Repository navigation
Fix Helm extension pull secrets and namespace port access - #25
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Extension pods now inherit configured
imagePullSecretsreferences. The release NetworkPolicy permits configured connector and component TCP ports from the same namespace, fixing connectors on ports such as 9123 that fell outside the default ingress ports.The additional rule applies to all pods selected by the release policy, deduplicates shared extension ports, and leaves external ingress peers and egress rules unchanged. The gates job provisions SHA-256-verified Helm 4.3.0 for deployment render tests. No secret values or cluster mutations are included.
Validation covers 31 render cases across unified sidecar, unified child and shared-engine topologies, empty/configured pull-secret references, connector/component/custom/shared ports, and disabled NetworkPolicy. The regression fixtures reproduced 24 failures and 7 passes on the original baseline; all 31 pass with the fix. The reviewed change also passed full pytest, locked mypy, scanner version/provenance checks, complexity/KISS and clone gates, and the pure-Python wheel build. Main integration preserved all four reviewed files and the frozen manifests; strict docs and final normal commit/push hooks validate the integrated candidate.
This is a bounded GRAPHOS-DEPLOY-R013 fix. R013 remains partial: offline rendering does not establish registry pulls, live CNI enforcement, or first-boot identity/secrets readiness.