Skip to content

fix: move validation admission policy outside of crds directory#9024

Open
zhaohuabing wants to merge 20 commits into
envoyproxy:mainfrom
zhaohuabing:fix-9015
Open

fix: move validation admission policy outside of crds directory#9024
zhaohuabing wants to merge 20 commits into
envoyproxy:mainfrom
zhaohuabing:fix-9015

Conversation

@zhaohuabing
Copy link
Copy Markdown
Member

@zhaohuabing zhaohuabing commented May 18, 2026

This PR moves validationAdmissionPolicy out of the crds directory and into the templates directory.

This fixes Flux installation as it treats all resources in the crds directory as CRDs.

Fixes #9015

Release Notes: Yes

@zhaohuabing zhaohuabing requested a review from a team as a code owner May 18, 2026 11:28
@netlify
Copy link
Copy Markdown

netlify Bot commented May 18, 2026

Deploy Preview for cerulean-figolla-1f9435 ready!

Name Link
🔨 Latest commit ff48f15
🔍 Latest deploy log https://app.netlify.com/projects/cerulean-figolla-1f9435/deploys/6a1a56f522439a0008c2e55e
😎 Deploy Preview https://deploy-preview-9024--cerulean-figolla-1f9435.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a0caaf38c2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@zhaohuabing zhaohuabing marked this pull request as draft May 18, 2026 11:37
@codecov
Copy link
Copy Markdown

codecov Bot commented May 18, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.83%. Comparing base (8d3cfb4) to head (ff48f15).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #9024      +/-   ##
==========================================
+ Coverage   74.77%   74.83%   +0.06%     
==========================================
  Files         252      252              
  Lines       40675    40675              
==========================================
+ Hits        30415    30440      +25     
+ Misses       8179     8158      -21     
+ Partials     2081     2077       -4     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@zhaohuabing
Copy link
Copy Markdown
Member Author

@codex review

@zhaohuabing zhaohuabing marked this pull request as ready for review May 22, 2026 03:15
Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c499193462

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@zhaohuabing zhaohuabing force-pushed the fix-9015 branch 2 times, most recently from 2e05bcc to d3ade13 Compare May 22, 2026 03:33
@zhaohuabing
Copy link
Copy Markdown
Member Author

@codex review

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3ade13519

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@zhaohuabing
Copy link
Copy Markdown
Member Author

@codex review

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a12ec94e88

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@zhaohuabing
Copy link
Copy Markdown
Member Author

@codex review

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 31c07399ba

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@zhaohuabing
Copy link
Copy Markdown
Member Author

@codex review

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4376333a5d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
@zhaohuabing
Copy link
Copy Markdown
Member Author

@codex review

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5f43969e13

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +14 to +15
{{- $vap := lookup "admissionregistration.k8s.io/v1" "ValidatingAdmissionPolicy" "" $safeUpgradePolicyName -}}
{{- $vapBinding := lookup "admissionregistration.k8s.io/v1" "ValidatingAdmissionPolicyBinding" "" $safeUpgradePolicyName -}}
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Guard lookup against unavailable API or RBAC denial

These unconditional lookup calls can make chart rendering fail before any manifests are emitted: Helm documents that lookup errors from the API server (including missing resource types or permission errors) fail template processing. That means installs/upgrades now fail on clusters where ValidatingAdmissionPolicy is unavailable/disabled or where the installer cannot get these cluster-scoped resources, even in --skip-crds workflows that previously avoided this path. Consider gating with capability checks (and/or avoiding lookup in skip-CRD flows) so unsupported environments can still install.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I see the concern, but I think this is an expected install prerequisite rather than a regression. Gateway API installation now includes ValidatingAdmissionPolicy resources, so clusters using this chart path need to expose admissionregistration.k8s.io/v1/ValidatingAdmissionPolicy. Similarly, Helm uses the Kubernetes identity running the install; that identity needs the cluster-scoped permissions required to install/read these resources.

rudrakhp
rudrakhp previously approved these changes May 27, 2026
cnvergence
cnvergence previously approved these changes May 27, 2026
@zhaohuabing zhaohuabing requested review from a team, arkodg, guydc and jukie May 28, 2026 02:03
jukie
jukie previously approved these changes May 28, 2026
Copy link
Copy Markdown
Contributor

@jukie jukie left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but let's discuss including this in the v1.8.1 cherry-pick.

This could be disruptive for users who exclude crds/ from gateway-helm and install through another path like the gateway-crds-helm chart. Before this change, those users had no VAP in their gateway-helm set, and if they already have the VAP installed through another path they'll need to work through an ownership transition. It's minor but it is an undesired behavior change for a patch release.

@zhaohuabing
Copy link
Copy Markdown
Member Author

zhaohuabing commented May 28, 2026

LGTM, but let's discuss including this in the v1.8.1 cherry-pick.

This could be disruptive for users who exclude crds/ from gateway-helm and install through another path like the gateway-crds-helm chart. Before this change, those users had no VAP in their gateway-helm set, and if they already have the VAP installed through another path they'll need to work through an ownership transition. It's minor but it is an undesired behavior change for a patch release.

Let's discuss this at this week's community meeting.

@zhaohuabing zhaohuabing dismissed stale reviews from jukie, cnvergence, and rudrakhp via ec789fc May 28, 2026 15:39
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
@zhaohuabing
Copy link
Copy Markdown
Member Author

@jukie @arkodg the release note has been updated to explain the required upgrade steps according to the discussion at today's meeting.

Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
@@ -0,0 +1,3 @@
gatewayAPI:
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Member Author

@zhaohuabing zhaohuabing Jun 1, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, it’s technically possible, but I think crds.gatewayAPI.supportingResources.enabled reads more clearly: the full path makes it explicit that these supporting resources are associated with the Gateway API CRDs. It also fits Helm’s existing value-scoping model better and stays consistent with crds.gatewayAPI.enabled / crds.gatewayAPI.channel.

If we prefer a top-level gatewayAPI.supportingResources.enabled value, I can move the VAP template into the main gateway-helm chart so it can read that value directly. My slight preference is to keep it in the crds subchart and expose it as crds.gatewayAPI.supportingResources.enabled, since these supporting resources are used for the Gateway API CRDs

@zhaohuabing zhaohuabing requested a review from arkodg June 1, 2026 03:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ValidatingAdmissionPolicy in charts/crds/crds/ (Helm CRD dir) breaks external CRD management tools

6 participants