Skip to content

fix(csi): also grant patch on VolumeSnapshots to external-provisioner - #222

Merged
duckhawk merged 1 commit into
mainfrom
fix/csi-provisioner-patch-volumesnapshots
Sep 30, 2026
Merged

duckhawk merged 1 commit into
mainfrom
fix/csi-provisioner-patch-volumesnapshots

Conversation

@duckhawk

@duckhawk duckhawk commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Description

helm_lib_csi_controller_rbac: the external-provisioner rule on volumesnapshots also grants patch. It is now get, list, watch, update, patch. Chart version 1.72.26.

Why do we need it, and what problem does it solve?

#221 granted update so that external-provisioner v6.3.0 can protect the source VolumeSnapshot with a finalizer while it restores a volume from it. Upstream writes that finalizer with an Update of the whole typed object.

That Update drops any field a VolumeSnapshot CRD adds to spec, because the typed VolumeSnapshot does not know it. The storage-foundation CRD adds spec.mode, with a default of Capture and an immutability rule, so the Update is rejected for a VolumeSnapshot in mode: Import:

VolumeSnapshot.snapshot.storage.k8s.io "<name>" is invalid: spec.mode: Invalid value: "string": mode is immutable

Because of this, the storage-foundation build of the provisioner now writes the finalizer as a JSON merge patch of metadata.finalizers only (storage-foundation MR !173). The rule has to allow that write, so it now grants patch next to update. Both kinds of provisioner build keep working. Which build a module runs against is settled by the module's dependencies, not by this library.

What is the expected result?

  • A provisioner that patches the finalizer is allowed to.
  • A provisioner that updates the object behaves as it did with 1.72.25.

Checklist

  • The code is covered by unit tests.
  • e2e tests passed.
  • Documentation updated according to the changes.
  • Changes were tested in the Kubernetes cluster manually.

external-provisioner protects the source VolumeSnapshot with a finalizer
while it restores a volume from it. Upstream writes that finalizer with an
Update of the whole object; a build may instead patch metadata.finalizers
only, which is what the storage-foundation build now does, because an
Update through the typed VolumeSnapshot drops fields a CRD adds to spec.

The rule granted get, list, watch and update since #221, so a provisioner
that patches is refused. It now grants patch as well, and serves both
kinds of provisioner build.

Bump chart version to 1.72.26.

Signed-off-by: v.oleynikov <vasily.oleynikov@flant.com>
@duckhawk
duckhawk force-pushed the fix/csi-provisioner-patch-volumesnapshots branch from 579e427 to d637617 Compare September 29, 2026 16:37
@duckhawk duckhawk changed the title fix(csi): grant patch instead of update on VolumeSnapshots to external-provisioner fix(csi): also grant patch on VolumeSnapshots to external-provisioner Sep 29, 2026
@duckhawk
duckhawk merged commit 228dc9c into main Sep 30, 2026
4 checks passed
@duckhawk
duckhawk deleted the fix/csi-provisioner-patch-volumesnapshots branch September 30, 2026 03:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants