Repository navigation
docs(adr): create ADRs for k8s operator + helm + eBPF DRAFT PRs - #535
Merged
Merged
Conversation
lusoris
force-pushed
the
docs/adr-missing-draft-prs
branch
from
June 3, 2026 12:47
602b6dd to
f2652d5
Compare
lusoris
marked this pull request as ready for review
June 3, 2026 12:47
#184/#439 Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
force-pushed
the
docs/adr-missing-draft-prs
branch
from
June 3, 2026 12:49
f2652d5 to
3d19e1a
Compare
There was a problem hiding this comment.
Pull request overview
This PR backfills four missing Architecture Decision Records (ADRs) under docs/adr/ to document design rationale for existing open draft implementation PRs (eBPF rclone bypass, k8s e2e harness, distroless operator/node images, and Helm NetworkPolicy/PSA hardening), and updates the ADR index accordingly.
Changes:
- Add four new ADR markdown files (0779, 0783, 0815, 0930) capturing context/decision/alternatives/consequences.
- Update
docs/adr/README.mdto include index rows for the newly added ADRs.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| docs/adr/README.md | Adds new ADR index rows for the backfilled ADRs. |
| docs/adr/0779-ebpf-fuse-bypass-rclone.md | New ADR documenting the eBPF FUSE bypass design for rclone. |
| docs/adr/0783-k8s-e2e-integration-test-harness.md | New ADR documenting the kind+kuttl k8s e2e test harness approach. |
| docs/adr/0815-operator-node-distroless-dockerfiles.md | New ADR documenting distroless multi-arch operator/node images and release CI. |
| docs/adr/0930-helm-networkpolicy-pss.md | New ADR documenting Helm chart NetworkPolicy defaults and PSA restricted baseline. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+821
to
+824
| | [ADR-0779](0779-ebpf-fuse-bypass-rclone.md) | eBPF FUSE bypass for rclone zero-copy path in vmafx-node: probe-only tracepoint program + Go cilium/ebpf loader; 37× warm-cache latency improvement; opt-in via VMAFX_EBPF_BYPASS=1 | Proposed | 2026-06-03 | ci, go, ebpf, rclone, performance, security, supply-chain | | ||
| | [ADR-0783](0783-k8s-e2e-integration-test-harness.md) | Kubernetes end-to-end integration test harness — kind + kuttl: five test cases covering operator/node/trainer stack; nightly CI + opt-in PR label gate | Proposed | 2026-06-03 | ci, testing, k8s, github | | ||
| | [ADR-0815](0815-operator-node-distroless-dockerfiles.md) | Distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI: gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM | Proposed | 2026-06-03 | ci, build, security, supply-chain, github, docker | | ||
| | [ADR-0930](0930-helm-networkpolicy-pss.md) | Helm chart NetworkPolicy default-deny + Pod Security Standards "restricted" baseline: PSA-restricted pod contexts, uid 65532, opt-in NetworkPolicy bundle with narrow allow-rules | Proposed | 2026-06-03 | security, k8s, ci, build, github | |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docs/adr/0779-ebpf-fuse-bypass-rclone.md): eBPF FUSE bypass for rclone zero-copy path — backs open DRAFT PR feat(node): eBPF FUSE bypass for rclone (ADR-0779) #137. Covers probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache latency improvement; opt-in viaVMAFX_EBPF_BYPASS=1.docs/adr/0783-k8s-e2e-integration-test-harness.md): Kubernetes e2e integration test harness — backs open DRAFT PR feat(ci): k8s e2e integration test harness — kind + kuttl (ADR-0783) #152. Covers kind + kuttl design rationale; kuttl vs chainsaw vs envtest vs cloud cluster alternatives.docs/adr/0815-operator-node-distroless-dockerfiles.md): Distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node — backs open DRAFT PR feat(docker): Dockerfile.operator + node publish CI — distroless multi-arch (ADR-0815) #184. Covers image-base selection, uid 65532 alignment, cosign + syft SBOM.docs/adr/0930-helm-networkpolicy-pss.md): Helm chart NetworkPolicy default-deny + PSA "restricted" baseline — backs open DRAFT PR feat(helm): NetworkPolicy default-deny + Pod Security Standards "restricted" baseline (ADR-0930) #439. Covers UID migration 65534→65532, opt-in NetworkPolicy bundle, PSArestrictedsatisfaction.Per CLAUDE.md rule 8, ADRs must land before implementation PRs. All four cited ADR numbers were missing backing
.mdfiles on disk.ADR-0715 and ADR-0716 status
ADR-0715 and ADR-0716 do not exist on disk and are not referenced by any currently open PR. No context is available to reconstruct what decisions they were intended to document. Flagged here for maintainer awareness — if these numbers were allocated for in-progress work that was abandoned, the allocator stubs should be released via
scripts/adr/next-free.sh --release <NNNN>.ADR-0108 deliverables checklist
## Alternatives consideredtable with ≥2 entries.docs/adr/markdown, no C/Go/Python surface touched.pre-commit run --files docs/adr/0779-ebpf-fuse-bypass-rclone.md docs/adr/0783-k8s-e2e-integration-test-harness.md docs/adr/0815-operator-node-distroless-dockerfiles.md docs/adr/0930-helm-networkpolicy-pss.md docs/adr/README.md— all hooks pass.docs/adr/is a fork-local directory with no upstream equivalent.🤖 Generated with Claude Code