Skip to content

ROX-34110: Turning on ROX_LABEL_BASED_POLICY_SCOPING feature flag - #19987

Merged
AlexVulaj merged 2 commits into
masterfrom
AlexVulaj/ROX-34110-fix-sensor-feature-flag
Apr 22, 2026
Merged

AlexVulaj merged 2 commits into
masterfrom
AlexVulaj/ROX-34110-fix-sensor-feature-flag

Conversation

@AlexVulaj

@AlexVulaj AlexVulaj commented Apr 14, 2026 •

Copy link
Copy Markdown
Contributor

Description

The AC label scoping tests (AdmissionControllerTest.groovy) fail on OpenShift when deployed via the operator path. The root cause is that deploy_sensor_via_operator() in tests/e2e/lib.sh does not inject ROX_LABEL_BASED_POLICY_SCOPING into Sensor's environment variables. Without this flag, Sensor's detector rejects namespace-label-scoped policies at pkg/scopecomp/scope.go:75-76, so the Admission Controller never receives them. deploy_central_via_operator() already sets this flag, but the Sensor operator deploy path was missing it.

User-facing documentation

Testing and quality

  • the change is production ready: the change is GA, or otherwise the functionality is gated by a feature flag
  • CI results are inspected

Automated testing

  • added unit tests
  • added e2e tests
  • added regression tests
  • added compatibility tests
  • modified existing tests

How I validated my change

The re-enabled Groovy tests will serve as the primary validation. These tests were failing on the OCP qa e2e tests specifically. CI results on this branch (particularly OCP QA e2e runs) need to be inspected to confirm the tests pass with the flag now injected into Sensor.

@AlexVulaj
AlexVulaj requested a review from janisz as a code owner April 14, 2026 13:57
@AlexVulaj AlexVulaj self-assigned this Apr 14, 2026
@github-actions

github-actions Bot commented Apr 14, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Build Images Ready

Images are ready for commit ca48bc0. To use with deploy scripts:

export MAIN_IMAGE_TAG=4.11.x-741-gca48bc029d

@codecov

codecov Bot commented Apr 14, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 49.61%. Comparing base (4d2d701) to head (a5c7347).
⚠️ Report is 84 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #19987      +/-   ##
==========================================
- Coverage   49.61%   49.61%   -0.01%     
==========================================
  Files        2765     2765              
  Lines      208628   208628              
==========================================
- Hits       103509   103508       -1     
- Misses      97462    97464       +2     
+ Partials     7657     7656       -1     
Flag Coverage Δ
go-unit-tests 49.61% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@AlexVulaj

Copy link
Copy Markdown
Contributor Author

/test ocp-4-21-qa-e2e-tests

@openshift-ci

openshift-ci Bot commented Apr 14, 2026

Copy link
Copy Markdown

@AlexVulaj: No presubmit jobs available for stackrox/stackrox@AlexVulaj/ROX-34110-skip-ac-label-tests-openshift

Details

In response to this:

/test ocp-4-21-qa-e2e-tests

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Base automatically changed from AlexVulaj/ROX-34110-skip-ac-label-tests-openshift to master April 14, 2026 16:05
@AlexVulaj
AlexVulaj force-pushed the AlexVulaj/ROX-34110-fix-sensor-feature-flag branch from cb6a785 to 38d1ce5 Compare April 14, 2026 16:14
@AlexVulaj

Copy link
Copy Markdown
Contributor Author

/test ocp-4-21-qa-e2e-tests

@clickboo clickboo left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given the feature flag ROX_LABEL_BASED_POLICY_SCOPING will be required to be set to true before release, some of the changes in this PR will not be required and the recommendation below will be a cleaner fix for the long term:

  1. Set it to true.
  2. Add the ci-release-build label on the PR that implements 1. Ensure CI green.
  3. Merge PR and profit.

If you choose a separate PR to enable the feature flag, then hold back on this one, and then merge this one such that only the IgnoreIfs are removed after your PR to enable is merged. Or implement the recommendation in this one. Either way.

@AlexVulaj
AlexVulaj force-pushed the AlexVulaj/ROX-34110-fix-sensor-feature-flag branch from 38d1ce5 to a5c7347 Compare April 15, 2026 13:17
@AlexVulaj
AlexVulaj requested a review from a team as a code owner April 15, 2026 13:17
@AlexVulaj AlexVulaj added the ci-release-build Simulate a release build with all images with GOTAGS=release label Apr 15, 2026
@AlexVulaj

Copy link
Copy Markdown
Contributor Author

/test ocp-4-21-qa-e2e-tests

@AlexVulaj
AlexVulaj requested a review from clickboo April 15, 2026 13:27
@AlexVulaj

Copy link
Copy Markdown
Contributor Author

The gke-nongroovy-e2e-tests failure is unrelated to our changes. The only failing test is TestMetadataIsSetCorrectly, which expects a "development" build but gets "release" — expected since we added the ci-release-build label:

  metadata_test.go:40:
      Error:      Not equal:
                  expected: "release"
                  actual  : "development"

All four label scoping tests passed:

  --- PASS: TestLabelScopedPolicies (39.80s)
      --- PASS: TestLabelScopedPolicies/TestNamespaceLabelPolicyScoping (6.95s)
      --- PASS: TestLabelScopedPolicies/TestNamespaceLabelRemoval (7.00s)
      --- PASS: TestLabelScopedPolicies/TestPolicyDryRunWithNamespaceLabel (11.99s)
      --- PASS: TestLabelScopedPolicies/TestRuntimeDetectionWithNamespaceLabels (13.86s)

https://prow.ci.openshift.org/view/gs/test-platform-results/pr-logs/pull/stackrox_stackrox/19987/pull-ci-stackrox-stackrox-master-gke-nongroovy-e2e-tests/2044416387706785792

@AlexVulaj AlexVulaj removed the ci-release-build Simulate a release build with all images with GOTAGS=release label Apr 15, 2026
@AlexVulaj

Copy link
Copy Markdown
Contributor Author

/retest

@AlexVulaj
AlexVulaj enabled auto-merge (squash) April 20, 2026 21:15
@clickboo
clickboo requested a review from bradr5 April 22, 2026 13:07
@clickboo clickboo changed the title ROX-34110: Inject label FF into Sensor via operator deploy ROX-34110: Turning on ROX_LABEL_BASED_POLICY_SCOPING feature flag Apr 22, 2026

@clickboo clickboo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. @bradr5 Tagging for visibility.

@AlexVulaj
AlexVulaj merged commit ca48bc0 into master Apr 22, 2026
107 checks passed
@AlexVulaj
AlexVulaj deleted the AlexVulaj/ROX-34110-fix-sensor-feature-flag branch April 22, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants