Skip to content

Remove native WebDAV blobstore provider - #697

Open
WeiQuan0605 wants to merge 1 commit into
cloudfoundry:developfrom
sap-contributions:remove-webdav-provider
Open

WeiQuan0605 wants to merge 1 commit into
cloudfoundry:developfrom
sap-contributions:remove-webdav-provider

Conversation

@WeiQuan0605

@WeiQuan0605 WeiQuan0605 commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor
  • An explanation of the use cases your change solves:
    • Operators running DAV-backed blobstores can continue using DAV through the storage-cli path (blobstore_type: storage-cli, provider: dav), which is already the path used in cf-deployment. No behaviour change for them.
    • Removal of the blobstore job: operators no longer need to deploy the nginx WebDAV server and blobstore_url_signer sidecar processes — the storage-cli binary handles DAV natively.
    • Dependency reduction: removes packages/nginx_webdav and packages/blobstore_url_signer, shrinking the release footprint and eliminating the Go binary vendored under src/github.com/cloudfoundry/blobstore_url_signer.
    • CI simplification: removes the blobstore_url_signer git resource from the bump-capi-release pipeline job, which was an extra trigger and submodule bump that no longer has anything to track.
  • Links to any other associated PRs:

Migration note

Operators with an explicit blobstore_type: webdav in their CC config must migrate before upgrading:

  1. Change blobstore_type: webdav to blobstore_type: storage-cli with provider: dav
  2. Remove the blobstore job from their deployment

After this change, any deployment still using blobstore_type: webdav will fail at CC boot with:
Unknown blobstore type: "webdav" (see cloud_controller_ng#5480).

Operators using cf-deployment are unaffected — cf-deployment already uses the storage-cli path.

  • I have viewed signed and have submitted the Contributor License Agreement

  • I have made this pull request to the develop branch

  • I have run CF Acceptance Tests on bosh lite

The native WebDAV blobstore (nginx + blobstore_url_signer) is no longer
supported. DAV is still available via blobstore_type: storage-cli with
provider: dav.

Removed:
- jobs/blobstore (nginx_webdav + blobstore_url_signer processes)
- packages/nginx_webdav and packages/blobstore_url_signer
- src/github.com/cloudfoundry/blobstore_url_signer submodule
- webdav_config sections from all job templates (cc_ng, worker, clock,
  cc_deployment_updater, blobstore_benchmark)
- webdav ca_cert.pem templates from cc_ng, cc_deployment_updater, and
  shared_job_templates
- webdav_config properties from cc_ng, worker, clock specs
- blobstore_waiter webdav health check (no-op for storage-cli providers)
- webdav test fixtures in cc_ng and cc_deployment_updater specs
@WeiQuan0605
WeiQuan0605 force-pushed the remove-webdav-provider branch 2 times, most recently from 6bd1b6b to 50d1b58 Compare September 25, 2026 12:13
@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Maybe we need a spec verifying that webdav_config no longer renders in the CC templates?

@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

In config/blobs.yml. nginx/nginx-dav-ext-module-3.0.0.tar.gz and nginx/ngx_http_hmac_secure_link_module-0.3.tar.gz are still listed. Can they be removed?

@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Should we add somewhere a note for operators? A migration note?
Any deployment with an explicit blobstore_type: webdav will:
- at the manifest level: blobstore_type: webdav still renders fine, but
- at CC boot: hit #5480's new raise "Unknown blobstore type: "webdav"" and fail to start.

@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Are the jobs/cloud_controller_ng/templates/blobstore_waiter.sh.erb files and calls of wait_for_blobstore still needed?

Comment on lines 23 to 26
buildpacks_ca_cert.pem.erb: config/certs/buildpacks_ca_cert.pem
droplets_ca_cert.pem.erb: config/certs/droplets_ca_cert.pem
packages_ca_cert.pem.erb: config/certs/packages_ca_cert.pem
resource_pool_ca_cert.pem.erb: config/certs/resource_pool_ca_cert.pem

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

still lists four template mappings which were removed in the other specs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants