Skip to content

fix(capi): describe each hostPort in the controller manager SecurityPolicyException - #224

Merged
pabateman merged 1 commit into
mainfrom
fix-capi-spe-hostports-description
Oct 9, 2026
Merged

pabateman merged 1 commit into
mainfrom
fix-capi-spe-hostports-description

Conversation

@AlwxSin

@AlwxSin AlwxSin commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Description

helm_lib_capi_controller_manager_manifests: in the SecurityPolicyException rendered for a controller manager in the host network, every spec.network.hostPorts item now has metadata.description ("CAPI infrastructure controller manager port, bound on the node because the Pod runs in the host network."; the port number when the port has no name). hostNetwork in the same SecurityPolicyException already had one. additionalPorts items are not changed, since the same list goes to the container ports. Chart version 1.72.28.

Why do we need it, and what problem does it solve?

Every allowance in a SecurityPolicyException is expected to carry a description: the component permission documentation is built from them. The new dmt rule security-policy-exception-description (deckhouse/dmt#485) reports allowances without one, and currently fires on cloud-provider-openstack (capo-controller-manager) and cloud-provider-vsphere (capv-controller-manager) because of this helper.

Testing

helm-unittest: a new case with two host-network ports (named and unnamed, protocol default) checks the whole spec.network.hostPorts; the case without additionalPorts asserts there are no hostPorts. All suites pass (438 tests).

…olicyException

With hostNetwork the SecurityPolicyException lists additionalPorts under
spec.network.hostPorts, but only hostNetwork carried metadata.description.
Every relaxation in a SecurityPolicyException is expected to be described:
the descriptions feed the component permissions documentation, and the dmt
security-policy-exception-description rule reports a missing one as an error.

Each hostPorts entry now gets a description built from the port name, or
from the port number when the port has no name. additionalPorts themselves
are left untouched, since the same list is rendered into the container
ports.

Bump chart version to 1.72.28.

Signed-off-by: Aleksandr Sinichkin <aleksandr.sinichkin@flant.com>
@pabateman
pabateman merged commit 6693f5e into main Oct 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants