Skip to content

feat(providers): add CLI label creation and filtering - #4265

Open
johntmyers wants to merge 2 commits into
mainfrom
docs/4250-workspace-provider-labels/johntmyers
Open

johntmyers wants to merge 2 commits into
mainfrom
docs/4250-workspace-provider-labels/johntmyers

Conversation

@johntmyers

@johntmyers johntmyers commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Provider labels were available only through API creation, and provider lists could not filter them. Add CLI label creation, inspection, and filtering, and document the workspace and provider label workflows.

Related Issue

Closes #4250
Closes #4312

Changes

  • Add repeatable provider create --label KEY=VALUE, provider list --label-selector key=value,key2=value2, and labels in provider get output.
  • Add ListProvidersRequest.label_selector and reuse gateway selector filtering before pagination for named and all-workspaces scopes. Bind continuation tokens to the selector and preserve authorization and credential redaction.
  • Regenerate the checked-in Go protobuf bindings and update existing Rust request constructors.
  • Document workspace labels, provider labels, and create-time-only label semantics; update the public CLI skill.
  • Cover credential-source forwarding, malformed labels and selectors, filtered pagination, changed-selector tokens, workspace isolation, and secret redaction.

Testing

  • Provider CLI parsing tests and both provider CLI integration suites passed.
  • Gateway label filtering tests, non-member authorization tests, and provider workspace-isolation test passed.
  • mise run sdk:ts:ci and mise run go:ci passed; Python protobuf generation passed.
  • mise run docs, Markdown lint, and git diff --check passed. Fern reported the existing gateway configuration MDX, unauthenticated redirect-check, and theme-contrast warnings.
  • Full mise run pre-commit passed through the commit hook.
  • Unit and integration tests added/updated.
  • E2E changes are not applicable; this does not change sandbox or deployment infrastructure.

Checklist

  • Follows Conventional Commits.
  • Commits are signed off (DCO).
  • Architecture documentation updates are not applicable; the existing metadata storage and pager are reused.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
@johntmyers johntmyers added the area:cli CLI-related work label Oct 7, 2026
@johntmyers johntmyers changed the title docs: document workspace and provider labels feat(providers): add CLI label creation and filtering Oct 7, 2026

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The provider label workflow fits the linked issues, and the CLI, filtering, docs, and generated bindings were reviewed. One blocking finding remains: the added public protobuf field changes the schema fingerprint without updating its reviewed value, which is failing all three required Rust test jobs.

Action required: @johntmyers, update the reviewed public schema fingerprint and verify the focused inventory test before pushing a new head.

Blocking findings:

  • GATOR-5ed7c0d8-01: Update the public schema fingerprint for the new selector field; details are inline.

Carried findings: None.

Gator metadata
  • Validation: Maintainer-authored provider CLI feature and label documentation covered by #4250 and #4312.
  • Docs: Relevant Fern provider and workspace pages, plus the public CLI skill, are updated.
  • Checks: Branch Checks fails on x86_64-linux, aarch64-linux, and aarch64-darwin at the same schema inventory assertion. DCO, Helm gate, and Trivy gate pass.
  • E2E: No additional test dispatch in this cycle; review feedback must be addressed before pipeline handoff.
  • Head SHA: 5ed7c0d81e2f432f005efa035193e7620f65dce3
  • Base SHA: 9a6148fc988a5e7a20a43805a52fdfaad766f8ae
  • Merge base SHA: 0bca9fb8280045224c910610cba005b7fa5a6a83
  • Patch ID: 0eb5b5f7761c4e39006eaede310ca7b0fe1e8967
  • Gator payload: 11
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

Comment thread proto/openshell.proto
// except page_size must match the request that produced it.
string page_token = 2;
// Optional label selector for filtering (format: "key1=value1,key2=value2").
string label_selector = 4;

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

Warning — GATOR-5ed7c0d8-01 · Update the reviewed public schema fingerprint

Summary: Adding this request field changes the public schema fingerprint, but PUBLIC_RPC_SCHEMA_SHA256 in crates/openshell-server/src/storage_proto.rs:137 still has the previous value. The schema inventory test consequently fails in the x86_64-linux, aarch64-linux, and aarch64-darwin Branch Checks jobs, preventing the required CI gate from passing.

Fix: After reviewing this additive public-only field, update PUBLIC_RPC_SCHEMA_SHA256 to 00edf58cc057357617f724ae07a815139a08461c1c6dc8537390d25e3231b717. Preserve the unchanged durable and overlap fingerprints and verify the focused inventory test passes.

Verify: Run cargo test -p openshell-server storage_proto::tests::public_and_durable_schema_inventories_are_complete. The current head fails with the new public hash versus the old expected value; after the update the assertion should pass. All three existing CI logs show this same mismatch, with matching counts, durable hash, and overlap hash.

Agent context
  • Ownership: This is the PR's only protobuf schema change, and the diff does not update the reviewed fingerprint.
  • Location: proto/openshell.proto:2145; failing assertion at crates/openshell-server/src/storage_proto.rs:597.

@johntmyers johntmyers added gator:in-review Gator is reviewing or awaiting PR review feedback gator:blocked Gator is blocked by process or repository gates and removed gator:in-review Gator is reviewing or awaiting PR review feedback labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:cli CLI-related work area:providers gator:blocked Gator is blocked by process or repository gates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(providers): support CLI label creation, inspection, and filtering docs: document workspace and provider label capabilities

1 participant