fix: allow Domain and Group in catalog rules#24
Merged
Conversation
The catalog.rules allow-list gated location-sourced entities to Component/System/API/Resource/Location, so Domain and Group entities declared inside a discovered catalog-info.yaml were rejected with "not of an allowed kind for that location". The infra catalog snapshot leads with a Group, which trips this on the very first entity. Add Domain and Group to the allow-list so a repo descriptor can declare its owning team and domain taxonomy. Provider-emitted org data (githubOrg users/teams) is unaffected — it bypasses catalog.rules. Claude-Session: https://claude.ai/code/session_01NMSkwUcaTmZr7S5XmV2aFG
scotwells
enabled auto-merge
July 2, 2026 17:53
ecv
approved these changes
Jul 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Allow
DomainandGroupfrom catalog locationsStaging Backstage discovers the infra
catalog-info.yamlbut rejects entities from it, logging:Cause
catalog.rulesgated location-sourced entities toComponent/System/API/Resource/Location. Entities defined inside a discoveredcatalog-info.yamlare children of that Location and are checked against this allow-list, so the snapshot'sDomain(7) andGroup(3) entities are refused. Because the file leads withkind: Group, the rules check trips on the first entity.Note this only affects entities declared in catalog files — org data imported by the
githubOrgprovider is emitted directly by the provider and bypassescatalog.rules, which is why Users/Teams import fine while in-file Groups do not.Fix
Add
DomainandGroupto the allow-list so a repo's descriptor can declare its owning team and domain taxonomy alongside its components.Related