Skip to content

Conversation

@a-hilaly
Copy link
Member

When the IAMRoleSelector feature is enabled, the IRS internal cache
runs its own NamespaceCache to support namespace based matching.
However, the reconciler's namespace lookup methods (getDefaultRegion,
getEndpointURL, getDeletionPolicy) were only checking
carmCache.Namespaces, causing these values to be unavailable when only
the IAMRoleSelector cache was running. This change makes the Namespaces
field public on the IAMRoleSelector cache and adds fallback logic in the
reconciler to check irsCache.Namespaces when carmCache.Namespaces
doesn't have the requested data, ensuring namespace annotations remain
accessible regardless of which cache is active.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

When the IAMRoleSelector feature is enabled, the IAMRoleSelector cache
runs its own `NamespaceCache` to support namespace based matching.
However, the reconciler's namespace lookup methods (`getDefaultRegion`,
`getEndpointURL`, `getDeletionPolicy`) were only checking
`carmCache.Namespaces`, causing these values to be unavailable when only
the IAMRoleSelector cache was running. This change makes the `Namespaces`
field public on the IAMRoleSelector cache and adds fallback logic in the
reconciler to check `irsCache.Namespaces` when `carmCache.Namespaces`
doesn't have the requested data, ensuring namespace annotations remain
accessible regardless of which cache is active.
@ack-prow ack-prow bot requested review from jlbutler and michaelhtm November 23, 2025 04:51
@ack-prow ack-prow bot added the approved label Nov 23, 2025
@ack-prow
Copy link

ack-prow bot commented Nov 23, 2025

@a-hilaly: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
verify-attribution e2de227 link false /test verify-attribution

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

Copy link
Member

@michaelhtm michaelhtm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice 💯
/lgtm

@ack-prow ack-prow bot added the lgtm Indicates that a PR is ready to be merged. label Nov 23, 2025
@ack-prow
Copy link

ack-prow bot commented Nov 23, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: a-hilaly, michaelhtm

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:
  • OWNERS [a-hilaly,michaelhtm]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@michaelhtm michaelhtm merged commit 10474d5 into aws-controllers-k8s:main Nov 23, 2025
0 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants