Skip to content

refactor: construct mutation dependencies only when mutation operations run - #4787

Closed
longxiucai wants to merge 1 commit into
open-policy-agent:masterfrom
longxiucai:mutation-system-conditional
Closed

longxiucai wants to merge 1 commit into
open-policy-agent:masterfrom
longxiucai:mutation-system-conditional

Conversation

@longxiucai

Copy link
Copy Markdown

What this PR does / why we need it:

Part of the controller dependency cleanup tracked in #3964.

setupControllers always constructs the mutation system, and
pkg/controller/mutators/instances.Adder.Add creates the
conflict-routing channels and registers the routeConflictEvents
runnable before the individual mutator controllers check
mutation.Enabled(). Non-mutation processes therefore carry an unused
mutation system and runnable.

Changes:

  • Construct the mutation system only when a mutation operation is
    assigned (mutation.Enabled()), via a small helper that is unit
    tested.
  • Wire the external-data provider cache and client cert watcher into
    the mutation options only in that case; they keep serving the
    validation client independently.
  • Return from the instances Adder before creating any conflict-routing
    state when mutation is disabled.

Workload expansion remains safe: expansion.System already accepts a
nil mutation system and skips applying mutators, which is covered by
the existing expansion tests.

Which issue(s) this PR fixes:

Fixes #4772

Special notes for your reviewer:

  • TestNewMutationSystem covers mutation-disabled and mutation-enabled
    operation sets; the disabled case fails if unconditional construction
    is restored.
  • TestAddSkipsSetupWhenMutationDisabled proves the instances Adder
    returns before touching the manager when mutation is disabled.
  • go test ./pkg/mutation/... ./pkg/expansion/... passes.

…ns run

Today setupControllers always constructs the mutation system and the
mutator instances Adder registers its conflict-routing channels and
runnable before the individual controllers check mutation.Enabled().
Non-mutation processes therefore carry an unused mutation system and
runnable.

Construct the mutation system only when a mutation operation is
assigned, and wire the external-data provider cache and client cert
watcher into it only in that case; they keep serving the validation
client independently. Return from the instances Adder before creating
any conflict-routing state when mutation is disabled. Workload
expansion remains safe: expansion.System already accepts a nil mutation
system and skips applying mutators.

Fixes open-policy-agent#4772

Signed-off-by: longyuxiang <longyuxiang@kylinos.cn>
@longxiucai
longxiucai requested a review from a team as a code owner August 26, 2026 05:40
@longxiucai

Copy link
Copy Markdown
Author

Closing in favor of #4777, which covers the same change and was opened first. No need to review this one.

@longxiucai longxiucai closed this Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Initialize mutation dependencies only for mutation operations

1 participant