GitLab instance form

Status: Implemented Issue: none Parent: none

Goal

An administrator creates and edits a GitLab instance, and its add-ons, in the Bridge UI without writing YAML, and can leave the form half-filled while looking at another section.

Requirements

  • The form writes one GitLabCore, in sections: Basics, Dependencies, Networking, Add-ons, and Overrides.
  • Moving between sections validates nothing.
  • A section with unsaved changes shows a dot, and a section that fails validation a red mark.
  • Create and Save validate the sections in order, and open the first one that fails.
  • The PostgreSQL, Valkey, object storage, and license groups are each all-or-nothing. An incomplete group is reported before any request is sent.
  • The license group shows for Enterprise Edition only. Community Edition sends no license.
  • The form creates in gitlab-system. An existing resource is edited in its own namespace, and its name cannot change.
  • The chart version has no default and no fixed list of choices.
  • Manual networking leaves spec.networking unset.
  • The Secret Manager add-on writes spec.openbao. Add-ons that are not built yet show as disabled.
  • Enabling Siphon writes a Siphon resource of its own, after the instance is saved.
  • When the Siphon fails to save, the instance stays saved, and the form stays open on the add-on. Saving again updates the instance and retries the Siphon, without creating the instance again.
  • Clearing Enable Siphon deletes the Siphon after a confirmation. Declining keeps it.
  • A caller who cannot read Siphon resources can still save the instance. The add-on shows as Unknown and locked, and an existing Siphon is left untouched.
  • While a Siphon exists, the panel reports its PostgreSQL publication, replication slot, and NATS stream.

Out of scope

  • A choice of namespace when creating an instance.
  • A schema for the chart values in the Overrides section.
  • Editing the chart values of a Siphon in the form.

FAQ

  • Why is Siphon saved after the instance? The Siphon references the instance, not the other way around.
  • Why does the form warn before deleting a Siphon? Deleting it stops the pipeline and leaves the publication, the replication slot, and the NATS stream behind. A retained slot pins write-ahead log on the source server until its volume fills.
  • Why does the form keep the chart values of a Siphon it cannot edit? The save replaces the whole resource, so values the form did not load would otherwise be dropped.