KamoCRM

An access policy and its lists are one write, and tenants never see a Kamo service's in-cluster address

FixAIService
Shipped
September 29, 2026 at 12:28 AM UTC
Author
Kamo
Commit
bb4d2e3

SP98 Task 1 A-7 and A-8. - A-7: AccessPolicyWriter saves the policy and replaces its lists in one transaction, retried whole on a Yugabyte conflict (@RetryOnDbConflict outside @Transactional); AccessPolicyLists.replace runs only inside it (MANDATORY). A failure leaves neither, so a retried create makes one policy. Every failure is logged with its route and answered with the generic body; a malformed limit or a missing name is 400 validation_failed. - A-8: a PLATFORM (Provided by Kamo) provider seen through the tenant routes carries baseUrl and effectiveBaseUrl null; the operator console keeps them. The catalog's defaultBaseUrl is null for Kamo-only types unless the caller holds MANAGE_AI_PLATFORM_SERVICES.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing