fix: match cell name against cluster URLs before jurisdiction fallback · Entire

fix: match cell name against cluster URLs before jurisdiction fallback

43ae606→main·

evisdren·1w ago·2 files·+65 added/-7 removed

When a placement-derived group lacks a cluster slug, try matching
the group's cell name against cluster ApiUrl/PublicUrl hosts (e.g.
cell "aws-eu-central-1" matches "https://aws-eu-central-1.api.entire.io")
before falling back to the jurisdiction-level default cluster.

This prevents binding a mirror group to the wrong cell's baseURL when
a jurisdiction contains multiple cells — the cell-URL match is precise
while the jurisdiction fallback is ambiguous.

Resolution order:

  1. Cluster slug join (exact, for home placements)
  2. Cell name in cluster URL host (precise, for mirror placements)
  3. Default cluster in jurisdiction (fallback)

Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

Sessions

01KWZZ4E8MK7FMHS55VH48Q6XXView transcript

[?
Fix Code Search across Mirror PlacementsClaude Code·Opus 4.6·2 steps](/content/gh/entireio/cli/session/049ddfe6-94db-4012-a48d-d8e512970d53#timeline-01KWZZ4E8MK7FMHS55VH48Q6XX/index.html)

Changes

2

1 unmodified line

2
3
4
5
6
7
8
146 unmodified lines

155
156
157
158
159
160
161
162
163
164
165
166
158
159
167
168
169
170
171
172
19 unmodified lines

192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222

1 unmodified line

import (
    "context"
    "net/url"
    "sort"
    "strings"
    "sync"
146 unmodified lines

}
    for i := range cells {
        cl, ok := bySlug[cells[i].clusterSlug]
        if !ok && cells[i].cell != "" {
            // Try matching the group's cell name against catalog apiUrl
            // hosts (e.g. cell "aws-eu-central-1" matches
            // "https://aws-eu-central-1.api.entire.io"). This is more
            // precise than jurisdiction when a jurisdiction has multiple
            // cells — mirroring matchClusterByHost in cell_target.go.
            cl, ok = matchClusterByCellInURL(clusters.Clusters, cells[i].cell)
        }
        if !ok && cells[i].jurisdiction != "" {
            // Placement-derived groups lack a cluster slug; fall back to
            // jurisdiction so mirror placements still resolve a baseURL.
            // Last resort: jurisdiction-level fallback using the default
            // cluster. Less precise, but still routes to the right
            // jurisdiction when the cell name doesn't appear in any URL.
            cl, ok = byJurisdiction[cells[i].jurisdiction]
        }
        if !ok {
19 unmodified lines

}
}

// matchClusterByCellInURL finds a catalog cluster whose ApiUrl or PublicUrl
// host contains the cell name as a prefix (e.g. cell "aws-eu-central-1"
// matches "https://aws-eu-central-1.api.entire.io"). This is more precise
// than a jurisdiction-level fallback when multiple clusters share a
// jurisdiction — each cluster serves a different cell.
func matchClusterByCellInURL(clusters []coreapi.Cluster, cell string) (coreapi.Cluster, bool) {
    prefix := strings.ToLower(strings.TrimSpace(cell)) + "."
    for _, cl := range clusters {
        for _, rawURL := range []string{cl.ApiUrl.Or(""), cl.PublicUrl} {
            rawURL = strings.TrimSpace(rawURL)
            if rawURL == "" {
                continue
            }
            u, err := url.Parse(rawURL)
            if err != nil {
                continue
            }
            if strings.HasPrefix(strings.ToLower(u.Hostname()), prefix) {
                return cl, true
            }
        }
    }
    return coreapi.Cluster{}, false
}

// cellTarget converts the group's routing coordinates into the auth layer's
// CellTarget: full target when the catalog resolved a baseURL,
// jurisdiction-only when it didn't, nil (home routing) when neither is known.

Mcmd/entire/cli/cell_fanout.go+37/-2

185 unmodified lines

186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 190 191 212 213 214 215 216 195 217 218 219 220 221 222 223 201 224 225 226 204 227 228 229 230

185 unmodified lines

} }

// TestResolveCellBaseURLs_CellURLMatchOverJurisdiction verifies that when a // jurisdiction has multiple clusters, the resolver matches the group's cell // name against cluster ApiUrl hosts rather than picking an arbitrary one. // This prevents binding a mirror group to the wrong cell's baseURL. func TestResolveCellBaseURLs_CellURLMatchOverJurisdiction(t *testing.T) { t.Parallel() cells := []cellGroup{ // Mirror group whose cell name appears in the second cluster's URL. {cell: "aws-eu-central-1", clusterSlug: "", jurisdiction: "eu"}, } fake := &fakeCellCore{clusters: []coreapi.Cluster{ // Different EU cell — must NOT be picked even though it's first and default. {Slug: "eu-west-prod", Jurisdiction: "eu", IsDefault: true, ApiUrl: coreapi.NewOptString("https://aws-eu-west-1.api.entire.io")}, // Matching cell — should be picked by cell-URL matching. {Slug: "eu-central-prod", Jurisdiction: "eu", ApiUrl: coreapi.NewOptString("https://aws-eu-central-1.api.entire.io")}, }} resolveCellBaseURLs(context.Background(), fake, cells) if cells[0].baseURL != "https://aws-eu-central-1.api.entire.io" { t.Fatalf("eu baseURL = %q, want cell-matched URL, not default cluster", cells[0].baseURL) } }

// TestResolveCellBaseURLs_JurisdictionFallbackPrefersDefault verifies that // when multiple clusters exist in a jurisdiction, the fallback picks the one // with IsDefault=true — matching the auth layer's resolution. // when cell-URL matching doesn't find a match, the jurisdiction fallback // picks the cluster with IsDefault=true. func TestResolveCellBaseURLs_JurisdictionFallbackPrefersDefault(t *testing.T) { t.Parallel() cells := []cellGroup{ {cell: "aws-eu-central-1", clusterSlug: "", jurisdiction: "eu"}, // Cell name doesn't appear in any cluster URL — falls through to jurisdiction. {cell: "aws-eu-unknown-1", clusterSlug: "", jurisdiction: "eu"}, } fake := &fakeCellCore{clusters: []coreapi.Cluster{ // Non-default listed first — must not win. {Slug: "eu-staging", Jurisdiction: "eu", ApiUrl: coreapi.NewOptString("https://eu-staging.api.entire.io")}, // Default cluster — should be preferred. {Slug: "eu-prod", Jurisdiction: "eu", IsDefault: true, ApiUrl: coreapi.NewOptString("https://aws-eu-central-1.api.entire.io")}, {Slug: "eu-prod", Jurisdiction: "eu", IsDefault: true, ApiUrl: coreapi.NewOptString("https://eu-default.api.entire.io")}, }} resolveCellBaseURLs(context.Background(), fake, cells) if cells[0].baseURL != "https://aws-eu-central-1.api.entire.io" { if cells[0].baseURL != "https://eu-default.api.entire.io" { t.Fatalf("eu baseURL = %q, want default cluster's URL", cells[0].baseURL) } } }