Skip to content

refactor: scope expansion ingestion to operations that evaluate expanded resources - #4788

Closed
longxiucai wants to merge 1 commit into
open-policy-agent:masterfrom
longxiucai:expansion-evaluation-operations
Closed

longxiucai wants to merge 1 commit into
open-policy-agent:masterfrom
longxiucai:expansion-evaluation-operations

Conversation

@longxiucai

Copy link
Copy Markdown

What this PR does / why we need it:

Part of the controller dependency cleanup tracked in #3964.

The ExpansionTemplate ingestion controller checked only
--enable-generator-resource-expansion, which defaults to true, so
status-only, generate-only and other processes that never evaluate
admission or audit resources still registered it.

Changes:

  • Add operations.HasExpansionEvaluationOperations, true only for the
    validating webhook and audit operations — the consumers that actually
    evaluate expanded resources.
  • Register the ingestion controller only when the feature is enabled
    and one of those consumers is assigned. Expansion status aggregation
    keeps its existing, separate status-operation gate.
  • Wire the readiness tracker with the same predicate, so pods that do
    not ingest ExpansionTemplates also do not build unsatisfiable
    expectations for them (otherwise readiness would never be reached on
    e.g. status-only pods with ExpansionTemplates present).

Default all-operations behavior is unchanged.

Which issue(s) this PR fixes:

Fixes #4773

Special notes for your reviewer:

  • Test_HasExpansionEvaluationOperations covers the isolated operation
    sets plus the shipped audit+status+mutation-status+generate
    combination.
  • TestAddSkipsWhenExpansionDisabled and
    TestAddSkipsNonEvaluationOperations prove the Adder returns before
    touching the manager when the feature flag is off or no evaluation
    operation is assigned.

…ded resources

The ExpansionTemplate ingestion controller checked only
--enable-generator-resource-expansion, which defaults to true, so
status-only, generate-only and other processes that never evaluate
admission or audit resources still registered it.

Add operations.HasExpansionEvaluationOperations, true only for the
validating webhook and audit operations, and register the ingestion
controller only when the feature is enabled and one of those consumers
is assigned. Expansion status aggregation keeps its existing, separate
status-operation gate.

The readiness tracker is wired with the same predicate so pods that do
not ingest ExpansionTemplates also do not build unsatisfiable
expectations for them.

Fixes open-policy-agent#4773

Signed-off-by: longyuxiang <longyuxiang@kylinos.cn>
@longxiucai
longxiucai requested a review from a team as a code owner August 26, 2026 05:40
@longxiucai

Copy link
Copy Markdown
Author

Closing in favor of #4778, which covers the same change and was opened first. No need to review this one.

@longxiucai longxiucai closed this Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Scope expansion controllers to operations that evaluate expanded resources

1 participant