Repository navigation
feat(helm): NetworkPolicy default-deny + Pod Security Standards "restricted" baseline (ADR-0930) - #439
Merged
Conversation
5 of 6 tasks
lusoris
marked this pull request as ready for review
May 31, 2026 12:31
Contributor
Author
|
Superseded by master after the 117-PR merge marathon of 2026-05-31. Diff-extract produced empty rebase (AHEAD=0), indicating intended content already landed via sibling merges. |
lusoris
marked this pull request as draft
May 31, 2026 18:48
3 of 6 tasks
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
#184/#439 Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
#184/#439 Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
#184/#439 (#535) Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
force-pushed
the
chore/helm-networkpolicy-pss
branch
from
June 3, 2026 13:28
ad9d417 to
cb78188
Compare
lusoris
marked this pull request as ready for review
June 3, 2026 13:28
…ricted" baseline (ADR-0930) Updates `deploy/helm/vmafx/` so the chart's default render satisfies the Kubernetes `pod-security.kubernetes.io/enforce=restricted` admission profile out of the box, and adds an opt-in NetworkPolicy bundle for clusters with a NetworkPolicy-aware CNI. Pod Security Standards: - UID/GID `65532` everywhere (matches distroless `nonroot` baked into every production image by ADR-0878 / PR #367), replacing the drifted `65534` value. - Container `securityContext` now sets `runAsNonRoot=true` / `runAsUser=65532` in addition to the pod-level setting (PSA `restricted` checks both scopes). - `seccompProfile.type=RuntimeDefault` added at both pod and container scope. - `operator-deployment.yaml` and `tests/test-connection.yaml` refactored to inherit `podSecurityContext` / `securityContext` from `.Values` instead of hard-coding their own blocks. NetworkPolicy (opt-in via `--set networkPolicy.enabled=true`): - New `templates/networkpolicy.yaml` emits a default-deny ingress + egress baseline (per workload component) plus narrow allow-rules. ADR-0930, Research-0930 filed. Rebase-notes entry added. State.md row added. Changelog fragment under `added/`. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
force-pushed
the
chore/helm-networkpolicy-pss
branch
from
June 3, 2026 13:32
cb78188 to
ca1ae82
Compare
9 tasks done
lusoris
added a commit
that referenced
this pull request
Jun 7, 2026
…89 stub (#841) - docs/state.md: moved T-CUDA-MOTION-SAD-BATCH-PENDING-2026-05-29 from Open to Recently Closed; PR #217 merged 2026-06-03 (ADR-0845). Row for T-PIC-PREALLOC-RECURRING-FAILURE and T-SYCL-MOTION-ADD-UV-SIGSEGV were already present in Recently Closed; no further action required for those. - changelog.d/changed/hw-backend-audit.md: corrected PR reference from #733 to #733. - changelog.d/fixed/restore-vkpipelinecache-pr867.md: deleted; referenced PR #1067 which does not exist on VMAFx/vmafx (confirmed via gh). - changelog.d/added/vmafx-server-go.md: removed line referencing nonexistent PR #1583 (confirmed via gh); remainder of fragment kept intact. - changelog.d/changed/0573-dev-container-ubuntu-26-04-cuda-13-2.md: replaced "Closes PR #1330" (nonexistent PR, confirmed via gh) with a neutral past-tense statement. - docs/rebase-notes.md: updated DEFAULT_FALLBACKS invariant to reflect ADR-0726 Vulkan removal — tuple is now ("cuda","sycl","hip","cpu"). Replaced `libvmaf` with `core` in DNN multi-output smoke command (ADR-0700 rename). Converted three forward-looking archival claims to past tense: PR #351/#374 "in-flight" references, PR #379 "if round-2 not yet merged", PR #439 "will rebase cleanly" — all three PRs have since merged. - docs/adr/0789-rust-crate-audit.md.stub: deleted; 9-day-old reservation expired without producing a full ADR file. Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Updates
deploy/helm/vmafx/so the chart's default render satisfies theKubernetes
pod-security.kubernetes.io/enforce=restrictedadmission profileout of the box, and adds an opt-in NetworkPolicy bundle for clusters with a
NetworkPolicy-aware CNI.
nonrootbaked into every production image (65532, ADR-0878), eliminates pod/container drift onrunAsNonRoot+ seccomp, and refactorsoperator-deployment.yamlandtests/test-connection.yamlto inherit security blocks from.Values.templates/networkpolicy.yamlwith a default-deny baseline plus narrow allow-rules (controller -> node gRPC, node -> object store HTTPS, operator -> apiserver, DNS, in-namespace HTTP ingress), all gated bynetworkPolicy.enabled=falseso existing installs are unaffected.NOTES.txtand documents the full NetworkPolicy matrix indocs/development/k8s-deployment.md.Type
feat— new feature (NetworkPolicy template + values block)chore/build— Helm template hardeningChecklist
feat(helm):prefix; commit-msg hook passed).helm lint deploy/helm/vmafx --strictgreen;helm template ... | kubectl create --dry-run=clientaccepts every emitted resource..c/.cpp/.cu/.h/.hppfiles.podSecurityContext.runAsUserflips from65534to65532; release note + ADR call out the migration.docs/adr/_index_fragments/0930-helm-networkpolicy-pss.mdand the slug is appended to_order.txt;docs/adr/README.mdregenerated viascripts/docs/concat-adr-index.sh --write.Bug-status hygiene (ADR-0165)
docs/state.mdupdated — rowT-HELM-NETWORKPOLICY-PSS-2026-05-31added under## Recently closed.Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Deep-dive deliverables (ADR-0108)
docs/research/0930-helm-networkpolicy-pss.md(before/after surface inventory, PSArestrictedrequirement table, NetworkPolicy matrix, validation evidence).## Alternatives consideredindocs/adr/0930-helm-networkpolicy-pss.md(6 alternatives weighed: NP default-on, BYO CNI policy, UID 65534, inline security blocks, PSP,seccompProfile.type=Localhost).AGENTS.mdinvariant note — no rebase-sensitive invariants:deploy/helm/vmafx/is a fork-local directory (Netflix upstream ships no Helm chart) anddeploy/has noAGENTS.md. Touched files: chart templates + values + fork-local docs only.changelog.d/added/helm-networkpolicy-pss.md.ADR-0930 — Helm NetworkPolicy + PSS baseline — 2026-05-31added todocs/rebase-notes.md(no rebase impact: REASON— fork-local chart, fork-local docs only).Reproducer
ADR
nonrootUID 65532)Migration
Installs that hard-coded
--set podSecurityContext.runAsUser=65534shoulddrop the override or flip it to
65532to keep file ownership consistentwith the distroless
nonrootbaked into every production image sinceADR-0878. No other override surface changes.
Known follow-ups
vmafx-controllerService ships, retarget thecontroller-to-nodeallow-rule from "any pod in namespace" tocomponent=controller.appArmorProfile(1.31+) for per-backend AppArmor.nodeEgressObjectStore.cidrsin the production values overlayonce a VPC topology guide ships.
🤖 Generated with Claude Code