Repository navigation
fix(capi): describe each hostPort in the controller manager SecurityPolicyException - #224
Merged
Merged
Conversation
…olicyException With hostNetwork the SecurityPolicyException lists additionalPorts under spec.network.hostPorts, but only hostNetwork carried metadata.description. Every relaxation in a SecurityPolicyException is expected to be described: the descriptions feed the component permissions documentation, and the dmt security-policy-exception-description rule reports a missing one as an error. Each hostPorts entry now gets a description built from the port name, or from the port number when the port has no name. additionalPorts themselves are left untouched, since the same list is rendered into the container ports. Bump chart version to 1.72.28. Signed-off-by: Aleksandr Sinichkin <aleksandr.sinichkin@flant.com>
pabateman
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
helm_lib_capi_controller_manager_manifests: in the SecurityPolicyException rendered for a controller manager in the host network, everyspec.network.hostPortsitem now hasmetadata.description("CAPI infrastructure controller manager port, bound on the node because the Pod runs in the host network."; the port number when the port has no name).hostNetworkin the same SecurityPolicyException already had one.additionalPortsitems are not changed, since the same list goes to the containerports. Chart version 1.72.28.Why do we need it, and what problem does it solve?
Every allowance in a SecurityPolicyException is expected to carry a description: the component permission documentation is built from them. The new dmt rule
security-policy-exception-description(deckhouse/dmt#485) reports allowances without one, and currently fires oncloud-provider-openstack(capo-controller-manager) andcloud-provider-vsphere(capv-controller-manager) because of this helper.Testing
helm-unittest: a new case with two host-network ports (named and unnamed, protocol default) checks the whole
spec.network.hostPorts; the case withoutadditionalPortsasserts there are nohostPorts. All suites pass (438 tests).