Skip to content

fix(helm): operator-deployment use .Values.podSecurityContext (Round 26 B.4) - #485

Merged
lusoris merged 1 commit into
masterfrom
fix/helm-operator-security-context-consistency
May 31, 2026
Merged

lusoris merged 1 commit into
masterfrom
fix/helm-operator-security-context-consistency

Conversation

@lusoris

@lusoris lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor

Summary

Replace hardcoded inline securityContext block (lines 38-41) in
deploy/helm/vmafx/templates/operator-deployment.yaml with the values-driven
pattern used by all other workload templates (deployment.yaml, job.yaml,
node-deployment.yaml):

securityContext:
  {{- toYaml .Values.podSecurityContext | nindent 8 }}

This brings the operator Deployment into line with the rest of the chart and
ensures it inherits seccompProfile: RuntimeDefault (added in PR #474) and
any future .Values.podSecurityContext policy changes automatically.

Round 26 audit item B.4.

Type

  • fix — bug fix

Checklist

  • Commits follow Conventional Commits (the commit-msg hook enforces this).
  • make format && make lint is green locally.
  • Unit tests pass: meson test -C build.
  • If I touched any SIMD/GPU code path, I ran /cross-backend-diff and the worst ULP is ≤ 2.
  • If I touched a feature extractor with SIMD/GPU twins, I either updated every twin or listed the gap under "Known follow-ups" below.
  • If I added a new .c / .cpp / .cu / .h / .hpp, it has the appropriate license header (see CONTRIBUTING.md).
  • If this is a breaking change, the commit message uses ! or BREAKING CHANGE: and the migration path is documented below.
  • If this PR adds an ADR, the ADR row lives in docs/adr/_index_fragments/<NNNN-slug>.md.

Bug-status hygiene (ADR-0165)

no state delta: helm chart consistency fix per CLAUDE.md §12 r8

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.
  • If I believe a golden value must change, I have explained why below AND pinged @lusoris for a CODEOWNERS exception.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: trivial change, match existing pattern.
  • Decision matrix — no alternatives: only-one-way fix — all other templates already use this pattern.
  • AGENTS.md invariant note — no rebase-sensitive invariants: existing seccomp invariant from PR fix(helm): add seccompProfile to podSecurityContext + fix node-deployment image helper (Round 26 audit) #474 already covers the operator workload via podSecurityContext.
  • Reproducer / smoke-test command — see Reproducer section below.
  • CHANGELOG fragment — no changelog entry: helm chart consistency fix, no user-visible API or behavioral change.
  • Rebase note — no rebase impact: helm-only template consistency fix with no C API or protocol changes.

Reproducer

helm template test deploy/helm/vmafx/ --set operator.enabled=true | grep -B2 -A10 'kind: Deployment' | head -80
# Both Deployment blocks now show seccompProfile: RuntimeDefault from .Values.podSecurityContext
helm lint deploy/helm/vmafx/

Known follow-ups

None.

🤖 Generated with Claude Code

…26 B.4)

Replace hardcoded pod-level securityContext block (runAsNonRoot,
runAsUser/Group/fsGroup) in operator-deployment.yaml with the standard
values-driven pattern used by deployment.yaml and job.yaml:

  securityContext:
    {{- toYaml .Values.podSecurityContext | nindent 8 }}

This ensures the operator workload inherits seccompProfile: RuntimeDefault
(added in PR #474) and any future policy changes via .Values.podSecurityContext
without a separate template edit — consistent with all other workload templates.

Round 26 audit item B.4.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris marked this pull request as ready for review May 31, 2026 12:34
@lusoris
lusoris merged commit 405ff24 into master May 31, 2026
54 of 89 checks passed
@lusoris
lusoris deleted the fix/helm-operator-security-context-consistency branch May 31, 2026 12:34
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant