SIGN IN SIGN UP

feat(cel): restore ap./nn. namespace aliases for backward compatibility (#901)

#864 renamed the ap.*/nn.* CEL rule-library helper namespaces to cp.* with
no backward-compatible aliases. Since CEL rules are loaded from CRDs at
runtime (user-authored detection rules), any pre-existing rule still
referencing ap.*/nn.* now fails to compile — and pkg/utils/cel.go silently
disables the expression on a compile failure (logs a warning, no error
surfaced), so affected rules just stop detecting anything.

Register the same 14 ap.* and 6 nn.* helper functions (e.g. ap.was_executed,
nn.is_domain_in_egress) alongside the existing cp.* namespace, wired to the
exact same Go implementations via a shared funcSpecs table per library, so
cp.* and its legacy alias can never drift apart. cel-go requires overload
ids to be unique per environment, so the alias registers its own overload
ids (ap_*/nn_*) rather than literally reusing cp.*'s FunctionOpt values —
only the CEL-facing glue is duplicated, not the detection logic.

These aliases are a deliberate transition/deprecation window, not a
permanent API; both AP()/NN() and the CEL registration in cel.go are
commented accordingly for removal once user rules have migrated to cp.*.



Docs-exempt: internal CEL rule-library namespace change; #864 (the PR that
introduced the cp.* rename this follows up on) made no docs/ changes either,
and no doc in this repo documents the ap./nn./cp. helper namespaces. The
change is self-documented via code comments on AP()/NN() and in this PR
description.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
M
Matthias Bertschy committed
664ecbc5fcf5ed9ead778ebaff1046c004580725
Parent: 4858928
Committed by GitHub <noreply@github.com> on 8/18/2026, 10:30:14 AM