The GitHub Actions job "Required Checks" on texera.git/feat/mount-B1-platform has succeeded. Run started by GitHub user aicam (triggered by aicam).
Head commit for run: 962260eda4b73018ad1195c374325d220fc2fec5 / ali <[email protected]> feat(dataset-mount): authorize and perform a repository mount Let a computing unit have a versioned LakeFS repository mounted into it, on the infrastructure merged in #6866. The per-node mounter authorizes nothing — it performs what it is told, which is why it admits exactly one caller, verified with TokenReview against an audience-bound service-account token that only access-control-service holds. Every decision therefore has to be made here, and this endpoint makes four before anything reaches the mounter: the request has the shape a mount path can be built from; the caller holds write access to the computing unit, mounting being a change to it; the caller may read the repository, matched by name across datasets and models and refused unless exactly one matches; and the commit belongs to that repository. It then resolves which node the unit's pod is on — itself, rather than taking one from the caller, or anything reaching it could aim requests at any node's privileged mounter — and forwards. file-service still re-checks read access on every byte it serves, but as the last line rather than the only one: without the check here a caller could have a mount created for a repository they cannot read, learning it exists and spending a node's resources on it. The rules themselves move to common/resource so both services decide from one definition. Mounts are released when the pod is deleted, so there is no unmount path. No new configuration: the mounter's port and file-service's root come from the environment the chart already sets. Everything is behind mounter.enabled. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01Fy9tJ1AB4trv6ZYGwfm9pR Report URL: https://github.com/apache/texera/actions/runs/34284494369 With regards, GitHub Actions via GitBox
