Repository navigation
fix: bound atenet-egress's ephemeral storage, oauth2-proxy from gsoci - #912
Merged
Merged
Conversation
Published Helm chart
|
| Chart | agent-platform |
| Version | 4.124.1-rca6c70c7t20261010101132h88d601a |
| OCI reference | oci://gsoci.azurecr.io/charts/giantswarm/agent-platform:4.124.1-rca6c70c7t20261010101132h88d601a |
| Digest | sha256:d526f4417d9ed28b82bf4899d47310b932b431dfa44a866d0b3d77650aa0e05f |
| Registry | public — gsoci.azurecr.io |
| Git catalog | giantswarm-test-catalog (index) |
Pull this chart
helm pull oci://gsoci.azurecr.io/charts/giantswarm/agent-platform --version 4.124.1-rca6c70c7t20261010101132h88d601aPosted by architect-orb · build 20992 · commit 88d601a · updated in place on every push
Published Helm chart
|
| Chart | agent-platform-connectivity |
| Version | 4.124.1-rca6c70c7t20261010101132h88d601a |
| OCI reference | oci://gsoci.azurecr.io/charts/giantswarm/agent-platform-connectivity:4.124.1-rca6c70c7t20261010101132h88d601a |
| Digest | sha256:16906b1f0bea86e9a1b9f19216cb11e5ba7b9336b8f207362d372abb3283f04e |
| Registry | public — gsoci.azurecr.io |
| Git catalog | giantswarm-test-catalog (index) |
Pull this chart
helm pull oci://gsoci.azurecr.io/charts/giantswarm/agent-platform-connectivity --version 4.124.1-rca6c70c7t20261010101132h88d601aPosted by architect-orb · build 20995 · commit 88d601a · updated in place on every push
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #880.
Problem
A 4.x installation with Kyverno reports two Audit findings of the platform's own workloads:
require-emptydir-requests-and-limitsonDeployment ate-system/atenet-egress: the Substrate chart renders thedrain-signalemptyDir without asizeLimitand both containers (agentgateway,ext-proc) without resources.restrict-image-registriesonDeployment kagent/kagent-oauth2-proxy: the kagent chart's oauth2-proxy subchart defaults toquay.io/oauth2-proxy/oauth2-proxy:v7.15.5.Change
The egress gateway's ephemeral storage.
substrate.atenetEgresscarries ephemeral-storage requests16Miand limits256Mifor both containers (they write nothing but their logs and the drain marker; CPU and memory stay the installation's to size) and a16MisizeLimitfor the emptyDir. Two halves, and why:substrate:block travels verbatim into the substrate HelmRelease's values, the Substrate chart carries no values schema (a key it does not know is pruned in silence), andcomponents.substrate.versionRangeconfines one minor (agent-platform.substrate.validateRange). The Substrate line now takes the three keys (atenetEgress.resources,atenetEgress.extProc.resources,atenetEgress.drainSignal.sizeLimit, fix(chart): bound the egress gateway's ephemeral storage substrate#255: upstream-shaped, with defaults that make the chart's render compliant on its own), from its release 1.8.0 on. That is the half that survives every Substrate upgrade: values are the chart's contract.mainis>=1.7.0 <1.8.0, and the line'sgiantswarmbranch is already past 1.7.0, so no release the range admits can carry the keys before a re-pin. Below the releaseagent-platform.substrate.egressStorageFloornames (1.8.0) the meta chart therefore applies the same bound as one kustomize strategic-merge patch on the substrate HelmRelease (a Flux postRenderer,agent-platform.substrate.egressStoragePatch, built from the same values): the containersagentgatewayandext-procmerged by name, the volumedrain-signallikewise. Those names are upstream's canonicalate-systemrender, unchanged from 1.6 through the line's 1.8 candidates, and the range confines one minor, so a Substrate patch within it keeps them; the re-pin that moves the floor past 1.8.0 retires the patch and the chart renders the bound from the forwarded keys. A patch without the floor would have had no end of life and no guard against a chart that renders the bound itself; the keys without the patch would have fixed nothing on today's range. A null key bounds nothing (the chart's own default from the floor on, no patch for it below).oauth2-proxy from gsoci.
kagent.oauth2-proxy.imagepinsgsoci.azurecr.io/giantswarm/oauth2-proxy:v7.15.5, retagger's mirror of the subchart's default at the same digest (sha256:8498b0d0…on both registries). The pin holds the tag of the subchart the kagent release at the range's floor bundles (kagent 1.6.0: oauth2-proxy chart 10.7.1, appVersion 7.15.5), so a kagent re-pin that bumps the subchart moves it.Checks.
make verify-substrate-egress-ephemeral-storage: the substrate chart at the range's floor, rendered with the forwarded values, fails the rule by itself below the floor (the floor is not stale) and passes with the HelmRelease's one patch merged by name (every container and volume the patch names rendered by the release); at or above the floor no patch renders and the chart passes from the forwarded keys; the three knobs null render no patch; the forwarded block is verbatim.make verify-kagent-oauth2-proxy-image: the pin reaches the kagent release verbatim, is the gsoci copy of the subchart the kagent floor bundles, and is published. Goldens regenerated (tests/golden/meta-*.yaml: the forwarded keys, the patch on the engine-off shape), README rows by helm-docs, CHANGELOG.Proof
helm templatewith the chart's defaults and the CI inputs): thesubstrateHelmRelease carrieskagentHelmRelease's valuesoauth2-proxy.image: {registry: gsoci.azurecr.io, repository: giantswarm/oauth2-proxy, tag: v7.15.5}.kubectl kustomizewith the patch — on both,agentgatewayandext-proccarryrequests.ephemeral-storage: 16Mi,limits.ephemeral-storage: 256Mi,drain-signalisemptyDir: {sizeLimit: 16Mi}, images unchanged.make verify-substrate-egress-ephemeral-storage: "the substrate chart 1.7.0 (below 1.8.0) fails the rule by itself (ext-proc mounts an unbounded emptyDir and has no resources.requests.ephemeral-storage; … limits …) and passes with the HelmRelease's patch merged by name"; "the three knobs null render no patch".make verify-kagent-oauth2-proxy-image: "kagent 1.6.0 bundles oauth2-proxy chart 10.7.1 (appVersion 7.15.5); the pin gsoci.azurecr.io/giantswarm/oauth2-proxy:v7.15.5 is its gsoci copy and is published".verify-meta,verify-target,verify-substrate-images,verify-images,verify-workerpoolgreen.kubectl get policyreports -n ate-systemshowsDeployment atenet-egresswith FAIL 1 —require-emptydir-requests-and-limits/autogen-check-emptydir-requests-limits … failed at path /resources/limits/;-n kagentshowsDeployment kagent-oauth2-proxyand its ReplicaSets with FAIL 1 —restrict-image-registries/autogen-validate-registries … failed at path /spec/template/spec/containers/0/image/; the live Deployment runsquay.io/oauth2-proxy/oauth2-proxy:v7.15.5. The installation follows the release candidates of this chart through its GitOps range; the policyreports after the candidate rolls there are recorded on fix: atenet-egress emptyDir limits and oauth2-proxy registry on 4.x #880.Written by an agent.