Repository navigation
fix(helm): operator-deployment use .Values.podSecurityContext (Round 26 B.4) - #485
Merged
Merged
Conversation
…26 B.4)
Replace hardcoded pod-level securityContext block (runAsNonRoot,
runAsUser/Group/fsGroup) in operator-deployment.yaml with the standard
values-driven pattern used by deployment.yaml and job.yaml:
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
This ensures the operator workload inherits seccompProfile: RuntimeDefault
(added in PR #474) and any future policy changes via .Values.podSecurityContext
without a separate template edit — consistent with all other workload templates.
Round 26 audit item B.4.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replace hardcoded inline
securityContextblock (lines 38-41) indeploy/helm/vmafx/templates/operator-deployment.yamlwith the values-drivenpattern used by all other workload templates (
deployment.yaml,job.yaml,node-deployment.yaml):This brings the operator Deployment into line with the rest of the chart and
ensures it inherits
seccompProfile: RuntimeDefault(added in PR #474) andany future
.Values.podSecurityContextpolicy changes automatically.Round 26 audit item B.4.
Type
fix— bug fixChecklist
make format && make lintis green locally.meson test -C build./cross-backend-diffand the worst ULP is ≤ 2..c/.cpp/.cu/.h/.hpp, it has the appropriate license header (seeCONTRIBUTING.md).!orBREAKING CHANGE:and the migration path is documented below.docs/adr/_index_fragments/<NNNN-slug>.md.Bug-status hygiene (ADR-0165)
no state delta: helm chart consistency fix per CLAUDE.md §12 r8
Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Deep-dive deliverables (ADR-0108)
AGENTS.mdinvariant note — no rebase-sensitive invariants: existing seccomp invariant from PR fix(helm): add seccompProfile to podSecurityContext + fix node-deployment image helper (Round 26 audit) #474 already covers the operator workload viapodSecurityContext.Reproducer
Known follow-ups
None.
🤖 Generated with Claude Code