Repository navigation
fix(postgres): allow ImageVolume mounts in restore workloads - #852
danielgaskins wants to merge 2 commits into
Conversation
fiunchinho
left a comment
There was a problem hiding this comment.
Thank you for splitting this out. The fix is correct: the network policies and the AWS role trust already allow <clusterName>-restore, and this PR closes the same gap for the ImageVolume exception.
Two changes before we can merge:
1. Update the existing selector check in verify-modes
Makefile.custom.mk (the "CNPG ImageVolume exception renders only with an extension image" step of verify-modes) looks for the literal text cnpg.io/cluster: kagent-pg in the render:
elif ! grep -q "cnpg.io/cluster: kagent-pg" $(VERIFY_TMP)/vm-pe-img.out; then \
echo "FAIL: the exception is not scoped to the Cluster's own pods"; exit 1; \With the new matchExpressions selector, that text is no longer in the render. The substrate network policy also renders it, but substrate is off in that render (KYVERNO_ALL). So we expect make verify-modes to fail on this step. Please update the check to the new selector form, or replace it with a reference to verify-postgres-restore, so that both checks agree. Please run make verify-modes too.
2. Rebase on main
CHANGELOG.md has a conflict with main. When you rebase, please also change the entry's reference from #825 to #852.
Thank you!
Signed-off-by: Daniel Gaskins <danielgaskins99@gmail.com>
Signed-off-by: Daniel Gaskins <danielgaskins99@gmail.com>
24cb942 to
9822e71
Compare
|
I rebased on main and changed the changelog reference to #852. I also marked the regression script executable to fix pre-commit. |
Split the restore-policy fix from #825 as requested.
The documented
<clusterName>-restoreCluster needs the same pgvector ImageVolume as the source. Its Pods and recovery Jobs currently fall outside the source-only PolicyException.Change the selector to allow exactly the source name and
<clusterName>-restore, limited to Pods and Jobs in the source namespace. Keep the existing extension-image and Kyverno gates.The regression check uses
tests/pick-doc.pyand covers default and custom Cluster names and namespaces, the exact allowed names, and disabled configurations. The changelog entry uses the existing Fixed section.Validation:
make verify-postgrespasses.make verify-kyvernopasses.Checked with Helm 3.17.3. This PR contains no cnpg-drill runbook or dependency.