From 8f1669133ae34d0180f1af33060d783be3ea5b6b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20ROBERT?= Date: Fri, 25 Sep 2026 08:42:18 +0200 Subject: [PATCH] chore(scaleway): the metadata API's five operations moved to their context variants MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The nightly drift scan has been red since 2026-09-24, and both halves of its message are the same event: 5 new upstream operation(s), none triaged 5 route(s) reference an operation that no longer exists upstream Scaleway added a `WithContext` variant of each MetadataAPI call and turned the bare one into a deprecated wrapper: // Deprecated: use GetMetadataWithContext instead //go:fix inline func (meta *MetadataAPI) GetMetadata() (m *Metadata, err error) { ctx, cancel := context.WithTimeout(context.Background(), metadataTimeout) defer cancel() return meta.GetMetadataWithContext(ctx) } So the endpoints did not move; the names did. The scan stopped counting the old spellings and it is right to: a method that composes an exported one adds no endpoint, which is the rule already keeping WaitForServer and ServerActionAndWait out of the surface. The refusal is retargeted rather than extended. Listing both spellings was the first attempt and `drift:update` refused it in one line — `orphan routes (no upstream match)` on the five old names — which is the report's own alarm for a refusal naming something upstream no longer has. The reason itself is unchanged and still true: the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials. Serving it would mean an HTTP listener inside every emulated machine, and user data reaches the guest through the runtime instead. `mise run drift:check` green, `mise run prepush` green. Assisted-by: Claude Code (claude-opus-5) --- coverage/scaleway-coverage.json | 10 +++++----- internal/providers/scaleway/pack.go | 22 +++++++++++++++++----- 2 files changed, 22 insertions(+), 10 deletions(-) diff --git a/coverage/scaleway-coverage.json b/coverage/scaleway-coverage.json index 8eb14a8..0f7858d 100644 --- a/coverage/scaleway-coverage.json +++ b/coverage/scaleway-coverage.json @@ -1818,35 +1818,35 @@ "status": "implemented" }, { - "operation": "instance/v1/MetadataAPI.DeleteUserData", + "operation": "instance/v1/MetadataAPI.DeleteUserDataWithContext", "product": "instance", "reason": "the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials", "version": "v1", "status": "declined" }, { - "operation": "instance/v1/MetadataAPI.GetMetadata", + "operation": "instance/v1/MetadataAPI.GetMetadataWithContext", "product": "instance", "reason": "the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials", "version": "v1", "status": "declined" }, { - "operation": "instance/v1/MetadataAPI.GetUserData", + "operation": "instance/v1/MetadataAPI.GetUserDataWithContext", "product": "instance", "reason": "the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials", "version": "v1", "status": "declined" }, { - "operation": "instance/v1/MetadataAPI.ListUserData", + "operation": "instance/v1/MetadataAPI.ListUserDataWithContext", "product": "instance", "reason": "the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials", "version": "v1", "status": "declined" }, { - "operation": "instance/v1/MetadataAPI.SetUserData", + "operation": "instance/v1/MetadataAPI.SetUserDataWithContext", "product": "instance", "reason": "the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials", "version": "v1", diff --git a/internal/providers/scaleway/pack.go b/internal/providers/scaleway/pack.go index 031ea24..8af9a24 100644 --- a/internal/providers/scaleway/pack.go +++ b/internal/providers/scaleway/pack.go @@ -873,12 +873,24 @@ func (p *Pack) Declined() []emulator.Decline { // and serving it would mean an HTTP listener inside every emulated // machine. User data reaches the guest through the runtime instead, // which is what cloud-init reads. + // + // The names moved on 2026-09-2x and the endpoints did not. Scaleway added a + // `WithContext` variant of each and turned the bare one into a deprecated + // wrapper — `GetMetadata()` is now `GetMetadataWithContext(ctx)` with a + // timeout around it, carrying a `//go:fix inline` directive. + // + // So the scan stopped counting the old spellings, and it is right to: a + // method that composes an exported one adds no endpoint, which is the rule + // that already keeps WaitForServer and ServerActionAndWait out. The five + // listed here are the ones that build a request today. Keeping the old + // names beside them would leave five orphan routes — a refusal naming + // something upstream no longer has, which is the drift report's own alarm. emulator.Because("the metadata service answers on the link-local address 169.254.42.42, from inside the machine, to a caller that carries no credentials", - "instance/v1/MetadataAPI.GetMetadata", - "instance/v1/MetadataAPI.GetUserData", - "instance/v1/MetadataAPI.ListUserData", - "instance/v1/MetadataAPI.SetUserData", - "instance/v1/MetadataAPI.DeleteUserData"), + "instance/v1/MetadataAPI.GetMetadataWithContext", + "instance/v1/MetadataAPI.GetUserDataWithContext", + "instance/v1/MetadataAPI.ListUserDataWithContext", + "instance/v1/MetadataAPI.SetUserDataWithContext", + "instance/v1/MetadataAPI.DeleteUserDataWithContext"), // IAM, everything except the SSH keys the pack serves. //