Skip to content

bb-run-approve-abort: approve and abort building block runs - #27

Draft
grubmeshi wants to merge 4 commits into
mainfrom
feature/bb-run-approve-abort
Draft

grubmeshi wants to merge 4 commits into
mainfrom
feature/bb-run-approve-abort

Conversation

@grubmeshi

@grubmeshi grubmeshi commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

🤖 Written by AI agent

bb-run-approve-abort

Two new interactive commands let a person approve a building block run that waits for approval, and abort a run, without meshPanel:

  • meshstack buildingblock approve-run <building-block-uuid> shows the plan of the waiting run and asks "Approve this plan? [y/N]". The approval names the predecessor run that made the shown plan, so meshStack refuses it (409) when the run was planned again in the meantime. The CLI then asks you to run the command again to review the new plan.
  • meshstack buildingblock abort-run <building-block-uuid> takes the newest dry run when there is one, else the latest run, shows it and asks "Abort this run? [y/N]".

Both commands run only on a terminal, because the decision belongs to a person who saw the run. They start from the building block and follow HAL links only: latestRun and latestDryRun on the building block, and predecessor, downloadLogs, approve and abort on the run. When meshStack does not send the needed link (the run does not wait, cannot be aborted, or the caller may not act), the command stops with a clear message before it asks. After the action it reads the building block again and writes it, because a run shows WAITING_FOR_APPROVAL as IN_PROGRESS and ABORTED as FAILED.

Do not merge before the meshfed-release backend PR (meshcloud/meshfed-release#11281) is released. It adds the approve and abort endpoints and the new links. Until then the commands stop with the missing-link message.

For the Terraform provider

Nothing to do on the next bump. The new client methods sit on a new Client.BuildingBlockRunAction field, so the mocks keep compiling, and the new Links field is on MeshBuildingBlockRun, which the provider does not map to a schema. The provider's main builds, vets and passes its unit tests against this branch.

Tests

No acceptance test: the suite talks to the commands through stdin, which is no terminal, so it cannot drive an interactive command. Unit tests cover the guards: no terminal, the approved predecessor is the shown one, a changed plan, missing links, and the dry run taking precedence on abort.

Cross-repo PRs

  • meshcloud/meshstack-cli — this PR: the client methods and the two commands
  • meshcloud/meshfed-release#11281 — the approve and abort run endpoints and the links on run v1 and building block v2
  • meshcloud/meshfed-release#11282 — the Panel's trigger and abort follow run transparency

🤖 Generated with Claude Code

grubmeshi and others added 4 commits October 5, 2026 16:28
…bort them

The CLI approves and aborts a run through the approve and abort links that
meshStack puts on a run while the caller may take the action. The client
reads a run and its logs from a link, and sends the token only to a link
below the endpoint.

The methods sit on a new Client field, so the mocks of the Terraform
provider keep compiling.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
profile delete asked its question and read the answer itself. The commands
that approve and abort building block runs ask the same way, so the question
moves to the prompt.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…gblock approve-run

The command finds the run that waits for approval through the building block,
shows the plan that its predecessor run made, and asks before it approves.
The approval names that predecessor, so meshStack refuses it when the run was
planned again after the person saw the plan. Because the decision belongs to a
person, the command runs only on a terminal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…gblock abort-run

The command takes the dry run when it is newer than the latest run, and the
latest run otherwise. It shows the run and asks before it aborts, so it runs
only on a terminal, as approve-run does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@grubmeshi
grubmeshi force-pushed the feature/bb-run-approve-abort branch from 53f3c58 to 6186f13 Compare October 5, 2026 14:29
@meshcloud-gh-actions

Copy link
Copy Markdown

Coverage of the acceptance run against the meshStack backend, on 6186f1311101fa76df684a511c9ed027478c9b28.

Scope Coverage
Unit tests 79.1%
Acceptance tests 51.8%
Combined 83.2%
Uncovered functions
client/api_key.go:55: meshApiKeyClient.Create 0.0%
client/api_key.go:59: meshApiKeyClient.Read 0.0%
client/api_key.go:63: meshApiKeyClient.Update 0.0%
client/api_key.go:71: meshApiKeyClient.Delete 0.0%
client/api_key_permissions.go:20: ApiKeyPermissions.AllCodes 0.0%
client/api_key_permissions.go:33: ApiKeyPermissions.WorkspaceCodes 0.0%
client/api_key_permissions.go:295: AllApiKeyPermissions 0.0%
client/api_key_permissions.go:299: WorkspacePermissionCodes 0.0%
client/building_block_definition.go:71: MeshBuildingBlockDefinitionApprovalPolicies.NothingRequiresApproval 0.0%
client/building_block_definition.go:82: DisabledSchedule 0.0%
client/building_block_definition.go:89: MeshBuildingBlockDefinitionSchedule.IsDisabled 0.0%
client/building_block_definition.go:93: MeshBuildingBlockDefinitionSpec.HasNeutralPolicies 0.0%
client/building_block_definition.go:97: MeshBuildingBlockDefinitionSpec.WithNeutralPolicies 0.0%
client/building_block_definition.go:166: meshBuildingBlockDefinitionClient.List 0.0%
client/building_block_definition.go:173: meshBuildingBlockDefinitionClient.Read 0.0%
client/building_block_definition.go:177: meshBuildingBlockDefinitionClient.Create 0.0%
client/building_block_definition.go:181: meshBuildingBlockDefinitionClient.Update 0.0%
client/building_block_definition.go:185: meshBuildingBlockDefinitionClient.Delete 0.0%
client/building_block_definition_version.go:100: MeshBuildingBlockType.TagInputTargets 0.0%
client/building_block_definition_version.go:245: meshBuildingBlockDefinitionVersionClient.Create 0.0%
client/building_block_definition_version.go:254: meshBuildingBlockDefinitionVersionClient.Update 0.0%
client/building_block_definition_version_implementation.go:80: MeshBuildingBlockDefinitionImplementation.InferType 0.0%
client/building_block_definition_version_implementation.go:94: MeshBuildingBlockDefinitionImplementation.MarshalJSON 0.0%
client/building_block_definition_version_implementation.go:107: *MeshBuildingBlockDefinitionImplementation.UnmarshalJSON 0.0%
client/building_block_runner.go:82: meshBuildingBlockRunnerClient.Create 0.0%
... and 123 more

covdata func names a method without its receiver, so an entry can belong to an implementation nothing selects rather than to a function the tests never reached. Open the file and line before reading one as a coverage gap.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant