refactor: scope expansion ingestion to operations that evaluate expanded resources - #4788
Closed
longxiucai wants to merge 1 commit into
Closed
longxiucai wants to merge 1 commit into
longxiucai wants to merge 1 commit into
Conversation
…ded resources The ExpansionTemplate ingestion controller checked only --enable-generator-resource-expansion, which defaults to true, so status-only, generate-only and other processes that never evaluate admission or audit resources still registered it. Add operations.HasExpansionEvaluationOperations, true only for the validating webhook and audit operations, and register the ingestion controller only when the feature is enabled and one of those consumers is assigned. Expansion status aggregation keeps its existing, separate status-operation gate. The readiness tracker is wired with the same predicate so pods that do not ingest ExpansionTemplates also do not build unsatisfiable expectations for them. Fixes open-policy-agent#4773 Signed-off-by: longyuxiang <longyuxiang@kylinos.cn>
Author
|
Closing in favor of #4778, which covers the same change and was opened first. No need to review this one. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it:
Part of the controller dependency cleanup tracked in #3964.
The ExpansionTemplate ingestion controller checked only
--enable-generator-resource-expansion, which defaults to true, sostatus-only, generate-only and other processes that never evaluate
admission or audit resources still registered it.
Changes:
operations.HasExpansionEvaluationOperations, true only for thevalidating webhook and audit operations — the consumers that actually
evaluate expanded resources.
and one of those consumers is assigned. Expansion status aggregation
keeps its existing, separate status-operation gate.
not ingest ExpansionTemplates also do not build unsatisfiable
expectations for them (otherwise readiness would never be reached on
e.g. status-only pods with ExpansionTemplates present).
Default all-operations behavior is unchanged.
Which issue(s) this PR fixes:
Fixes #4773
Special notes for your reviewer:
Test_HasExpansionEvaluationOperationscovers the isolated operationsets plus the shipped
audit+status+mutation-status+generatecombination.
TestAddSkipsWhenExpansionDisabledandTestAddSkipsNonEvaluationOperationsprove the Adder returns beforetouching the manager when the feature flag is off or no evaluation
operation is assigned.