feat(cel): restore ap./nn. namespace aliases for backward compatibility (#901)
#864 renamed the ap.*/nn.* CEL rule-library helper namespaces to cp.* with no backward-compatible aliases. Since CEL rules are loaded from CRDs at runtime (user-authored detection rules), any pre-existing rule still referencing ap.*/nn.* now fails to compile — and pkg/utils/cel.go silently disables the expression on a compile failure (logs a warning, no error surfaced), so affected rules just stop detecting anything. Register the same 14 ap.* and 6 nn.* helper functions (e.g. ap.was_executed, nn.is_domain_in_egress) alongside the existing cp.* namespace, wired to the exact same Go implementations via a shared funcSpecs table per library, so cp.* and its legacy alias can never drift apart. cel-go requires overload ids to be unique per environment, so the alias registers its own overload ids (ap_*/nn_*) rather than literally reusing cp.*'s FunctionOpt values — only the CEL-facing glue is duplicated, not the detection logic. These aliases are a deliberate transition/deprecation window, not a permanent API; both AP()/NN() and the CEL registration in cel.go are commented accordingly for removal once user rules have migrated to cp.*. Docs-exempt: internal CEL rule-library namespace change; #864 (the PR that introduced the cp.* rename this follows up on) made no docs/ changes either, and no doc in this repo documents the ap./nn./cp. helper namespaces. The change is self-documented via code comments on AP()/NN() and in this PR description. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
M
Matthias Bertschy committed
664ecbc5fcf5ed9ead778ebaff1046c004580725
Parent: 4858928
Committed by GitHub <noreply@github.com>
on 8/18/2026, 10:30:14 AM