feat: add schema validation - #780
Merged
Merged
Conversation
Contributor
📝 Changelog previewBelow is a preview of the Changelog that will be added to the next release. Only commit messages that follow the Conventional Commits specification will be included in the Changelog. v5.50.0 - 2026-09-24Full Changelog: v5.49.3...v5.50.0 🚀 Features
🐛 Bug Fixes
|
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved schema caching, parse-error handling, and validation-bypass issues remain.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds preflight JSON Schema validation for native Nais manifests before nais apply, with warnings when schemas are unavailable.
Changes:
- Added schema loading, resolution, validation, and error formatting.
- Integrated validation into the apply workflow.
- Added validation and schema-loading tests.
| File | Summary |
|---|---|
internal/apply/validate.go |
Implements schema validation. Findings: compiled schemas are refetched per invocation (moderate, 1 vote); parse errors are discarded (moderate, 1 vote); empty schema aggregates can silently bypass validation (critical, 2 votes). |
internal/apply/validate_test.go |
Adds validation and schema-loading test coverage. |
internal/apply/apply.go |
Runs validation before applying resources. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This pull request introduces schema validation for native Nais resource manifests (such as Postgres, Valkey, and OpenSearch) in the apply workflow. If schema validation is unavailable (for example, due to a network error), a warning is issued and the process continues; however, if a manifest fails validation, the apply operation is halted. The main changes are the addition of a new validation module and its integration into the apply logic.
Schema validation for native resource manifests:
internal/apply/validate.go, which implements schema validation for native Nais manifests using the published JSON schema fromschemas.nais.io. This includes logic to fetch and cache the schema, validate manifests, and format any errors for user feedback.ValidateNativeManifestsfunction into the apply workflow ininternal/apply/apply.go, issuing a warning if schema validation is unavailable and halting the apply process if validation fails.