Relationships
#2642 Codegen/Hetzner: create-only required fields block list/get/delete in generated Hetzner models
Opened by stack72 · 9/28/2026· Shipped 9/29/2026
Follow-up to swamp-club #2287, which fixed this for GCP in PR 341 (codegen/gcp/pipeline.ts nonCreatePathParams, and the create/update templates in codegen/gcp/extensionModelGenerator.ts).
swamp validates the whole GlobalArgsSchema whenever any global argument is set. This generator emits fields that only the create request needs as required there, so read-only methods fail unless callers pass placeholder create values.
Apply the same rule as #2287:
- Keep required only what a non-create method reads from globalArgs, plus synthetic instance names.
- Make create-only required fields optional in GlobalArgsSchema.
- Enforce them with a generated check at the start of create that throws create requires global arguments: before any API call.
- Where update fully replaces the resource (PUT), fill those fields from globalArgs, then from stored state, and throw before the API call if neither has them.
- Regenerate the provider twice (the second run must produce zero diff) and update the provider's design doc.
Required-ness is decided in buildGlobalArgsProperties in codegen/hetzner/extensionModelGenerator.ts, from the POST body required list built in codegen/hetzner/pipeline.ts (postRequired).
Example: model/hetzner-cloud servers requires name, server_type and image, but get, delete and list read only the token (plus name for the instance key).
Notes:
- The synthetic name stays required.
- The nested-object requiredSet path is unrelated and stays as is.
- The test in codegen/hetzner/extensionModelGenerator_test.ts that asserts create-required args stay required must be reversed.
- codegen/designs/hetzner.md (around lines 606-612) wrongly says swamp does not enforce required global arguments. It only skips validation when no global arguments are set at all.
Shipped
Click a lifecycle step above to view its details.
stack72 commented 9/28/2026, 11:09:30 PM
Correction to the premise, found while fixing the Cloudflare sibling (#2645): swamp does not validate the whole GlobalArgsSchema on every method run. Method runs (direct and workflow steps) validate global args with .partial(). The full check happens in two places, and both are real failures: swamp model create with any --global-arg (libswamp/models/create.ts), and swamp workflow validate for steps that name a model type rather than a definition (libswamp/workflows/validate.ts adds every required global to the step). Reproduced on Cloudflare alerting/policies: model create with only account_id failed, and a type-based get step failed validate; get on an existing definition worked. The fix is the same, but verify against those two paths.
For the PUT fallback, #2645 deliberately deviates from #2287: unset create-required fields are filled from a GET of the live resource, not from stored state. Stored state is only what swamp last saw, so filling from it silently reverts changes made outside swamp since the last get/sync. The GET is skipped when global args set every such field, and update throws before the PUT if the live resource lacks one. Recommend the same here. Separately, #2656 tracks PUT updates clearing optional fields that global args leave unset.
Sign in to post a ripple.