Objectives & prerequisites
Learning objectives
- Take the Crossplane XR the hand-off lab produced and drive it through the four outer-loop stages against live infrastructure.
- Identify the environment repository (not the Sandcastle) as the source of truth for the merged XR, and recognise merge as a policy transition rather than a script step.
- Attach the three outer-loop guardrails — automated verification on the PR, review on the PR, and policy at cluster admission — to concrete surfaces on GitHub and (optionally) on the cluster.
- Reconcile the merged XR onto the cluster via GitOps (Flux) or an equivalent single-shot pull (
kubectl), and confirm that Crossplane closes the loop by composing the same KubernetesJobthe Hello Pico on Kubernetes lab already verifies in isolation.
Prerequisites
Completion of the Sandcastle → Kubernetes hand-off lab — you need
work/handoff-sandcastle-to-kubernetes/build/xr.yaml. If it is missing, this lab’sverify.shwill run the hand-off (and the Sandcastle lab that feeds it) for you.A learner-controlled GitHub environment repository. A private repo dedicated to this lab is recommended. Create one with:
gh repo create your-handle/oe-env-hello-world-pico \ --private --add-readmeExport it once per shell:
export OE_ENV_REPO=your-handle/oe-env-hello-world-picoghCLI authenticated (gh auth login) with permission to push, open PRs, and merge on that repo.Stages 3–4 only: a Crossplane cluster set up per the Hello Pico on Kubernetes walkthrough steps 1–4, plus either the
fluxCLI (preferred) orkubectlpointed at that cluster. Without a cluster the lab is still runnable through stages 1–2;verify.shprints a NOTE and exits cleanly.
Honest hosted dependencies
- GitHub is a real hosted dependency. Every stage 1–2 command in this lab creates real branches, real PRs, and real merge commits on the repository you point
OE_ENV_REPOat. Use a dedicated, learner-owned repo — do not point this at a shared production environment repo. - The GitHub token in your
ghCLI session is the only credential the lab uses; the lab writes no secrets to disk and passes no tokens as command-line arguments. - Flux and
kubectlare operator-controlled tools. If you use Flux mode, Flux is installed on your cluster the usual way (flux installorflux bootstrap); this lab does not bootstrap Flux for you.
Environment
Supported OS: macOS (Apple Silicon or Intel), Linux, or WSL.
Required shell:
bash3.2+ orzsh5.0+.Required tools:
git,python3, and standard POSIX utilities.gh(GitHub CLI) — real GitHub API access.- Stages 3–4:
kubectl; optionallyflux.
Estimated time: 30–60 minutes, depending on whether you also run the cluster stages.
Cleanup step (also repeated at the end of the walkthrough):
rm -rf work/outer-delivery-loop # optional: remove the feature branch and Flux resources gh api "repos/$OE_ENV_REPO/git/refs/heads/$(cat work/outer-delivery-loop/state/branch.txt 2>/dev/null)" \ -X DELETE || true kubectl delete kustomization oe-env-hello-world-pico -n flux-system 2>/dev/null || true kubectl delete gitrepository oe-env-hello-world-pico -n flux-system 2>/dev/null || true
Install commands
On macOS with Homebrew:
brew install git python3 gh
# Optional (stages 3–4):
brew install kubernetes-cli fluxcd/tap/fluxOn Linux, use your distribution’s package manager, and follow the GitHub CLI and Flux upstream instructions. Confirm each tool resolves and gh is authenticated:
command -v gh && gh --version
gh auth status
command -v kubectl && kubectl version --client=true --short 2>/dev/null || true
command -v flux && flux --version 2>/dev/null || true