Skip to content

feat: add schema validation - #780

Merged
jhrv merged 2 commits into
mainfrom
schema-validation
Sep 24, 2026
Merged

jhrv merged 2 commits into
mainfrom
schema-validation

Conversation

@jhrv

@jhrv jhrv commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

This pull request introduces schema validation for native Nais resource manifests (such as Postgres, Valkey, and OpenSearch) in the apply workflow. If schema validation is unavailable (for example, due to a network error), a warning is issued and the process continues; however, if a manifest fails validation, the apply operation is halted. The main changes are the addition of a new validation module and its integration into the apply logic.

Schema validation for native resource manifests:

  • Added internal/apply/validate.go, which implements schema validation for native Nais manifests using the published JSON schema from schemas.nais.io. This includes logic to fetch and cache the schema, validate manifests, and format any errors for user feedback.
  • Integrated the new ValidateNativeManifests function into the apply workflow in internal/apply/apply.go, issuing a warning if schema validation is unavailable and halting the apply process if validation fails.

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

📝 Changelog preview

Below is a preview of the Changelog that will be added to the next release. Only commit messages that follow the Conventional Commits specification will be included in the Changelog.

v5.50.0 - 2026-09-24

Full Changelog: v5.49.3...v5.50.0

🚀 Features

🐛 Bug Fixes

  • Reject empty native resource schema aggregate (4cbc961)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved schema caching, parse-error handling, and validation-bypass issues remain.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds preflight JSON Schema validation for native Nais manifests before nais apply, with warnings when schemas are unavailable.

Changes:

  • Added schema loading, resolution, validation, and error formatting.
  • Integrated validation into the apply workflow.
  • Added validation and schema-loading tests.
File Summary
internal/​apply/​validate.go Implements schema validation. Findings: compiled schemas are refetched per invocation (moderate, 1 vote); parse errors are discarded (moderate, 1 vote); empty schema aggregates can silently bypass validation (critical, 2 votes).
internal/​apply/​validate_test.go Adds validation and schema-loading test coverage.
internal/​apply/​apply.go Runs validation before applying resources.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/apply/validate.go
@jhrv
jhrv merged commit 54e5834 into main Sep 24, 2026
22 checks passed
@jhrv
jhrv deleted the schema-validation branch September 24, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants