Skip to content

fix(gateway): require ReferenceGrant for cross-namespace backends in filterconfig - #2750

Open
nacx wants to merge 6 commits into
mainfrom
reference-grant
Open

nacx wants to merge 6 commits into
mainfrom
reference-grant

Conversation

@nacx

@nacx nacx commented Sep 27, 2026

Copy link
Copy Markdown
Member

Description

GatewayController resolved cross-namespace AIServiceBackend/InferencePool backends (and their BackendSecurityPolicy credentials) into the shared extproc filter-config Secret without checking a ReferenceGrant, even though AIGatewayRouteController already enforces one for HTTPRoute generation. Gate both backend kinds on the same check.

Also reconcile BackendSecurityPolicy on grant changes. ReferenceGrantController only requeued AIGatewayRoutes when a ReferenceGrant changed, so a BackendSecurityPolicy left NotAccepted for lacking a grant to its Secret wouldn't re-reconcile until something else touched it. Requeue affected BackendSecurityPolicies too.

Related Issues/PRs (if applicable)

N/A

Special notes for reviewers (if applicable)

N/A

…filter config

GatewayController resolved cross-namespace AIServiceBackend/InferencePool
backends (and their BackendSecurityPolicy credentials) into the shared
extproc filter-config Secret without checking a ReferenceGrant, even
though AIGatewayRouteController already enforces one for HTTPRoute
generation. Gate both backend kinds on the same check.

Also reconcile BackendSecurityPolicy on grant changes.
ReferenceGrantController only requeued AIGatewayRoutes when a
ReferenceGrant changed, so a BackendSecurityPolicy left NotAccepted for
lacking a grant to its Secret wouldn't re-reconcile until something
else touched it. Requeue affected BackendSecurityPolicies too.

Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@nacx
nacx requested a review from a team as a code owner September 27, 2026 17:52
@netlify

netlify Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for theagentrouter canceled.

Name Link
🔨 Latest commit d3a81bd
🔍 Latest deploy log https://app.netlify.com/projects/theagentrouter/deploys/6abc484ad93d5b0008fdd300

@codecov

codecov Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 94.28571% with 4 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/controller/referencegrant_controller.go 88.88% 4 Missing ⚠️

📢 Thoughts on this report? Let us know!

@siddharth1036

Copy link
Copy Markdown
Contributor

LGTM!

@nacx one related gap I noticed (pre-existing, not introduced here): we don’t reconcile any AIGatewayRoute or BackendSecurityPolicy when a ReferenceGrant is deleted.

On delete, ReferenceGrantController hits NotFound and returns without enqueueing anything, so revoke doesn’t fan out. Until something else triggers a reconcile, the AI Gateway dataplane can keep using previously admitted cross-namespace backends / credentials, which doesn’t match the intended ReferenceGrant semantics.

@nacx

nacx commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

That's correct. Let me include that in this PR

Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@nacx

nacx commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Done. PTAL!

@nacx

nacx commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

/retest

@siddharth1036

siddharth1036 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

@nacx the delete grant fix looks good, but there’s one more gap for revoke.

Even when deletion triggers an AIGatewayRoute reconcile, newHTTPRoute fails the ReferenceGrant check and we return before syncGateways. So the generated HTTPRoute and filter-config Secret stay at last-good, and the dataplane can keep serving the cross-namespace backend after the grant is revoked (route goes NotAccepted, but traffic/config aren’t torn down).

Could we still sync parent Gateways (update the HTTPRoute) when the route fails for a missing/invalid ReferenceGrant?

Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@nacx

nacx commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Good catch. I've added it to still run the reconciles if there are referencegrant failed validations, and still returning an error at the end. PTAL

@siddharth1036 siddharth1036 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@siddharth1036

Copy link
Copy Markdown
Contributor

/retest

@nacx
nacx enabled auto-merge (squash) September 30, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants