Skip to content

fix(helm): add seccompProfile to podSecurityContext + fix node-deployment image helper (Round 26 audit) - #474

Merged
lusoris merged 2 commits into
masterfrom
fix/helm-seccomp-and-node-image
May 31, 2026
Merged

lusoris merged 2 commits into
masterfrom
fix/helm-seccomp-and-node-image

Conversation

@lusoris

@lusoris lusoris commented May 31, 2026 •

Copy link
Copy Markdown
Contributor

Fix Round 26 audit B.1 + B.3 in deploy/helm/vmafx/.

B.1 — podSecurityContext missing seccompProfile: values.yaml:217-221 only had runAsNonRoot/runAsUser/runAsGroup/fsGroup. Pod Security Standards "restricted" admission REJECTS pods without seccompProfile.type: RuntimeDefault. All 4 workload templates (deployment.yaml, job.yaml, statefulset.yaml, node-deployment.yaml) import this block verbatim, so all deployments fail on restricted namespaces. Fix: add seccompProfile: { type: RuntimeDefault } to values.yaml.

B.3 — node-deployment.yaml broken image ref: Line 65 inline-rendered {{ .Values.node.image.repository }}:{{ .Values.node.image.tag | default .Chart.AppVersion }} bypassed the vmafx.nodeImage helper at _helpers.tpl:145. With default empty node.image.repository, rendered image was :3.0.0 → ImagePullBackOff: invalid reference format. Fix: use {{ include "vmafx.nodeImage" . }}.

helm lint --strict PASS. helm template shows seccompProfile on every workload + valid node image ref with default values.

no state delta: helm chart fixes per CLAUDE.md §12 r8; no bug tracker entry; PSS admission failure is environment-dependent.

ADR-0108 deliverables checklist

🤖 Generated with Claude Code

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 08:20
@lusoris
lusoris enabled auto-merge (squash) May 31, 2026 08:20
@lusoris
lusoris marked this pull request as draft May 31, 2026 09:01
auto-merge was automatically disabled May 31, 2026 09:01

Pull request was converted to draft

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 11:52
@lusoris
lusoris force-pushed the fix/helm-seccomp-and-node-image branch from 67b8b58 to 711dc95 Compare May 31, 2026 11:52
@lusoris
lusoris merged commit 7a0a078 into master May 31, 2026
54 of 57 checks passed
@lusoris
lusoris deleted the fix/helm-seccomp-and-node-image branch May 31, 2026 11:53
lusoris added a commit that referenced this pull request May 31, 2026
…nel (round-25 audit)

Round 25 audit B.3 + B.4 fixes for the vmafx-controller. Re-applied
cleanly on top of current master (PR #468 SetGetUnlockedHookForTest
+ PR #474 helm seccomp) after a previous quick-rebase left conflict
markers in cmd/vmafx-controller/queue/queue.go and the AGENTS.md
sidecar.

B.3 — controllerServer.StreamJobs snapshot:
  * queue.Queue interface gains ListAll(ctx, statuses) ([]*Job, error).
  * SQLiteQueue implements it with a status-IN filter (parameterised,
    bounded to the 5-element Status enum) and per-row copy semantics.
  * grpc_server.go StreamJobs sends a single snapshot via ListAll,
    converting Job.Status with protoStatusToQueue/queueStatusToProto
    helpers kept in lockstep.

B.4 — reaper goroutine stop signal:
  * nodes.NewRegistry(ctx, log) signature now takes a required context.
  * reaper goroutine selects on ctx.Done() + ticker.C and exits when
    the controller's shutdown context is cancelled.
  * registry gains Close() which cancels its own derived context.
  * main.go wires NewShutdownContext()'s context into NewRegistry and
    defers nodeRegistry.Close() after jobQueue.Close().

Tests, ADR, research digest, changelog fragment, AGENTS.md sidecar,
rebase-notes entry, ADR index update — all in this PR.

ADR-0962. Research: docs/research/0962-controller-streamjobs-reaper-fixes-2026-05-31.md.

Conflict resolution notes:
  * cmd/vmafx-controller/queue/queue.go — both #468's
    SetGetUnlockedHookForTest and #472's ListAll/repeatCommaQ kept,
    with the missing closing brace for SetGetUnlockedHookForTest
    restored (previous botched rebase had sed-stripped the marker
    and left a syntax error).
  * cmd/vmafx-controller/AGENTS.md — kept both halves additively:
    governance/queue invariants from master plus rebase-sensitive
    invariants from this PR, with ADR-0962 added to the Governing
    ADRs table and entries split across the queue / nodes / grpc
    server / main sections.
  * docs/adr/README.md, docs/adr/_index_fragments/_order.txt,
    docs/rebase-notes.md — additive (both halves preserved).
lusoris added a commit that referenced this pull request May 31, 2026
…26 B.4) (#485)

Replace hardcoded pod-level securityContext block (runAsNonRoot,
runAsUser/Group/fsGroup) in operator-deployment.yaml with the standard
values-driven pattern used by deployment.yaml and job.yaml:

  securityContext:
    {{- toYaml .Values.podSecurityContext | nindent 8 }}

This ensures the operator workload inherits seccompProfile: RuntimeDefault
(added in PR #474) and any future policy changes via .Values.podSecurityContext
without a separate template edit — consistent with all other workload templates.

Round 26 audit item B.4.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant