Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

fix(crd): AgentRuntime.spec.auth.outbound[].destination.hostRegex should be documented as glob, not regex

Open Beginner friendly
#520 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
65/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Active
Tech stack
go, kubernetes

Research direction

Locate the AgentRuntime CRD type and its hostRegex field documentation, then read authbridge/authlib/routing/router.go and PR #517's warning to confirm the glob syntax. Resolve whether to document hostRegex in place or use the proposed deprecation and rename, then update the affected description and examples so the CRD clearly reflects the supported syntax.

Written by the indexing model from the issue text.

Description

Problem

The AgentRuntime CRD field spec.auth.outbound[].destination.hostRegex is documented as accepting regex patterns, but AuthBridge's routing engine expects glob patterns.

Current CRD documentation:

// HostRegex is a regex pattern to match hostnames.
// Example: ".*\\.team1\\.svc\\.cluster\\.local"

AuthBridge reality:

// authbridge/authlib/routing/router.go
g, err := glob.Compile(r.Host, '.')  // Uses github.com/gobwas/glob, not regexp

Users who follow the CRD documentation and provide regex syntax (e.g., .*\.team1\.svc\.cluster\.local) will get routes that don't match because glob syntax is different from regex.

Impact

  • Silent mismatch: Routes silently fail to match because regex metacharacters are interpreted as literal characters in glob matching
  • Wrong examples: The CRD example shows regex syntax that won't work
  • Confusing field name: hostRegex implies regex when it should be glob

Proposed Solution

Option A: Rename field + deprecate (breaking change)
// HostGlob is a glob pattern to match hostnames.
// Supports * (any chars) and ? (single char).
// Example: "*.team1.svc.cluster.local"
HostGlob string `json:"hostGlob,omitempty"`

// HostRegex is deprecated - use HostGlob instead.
// This field was misnamed; it expects glob syntax, not regex.
// +deprecated
HostRegex string `json:"hostRegex,omitempty"`
Option B: Fix documentation only (non-breaking)
// HostRegex is a glob pattern to match hostnames (name is misleading).
// Supports * (any chars) and ? (single char), NOT regex syntax.
// Example: "*.team1.svc.cluster.local"
HostRegex string `json:"hostRegex,omitempty"`

Workaround

PR #517 added a warning log when hostRegex is used:

mutatorLog.Info("hostRegex field is mapped to AuthBridge glob pattern (not regex)",
    "note", "use glob syntax like '*.team1.svc.cluster.local', not regex")

This helps users discover the issue but doesn't fix the root cause.

Related

  • PR #517 discovered this while implementing routes generation
  • No examples currently use hostRegex (all use exact host matches)
  • AuthBridge glob implementation: https://github.com/gobwas/glob

/cc @alantech

Dominant language
Go
Stars
18
Forks
50
Avg merge
3d 20h
Merged PRs (30d)
6

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from rossoctl/operator

All issues in rossoctl/operator

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.