Skip to content

fix(chart): bound the egress gateway's ephemeral storage - #255

Merged
teemow merged 2 commits into
giantswarmfrom
fork/atenet-egress-ephemeral-storage
Oct 10, 2026
Merged

teemow merged 2 commits into
giantswarmfrom
fork/atenet-egress-ephemeral-storage

Conversation

@teemow

@teemow teemow commented Oct 10, 2026

Copy link
Copy Markdown
Member

Problem

charts/substrate renders the atenet-egress Deployment with both containers (agentgateway, ext-proc) without resources and its drain-signal emptyDir without a sizeLimit. A cluster policy that requires bounded ephemeral storage for a container mounting an emptyDir (Kyverno's require-emptydir-requests-and-limits, which skips a volume that carries a sizeLimit) reports the egress gateway on every install. Nothing else in the chart's render is reported: the bundled Postgres carries postgres.resources, the other workloads mount no emptyDir.

Change

Three chart values, upstream-shaped like postgres.resources, with defaults that make the render compliant by itself:

  • atenetEgress.resources (the agentgateway container) and atenetEgress.extProc.resources: ephemeral-storage requests 16Mi, limits 256Mi. Both containers write nothing but their logs (kubelet rotates them at 10Mi × 5) and, the ext-proc, the drain marker. CPU and memory stay the operator's to size; a value merges over the defaults as Helm merges maps.
  • atenetEgress.drainSignal.sizeLimit: 16Mi on the drain-signal emptyDir the ext-proc writes its drain marker to (/var/run/atenet, one small file).
  • null renders the field as before (no resources, emptyDir: {}).

charts/substrate/tests/atenet_egress_ephemeral_storage_test.yaml asserts the defaults on both containers and the volume, an override merged over the defaults, and the null case. README rows for the three keys. The preserved kubectl-apply manifest manifests/ate-install/atenet-egress.yaml (the Envoy data plane) is hand-maintained and untouched; hack/render-manifests.sh --check passes.

One commit, upstream-ready: the change is the chart's own gap (upstream's atenet-egress.yaml renders the same unbounded shape); the ledger row names it as to file.

Acceptance

  • helm template of the chart renders requests.ephemeral-storage: 16Mi, limits.ephemeral-storage: 256Mi on agentgateway and ext-proc and emptyDir.sizeLimit: 16Mi on drain-signal by default; helm unittest charts/substrate passes (94 tests).
  • A consumer that forwards the three keys gets its values verbatim; one that sets them null gets the previous render.

Written by an agent.

The atenet-egress Deployment rendered both containers without resources
and its drain-signal emptyDir without a sizeLimit, so a cluster policy that
requires bounded ephemeral storage for a container mounting an emptyDir
(Kyverno's require-emptydir-requests-and-limits) reported the egress
gateway on every install. The chart now takes atenetEgress.resources (the
agentgateway container), atenetEgress.extProc.resources and
atenetEgress.drainSignal.sizeLimit, defaulting to ephemeral-storage
requests of 16Mi and limits of 256Mi on both containers (they write nothing
but their logs and the drain marker) and a 16Mi sizeLimit on the emptyDir;
null renders the field as before. CPU and memory stay the operator's to
size. Unit tests cover the defaults, an override merged over them and the
null case; the preserved kubectl-apply manifest is untouched.

Signed-off-by: Timo Derstappen <teemow@gmail.com>
@teemow
teemow requested a review from a team as a code owner October 10, 2026 09:59
Signed-off-by: Timo Derstappen <teemow@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant