Skip to main content

Crate lava_operator

Crate lava_operator 

Source
Expand description

lava-operator — typed Kubernetes controller for the LavaArchitecture CRD. Pangea-operator analog for the lava + tatara-lisp stack.

§Shape

Operator authors a LavaArchitecture manifest:

apiVersion: lava.pleme.io/v1alpha1
kind: LavaArchitecture
metadata: { name: prod-vpc, namespace: infra }
spec:
  source:
    # Either inline tlisp source ...
    inline: |
      (deflava-architecture demo-vpc
        :inputs ((:cidr "10.42.0.0/16"))
        :resources ((aws-vpc "main" :cidr-block "{cidr}")))
    # ... or a registry-hosted reference:
    # name: aws-vpc-network  (looks up bundled architecture)
  bindings:
    name: prod
    cidr: 10.42.0.0/16
  gate: aws-vpc-network              # optional typed Interface gate
  engine: embedded                   # embedded | tofu | terraform
status:
  phase: Applied
  conditions:
    - type: Synthesized | Planned | Applied | Failed
      status: True

The controller’s Reconcile loop:

  1. Resolve source (inline or bundled name)
  2. magma-lava::synthesize → typed Architecture + terraform.json
  3. (Optional) typed-interface gate
  4. engine: embedded (in-process) OR shell out to tofu/terraform
  5. Status update with typed Conditions

§Status

This crate ships the typed CRD schema + reconcile state machine (typed Phase + Condition + RenderRecord values). The kube-rs controller binary is the next-milestone (M1) wrapper — keeps this crate dependency-light + testable without a live cluster.

Modules§

anomaly_bridge
Bridge between the controller’s typed surfaces and lava-anomaly’s routing primitives. Translates DriftScanOutcome / synth errors / apply errors into typed LavaAnomalys, then routes them through the configured AnomalyRouter.
attest
Attestation bridge — wires the reconcile loop into lava_outcome_chain so every phase transition produces a signed BLAKE3-linked receipt.
controller
kube-rs controller wrapper for crate::LavaArchitectureSpec.
drift
Drift integration — wires lava_drift::DriftDetector into the controller’s reconcile path.
finalizer
Finalizer — runs the destroy path before the CR is removed from etcd. Solid abstraction: the controller calls run_finalizer with a typed DestroyBackend; this module never imports kube-rs (lives in lib defaults too).
magma_bridge
magma-lava bridge — produces a SynthesizeFn callback the controller can register with lava_operator::controller::run.
viggy_loop
Viggy loop — drives ViggyEngine::tick on every reconcile pass.

Structs§

Condition
LavaArchitecture
Top-level CRD spec + status.
LavaArchitectureSpec
LavaArchitectureStatus
ObjectMeta
ReconcileOutcome
Result of one reconcile pass. The controller serializes this back into the resource’s .status block.

Enums§

Phase
Typed phase the controller drives the resource through.
ReconcileError
Source

Functions§

crd_yaml
Render the LavaArchitecture CRD YAML for kubectl apply. Backwards-compat single-CRD form — new consumers should use crd_yaml_all which emits every CRD the operator owns.
crd_yaml_all
Emit every CRD the operator owns, joined with --- separators so the output is a single kubectl apply -f - stream. Each CRD carries a full openAPIV3Schema derived from the kube-rs #[derive(CustomResource, JsonSchema)] shapes — apiextensions/v1 requires this; the hand-rolled crd_yaml_for helper below is kept only for the backwards-compat single-CRD form.
reconcile
Pure state-machine: given the current resource + a synthesize callback, advance the phase. The kube-rs wrapper supplies the callback (which routes through magma-lava); this function stays kube-free + unit-testable.