OCPBUGS-72408: change allow-all allowedregistries to deny-all with sane exceptions#607
OCPBUGS-72408: change allow-all allowedregistries to deny-all with sane exceptions#607dusk125 wants to merge 1 commit intoopenshift:mainfrom
Conversation
|
@dusk125: This pull request references Jira Issue OCPBUGS-72408, which is valid. The bug has been moved to the POST state. 3 validation(s) were run on this bug
Requesting review from QA contact: The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this: Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dusk125 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
58e0453 to
ae66a3d
Compare
WalkthroughThis pull request removes an unused context import and eliminates a fallback mechanism in the apiserver that previously defaulted to whitelisting all registries when the allowed registries list was empty. After these changes, the whitelister will be nil in that scenario instead of providing a default "allow all" implementation. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches
🧪 Generate unit tests (beta)
Comment |
|
@dusk125: This pull request references Jira Issue OCPBUGS-72408, which is valid. 3 validation(s) were run on this bug
Requesting review from QA contact: DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
openshift/cluster-openshift-apiserver-operator#651 would need to merge first so that we don't deny everything and break ourselves. |
ae66a3d to
7f30dae
Compare
|
@dusk125: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
This failure proves that the deny-all is working properly and that the defaults in the linked operator PR will be necessary: link. |
|
/testwith ? |
|
/testwith openshift/openshift-apiserver/main/e2e-aws-ovn openshift/cluster-openshift-apiserver-operator#651 |
|
/testwith openshift/openshift-apiserver/main/e2e-aws-ovn openshift/cluster-openshift-apiserver-operator#651 |
Change the default behavior of an empty/unspecified AllowRegistriesForImport from allow-all to deny-all.