Skip to content

feat(operator): Add explicit manifest workload security profiles - #381

Draft
casey-coreweave wants to merge 1 commit into
mainfrom
cabernathy/cis-wb-004-security-profile-refresh
Draft

casey-coreweave wants to merge 1 commit into
mainfrom
cabernathy/cis-wb-004-security-profile-refresh

Conversation

@casey-coreweave

@casey-coreweave casey-coreweave commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Server images differ in whether they support non-root execution and a read-only
root filesystem. Add an explicit per-application and per-migration server-manifest
contract so Core can select compatible workloads without changing older releases
based on their version string.

securityProfile.runAsNonRoot and securityProfile.readOnlyRootFilesystem are
optional booleans. Omitted/empty profiles preserve legacy rendering; explicit
false is retained. Application profiles cover all containers and init containers.
Migration profiles apply to newly created Jobs without restarting completed
migrations. No numeric pod identity is introduced.

Application fragments merge profile fields in filename order; later explicit
values win. Migration definitions retain their existing whole-entry replacement
semantics. Documentation includes examples, rollback behavior, and image/runtime
requirements. Current Watchtower triage fields and baseline contexts are preserved.

Validation:

  • Clean-main manifest/reconciler baseline passed.
  • Focused tests cover omission, empty/partial profiles, explicit false, conflicting
    fragments, sizing merge, version independence, single/multiple/init containers,
    migration rendering, completed migrations, and stable reconciliation/rollback.
  • make test and make build passed, including vet. Chart dependencies were
    resolved locally; no Chart.lock or generated API changes.
  • Current Core manifest plus sizing bundle: all 14 application and 3 migration
    definitions remain unprofiled; application rendering is unchanged across tested
    server versions.

Test output

Selected excerpts from saved validation logs (not a complete log):

$ go test ./pkg/wandb/manifest ./internal/controller/reconciler
ok  github.com/wandb/operator/pkg/wandb/manifest (cached)
ok  github.com/wandb/operator/internal/controller/reconciler 2.217s

# make test — affected-package excerpts; full repository suite passed
ok  github.com/wandb/operator/internal/controller/reconciler (cached) coverage: 43.3% of statements
ok  github.com/wandb/operator/pkg/wandb/manifest (cached) coverage: 46.5% of statements

# make build — final commands; completed successfully
go fmt ./...
go vet ./...
Synced CRDs into internal/crdinstaller/crds/{operator,redis,clickhouse}/
go build -o bin/manager ./cmd/manager
go build -o bin/crd-installer ./cmd/crd-installer

# Current Core manifest + sizing compatibility check
--- PASS: TestCurrentCoreBundleSecurityCompatibility (0.01s)
PASS

# Assertions against captured live resources
PASS: 13 legacy Applications preserve omission; explicit API Application/Deployment/Pod and successful Gorilla migration apply both flags without numeric identities.

# Disposable WESTest explicit-profile scenario
Destroy complete! Resources: 13 destroyed.
[westest] Scenario local-kind-security-profile finished successfully
Explicit operator image load completed: True

Triage *ApplicationTriage `yaml:"triage,omitempty"`
// SecurityProfile opts this workload into security settings supported by
// newer server images. A nil or empty profile preserves legacy behavior.
SecurityProfile *WorkloadSecurityProfile `yaml:"securityProfile,omitempty"`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

would it make sense to make this not be a pointer, since all the values within are pointers it would reduce the amount of nil checks needed, assuming that new values will be added within the struct those might always need explicit behaviors for nil values, it should reduce the complexity abit to remove the outer nil check.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants