Repository navigation
fix(helm): add seccompProfile to podSecurityContext + fix node-deployment image helper (Round 26 audit) - #474
Merged
Merged
Conversation
lusoris
marked this pull request as ready for review
May 31, 2026 08:20
lusoris
enabled auto-merge (squash)
May 31, 2026 08:20
lusoris
marked this pull request as draft
May 31, 2026 09:01
auto-merge was automatically disabled
May 31, 2026 09:01
Pull request was converted to draft
lusoris
marked this pull request as ready for review
May 31, 2026 11:52
…ment image helper (round-26 audit)
lusoris
force-pushed
the
fix/helm-seccomp-and-node-image
branch
from
May 31, 2026 11:52
67b8b58 to
711dc95
Compare
lusoris
added a commit
that referenced
this pull request
May 31, 2026
…nel (round-25 audit) Round 25 audit B.3 + B.4 fixes for the vmafx-controller. Re-applied cleanly on top of current master (PR #468 SetGetUnlockedHookForTest + PR #474 helm seccomp) after a previous quick-rebase left conflict markers in cmd/vmafx-controller/queue/queue.go and the AGENTS.md sidecar. B.3 — controllerServer.StreamJobs snapshot: * queue.Queue interface gains ListAll(ctx, statuses) ([]*Job, error). * SQLiteQueue implements it with a status-IN filter (parameterised, bounded to the 5-element Status enum) and per-row copy semantics. * grpc_server.go StreamJobs sends a single snapshot via ListAll, converting Job.Status with protoStatusToQueue/queueStatusToProto helpers kept in lockstep. B.4 — reaper goroutine stop signal: * nodes.NewRegistry(ctx, log) signature now takes a required context. * reaper goroutine selects on ctx.Done() + ticker.C and exits when the controller's shutdown context is cancelled. * registry gains Close() which cancels its own derived context. * main.go wires NewShutdownContext()'s context into NewRegistry and defers nodeRegistry.Close() after jobQueue.Close(). Tests, ADR, research digest, changelog fragment, AGENTS.md sidecar, rebase-notes entry, ADR index update — all in this PR. ADR-0962. Research: docs/research/0962-controller-streamjobs-reaper-fixes-2026-05-31.md. Conflict resolution notes: * cmd/vmafx-controller/queue/queue.go — both #468's SetGetUnlockedHookForTest and #472's ListAll/repeatCommaQ kept, with the missing closing brace for SetGetUnlockedHookForTest restored (previous botched rebase had sed-stripped the marker and left a syntax error). * cmd/vmafx-controller/AGENTS.md — kept both halves additively: governance/queue invariants from master plus rebase-sensitive invariants from this PR, with ADR-0962 added to the Governing ADRs table and entries split across the queue / nodes / grpc server / main sections. * docs/adr/README.md, docs/adr/_index_fragments/_order.txt, docs/rebase-notes.md — additive (both halves preserved).
14 of 17 tasks
lusoris
added a commit
that referenced
this pull request
May 31, 2026
…26 B.4) (#485) Replace hardcoded pod-level securityContext block (runAsNonRoot, runAsUser/Group/fsGroup) in operator-deployment.yaml with the standard values-driven pattern used by deployment.yaml and job.yaml: securityContext: {{- toYaml .Values.podSecurityContext | nindent 8 }} This ensures the operator workload inherits seccompProfile: RuntimeDefault (added in PR #474) and any future policy changes via .Values.podSecurityContext without a separate template edit — consistent with all other workload templates. Round 26 audit item B.4. Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix Round 26 audit B.1 + B.3 in
deploy/helm/vmafx/.B.1 —
podSecurityContextmissingseccompProfile:values.yaml:217-221only hadrunAsNonRoot/runAsUser/runAsGroup/fsGroup. Pod Security Standards "restricted" admission REJECTS pods withoutseccompProfile.type: RuntimeDefault. All 4 workload templates (deployment.yaml,job.yaml,statefulset.yaml,node-deployment.yaml) import this block verbatim, so all deployments fail on restricted namespaces. Fix: addseccompProfile: { type: RuntimeDefault }tovalues.yaml.B.3 —
node-deployment.yamlbroken image ref: Line 65 inline-rendered{{ .Values.node.image.repository }}:{{ .Values.node.image.tag | default .Chart.AppVersion }}bypassed thevmafx.nodeImagehelper at_helpers.tpl:145. With default emptynode.image.repository, rendered image was:3.0.0→ImagePullBackOff: invalid reference format. Fix: use{{ include "vmafx.nodeImage" . }}.helm lint --strictPASS.helm templateshows seccompProfile on every workload + valid node image ref with default values.no state delta: helm chart fixes per CLAUDE.md §12 r8; no bug tracker entry; PSS admission failure is environment-dependent.ADR-0108 deliverables checklist
helm template test deploy/helm/vmafx/ | grep -A2 seccompProfileshows RuntimeDefault on every workload;helm template test deploy/helm/vmafx/ --set node.enabled=true | grep image:shows valid ref.🤖 Generated with Claude Code