline `"listeners"` literal at the `gateway_routes` per-
6060 // Aplicacao Gateway's `g_spec.insert("listeners", …)` call site
6061 // (the sole per-production-code per-Gateway L7-listener-set-
6062 // container-axis emitter) plus the matching test-side fixture
6063 // site (`gateway_listener_carries_aplicacao_host`'s
6064 // `.get("listeners")` navigation) to a re-export of
6065 // [`caixa_core::GATEWAY_API_KEY_LISTENERS`] so the Gateway-API-
6066 // CRD per-Gateway L7-listener-set-container-axis-key string
6067 // lives in exactly one place across every caixa renderer. Pin
6068 // the equality + static-data identity here so any local re-
6069 // introduction of a sibling
6070 // `pub const GATEWAY_API_KEY_LISTENERS: &str = "…"` (the
6071 // canonical drift footgun where a sibling local `pub const`
6072 // could happen to carry the same string at the source while
6073 // pointing at a different `&'static` allocation) is a build-
6074 // time test failure naming the offending drift, not a silent
6075 // apply-time symptom — the prior shape would have let a
6076 // Gateway-API-CRD per-Gateway L7-listener-set-axis rebrand on
6077 // the caixa-mesh side without a coordinated caixa-core edit
6078 // silently land per-Gateway L7-listener fan-outs at the
6079 // drifted axis; no listener is opened, and every external
6080 // `:entrada` flow drops at the gateway-class-controller's per-
6081 // Gateway reconcile with no field naming the L7-listener-set-
6082 // drift root cause. Peer to
6083 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
6084 // /
6085 // [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
6086 // on the sibling canonical-Gateway-API-HTTPRoute-body-axis re-
6087 // export identity-pin set — extends the per-Gateway-API-CRD-
6088 // body-axis re-export identity-pin set (`parentRefs`,
6089 // `backendRefs`, `listeners`, future `hostnames`) this crate's
6090 // `gateway_routes` renderer's external `:entrada` ingress
6091 // contract rests on across the Gateway API CRD-side body-
6092 // shape.
6093 caixa_core::assert_str_reexport_identity(
6094 "GATEWAY_API_KEY_LISTENERS",
6095 GATEWAY_API_KEY_LISTENERS,
6096 caixa_core::GATEWAY_API_KEY_LISTENERS,
6097 );
6098 }
6099
6100 #[test]
6101 fn gateway_api_key_hostname_re_export_points_at_caixa_core_canonical() {
6102 // The renderer's `GATEWAY_API_KEY_HOSTNAME` was lifted from the
6103 // inline `"hostname"` literal at the `gateway_routes` per-
6104 // Aplicacao Gateway's per-listener
6105 // `listener.insert("hostname", …)` call site (the sole per-
6106 // production-code per-listener DNS-host-discriminator-axis
6107 // emitter) plus the matching test-side fixture site
6108 // (`gateway_listener_carries_aplicacao_host`'s `.get("hostname")`
6109 // navigation) to a re-export of
6110 // [`caixa_core::GATEWAY_API_KEY_HOSTNAME`] so the Gateway-API-
6111 // CRD per-listener DNS-host-discriminator-axis-key string lives
6112 // in exactly one place across every caixa renderer. Pin the
6113 // equality + static-data identity here so any local re-
6114 // introduction of a sibling
6115 // `pub const GATEWAY_API_KEY_HOSTNAME: &str = "…"` (the
6116 // canonical drift footgun where a sibling local `pub const`
6117 // could happen to carry the same string at the source while
6118 // pointing at a different `&'static` allocation) is a build-
6119 // time test failure naming the offending drift, not a silent
6120 // apply-time symptom — the prior shape would have let a
6121 // Gateway-API-CRD per-listener DNS-host-discriminator-axis
6122 // rebrand on the caixa-mesh side without a coordinated caixa-
6123 // core edit silently land per-listener virtual-host filters at
6124 // the drifted axis; the listener accepts traffic on the
6125 // wildcard host rather than the typed `:entrada :host`, and
6126 // every external `:entrada` flow drops at the gateway-class-
6127 // controller's per-listener dispatch with no field naming the
6128 // DNS-host-discriminator-drift root cause. Peer to
6129 // [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
6130 // /
6131 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
6132 // /
6133 // [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
6134 // on the sibling canonical-Gateway-API-CRD-body-axis re-
6135 // export identity-pin set — nests the per-Gateway-API-CRD-
6136 // body-axis re-export identity-pin set (`parentRefs`,
6137 // `backendRefs`, `listeners`, `hostname`, future `hostnames`)
6138 // one level deeper onto the per-listener body-axis surface this
6139 // crate's `gateway_routes` renderer's external `:entrada`
6140 // ingress contract rests on across the Gateway API CRD-side
6141 // body-shape.
6142 caixa_core::assert_str_reexport_identity(
6143 "GATEWAY_API_KEY_HOSTNAME",
6144 GATEWAY_API_KEY_HOSTNAME,
6145 caixa_core::GATEWAY_API_KEY_HOSTNAME,
6146 );
6147 }
6148
6149 #[test]
6150 fn gateway_api_key_hostnames_re_export_points_at_caixa_core_canonical() {
6151 // The renderer's `GATEWAY_API_KEY_HOSTNAMES` was lifted from the
6152 // inline `"hostnames"` literal at the `gateway_routes` per-
6153 // Aplicacao HTTPRoute's spec-level `r_spec.insert("hostnames",
6154 // …)` call site (the sole production-code per-route DNS-host-
6155 // filter-axis emitter) to a re-export of
6156 // [`caixa_core::GATEWAY_API_KEY_HOSTNAMES`] so the Gateway-API-
6157 // CRD per-route DNS-host-filter-axis-key string lives in exactly
6158 // one place across every caixa renderer. Pin the equality +
6159 // static-data identity here so any local re-introduction of a
6160 // sibling `pub const GATEWAY_API_KEY_HOSTNAMES: &str = "…"` (the
6161 // canonical drift footgun where a sibling local `pub const` could
6162 // happen to carry the same string at the source while pointing
6163 // at a different `&'static` allocation) is a build-time test
6164 // failure naming the offending drift, not a silent apply-time
6165 // symptom — the prior shape would have let a Gateway-API-CRD
6166 // per-route DNS-host-filter-axis rebrand on the caixa-mesh side
6167 // without a coordinated caixa-core edit silently land per-route
6168 // virtual-host filters at the drifted axis; the route accepts
6169 // traffic on every host the parent Gateway's listener accepts
6170 // rather than the typed `:entrada :host`, and every external
6171 // `:entrada` flow drops at the gateway-class-controller's per-
6172 // route dispatch with no field naming the DNS-host-filter-drift
6173 // root cause. Peer to
6174 // [`gateway_api_key_hostname_re_export_points_at_caixa_core_canonical`]
6175 // /
6176 // [`gateway_api_key_listeners_re_export_points_at_caixa_core_canonical`]
6177 // /
6178 // [`gateway_api_key_parent_refs_re_export_points_at_caixa_core_canonical`]
6179 // /
6180 // [`gateway_api_key_backend_refs_re_export_points_at_caixa_core_canonical`]
6181 // on the sibling canonical-Gateway-API-CRD-body-axis re-export
6182 // identity-pin set — closes the per-Gateway-API-CRD `HTTPRoute`
6183 // per-route body-axis re-export identity-pin pair across the
6184 // singular / plural DNS-host discriminator surface (`hostname`
6185 // at the parent-Gateway per-listener discriminator + `hostnames`
6186 // at the child HTTPRoute per-route filter list), so both halves
6187 // of the DNS-host-discriminator convention across the
6188 // `(Gateway, HTTPRoute)` pair this crate's `gateway_routes`
6189 // renderer's external `:entrada` ingress contract emits together
6190 // now carry one lifted `&'static str` re-export identity-pin
6191 // apiece.
6192 caixa_core::assert_str_reexport_identity(
6193 "GATEWAY_API_KEY_HOSTNAMES",
6194 GATEWAY_API_KEY_HOSTNAMES,
6195 caixa_core::GATEWAY_API_KEY_HOSTNAMES,
6196 );
6197 }
6198
6199 #[test]
6200 fn cilium_network_policies_use_lifted_cilium_kind_network_policy() {
6201 // Fail-before-pass-after pin parsing every rendered
6202 // `CiliumNetworkPolicy` document and asserting its top-level
6203 // `kind` axis equals the lifted constant by value. Peer to the
6204 // canonical-string pin (`cilium_policy_carries_canonical_kube_skeleton`
6205 // — still present below as the bridge-arm pin asserting the
6206 // inline canonical string) and the re-export-identity pin
6207 // (`cilium_kind_network_policy_re_export_points_at_caixa_core_canonical`)
6208 // — together the three arms (canonical-string pin, lifted-uses
6209 // pin, re-export-identity pin) close the three-arm drift
6210 // footgun the inline-literal-pair-across-the-production-
6211 // skeleton-call-plus-test-fixture shape carried by
6212 // construction. Peer to
6213 // [`cilium_network_policies_use_lifted_cilium_api_version`] on
6214 // the sibling Cilium-CRD-apiVersion-axis lift trajectory —
6215 // completes the per-Cilium-CRD kind+apiVersion lifted-uses
6216 // pin pair the renderer's exit threading through the lifted
6217 // [`CILIUM_API_VERSION`] + [`CILIUM_KIND_NETWORK_POLICY`] pair
6218 // demands.
6219 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
6220 assert!(
6221 !policies.is_empty(),
6222 "the aplicacao fixture must emit at least one CiliumNetworkPolicy \
6223 — drift here masks the lifted-uses assertion below"
6224 );
6225 for p in &policies {
6226 assert_eq!(
6227 kube_root_str_field(p, KUBE_KEY_KIND),
6228 Some(CILIUM_KIND_NETWORK_POLICY),
6229 "every rendered CiliumNetworkPolicy must declare the lifted \
6230 [`CILIUM_KIND_NETWORK_POLICY`] constant on its top-level kind \
6231 axis — drift here means the per-policy skeleton call no \
6232 longer threads the lifted constant through"
6233 );
6234 }
6235 }
6236
6237 #[test]
6238 fn cilium_network_policies_use_lifted_cilium_api_version() {
6239 // Fail-before-pass-after pin parsing every rendered
6240 // `CiliumNetworkPolicy` document and asserting its top-level
6241 // `apiVersion` axis equals the lifted constant by value. Peer to
6242 // the canonical-string pin
6243 // (`cilium_policy_carries_canonical_kube_skeleton` — still
6244 // present below as the bridge-arm pin asserting the inline
6245 // canonical string) and the re-export-identity pin
6246 // (`cilium_api_version_re_export_points_at_caixa_core_canonical`)
6247 // — together the three arms (canonical-string pin,
6248 // lifted-uses pin, re-export-identity pin) close the
6249 // three-arm drift footgun the inline-literal-pair-across-the-
6250 // production-skeleton-call-plus-test-fixture shape carried by
6251 // construction. Peer to
6252 // [`gateway_routes_gateway_uses_lifted_gateway_api_api_version`]
6253 // / [`gateway_routes_httproute_uses_lifted_gateway_api_api_version`]
6254 // on the sibling K8s Gateway API CRD-axis lift trajectory.
6255 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
6256 assert!(
6257 !policies.is_empty(),
6258 "the aplicacao fixture must emit at least one CiliumNetworkPolicy \
6259 — drift here masks the lifted-uses assertion below"
6260 );
6261 for p in &policies {
6262 assert_eq!(
6263 kube_root_str_field(p, KUBE_KEY_API_VERSION),
6264 Some(CILIUM_API_VERSION),
6265 "every rendered CiliumNetworkPolicy must declare the lifted \
6266 [`CILIUM_API_VERSION`] constant on its top-level apiVersion \
6267 axis — drift here means the per-policy skeleton call no \
6268 longer threads the lifted constant through"
6269 );
6270 }
6271 }
6272
6273 #[test]
6274 fn programs_for_aplicacao_emits_one_entry_per_member() {
6275 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
6276 assert_eq!(entries.len(), 3);
6277 let names: Vec<_> = entries
6278 .iter()
6279 .map(|e| {
6280 e.get(FLEET_PROGRAMS_KEY_NAME)
6281 .and_then(|n| n.as_str())
6282 .unwrap()
6283 .to_string()
6284 })
6285 .collect();
6286 assert_eq!(names, vec!["catalog", "cart", "payment"]);
6287 }
6288
6289 #[test]
6290 fn programs_for_aplicacao_annotates_with_parent_nome() {
6291 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
6292 for e in &entries {
6293 assert_eq!(
6294 e.get(FLEET_PROGRAMS_KEY_APLICACAO).and_then(|v| v.as_str()),
6295 Some("checkout")
6296 );
6297 }
6298 }
6299
6300 #[test]
6301 fn fleet_programs_key_aplicacao_pins_canonical_value() {
6302 // Bridge-arm pin on the emit-side/probe-side coordinate — the
6303 // [`caixa_core::FLEET_PROGRAMS_KEY_APLICACAO`] constant this
6304 // crate now consumes at the `entry.insert(…)` per-`:membros`
6305 // parent-graph-annotation emit site + at the peer readback
6306 // probe above must resolve to the canonical `"aplicacao"` byte
6307 // the substrate operator's fleet-aggregator reads to group
6308 // each `programs[]` entry back onto its parent Aplicacao. A
6309 // future rebrand on the per-entry parent-graph-annotation
6310 // axis surfaces here as a coordinated edit-point rather than
6311 // as a silent apply-time split between the emitter's write
6312 // and the aggregator's per-graph reduce step. Peer of the
6313 // in-file [`fleet_programs_key_aplicacao_re_export_static_identity`]
6314 // static-data identity pin below and of the sibling
6315 // [`caixa_core::render::tests::fleet_programs_key_aplicacao_pins_canonical_value`]
6316 // canonical-value pin on the definition-site coordinate.
6317 assert_eq!(FLEET_PROGRAMS_KEY_APLICACAO, "aplicacao");
6318 }
6319
6320 #[test]
6321 fn fleet_programs_key_aplicacao_re_export_static_identity() {
6322 // Second coordinate of the re-export pin triangle: the
6323 // symbol this crate imports as `FLEET_PROGRAMS_KEY_APLICACAO`
6324 // must be *the same* `&'static str` as the canonical
6325 // [`caixa_core::FLEET_PROGRAMS_KEY_APLICACAO`] definition (a
6326 // sibling `pub const` at this crate's use-site would trip the
6327 // equality above without tripping this identity guard — the
6328 // exact drift shape the peer `caixa_flux`
6329 // [`fleet_programs_key_name_re_export_static_identity`] guard
6330 // catches on the per-entry-name-axis surface). Pinned via
6331 // `std::ptr::eq` on the two `.as_ptr()` addresses so a future
6332 // refactor that re-inlines the const here instead of importing
6333 // it from `caixa_core` fails at the fail-before-deploy posture.
6334 assert!(
6335 std::ptr::eq(
6336 FLEET_PROGRAMS_KEY_APLICACAO.as_ptr(),
6337 caixa_core::FLEET_PROGRAMS_KEY_APLICACAO.as_ptr(),
6338 ),
6339 "FLEET_PROGRAMS_KEY_APLICACAO must resolve to the canonical \
6340 caixa_core::FLEET_PROGRAMS_KEY_APLICACAO static, not a sibling \
6341 `pub const` — the aggregator/emitter drift footgun the lift closes."
6342 );
6343 }
6344
6345 #[test]
6346 fn fleet_programs_key_versao_pins_canonical_value() {
6347 // Bridge-arm pin on the emit-side coordinate — the
6348 // [`caixa_core::FLEET_PROGRAMS_KEY_VERSAO`] constant this crate
6349 // now consumes at the `entry.insert(…)` per-`:membros` version-
6350 // constraint emit site must resolve to the canonical `"versao"`
6351 // byte the substrate operator's per-`:membros` resolver reads
6352 // to project each entry back onto its M3 Aplicacao's declared
6353 // version-constraint. Peer of the in-file
6354 // [`fleet_programs_key_versao_re_export_static_identity`]
6355 // static-data identity pin below and of the sibling
6356 // [`caixa_core::render::tests::fleet_programs_key_versao_pins_canonical_value`]
6357 // canonical-value pin on the definition-site coordinate.
6358 assert_eq!(FLEET_PROGRAMS_KEY_VERSAO, "versao");
6359 }
6360
6361 #[test]
6362 fn fleet_programs_key_versao_re_export_static_identity() {
6363 // Second coordinate of the re-export pin triangle: the
6364 // symbol this crate imports as `FLEET_PROGRAMS_KEY_VERSAO`
6365 // must be *the same* `&'static str` as the canonical
6366 // [`caixa_core::FLEET_PROGRAMS_KEY_VERSAO`] definition (a
6367 // sibling `pub const` at this crate's use-site would trip the
6368 // equality above without tripping this identity guard). Peer
6369 // of the sibling
6370 // [`fleet_programs_key_aplicacao_re_export_static_identity`]
6371 // guard on the per-entry parent-graph-annotation axis surface.
6372 // Pinned via `std::ptr::eq` on the two `.as_ptr()` addresses
6373 // so a future refactor that re-inlines the const here instead
6374 // of importing it from `caixa_core` fails at the fail-before-
6375 // deploy posture.
6376 assert!(
6377 std::ptr::eq(
6378 FLEET_PROGRAMS_KEY_VERSAO.as_ptr(),
6379 caixa_core::FLEET_PROGRAMS_KEY_VERSAO.as_ptr(),
6380 ),
6381 "FLEET_PROGRAMS_KEY_VERSAO must resolve to the canonical \
6382 caixa_core::FLEET_PROGRAMS_KEY_VERSAO static, not a sibling \
6383 `pub const` — the resolver/emitter drift footgun the lift closes."
6384 );
6385 }
6386
6387 #[test]
6388 fn programs_for_aplicacao_carries_lifted_fleet_programs_key_versao() {
6389 // Production-emit pin: each `programs[]` entry the per-
6390 // `:membros` fan-out writes must carry the source Membro's
6391 // `:versao` constraint under the lifted
6392 // [`caixa_core::FLEET_PROGRAMS_KEY_VERSAO`] axis-key, in
6393 // declaration order. Peer of the sibling
6394 // [`programs_for_aplicacao_annotates_with_parent_nome`]
6395 // per-`:membros` parent-graph-annotation-axis emit pin;
6396 // together the two pins pin every per-entry axis the
6397 // caixa-mesh fan-out writes (name / versao / aplicacao) at the
6398 // production-emit coordinate.
6399 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
6400 let versoes: Vec<_> = entries
6401 .iter()
6402 .map(|e| {
6403 e.get(FLEET_PROGRAMS_KEY_VERSAO)
6404 .and_then(|v| v.as_str())
6405 .unwrap()
6406 .to_string()
6407 })
6408 .collect();
6409 assert_eq!(versoes, vec!["^0.1", "^0.1", "^0.2"]);
6410 }
6411
6412 #[test]
6413 fn programs_for_aplicacao_entry_name_routes_through_membro_nome_accessor() {
6414 // Emit-path pin: each `programs[]` entry's `name:` byte-string
6415 // must resolve through the typed [`caixa_core::Membro::nome`]
6416 // accessor, not the raw `.caixa` field. Pins the
6417 // last-`.clone()`-site lift the `m.nome().to_string()` edit at
6418 // the per-`:membros` emit call site above landed against a
6419 // future silent detour that re-inlined `m.caixa.clone()` — the
6420 // regression would round-trip past the sibling
6421 // [`programs_for_aplicacao_emits_one_entry_per_member`] fixture-
6422 // literal pin (which spells the emitted `name:` byte-string
6423 // verbatim) but would silently split the emit-side write from
6424 // any future substrate-side rewrite the accessor grows (a
6425 // per-cluster alias table, an M4 namespace-qualified rewrite,
6426 // the `:membros :nome-suffix` overlay MESH-COMPOSITION §III.2
6427 // acknowledges). Asserted against the accessor byte-for-byte,
6428 // per-membro, in declaration order — a mutation of the emit
6429 // site back to `.caixa.clone()` still passes this pin *today*
6430 // (nome() is byte-equal to .caixa on the sibling
6431 // [`caixa_core::aplicacao::tests::membro_nome_returns_caixa_byte_equal_across_permutations`]
6432 // pin), but any future accessor extension immediately fires the
6433 // regression here — the pair `(emit path, accessor path)` moves
6434 // as a unit on the substrate primitive.
6435 let c = aplicacao_caixa();
6436 let membros = &c
6437 .aplicacao_view()
6438 .expect("Aplicacao view for fixture")
6439 .membros;
6440 let entries = programs_for_aplicacao(&c).unwrap();
6441 assert_eq!(entries.len(), membros.len());
6442 for (m, entry) in membros.iter().zip(entries.iter()) {
6443 let emitted = entry
6444 .get(FLEET_PROGRAMS_KEY_NAME)
6445 .and_then(|v| v.as_str())
6446 .expect("programs.yaml entry carries name: as a string");
6447 assert_eq!(
6448 emitted,
6449 m.nome(),
6450 "programs.yaml entry `name:` must byte-equal Membro::nome() — \
6451 emit path must route through the typed accessor, not the \
6452 raw `.caixa` field"
6453 );
6454 }
6455 }
6456
6457 #[test]
6458 fn programs_for_aplicacao_entry_versao_routes_through_membro_versao_requirement_accessor() {
6459 // Emit-path pin: each `programs[]` entry's `versao:` byte-string
6460 // must resolve through the typed
6461 // [`caixa_core::Membro::versao_requirement`] accessor, not the
6462 // raw `.versao` field. Peer of the sibling
6463 // [`programs_for_aplicacao_entry_name_routes_through_membro_nome_accessor`]
6464 // pin on the per-`:membros` version-constraint axis; together
6465 // the two pins pin the last two `.clone()` sites the a40b0e3 /
6466 // 4a32abf sibling per-`:membros` accessor lifts left carrying
6467 // raw-field-access `String`-carry copies (the sibling `&str`-
6468 // read sites already route through the accessors). A future
6469 // extension of the version-constraint accessor (a per-cluster
6470 // version-pin overlay the operator pins through a future
6471 // `:placement`-scoped slot, a lacre-projected concrete-version
6472 // rewrite, an M4 canary version-pinning slot) that lands on the
6473 // accessor now flows through the emitted programs.yaml `versao:`
6474 // by construction.
6475 let c = aplicacao_caixa();
6476 let membros = &c
6477 .aplicacao_view()
6478 .expect("Aplicacao view for fixture")
6479 .membros;
6480 let entries = programs_for_aplicacao(&c).unwrap();
6481 assert_eq!(entries.len(), membros.len());
6482 for (m, entry) in membros.iter().zip(entries.iter()) {
6483 let emitted = entry
6484 .get(FLEET_PROGRAMS_KEY_VERSAO)
6485 .and_then(|v| v.as_str())
6486 .expect("programs.yaml entry carries versao: as a string");
6487 assert_eq!(
6488 emitted,
6489 m.versao_requirement(),
6490 "programs.yaml entry `versao:` must byte-equal \
6491 Membro::versao_requirement() — emit path must route \
6492 through the typed accessor, not the raw `.versao` field"
6493 );
6494 }
6495 }
6496
6497 #[test]
6498 fn programs_for_aplicacao_entry_aplicacao_routes_through_caixa_nome_accessor() {
6499 // Emit-path pin: each `programs[]` entry's `aplicacao:`
6500 // byte-string must resolve through the typed
6501 // [`caixa_core::Caixa::nome`] accessor, not the raw `.nome`
6502 // field. Pins the `caixa.nome().to_string()` edit at the
6503 // per-`:membros` emit call site above against a future silent
6504 // detour that re-inlined `caixa.nome.clone()` — the regression
6505 // would round-trip past every fixture-literal aplicacao-name
6506 // pin (which spells the emitted `aplicacao:` byte-string
6507 // verbatim as `"checkout"`) but would silently split the emit-
6508 // side write from any future substrate-side rewrite the
6509 // accessor grows (a per-cluster alias table the operator pins
6510 // through a future `:placement`-scoped slot, an M4 namespace-
6511 // qualified rewrite the CR materializer applies per-CR, the
6512 // future `:nome-suffix` overlay the MESH-COMPOSITION §III.2
6513 // roadmap acknowledges). Asserted against the accessor byte-
6514 // for-byte, per-entry — a mutation of the emit site back to
6515 // `.nome.clone()` still passes this pin *today* (nome() is
6516 // byte-equal to .nome on the sibling
6517 // [`caixa_core::manifest::tests`] accessor pins), but any
6518 // future accessor extension immediately fires the regression
6519 // here — the pair `(emit path, accessor path)` moves as a unit
6520 // on the substrate primitive. Peer of the sibling
6521 // [`programs_for_aplicacao_entry_name_routes_through_membro_nome_accessor`]
6522 // pin on the per-`:membros` `name:` axis (4127bb6) extended
6523 // onto the parent-`Aplicacao` `aplicacao:` annotation axis;
6524 // opens the "converge every remaining `caixa.nome.clone()`
6525 // raw-field-access `String`-carry site in caixa-mesh onto
6526 // Caixa::nome" sweep the sibling
6527 // [`cilium_network_policies_label_aplicacao_routes_through_caixa_nome_accessor`]
6528 // and
6529 // [`gateway_routes_parent_ref_name_routes_through_caixa_nome_accessor`]
6530 // pins fold on.
6531 let c = aplicacao_caixa();
6532 let entries = programs_for_aplicacao(&c).unwrap();
6533 assert!(!entries.is_empty());
6534 for entry in &entries {
6535 let emitted = entry
6536 .get(FLEET_PROGRAMS_KEY_APLICACAO)
6537 .and_then(|v| v.as_str())
6538 .expect("programs.yaml entry carries aplicacao: as a string");
6539 assert_eq!(
6540 emitted,
6541 c.nome(),
6542 "programs.yaml entry `aplicacao:` must byte-equal \
6543 Caixa::nome() — emit path must route through the typed \
6544 accessor, not the raw `.nome` field"
6545 );
6546 }
6547 }
6548
6549 #[test]
6550 fn cilium_network_policies_label_aplicacao_routes_through_caixa_nome_accessor() {
6551 // Emit-path pin: each CNP's
6552 // `metadata.labels.pleme.pleme.io/aplicacao` byte-string must
6553 // resolve through the typed [`caixa_core::Caixa::nome`]
6554 // accessor, not the raw `.nome` field. Sibling of the peer
6555 // [`programs_for_aplicacao_entry_aplicacao_routes_through_caixa_nome_accessor`]
6556 // pin on the fleet-programs `aplicacao:` annotation axis,
6557 // extended onto the per-`(:de, :para)` CNP `LABEL_APLICACAO`
6558 // label-axis — same "the emit path must route through the
6559 // substrate-primitive typed dispatch" discipline extended onto
6560 // the peer per-CNP `String`-carry site. A future extension of
6561 // the accessor to a richer author surface (a per-cluster alias
6562 // table, an M4 namespace-qualified rewrite, the future
6563 // `:nome-suffix` overlay MESH-COMPOSITION §III.2 acknowledges)
6564 // that landed on the accessor but not on this label would have
6565 // silently split the parent-Aplicacao identity between two
6566 // consumers — the operator's `kubectl -n tatara-system get cnp
6567 // -l pleme.pleme.io/aplicacao=<name>` grep-by-label would land
6568 // on a policy whose parent-Aplicacao annotation drifted from
6569 // the accessor's projection.
6570 let c = aplicacao_caixa();
6571 let policies = cilium_network_policies(&c).unwrap();
6572 assert!(!policies.is_empty());
6573 for policy in &policies {
6574 let emitted = policy
6575 .get(KUBE_KEY_METADATA)
6576 .and_then(|m| m.get(KUBE_KEY_LABELS))
6577 .and_then(|l| l.get(LABEL_APLICACAO))
6578 .and_then(|v| v.as_str())
6579 .expect("CNP metadata.labels carries LABEL_APLICACAO as a string");
6580 assert_eq!(
6581 emitted,
6582 c.nome(),
6583 "CNP `metadata.labels.{LABEL_APLICACAO}` must byte-equal \
6584 Caixa::nome() — emit path must route through the typed \
6585 accessor, not the raw `.nome` field"
6586 );
6587 }
6588 }
6589
6590 #[test]
6591 fn gateway_routes_parent_ref_name_routes_through_caixa_nome_accessor() {
6592 // Emit-path pin: the HTTPRoute's
6593 // `spec.parentRefs[0].name` byte-string must resolve through
6594 // the typed [`caixa_core::Caixa::nome`] accessor, not the raw
6595 // `.nome` field. Third and final sibling of the peer
6596 // [`programs_for_aplicacao_entry_aplicacao_routes_through_caixa_nome_accessor`]
6597 // + [`cilium_network_policies_label_aplicacao_routes_through_caixa_nome_accessor`]
6598 // pins — closes the last unlifted `caixa.nome.clone()` raw-
6599 // field-access `String`-carry site in caixa-mesh. The
6600 // parentRefs[].name binds the emitted HTTPRoute to the peer
6601 // Gateway whose `metadata.name` is derived from the same
6602 // Caixa::nome earlier in this same emitter (via
6603 // `kube_resource_skeleton(..., &caixa.nome, ...)` at the
6604 // Gateway skeleton call above — a peer `&str`-read site out of
6605 // scope for this `String`-carry sweep); a future accessor
6606 // extension that split those two projections would orphan the
6607 // route from its parent Gateway at every apply-time Gateway
6608 // API v1.x per-parentRef resolution step. Pinning the emit
6609 // path against the accessor byte-for-byte here fires that
6610 // regression at caixa-mesh build time rather than at K8s API
6611 // server admission.
6612 let c = aplicacao_caixa();
6613 let routes = gateway_routes(&c).unwrap();
6614 let route = routes
6615 .iter()
6616 .find(|r| {
6617 r.get(KUBE_KEY_KIND)
6618 .and_then(|k| k.as_str())
6619 .is_some_and(|k| k == GATEWAY_API_KIND_HTTP_ROUTE)
6620 })
6621 .expect("gateway_routes emits at least one HTTPRoute for the fixture Aplicacao");
6622 let emitted = route
6623 .get(KUBE_KEY_SPEC)
6624 .and_then(|s| s.get(GATEWAY_API_KEY_PARENT_REFS))
6625 .and_then(|p| p.as_sequence())
6626 .and_then(|s| s.first())
6627 .and_then(|p| p.get(GATEWAY_API_KEY_NAME))
6628 .and_then(|v| v.as_str())
6629 .expect("HTTPRoute spec.parentRefs[0].name is a string");
6630 assert_eq!(
6631 emitted,
6632 c.nome(),
6633 "HTTPRoute `spec.parentRefs[0].{GATEWAY_API_KEY_NAME}` must \
6634 byte-equal Caixa::nome() — emit path must route through the \
6635 typed accessor, not the raw `.nome` field"
6636 );
6637 }
6638
6639 #[test]
6640 fn cilium_network_policy_metadata_name_routes_through_caixa_nome_accessor() {
6641 // Emit-path pin: each CNP's `metadata.name` byte-string must
6642 // derive from the typed [`caixa_core::Caixa::nome`] accessor
6643 // byte-for-byte through the substrate-canonical
6644 // [`caixa_core::cilium_network_policy_name`] composer. Before
6645 // this converge the outer
6646 // `cilium_network_policy_name(&caixa.nome, de, para)` call at
6647 // [`cilium_network_policies`] carried a raw `&caixa.nome`
6648 // `&String`-borrow of the underlying field, bypassing the typed
6649 // accessor. Peer of the sibling
6650 // [`cilium_network_policies_label_aplicacao_routes_through_caixa_nome_accessor`]
6651 // pin on the co-resident per-CNP `metadata.labels
6652 // .pleme.pleme.io/aplicacao` `String`-carry site — extends the
6653 // "one typed dispatch on the substrate primitive, thin
6654 // projections at each consumer" discipline onto the
6655 // non-`.clone()` raw-field-access axis of `Caixa::nome` in
6656 // caixa-mesh (sibling of the 22461ef caixa-helm converge on the
6657 // per-`lareira-<nome>` chart-directory identity composer).
6658 // Byte-equal today (the accessor is `&self.nome`); the pin
6659 // catches any future accessor extension (a per-cluster alias
6660 // overlay, an M4 CR-materializer name rewrite, a future
6661 // `:nome-suffix` slot) whose emit-side write regresses to the
6662 // raw `&caixa.nome` field access.
6663 let c = aplicacao_caixa();
6664 let policies = cilium_network_policies(&c).unwrap();
6665 assert!(!policies.is_empty());
6666 for policy in &policies {
6667 let emitted = kube_metadata_str_field(policy, KUBE_KEY_NAME)
6668 .expect("CNP metadata.name scalar present");
6669 // Extract the (de, para) pair back out of
6670 // `<aplicacao>-<de>-to-<para>` by stripping the accessor-
6671 // canonical `<aplicacao>-` prefix and splitting on the
6672 // canonical `-to-` separator — pins the composer's byte
6673 // shape (aplicacao-name arg first, `-to-` separator,
6674 // destination-name arg last) against the emitted encoding.
6675 let stripped = emitted
6676 .strip_prefix(&format!("{}-", c.nome()))
6677 .expect("CNP metadata.name carries the accessor-derived aplicacao prefix");
6678 let (de, para) = stripped
6679 .split_once(CONTRATO_EDGE_LABEL_SEPARATOR)
6680 .expect("CNP metadata.name carries the canonical `-to-` edge separator");
6681 assert_eq!(
6682 emitted,
6683 cilium_network_policy_name(c.nome(), de, para),
6684 "CNP `metadata.name` must derive from the typed \
6685 `caixa_core::Caixa::nome` accessor through \
6686 `caixa_core::cilium_network_policy_name` byte-for-byte \
6687 — a regression that re-inlines \
6688 `cilium_network_policy_name(&caixa.nome, de, para)` at \
6689 the emit site silently splits the per-CNP \
6690 `metadata.name` axis (the operator-side `kubectl -n \
6691 tatara-system get cnp <aplicacao>-<de>-to-<para>` \
6692 grep-by-name lookup key) from every future accessor \
6693 extension that lands on the accessor"
6694 );
6695 }
6696 }
6697
6698 #[test]
6699 fn cilium_network_policy_from_endpoints_aplicacao_scope_routes_through_caixa_nome_accessor() {
6700 // Emit-path pin: each CNP's `spec.ingress[0].fromEndpoints[0]
6701 // .matchLabels.pleme.pleme.io/aplicacao` byte-string (the
6702 // aplicacao-scope axis of the two-axis source selector
6703 // [`caixa_core::pleme_program_in_aplicacao_selector`] emits)
6704 // must resolve through the typed [`caixa_core::Caixa::nome`]
6705 // accessor. Before this converge the outer
6706 // `pleme_program_in_aplicacao_selector(de, &caixa.nome)` call
6707 // at [`cilium_network_policies`] carried a raw `&caixa.nome`
6708 // `&String`-borrow of the underlying field, bypassing the typed
6709 // accessor. Load-bearing safety property: a same-named program
6710 // in a *different* Aplicacao cannot satisfy the CNP's ingress
6711 // rule — if the emit-side aplicacao-scope value ever drifted
6712 // from the accessor-canonical projection of `Caixa::nome`, a
6713 // future accessor extension (per-cluster alias overlay, M4 CR-
6714 // materializer name rewrite, `:nome-suffix` slot) that rewrote
6715 // the parent-Aplicacao identity on the accessor but not on this
6716 // selector site would silently break the aplicacao-scoping
6717 // guarantee at every Cilium data-plane admission decision.
6718 let c = aplicacao_caixa();
6719 let policies = cilium_network_policies(&c).unwrap();
6720 assert!(!policies.is_empty());
6721 for policy in &policies {
6722 let selector = policy
6723 .get(KUBE_KEY_SPEC)
6724 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
6725 .and_then(|i| i.as_sequence())
6726 .and_then(|s| s.first())
6727 .and_then(|i| i.get(CILIUM_KEY_FROM_ENDPOINTS))
6728 .and_then(|e| e.as_sequence())
6729 .and_then(|s| s.first())
6730 .and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))
6731 .and_then(|m| m.as_mapping())
6732 .expect("CNP spec.ingress[0].fromEndpoints[0].matchLabels mapping present");
6733 let emitted = selector
6734 .get(LABEL_APLICACAO)
6735 .and_then(|v| v.as_str())
6736 .expect("fromEndpoints selector carries LABEL_APLICACAO as a string");
6737 assert_eq!(
6738 emitted,
6739 c.nome(),
6740 "CNP `spec.ingress[0].fromEndpoints[0].matchLabels.{LABEL_APLICACAO}` \
6741 must byte-equal Caixa::nome() — emit path must route \
6742 through the typed accessor, not the raw `.nome` field, \
6743 so a future accessor extension that rewrites the \
6744 parent-Aplicacao identity reaches this aplicacao-scope \
6745 axis by construction and preserves the load-bearing \
6746 safety property that a same-named program in a \
6747 different Aplicacao cannot satisfy the ingress rule"
6748 );
6749 }
6750 }
6751
6752 #[test]
6753 fn gateway_routes_gateway_metadata_name_routes_through_caixa_nome_accessor() {
6754 // Emit-path pin: the Gateway's `metadata.name` byte-string must
6755 // resolve through the typed [`caixa_core::Caixa::nome`]
6756 // accessor byte-for-byte. Before this converge the outer
6757 // `kube_resource_skeleton(..., &caixa.nome, ...)` call at
6758 // [`gateway_routes`]'s Gateway skeleton site carried a raw
6759 // `&caixa.nome` `&String`-borrow of the underlying field,
6760 // bypassing the typed accessor. Companion to the sibling
6761 // [`gateway_routes_parent_ref_name_routes_through_caixa_nome_accessor`]
6762 // pin on the HTTPRoute `spec.parentRefs[0].name` axis: the pair
6763 // `(Gateway metadata.name, HTTPRoute spec.parentRefs[0].name)`
6764 // — the two halves of the Gateway API v1 parent-binding contract
6765 // Envoy's per-listener attachment resolver keys off — must
6766 // share exactly one typed dispatch on the substrate primitive.
6767 // A future accessor extension that rewrote the parent-
6768 // Aplicacao identity on the accessor but not on this skeleton-
6769 // name site would orphan every emitted HTTPRoute from its
6770 // parent Gateway at K8s API-server admission time.
6771 let c = aplicacao_caixa();
6772 let docs = gateway_routes(&c).unwrap();
6773 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY)
6774 .expect("Gateway present under a `:entrada`-carrying fixture Aplicacao");
6775 let emitted = kube_metadata_str_field(gateway, KUBE_KEY_NAME)
6776 .expect("Gateway metadata.name scalar present");
6777 assert_eq!(
6778 emitted,
6779 c.nome(),
6780 "Gateway `metadata.name` must derive from the typed \
6781 `caixa_core::Caixa::nome` accessor byte-for-byte — a \
6782 regression that re-inlines \
6783 `kube_resource_skeleton(..., &caixa.nome, ...)` at the emit \
6784 site silently splits the Gateway `metadata.name` axis (the \
6785 operator-side `kubectl -n tatara-system get gateway \
6786 <aplicacao>` grep-by-name lookup key and the peer sibling \
6787 HTTPRoute `spec.parentRefs[0].name` binding) from every \
6788 future accessor extension that lands on the accessor"
6789 );
6790 }
6791
6792 #[test]
6793 fn gateway_routes_httproute_metadata_name_routes_through_caixa_nome_accessor() {
6794 // Emit-path pin: the HTTPRoute's `metadata.name` byte-string
6795 // must derive from the typed [`caixa_core::Caixa::nome`]
6796 // accessor byte-for-byte through the substrate-canonical
6797 // [`caixa_core::gateway_api_http_route_name`] composer. Before
6798 // this converge the outer
6799 // `gateway_api_http_route_name(&caixa.nome, entrada.destination())`
6800 // call at [`gateway_routes`]'s HTTPRoute skeleton site carried
6801 // a raw `&caixa.nome` `&String`-borrow of the underlying field,
6802 // bypassing the typed accessor. Peer of the sibling per-CNP
6803 // `metadata.name` composer converge above and the co-resident
6804 // Gateway `metadata.name` skeleton-arg converge — closes the
6805 // last unlifted non-`.clone()` raw-field-access `Caixa::nome`
6806 // site in caixa-mesh. A future accessor extension that
6807 // rewrote the parent-Aplicacao identity on the accessor but
6808 // not on this HTTPRoute-name site would silently split the
6809 // per-HTTPRoute `metadata.name` axis (the operator-side
6810 // `kubectl -n tatara-system get httproute
6811 // <aplicacao>-<destination>` grep-by-name lookup key) from
6812 // every future accessor extension.
6813 let c = aplicacao_caixa();
6814 let docs = gateway_routes(&c).unwrap();
6815 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE)
6816 .expect("HTTPRoute present under a `:entrada`-carrying fixture Aplicacao");
6817 let emitted = kube_metadata_str_field(route, KUBE_KEY_NAME)
6818 .expect("HTTPRoute metadata.name scalar present");
6819 let entrada = c
6820 .entrada
6821 .as_ref()
6822 .expect("aplicacao_caixa carries a typed `:entrada` block");
6823 assert_eq!(
6824 emitted,
6825 gateway_api_http_route_name(c.nome(), entrada.destination()),
6826 "HTTPRoute `metadata.name` must derive from the typed \
6827 `caixa_core::Caixa::nome` accessor through \
6828 `caixa_core::gateway_api_http_route_name` byte-for-byte — \
6829 a regression that re-inlines \
6830 `gateway_api_http_route_name(&caixa.nome, \
6831 entrada.destination())` at the emit site silently splits \
6832 the per-HTTPRoute `metadata.name` axis (the operator-side \
6833 `kubectl -n tatara-system get httproute \
6834 <aplicacao>-<destination>` grep-by-name lookup key) from \
6835 every future accessor extension that lands on the accessor"
6836 );
6837 }
6838
6839 #[test]
6840 fn programs_for_aplicacao_rejects_non_aplicacao_kinds() {
6841 let mut c = aplicacao_caixa();
6842 c.kind = CaixaKind::Servico;
6843 c.servicos = vec!["servicos/x.computeunit.yaml".into()];
6844 let err = programs_for_aplicacao(&c).unwrap_err();
6845 assert!(matches!(err, Error::NotAnAplicacao(_)));
6846 }
6847
6848 #[test]
6849 fn kind_mismatch_error_names_offending_caixa_nome() {
6850 // Pinning the lifted [`caixa_core::KindMismatch`] view's
6851 // load-bearing property: a kind-mismatched caixa surfaces a
6852 // diagnostic that *names the offending caixa* (`checkout`),
6853 // not just the rejected kind. Before the lift the renderer
6854 // raised `Error::NotAnAplicacao(CaixaKind::Servico)` whose
6855 // Display said "caixa :kind must be Aplicacao for caixa-mesh
6856 // rendering, got Servico" — the user had to grep their
6857 // source tree for which caixa.lisp triggered it. After the
6858 // lift the wrapped KindMismatch carries the `:nome`, the
6859 // renderer's `#[error("{0}")]` arm prints it through, and
6860 // the diagnostic is self-locating.
6861 let mut c = aplicacao_caixa();
6862 c.kind = CaixaKind::Servico;
6863 c.servicos = vec!["servicos/x.computeunit.yaml".into()];
6864 let err = programs_for_aplicacao(&c).unwrap_err();
6865 let msg = format!("{err}");
6866 assert!(
6867 msg.contains("checkout"),
6868 "kind-mismatch diagnostic must name the offending caixa nome \
6869 (got: {msg:?})"
6870 );
6871 assert!(
6872 msg.contains("Aplicacao"),
6873 "diagnostic must name the expected kind (got: {msg:?})"
6874 );
6875 assert!(
6876 msg.contains("Servico"),
6877 "diagnostic must name the actual kind (got: {msg:?})"
6878 );
6879 }
6880
6881 #[test]
6882 fn typed_view_kind_mismatch_names_offending_caixa_nome() {
6883 // The second kind-checking call site in caixa-mesh —
6884 // [`typed_view`] (consumed by every downstream renderer:
6885 // `cilium_network_policies`, `gateway_routes`, the future
6886 // per-:politicas `CiliumClusterwideEnvoyConfig` emitter) —
6887 // must surface the same lifted diagnostic shape. Pinning so
6888 // a future divergence between `programs_for_aplicacao` and
6889 // `typed_view` (e.g. one re-inlines the kind check, the other
6890 // uses `require_kind`) surfaces here as a test failure rather
6891 // than as a silent diagnostic regression on the per-Aplicacao
6892 // mesh-emission path.
6893 let mut c = aplicacao_caixa();
6894 c.kind = CaixaKind::Supervisor;
6895 c.servicos = vec![];
6896 c.children = vec![];
6897 let err = typed_view(&c).unwrap_err();
6898 let msg = format!("{err}");
6899 assert!(
6900 msg.contains("checkout"),
6901 "typed_view's kind-mismatch must also name the caixa nome \
6902 (got: {msg:?})"
6903 );
6904 match err {
6905 Error::NotAnAplicacao(km) => {
6906 assert_eq!(km.nome, "checkout");
6907 assert_eq!(km.expected, CaixaKind::Aplicacao);
6908 assert_eq!(km.actual, CaixaKind::Supervisor);
6909 }
6910 other => panic!("expected Error::NotAnAplicacao, got {other:?}"),
6911 }
6912 }
6913
6914 #[test]
6915 fn programs_for_aplicacao_validates_typed_shape() {
6916 let mut c = aplicacao_caixa();
6917 // Add an invalid contrato pointing at a non-member.
6918 c.contratos.push(WitContract {
6919 de: "cart".into(),
6920 para: "phantom".into(),
6921 wit: "wasi:http/proxy".into(),
6922 endpoint: Some("/x".into()),
6923 subject: None,
6924 slot: None,
6925 });
6926 let err = programs_for_aplicacao(&c).unwrap_err();
6927 assert!(matches!(err, Error::InvalidAplicacao(_)));
6928 }
6929
6930 #[test]
6931 fn programs_for_aplicacao_routes_entry_gate_through_typed_view() {
6932 // Drift-detection pin on the lifted per-Aplicacao entry-gate
6933 // cascade: `programs_for_aplicacao` and its sibling
6934 // per-Aplicacao renderers (`cilium_network_policies`,
6935 // `gateway_routes`) all funnel through [`typed_view`]'s
6936 // `require_kind + aplicacao_view + AplicacaoSpec::validate`
6937 // three-arm gate before touching any renderer-specific
6938 // emission. Feeding the same offending caixa into both paths
6939 // must therefore surface byte-identical `Error` diagnostics —
6940 // the same variant, the same self-locating fields, the same
6941 // `Display` prose.
6942 //
6943 // Until `programs_for_aplicacao` was refactored onto
6944 // `typed_view` it re-inlined the three-arm cascade by hand.
6945 // Both paths happened to agree today only because the
6946 // hand-written scaffold was the same three lines, but a
6947 // future entry-gate widening on one side without a matching
6948 // edit on the other would have surfaced only at the sibling
6949 // renderer that took the drifted path — silently on the one
6950 // that stayed on the pre-widening cascade. Pinning both
6951 // paths' error surface on the same input structurally
6952 // eliminates that drift: a future entry-gate change threads
6953 // through both call sites together, or this test fires.
6954 //
6955 // Peer to the sibling `typed_view_kind_mismatch_names_
6956 // offending_caixa_nome` test on the kind-check arm; this test
6957 // covers the `AplicacaoSpec::validate` arm (via a
6958 // non-member `:contratos :para` reference — the same fixture
6959 // the pre-existing `programs_for_aplicacao_validates_typed_
6960 // shape` test uses).
6961 let mut c = aplicacao_caixa();
6962 c.contratos.push(WitContract {
6963 de: "cart".into(),
6964 para: "phantom".into(),
6965 wit: "wasi:http/proxy".into(),
6966 endpoint: Some("/x".into()),
6967 subject: None,
6968 slot: None,
6969 });
6970 let programs_err = programs_for_aplicacao(&c).unwrap_err();
6971 let typed_view_err = typed_view(&c).unwrap_err();
6972 assert_eq!(
6973 format!("{programs_err}"),
6974 format!("{typed_view_err}"),
6975 "programs_for_aplicacao must surface the same entry-gate \
6976 diagnostic as typed_view — a divergence here means the \
6977 renderer skipped the shared cascade"
6978 );
6979 assert!(
6980 matches!(programs_err, Error::InvalidAplicacao(_)),
6981 "programs_for_aplicacao must surface the AplicacaoSpec::validate \
6982 failure through the same Error::InvalidAplicacao variant \
6983 typed_view raises"
6984 );
6985 assert!(
6986 matches!(typed_view_err, Error::InvalidAplicacao(_)),
6987 "typed_view must raise the same variant so a future divergence \
6988 on either path is a compile-time signal, not a silent \
6989 renderer-side drift"
6990 );
6991 }
6992
6993 #[test]
6994 fn programs_for_aplicacao_kind_mismatch_matches_typed_view() {
6995 // Companion of the validate-arm drift-detection pin
6996 // immediately above: on the kind-check arm (Supervisor caixa
6997 // fed into a per-Aplicacao renderer), both `typed_view` and
6998 // `programs_for_aplicacao` must surface byte-identical
6999 // diagnostics — the same lifted [`caixa_core::KindMismatch`]
7000 // view wrapped in the same `Error::NotAnAplicacao` variant.
7001 // Pinning both arms of the shared entry-gate cascade closes
7002 // the drift surface structurally; a future edit that widens
7003 // the kind-check on one path without the other would have
7004 // silently regressed on the sibling renderer.
7005 let mut c = aplicacao_caixa();
7006 c.kind = CaixaKind::Supervisor;
7007 c.servicos = vec![];
7008 c.children = vec![];
7009 let programs_err = programs_for_aplicacao(&c).unwrap_err();
7010 let typed_view_err = typed_view(&c).unwrap_err();
7011 assert_eq!(
7012 format!("{programs_err}"),
7013 format!("{typed_view_err}"),
7014 "programs_for_aplicacao and typed_view must agree on the \
7015 kind-mismatch diagnostic — divergence indicates one path \
7016 skipped the shared `require_kind` gate"
7017 );
7018 }
7019
7020 #[test]
7021 fn typed_view_routes_through_caixa_core_require_aplicacao_view_helper() {
7022 // Fail-before-pass-after pin on the [`typed_view`] delegation
7023 // to the lifted [`caixa_core::require_aplicacao_view`]
7024 // primitive: pre-lift the wrapper carried the three-line
7025 // `require_kind + aplicacao_view + AplicacaoSpec::validate`
7026 // cascade inline at this crate's own [`typed_view`] body with
7027 // no compile-time link to any substrate-canonical compound
7028 // entry-gate the sibling per-Servico renderers already route
7029 // through ([`caixa_core::require_v0_servico_shape`]).
7030 // Converging the wrapper on the substrate-canonical
7031 // [`caixa_core::require_aplicacao_view`] compound gate closes
7032 // the drift potential structurally: every future per-Aplicacao
7033 // consumer (the deferred `mesh.pleme.io/v1alpha1/Aplicacao`
7034 // CR materializer's admission webhook the M4 roadmap names,
7035 // `caixa-tatara`'s spec-consuming validate arm when it grows
7036 // beyond the `require_kind`-only entry gate it carries today
7037 // at caixa-tatara/src/lib.rs:203, a future `feira validate
7038 // --aplicacao` per-caixa admission verb) reaches for one
7039 // `caixa_core::require_aplicacao_view::<Error>(caixa)?`
7040 // one-liner and gets the compound three-arm gate for free —
7041 // matching the peer [`caixa_core::require_v0_servico_shape`]
7042 // discipline every per-Servico renderer already routes
7043 // through.
7044 //
7045 // Byte-for-byte parity assertion: [`typed_view`]'s
7046 // Ok/Err discrimination on every fixture must equal
7047 // [`caixa_core::require_aplicacao_view`]'s discrimination on
7048 // the same fixture (Ok arm — same serialized `AplicacaoSpec`;
7049 // Err arm — same Display bytes). Trips at the caller's build
7050 // time, not silently at the diagnostic-emission site. Peer to
7051 // the sibling `programs_for_aplicacao_routes_entry_gate_
7052 // through_typed_view` drift-detection pin already in place on
7053 // this crate's per-renderer entry-gate axis.
7054 let ok_cases: Vec<Caixa> = vec![aplicacao_caixa()];
7055 for c in ok_cases {
7056 let via_wrapper = typed_view(&c).expect("valid aplicacao passes typed_view");
7057 let via_primitive = caixa_core::require_aplicacao_view::<Error>(&c)
7058 .expect("valid aplicacao passes require_aplicacao_view");
7059 assert_eq!(
7060 serde_yaml::to_string(&via_wrapper).expect("typed_view spec serializes"),
7061 serde_yaml::to_string(&via_primitive)
7062 .expect("require_aplicacao_view spec serializes"),
7063 "typed_view's Ok-arm AplicacaoSpec must equal \
7064 caixa_core::require_aplicacao_view's Ok-arm AplicacaoSpec \
7065 byte-for-byte on the same fixture — otherwise typed_view \
7066 has drifted from the substrate primitive"
7067 );
7068 }
7069
7070 // Kind-mismatch axis: mis-kinded input surfaces the same
7071 // [`KindMismatch`]-carrying diagnostic through both paths.
7072 let mut c = aplicacao_caixa();
7073 c.kind = CaixaKind::Supervisor;
7074 c.servicos = vec![];
7075 c.children = vec![];
7076 let wrapper_err = typed_view(&c).unwrap_err();
7077 let primitive_err = caixa_core::require_aplicacao_view::<Error>(&c).unwrap_err();
7078 assert_eq!(
7079 format!("{wrapper_err}"),
7080 format!("{primitive_err}"),
7081 "typed_view's kind-mismatch Display bytes must equal \
7082 caixa_core::require_aplicacao_view's kind-mismatch Display \
7083 bytes — a future format edit lands in exactly one place \
7084 (caixa-core::render), not duplicated across every \
7085 per-Aplicacao renderer"
7086 );
7087 assert!(
7088 matches!(wrapper_err, Error::NotAnAplicacao(_)),
7089 "typed_view must forward the KindMismatch through the \
7090 Error::NotAnAplicacao #[from] arm"
7091 );
7092 assert!(
7093 matches!(primitive_err, Error::NotAnAplicacao(_)),
7094 "caixa_core::require_aplicacao_view must forward the \
7095 KindMismatch through the Error::NotAnAplicacao #[from] arm \
7096 — same discipline as the sibling require_v0_servico_shape \
7097 `E: From<KindMismatch>` bound"
7098 );
7099
7100 // Invalid-aplicacao axis: a valid-kind but spec-invalid caixa
7101 // (a `:contratos` entry referencing a non-member) surfaces
7102 // the same [`caixa_core::AplicacaoError`]-carrying diagnostic
7103 // through both paths — the peer `programs_for_aplicacao_
7104 // routes_entry_gate_through_typed_view` pin already covers
7105 // this axis on the outer renderer surface; extending it onto
7106 // the wrapper-vs-primitive surface here closes the drift
7107 // potential at both altitudes.
7108 let mut c = aplicacao_caixa();
7109 c.contratos.push(WitContract {
7110 de: "cart".into(),
7111 para: "phantom".into(),
7112 wit: "wasi:http/proxy".into(),
7113 endpoint: Some("/x".into()),
7114 subject: None,
7115 slot: None,
7116 });
7117 let wrapper_err = typed_view(&c).unwrap_err();
7118 let primitive_err = caixa_core::require_aplicacao_view::<Error>(&c).unwrap_err();
7119 assert_eq!(
7120 format!("{wrapper_err}"),
7121 format!("{primitive_err}"),
7122 "typed_view's invalid-aplicacao Display bytes must equal \
7123 caixa_core::require_aplicacao_view's invalid-aplicacao \
7124 Display bytes on the same non-member `:contratos :para` \
7125 fixture"
7126 );
7127 assert!(
7128 matches!(wrapper_err, Error::InvalidAplicacao(_)),
7129 "typed_view must forward the AplicacaoError through the \
7130 Error::InvalidAplicacao #[from] arm"
7131 );
7132 assert!(
7133 matches!(primitive_err, Error::InvalidAplicacao(_)),
7134 "caixa_core::require_aplicacao_view must forward the \
7135 AplicacaoError through the Error::InvalidAplicacao \
7136 #[from] arm"
7137 );
7138 }
7139
7140 // ── programs.yaml :placement overlay ─────────────────────────────────
7141
7142 fn placement_blocks(entries: &[serde_yaml::Value]) -> Vec<&serde_yaml::Mapping> {
7143 entries
7144 .iter()
7145 .map(|e| {
7146 e.get(M3_KEY_PLACEMENT)
7147 .and_then(|p| p.as_mapping())
7148 .expect("every member entry must carry a placement mapping")
7149 })
7150 .collect()
7151 }
7152
7153 #[test]
7154 fn programs_entry_carries_placement_block() {
7155 // The fixture sets `:placement :estrategia Replicated
7156 // :clusters ("rio" "mar") :affinity "data-locality"`. Every
7157 // emitted programs.yaml entry must carry a `placement:` block
7158 // wiring the typed `:placement` slot through to the rendered
7159 // artifact under the canonical [`M3_KEY_PLACEMENT`] key. Before
7160 // this overlay landed the typed slot was inert past
7161 // `AplicacaoSpec::validate_placement` — the rendered entry
7162 // carried only `name + versao + aplicacao`, so the
7163 // lareira-fleet-programs aggregator and the future
7164 // `app-operator` had no way to scope each entry by its parent
7165 // Aplicacao's distribution strategy. This test is the pinned
7166 // proof that the slot now reaches the cluster artifact (the
7167 // fail-before-pass-after pin: the assertion below fails on any
7168 // pre-overlay codebase, since the entry had no `placement:`
7169 // key at all).
7170 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
7171 assert!(!entries.is_empty());
7172 for e in &entries {
7173 assert!(
7174 e.get(M3_KEY_PLACEMENT).is_some(),
7175 "every member entry must carry a `placement:` block"
7176 );
7177 }
7178 }
7179
7180 #[test]
7181 fn programs_entry_placement_carries_strategy() {
7182 // Pin that the `placement.estrategia` axis round-trips the
7183 // typed [`PlacementStrategy`] enum verbatim — the fixture sets
7184 // `Replicated`, the serde Serialize impl emits the variant name
7185 // exactly. A future refactor that adds a `#[serde(rename_all =
7186 // …)]` attribute on the enum (e.g. shifting to lowercase to
7187 // match the lisp authoring spelling) is an intentional break
7188 // this test surfaces — coordinated with the consumer-side
7189 // (lareira-fleet-programs aggregator's strategy dispatcher,
7190 // future `app-operator` reconciler) to keep the contract
7191 // round-tripping end-to-end.
7192 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
7193 for p in placement_blocks(&entries) {
7194 assert_eq!(
7195 p.get(M3_PLACEMENT_KEY_ESTRATEGIA).and_then(|v| v.as_str()),
7196 Some(M3_PLACEMENT_ESTRATEGIA_REPLICATED),
7197 "placement.estrategia must round-trip the typed PlacementStrategy variant"
7198 );
7199 }
7200 }
7201
7202 #[test]
7203 fn programs_entry_placement_carries_clusters_list() {
7204 // Pin that the `placement.clusters` list round-trips the
7205 // validated cluster-pool list (non-empty + duplicate-free per
7206 // [`AplicacaoSpec::validate_placement`]) verbatim. The
7207 // downstream aggregator's per-cluster filter
7208 // (`programs.filter(|p| p.placement.clusters.contains(<self>))`)
7209 // depends on this round-tripping bit-for-bit — drift here
7210 // silently drops workloads from clusters that should run them.
7211 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
7212 for p in placement_blocks(&entries) {
7213 let clusters = p
7214 .get(M3_PLACEMENT_KEY_CLUSTERS)
7215 .and_then(|c| c.as_sequence())
7216 .expect("placement.clusters sequence");
7217 let names: Vec<&str> = clusters.iter().filter_map(|v| v.as_str()).collect();
7218 assert_eq!(names, vec!["rio", "mar"]);
7219 }
7220 }
7221
7222 #[test]
7223 fn programs_entry_placement_carries_affinity_when_set() {
7224 // The fixture's `:affinity "data-locality"` (Some) round-trips
7225 // through. Pin both the key spelling and the value to guard
7226 // against future rename / placement-engine semantic drift —
7227 // the `affinity:` value flows into the M3 Adaptive compression
7228 // weighting (MESH-COMPOSITION §V) and the wasm-operator's pod
7229 // affinity overlay.
7230 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
7231 for p in placement_blocks(&entries) {
7232 assert_eq!(
7233 p.get(M3_PLACEMENT_KEY_AFFINITY).and_then(|v| v.as_str()),
7234 Some("data-locality")
7235 );
7236 }
7237 }
7238
7239 #[test]
7240 fn programs_entry_placement_omits_affinity_and_shard_key_when_unset() {
7241 // Empty-axis-skip semantic (mirrors the `:politicas`
7242 // `:timeout`/`:retries`/`:mtls-required` overlays' omit-when-
7243 // unset contract): an Aplicacao that doesn't declare
7244 // `:placement :affinity` and uses a non-Sharded strategy
7245 // (`shardKey` always None) emits a `placement:` block with
7246 // exactly `estrategia` + `clusters` and no `affinity:` /
7247 // `shardKey:` keys. The Placement struct's
7248 // `skip_serializing_if = "Option::is_none"` semantic is what
7249 // delivers this; pin it at the renderer's exit so a future
7250 // refactor that drops the attribute (e.g. forcing every axis
7251 // to round-trip) silently bloating downstream programs.yaml
7252 // surfaces here.
7253 let mut c = aplicacao_caixa();
7254 if let Some(p) = c.placement.as_mut() {
7255 p.affinity = None;
7256 p.shard_key = None;
7257 }
7258 let entries = programs_for_aplicacao(&c).unwrap();
7259 for p in placement_blocks(&entries) {
7260 assert!(
7261 p.get(M3_PLACEMENT_KEY_AFFINITY).is_none(),
7262 "placement.affinity must be absent when :affinity is None"
7263 );
7264 assert!(
7265 p.get(M3_PLACEMENT_KEY_SHARD_KEY).is_none(),
7266 "placement.shardKey must be absent when :shard-key is None"
7267 );
7268 // Exactly 2 keys remain — estrategia + clusters.
7269 assert_eq!(p.len(), 2);
7270 }
7271 }
7272
7273 #[test]
7274 fn programs_entry_placement_carries_shard_key_when_sharded() {
7275 // The `Sharded` strategy carries a `:shard-key` (validated
7276 // non-empty by [`AplicacaoSpec::validate_placement`] — the
7277 // ShardedKeyEmpty arm). Pin that the typed slot's value
7278 // round-trips through to `placement.shardKey` under the
7279 // canonical camelCase key — the future Akka-style cluster-
7280 // sharding reconciler (MESH-COMPOSITION §II.4) keys off this
7281 // exact spelling to compute hash-based entity placement.
7282 let mut c = aplicacao_caixa();
7283 if let Some(p) = c.placement.as_mut() {
7284 p.estrategia = PlacementStrategy::Sharded;
7285 p.shard_key = Some("$tenantId".into());
7286 }
7287 let entries = programs_for_aplicacao(&c).unwrap();
7288 for p in placement_blocks(&entries) {
7289 assert_eq!(
7290 p.get(M3_PLACEMENT_KEY_ESTRATEGIA).and_then(|v| v.as_str()),
7291 Some(M3_PLACEMENT_ESTRATEGIA_SHARDED)
7292 );
7293 assert_eq!(
7294 p.get(M3_PLACEMENT_KEY_SHARD_KEY).and_then(|v| v.as_str()),
7295 Some("$tenantId")
7296 );
7297 }
7298 }
7299
7300 #[test]
7301 fn programs_entry_placement_appears_on_every_member() {
7302 // Multiple `:membros` entries → multiple programs.yaml rows.
7303 // The placement overlay must apply to every entry, not just
7304 // the first one — pin so a future refactor that hoists the
7305 // overlay out of the loop without re-cloning into each row
7306 // can't accidentally drop the placement from the tail
7307 // entries. Same hoist-out-of-loop guard the `:politicas`
7308 // overlay tests enshrine for HTTPRoute / CNP rules. The
7309 // fixture has 3 members; the assertion catches any regression
7310 // that drops the block from the 2nd or 3rd entry.
7311 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
7312 assert_eq!(entries.len(), 3);
7313 let placements = placement_blocks(&entries);
7314 assert_eq!(placements.len(), 3);
7315 // Every placement block must carry the same estrategia +
7316 // clusters — the placement is graph-level (one per
7317 // Aplicacao), so it's identical across members by
7318 // construction.
7319 let first = placements[0];
7320 for p in &placements[1..] {
7321 assert_eq!(
7322 p.get(M3_PLACEMENT_KEY_ESTRATEGIA),
7323 first.get(M3_PLACEMENT_KEY_ESTRATEGIA),
7324 "placement.estrategia must be identical across all members"
7325 );
7326 assert_eq!(
7327 p.get(M3_PLACEMENT_KEY_CLUSTERS),
7328 first.get(M3_PLACEMENT_KEY_CLUSTERS),
7329 "placement.clusters must be identical across all members"
7330 );
7331 }
7332 }
7333
7334 #[test]
7335 fn programs_entry_placement_uses_lifted_canonical_key() {
7336 // Pin the key spelling via the lifted [`M3_KEY_PLACEMENT`]
7337 // const (instead of an inline `"placement"` literal). Drift
7338 // between the renderer-side emission and the consumer-side
7339 // (lareira-fleet-programs aggregator's filter, future
7340 // `app-operator` dispatcher) is a programs.yaml entry whose
7341 // placement is silently dropped at the consumer's filter
7342 // step. Lifting the key to a const + pinning the const here
7343 // makes a future top-level rename a one-line edit + this
7344 // test's verification, not a search-and-replace across every
7345 // consumer crate.
7346 assert_eq!(M3_KEY_PLACEMENT, "placement");
7347 let entries = programs_for_aplicacao(&aplicacao_caixa()).unwrap();
7348 for e in &entries {
7349 let m = e.as_mapping().expect("entry mapping");
7350 assert!(
7351 m.contains_key(M3_KEY_PLACEMENT),
7352 "entry must carry the M3_KEY_PLACEMENT key exactly"
7353 );
7354 }
7355 }
7356
7357 #[test]
7358 fn m3_placement_key_estrategia_pins_canonical_value() {
7359 // Bridge-arm pin: [`M3_PLACEMENT_KEY_ESTRATEGIA`] resolves to
7360 // the canonical `"estrategia"` byte today — the exact YAML
7361 // sub-key the M3 [`caixa_core::aplicacao::Placement`] struct's
7362 // `#[serde(rename_all = "camelCase")]` derive emits for its
7363 // `estrategia` field, and the exact scalar every downstream
7364 // dispatch consults (the lareira-fleet-programs aggregator's
7365 // per-entry `placement.estrategia` strategy branch, the future
7366 // `app-operator` reconciler's per-Aplicacao takeover dispatch,
7367 // the future `mesh.pleme.io/v1alpha1/Aplicacao` CR
7368 // materializer's admission-time typed-enum bind, the M3
7369 // Adaptive compression weighting per MESH-COMPOSITION.md §V).
7370 // Peer with the [`programs_entry_placement_uses_lifted_canonical_key`]
7371 // canonical-literal pin on the sibling per-entry overlay-key
7372 // surface — that pin anchors the top-level `placement:` byte,
7373 // this pin anchors the per-sub-block `estrategia:` byte both
7374 // consumers dispatch on.
7375 assert_eq!(M3_PLACEMENT_KEY_ESTRATEGIA, "estrategia");
7376 }
7377
7378 #[test]
7379 fn m3_placement_key_estrategia_matches_placement_serde_derive() {
7380 // Structural pin: the lifted [`M3_PLACEMENT_KEY_ESTRATEGIA`]
7381 // byte equals the exact key
7382 // [`caixa_core::aplicacao::Placement`]'s
7383 // `#[serde(rename_all = "camelCase")]` derive emits for its
7384 // `estrategia` field. A future refactor that (a) renames the
7385 // Rust field to `strategy` / `distribution` for English-
7386 // uniformity, or (b) retains the field name but adds a
7387 // per-field `#[serde(rename = "…")]` override, or (c) drops
7388 // the `rename_all = "camelCase"` attribute entirely, would
7389 // silently emit a `placement:` block whose distribution-
7390 // strategy discriminator lands under one key while every
7391 // downstream consumer (the lareira-fleet-programs aggregator's
7392 // dispatch, the future `app-operator` reconciler, the future
7393 // CR materializer's admission bind) still probes another. The
7394 // structural bind between the derive-time output and the
7395 // consumer-side navigation const is what this pin enforces —
7396 // any derive-side rebrand must be a coordinated edit at the
7397 // lifted const's definition site + here, not a silent apply-
7398 // time no-op at the aggregator's filter step. Peer with the
7399 // [`FLEET_PROGRAMS_KEY_APLICACAO`] / [`FLEET_PROGRAMS_KEY_VERSAO`]
7400 // / [`FLEET_PROGRAMS_KEY_NAME`] canonical-literal pins on the
7401 // sibling per-entry fleet-programs schema-key surfaces on the
7402 // same "one const, structurally bound to the derive-emitted
7403 // shape, tested at both endpoints" discipline every prior
7404 // canonical-schema-key lift on this surface established.
7405 let placement = Placement {
7406 estrategia: PlacementStrategy::Replicated,
7407 clusters: vec!["rio".to_string(), "mar".to_string()],
7408 affinity: None,
7409 shard_key: None,
7410 };
7411 let value = serde_yaml::to_value(&placement).expect("serialize Placement");
7412 let mapping = value
7413 .as_mapping()
7414 .expect("Placement serializes to a mapping");
7415 assert!(
7416 mapping.contains_key(M3_PLACEMENT_KEY_ESTRATEGIA),
7417 "Placement's serde derive must emit the estrategia axis under the exact key \
7418 the lifted M3_PLACEMENT_KEY_ESTRATEGIA const carries; got mapping keys: {keys:?}",
7419 keys = mapping
7420 .keys()
7421 .filter_map(|k| k.as_str().map(str::to_string))
7422 .collect::<Vec<_>>()
7423 );
7424 }
7425
7426 #[test]
7427 fn m3_placement_key_clusters_pins_canonical_value() {
7428 // Bridge-arm pin: [`M3_PLACEMENT_KEY_CLUSTERS`] resolves to the
7429 // canonical `"clusters"` byte today — the exact YAML sub-key the
7430 // M3 [`caixa_core::aplicacao::Placement`] struct's
7431 // `#[serde(rename_all = "camelCase")]` derive emits for its
7432 // `clusters` field, and the exact scalar every downstream
7433 // per-cluster fanout consumer scopes off (the lareira-fleet-
7434 // programs aggregator's per-cluster `.placement.clusters | contains
7435 // .Values.cluster` filter, the future `app-operator` reconciler's
7436 // per-Aplicacao cluster-set dispatch, the future
7437 // `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's admission-
7438 // time typed-list bind, the M3 Adaptive per-cluster weighting per
7439 // MESH-COMPOSITION.md §V). Peer with the
7440 // [`m3_placement_key_estrategia_pins_canonical_value`] canonical-
7441 // literal pin on the sibling per-sub-block strategy-discriminator
7442 // surface — that pin anchors the per-`placement:` `estrategia:`
7443 // byte every dispatch consumer branches on, this pin anchors the
7444 // per-`placement:` `clusters:` byte every per-cluster fanout
7445 // consumer filters by.
7446 assert_eq!(M3_PLACEMENT_KEY_CLUSTERS, "clusters");
7447 }
7448
7449 #[test]
7450 fn m3_placement_key_clusters_matches_placement_serde_derive() {
7451 // Structural pin: the lifted [`M3_PLACEMENT_KEY_CLUSTERS`] byte
7452 // equals the exact key [`caixa_core::aplicacao::Placement`]'s
7453 // `#[serde(rename_all = "camelCase")]` derive emits for its
7454 // `clusters` field. A future refactor that (a) renames the Rust
7455 // field to `clusterPool` / `sites` for schema-clarity or eventual
7456 // multi-substrate reach, or (b) retains the field name but adds a
7457 // per-field `#[serde(rename = "…")]` override, or (c) drops the
7458 // `rename_all = "camelCase"` attribute entirely, would silently
7459 // emit a `placement:` block whose cluster-list lands under one
7460 // key while every downstream per-cluster fanout consumer (the
7461 // lareira-fleet-programs aggregator's filter, the future
7462 // `app-operator` reconciler, the future CR materializer's
7463 // admission bind) still probes another. The structural bind
7464 // between the derive-time output and the consumer-side navigation
7465 // const is what this pin enforces — any derive-side rebrand must
7466 // be a coordinated edit at the lifted const's definition site +
7467 // here, not a silent apply-time no-op at the aggregator's fanout
7468 // step. Peer with the
7469 // [`m3_placement_key_estrategia_matches_placement_serde_derive`]
7470 // structural pin on the sibling per-sub-block strategy-
7471 // discriminator axis on the same "one const, structurally bound
7472 // to the derive-emitted shape, tested at both endpoints"
7473 // discipline every prior canonical-schema-key lift on this
7474 // surface established.
7475 let placement = Placement {
7476 estrategia: PlacementStrategy::Replicated,
7477 clusters: vec!["rio".to_string(), "mar".to_string()],
7478 affinity: None,
7479 shard_key: None,
7480 };
7481 let value = serde_yaml::to_value(&placement).expect("serialize Placement");
7482 let mapping = value
7483 .as_mapping()
7484 .expect("Placement serializes to a mapping");
7485 assert!(
7486 mapping.contains_key(M3_PLACEMENT_KEY_CLUSTERS),
7487 "Placement's serde derive must emit the clusters axis under the exact key \
7488 the lifted M3_PLACEMENT_KEY_CLUSTERS const carries; got mapping keys: {keys:?}",
7489 keys = mapping
7490 .keys()
7491 .filter_map(|k| k.as_str().map(str::to_string))
7492 .collect::<Vec<_>>()
7493 );
7494 }
7495
7496 #[test]
7497 fn m3_placement_key_affinity_pins_canonical_value() {
7498 // Bridge-arm pin: [`M3_PLACEMENT_KEY_AFFINITY`] resolves to the
7499 // canonical `"affinity"` byte today — the exact YAML sub-key the
7500 // M3 [`caixa_core::aplicacao::Placement`] struct's
7501 // `#[serde(rename_all = "camelCase")]` derive emits for its
7502 // `affinity` field, and the exact scalar every downstream
7503 // placement-hint consumer weights off (the lareira-fleet-programs
7504 // aggregator's per-entry M3 Adaptive compression pass per
7505 // MESH-COMPOSITION.md §V, the future `app-operator` reconciler's
7506 // per-Aplicacao pod-affinity / node-affinity K8s-primitive
7507 // materializer, the future `mesh.pleme.io/v1alpha1/Aplicacao` CR
7508 // materializer's admission-time typed-string bind, the M4 cross-
7509 // cluster placement engine's per-hint takeover-priority dispatch).
7510 // Peer with the [`m3_placement_key_estrategia_pins_canonical_value`]
7511 // + [`m3_placement_key_clusters_pins_canonical_value`] canonical-
7512 // literal pins on the sibling per-sub-block always-emitted
7513 // strategy-discriminator / cluster-pool surfaces — those pins
7514 // anchor the always-emitted `estrategia:` / `clusters:` bytes
7515 // every dispatch / fanout consumer branches on, this pin anchors
7516 // the optional-emitted `affinity:` byte every weighting consumer
7517 // reads off when the typed slot resolves to `Some(_)`.
7518 assert_eq!(M3_PLACEMENT_KEY_AFFINITY, "affinity");
7519 }
7520
7521 #[test]
7522 fn m3_placement_key_affinity_matches_placement_serde_derive() {
7523 // Structural pin: the lifted [`M3_PLACEMENT_KEY_AFFINITY`] byte
7524 // equals the exact key [`caixa_core::aplicacao::Placement`]'s
7525 // `#[serde(rename_all = "camelCase")]` derive emits for its
7526 // `affinity` field when the typed slot resolves to `Some(_)`. A
7527 // future refactor that (a) renames the Rust field to
7528 // `affinityHint` / `placementHint` for schema-clarity, or (b)
7529 // retains the field name but adds a per-field
7530 // `#[serde(rename = "…")]` override, or (c) drops the
7531 // `rename_all = "camelCase"` attribute entirely, or (d) drops the
7532 // `skip_serializing_if = "Option::is_none"` attribute (letting a
7533 // `None` slot emit `affinity: null` and thereby breaking the
7534 // omit-when-unset contract every peer typed slot carries), would
7535 // silently emit a `placement:` block whose affinity hint lands
7536 // under one key while every downstream weighting consumer (the M3
7537 // Adaptive compression pass, the future `app-operator`
7538 // reconciler's pod-affinity / node-affinity materializer, the
7539 // future CR materializer's admission bind, the M4 cross-cluster
7540 // placement engine's per-hint dispatch) still probes another. The
7541 // structural bind between the derive-time output and the
7542 // consumer-side navigation const is what this pin enforces — any
7543 // derive-side rebrand must be a coordinated edit at the lifted
7544 // const's definition site + here, not a silent apply-time no-op
7545 // at the aggregator's weighting step. Peer with the
7546 // [`m3_placement_key_estrategia_matches_placement_serde_derive`]
7547 // + [`m3_placement_key_clusters_matches_placement_serde_derive`]
7548 // structural pins on the sibling per-sub-block always-emitted
7549 // axes on the same "one const, structurally bound to the derive-
7550 // emitted shape, tested at both endpoints" discipline every prior
7551 // canonical-schema-key lift on this surface established. Unlike
7552 // the peer pins (which construct a `Placement` with the axis
7553 // always present and simply probe for the key), this pin
7554 // constructs a `Placement` with `affinity: Some(_)` to force the
7555 // `skip_serializing_if` gate open so the derive-emitted key
7556 // actually appears in the serialized mapping.
7557 let placement = Placement {
7558 estrategia: PlacementStrategy::Replicated,
7559 clusters: vec!["rio".to_string(), "mar".to_string()],
7560 affinity: Some("data-locality".to_string()),
7561 shard_key: None,
7562 };
7563 let value = serde_yaml::to_value(&placement).expect("serialize Placement");
7564 let mapping = value
7565 .as_mapping()
7566 .expect("Placement serializes to a mapping");
7567 assert!(
7568 mapping.contains_key(M3_PLACEMENT_KEY_AFFINITY),
7569 "Placement's serde derive must emit the affinity axis under the exact key \
7570 the lifted M3_PLACEMENT_KEY_AFFINITY const carries when the typed slot \
7571 resolves to `Some(_)`; got mapping keys: {keys:?}",
7572 keys = mapping
7573 .keys()
7574 .filter_map(|k| k.as_str().map(str::to_string))
7575 .collect::<Vec<_>>()
7576 );
7577 }
7578
7579 #[test]
7580 fn m3_placement_key_shard_key_pins_canonical_value() {
7581 // Bridge-arm pin: [`M3_PLACEMENT_KEY_SHARD_KEY`] resolves to the
7582 // canonical `"shardKey"` byte today — the exact YAML sub-key the
7583 // M3 [`caixa_core::aplicacao::Placement`] struct's
7584 // `#[serde(rename_all = "camelCase")]` derive emits for its
7585 // `shard_key` field, and the exact scalar every downstream shard-
7586 // dispatch consumer materializes off (the lareira-fleet-programs
7587 // aggregator's per-entry M3 shard-pool dispatch materializer per
7588 // MESH-COMPOSITION.md §II.4, the future `app-operator`
7589 // reconciler's per-Aplicacao `ShardedResource` CR emitter, the
7590 // future `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's
7591 // admission-time typed-string bind, the M4 Orleans-style virtual-
7592 // actor runtime's per-grain placement dispatch per
7593 // RUNTIME-PATTERNS.md). Peer with the
7594 // [`m3_placement_key_estrategia_pins_canonical_value`] +
7595 // [`m3_placement_key_clusters_pins_canonical_value`] +
7596 // [`m3_placement_key_affinity_pins_canonical_value`] canonical-
7597 // literal pins on the sibling per-sub-block strategy-discriminator
7598 // / cluster-pool / placement-hint surfaces — those pins anchor
7599 // the peer axes' bytes, this pin anchors the optional-emitted
7600 // `shardKey:` byte every shard-dispatch consumer keys off when
7601 // the typed slot resolves to `Some(_)` under the `Sharded`
7602 // strategy.
7603 assert_eq!(M3_PLACEMENT_KEY_SHARD_KEY, "shardKey");
7604 }
7605
7606 #[test]
7607 fn m3_placement_key_shard_key_matches_placement_serde_derive() {
7608 // Structural pin: the lifted [`M3_PLACEMENT_KEY_SHARD_KEY`] byte
7609 // equals the exact key [`caixa_core::aplicacao::Placement`]'s
7610 // `#[serde(rename_all = "camelCase")]` derive emits for its
7611 // `shard_key` field when the typed slot resolves to `Some(_)`. A
7612 // future refactor that (a) renames the Rust field to
7613 // `partition_key` for Kafka-symmetric naming, `entity_key` for
7614 // Akka/Orleans-symmetric naming, `hash_key` for schema-clarity,
7615 // etc., or (b) retains the field name but adds a per-field
7616 // `#[serde(rename = "…")]` override, or (c) drops the
7617 // `rename_all = "camelCase"` attribute entirely, or (d) drops the
7618 // `skip_serializing_if = "Option::is_none"` attribute (letting a
7619 // `None` slot emit `shardKey: null` and thereby breaking the
7620 // omit-when-unset contract every peer typed slot carries), would
7621 // silently emit a `placement:` block whose shard-selection
7622 // template lands under one key while every downstream shard-
7623 // dispatch consumer (the M3 shard-pool dispatch materializer, the
7624 // future `app-operator` reconciler's `ShardedResource` CR
7625 // emitter, the future CR materializer's admission bind, the M4
7626 // Orleans-style virtual-actor runtime's per-grain placement
7627 // dispatch) still probes another. The structural bind between the
7628 // derive-time output and the consumer-side navigation const is
7629 // what this pin enforces — any derive-side rebrand must be a
7630 // coordinated edit at the lifted const's definition site + here,
7631 // not a silent apply-time no-op at the aggregator's shard-
7632 // dispatch step. Peer with the sibling per-sub-block
7633 // `matches_placement_serde_derive` pins on the same "one const,
7634 // structurally bound to the derive-emitted shape, tested at both
7635 // endpoints" discipline every prior canonical-schema-key lift on
7636 // this surface established. Like the peer
7637 // [`m3_placement_key_affinity_matches_placement_serde_derive`]
7638 // pin (and unlike the always-emitted `estrategia` / `clusters`
7639 // pins), this pin constructs a `Placement` with
7640 // `shard_key: Some(_)` to force the `skip_serializing_if` gate
7641 // open so the derive-emitted key actually appears in the
7642 // serialized mapping. Uniquely on this axis (relative to every
7643 // sibling `Placement` sub-key pin), the underlying serde
7644 // transform is *not* a no-op — the source-side field name
7645 // `shard_key` carries a `_` the `rename_all = "camelCase"`
7646 // derive actively transforms to `shardKey`, so any rebrand that
7647 // touches either endpoint of the transform (the field name OR
7648 // the `rename_all` attribute OR a per-field `rename` override)
7649 // reaches this assertion by construction.
7650 let placement = Placement {
7651 estrategia: PlacementStrategy::Sharded,
7652 clusters: vec!["rio".to_string(), "mar".to_string()],
7653 affinity: None,
7654 shard_key: Some("$tenantId".to_string()),
7655 };
7656 let value = serde_yaml::to_value(&placement).expect("serialize Placement");
7657 let mapping = value
7658 .as_mapping()
7659 .expect("Placement serializes to a mapping");
7660 assert!(
7661 mapping.contains_key(M3_PLACEMENT_KEY_SHARD_KEY),
7662 "Placement's serde derive must emit the shard_key axis under the exact key \
7663 the lifted M3_PLACEMENT_KEY_SHARD_KEY const carries when the typed slot \
7664 resolves to `Some(_)`; got mapping keys: {keys:?}",
7665 keys = mapping
7666 .keys()
7667 .filter_map(|k| k.as_str().map(str::to_string))
7668 .collect::<Vec<_>>()
7669 );
7670 }
7671
7672 #[test]
7673 fn typed_view_returns_validated_spec() {
7674 let spec = typed_view(&aplicacao_caixa()).unwrap();
7675 // Route the per-`:membros` / per-`:contratos` list-length probes and
7676 // the per-`:placement` distribution-target-list length probe through
7677 // the lifted [`caixa_core::AplicacaoSpec::membros`] /
7678 // [`caixa_core::AplicacaoSpec::contratos`] slice-return accessors and
7679 // the paired [`caixa_core::AplicacaoSpec::placement`] +
7680 // [`caixa_core::Placement::clusters`] outer-then-inner accessors
7681 // rather than the raw `spec.<field>` / `spec.placement.clusters`
7682 // field accesses — sibling to the peer per-`:entrada` presence-bit
7683 // probe below that already routes through
7684 // [`caixa_core::AplicacaoSpec::entrada`] (9e8630e). Every accessor
7685 // projects its backing slot verbatim (byte-equal to the raw field
7686 // access), pinned in caixa-core at
7687 // `aplicacao_spec_membros_returns_membros_slice_byte_equal_across_permutations`,
7688 // `aplicacao_spec_contratos_returns_contratos_slice_byte_equal_across_permutations`,
7689 // `aplicacao_spec_placement_returns_placement_ref_byte_equal_across_permutations`,
7690 // and
7691 // `placement_clusters_returns_clusters_slice_byte_equal_across_permutations`.
7692 // Closes the last unlifted per-`AplicacaoSpec` raw-field-access
7693 // sites in the caixa-mesh `typed_view_returns_validated_spec` test.
7694 assert_eq!(spec.membros().len(), 3);
7695 assert_eq!(spec.contratos().len(), 2);
7696 // Route the per-`:entrada` presence-bit probe through the lifted
7697 // [`caixa_core::AplicacaoSpec::entrada`] accessor rather than the
7698 // raw `spec.entrada.is_some()` field access — sibling to the
7699 // production `gateway_routes` reader at :2806 that already routes
7700 // its `Some(_)` / `None` early-return partition through the same
7701 // accessor. The accessor projects the raw `Option<Entrada>` slot's
7702 // presence bit through the reference-return unchanged (`entrada()
7703 // -> Option<&Entrada>` = `self.entrada.as_ref()`), so `is_some()`
7704 // on both sides is byte-equal — pinned in caixa-core at
7705 // `aplicacao_spec_entrada_returns_entrada_option_ref_byte_equal_across_permutations`.
7706 assert!(spec.entrada().is_some());
7707 assert_eq!(spec.placement().clusters().len(), 2);
7708 }
7709
7710 #[test]
7711 fn cilium_emits_one_policy_per_de_para_pair() {
7712 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
7713 assert_eq!(policies.len(), 2);
7714 let names: Vec<_> = policies
7715 .iter()
7716 .map(|p| {
7717 kube_metadata_str_field(p, KUBE_KEY_NAME)
7718 .unwrap()
7719 .to_string()
7720 })
7721 .collect();
7722 assert!(names.contains(&"checkout-cart-to-catalog".to_string()));
7723 assert!(names.contains(&"checkout-cart-to-payment".to_string()));
7724 }
7725
7726 #[test]
7727 fn cilium_fans_same_de_para_edges_into_one_policy() {
7728 // Fail-before / pass-after: AplicacaoSpec::validate permits two
7729 // contratos sharing a `(:de, :para)` pair with distinct payloads
7730 // (cart→catalog at `/products/:id` *and* `/search`). The renderer
7731 // names every CiliumNetworkPolicy `<aplicacao>-<de>-to-<para>`, so
7732 // before the per-pair fan-in those two contratos rendered two
7733 // objects both named `checkout-cart-to-catalog` — a `kubectl apply`
7734 // collision far from the source caixa.lisp. They must now fan into
7735 // exactly one policy whose `ingress[0].toPorts[]` carries both
7736 // edges' L7 paths.
7737 let mut c = aplicacao_caixa();
7738 c.contratos.push(WitContract {
7739 de: "cart".into(),
7740 para: "catalog".into(),
7741 wit: "wasi:http/proxy".into(),
7742 endpoint: Some("/search".into()),
7743 subject: None,
7744 slot: None,
7745 });
7746 let policies = cilium_network_policies(&c).unwrap();
7747
7748 let cart_to_catalog: Vec<_> = policies
7749 .iter()
7750 .filter(|p| {
7751 kube_metadata_str_field(p, KUBE_KEY_NAME) == Some("checkout-cart-to-catalog")
7752 })
7753 .collect();
7754 assert_eq!(
7755 cart_to_catalog.len(),
7756 1,
7757 "two cart→catalog contratos must fan into one policy, not two \
7758 colliding `checkout-cart-to-catalog` objects"
7759 );
7760
7761 let to_ports = cart_to_catalog[0]
7762 .get(KUBE_KEY_SPEC)
7763 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
7764 .and_then(|i| i.as_sequence())
7765 .and_then(|s| s.first())
7766 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
7767 .and_then(|p| p.as_sequence())
7768 .expect("ingress[0].toPorts sequence");
7769 assert_eq!(
7770 to_ports.len(),
7771 2,
7772 "each typed edge in the (cart, catalog) group contributes one toPorts entry"
7773 );
7774 let paths: Vec<&str> = to_ports
7775 .iter()
7776 .filter_map(|tp| {
7777 tp.get(KUBE_KEY_RULES)
7778 .and_then(|r| r.get(CILIUM_KEY_HTTP))
7779 .and_then(|h| h.as_sequence())
7780 .and_then(|s| s.first())
7781 .and_then(|rule| rule.get(CILIUM_KEY_PATH))
7782 .and_then(|v| v.as_str())
7783 })
7784 .collect();
7785 assert!(
7786 paths.contains(&"/products/:id") && paths.contains(&"/search"),
7787 "both edges' L7 paths must survive the fan-in, got {paths:?}"
7788 );
7789 }
7790
7791 #[test]
7792 fn cilium_policies_are_identity_based() {
7793 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
7794 for p in &policies {
7795 let endpoint = p
7796 .get(KUBE_KEY_SPEC)
7797 .and_then(|s| s.get(CILIUM_KEY_ENDPOINT_SELECTOR))
7798 .and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))
7799 .unwrap();
7800 assert!(endpoint.get(LABEL_PROGRAM).is_some());
7801 // Source endpoint must include both program + aplicacao labels
7802 let from = p
7803 .get(KUBE_KEY_SPEC)
7804 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
7805 .and_then(|i| i.as_sequence())
7806 .and_then(|s| s.first())
7807 .and_then(|i| i.get(CILIUM_KEY_FROM_ENDPOINTS))
7808 .and_then(|e| e.as_sequence())
7809 .and_then(|s| s.first())
7810 .and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))
7811 .unwrap();
7812 assert_eq!(
7813 from.get(LABEL_APLICACAO).and_then(|v| v.as_str()),
7814 Some("checkout")
7815 );
7816 let from_program = from.get(LABEL_PROGRAM).and_then(|v| v.as_str()).unwrap();
7817 assert!(
7818 from_program == "cart" || from_program == "payment",
7819 "fromEndpoints.matchLabels.{LABEL_PROGRAM} = {from_program:?} \
7820 must name the source caixa of one of the fixture's two contratos"
7821 );
7822 }
7823 }
7824
7825 #[test]
7826 fn cilium_policy_metadata_labels_use_lifted_consts() {
7827 // The policy's own labels (carried at metadata.labels, not on
7828 // workload pods) must come through caixa_core::render's typed
7829 // constants. Pinning the keys via the lifted consts (instead
7830 // of inline `"pleme.pleme.io/aplicacao"` strings) makes drift
7831 // between render-side emission and consumer-side selection
7832 // (Hubble flow grouping, operator policy filters) a build
7833 // error: a future label-namespace rename is one PLEME_LABEL_PREFIX
7834 // edit, and this test pins that the rename actually flows
7835 // through to the policy metadata.
7836 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
7837 for p in &policies {
7838 let labels = p
7839 .get(KUBE_KEY_METADATA)
7840 .and_then(|m| m.get(KUBE_KEY_LABELS))
7841 .and_then(|l| l.as_mapping())
7842 .expect("policy metadata.labels mapping");
7843 assert_eq!(
7844 labels.get(LABEL_APLICACAO).and_then(|v| v.as_str()),
7845 Some("checkout")
7846 );
7847 // The contrato label is `<de>-to-<para>`; both fixture
7848 // edges have :de = "cart".
7849 let contrato_val = labels
7850 .get(LABEL_CONTRATO)
7851 .and_then(|v| v.as_str())
7852 .expect("contrato label present");
7853 assert!(
7854 contrato_val.starts_with("cart-to-"),
7855 "contrato label {contrato_val:?} must follow `<de>-to-<para>` shape"
7856 );
7857 // No leaked stale labels — every pleme-prefixed key on the
7858 // policy's own metadata must come from the lifted const set.
7859 // (Workload-identity labels live elsewhere — this only
7860 // checks the policy's *own* metadata.labels block.)
7861 for (k, _) in labels {
7862 if let Some(s) = k.as_str() {
7863 if s.starts_with(caixa_core::PLEME_LABEL_PREFIX) {
7864 assert!(
7865 s == LABEL_APLICACAO || s == LABEL_CONTRATO,
7866 "policy metadata.labels carries unexpected pleme-prefixed key {s:?} \
7867 (only LABEL_APLICACAO + LABEL_CONTRATO are canonical here)"
7868 );
7869 }
7870 }
7871 }
7872 }
7873 }
7874
7875 #[test]
7876 fn cilium_endpoint_selector_is_program_only() {
7877 // The destination matchLabels must be the single-axis
7878 // (program-only) selector — pinning that the lift to the
7879 // typed helper preserves the existing one-key semantic
7880 // (caixa-mesh deliberately matches every pod with the
7881 // destination program name in this cluster, regardless of
7882 // Aplicacao). If a future change wants to scope the
7883 // destination by Aplicacao too, that's an intentional
7884 // semantic shift, not an accidental drift.
7885 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
7886 for p in &policies {
7887 let selector = p
7888 .get(KUBE_KEY_SPEC)
7889 .and_then(|s| s.get(CILIUM_KEY_ENDPOINT_SELECTOR))
7890 .and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))
7891 .and_then(|m| m.as_mapping())
7892 .expect("endpointSelector.matchLabels mapping");
7893 assert_eq!(
7894 selector.len(),
7895 1,
7896 "destination endpointSelector must be the program-only selector"
7897 );
7898 assert!(selector.get(LABEL_PROGRAM).is_some());
7899 }
7900 }
7901
7902 #[test]
7903 fn cilium_from_endpoints_carries_aplicacao_scoped_selector() {
7904 // The source fromEndpoints.matchLabels must be the two-axis
7905 // selector (program + aplicacao) — pinning that the lift to
7906 // pleme_program_in_aplicacao_selector preserves the safety
7907 // property that a same-named program in a different Aplicacao
7908 // cannot satisfy the rule.
7909 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
7910 for p in &policies {
7911 let from = p
7912 .get(KUBE_KEY_SPEC)
7913 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
7914 .and_then(|i| i.as_sequence())
7915 .and_then(|s| s.first())
7916 .and_then(|i| i.get(CILIUM_KEY_FROM_ENDPOINTS))
7917 .and_then(|e| e.as_sequence())
7918 .and_then(|s| s.first())
7919 .and_then(|e| e.get(KUBE_KEY_MATCH_LABELS))
7920 .and_then(|m| m.as_mapping())
7921 .expect("fromEndpoints[0].matchLabels mapping");
7922 assert_eq!(
7923 from.len(),
7924 2,
7925 "source fromEndpoints must be the program-in-aplicacao selector (2 axes)"
7926 );
7927 assert!(from.get(LABEL_PROGRAM).is_some());
7928 assert!(from.get(LABEL_APLICACAO).is_some());
7929 }
7930 }
7931
7932 #[test]
7933 fn cilium_http_contracts_emit_l7_rules() {
7934 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
7935 let cart_to_catalog = policies
7936 .iter()
7937 .find(|p| kube_metadata_str_field(p, KUBE_KEY_NAME) == Some("checkout-cart-to-catalog"))
7938 .unwrap();
7939 let http_rules = cart_to_catalog
7940 .get(KUBE_KEY_SPEC)
7941 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
7942 .and_then(|i| i.as_sequence())
7943 .and_then(|s| s.first())
7944 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
7945 .and_then(|p| p.as_sequence())
7946 .and_then(|s| s.first())
7947 .and_then(|p| p.get(KUBE_KEY_RULES))
7948 .and_then(|r| r.get(CILIUM_KEY_HTTP))
7949 .and_then(|h| h.as_sequence())
7950 .unwrap();
7951 assert_eq!(http_rules.len(), 1);
7952 assert_eq!(
7953 http_rules[0].get(CILIUM_KEY_PATH).and_then(|v| v.as_str()),
7954 Some("/products/:id")
7955 );
7956 }
7957
7958 #[test]
7959 fn cilium_pubsub_contracts_skip_l7_rules() {
7960 let mut c = aplicacao_caixa();
7961 c.contratos.push(WitContract {
7962 de: "payment".into(),
7963 para: "cart".into(), // back-edge for testing only
7964 wit: "nats:pub-sub".into(),
7965 endpoint: None,
7966 subject: Some("checkout.events.charge.failed".into()),
7967 slot: None,
7968 });
7969 let policies = cilium_network_policies(&c).unwrap();
7970 let nats_policy = policies
7971 .iter()
7972 .find(|p| kube_metadata_str_field(p, KUBE_KEY_NAME) == Some("checkout-payment-to-cart"))
7973 .unwrap();
7974 let to_ports = nats_policy
7975 .get(KUBE_KEY_SPEC)
7976 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
7977 .and_then(|i| i.as_sequence())
7978 .and_then(|s| s.first())
7979 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
7980 .and_then(|p| p.as_sequence())
7981 .and_then(|s| s.first())
7982 .unwrap();
7983 // L4 ports yes; L7 rules no.
7984 assert!(to_ports.get(CILIUM_KEY_PORTS).is_some());
7985 assert!(to_ports.get(KUBE_KEY_RULES).is_none());
7986 }
7987
7988 #[test]
7989 fn gateway_emits_gateway_plus_httproute_pair() {
7990 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
7991 assert_eq!(docs.len(), 2);
7992 let kinds: Vec<_> = docs
7993 .iter()
7994 .map(|d| {
7995 d.get(KUBE_KEY_KIND)
7996 .and_then(|k| k.as_str())
7997 .unwrap()
7998 .to_string()
7999 })
8000 .collect();
8001 assert!(kinds.contains(&GATEWAY_API_KIND_GATEWAY.to_string()));
8002 assert!(kinds.contains(&GATEWAY_API_KIND_HTTP_ROUTE.to_string()));
8003 }
8004
8005 #[test]
8006 fn gateway_listener_carries_aplicacao_host() {
8007 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8008 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).unwrap();
8009 let listener = gateway
8010 .get(KUBE_KEY_SPEC)
8011 .and_then(|s| s.get(GATEWAY_API_KEY_LISTENERS))
8012 .and_then(|l| l.as_sequence())
8013 .and_then(|s| s.first())
8014 .unwrap();
8015 assert_eq!(
8016 listener
8017 .get(GATEWAY_API_KEY_HOSTNAME)
8018 .and_then(|h| h.as_str()),
8019 Some("checkout.quero.cloud")
8020 );
8021 assert_eq!(
8022 listener.get(KUBE_KEY_PROTOCOL).and_then(|p| p.as_str()),
8023 Some(GATEWAY_API_PROTOCOL_HTTP)
8024 );
8025 }
8026
8027 #[test]
8028 fn gateway_listener_name_routes_through_lifted_default_http_listener_name() {
8029 // The per-Aplicacao `Gateway`'s sole per-listener name-
8030 // discriminator axis (the `listener.insert(GATEWAY_API_KEY_NAME,
8031 // …)` call site in [`gateway_routes`]) must read from the lifted
8032 // [`caixa_core::GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`]
8033 // `&'static str` constant — not from an open-coded `"http"`
8034 // literal that could drift if the substrate's canonical
8035 // author-chosen short listener-name ever moved (`"http" →
8036 // "http-v1"` on the multi-listener HTTPS-by-default trajectory,
8037 // a per-cluster override the operator pins through a future
8038 // `:entrada :listener-name` slot). A future rebrand of the
8039 // constant must reach this consumer by construction so
8040 // downstream `HTTPRoute.spec.parentRefs[].sectionName`
8041 // selectors that bind by the canonical byte-string can't
8042 // silently orphan the route at attachment time. Peer with the
8043 // sibling
8044 // [`gateway_listener_port_routes_through_lifted_default_http_listener_port`]
8045 // pin on the [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] port-
8046 // scalar consumer at the same emitter — the two per-listener
8047 // substrate-canonical scalar-value axes name distinct scalars
8048 // (listener name identifier vs listener port), both now routed
8049 // through their own lifted const, so a substrate-side rebrand
8050 // on either axis lands at exactly one consumer per axis
8051 // without coupling the two rebrand cycles.
8052 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8053 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
8054 let listener = gateway
8055 .get(KUBE_KEY_SPEC)
8056 .and_then(|s| s.get(GATEWAY_API_KEY_LISTENERS))
8057 .and_then(|l| l.as_sequence())
8058 .and_then(|s| s.first())
8059 .expect("first listener present");
8060 assert_eq!(
8061 listener.get(GATEWAY_API_KEY_NAME).and_then(|n| n.as_str()),
8062 Some(GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME),
8063 "the Gateway per-listener name-discriminator scalar must render \
8064 the lifted GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME constant \
8065 verbatim — drift here means the constant lift no longer reaches \
8066 this consumer and every downstream HTTPRoute `sectionName` \
8067 selector authored against the substrate's canonical name would \
8068 miss its listener at attachment time"
8069 );
8070 }
8071
8072 #[test]
8073 fn httproute_parent_ref_pins_section_name_to_lifted_default_http_listener_name() {
8074 // The per-Aplicacao `HTTPRoute`'s sole per-parentRef listener-
8075 // selector sub-axis (the `parent_ref.insert(GATEWAY_API_KEY_SECTION_NAME,
8076 // GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME)` call site in
8077 // [`gateway_routes`]) must render the same lifted
8078 // [`caixa_core::GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`]
8079 // `&'static str` constant the sibling Gateway listener-name
8080 // emitter reaches for — the paired
8081 // [`gateway_listener_name_routes_through_lifted_default_http_listener_name`]
8082 // pin fires the same byte-string on the sibling
8083 // `listener.insert(GATEWAY_API_KEY_NAME, …)` call, and this
8084 // pin closes the sectionName half so the substrate's canonical
8085 // per-listener identity pair (`Gateway.spec.listeners[].name`
8086 // + `HTTPRoute.spec.parentRefs[].sectionName`) moves as a
8087 // single unit through one lifted `&'static str`.
8088 //
8089 // Until this line landed the emitter omitted the selector
8090 // entirely, silently accepting the Gateway API v1 default
8091 // attach-to-every-listener fan-out. A future substrate-side
8092 // second listener under the same parent Gateway (the
8093 // cert-manager-issued per-`:entrada :host` HTTPS listener the
8094 // sibling [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] docstring
8095 // forecasts) would have silently doubled every route's per-
8096 // request dispatch surface — every external `:entrada`
8097 // request the route was authored to accept on the HTTP
8098 // listener would have accepted a matching request on the
8099 // paired HTTPS listener too, with the second-listener leak
8100 // surfacing only in per-request access logs (never in
8101 // `kubectl describe httproute` — the implicit fan-out reads
8102 // as intended per the Gateway API v1 spec). Pinning the
8103 // selector by construction closes that drift footgun
8104 // structurally: a substrate-side rebrand of the canonical
8105 // listener-name identifier reaches both the listener-name
8106 // emitter and the sectionName selector at construction time.
8107 //
8108 // Peer with the sibling
8109 // [`gateway_listener_name_routes_through_lifted_default_http_listener_name`]
8110 // pin on the same lifted const — the two per-listener
8111 // substrate-canonical byte-string axes (`Gateway.spec.
8112 // listeners[].name` vs `HTTPRoute.spec.parentRefs[].sectionName`)
8113 // now bind by construction to the same lifted `&'static str`,
8114 // so a rebrand on either axis reaches its consumer through
8115 // one canonical caixa-core declaration.
8116 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8117 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
8118 let parent = route
8119 .get(KUBE_KEY_SPEC)
8120 .and_then(|s| s.get(GATEWAY_API_KEY_PARENT_REFS))
8121 .and_then(|p| p.as_sequence())
8122 .and_then(|s| s.first())
8123 .expect("first parentRef present");
8124 assert_eq!(
8125 parent
8126 .get(GATEWAY_API_KEY_SECTION_NAME)
8127 .and_then(|n| n.as_str()),
8128 Some(GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME),
8129 "the HTTPRoute per-parentRef listener-selector scalar must \
8130 render the lifted GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME \
8131 constant verbatim — the Gateway listener-name emitter and \
8132 this sectionName selector must move as a unit through one \
8133 canonical caixa-core `&'static str`, else a future \
8134 listener-name rebrand silently splits the per-listener \
8135 identity pair and the emitted route reverts to the Gateway \
8136 API v1 attach-to-every-listener default fan-out"
8137 );
8138 }
8139
8140 #[test]
8141 fn gateway_listener_port_routes_through_lifted_default_http_listener_port() {
8142 // The per-Aplicacao `Gateway`'s sole per-listener HTTP-listener-
8143 // port axis (the `listener.insert(KUBE_KEY_PORT, …)` call site
8144 // in [`gateway_routes`]) must read from the lifted
8145 // [`caixa_core::GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] `u16`
8146 // constant — not from an open-coded `80` literal that could
8147 // drift if the substrate's canonical external-Gateway HTTP
8148 // listener port ever moved (`:80 → :443` on the HTTPS-by-
8149 // default trajectory, a per-cluster override the operator
8150 // pins). A future rebrand of the constant must reach this
8151 // consumer by construction. Peer with the sibling
8152 // [`cnp_l4_fallback_port_routes_through_lifted_default_servico_port`]
8153 // pin on the [`DEFAULT_SERVICO_PORT`] fallback in the
8154 // `cilium_network_policies` per-`(:de, :para)` L4 port
8155 // resolver — the two axes name distinct scalars (external
8156 // Gateway listener port vs in-cluster Servico port), both now
8157 // routed through their own lifted `u16` const, so a substrate-
8158 // side port migration on either axis lands at exactly one
8159 // consumer per axis without coupling the two rebrand cycles.
8160 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8161 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
8162 let listener = gateway
8163 .get(KUBE_KEY_SPEC)
8164 .and_then(|s| s.get(GATEWAY_API_KEY_LISTENERS))
8165 .and_then(|l| l.as_sequence())
8166 .and_then(|s| s.first())
8167 .expect("first listener present");
8168 assert_eq!(
8169 listener.get(KUBE_KEY_PORT).and_then(|p| p.as_u64()),
8170 Some(u64::from(GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT)),
8171 "the Gateway per-listener HTTP-listener-port scalar must render \
8172 the lifted GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT constant \
8173 verbatim — drift here means the constant lift no longer reaches \
8174 this consumer"
8175 );
8176 }
8177
8178 #[test]
8179 fn httproute_catch_all_path_routes_through_lifted_default_http_route_path() {
8180 // The per-Aplicacao `HTTPRoute`'s empty-`:entrada :paths`
8181 // catch-all resolver (the `let paths: Vec<&str> = if
8182 // entrada.paths.is_empty() { vec![…] } else { … }` branch in
8183 // [`gateway_routes`]) must read from the lifted
8184 // [`caixa_core::GATEWAY_API_DEFAULT_HTTP_ROUTE_PATH`]
8185 // `&'static str` constant — not from an open-coded `"/"`
8186 // literal that could drift if the substrate's canonical
8187 // catch-all URL-path shape ever moved (`"/"` → the Gateway API
8188 // v2 `Exact ""` idiom on a per-controller variant that treats
8189 // `"/"` as a literal prefix rather than the catch-all, an
8190 // operator-pinned override the future `:entrada :default-path`
8191 // slot promotes). A future rebrand of the constant must reach
8192 // this consumer by construction so an author who declared an
8193 // external `:entrada` but no per-path rule surface still gets
8194 // a route whose sole `HTTPPathMatch` matches every incoming
8195 // request under the paired
8196 // [`GATEWAY_API_PATH_MATCH_TYPE_PATH_PREFIX`] discriminator.
8197 // Peer with the sibling
8198 // [`gateway_listener_name_routes_through_lifted_default_http_listener_name`]
8199 // and
8200 // [`gateway_listener_port_routes_through_lifted_default_http_listener_port`]
8201 // pins on the [`GATEWAY_API_DEFAULT_HTTP_LISTENER_NAME`] /
8202 // [`GATEWAY_API_DEFAULT_HTTP_LISTENER_PORT`] consumers at the
8203 // same emitter — all three per-Gateway-API-CRD substrate-
8204 // canonical scalar-value axes now routed through their own
8205 // lifted const, so a substrate-side rebrand on any one axis
8206 // lands at exactly one consumer per axis without coupling the
8207 // rebrand cycles.
8208 let mut caixa = aplicacao_caixa();
8209 caixa.entrada.as_mut().unwrap().paths = Vec::new();
8210 let docs = gateway_routes(&caixa).unwrap();
8211 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
8212 let match_path_value = route
8213 .get(KUBE_KEY_SPEC)
8214 .and_then(|s| s.get(KUBE_KEY_RULES))
8215 .and_then(|r| r.as_sequence())
8216 .and_then(|s| s.first())
8217 .and_then(|r| r.get(GATEWAY_API_KEY_MATCHES))
8218 .and_then(|m| m.as_sequence())
8219 .and_then(|s| s.first())
8220 .and_then(|m| m.get(GATEWAY_API_KEY_PATH))
8221 .and_then(|p| p.get(GATEWAY_API_KEY_VALUE))
8222 .and_then(|v| v.as_str())
8223 .expect("HTTPRoute rules[0].matches[0].path.value present");
8224 assert_eq!(
8225 match_path_value, GATEWAY_API_DEFAULT_HTTP_ROUTE_PATH,
8226 "the HTTPRoute empty-`:entrada :paths` catch-all URL-path scalar \
8227 must render the lifted GATEWAY_API_DEFAULT_HTTP_ROUTE_PATH \
8228 constant verbatim — drift here means the constant lift no longer \
8229 reaches this consumer and every external `:entrada` HTTP flow \
8230 authored against a Servico with no per-path rule surface would \
8231 drop at the first hop with no diagnostic naming the catch-all-path \
8232 drift root cause"
8233 );
8234 }
8235
8236 #[test]
8237 fn httproute_path_list_routes_through_lifted_entrada_resolved_paths() {
8238 // Cross-crate pin: the per-Aplicacao HTTPRoute rules[] path list
8239 // must render exactly [`caixa_core::Entrada::resolved_paths`]'s
8240 // typed dispatch on the substrate primitive — one rule per
8241 // resolved path, in the resolver's authored order. Pins that a
8242 // future renderer-side detour that re-inlined the `paths.is_empty()`
8243 // cascade (or reordered / deduped / dropped author-declared
8244 // paths) surfaces at caixa-mesh build time rather than at
8245 // cluster-apply time as a silently-dropped-route HTTP flow.
8246 //
8247 // Exercises BOTH arms of the resolver's accept-set at one
8248 // emitter call site: the empty-`:entrada :paths` catch-all
8249 // arm (fixture cleared to `Vec::new()`; resolver returns the
8250 // lifted `[GATEWAY_API_DEFAULT_HTTP_ROUTE_PATH]` singleton)
8251 // and the author-declared non-empty arm (fixture's baseline
8252 // two-path `["/api/cart", "/api/products"]` list; resolver
8253 // returns each entry verbatim in order). Peer discipline with
8254 // the sibling
8255 // [`httproute_catch_all_path_routes_through_lifted_default_http_route_path`]
8256 // pin on the empty-arm arm-scalar axis — that pin nails the
8257 // per-rule fallback scalar; this pin nails the per-rule
8258 // dispatch shape the typed method drives.
8259 for paths in [
8260 vec![],
8261 vec!["/api/cart".to_string(), "/api/products".to_string()],
8262 vec!["/only".to_string()],
8263 ] {
8264 let mut caixa = aplicacao_caixa();
8265 let expected: Vec<String> = caixa
8266 .entrada
8267 .as_mut()
8268 .map(|e| {
8269 e.paths.clone_from(&paths);
8270 e.resolved_paths().iter().map(|&s| s.to_string()).collect()
8271 })
8272 .expect("aplicacao_caixa carries a typed `:entrada` block");
8273 let docs = gateway_routes(&caixa).unwrap();
8274 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE)
8275 .expect("HTTPRoute present under every :entrada permutation");
8276 let rules = route
8277 .get(KUBE_KEY_SPEC)
8278 .and_then(|s| s.get(KUBE_KEY_RULES))
8279 .and_then(|r| r.as_sequence())
8280 .expect("HTTPRoute.spec.rules[] present");
8281 let emitted: Vec<String> = rules
8282 .iter()
8283 .map(|r| {
8284 r.get(GATEWAY_API_KEY_MATCHES)
8285 .and_then(|m| m.as_sequence())
8286 .and_then(|s| s.first())
8287 .and_then(|m| m.get(GATEWAY_API_KEY_PATH))
8288 .and_then(|p| p.get(GATEWAY_API_KEY_VALUE))
8289 .and_then(|v| v.as_str())
8290 .expect("each HTTPRoute rule carries a matches[0].path.value scalar")
8291 .to_string()
8292 })
8293 .collect();
8294 assert_eq!(
8295 emitted, expected,
8296 "HTTPRoute per-rule path list must render \
8297 `Entrada::resolved_paths()` verbatim (in author-\
8298 declared order for the non-empty arm, as the lifted \
8299 catch-all singleton for the empty arm) — drift here \
8300 means the emitter no longer routes through the \
8301 substrate-primitive typed dispatch and a future \
8302 resolver axis (:default-path override, per-cluster \
8303 overlay) would silently disagree between caixa-core \
8304 and caixa-mesh on which paths a given `:entrada` \
8305 block resolves to. Input paths: {paths:?}"
8306 );
8307 }
8308 }
8309
8310 #[test]
8311 fn gateway_listener_hostname_routes_through_lifted_entrada_hostname() {
8312 // Cross-crate pin: the per-Aplicacao `Gateway`'s sole per-
8313 // listener singular `hostname:` filter must render exactly
8314 // [`caixa_core::Entrada::hostname`]'s typed dispatch on the
8315 // substrate primitive — not from an open-coded `entrada.host.
8316 // clone()` field access that could silently disagree with the
8317 // peer per-HTTPRoute plural `spec.hostnames[]` filter list on
8318 // future extensions of the `:entrada` slot to a multi-hostname
8319 // author surface. A drift here would surface at cluster-apply
8320 // time as an `Accepted:False/NoMatchingParent` reject on the
8321 // HTTPRoute (the parent Gateway's listener hostname doesn't
8322 // intersect the route's hostname filter list) — far from any
8323 // single-site commit and never surfacing in the emitted YAML.
8324 // Peer with the sibling
8325 // [`httproute_hostnames_routes_through_lifted_entrada_hostnames`]
8326 // pin on the plural-axis half of the DNS-hostname resolver
8327 // pair — the two pin tests together nail the two-consumer
8328 // coherence discipline the pair-invariant `hostnames() ==
8329 // vec![hostname()]` (pinned in
8330 // [`caixa_core::aplicacao::tests::hostnames_returns_singleton_of_hostname_accessor`])
8331 // encodes. Peer discipline with the sibling
8332 // [`httproute_path_list_routes_through_lifted_entrada_resolved_paths`]
8333 // pin on the sibling per-`:entrada` path-list resolver axis.
8334 for host in ["checkout.quero.cloud", "shop.pleme.dev", "app.example.io"] {
8335 let mut caixa = aplicacao_caixa();
8336 let expected = caixa
8337 .entrada
8338 .as_mut()
8339 .map(|e| {
8340 e.host = host.into();
8341 e.hostname().to_string()
8342 })
8343 .expect("aplicacao_caixa carries a typed `:entrada` block");
8344 let docs = gateway_routes(&caixa).unwrap();
8345 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY)
8346 .expect("Gateway present under every :entrada permutation");
8347 let listener = gateway
8348 .get(KUBE_KEY_SPEC)
8349 .and_then(|s| s.get(GATEWAY_API_KEY_LISTENERS))
8350 .and_then(|l| l.as_sequence())
8351 .and_then(|s| s.first())
8352 .expect("first listener present");
8353 let emitted = listener
8354 .get(GATEWAY_API_KEY_HOSTNAME)
8355 .and_then(|h| h.as_str())
8356 .expect("Gateway listener carries a hostname scalar");
8357 assert_eq!(
8358 emitted, expected,
8359 "Gateway per-listener singular `hostname:` scalar must \
8360 render `Entrada::hostname()` verbatim — drift here \
8361 means the emitter no longer routes through the \
8362 substrate-primitive typed dispatch and a future \
8363 hostname-resolution axis (per-cluster :alt-hosts \
8364 overlay, SNI fan-out) would silently disagree with \
8365 the plural sibling. Input host: {host:?}"
8366 );
8367 }
8368 }
8369
8370 #[test]
8371 fn httproute_hostnames_routes_through_lifted_entrada_hostnames() {
8372 // Cross-crate pin: the per-Aplicacao HTTPRoute's plural
8373 // `spec.hostnames[]` filter list must render exactly
8374 // [`caixa_core::Entrada::hostnames`]'s typed dispatch on the
8375 // substrate primitive — one entry per resolved hostname, in
8376 // the resolver's authored order. Pins that a future renderer-
8377 // side detour that re-inlined the `vec![entrada.host.
8378 // clone()]` construction (or reordered / deduped / dropped
8379 // resolver-declared hostnames) surfaces at caixa-mesh build
8380 // time rather than at cluster-apply time as an
8381 // `Accepted:False/NoMatchingParent` reject.
8382 //
8383 // Peer with the sibling
8384 // [`gateway_listener_hostname_routes_through_lifted_entrada_hostname`]
8385 // pin on the singular-axis half — the two pin tests together
8386 // nail the two-consumer coherence discipline the pair-invariant
8387 // `hostnames() == vec![hostname()]` (pinned in
8388 // [`caixa_core::aplicacao::tests::hostnames_returns_singleton_of_hostname_accessor`])
8389 // encodes.
8390 for host in ["checkout.quero.cloud", "shop.pleme.dev", "app.example.io"] {
8391 let mut caixa = aplicacao_caixa();
8392 let expected: Vec<String> = caixa
8393 .entrada
8394 .as_mut()
8395 .map(|e| {
8396 e.host = host.into();
8397 e.hostnames().into_iter().map(String::from).collect()
8398 })
8399 .expect("aplicacao_caixa carries a typed `:entrada` block");
8400 let docs = gateway_routes(&caixa).unwrap();
8401 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE)
8402 .expect("HTTPRoute present under every :entrada permutation");
8403 let hostnames = route
8404 .get(KUBE_KEY_SPEC)
8405 .and_then(|s| s.get(GATEWAY_API_KEY_HOSTNAMES))
8406 .and_then(|h| h.as_sequence())
8407 .expect("HTTPRoute.spec.hostnames[] present");
8408 let emitted: Vec<String> = hostnames
8409 .iter()
8410 .map(|v| {
8411 v.as_str()
8412 .expect("each HTTPRoute.spec.hostnames[] entry is a scalar string")
8413 .to_string()
8414 })
8415 .collect();
8416 assert_eq!(
8417 emitted, expected,
8418 "HTTPRoute per-route plural `spec.hostnames[]` list \
8419 must render `Entrada::hostnames()` verbatim — drift \
8420 here means the emitter no longer routes through the \
8421 substrate-primitive typed dispatch and a future \
8422 hostname-resolution axis (per-cluster :alt-hosts \
8423 overlay, SNI fan-out) would silently disagree \
8424 between caixa-core and caixa-mesh on which hostname \
8425 set a given `:entrada` block resolves to. Input \
8426 host: {host:?}"
8427 );
8428 }
8429 }
8430
8431 #[test]
8432 fn gateway_listener_hostname_and_httproute_hostnames_pair_invariant_at_emit_site() {
8433 // The pair-invariant cross-crate pin: the singular Gateway
8434 // listener `hostname:` filter and the plural HTTPRoute
8435 // `spec.hostnames[]` filter list at the same [`gateway_routes`]
8436 // emit site must project as the substrate-canonical pair
8437 // `hostnames == vec![hostname]` — the invariant
8438 // [`caixa_core::Entrada`] pins at the typed-primitive level
8439 // (see
8440 // [`caixa_core::aplicacao::tests::hostnames_returns_singleton_of_hostname_accessor`])
8441 // must reach every per-Aplicacao emit site by construction.
8442 // Pins that any future renderer-side detour that broke the
8443 // singular-plural coherence (an accidental prefix substitution
8444 // on one axis, a trailing-`.` FQDN normalization on the peer
8445 // that didn't land on the peer axis, a wildcard-prefix SNI
8446 // fan-out overlay that authored only one axis) surfaces at
8447 // caixa-mesh build time rather than at cluster-apply time as
8448 // an `Accepted:False/NoMatchingParent` reject far from any
8449 // single-site commit. Peer discipline with the two singular /
8450 // plural pin tests immediately above.
8451 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8452 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
8453 let listener_hostname = gateway
8454 .get(KUBE_KEY_SPEC)
8455 .and_then(|s| s.get(GATEWAY_API_KEY_LISTENERS))
8456 .and_then(|l| l.as_sequence())
8457 .and_then(|s| s.first())
8458 .and_then(|l| l.get(GATEWAY_API_KEY_HOSTNAME))
8459 .and_then(|h| h.as_str())
8460 .expect("Gateway listener carries a hostname scalar")
8461 .to_string();
8462 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
8463 let route_hostnames: Vec<String> = route
8464 .get(KUBE_KEY_SPEC)
8465 .and_then(|s| s.get(GATEWAY_API_KEY_HOSTNAMES))
8466 .and_then(|h| h.as_sequence())
8467 .expect("HTTPRoute.spec.hostnames[] present")
8468 .iter()
8469 .map(|v| {
8470 v.as_str()
8471 .expect("each HTTPRoute.spec.hostnames[] entry is a scalar string")
8472 .to_string()
8473 })
8474 .collect();
8475 assert_eq!(
8476 route_hostnames,
8477 vec![listener_hostname.clone()],
8478 "The Gateway listener singular `hostname:` filter and the \
8479 HTTPRoute plural `spec.hostnames[]` filter list must \
8480 project as the pair `hostnames == vec![hostname]` at the \
8481 gateway_routes emit site — Gateway API v1.x conformance \
8482 requires the HTTPRoute's hostname filter to intersect \
8483 the parent listener's hostname; drift breaks that at \
8484 cluster-apply time. Emitted listener_hostname: {:?}, \
8485 route_hostnames: {:?}",
8486 listener_hostname,
8487 route_hostnames,
8488 );
8489 }
8490
8491 #[test]
8492 fn httproute_name_composer_destination_arg_routes_through_lifted_entrada_destination() {
8493 // Cross-crate pin: the per-Aplicacao HTTPRoute's `metadata.name`
8494 // discriminator arg must render exactly
8495 // [`caixa_core::Entrada::destination`]'s typed dispatch on the
8496 // substrate primitive — not from an open-coded `entrada.para`
8497 // field access that could silently disagree with the peer per-
8498 // rule `backendRefs[0].name` axis on future extensions of the
8499 // `:entrada` slot to a multi-destination author surface. Drift
8500 // here would break the operator-side
8501 // `kubectl get httproute -n tatara-system <aplicacao>-<destination>`
8502 // grep-by-name lookup encoding — a route whose `metadata.name`
8503 // names one destination but whose `backendRefs[]` reach a
8504 // sibling Servico would silently drop every external
8505 // `:entrada` flow at the gateway. Peer with the sibling
8506 // [`httproute_backend_ref_name_routes_through_lifted_entrada_destination`]
8507 // pin on the per-rule backend-name half of the two-consumer
8508 // coherence axis.
8509 for para in ["cart", "catalog", "payment"] {
8510 let mut caixa = aplicacao_caixa();
8511 // Hoist the parent-Caixa's `:nome` off the typed
8512 // [`caixa_core::Caixa::nome`] accessor into a local before
8513 // the `&mut caixa.entrada` mutation below so both projections
8514 // (the peer `caixa.entrada.as_mut()` borrow inside the block
8515 // and the aplicacao-name arg of the substrate-canonical
8516 // [`caixa_core::gateway_api_http_route_name`] composer) reach
8517 // through disjoint borrows — the accessor's `&self` shape
8518 // can't coexist with the same-scope `&mut caixa.entrada`
8519 // borrow directly, but a hoisted `String` clone of its
8520 // return keeps the emit-side pin routed through the typed
8521 // dispatch on the substrate primitive.
8522 let nome = caixa.nome().to_string();
8523 let (expected_composed_name, expected_destination) = {
8524 let entrada = caixa
8525 .entrada
8526 .as_mut()
8527 .expect("aplicacao_caixa carries a typed `:entrada` block");
8528 entrada.para = para.into();
8529 (
8530 gateway_api_http_route_name(&nome, entrada.destination()),
8531 entrada.destination().to_string(),
8532 )
8533 };
8534 let docs = gateway_routes(&caixa).unwrap();
8535 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE)
8536 .expect("HTTPRoute present under every :entrada :para permutation");
8537 let emitted = kube_metadata_str_field(route, KUBE_KEY_NAME)
8538 .expect("HTTPRoute metadata.name scalar present");
8539 assert_eq!(
8540 emitted, expected_composed_name,
8541 "HTTPRoute `metadata.name` must equal \
8542 `gateway_api_http_route_name(caixa.nome, \
8543 entrada.destination())` verbatim — drift means the \
8544 composer no longer routes through the substrate-\
8545 primitive typed dispatch. Input :entrada :para: \
8546 {para:?}, expected destination: {expected_destination:?}"
8547 );
8548 }
8549 }
8550
8551 #[test]
8552 fn httproute_backend_ref_name_routes_through_lifted_entrada_destination() {
8553 // Cross-crate pin: the per-Aplicacao HTTPRoute's per-rule
8554 // `backendRefs[0].name` axis must render exactly
8555 // [`caixa_core::Entrada::destination`]'s typed dispatch on the
8556 // substrate primitive — not from an open-coded
8557 // `entrada.para.clone()` field access. Drift here would break
8558 // Gateway API v1.x conformance: the `backendRefs[].name` must
8559 // name a K8s Service in the same namespace as the parent
8560 // Gateway; a `backendRef` that silently references a peer
8561 // Servico's Service (because the emitter re-inlined the field
8562 // access) drops every external `:entrada` flow with the
8563 // destination-drift root cause invisible in the emitted YAML.
8564 // Peer with the sibling
8565 // [`httproute_name_composer_destination_arg_routes_through_lifted_entrada_destination`]
8566 // pin on the `metadata.name` discriminator half of the
8567 // two-consumer coherence axis — the two pin tests together
8568 // nail the two-consumer coherence discipline the pair-invariant
8569 // `metadata.name == "<caixa.nome>-<destination>"` /
8570 // `backendRefs[0].name == destination` encodes.
8571 for para in ["cart", "catalog", "payment"] {
8572 let mut caixa = aplicacao_caixa();
8573 let expected = {
8574 let entrada = caixa
8575 .entrada
8576 .as_mut()
8577 .expect("aplicacao_caixa carries a typed `:entrada` block");
8578 entrada.para = para.into();
8579 entrada.destination().to_string()
8580 };
8581 let docs = gateway_routes(&caixa).unwrap();
8582 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE)
8583 .expect("HTTPRoute present under every :entrada :para permutation");
8584 let backend = route
8585 .get(KUBE_KEY_SPEC)
8586 .and_then(|s| s.get(KUBE_KEY_RULES))
8587 .and_then(|r| r.as_sequence())
8588 .and_then(|s| s.first())
8589 .and_then(|r| r.get(GATEWAY_API_KEY_BACKEND_REFS))
8590 .and_then(|b| b.as_sequence())
8591 .and_then(|s| s.first())
8592 .expect("first HTTPRoute rule's first backendRef present");
8593 let emitted = backend
8594 .get(GATEWAY_API_KEY_NAME)
8595 .and_then(|n| n.as_str())
8596 .expect("backendRef name scalar present");
8597 assert_eq!(
8598 emitted, expected,
8599 "HTTPRoute per-rule `backendRefs[0].name` must render \
8600 `Entrada::destination()` verbatim — drift here means \
8601 the emitter no longer routes through the substrate-\
8602 primitive typed dispatch and the per-rule backend \
8603 would silently disagree with the `metadata.name` \
8604 discriminator on which destination Servico the \
8605 ingress fronts. Input :entrada :para: {para:?}"
8606 );
8607 }
8608 }
8609
8610 #[test]
8611 fn httproute_name_and_backend_ref_name_destination_pair_invariant_at_emit_site() {
8612 // The pair-invariant cross-crate pin: the HTTPRoute's
8613 // `metadata.name` discriminator and the per-rule
8614 // `backendRefs[0].name` axis at the same [`gateway_routes`]
8615 // emit site must project as the substrate-canonical pair
8616 // `metadata.name == gateway_api_http_route_name(caixa.nome,
8617 // backendRefs[0].name)` — the invariant the lifted
8618 // [`caixa_core::Entrada::destination`] typed accessor pins at
8619 // the substrate-primitive level. Pins that any future
8620 // renderer-side detour that broke the two-consumer coherence
8621 // (an accidental namespace-prefix rewrite on one axis, a
8622 // per-cluster suffix stamp on the peer, a weighted-canary
8623 // overlay that authored only one axis) surfaces at caixa-mesh
8624 // build time rather than at cluster-apply time — an HTTPRoute
8625 // whose `metadata.name` names one Servico but whose
8626 // `backendRefs[]` reach a peer silently drops external
8627 // `:entrada` flows and the destination-drift root cause is
8628 // invisible in the emitted YAML. Peer discipline with the two
8629 // singular / plural pin tests immediately above and the
8630 // sibling `gateway_listener_hostname_and_httproute_hostnames_
8631 // pair_invariant_at_emit_site` pin on the DNS-hostname axis.
