Skip to content

Fix Helm extension pull secrets and namespace port access - #25

Merged
Knucklessg1 merged 1 commit into
mainfrom
fix/helm-extension-connectivity
Oct 4, 2026
Merged

Knucklessg1 merged 1 commit into
mainfrom
fix/helm-extension-connectivity

Conversation

@Knucklessg1

Copy link
Copy Markdown
Member

Extension pods now inherit configured imagePullSecrets references. The release NetworkPolicy permits configured connector and component TCP ports from the same namespace, fixing connectors on ports such as 9123 that fell outside the default ingress ports.

The additional rule applies to all pods selected by the release policy, deduplicates shared extension ports, and leaves external ingress peers and egress rules unchanged. The gates job provisions SHA-256-verified Helm 4.3.0 for deployment render tests. No secret values or cluster mutations are included.

Validation covers 31 render cases across unified sidecar, unified child and shared-engine topologies, empty/configured pull-secret references, connector/component/custom/shared ports, and disabled NetworkPolicy. The regression fixtures reproduced 24 failures and 7 passes on the original baseline; all 31 pass with the fix. The reviewed change also passed full pytest, locked mypy, scanner version/provenance checks, complexity/KISS and clone gates, and the pure-Python wheel build. Main integration preserved all four reviewed files and the frozen manifests; strict docs and final normal commit/push hooks validate the integrated candidate.

This is a bounded GRAPHOS-DEPLOY-R013 fix. R013 remains partial: offline rendering does not establish registry pulls, live CNI enforcement, or first-boot identity/secrets readiness.

@Knucklessg1
Knucklessg1 marked this pull request as ready for review October 4, 2026 03:26
@Knucklessg1
Knucklessg1 merged commit e9d9929 into main Oct 4, 2026
4 checks passed
@Knucklessg1
Knucklessg1 deleted the fix/helm-extension-connectivity branch October 6, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant