Skip to content

fix(postgres): allow ImageVolume mounts in restore workloads - #852

Open
danielgaskins wants to merge 2 commits into
giantswarm:mainfrom
danielgaskins:fix/postgres-restore-image-volume
Open

danielgaskins wants to merge 2 commits into
giantswarm:mainfrom
danielgaskins:fix/postgres-restore-image-volume

Conversation

@danielgaskins

Copy link
Copy Markdown

Split the restore-policy fix from #825 as requested.

The documented <clusterName>-restore Cluster needs the same pgvector ImageVolume as the source. Its Pods and recovery Jobs currently fall outside the source-only PolicyException.

Change the selector to allow exactly the source name and <clusterName>-restore, limited to Pods and Jobs in the source namespace. Keep the existing extension-image and Kyverno gates.

The regression check uses tests/pick-doc.py and covers default and custom Cluster names and namespaces, the exact allowed names, and disabled configurations. The changelog entry uses the existing Fixed section.

Validation:

  • make verify-postgres passes.
  • make verify-kyverno passes.
  • The new regression check fails against the unpatched template.

Checked with Helm 3.17.3. This PR contains no cnpg-drill runbook or dependency.

@danielgaskins
danielgaskins requested a review from a team as a code owner October 8, 2026 02:41

@fiunchinho fiunchinho left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for splitting this out. The fix is correct: the network policies and the AWS role trust already allow <clusterName>-restore, and this PR closes the same gap for the ImageVolume exception.

Two changes before we can merge:

1. Update the existing selector check in verify-modes

Makefile.custom.mk (the "CNPG ImageVolume exception renders only with an extension image" step of verify-modes) looks for the literal text cnpg.io/cluster: kagent-pg in the render:

elif ! grep -q "cnpg.io/cluster: kagent-pg" $(VERIFY_TMP)/vm-pe-img.out; then \
    echo "FAIL: the exception is not scoped to the Cluster's own pods"; exit 1; \

With the new matchExpressions selector, that text is no longer in the render. The substrate network policy also renders it, but substrate is off in that render (KYVERNO_ALL). So we expect make verify-modes to fail on this step. Please update the check to the new selector form, or replace it with a reference to verify-postgres-restore, so that both checks agree. Please run make verify-modes too.

2. Rebase on main

CHANGELOG.md has a conflict with main. When you rebase, please also change the entry's reference from #825 to #852.

Thank you!

Signed-off-by: Daniel Gaskins <danielgaskins99@gmail.com>
Signed-off-by: Daniel Gaskins <danielgaskins99@gmail.com>
@danielgaskins
danielgaskins force-pushed the fix/postgres-restore-image-volume branch from 24cb942 to 9822e71 Compare October 10, 2026 18:35
@danielgaskins

Copy link
Copy Markdown
Author

I rebased on main and changed the changelog reference to #852. verify-modes now runs the shared restore-selector check instead of looking for the old matchLabels text.

I also marked the regression script executable to fix pre-commit. make verify-modes, make verify-postgres, and make verify-kyverno pass with Helm 3.17.3.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants