Repository navigation
Fix: Pin injected AuthBridge images to cortex v0.7.0-alpha.10 - #535
Conversation
Moves the four injected AuthBridge sidecar images from cortex
v0.7.0-alpha.3 to v0.7.0-alpha.10 ahead of the operator
v0.4.0-alpha.1 release.
All three pin sites move together:
* charts/operator/values.yaml (defaults.images.*) — what the chart
ships.
* operator/internal/webhook/config/defaults.go — the compiled
fallbacks that loader.go overlays the platform-config ConfigMap
on top of, so a no-ConfigMap deploy still injects a pinned tag.
* operator/test/e2e/e2e_suite_test.go (sidecarImages) — the images
pulled and loaded into Kind, so e2e exercises what the chart
actually ships.
release.yml's "injected AuthBridge images must be version-pinned"
guard only validates the first two. Leaving the e2e list behind
would pass that guard while e2e silently tested the older sidecars,
which is the drift its own comment warns against.
cortex v0.7.0-alpha.10 is tagged and all four images are published
and verified pullable from ghcr.io.
Signed-off-by: cwiklik <cwiklikj@gmail.com>
huang195
left a comment
There was a problem hiding this comment.
Verified the pin move end-to-end. Every factual claim in the description checks out; only nits below.
What I verified independently
v0.7.0-alpha.10exists and is the newestv0.7.0cortex tag.- All four images (
authbridge-envoy,authbridge,authbridge-lite,proxy-init) carry that tag on ghcr, so "published and verified pullable" holds. - No pin site was missed.
v0.7.0-alpha.3appears in exactly three files onmain, and all three are in this diff. The other two files referencingghcr.io/rossoctl/cortexare not pin sites:operator/test/e2e/README.mdis version-agnostic, andtransparent_inbound_test.go:553's:latestis a fixture input for a pre-existing init container, not an image that gets pulled. - The
release.ymlguard reasoning is accurate: it validatesvalues.yaml(loop over the four keys) anddefaults.go(grep), and note2e_suite_test.go— so including the e2e list here is the right call. The unanchored regex:v[0-9]+\.[0-9]+\.[0-9]+does match:v0.7.0-alpha.10.
An upside worth stating explicitly
This bump crosses cortex alpha.8, which is where proxy-init's egress guard broke in-cluster DNS on OpenShift: the CLUSTER_CIDRS default of 10.0.0.0/8 excluded OCP's 172.30/172.31 service network, so UDP/53 to the resolver hit the terminal DROP. By alpha.10 that is fixed — CLUSTER_CIDRS was removed outright and the DNS exemption now follows the pod's /etc/resolv.conf nameservers, which is cluster-agnostic. The operator is already aligned: container_builder_test.go:327 asserts enforce-redirect must not set CLUSTER_CIDRS.
So this carries an OpenShift fix rather than risking a regression. The corollary is that Kind e2e cannot validate that half — Kind's service net (10.96/16) sits inside the old 10/8 default, which is why the original bug survived CI. Worth one OCP/HyperShift run before cutting v0.4.0-alpha.1.
Nit, not blocking: the test-plan's first checkbox can't be satisfied by this PR — release.yml runs on tag push, not on PRs. The gate that actually runs here is the copy at .github/workflows/security-scans.yaml:156, which mirrors the same two-file scope.
Approving. I'd let the pending E2E go green before merge, since it's the only check that exercises the alpha.10 sidecars.
| "ghcr.io/rossoctl/cortex/authbridge-envoy:v0.7.0-alpha.10", | ||
| "ghcr.io/rossoctl/cortex/authbridge:v0.7.0-alpha.10", | ||
| "ghcr.io/rossoctl/cortex/authbridge-lite:v0.7.0-alpha.10", | ||
| "ghcr.io/rossoctl/cortex/proxy-init:v0.7.0-alpha.10", |
There was a problem hiding this comment.
nit (pre-existing, and this PR is the natural place to fix it): operator/test/e2e/README.md:18 describes this list as pulling authbridge-envoy, proxy-init, and spiffe-helper — which no longer matches. spiffe-helper isn't pulled separately (it's bundled into the combined images, as config/defaults.go's own comments note), and authbridge and authbridge-lite are missing from the prose. Since the comment just above this list is what keeps it honest against values.yaml, worth realigning the README to the four images actually loaded.
The prose listed authbridge-envoy, proxy-init and spiffe-helper. That predates the combined images: spiffe-helper is no longer pulled on its own (it ships inside authbridge-envoy and authbridge), and authbridge and authbridge-lite were missing from the list entirely. Pre-existing drift, but this is the natural PR to fix it in, since the sidecarImages list it describes is being touched here. Signed-off-by: cwiklik <cwiklikj@gmail.com>
Summary
Moves the four injected AuthBridge sidecar images from cortex
v0.7.0-alpha.3tov0.7.0-alpha.10, ahead of cutting operatorv0.4.0-alpha.1.cortex
v0.7.0-alpha.10is tagged and all four images are published and verified pullable fromghcr.io.Pin sites
All three move together:
charts/operator/values.yaml(defaults.images.*)operator/internal/webhook/config/defaults.goloader.gooverlays the platform-config ConfigMap on top of, so a no-ConfigMap deploy (make deploy,webhook.enable=false) still injects a pinned tagoperator/test/e2e/e2e_suite_test.go(sidecarImages)Note on the e2e list
The version-pinning guard validates only the first two files. Leaving
e2e_suite_test.gobehind would pass that guard while e2e silently exercised the older sidecars — the drift that file's own comment warns against:So this PR changes CI behavior as well as shipped metadata: e2e now loads the alpha.10 sidecars.
Also realigns
operator/test/e2e/README.md, whose prose still describedspiffe-helperas separately pulled and omittedauthbridge/authbridge-lite.What this bump carries
The range crosses cortex
alpha.8, whereproxy-init's egress guard broke in-cluster DNS on OpenShift — aCLUSTER_CIDRSdefault of10.0.0.0/8excluded OCP's 172.30/172.31 service network, so UDP/53 to the resolver hit the terminal DROP.alpha.10removesCLUSTER_CIDRSoutright and derives the DNS exemption from the pod's/etc/resolv.confnameservers. So this is an OpenShift fix, not a regression risk.Caveat: Kind e2e cannot validate that half. Kind's service network (10.96/16) sits inside the old 10/8 default, which is why the original bug survived CI.
Test plan
.github/workflows/security-scans.yaml(Guard — AuthBridge injection images must be version-pinned).release.ymlcarries the same two-file check but only runs on tag push, so it is not exercised here.v0.4.0-alpha.1, to cover the DNS path Kind structurally cannot