Test project-qualified extension import - #89
Open
IlyaasK wants to merge 68 commits into
Open
Conversation
Set the durable v1 target and release gates before resource implementation begins. Co-authored-by: Cursor <cursoragent@cursor.com>
Use the latest tagged SDK while keeping provider behavior unchanged.
Expose org-scoped project mutations without automatic retries so Terraform resource work can use the generated SDK safely.
Define the durable project schema and pure SDK conversion boundary before wiring resource lifecycle behavior.
Model definite, successful, and uncertain project creation without exposing a partial Terraform resource. Preserve recoverable identity on ambiguous outcomes and direct operators to import before retrying.
IlyaasK
marked this pull request as ready for review
July 11, 2026 17:44
IlyaasK
requested review from
Sayan- and
tnsardesai
and removed request for
Sayan- and
tnsardesai
July 11, 2026 17:44
Join all project flatten diagnostics in uncertain create outcomes so operators see every invalid durable field. Add a regression test covering simultaneous missing ID and name values.
Read projects by canonical state ID, remove state only for coded not-found responses, and reject malformed or identity-changing API responses. Cover the pure unregistered lifecycle core with focused tests.
Build SDK error and response fixtures before parallel Create subtests so helper failures use the owning parent test before child execution begins.
Build a name-only SDK patch for changed project plans, skip unchanged names, and reject unknown values before the network boundary.
Apply name-only patches by canonical state ID, skip no-op updates, and validate complete SDK responses before returning new Terraform state.
Implement non-force project deletion with explicit state-preserving diagnostics, idempotent coded-not-found handling, and focused status-boundary tests. Document the API's indistinguishable projects-disabled not-found response as a residual provider risk.
Seed imported project state with the exact non-empty canonical ID and an unknown name so the normal Read lifecycle settles durable state.
Translate Terraform create plans into the reviewed project creation core and persist recoverable identity before uncertain diagnostics. Keep registration deferred until the complete lifecycle is wired.
IlyaasK
force-pushed
the
hypeship/extension-data-source-acceptance
branch
from
July 13, 2026 13:35
592f176 to
96fc45a
Compare
IlyaasK
force-pushed
the
hypeship/extension-qualified-import-acceptance
branch
2 times, most recently
from
July 13, 2026 14:32
baff9e7 to
84d2e8f
Compare
Separate recovery guidance for creates with and without recoverable state, and normalize empty SDK errors so Terraform always reports an actionable reason.
Refresh validated durable state, remove only confirmed missing projects, and preserve pre-populated Terraform state on diagnostics or malformed input.
Translate Framework update requests into the tested project update core while preserving prior state on diagnostics and no-op plans.
Decode prior project state, delegate to the non-force delete core, and preserve Terraform ownership by returning diagnostics on malformed state or API failure.
IlyaasK
force-pushed
the
hypeship/extension-qualified-import-acceptance
branch
from
July 13, 2026 15:39
84d2e8f to
e245f76
Compare
Assert that the Framework delete adapter preserves the underlying core error detail, so the test verifies propagation rather than only the presence of an error.
Write exact imported identity with an unknown name and leave API validation to the normal Read lifecycle without requiring a configured client.
IlyaasK
force-pushed
the
hypeship/extension-qualified-import-acceptance
branch
from
July 20, 2026 19:38
e245f76 to
bfed729
Compare
Assemble the reviewed extension lifecycle helpers behind a Terraform Plugin Framework resource, require local archive inputs only for create or replacement, and publish generated schema documentation. This makes the durable extension surface usable while keeping runtime operations out of Terraform.
Add an opt-in Terraform acceptance test that uploads a valid extension archive, verifies stable plans and import, replaces content by checksum, confirms the old object is deleted, and checks final cleanup. Extend the manual acceptance matrix and release guidance so the durable extension resource has an explicit real-API release gate.
Add a Terraform 1.11-compatible extension example that tracks exact archive bytes with filesha256, publish the same snippet and import forms in generated Registry docs, and update the example index. This gives users a validated durable upload workflow without bundling a binary archive.
Prefer the API's authoritative resolved profile ID and ordered extension IDs over echoed selectors, validate their raw response shape before writing Terraform state, and retain only an ID-based compatibility path for older responses. This prevents name selectors from becoming non-canonical durable state.
When Kernel resolves a pool's extension IDs to an empty list, retain Terraform's prior distinction between an omitted attribute and an explicitly empty list. Validate the authoritative response first so malformed data still fails visibly, and cover both convergence paths.
Expose exact browser pool lookup by ID or name with predictable project scoping. Keep the first slice limited to canonical identity, name, and durable size so runtime state cannot enter Terraform.
Read canonical profile and ordered extension IDs from the SDK response, with strict validation and ID-only fallback for legacy echoes. Keep runtime fields outside Terraform state.
Read proxy and launch-mode fields into durable data-source state. Reject explicit null or malformed SDK values and preserve known false booleans through Terraform serialization.
Read start URL, timeout, and fill rate into durable data-source state. Validate SDK response types and ranges while preserving omitted values and known zero.
Read viewport configuration into a typed Terraform object. Reject malformed dimensions and preserve omitted viewport and refresh-rate values without partial state.
Normalize SDK Chrome-policy JSON into stable Terraform string state. Keep loose maps at the response boundary and preserve absent or null policy compatibility.
Add opt-in acceptance coverage for ID and exact-name lookup, durable state flattening, no-drift planning, project overrides, and cleanup. Run it only from the manual acceptance matrix.
Record the missing tagged proxy rename surface and the write-only password/import design required before Terraform can safely manage proxies.
Define the durable deployment lifecycle, partial-state recovery, write-only secret handling, import limits, and the API/SDK contracts required before implementation. Omit deployment force because the API currently forwards but does not consume it.
IlyaasK
force-pushed
the
hypeship/extension-data-source-acceptance
branch
from
July 21, 2026 20:15
e779a03 to
ebe2c13
Compare
IlyaasK
force-pushed
the
hypeship/extension-qualified-import-acceptance
branch
from
July 21, 2026 20:15
482edca to
86b58f3
Compare
IlyaasK
force-pushed
the
hypeship/extension-data-source-acceptance
branch
2 times, most recently
from
July 29, 2026 19:45
d360e8d to
aa323b3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
kernel_extensionimport<project-id>/<extension-id>Why this is v1 work
The qualified import form was implemented and unit-tested but lacked proof against the real Kernel API. This PR closes that narrow v1 release gap without changing provider behavior.
Verification
Before this change, the acceptance matrix explicitly required project-qualified extension import coverage. After the change, the existing extension acceptance package exercises both bare and qualified import paths.
gofmt -l cmd internalgo test -short -timeout=2m ./...go vet ./...go mod verifygo mod tidy -diffterraform fmt -check -recursive examplesbash scripts/check-docs.shbash scripts/check-markdown-links.shgit diff --checkLive acceptance was not run locally because
KERNEL_API_KEYandKERNEL_PROJECT_IDare unavailable. It remains part of the manual v1 release gate.Deferred
Profile, proxy, and app data-source fixture blockers remain separate v1 slices. Runtime/session operations remain intentionally unsupported.
Note
Low Risk
Test and documentation only; no provider or runtime behavior changes.
Overview
Adds live acceptance coverage for
kernel_extensionimport using theproject-id/extension-idform, matching the pattern already used for browser pools. The test creates an extension with explicitproject_id, imports viaImportStateIdFunc, verifies persisted state, and runs a no-drift plan.Updates
docs/acceptance.mdso the v1 matrix lists bare and project-qualified extension import paths and clears the former follow-up item for this resource.Reviewed by Cursor Bugbot for commit 86b58f3. Bugbot is set up for automated code reviews on this repo. Configure here.