Skip to content

ROX-37315: Keep deploy checks with image exclusions (release-4.10) - #23212

Draft
sachaudh wants to merge 1 commit into
release-4.10from
codex/backport-23107-release-4.10
Draft

sachaudh wants to merge 1 commit into
release-4.10from
codex/backport-23107-release-4.10

Conversation

@sachaudh

@sachaudh sachaudh commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Description

Jira: ROX-37315

Backport PR #23107 to release-4.10. Image-only exclusions currently cause Build and Deploy policies to skip all deployment checks. The fix keeps deploy-time detection and entity policy lists active while image exclusions continue to apply at Build.

  • Guard deployment and audit-event exclusion matching against image-only exclusions.
  • Carry the regression tests, adapting them to the 4.10 matcher and detection APIs.
  • Add the behavior notice to the next-release changelog.

Deployment exclusions remain the way to exempt deployments. Applying image exclusions at Deploy would change their documented Build-only behavior.

Release timing: Please have the 4.10 release engineer choose the patch cycle before merging this draft. Its presence does not request inclusion in a candidate already under validation.

User-facing documentation

Testing and quality

  • the change is production ready: the change is GA, or otherwise the functionality is gated by a feature flag
  • CI results are inspected

Automated testing

  • added unit tests
  • added e2e tests
  • added regression tests
  • added compatibility tests
  • modified existing tests

How I validated my change

  • Passed go test ./central/policy/matcher ./pkg/detection ./pkg/detection/deploytime on release-4.10.
  • No UI code changed. The matcher test covers policy visibility for deployments, namespaces, and clusters.

Backport PR #23107 to release-4.10 so secured clusters on this stream regain deploy-time checks. Adapt the fix and regression tests to the older matcher API, and document the behavior change for the next release.

(cherry picked from commit 7fdaba1)
Signed-off-by: Saif Chaudhry <schaudhr@redhat.com>
@sachaudh sachaudh added backport PR to backport changes from master to release branch ai-assisted labels Oct 2, 2026
@openshift-ci

openshift-ci Bot commented Oct 2, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@rhacs-bot

Copy link
Copy Markdown
Contributor

Images are ready for the commit at f738f97.

To use with deploy scripts, first export MAIN_IMAGE_TAG=4.10.10-rc.0-4-gf738f97b3b.

@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 49.48%. Comparing base (e646d42) to head (f738f97).

Additional details and impacted files
@@               Coverage Diff                @@
##           release-4.10   #23212      +/-   ##
================================================
- Coverage         49.48%   49.48%   -0.01%     
================================================
  Files              2662     2666       +4     
  Lines            201272   201352      +80     
================================================
+ Hits              99597    99635      +38     
- Misses            94227    94258      +31     
- Partials           7448     7459      +11     
Flag Coverage Δ
go-unit-tests 49.48% <100.00%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted area/central backport PR to backport changes from master to release branch do-not-merge/work-in-progress

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants