Skip to content

CLDYCON-7039: Add rbac.clusterRole.allowKubeProxy#334

Merged
alexsouthard merged 2 commits intomasterfrom
CLDYCON-7039-nodes-proxy
Mar 10, 2026
Merged

CLDYCON-7039: Add rbac.clusterRole.allowKubeProxy#334
alexsouthard merged 2 commits intomasterfrom
CLDYCON-7039-nodes-proxy

Conversation

@alexsouthard
Copy link
Contributor

@alexsouthard alexsouthard commented Mar 6, 2026

What does this PR do?

Adds a value to the helm chart which wraps the "nodes/proxy" permission to address an unaddressed vulnerability

Where should the reviewer start?

Should be relatively small, just a test on the helm chart install/node retrieval process

How should this be manually tested?

Must be using the helm chart to deploy

Any background context you want to provide?

Kubernetes has (at the time) said this is working as intended, so we need to add a fix

What picture best describes this PR (optional but encouraged)?

image

What are the relevant Github Issues?

Developer Done List

  • Tests Added/Updated
  • Updated README.md
  • Verified backward compatible
  • [] Verified database migrations will not be catastrophic
  • Considered Security, Availability and Confidentiality

For the Reviewer:

By approving this PR, the reviewer acknowledges that they have checked all items in this done list.

Reviewer/Approval Done List

  • Tests Pass Locally
  • CI Build Passes
  • Verified README.md is updated
  • Verified changes are backward compatible
  • Reviewed impact to Security, Availability and Confidentiality (if issue found, add comments and request changes)

Copy link
Contributor

@troy-chuang troy-chuang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@alexsouthard alexsouthard merged commit 11f7ff2 into master Mar 10, 2026
7 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants