The GitHub Actions job "Backport Approval Check" on 
texera.git/feat/mount-B1-platform has succeeded.
Run started by GitHub user aicam (triggered by aicam).

Head commit for run:
3ac9a96a29bd3f9a1638cf063fc03230b1fa91ba / ali <[email protected]>
feat(dataset-mount): mount authority and version resolution

Give the platform a way to mount a versioned LakeFS repository into a
computing unit, and the engine a way to ask for one — the plumbing the
Python UDF resource parameter needs (#6895). No user-facing surface:
mounting is implied by a UDF parameter that names a model or dataset,
not by an explicit action.

The per-node mounter admits exactly one caller, verified with
TokenReview against an audience-bound service-account token that only
access-control-service holds, so the mount endpoint lives there. It
validates the caller's JWT, confirms that user's access to the computing
unit, resolves which node the unit's pod is on, and forwards to that
node's mounter. It resolves the node itself rather than taking one from
the caller, or anything reaching it could aim requests at any node's
privileged mounter. Path components are validated on the way out,
mirroring the mounter's own check.

A version is named by a logical dataset or model path; the mounter
addresses it as a repository and commit, so the resolver learns that
conversion. The engine gets a client that asks the authority with the
computing unit's own user JWT and waits for the propagated mount to
appear in the pod. Nothing calls it yet.

Read access stays on the data path, where file-service authorizes every
read, and mounts are released when the pod is deleted, so there is no
unmount path. Everything is behind mounter.enabled.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01Fy9tJ1AB4trv6ZYGwfm9pR

Report URL: https://github.com/apache/texera/actions/runs/34275512414

With regards,
GitHub Actions via GitBox

Reply via email to