8632 let caixa = aplicacao_caixa();
8633 let docs = gateway_routes(&caixa).unwrap();
8634 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
8635 let route_name = kube_metadata_str_field(route, KUBE_KEY_NAME)
8636 .expect("HTTPRoute metadata.name scalar present")
8637 .to_string();
8638 let backend_name = route
8639 .get(KUBE_KEY_SPEC)
8640 .and_then(|s| s.get(KUBE_KEY_RULES))
8641 .and_then(|r| r.as_sequence())
8642 .and_then(|s| s.first())
8643 .and_then(|r| r.get(GATEWAY_API_KEY_BACKEND_REFS))
8644 .and_then(|b| b.as_sequence())
8645 .and_then(|s| s.first())
8646 .and_then(|b| b.get(GATEWAY_API_KEY_NAME))
8647 .and_then(|n| n.as_str())
8648 .expect("first HTTPRoute rule's first backendRef.name scalar present")
8649 .to_string();
8650 assert_eq!(
8651 route_name,
8652 gateway_api_http_route_name(caixa.nome(), &backend_name),
8653 "The HTTPRoute `metadata.name` discriminator and the per-\
8654 rule `backendRefs[0].name` axis must project as the pair \
8655 `metadata.name == gateway_api_http_route_name(caixa.nome, \
8656 backendRefs[0].name)` at the gateway_routes emit site — \
8657 Gateway API v1.x conformance requires the operator-side \
8658 `kubectl get httproute -n <namespace> <aplicacao>-<destination>` \
8659 grep-by-name lookup and the per-rule backend service reach \
8660 to name the same destination Servico; drift breaks that \
8661 lookup encoding at cluster-apply time. Emitted route_name: \
8662 {route_name:?}, backend_name: {backend_name:?}"
8663 );
8664 }
8665
8666 #[test]
8667 fn httproute_backend_ref_port_routes_through_lifted_port_for_destination_resolver() {
8668 // Cross-crate drift-detection pin: the per-Aplicacao HTTPRoute's
8669 // per-rule `backendRefs[0].port` axis in [`gateway_routes`] now
8670 // routes through the lifted
8671 // [`caixa_core::AplicacaoSpec::port_for_destination`] typed
8672 // dispatch (peer with the sibling
8673 // `cnp_l4_port_routes_through_lifted_port_for_destination_resolver`
8674 // pin on the per-`(:de, :para)` CNP L4-port axis — the two per-
8675 // Aplicacao renderers that reach for a per-destination Servico
8676 // TCP port scalar both key off exactly one typed dispatch on the
8677 // substrate primitive now). Pin the resolver-shaped rule at the
8678 // emit-side path across a non-default `:entrada :port` scalar
8679 // (`8443`, exercising a hypothetical HTTPS-by-default trajectory
8680 // for the destination Servico's listener port) and a `:para`
8681 // permutation, so a future renderer-side detour that re-inlined
8682 // the `entrada.port` field access at this call site would surface
8683 // as a caixa-mesh build-time test failure — the two consumer
8684 // paths on the per-Aplicacao L4 port axis (the resolver's own
8685 // typed dispatch at caixa-core, this renderer's emit-side reach
8686 // for it) must agree at every point on the port scalar the
8687 // emitted HTTPRoute renders, per the MESH-COMPOSITION §V "one
8688 // identity layer, one data plane" invariant that the CNP L4
8689 // whitelist port and the HTTPRoute `backendRefs[].port` name the
8690 // same destination Servico's listener.
8691 for (para, port) in [
8692 ("cart", 8080u16),
8693 ("catalog", 8443u16),
8694 ("payment", 9090u16),
8695 ] {
8696 let mut caixa = aplicacao_caixa();
8697 let expected_port = {
8698 let entrada = caixa
8699 .entrada
8700 .as_mut()
8701 .expect("aplicacao_caixa carries a typed `:entrada` block");
8702 entrada.para = para.into();
8703 entrada.port = port;
8704 let spec =
8705 typed_view(&caixa).expect("aplicacao_caixa fixture must be a valid Aplicacao");
8706 let entrada_ref = spec.entrada().expect("entrada present in spec");
8707 spec.port_for_destination(entrada_ref.destination())
8708 };
8709 let docs = gateway_routes(&caixa).unwrap();
8710 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE)
8711 .expect("HTTPRoute present under every :entrada :para permutation");
8712 let emitted_port = route
8713 .get(KUBE_KEY_SPEC)
8714 .and_then(|s| s.get(KUBE_KEY_RULES))
8715 .and_then(|r| r.as_sequence())
8716 .and_then(|s| s.first())
8717 .and_then(|r| r.get(GATEWAY_API_KEY_BACKEND_REFS))
8718 .and_then(|b| b.as_sequence())
8719 .and_then(|s| s.first())
8720 .and_then(|b| b.get(KUBE_KEY_PORT))
8721 .and_then(|p| p.as_u64())
8722 .expect("first HTTPRoute rule's first backendRef.port scalar present");
8723 assert_eq!(
8724 emitted_port,
8725 u64::from(expected_port),
8726 "HTTPRoute per-rule `backendRefs[0].port` must render \
8727 `AplicacaoSpec::port_for_destination(entrada.destination())` \
8728 verbatim — drift here means the emitter no longer routes \
8729 through the substrate-primitive typed dispatch and the \
8730 per-rule backend port would silently disagree with the \
8731 peer CNP L4 whitelist port on which destination Servico's \
8732 listener the ingress fronts. Input :entrada :para: \
8733 {para:?}, :entrada :port: {port}"
8734 );
8735 }
8736 }
8737
8738 #[test]
8739 fn httproute_backend_ref_port_and_cnp_l4_port_share_port_for_destination_resolver_at_emit_site()
8740 {
8741 // The two-renderer pair-invariant cross-crate pin: the per-
8742 // Aplicacao HTTPRoute's per-rule `backendRefs[0].port` axis (this
8743 // module's [`gateway_routes`] emit-side path) and the peer
8744 // per-`(:de, :para)` `CiliumNetworkPolicy` `toPorts[0].ports[0]
8745 // .port` axis (this module's [`cilium_network_policies`] emit-
8746 // side path) at the same fixture must both project to
8747 // [`caixa_core::AplicacaoSpec::port_for_destination`]'s scalar
8748 // for the entrada apex destination — the substrate-canonical
8749 // invariant the lifted resolver pins at the substrate-primitive
8750 // level and both consumers now reach for by construction. A
8751 // future renderer-side detour that broke the two-consumer
8752 // coherence (an accidental per-cluster port stamp on one
8753 // renderer, a hardcoded `DEFAULT_SERVICO_PORT` re-inline on the
8754 // peer, an mTLS-by-default overlay that authored only one axis)
8755 // surfaces at caixa-mesh build time rather than at cluster-apply
8756 // time — a two-renderer split silently blackholes every external
8757 // `:entrada` flow at the eBPF data plane far from the source
8758 // `caixa.lisp` with no field naming the port-drift root cause in
8759 // the emitted YAML. Peer discipline with the sibling
8760 // `httproute_name_and_backend_ref_name_destination_pair_invariant_at_emit_site`
8761 // pin on the per-`:entrada` destination-Servico scalar axis and
8762 // the `gateway_listener_hostname_and_httproute_hostnames_pair_invariant_at_emit_site`
8763 // pin on the DNS-hostname axis — same two-consumer coherence
8764 // discipline the M3 mesh contract lifts encode.
8765 let caixa = aplicacao_caixa();
8766 let spec = typed_view(&caixa).expect("aplicacao_caixa fixture must be a valid Aplicacao");
8767 let apex_destination = spec
8768 .entrada()
8769 .expect("aplicacao_caixa carries a typed `:entrada` block")
8770 .destination()
8771 .to_string();
8772 let expected_port = spec.port_for_destination(&apex_destination);
8773
8774 let gateway_docs = gateway_routes(&caixa).unwrap();
8775 let route =
8776 find_by_kind(&gateway_docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
8777 let httproute_port = route
8778 .get(KUBE_KEY_SPEC)
8779 .and_then(|s| s.get(KUBE_KEY_RULES))
8780 .and_then(|r| r.as_sequence())
8781 .and_then(|s| s.first())
8782 .and_then(|r| r.get(GATEWAY_API_KEY_BACKEND_REFS))
8783 .and_then(|b| b.as_sequence())
8784 .and_then(|s| s.first())
8785 .and_then(|b| b.get(KUBE_KEY_PORT))
8786 .and_then(|p| p.as_u64())
8787 .expect("HTTPRoute backendRef.port scalar present");
8788 assert_eq!(
8789 httproute_port,
8790 u64::from(expected_port),
8791 "HTTPRoute `backendRefs[0].port` must equal \
8792 `spec.port_for_destination(entrada.destination())` at the \
8793 gateway_routes emit site — this is one half of the two-\
8794 renderer pair-invariant on the per-destination Servico L4 \
8795 port axis."
8796 );
8797
8798 // The peer CNP `toPorts[0].ports[0].port` axis must render the
8799 // same resolver's answer for each destination. The per-`(:de, :para)`
8800 // CNP naming scheme is `<caixa.nome>-<de>-to-<para>`; extract the
8801 // `<para>` and confirm every emitted CNP's L4 port scalar equals
8802 // `spec.port_for_destination(<destination>)`.
8803 let policies = cilium_network_policies(&caixa).unwrap();
8804 for policy in &policies {
8805 let cnp_name = kube_metadata_str_field(policy, KUBE_KEY_NAME)
8806 .expect("every CNP has a metadata.name")
8807 .to_string();
8808 let Some(destination) = cnp_name.split("-to-").nth(1) else {
8809 continue;
8810 };
8811 let cnp_port = policy
8812 .get(KUBE_KEY_SPEC)
8813 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
8814 .and_then(|i| i.as_sequence())
8815 .and_then(|s| s.first())
8816 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
8817 .and_then(|t| t.as_sequence())
8818 .and_then(|s| s.first())
8819 .and_then(|tp| tp.get(CILIUM_KEY_PORTS))
8820 .and_then(|p| p.as_sequence())
8821 .and_then(|s| s.first())
8822 .and_then(|p| p.get(KUBE_KEY_PORT))
8823 .and_then(|v| v.as_str())
8824 .expect("CNP toPorts[0].ports[0].port present");
8825 assert_eq!(
8826 cnp_port,
8827 spec.port_for_destination(destination).to_string(),
8828 "CNP {cnp_name:?} toPorts[0].ports[0].port must equal \
8829 `spec.port_for_destination({destination:?})` — drift here \
8830 means the CNP emit-side path re-inlined the port \
8831 resolution rule and would silently disagree with the \
8832 HTTPRoute peer on the shared destination Servico's \
8833 listener port."
8834 );
8835 }
8836 }
8837
8838 #[test]
8839 fn httproute_routes_to_entrada_para() {
8840 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8841 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).unwrap();
8842 let backend = route
8843 .get(KUBE_KEY_SPEC)
8844 .and_then(|s| s.get(KUBE_KEY_RULES))
8845 .and_then(|r| r.as_sequence())
8846 .and_then(|s| s.first())
8847 .and_then(|r| r.get(GATEWAY_API_KEY_BACKEND_REFS))
8848 .and_then(|b| b.as_sequence())
8849 .and_then(|s| s.first())
8850 .unwrap();
8851 assert_eq!(
8852 backend.get(GATEWAY_API_KEY_NAME).and_then(|n| n.as_str()),
8853 Some("cart")
8854 );
8855 assert_eq!(
8856 backend.get(KUBE_KEY_PORT).and_then(|p| p.as_u64()),
8857 Some(8080)
8858 );
8859 }
8860
8861 #[test]
8862 fn gateway_skips_when_no_entrada() {
8863 let mut c = aplicacao_caixa();
8864 c.entrada = None;
8865 let docs = gateway_routes(&c).unwrap();
8866 assert!(docs.is_empty());
8867 }
8868
8869 #[test]
8870 fn cilium_policy_carries_canonical_kube_skeleton() {
8871 // Pin that the kube_resource_skeleton lift preserves the exact
8872 // apiVersion + kind + metadata.{name, namespace, labels} shape
8873 // every CNP carried before the lift. Drift here is invisible at
8874 // runtime (Cilium tolerates extra/missing keys quietly), so
8875 // structural pinning is the only signal a refactor would
8876 // accidentally drop apiVersion or shift the metadata block.
8877 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
8878 for p in &policies {
8879 assert_eq!(
8880 kube_root_str_field(p, KUBE_KEY_API_VERSION),
8881 Some("cilium.io/v2")
8882 );
8883 assert_eq!(
8884 kube_root_str_field(p, KUBE_KEY_KIND),
8885 Some(CILIUM_KIND_NETWORK_POLICY)
8886 );
8887 let metadata = p
8888 .get(KUBE_KEY_METADATA)
8889 .and_then(|m| m.as_mapping())
8890 .expect("metadata mapping");
8891 // metadata carries name + namespace + labels (3 keys) — no
8892 // accidental extras leak past the skeleton lift.
8893 assert_eq!(metadata.len(), 3);
8894 assert!(
8895 metadata
8896 .get(KUBE_KEY_NAME)
8897 .and_then(|v| v.as_str())
8898 .is_some()
8899 );
8900 assert_eq!(
8901 metadata.get(KUBE_KEY_NAMESPACE).and_then(|v| v.as_str()),
8902 Some(DEFAULT_NAMESPACE)
8903 );
8904 assert!(metadata.get(KUBE_KEY_LABELS).is_some());
8905 }
8906 }
8907
8908 #[test]
8909 fn gateway_carries_canonical_kube_skeleton_without_labels() {
8910 // Pin that Gateway emits apiVersion + kind + metadata.{name,
8911 // namespace} — and *not* metadata.labels (the empty-labels-skip
8912 // semantic of kube_resource_skeleton; Gateway does not need
8913 // per-Aplicacao label grouping at the K8s-resource axis today).
8914 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8915 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
8916 assert_eq!(
8917 kube_root_str_field(gateway, KUBE_KEY_API_VERSION),
8918 Some("gateway.networking.k8s.io/v1")
8919 );
8920 let metadata = gateway
8921 .get(KUBE_KEY_METADATA)
8922 .and_then(|m| m.as_mapping())
8923 .expect("metadata mapping");
8924 // Exactly 2 metadata keys (name + namespace) — labels absent.
8925 assert_eq!(metadata.len(), 2);
8926 assert_eq!(
8927 metadata.get(KUBE_KEY_NAME).and_then(|v| v.as_str()),
8928 Some("checkout")
8929 );
8930 assert_eq!(
8931 metadata.get(KUBE_KEY_NAMESPACE).and_then(|v| v.as_str()),
8932 Some(DEFAULT_NAMESPACE)
8933 );
8934 assert!(
8935 metadata.get(KUBE_KEY_LABELS).is_none(),
8936 "Gateway must not carry metadata.labels (empty-labels-skip \
8937 contract from kube_resource_skeleton)"
8938 );
8939 }
8940
8941 #[test]
8942 fn httproute_carries_canonical_kube_skeleton_without_labels() {
8943 // Same shape pin for HTTPRoute (the second lift site in
8944 // gateway_routes). Same empty-labels-skip semantic — the
8945 // route's parent-Gateway-association lives at spec.parentRefs,
8946 // not at metadata.labels.
8947 //
8948 // The `metadata.name` byte-shape probe now consults the lifted
8949 // [`gateway_api_http_route_name`] composer rather than a
8950 // verbatim `Some("checkout-cart")` literal so a future
8951 // per-Aplicacao Gateway API per-CR name-encoding rebrand
8952 // (which lands at the composer's caixa-core definition site)
8953 // reaches this probe by construction — pinning the composer's
8954 // output prevents the emitter and this probe from silently
8955 // splitting on any rebrand. Peer to the sibling
8956 // `cilium_fans_same_de_para_edges_into_one_policy` probe
8957 // pinning the CNP `metadata.name` via
8958 // [`cilium_network_policy_name`] on the same shared
8959 // "aplicacao-prefixed sub-identity" discipline.
8960 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
8961 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
8962 assert_eq!(
8963 kube_root_str_field(route, KUBE_KEY_API_VERSION),
8964 Some("gateway.networking.k8s.io/v1")
8965 );
8966 let metadata = route
8967 .get(KUBE_KEY_METADATA)
8968 .and_then(|m| m.as_mapping())
8969 .expect("metadata mapping");
8970 assert_eq!(metadata.len(), 2);
8971 assert_eq!(
8972 metadata.get(KUBE_KEY_NAME).and_then(|v| v.as_str()),
8973 Some(gateway_api_http_route_name("checkout", "cart").as_str())
8974 );
8975 assert!(metadata.get(KUBE_KEY_LABELS).is_none());
8976 }
8977
8978 #[test]
8979 fn gateway_routes_gateway_uses_lifted_gateway_api_api_version() {
8980 // Fail-before-pass-after pin parsing the rendered `Gateway`
8981 // document and asserting its top-level `apiVersion` axis
8982 // equals the lifted [`caixa_core::GATEWAY_API_API_VERSION`]
8983 // constant by value (not just by the canonical-literal
8984 // string, which the sibling
8985 // `gateway_carries_canonical_kube_skeleton_without_labels`
8986 // pin already enforces). The two pins form the bridge-arm
8987 // pair: this pin trips on drift between the renderer-side
8988 // threading and the lifted const, the sibling pin trips on
8989 // drift between the lifted const and the canonical literal,
8990 // and the
8991 // [`gateway_api_api_version_re_export_points_at_caixa_core_canonical`]
8992 // pin trips on drift between this crate's re-export and the
8993 // caixa-core canonical declaration — together they close the
8994 // three-arm drift footgun the inline-literal-pair-across-two-
8995 // skeleton-calls shape carried by construction. Peer to
8996 // `caixa_flux::tests::cluster_bundle_gitrepository_uses_lifted_flux_api_version`
8997 // / `cluster_bundle_helmrelease_uses_lifted_flux_api_version`
8998 // / `cluster_bundle_kustomization_uses_lifted_flux_api_version`
8999 // on the sibling Flux v2 controller-triplet lift trajectory.
9000 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9001 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
9002 assert_eq!(
9003 kube_root_str_field(gateway, KUBE_KEY_API_VERSION),
9004 Some(caixa_core::GATEWAY_API_API_VERSION),
9005 "Gateway's top-level apiVersion must equal the lifted \
9006 caixa_core::GATEWAY_API_API_VERSION by value — drift here \
9007 is the canonical footgun this lift closes"
9008 );
9009 }
9010
9011 #[test]
9012 fn gateway_routes_gateway_uses_lifted_gateway_api_kind_gateway() {
9013 // Fail-before-pass-after pin parsing the rendered `Gateway`
9014 // document and asserting its top-level `kind` axis equals the
9015 // lifted [`caixa_core::GATEWAY_API_KIND_GATEWAY`] constant by
9016 // value (not just by the canonical-literal string, which the
9017 // sibling `gateway_carries_canonical_kube_skeleton_without_labels`
9018 // pin already enforces). The two pins form the bridge-arm pair:
9019 // this pin trips on drift between the renderer-side threading
9020 // and the lifted const, the sibling pin trips on drift between
9021 // the lifted const and the canonical literal, and the
9022 // [`gateway_api_kind_gateway_re_export_points_at_caixa_core_canonical`]
9023 // pin trips on drift between this crate's re-export and the
9024 // caixa-core canonical declaration — together the three arms
9025 // (canonical-string pin, lifted-uses pin, re-export-identity
9026 // pin) close the three-arm drift footgun the inline-literal-
9027 // across-the-production-skeleton-call-plus-test-fixture shape
9028 // carried by construction. Peer to
9029 // [`gateway_routes_gateway_uses_lifted_gateway_api_api_version`]
9030 // on the sibling Gateway-API-CRD-apiVersion-axis lift trajectory
9031 // — begins the per-Gateway-API-CRD kind+apiVersion lifted-uses
9032 // pin pair the renderer's exit threading through the lifted
9033 // [`GATEWAY_API_API_VERSION`] + [`GATEWAY_API_KIND_GATEWAY`]
9034 // pair demands. Peer to
9035 // [`cilium_network_policies_use_lifted_cilium_kind_network_policy`]
9036 // on the sibling Cilium-CRD-kind-axis lift trajectory.
9037 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9038 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
9039 assert_eq!(
9040 kube_root_str_field(gateway, KUBE_KEY_KIND),
9041 Some(caixa_core::GATEWAY_API_KIND_GATEWAY),
9042 "Gateway's top-level kind must equal the lifted \
9043 caixa_core::GATEWAY_API_KIND_GATEWAY by value — drift here \
9044 is the canonical footgun this lift closes"
9045 );
9046 }
9047
9048 #[test]
9049 fn gateway_routes_httproute_uses_lifted_gateway_api_kind_http_route() {
9050 // Fail-before-pass-after pin parsing the rendered `HTTPRoute`
9051 // document and asserting its top-level `kind` axis equals the
9052 // lifted [`caixa_core::GATEWAY_API_KIND_HTTP_ROUTE`] constant
9053 // by value (not just by the canonical-literal string, which the
9054 // sibling `httproute_carries_canonical_kube_skeleton_without_labels`
9055 // pin already enforces). The two pins form the bridge-arm pair:
9056 // this pin trips on drift between the renderer-side threading
9057 // and the lifted const, the sibling pin trips on drift between
9058 // the lifted const and the canonical literal, and the
9059 // [`gateway_api_kind_http_route_re_export_points_at_caixa_core_canonical`]
9060 // pin trips on drift between this crate's re-export and the
9061 // caixa-core canonical declaration — together the three arms
9062 // (canonical-string pin, lifted-uses pin, re-export-identity
9063 // pin) close the three-arm drift footgun the inline-literal-
9064 // across-the-production-skeleton-call-plus-test-fixture shape
9065 // carried by construction. Peer to
9066 // [`gateway_routes_httproute_uses_lifted_gateway_api_api_version`]
9067 // on the sibling Gateway-API-CRD-apiVersion-axis lift trajectory
9068 // — completes the per-Gateway-API-CRD kind+apiVersion lifted-
9069 // uses pin pair the renderer's exit threading through the
9070 // lifted [`GATEWAY_API_API_VERSION`] + [`GATEWAY_API_KIND_HTTP_ROUTE`]
9071 // pair demands. Peer to
9072 // [`gateway_routes_gateway_uses_lifted_gateway_api_kind_gateway`]
9073 // on the sibling parent-Gateway-`kind`-axis lift trajectory —
9074 // completes the per-Gateway-API-CRD `kind`-axis lifted-uses
9075 // pin pair across the `(Gateway, HTTPRoute)` pair the renderer
9076 // emits together.
9077 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9078 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
9079 assert_eq!(
9080 kube_root_str_field(route, KUBE_KEY_KIND),
9081 Some(caixa_core::GATEWAY_API_KIND_HTTP_ROUTE),
9082 "HTTPRoute's top-level kind must equal the lifted \
9083 caixa_core::GATEWAY_API_KIND_HTTP_ROUTE by value — drift here \
9084 is the canonical footgun this lift closes"
9085 );
9086 }
9087
9088 #[test]
9089 fn gateway_routes_httproute_uses_lifted_gateway_api_api_version() {
9090 // Sibling-axis pin to
9091 // [`gateway_routes_gateway_uses_lifted_gateway_api_api_version`]
9092 // on the HTTPRoute CRD-group/version axis (the second
9093 // `kube_resource_skeleton` call site at
9094 // caixa-mesh/src/lib.rs:496). The K8s SIG-Network Gateway API
9095 // contract bumps `Gateway`, `HTTPRoute`, `GatewayClass`, and
9096 // the rest of the per-conformance CRD set as a unit; a future
9097 // Gateway-API GA promotion on one axis without a coordinated
9098 // edit on the other would land the rendered `Gateway` /
9099 // `HTTPRoute` pair pointing at distinct CRD versions, with
9100 // the per-route attached-policy resolution pipeline never
9101 // binding at apply time. Peer to the sibling Gateway-axis
9102 // pin above — together they enforce the per-CRD-axis
9103 // movement-as-a-unit invariant at the renderer's exit.
9104 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9105 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
9106 assert_eq!(
9107 kube_root_str_field(route, KUBE_KEY_API_VERSION),
9108 Some(caixa_core::GATEWAY_API_API_VERSION),
9109 "HTTPRoute's top-level apiVersion must equal the lifted \
9110 caixa_core::GATEWAY_API_API_VERSION by value — drift here \
9111 is the canonical footgun this lift closes"
9112 );
9113 }
9114
9115 #[test]
9116 fn gateway_gateway_class_name_uses_lifted_default_gateway_class_name() {
9117 // Fail-before-pass-after pin parsing the rendered `Gateway`
9118 // document and asserting its `spec.gatewayClassName` axis equals
9119 // the lifted [`caixa_core::DEFAULT_GATEWAY_CLASS_NAME`] constant
9120 // by value — the third arm of the three-arm drift footgun close
9121 // pattern the prior lifts (`GATEWAY_API_KIND_GATEWAY`,
9122 // `GATEWAY_API_API_VERSION`) established on the peer
9123 // Gateway-API-CRD-discriminator axes. The three arms:
9124 // this pin trips on drift between the renderer-side threading
9125 // and the lifted const, the sibling
9126 // `default_gateway_class_name_pins_canonical_value` in caixa-core
9127 // trips on drift between the lifted const and the canonical
9128 // literal value, and the
9129 // [`default_gateway_class_name_re_export_points_at_caixa_core_canonical`]
9130 // pin trips on drift between this crate's re-export and the
9131 // caixa-core canonical declaration — together they close the
9132 // three-arm drift footgun the inline-literal-across-the-
9133 // production-spec-map-plus-implicit-test-fixture shape carried
9134 // by construction. Peer to
9135 // [`gateway_routes_gateway_uses_lifted_gateway_api_kind_gateway`]
9136 // on the sibling parent-Gateway-`kind`-axis lifted-uses pin —
9137 // extends the discipline from the CRD-discriminator half of the
9138 // per-Gateway typed contract onto the controller-choice half.
9139 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9140 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
9141 let class_name = gateway
9142 .get(KUBE_KEY_SPEC)
9143 .and_then(|s| s.get(GATEWAY_API_KEY_GATEWAY_CLASS_NAME))
9144 .and_then(|c| c.as_str())
9145 .expect("Gateway spec.gatewayClassName present");
9146 assert_eq!(
9147 class_name,
9148 caixa_core::DEFAULT_GATEWAY_CLASS_NAME,
9149 "Gateway's spec.gatewayClassName must equal the lifted \
9150 caixa_core::DEFAULT_GATEWAY_CLASS_NAME by value — drift here \
9151 is the canonical footgun this lift closes"
9152 );
9153 }
9154
9155 #[test]
9156 fn gateway_routes_gateway_uses_lifted_gateway_api_key_gateway_class_name() {
9157 // Fail-before-pass-after pin parsing the rendered `Gateway`
9158 // document via the raw canonical `"gatewayClassName"` KEY
9159 // literal (not the lifted const, to trip on drift between the
9160 // renderer-side emitter and the lifted const), then asserting
9161 // the emitted key IS byte-identical to
9162 // [`caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME`]. The three
9163 // arms: this pin trips on drift between the renderer-side
9164 // emitter and the lifted const, the sibling
9165 // `gateway_api_key_gateway_class_name_pins_canonical_value` in
9166 // caixa-core trips on drift between the lifted const and the
9167 // canonical literal, and the
9168 // [`gateway_api_key_gateway_class_name_re_export_points_at_caixa_core_canonical`]
9169 // pin trips on drift between this crate's re-export and the
9170 // caixa-core canonical declaration — together they close the
9171 // three-arm drift footgun the inline-literal-across-the-
9172 // production-emit-plus-navigation shape carried by construction.
9173 // Sibling of the peer
9174 // `gateway_gateway_class_name_uses_lifted_default_gateway_class_name`
9175 // on the canonical-Gateway-API-`(key, value)`-pair-lifted-uses
9176 // pin surface this pin closes the KEY half of.
9177 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9178 let gateway = find_by_kind(&docs, GATEWAY_API_KIND_GATEWAY).expect("Gateway present");
9179 let spec = gateway
9180 .get(KUBE_KEY_SPEC)
9181 .and_then(|s| s.as_mapping())
9182 .expect("Gateway spec is a mapping");
9183 assert!(
9184 spec.contains_key(caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME),
9185 "Gateway spec must carry a key byte-identical to the lifted \
9186 caixa_core::GATEWAY_API_KEY_GATEWAY_CLASS_NAME — drift here \
9187 is the canonical footgun this lift closes"
9188 );
9189 }
9190
9191 #[test]
9192 fn gateway_routes_httproute_uses_lifted_gateway_api_key_hostnames() {
9193 // Fail-before-pass-after pin parsing the rendered `HTTPRoute`
9194 // document and asserting its `spec.hostnames[0]` axis is
9195 // navigable through the lifted
9196 // [`caixa_core::GATEWAY_API_KEY_HOSTNAMES`] constant by value
9197 // (and carries the Aplicacao's `:entrada :host` slot as its
9198 // single element, the same seed the sibling per-`Gateway`
9199 // per-listener `hostname` axis threads through
9200 // [`gateway_listener_carries_aplicacao_host`]). Peer to
9201 // [`gateway_routes_gateway_uses_lifted_gateway_api_kind_gateway`]
9202 // /
9203 // [`gateway_routes_httproute_uses_lifted_gateway_api_kind_http_route`]
9204 // on the sibling Gateway-API-CRD-kind-axis lift trajectory and
9205 // to
9206 // [`gateway_routes_gateway_uses_lifted_gateway_api_api_version`]
9207 // /
9208 // [`gateway_routes_httproute_uses_lifted_gateway_api_api_version`]
9209 // on the sibling Gateway-API-CRD-apiVersion-axis lift
9210 // trajectory — closes the per-Gateway-API-CRD `HTTPRoute` per-
9211 // route body-axis lifted-uses pin pair across the singular /
9212 // plural DNS-host discriminator surface (`hostname` at the
9213 // parent-Gateway per-listener discriminator + `hostnames` at
9214 // the child HTTPRoute per-route filter list), so both halves of
9215 // the DNS-host-discriminator convention across the
9216 // `(Gateway, HTTPRoute)` pair the M3 Aplicacao mesh renderer's
9217 // external `:entrada` ingress contract emits together now carry
9218 // one lifted-uses pin apiece. The
9219 // [`gateway_api_key_hostnames_re_export_points_at_caixa_core_canonical`]
9220 // pin trips on drift between this crate's re-export and the
9221 // caixa-core canonical declaration — together the two arms
9222 // (lifted-uses pin here, re-export-identity pin above) close
9223 // the drift footgun the inline-literal-at-the-production-
9224 // skeleton-call shape carried by construction.
9225 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9226 let route = find_by_kind(&docs, GATEWAY_API_KIND_HTTP_ROUTE).expect("HTTPRoute present");
9227 let hostnames = route
9228 .get(KUBE_KEY_SPEC)
9229 .and_then(|s| s.get(caixa_core::GATEWAY_API_KEY_HOSTNAMES))
9230 .and_then(|h| h.as_sequence())
9231 .expect("HTTPRoute spec.hostnames must be navigable through the lifted constant");
9232 assert_eq!(
9233 hostnames.len(),
9234 1,
9235 "HTTPRoute spec.hostnames must carry exactly one entry — the \
9236 typed `:entrada :host` seed"
9237 );
9238 assert_eq!(
9239 hostnames[0].as_str(),
9240 Some("checkout.quero.cloud"),
9241 "HTTPRoute spec.hostnames[0] must carry the Aplicacao's \
9242 `:entrada :host` slot — the same seed the sibling per-`Gateway` \
9243 per-listener `hostname` axis threads through"
9244 );
9245 }
9246
9247 #[test]
9248 fn gateway_routes_httproute_uses_lifted_gateway_api_key_matches() {
9249 // Fail-before-pass-after pin parsing the rendered `HTTPRoute`
9250 // document and asserting every per-rule route-match container-
9251 // axis is navigable through the lifted
9252 // [`caixa_core::GATEWAY_API_KEY_MATCHES`] constant by value
9253 // (and carries a non-empty per-rule request-selection predicate
9254 // sequence, one entry per typed `:entrada :paths` path). Peer
9255 // to
9256 // [`gateway_routes_httproute_uses_lifted_gateway_api_key_hostnames`]
9257 // on the sibling Gateway-API-HTTPRoute-body-axis lift
9258 // trajectory — completes the per-rule top-level-axis lifted-
9259 // uses pin set (`matches`, `backendRefs`, `timeouts`,
9260 // `retry`) the `httproute_rule_keys_pin_overlay_position` pin
9261 // binds against, so every one of the four per-rule top-level
9262 // axes now carries a lifted-uses pin apiece alongside its
9263 // sibling re-export-identity pin. The
9264 // [`gateway_api_key_matches_re_export_points_at_caixa_core_canonical`]
9265 // pin trips on drift between this crate's re-export and the
9266 // caixa-core canonical declaration — together the two arms
9267 // (lifted-uses pin here, re-export-identity pin above) close
9268 // the drift footgun the inline-literal-at-the-production-
9269 // per-rule-emitter shape carried by construction.
9270 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9271 let rules = httproute_rules(&docs);
9272 assert!(
9273 !rules.is_empty(),
9274 "HTTPRoute must carry at least one rule the per-rule route-match \
9275 axis nests under"
9276 );
9277 for rule in &rules {
9278 let matches = rule
9279 .get(caixa_core::GATEWAY_API_KEY_MATCHES)
9280 .and_then(|m| m.as_sequence())
9281 .expect(
9282 "HTTPRoute per-rule spec.rules[].matches must be navigable \
9283 through the lifted constant",
9284 );
9285 assert!(
9286 !matches.is_empty(),
9287 "per-rule matches sequence must carry at least one entry — the \
9288 typed `:entrada :paths` seed",
9289 );
9290 }
9291 }
9292
9293 #[test]
9294 fn gateway_routes_httproute_uses_lifted_gateway_api_key_path() {
9295 // Fail-before-pass-after pin parsing the rendered `HTTPRoute`
9296 // document and asserting every per-`HTTPRouteMatch` path-matcher
9297 // container-axis is navigable through the lifted
9298 // [`caixa_core::GATEWAY_API_KEY_PATH`] constant by value (and
9299 // carries a non-empty per-match `{type, value}` path-selection
9300 // predicate mapping, one entry per typed `:entrada :paths`
9301 // path). Peer to
9302 // [`gateway_routes_httproute_uses_lifted_gateway_api_key_matches`]
9303 // on the sibling per-rule route-match container-axis lift
9304 // trajectory — nests the per-Gateway-API-HTTPRoute-per-rule-
9305 // body-axis lifted-uses pin set (`matches`, `backendRefs`,
9306 // `timeouts`, `retry`) one level deeper onto the per-
9307 // `HTTPRouteMatch` body-axis surface, so the container-axis
9308 // key beneath the sibling `matches[]` axis now carries a
9309 // lifted-uses pin alongside its parent-container-axis
9310 // lifted-uses pin. The
9311 // [`gateway_api_key_path_re_export_points_at_caixa_core_canonical`]
9312 // pin trips on drift between this crate's re-export and the
9313 // caixa-core canonical declaration — together the two arms
9314 // (lifted-uses pin here, re-export-identity pin above) close
9315 // the drift footgun the inline-literal-at-the-production-
9316 // per-match-emitter shape carried by construction.
9317 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9318 let rules = httproute_rules(&docs);
9319 assert!(
9320 !rules.is_empty(),
9321 "HTTPRoute must carry at least one rule the per-match path-matcher \
9322 axis nests under"
9323 );
9324 for rule in &rules {
9325 let matches = rule
9326 .get(caixa_core::GATEWAY_API_KEY_MATCHES)
9327 .and_then(|m| m.as_sequence())
9328 .expect("HTTPRoute per-rule spec.rules[].matches sequence");
9329 assert!(
9330 !matches.is_empty(),
9331 "per-rule matches sequence must carry at least one entry — the \
9332 typed `:entrada :paths` seed the per-match path-matcher axis \
9333 nests under",
9334 );
9335 for m in matches {
9336 let path = m
9337 .get(caixa_core::GATEWAY_API_KEY_PATH)
9338 .and_then(|p| p.as_mapping())
9339 .expect(
9340 "HTTPRoute per-match spec.rules[].matches[].path must be \
9341 navigable through the lifted constant",
9342 );
9343 assert!(
9344 !path.is_empty(),
9345 "per-match path-matcher mapping must carry the typed \
9346 `{{type, value}}` path-selection predicate — the Gateway \
9347 API v1 HTTPRouteMatch canonical path shape",
9348 );
9349 }
9350 }
9351 }
9352
9353 #[test]
9354 fn cilium_policy_metadata_block_iterates_alphabetically() {
9355 // The kube_resource_skeleton's render-determinism contract:
9356 // metadata: block keys appear in alphabetical order (labels,
9357 // name, namespace) regardless of source-code declaration order.
9358 // Pinning this at the renderer's exit so a future
9359 // pretty-printer / round-trip / diff-friendly format depends
9360 // on the determinism property (mirrors the M2 overlay helper's
9361 // alphabetical-iteration determinism property — THEORY.md
9362 // §V.2.7).
9363 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
9364 for p in &policies {
9365 let metadata = p
9366 .get(KUBE_KEY_METADATA)
9367 .and_then(|m| m.as_mapping())
9368 .expect("metadata mapping");
9369 let keys: Vec<&str> = metadata.iter().filter_map(|(k, _)| k.as_str()).collect();
9370 assert_eq!(
9371 keys,
9372 vec![KUBE_KEY_LABELS, KUBE_KEY_NAME, KUBE_KEY_NAMESPACE],
9373 "metadata block must iterate alphabetically (the kube \
9374 skeleton's render-determinism contract)"
9375 );
9376 }
9377 }
9378
9379 #[test]
9380 fn render_all_includes_every_artifact_kind() {
9381 let docs = render_all(&aplicacao_caixa()).unwrap();
9382 // 3 programs + 2 cilium policies + 1 gateway + 1 httproute = 7
9383 assert_eq!(docs.len(), 7);
9384 let kinds: Vec<_> = docs
9385 .iter()
9386 .filter_map(|d| {
9387 d.get(KUBE_KEY_KIND)
9388 .and_then(|k| k.as_str())
9389 .map(|s| s.to_string())
9390 })
9391 .collect();
9392 // programs entries don't carry `kind:`; cilium + gateway docs do.
9393 assert!(kinds.contains(&CILIUM_KIND_NETWORK_POLICY.to_string()));
9394 assert!(kinds.contains(&GATEWAY_API_KIND_GATEWAY.to_string()));
9395 assert!(kinds.contains(&GATEWAY_API_KIND_HTTP_ROUTE.to_string()));
9396 }
9397
9398 // ── HTTPRoute :politicas :timeout overlay ────────────────────────────
9399
9400 fn httproute_rules(docs: &[serde_yaml::Value]) -> Vec<serde_yaml::Value> {
9401 find_by_kind(docs, GATEWAY_API_KIND_HTTP_ROUTE)
9402 .and_then(|d| d.get(KUBE_KEY_SPEC))
9403 .and_then(|s| s.get(KUBE_KEY_RULES))
9404 .and_then(|r| r.as_sequence())
9405 .cloned()
9406 .expect("HTTPRoute spec.rules sequence")
9407 }
9408
9409 #[test]
9410 fn httproute_carries_politicas_timeout_on_every_rule() {
9411 // The fixture sets `:politicas :timeout 30s`. Every emitted
9412 // HTTPRoute rule must carry `timeouts: { request: "30s" }`,
9413 // wiring the typed `:politicas :timeout` slot through to the
9414 // canonical Gateway API per-rule request-deadline shape:
9415 // https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts
9416 // Before this overlay landed the typed slot was inert past
9417 // validate() — the rendered HTTPRoute carried no timeouts:
9418 // block, so MESH-COMPOSITION §V "no infinite blocking" was
9419 // a build-time gate without runtime teeth. This test is the
9420 // pinned proof that the slot now reaches the cluster artifact.
9421 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9422 let rules = httproute_rules(&docs);
9423 assert!(!rules.is_empty(), "HTTPRoute must carry at least one rule");
9424 for rule in &rules {
9425 let timeouts = rule
9426 .get(GATEWAY_API_KEY_TIMEOUTS)
9427 .and_then(|t| t.as_mapping())
9428 .expect("rule must carry timeouts mapping when :politicas :timeout is set");
9429 assert_eq!(
9430 timeouts
9431 .get(GATEWAY_API_KEY_REQUEST)
9432 .and_then(|v| v.as_str()),
9433 Some("30s")
9434 );
9435 }
9436 }
9437
9438 #[test]
9439 fn httproute_omits_timeouts_when_politicas_timeout_unset() {
9440 // Empty-axis-skip semantic: an Aplicacao that doesn't declare
9441 // `:politicas :timeout` (politicas = MeshPolicy::default()
9442 // here) emits an HTTPRoute with no timeouts: key on any rule
9443 // — the K8s "no per-rule deadline declared" semantic, which
9444 // matches the prior pre-overlay behavior bit-for-bit. Pinning
9445 // so a future refactor of the overlay can't accidentally
9446 // emit `timeouts: {}` (the empty-mapping form, which some
9447 // Gateway API conformance suites reject as malformed).
9448 let mut c = aplicacao_caixa();
9449 c.politicas = Some(MeshPolicy::default());
9450 let docs = gateway_routes(&c).unwrap();
9451 let rules = httproute_rules(&docs);
9452 assert!(!rules.is_empty());
9453 for rule in &rules {
9454 assert!(
9455 rule.get(GATEWAY_API_KEY_TIMEOUTS).is_none(),
9456 "rule must omit `timeouts:` when :politicas :timeout is None"
9457 );
9458 }
9459 }
9460
9461 #[test]
9462 fn httproute_timeout_renders_every_rule_independently() {
9463 // Multiple `:entrada :paths` entries → multiple HTTPRoute
9464 // rules. The overlay must apply to every rule, not just the
9465 // first one — pin so a future refactor that hoists the
9466 // overlay out of the loop without re-cloning into each rule
9467 // can't accidentally drop the policy from the tail rules.
9468 let mut c = aplicacao_caixa();
9469 if let Some(e) = c.entrada.as_mut() {
9470 e.paths = vec![
9471 "/api/cart".into(),
9472 "/api/products".into(),
9473 "/healthz".into(),
9474 ];
9475 }
9476 let docs = gateway_routes(&c).unwrap();
9477 let rules = httproute_rules(&docs);
9478 assert_eq!(rules.len(), 3);
9479 for rule in &rules {
9480 let req = rule
9481 .get(GATEWAY_API_KEY_TIMEOUTS)
9482 .and_then(|t| t.get(GATEWAY_API_KEY_REQUEST))
9483 .and_then(|v| v.as_str())
9484 .expect("each of the 3 rules carries timeouts.request");
9485 assert_eq!(req, "30s");
9486 }
9487 }
9488
9489 #[test]
9490 fn httproute_timeout_uses_canonical_kube_duration_format() {
9491 // The duration formatter is shared with every other
9492 // typed-duration slot (caixa_core::supervisor::duration_codec
9493 // ::render). Pin that a 90-second timeout renders as `"90s"`
9494 // (the canonical form K8s tooling parses), not `"1m30s"`
9495 // (the ad-hoc multi-unit form some Go time.Duration formatters
9496 // produce, which the Gateway API parser rejects).
9497 let mut c = aplicacao_caixa();
9498 c.politicas = Some(MeshPolicy {
9499 timeout: Some(Duration::from_secs(90)),
9500 ..Default::default()
9501 });
9502 let docs = gateway_routes(&c).unwrap();
9503 let rules = httproute_rules(&docs);
9504 for rule in &rules {
9505 assert_eq!(
9506 rule.get(GATEWAY_API_KEY_TIMEOUTS)
9507 .and_then(|t| t.get(GATEWAY_API_KEY_REQUEST))
9508 .and_then(|v| v.as_str()),
9509 Some("90s")
9510 );
9511 }
9512 }
9513
9514 #[test]
9515 fn httproute_timeout_renders_minute_window_canonically() {
9516 // A 1-minute timeout must render as `"1m"` (canonical), not
9517 // `"60s"` (numerically equivalent but not the canonical form
9518 // duration_codec::render emits). Pinning the formatter's
9519 // round-trip contract through the renderer end-to-end so a
9520 // future change to the formatter that picks a non-canonical
9521 // unit surfaces here.
9522 let mut c = aplicacao_caixa();
9523 c.politicas = Some(MeshPolicy {
9524 timeout: Some(Duration::from_secs(60)),
9525 ..Default::default()
9526 });
9527 let docs = gateway_routes(&c).unwrap();
9528 let rules = httproute_rules(&docs);
9529 for rule in &rules {
9530 assert_eq!(
9531 rule.get(GATEWAY_API_KEY_TIMEOUTS)
9532 .and_then(|t| t.get(GATEWAY_API_KEY_REQUEST))
9533 .and_then(|v| v.as_str()),
9534 Some("1m")
9535 );
9536 }
9537 }
9538
9539 #[test]
9540 fn httproute_rule_keys_pin_overlay_position() {
9541 // Pin that timeouts: + retry: appear alongside matches: and
9542 // backendRefs: at the rule level, not nested inside either.
9543 // Gateway API v1.x defines both as top-level rule fields — a
9544 // misplaced `matches[].timeouts` or `matches[].retry` would
9545 // silently be ignored by the apiserver, which matches no
9546 // traffic visibly but disables the per-call deadline / retry
9547 // budget. The fixture sets both `:politicas :timeout` and
9548 // `:politicas :retries`, so every rule carries all 4 keys.
9549 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9550 let rules = httproute_rules(&docs);
9551 for rule in &rules {
9552 let m = rule.as_mapping().expect("rule mapping");
9553 // matches + backendRefs + timeouts + retry (4 top-level keys).
9554 assert_eq!(m.len(), 4);
9555 assert!(m.contains_key(GATEWAY_API_KEY_MATCHES));
9556 assert!(m.contains_key(GATEWAY_API_KEY_BACKEND_REFS));
9557 assert!(m.contains_key(GATEWAY_API_KEY_TIMEOUTS));
9558 assert!(m.contains_key(GATEWAY_API_KEY_RETRY));
9559 }
9560 }
9561
9562 // ── HTTPRoute :politicas :retries overlay ────────────────────────────
9563
9564 #[test]
9565 fn httproute_carries_politicas_retries_on_every_rule() {
9566 // The fixture sets `:politicas :retries 3`. Every emitted
9567 // HTTPRoute rule must carry `retry: { attempts: 3 }`, wiring
9568 // the typed `:politicas :retries` slot through to the
9569 // canonical Gateway API per-rule retry-policy shape:
9570 // https://gateway-api.sigs.k8s.io/api-types/httproute/#retry
9571 // Before this overlay landed the typed slot was inert past
9572 // validate() — `AplicacaoSpec::validate` refused zero via
9573 // PolicyRetriesZero, but a non-zero attempt count never
9574 // reached an emitted artifact. This test is the pinned proof
9575 // that the slot now reaches the cluster artifact (the
9576 // fail-before-pass-after pin: the assertion below fails on
9577 // any pre-overlay codebase, since the rule had no `retry:` key
9578 // at all).
9579 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9580 let rules = httproute_rules(&docs);
9581 assert!(!rules.is_empty(), "HTTPRoute must carry at least one rule");
9582 for rule in &rules {
9583 let retry = rule
9584 .get(GATEWAY_API_KEY_RETRY)
9585 .and_then(|r| r.as_mapping())
9586 .expect("rule must carry retry mapping when :politicas :retries is set");
9587 assert_eq!(
9588 retry.get(GATEWAY_API_KEY_ATTEMPTS).and_then(|v| v.as_u64()),
9589 Some(3),
9590 "retry.attempts must round-trip the typed :retries value"
9591 );
9592 }
9593 }
9594
9595 #[test]
9596 fn httproute_omits_retry_when_politicas_retries_unset() {
9597 // Empty-axis-skip semantic (mirrors the `:timeout` overlay's
9598 // omit-when-unset contract): an Aplicacao that doesn't declare
9599 // `:politicas :retries` (politicas = MeshPolicy::default()
9600 // here) emits an HTTPRoute with no `retry:` key on any rule
9601 // — the K8s "no per-rule retry policy declared" semantic,
9602 // which lets the cluster default policy take effect. Pinning
9603 // so a future refactor of the overlay can't accidentally emit
9604 // `retry: {}` (the empty-mapping form, which is structurally
9605 // distinct from "no retry policy" and may be rejected by the
9606 // Gateway API parser).
9607 let mut c = aplicacao_caixa();
9608 c.politicas = Some(MeshPolicy::default());
9609 let docs = gateway_routes(&c).unwrap();
9610 let rules = httproute_rules(&docs);
9611 assert!(!rules.is_empty());
9612 for rule in &rules {
9613 assert!(
9614 rule.get(GATEWAY_API_KEY_RETRY).is_none(),
9615 "rule must omit `retry:` when :politicas :retries is None"
9616 );
9617 }
9618 }
9619
9620 #[test]
9621 fn httproute_retry_renders_every_rule_independently() {
9622 // Multiple `:entrada :paths` entries → multiple HTTPRoute
9623 // rules. The retry overlay must apply to every rule, not just
9624 // the first one — pin so a future refactor that hoists the
9625 // overlay out of the loop without re-cloning into each rule
9626 // can't accidentally drop the policy from the tail rules.
9627 // Same hoist-out-of-loop guard the parallel `:timeout`
9628 // overlay test enshrines.
9629 let mut c = aplicacao_caixa();
9630 if let Some(e) = c.entrada.as_mut() {
9631 e.paths = vec![
9632 "/api/cart".into(),
9633 "/api/products".into(),
9634 "/healthz".into(),
9635 ];
9636 }
9637 let docs = gateway_routes(&c).unwrap();
9638 let rules = httproute_rules(&docs);
9639 assert_eq!(rules.len(), 3);
9640 for rule in &rules {
9641 let attempts = rule
9642 .get(GATEWAY_API_KEY_RETRY)
9643 .and_then(|r| r.get(GATEWAY_API_KEY_ATTEMPTS))
9644 .and_then(|v| v.as_u64())
9645 .expect("each of the 3 rules carries retry.attempts");
9646 assert_eq!(attempts, 3);
9647 }
9648 }
9649
9650 #[test]
9651 fn httproute_retry_round_trips_typed_attempt_count() {
9652 // The overlay must round-trip whatever value the typed
9653 // `:retries` slot carries — pin a non-fixture value (5) so a
9654 // future change to the formatter / overlay shape (e.g.
