Skip to content

feat(helm): NetworkPolicy default-deny + Pod Security Standards "restricted" baseline (ADR-0930) - #439

Merged
lusoris merged 1 commit into
masterfrom
chore/helm-networkpolicy-pss
Jun 3, 2026
Merged

lusoris merged 1 commit into
masterfrom
chore/helm-networkpolicy-pss

Conversation

@lusoris

@lusoris lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor

Summary

Updates deploy/helm/vmafx/ so the chart's default render satisfies the
Kubernetes pod-security.kubernetes.io/enforce=restricted admission profile
out of the box, and adds an opt-in NetworkPolicy bundle for clusters with a
NetworkPolicy-aware CNI.

  • Aligns UID/GID to the distroless nonroot baked into every production image (65532, ADR-0878), eliminates pod/container drift on runAsNonRoot + seccomp, and refactors operator-deployment.yaml and tests/test-connection.yaml to inherit security blocks from .Values.
  • Ships templates/networkpolicy.yaml with a default-deny baseline plus narrow allow-rules (controller -> node gRPC, node -> object store HTTPS, operator -> apiserver, DNS, in-namespace HTTP ingress), all gated by networkPolicy.enabled=false so existing installs are unaffected.
  • Surfaces the PSA namespace-labelling command in NOTES.txt and documents the full NetworkPolicy matrix in docs/development/k8s-deployment.md.

Type

  • feat — new feature (NetworkPolicy template + values block)
  • chore / build — Helm template hardening

Checklist

  • Commits follow Conventional Commits (feat(helm): prefix; commit-msg hook passed).
  • helm lint deploy/helm/vmafx --strict green; helm template ... | kubectl create --dry-run=client accepts every emitted resource.
  • No SIMD/GPU code path touched.
  • No new .c / .cpp / .cu / .h / .hpp files.
  • No breaking change at the libvmaf level. Helm values podSecurityContext.runAsUser flips from 65534 to 65532; release note + ADR call out the migration.
  • ADR row lives in docs/adr/_index_fragments/0930-helm-networkpolicy-pss.md and the slug is appended to _order.txt; docs/adr/README.md regenerated via scripts/docs/concat-adr-index.sh --write.

Bug-status hygiene (ADR-0165)

  • docs/state.md updated — row T-HELM-NETWORKPOLICY-PSS-2026-05-31 added under ## Recently closed.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.

Deep-dive deliverables (ADR-0108)

  • Research digest — docs/research/0930-helm-networkpolicy-pss.md (before/after surface inventory, PSA restricted requirement table, NetworkPolicy matrix, validation evidence).
  • Decision matrix — ## Alternatives considered in docs/adr/0930-helm-networkpolicy-pss.md (6 alternatives weighed: NP default-on, BYO CNI policy, UID 65534, inline security blocks, PSP, seccompProfile.type=Localhost).
  • AGENTS.md invariant note — no rebase-sensitive invariants: deploy/helm/vmafx/ is a fork-local directory (Netflix upstream ships no Helm chart) and deploy/ has no AGENTS.md. Touched files: chart templates + values + fork-local docs only.
  • Reproducer / smoke-test command — pasted below under "Reproducer".
  • CHANGELOG fragment — changelog.d/added/helm-networkpolicy-pss.md.
  • Rebase note — entry ADR-0930 — Helm NetworkPolicy + PSS baseline — 2026-05-31 added to docs/rebase-notes.md (no rebase impact: REASON — fork-local chart, fork-local docs only).

Reproducer

# Default render — no NetworkPolicy resources, pods pass PSA `restricted`.
helm lint deploy/helm/vmafx --strict

# Full render with operator + node + NetworkPolicy enabled —
# 8 NetworkPolicy resources + every workload kind validates clean.
helm template deploy/helm/vmafx \
  --set networkPolicy.enabled=true \
  --set operator.enabled=true \
  --set node.enabled=true \
  --set node.image.repository=ghcr.io/vmafx/vmafx-node \
  | kubectl create --dry-run=client --validate=false -f -

# Expected: 8 networkpolicy.networking.k8s.io/... created (dry run)
#   release-name-vmafx-default-deny
#   release-name-vmafx-operator-default-deny
#   release-name-vmafx-node-default-deny
#   release-name-vmafx-allow-http-ingress
#   release-name-vmafx-allow-controller-to-node
#   release-name-vmafx-allow-node-egress-object-store
#   release-name-vmafx-allow-operator-to-apiserver
#   release-name-vmafx-allow-dns-egress

# Verify no NetworkPolicies render by default:
helm template deploy/helm/vmafx | grep -c NetworkPolicy  # -> 0

ADR

Migration

Installs that hard-coded --set podSecurityContext.runAsUser=65534 should
drop the override or flip it to 65532 to keep file ownership consistent
with the distroless nonroot baked into every production image since
ADR-0878. No other override surface changes.

Known follow-ups

  • When a dedicated vmafx-controller Service ships, retarget the
    controller-to-node allow-rule from "any pod in namespace" to
    component=controller.
  • Track Kubernetes appArmorProfile (1.31+) for per-backend AppArmor.
  • Tighten nodeEgressObjectStore.cidrs in the production values overlay
    once a VPC topology guide ships.

🤖 Generated with Claude Code

@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by master after the 117-PR merge marathon of 2026-05-31. Diff-extract produced empty rebase (AHEAD=0), indicating intended content already landed via sibling merges.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the chore/helm-networkpolicy-pss branch May 31, 2026 13:14
@lusoris
lusoris restored the chore/helm-networkpolicy-pss branch May 31, 2026 18:38
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:48
lusoris added a commit that referenced this pull request Jun 3, 2026
#184/#439

Four ADR numbers referenced in open DRAFT PR bodies had no backing .md
files on disk, violating CLAUDE.md rule 8 (ADR before implementation).

- ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint
  program + cilium/ebpf Go loader; 37× warm-cache clip-open latency
  improvement; opt-in via VMAFX_EBPF_BYPASS=1.
- ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl,
  five test cases covering the full operator/node/trainer stack.
- ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and
  vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12,
  uid 65532, amd64+arm64, cosign + syft SBOM.
- ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted"
  baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment.

Also adds four index rows to docs/adr/README.md.

Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any
open PRs; flagged in the PR description for maintainer awareness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
#184/#439

Four ADR numbers referenced in open DRAFT PR bodies had no backing .md
files on disk, violating CLAUDE.md rule 8 (ADR before implementation).

- ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint
  program + cilium/ebpf Go loader; 37× warm-cache clip-open latency
  improvement; opt-in via VMAFX_EBPF_BYPASS=1.
- ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl,
  five test cases covering the full operator/node/trainer stack.
- ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and
  vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12,
  uid 65532, amd64+arm64, cosign + syft SBOM.
- ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted"
  baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment.

Also adds four index rows to docs/adr/README.md.

Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any
open PRs; flagged in the PR description for maintainer awareness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
#184/#439 (#535)

Four ADR numbers referenced in open DRAFT PR bodies had no backing .md
files on disk, violating CLAUDE.md rule 8 (ADR before implementation).

- ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint
  program + cilium/ebpf Go loader; 37× warm-cache clip-open latency
  improvement; opt-in via VMAFX_EBPF_BYPASS=1.
- ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl,
  five test cases covering the full operator/node/trainer stack.
- ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and
  vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12,
  uid 65532, amd64+arm64, cosign + syft SBOM.
- ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted"
  baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment.

Also adds four index rows to docs/adr/README.md.

Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any
open PRs; flagged in the PR description for maintainer awareness.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the chore/helm-networkpolicy-pss branch from ad9d417 to cb78188 Compare June 3, 2026 13:28
@lusoris
lusoris marked this pull request as ready for review June 3, 2026 13:28
Copilot AI review requested due to automatic review settings June 3, 2026 13:28
…ricted" baseline (ADR-0930)

Updates `deploy/helm/vmafx/` so the chart's default render satisfies the
Kubernetes `pod-security.kubernetes.io/enforce=restricted` admission profile
out of the box, and adds an opt-in NetworkPolicy bundle for clusters with
a NetworkPolicy-aware CNI.

Pod Security Standards:
- UID/GID `65532` everywhere (matches distroless `nonroot` baked into
  every production image by ADR-0878 / PR #367), replacing the drifted
  `65534` value.
- Container `securityContext` now sets `runAsNonRoot=true` /
  `runAsUser=65532` in addition to the pod-level setting (PSA
  `restricted` checks both scopes).
- `seccompProfile.type=RuntimeDefault` added at both pod and container
  scope.
- `operator-deployment.yaml` and `tests/test-connection.yaml` refactored
  to inherit `podSecurityContext` / `securityContext` from `.Values`
  instead of hard-coding their own blocks.

NetworkPolicy (opt-in via `--set networkPolicy.enabled=true`):
- New `templates/networkpolicy.yaml` emits a default-deny ingress +
  egress baseline (per workload component) plus narrow allow-rules.

ADR-0930, Research-0930 filed. Rebase-notes entry added. State.md row added.
Changelog fragment under `added/`.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the chore/helm-networkpolicy-pss branch from cb78188 to ca1ae82 Compare June 3, 2026 13:32
@lusoris
lusoris merged commit 129b5bb into master Jun 3, 2026
24 of 59 checks passed
@lusoris
lusoris deleted the chore/helm-networkpolicy-pss branch June 3, 2026 13:32
@lusoris
lusoris removed the request for review from Copilot June 3, 2026 13:49
lusoris added a commit that referenced this pull request Jun 7, 2026
…89 stub (#841)

- docs/state.md: moved T-CUDA-MOTION-SAD-BATCH-PENDING-2026-05-29 from
  Open to Recently Closed; PR #217 merged 2026-06-03 (ADR-0845). Row for
  T-PIC-PREALLOC-RECURRING-FAILURE and T-SYCL-MOTION-ADD-UV-SIGSEGV were
  already present in Recently Closed; no further action required for those.
- changelog.d/changed/hw-backend-audit.md: corrected PR reference from
  #733 to #733.
- changelog.d/fixed/restore-vkpipelinecache-pr867.md: deleted; referenced
  PR #1067 which does not exist on VMAFx/vmafx (confirmed via gh).
- changelog.d/added/vmafx-server-go.md: removed line referencing nonexistent
  PR #1583 (confirmed via gh); remainder of fragment kept intact.
- changelog.d/changed/0573-dev-container-ubuntu-26-04-cuda-13-2.md:
  replaced "Closes PR #1330" (nonexistent PR, confirmed via gh) with a
  neutral past-tense statement.
- docs/rebase-notes.md: updated DEFAULT_FALLBACKS invariant to reflect
  ADR-0726 Vulkan removal — tuple is now ("cuda","sycl","hip","cpu").
  Replaced `libvmaf` with `core` in DNN multi-output smoke command (ADR-0700
  rename). Converted three forward-looking archival claims to past tense:
  PR #351/#374 "in-flight" references, PR #379 "if round-2 not yet merged",
  PR #439 "will rebase cleanly" — all three PRs have since merged.
- docs/adr/0789-rust-crate-audit.md.stub: deleted; 9-day-old reservation
  expired without producing a full ADR file.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant