Expand description
lava-operator — typed Kubernetes controller for the LavaArchitecture CRD. Pangea-operator analog for the lava + tatara-lisp stack.
§Shape
Operator authors a LavaArchitecture manifest:
apiVersion: lava.pleme.io/v1alpha1
kind: LavaArchitecture
metadata: { name: prod-vpc, namespace: infra }
spec:
source:
# Either inline tlisp source ...
inline: |
(deflava-architecture demo-vpc
:inputs ((:cidr "10.42.0.0/16"))
:resources ((aws-vpc "main" :cidr-block "{cidr}")))
# ... or a registry-hosted reference:
# name: aws-vpc-network (looks up bundled architecture)
bindings:
name: prod
cidr: 10.42.0.0/16
gate: aws-vpc-network # optional typed Interface gate
engine: embedded # embedded | tofu | terraform
status:
phase: Applied
conditions:
- type: Synthesized | Planned | Applied | Failed
status: TrueThe controller’s Reconcile loop:
- Resolve source (inline or bundled name)
- magma-lava::synthesize → typed Architecture + terraform.json
- (Optional) typed-interface gate
- engine: embedded (in-process) OR shell out to tofu/terraform
- Status update with typed Conditions
§Status
This crate ships the typed CRD schema + reconcile state machine (typed Phase + Condition + RenderRecord values). The kube-rs controller binary is the next-milestone (M1) wrapper — keeps this crate dependency-light + testable without a live cluster.
Modules§
- anomaly_
bridge - Bridge between the controller’s typed surfaces and lava-anomaly’s
routing primitives. Translates DriftScanOutcome / synth errors /
apply errors into typed
LavaAnomalys, then routes them through the configuredAnomalyRouter. - attest
- Attestation bridge — wires the reconcile loop into
lava_outcome_chainso every phase transition produces a signed BLAKE3-linked receipt. - controller
- kube-rs controller wrapper for
crate::LavaArchitectureSpec. - drift
- Drift integration — wires
lava_drift::DriftDetectorinto the controller’s reconcile path. - finalizer
- Finalizer — runs the destroy path before the CR is removed from
etcd. Solid abstraction: the controller calls
run_finalizerwith a typedDestroyBackend; this module never imports kube-rs (lives in lib defaults too). - magma_
bridge - magma-lava bridge — produces a
SynthesizeFncallback the controller can register withlava_operator::controller::run. - viggy_
loop - Viggy loop — drives
ViggyEngine::tickon every reconcile pass.
Structs§
- Condition
- Lava
Architecture - Top-level CRD spec + status.
- Lava
Architecture Spec - Lava
Architecture Status - Object
Meta - Reconcile
Outcome - Result of one reconcile pass. The controller serializes this back
into the resource’s
.statusblock.
Enums§
- Phase
- Typed phase the controller drives the resource through.
- Reconcile
Error - Source
Functions§
- crd_
yaml - Render the LavaArchitecture CRD YAML for
kubectl apply. Backwards-compat single-CRD form — new consumers should usecrd_yaml_allwhich emits every CRD the operator owns. - crd_
yaml_ all - Emit every CRD the operator owns, joined with
---separators so the output is a singlekubectl apply -f -stream. Each CRD carries a fullopenAPIV3Schemaderived from the kube-rs#[derive(CustomResource, JsonSchema)]shapes — apiextensions/v1 requires this; the hand-rolledcrd_yaml_forhelper below is kept only for the backwards-compat single-CRD form. - reconcile
- Pure state-machine: given the current resource + a synthesize callback, advance the phase. The kube-rs wrapper supplies the callback (which routes through magma-lava); this function stays kube-free + unit-testable.