9655 // accidentally clamping attempts to a constant, mis-mapping
9656 // the typed `u32` to a string) surfaces here.
9657 let mut c = aplicacao_caixa();
9658 c.politicas = Some(MeshPolicy {
9659 retries: Some(5),
9660 ..Default::default()
9661 });
9662 let docs = gateway_routes(&c).unwrap();
9663 let rules = httproute_rules(&docs);
9664 for rule in &rules {
9665 assert_eq!(
9666 rule.get(GATEWAY_API_KEY_RETRY)
9667 .and_then(|r| r.get(GATEWAY_API_KEY_ATTEMPTS))
9668 .and_then(|v| v.as_u64()),
9669 Some(5),
9670 "retry.attempts must round-trip the typed :retries value verbatim"
9671 );
9672 }
9673 }
9674
9675 #[test]
9676 fn httproute_retry_attempts_serialized_as_yaml_number() {
9677 // Pin the YAML scalar shape: `attempts:` is an *integer* in
9678 // the Gateway API schema (HTTPRouteRetry.attempts: integer),
9679 // not a string. A renderer that accidentally emits
9680 // `attempts: "3"` would round-trip past serde_yaml but be
9681 // rejected by the apiserver-side OpenAPI schema validation
9682 // — pin the scalar kind here so a regression surfaces at
9683 // build time, not at apply time.
9684 let docs = gateway_routes(&aplicacao_caixa()).unwrap();
9685 let rules = httproute_rules(&docs);
9686 for rule in &rules {
9687 let attempts = rule
9688 .get(GATEWAY_API_KEY_RETRY)
9689 .and_then(|r| r.get(GATEWAY_API_KEY_ATTEMPTS))
9690 .expect("retry.attempts present");
9691 assert!(
9692 attempts.is_u64() || attempts.is_i64(),
9693 "retry.attempts must be a YAML integer (got: {attempts:?})"
9694 );
9695 }
9696 }
9697
9698 #[test]
9699 fn httproute_timeouts_and_retry_coexist_independently() {
9700 // The two `:politicas` axes (`:timeout` + `:retries`) emit
9701 // independently — one set, the other unset, must surface
9702 // exactly the expected single overlay. Pin both directions
9703 // (timeout-only and retries-only) so a future refactor can't
9704 // accidentally couple the two emission gates.
9705 let mut c = aplicacao_caixa();
9706 c.politicas = Some(MeshPolicy {
9707 timeout: Some(Duration::from_secs(15)),
9708 retries: None,
9709 ..Default::default()
9710 });
9711 let docs = gateway_routes(&c).unwrap();
9712 let rules = httproute_rules(&docs);
9713 for rule in &rules {
9714 assert_eq!(
9715 rule.get(GATEWAY_API_KEY_TIMEOUTS)
9716 .and_then(|t| t.get(GATEWAY_API_KEY_REQUEST))
9717 .and_then(|v| v.as_str()),
9718 Some("15s")
9719 );
9720 assert!(
9721 rule.get(GATEWAY_API_KEY_RETRY).is_none(),
9722 "retry: must be absent when only :timeout is set"
9723 );
9724 }
9725
9726 let mut c2 = aplicacao_caixa();
9727 c2.politicas = Some(MeshPolicy {
9728 timeout: None,
9729 retries: Some(2),
9730 ..Default::default()
9731 });
9732 let docs = gateway_routes(&c2).unwrap();
9733 let rules = httproute_rules(&docs);
9734 for rule in &rules {
9735 assert!(
9736 rule.get(GATEWAY_API_KEY_TIMEOUTS).is_none(),
9737 "timeouts: must be absent when only :retries is set"
9738 );
9739 assert_eq!(
9740 rule.get(GATEWAY_API_KEY_RETRY)
9741 .and_then(|r| r.get(GATEWAY_API_KEY_ATTEMPTS))
9742 .and_then(|v| v.as_u64()),
9743 Some(2)
9744 );
9745 }
9746 }
9747
9748 // ── CiliumNetworkPolicy :politicas :mtls-required overlay ────────────
9749
9750 fn cnp_ingress_rules(docs: &[serde_yaml::Value]) -> Vec<serde_yaml::Value> {
9751 docs.iter()
9752 .filter(|d| kube_kind_is(d, CILIUM_KIND_NETWORK_POLICY))
9753 .filter_map(|d| {
9754 d.get(KUBE_KEY_SPEC)
9755 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
9756 .and_then(|i| i.as_sequence())
9757 .and_then(|s| s.first())
9758 .cloned()
9759 })
9760 .collect()
9761 }
9762
9763 #[test]
9764 fn cnp_carries_politicas_mtls_required_on_every_rule() {
9765 // The fixture sets `:politicas :mtls-required t`. Every
9766 // emitted CiliumNetworkPolicy ingress rule must carry
9767 // `authentication: { mode: "required" }`, wiring the typed
9768 // `:politicas :mtls-required` slot through to the canonical
9769 // Cilium per-rule mutual-authentication shape:
9770 // https://docs.cilium.io/en/stable/network/servicemesh/mutual-authentication/
9771 // Before this overlay landed the typed slot was inert past
9772 // validate() — the rendered CNP carried no authentication:
9773 // block, so MESH-COMPOSITION §V "no plaintext intra-mesh"
9774 // was a build-time gate without runtime teeth. This test is
9775 // the pinned proof that the slot now reaches the cluster
9776 // artifact (the fail-before-pass-after pin: the assertion
9777 // below fails on any pre-overlay codebase, since the rule
9778 // had no `authentication:` key at all).
9779 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
9780 let rules = cnp_ingress_rules(&policies);
9781 assert!(
9782 !rules.is_empty(),
9783 "CNPs must carry at least one ingress rule"
9784 );
9785 for rule in &rules {
9786 let auth = rule
9787 .get(CILIUM_KEY_AUTHENTICATION)
9788 .and_then(|a| a.as_mapping())
9789 .expect("rule must carry authentication mapping when :mtls-required is set");
9790 assert_eq!(
9791 auth.get(CILIUM_KEY_MODE).and_then(|v| v.as_str()),
9792 Some(CILIUM_AUTH_MODE_REQUIRED)
9793 );
9794 }
9795 }
9796
9797 #[test]
9798 fn cnp_omits_authentication_when_mtls_required_unset() {
9799 // Empty-axis-skip semantic (mirrors the `:timeout`/`:retries`
9800 // overlays' omit-when-unset contract): an Aplicacao that
9801 // doesn't declare `:politicas :mtls-required` (politicas =
9802 // MeshPolicy::default() here) emits CNPs with no
9803 // `authentication:` key on any ingress rule — the Cilium
9804 // "no per-rule auth mode declared" semantic, which lets the
9805 // cluster default policy take effect (typically "disabled").
9806 // Pinning so a future refactor of the overlay can't
9807 // accidentally emit `authentication: {}` (the empty-mapping
9808 // form, which the Cilium agent rejects as malformed since
9809 // the `mode:` field is required when the block is present).
9810 let mut c = aplicacao_caixa();
9811 c.politicas = Some(MeshPolicy::default());
9812 let policies = cilium_network_policies(&c).unwrap();
9813 let rules = cnp_ingress_rules(&policies);
9814 assert!(!rules.is_empty());
9815 for rule in &rules {
9816 assert!(
9817 rule.get(CILIUM_KEY_AUTHENTICATION).is_none(),
9818 "rule must omit `authentication:` when :mtls-required is None"
9819 );
9820 }
9821 }
9822
9823 #[test]
9824 fn cnp_explicit_mtls_required_false_emits_disabled_mode() {
9825 // The author-facing `:mtls-required` slot is a tristate. The
9826 // `Some(false)` arm is *not* the same as `None` — the author
9827 // explicitly named the axis and asked for the mTLS handshake
9828 // to be skipped on this Aplicacao's edges (e.g. a debug or
9829 // legacy-bridge Aplicacao that needs to talk to non-mesh
9830 // peers). The renderer must surface that explicit opt-out as
9831 // `mode: "disabled"`, *not* fall back to omitting the block
9832 // (which would let the cluster default — typically also
9833 // "disabled" today, but environment-divergent — take effect).
9834 // Pinning so a future refactor that collapses the tristate
9835 // into a bool can't silently lose the authored intent.
9836 let mut c = aplicacao_caixa();
9837 c.politicas = Some(MeshPolicy {
9838 mtls_required: Some(false),
9839 ..Default::default()
9840 });
9841 let policies = cilium_network_policies(&c).unwrap();
9842 let rules = cnp_ingress_rules(&policies);
9843 assert!(!rules.is_empty());
9844 for rule in &rules {
9845 let auth = rule
9846 .get(CILIUM_KEY_AUTHENTICATION)
9847 .and_then(|a| a.as_mapping())
9848 .expect("rule must carry authentication mapping for explicit :mtls-required nil");
9849 assert_eq!(
9850 auth.get(CILIUM_KEY_MODE).and_then(|v| v.as_str()),
9851 Some(CILIUM_AUTH_MODE_DISABLED)
9852 );
9853 }
9854 }
9855
9856 #[test]
9857 fn cnp_authentication_renders_every_policy_independently() {
9858 // Multiple `:contratos` → multiple CiliumNetworkPolicies.
9859 // The auth overlay must apply to every policy's ingress
9860 // rule, not just the first one — pin so a future refactor
9861 // that hoists the overlay out of the loop without re-cloning
9862 // into each rule can't accidentally drop the policy from the
9863 // tail CNPs. Same hoist-out-of-loop guard the parallel
9864 // `:timeout`/`:retries` overlay tests enshrine for HTTPRoute.
9865 let mut c = aplicacao_caixa();
9866 // Three `:contratos` → three CNPs.
9867 c.contratos.push(WitContract {
9868 de: "payment".into(),
9869 para: "catalog".into(),
9870 wit: "wasi:http/proxy".into(),
9871 endpoint: Some("/inventory".into()),
9872 subject: None,
9873 slot: None,
9874 });
9875 let policies = cilium_network_policies(&c).unwrap();
9876 assert_eq!(policies.len(), 3);
9877 let rules = cnp_ingress_rules(&policies);
9878 assert_eq!(rules.len(), 3);
9879 for rule in &rules {
9880 assert_eq!(
9881 rule.get(CILIUM_KEY_AUTHENTICATION)
9882 .and_then(|a| a.get(CILIUM_KEY_MODE))
9883 .and_then(|v| v.as_str()),
9884 Some(CILIUM_AUTH_MODE_REQUIRED),
9885 "every CNP's ingress rule must carry the authentication overlay"
9886 );
9887 }
9888 }
9889
9890 #[test]
9891 fn cnp_authentication_position_is_rule_level_not_nested() {
9892 // Pin that `authentication:` appears at the ingress-rule
9893 // level (alongside `fromEndpoints` + `toPorts`), not nested
9894 // inside either. Cilium's per-rule mutual-auth schema places
9895 // the field at the IngressRule axis — a misplaced
9896 // `fromEndpoints[].authentication` or
9897 // `toPorts[].authentication` would silently be ignored by
9898 // the Cilium agent (matches no traffic visibly but disables
9899 // the per-edge mTLS contract). The fixture sets
9900 // `:mtls-required t`, so every rule carries fromEndpoints +
9901 // toPorts + authentication (3 top-level rule keys).
9902 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
9903 let rules = cnp_ingress_rules(&policies);
9904 for rule in &rules {
9905 let m = rule.as_mapping().expect("rule mapping");
9906 assert_eq!(m.len(), 3);
9907 assert!(m.contains_key(CILIUM_KEY_FROM_ENDPOINTS));
9908 assert!(m.contains_key(CILIUM_KEY_TO_PORTS));
9909 assert!(m.contains_key(CILIUM_KEY_AUTHENTICATION));
9910 // The auth block must not leak inside fromEndpoints[] or
9911 // toPorts[] — guards the Cilium-side schema contract that
9912 // mutual-auth is an ingress-rule-level concern.
9913 let from = m
9914 .get(CILIUM_KEY_FROM_ENDPOINTS)
9915 .and_then(|f| f.as_sequence())
9916 .expect("fromEndpoints sequence");
9917 for fe in from {
9918 assert!(
9919 fe.get(CILIUM_KEY_AUTHENTICATION).is_none(),
9920 "authentication must not nest inside fromEndpoints[]"
9921 );
9922 }
9923 let to = m
9924 .get(CILIUM_KEY_TO_PORTS)
9925 .and_then(|t| t.as_sequence())
9926 .expect("toPorts sequence");
9927 for tp in to {
9928 assert!(
9929 tp.get(CILIUM_KEY_AUTHENTICATION).is_none(),
9930 "authentication must not nest inside toPorts[]"
9931 );
9932 }
9933 }
9934 }
9935
9936 #[test]
9937 fn cnp_authentication_pubsub_contracts_carry_overlay_too() {
9938 // The auth overlay applies to every `:contratos` edge,
9939 // regardless of WIT shape. Cilium's mutual-auth happens at
9940 // L4 (per the SPIFFE-identity handshake) — same as the
9941 // identity-bound fromEndpoints selector — so a `nats:pub-sub`
9942 // contrato (which the existing `cilium_pubsub_contracts_skip_l7_rules`
9943 // test pins as L4-only) still carries the auth block. Pin
9944 // here so a future overlay refactor that mistakenly couples
9945 // the auth overlay to L7-shape (e.g. only adds it when
9946 // `target() == WitTarget::Http`) surfaces.
9947 let mut c = aplicacao_caixa();
9948 c.contratos.push(WitContract {
9949 de: "payment".into(),
9950 para: "cart".into(), // back-edge for testing only
9951 wit: "nats:pub-sub".into(),
9952 endpoint: None,
9953 subject: Some("checkout.events.charge.failed".into()),
9954 slot: None,
9955 });
9956 let policies = cilium_network_policies(&c).unwrap();
9957 let nats_policy = policies
9958 .iter()
9959 .find(|p| kube_metadata_str_field(p, KUBE_KEY_NAME) == Some("checkout-payment-to-cart"))
9960 .expect("pubsub CNP present");
9961 let rule = nats_policy
9962 .get(KUBE_KEY_SPEC)
9963 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
9964 .and_then(|i| i.as_sequence())
9965 .and_then(|s| s.first())
9966 .expect("ingress[0]");
9967 assert_eq!(
9968 rule.get(CILIUM_KEY_AUTHENTICATION)
9969 .and_then(|a| a.get(CILIUM_KEY_MODE))
9970 .and_then(|v| v.as_str()),
9971 Some(CILIUM_AUTH_MODE_REQUIRED)
9972 );
9973 }
9974
9975 #[test]
9976 fn cnp_l4_fallback_port_routes_through_lifted_default_servico_port() {
9977 // The L4-fallback in [`cilium_network_policies`] (the
9978 // `.unwrap_or(DEFAULT_SERVICO_PORT)` branch fired when the
9979 // typed `:entrada` block doesn't name the per-`:contratos`
9980 // destination Servico) must read from the lifted
9981 // [`caixa_core::DEFAULT_SERVICO_PORT`] constant — not from an
9982 // open-coded `8080` literal that could drift if the
9983 // substrate's canonical Servico port ever moved. The fixture's
9984 // `cart → payment` HTTP contrato exercises this arm: the
9985 // fixture's `:entrada` block names `:para "cart"`, so the
9986 // sibling `cart → catalog` and `cart → payment` contratos
9987 // don't match the entrada's `:para` axis (the entrada is the
9988 // ingress *to* cart, not *to* payment / catalog), and the
9989 // renderer falls back to DEFAULT_SERVICO_PORT on the per-CNP
9990 // L4 port. Pin the rendered L4 port at `DEFAULT_SERVICO_PORT`
9991 // verbatim so a future rebrand of the constant reaches this
9992 // consumer by construction, peer with the
9993 // `default_namespace_re_export_points_at_caixa_core_canonical`
9994 // pin on the namespace-axis lifted-constant.
9995 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
9996 let cart_to_payment = policies
9997 .iter()
9998 .find(|p| kube_metadata_str_field(p, KUBE_KEY_NAME) == Some("checkout-cart-to-payment"))
9999 .expect("cart→payment CNP present");
10000 let port_value = cart_to_payment
10001 .get(KUBE_KEY_SPEC)
10002 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
10003 .and_then(|i| i.as_sequence())
10004 .and_then(|s| s.first())
10005 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
10006 .and_then(|t| t.as_sequence())
10007 .and_then(|s| s.first())
10008 .and_then(|tp| tp.get(CILIUM_KEY_PORTS))
10009 .and_then(|p| p.as_sequence())
10010 .and_then(|s| s.first())
10011 .and_then(|p| p.get(KUBE_KEY_PORT))
10012 .and_then(|v| v.as_str())
10013 .expect("toPorts[0].ports[0].port present");
10014 assert_eq!(
10015 port_value,
10016 DEFAULT_SERVICO_PORT.to_string(),
10017 "the L4 fallback must render the lifted DEFAULT_SERVICO_PORT \
10018 constant verbatim — drift here means the constant lift no \
10019 longer reaches this consumer"
10020 );
10021 }
10022
10023 #[test]
10024 fn cnp_l4_port_routes_through_lifted_port_for_destination_resolver() {
10025 // Cross-crate drift-detection pin: the CNP L4-fallback port axis
10026 // in [`cilium_network_policies`] now routes through the lifted
10027 // [`caixa_core::AplicacaoSpec::port_for_destination`] typed
10028 // dispatch (peer with the sibling
10029 // `cnp_l4_fallback_port_routes_through_lifted_default_servico_port`
10030 // pin on the DEFAULT_SERVICO_PORT canonical-constant axis). Pin
10031 // the resolver-shaped rule at the emit-side path so a future
10032 // renderer-side detour that re-inlined the "if entrada matches
10033 // this destination use its :port else fall back to
10034 // DEFAULT_SERVICO_PORT" cascade would surface as a caixa-mesh
10035 // build-time test failure — the two consumer paths on the
10036 // per-Aplicacao L4 port axis (the resolver's own typed dispatch
10037 // at caixa-core, this renderer's emit-side reach for it) must
10038 // agree at every point on the port scalar the emitted CNP
10039 // renders, per the CNP identity rule that the destination
10040 // Servico's L4 port is a substrate-canonical scalar the M4 CR
10041 // materializer + the future per-edge policy resolver inherit
10042 // by construction.
10043 let caixa = aplicacao_caixa();
10044 let spec = typed_view(&caixa).expect("aplicacao_caixa fixture must be a valid Aplicacao");
10045 let policies = cilium_network_policies(&caixa).unwrap();
10046
10047 // The `checkout-cart-to-catalog` CNP's toPorts[0].ports[0].port
10048 // scalar must match the resolver's scalar for the `catalog`
10049 // destination (a non-apex destination — the entrada names
10050 // `:para "cart"`, so the resolver falls back to the substrate
10051 // floor).
10052 let cart_to_catalog = policies
10053 .iter()
10054 .find(|p| kube_metadata_str_field(p, KUBE_KEY_NAME) == Some("checkout-cart-to-catalog"))
10055 .expect("cart→catalog CNP present");
10056 let port_value = cart_to_catalog
10057 .get(KUBE_KEY_SPEC)
10058 .and_then(|s| s.get(CILIUM_KEY_INGRESS))
10059 .and_then(|i| i.as_sequence())
10060 .and_then(|s| s.first())
10061 .and_then(|i| i.get(CILIUM_KEY_TO_PORTS))
10062 .and_then(|t| t.as_sequence())
10063 .and_then(|s| s.first())
10064 .and_then(|tp| tp.get(CILIUM_KEY_PORTS))
10065 .and_then(|p| p.as_sequence())
10066 .and_then(|s| s.first())
10067 .and_then(|p| p.get(KUBE_KEY_PORT))
10068 .and_then(|v| v.as_str())
10069 .expect("toPorts[0].ports[0].port present");
10070 assert_eq!(
10071 port_value,
10072 spec.port_for_destination("catalog").to_string(),
10073 "the per-CNP L4 port must match the port_for_destination \
10074 resolver's scalar for the same destination — drift here \
10075 means the emit-side path re-inlined the resolution rule"
10076 );
10077 }
10078
10079 #[test]
10080 fn cnp_authentication_mode_serialized_as_yaml_string() {
10081 // Pin the YAML scalar shape: `mode:` is a *string* in the
10082 // Cilium CRD schema (CiliumNetworkPolicy.spec.ingress[]
10083 // .authentication.mode: string enum {required, disabled,
10084 // test-always-fail}), not a bool. A renderer that
10085 // accidentally emits `mode: true` (the raw typed slot's
10086 // bool) would round-trip past serde_yaml but be rejected by
10087 // the apiserver-side OpenAPI schema validation — pin the
10088 // scalar kind here so a regression surfaces at build time,
10089 // not at apply time.
10090 let policies = cilium_network_policies(&aplicacao_caixa()).unwrap();
10091 let rules = cnp_ingress_rules(&policies);
10092 for rule in &rules {
10093 let mode = rule
10094 .get(CILIUM_KEY_AUTHENTICATION)
10095 .and_then(|a| a.get(CILIUM_KEY_MODE))
10096 .expect("authentication.mode present");
10097 assert!(
10098 mode.is_string(),
10099 "authentication.mode must be a YAML string (got: {mode:?})"
10100 );
10101 }
10102 }
10103
10104 /// Byte-parity converge pin on the per-`:entrada` outer-composite
10105 /// `Option<&Entrada>` accessor axis: [`AplicacaoSpec::entrada`] must
10106 /// agree with the raw `spec.entrada.as_ref()` field access on the
10107 /// `aplicacao_caixa` fixture across both the `Some(_)` presence-bit
10108 /// arm and the projected `Entrada` composite's per-axis `:host`,
10109 /// `:para`, `:paths`, `:port` scalar reads, and on the mutated
10110 /// `entrada = None` `None` arm the sibling `gateway_skips_when_no_entrada`
10111 /// test exercises. Peer of the caixa-core-side
10112 /// `aplicacao_spec_entrada_returns_entrada_option_ref_byte_equal_across_permutations`
10113 /// pin (the substrate-primitive accessor definition — `entrada(&self)
10114 /// -> Option<&Entrada>` = `self.entrada.as_ref()`) — this pin lands
10115 /// the sibling drift-detection gate at the caixa-mesh boundary so a
10116 /// future extension of the `:entrada` slot (a per-cluster ingress
10117 /// alias table pinned through a future `:entrada-overrides` overlay
10118 /// the MESH-COMPOSITION §V federation roadmap acknowledges, an M4
10119 /// `mesh.pleme.io/v1alpha1/Aplicacao` CR materializer's admission-
10120 /// webhook per-tenant `:host` rewrite, a canonicalization pass that
10121 /// lowercases the DNS-1123 label post-parse) that landed on the
10122 /// accessor without a lockstep edit on the raw field access — or vice
10123 /// versa — surfaces at caixa-mesh build time rather than at cluster-
10124 /// apply time. The three prior caixa-mesh test-side raw
10125 /// `spec.entrada.<field>` sites (the `typed_view_returns_validated_spec`
10126 /// presence-bit probe, the
10127 /// `httproute_backend_ref_port_routes_through_lifted_port_for_destination_resolver`
10128 /// per-permutation `entrada_ref` bind, and the
10129 /// `httproute_backend_ref_port_and_cnp_l4_port_share_port_for_destination_resolver_at_emit_site`
10130 /// apex-destination bind) are the consumers this pin protects — the
10131 /// converge routed each onto the substrate primitive; the pin here
10132 /// guards the primitive's byte-parity contract against silent
10133 /// divergence.
10134 #[test]
10135 fn spec_entrada_accessor_byte_equal_to_raw_field_access() {
10136 // `Some(_)` arm — the aplicacao_caixa fixture carries a typed
10137 // `:entrada` block, so the accessor projects `Some(&Entrada)`
10138 // byte-equal to the raw `self.entrada.as_ref()`.
10139 let spec = typed_view(&aplicacao_caixa()).expect("fixture is a valid Aplicacao");
10140 let via_accessor: Option<&Entrada> = spec.entrada();
10141 let via_raw: Option<&Entrada> = spec.entrada.as_ref();
10142 assert_eq!(
10143 via_accessor.is_some(),
10144 via_raw.is_some(),
10145 "AplicacaoSpec::entrada() must project the raw \
10146 Option<Entrada> slot's presence bit byte-equal to \
10147 self.entrada.as_ref() — drift would let the accessor's \
10148 Some/None partition disagree with the raw field's on a \
10149 fixture the substrate contract pins as Some(_)"
10150 );
10151 let acc = via_accessor.expect("accessor Some arm");
10152 let raw = via_raw.expect("raw Some arm");
10153 assert_eq!(
10154 acc.hostname(),
10155 raw.hostname(),
10156 "accessor and raw must agree on Entrada::hostname()"
10157 );
10158 assert_eq!(
10159 acc.destination(),
10160 raw.destination(),
10161 "accessor and raw must agree on Entrada::destination()"
10162 );
10163 assert_eq!(
10164 acc.port(),
10165 raw.port(),
10166 "accessor and raw must agree on Entrada::port()"
10167 );
10168 assert_eq!(
10169 acc.paths(),
10170 raw.paths(),
10171 "accessor and raw must agree on Entrada::paths()"
10172 );
10173
10174 // `None` arm — mutate the fixture to drop `:entrada`, matching
10175 // the sibling `gateway_skips_when_no_entrada` early-return
10176 // partition. The accessor and the raw field must both project
10177 // `None`.
10178 let mut no_entrada = aplicacao_caixa();
10179 no_entrada.entrada = None;
10180 let spec_none = typed_view(&no_entrada).expect("fixture without :entrada is still valid");
10181 assert!(
10182 spec_none.entrada().is_none(),
10183 "accessor must project None on a fixture with no :entrada"
10184 );
10185 assert!(
10186 spec_none.entrada.is_none(),
10187 "raw field must project None on a fixture with no :entrada"
10188 );
10189 }
10190}