Skip to content

fix computedomain daemon permissions in openshift - #3011

Merged
rahulait merged 1 commit into
NVIDIA:mainfrom
rahulait:fix-computedomain-openshift-permissions
Oct 6, 2026
Merged

rahulait merged 1 commit into
NVIDIA:mainfrom
rahulait:fix-computedomain-openshift-permissions

Conversation

@rahulait

@rahulait rahulait commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Description

Fixes #3010

Checklist

  • No secrets, sensitive information, or unrelated changes
  • Lint checks passing (make lint)
  • Generated assets in-sync (make validate-generated-assets)
  • Go mod artifacts in-sync (make validate-modules)
  • Test cases are added for new code paths

Testing


Devin Review

@rahulait
rahulait requested a review from a team as a code owner October 5, 2026 16:12
@rahulait

rahulait commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-26.7

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/gpu-operator/.coderabbit.yaml
  • Review profile: QUIET
  • Plan: Enterprise
  • Run ID: ef978128-8239-435d-862e-251db618e5e7
📥 Commits

Reviewing files that changed from the base of the PR and between f1f7ff4 and f4aa102.

⛔ Files ignored due to path filters (1)
  • internal/state/testdata/golden/gpucluster-dra-driver-full-spec.yaml is excluded by !**/testdata/**
📒 Files selected for processing (6)
  • bundle/manifests/gpu-operator-certified.clusterserviceversion.yaml
  • deployments/gpu-operator/templates/clusterrole.yaml
  • internal/state/dra_driver_test.go
  • internal/state/gpucluster_scc_test.go
  • manifests/state-dra-driver/0120_compute-domain-daemon-rbac.yaml
  • manifests/state-dra-driver/0450_scc.openshift.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The changes add delete permission for computedomaincliques to three RBAC declarations. The OpenShift SCC priority changes from null to 10. Tests check the daemon ClusterRole permissions and the SCC service account, priority, and run-as-user strategy.

Priority: ➖ Normal

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to f4aa1

No actionable issue is identified that would prevent merging after normal checks.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

@tariq1890

Copy link
Copy Markdown
Contributor

I presume this change is needed to address scenarios where the OwnerReferencesPermissionEnforcement admissions controller is enabled?

Are there other areas in our RBAC which would need a similar change?

@rahulait
rahulait force-pushed the fix-computedomain-openshift-permissions branch from f4aa102 to d89838e Compare October 5, 2026 21:36
devin-ai-integration[bot]

This comment was marked as resolved.

@rahulait
rahulait force-pushed the fix-computedomain-openshift-permissions branch 2 times, most recently from 92b3acc to 75ed812 Compare October 5, 2026 22:16
@rahulait

rahulait commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

I presume this change is needed to address scenarios where the OwnerReferencesPermissionEnforcement admissions controller is enabled?

Correct, openshift has this admission plugin enabled by default: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/architecture/admission-plug-ins

Are there other areas in our RBAC which would need a similar change?

I don't think so, tried analyzing the code and no other recommendation was suggested where such permissions are missing.

@rahulait rahulait self-assigned this Oct 6, 2026
@shivamerla

Copy link
Copy Markdown
Contributor

Usage of anyuid SCC aligns with the DRA helm chart deployment. The fix looks good to me.

Signed-off-by: Rahul Sharma <rahulsharm@nvidia.com>
@rahulait
rahulait force-pushed the fix-computedomain-openshift-permissions branch from 75ed812 to 842ec60 Compare October 6, 2026 18:26
@rahulait
rahulait merged commit 57378e9 into NVIDIA:main Oct 6, 2026
21 checks passed
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 Backport PR created for release-26.7: #3022 ✅

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix ComputeDomain daemon permissions on OpenShift

3 participants