Skip to content

Crds read permissions - #1087

Closed
arikalon1 wants to merge 3 commits into
masterfrom
crds-read-permissions
Closed

arikalon1 wants to merge 3 commits into
masterfrom
crds-read-permissions

Conversation

@arikalon1

Copy link
Copy Markdown
Collaborator

No description provided.

Will help to generate the CRDs feature required cluster roles
@arikalon1
arikalon1 requested a review from aantn October 29, 2025 00:12
@coderabbitai

coderabbitai Bot commented Oct 29, 2025 •

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a ClusterRole rule granting list/get on apiextensions.k8s.io/customresourcedefinitions and reorders several Python imports to occur after certificate handling during initialization.

Changes

Cohort / File(s) Summary
Kubernetes RBAC Configuration
helm/holmes/templates/holmesgpt-service-account.yaml
Inserts a ClusterRole rule for apiextensions.k8s.io → customresourcedefinitions with list and get verbs.
Python import reordering (certificate ordering)
holmes/main.py, server.py
Moves imports (e.g., USER_COLOR, json, litellm, sentry_sdk, typing symbols, version helpers) to execute after certificate addition/handling to change initialization/import timing.

Sequence Diagram(s)

sequenceDiagram
  autonumber
  participant Init as Process start
  participant Cert as Certificate setup
  participant Imports as Deferred imports
  participant App as Application runtime

  rect #f0f7ff
    Init->>Cert: perform certificate addition/check
    Cert-->>Init: success/failure
  end

  rect #f7fff0
    Init->>Imports: import USER_COLOR, litellm, sentry_sdk, etc.
    Imports-->>Init: modules loaded (possible side-effects)
  end

  Init->>App: continue initialization and start services
Loading

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

  • Check for potential import-time side effects from newly deferred imports (sentry_sdk, litellm).
  • Verify no circular imports are introduced by moving USER_COLOR and other imports.
  • Confirm the RBAC addition matches cluster naming/convention and provides only intended permissions.

Possibly related PRs

Suggested reviewers

  • moshemorad

Pre-merge checks and finishing touches

❌ Failed checks (1 warning, 1 inconclusive)
Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. You can run @coderabbitai generate docstrings to improve docstring coverage.
Description Check ❓ Inconclusive No pull request description was provided by the author. While the check is intentionally lenient and does not require extensive documentation, the complete absence of a description makes it unclear whether the intent was to omit one entirely or if it was overlooked. The check instructions assume a description exists to evaluate for relevance, making it difficult to conclusively determine whether the criterion of being "related in some way to the changeset" is satisfied when no content is present to evaluate. Consider adding a brief pull request description that explains the motivation behind the CRD read permissions change, any dependencies between the changes in different files, and whether the import modifications in holmes/main.py and server.py are related to this functionality or should be submitted in a separate pull request. This will provide clarity to reviewers and maintain a clear commit history.
✅ Passed checks (1 passed)
Check name Status Explanation
Title Check ✅ Passed The pull request title "Crds read permissions" directly describes the primary functional change in the changeset. The main modification is the addition of RBAC rules in the Helm template to grant read permissions (list and get verbs) for customresourcedefinitions, which aligns precisely with the title. While the PR also includes secondary changes such as import reordering in holmes/main.py and additional imports in server.py, the title appropriately focuses on the most significant functional change and is clear, concise, and specific enough for a developer scanning history to understand the primary intent.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch crds-read-permissions

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 407987a and edc02e9.

📒 Files selected for processing (2)
  • holmes/main.py (1 hunks)
  • server.py (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • holmes/main.py
🧰 Additional context used
📓 Path-based instructions (1)
**/*.py

📄 CodeRabbit inference engine (CLAUDE.md)

**/*.py: Use Ruff for formatting and linting (configured in pyproject.toml) for all Python code
Type hints are required; code should pass mypy (configured in pyproject.toml)
ALWAYS place Python imports at the top of the file, not inside functions or methods

Files:

  • server.py
🧬 Code graph analysis (1)
server.py (1)
holmes/version.py (2)
  • get_version (48-130)
  • is_official_release (40-44)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Pre-commit checks
  • GitHub Check: llm_evals
  • GitHub Check: build

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

aantn
aantn previously approved these changes Oct 29, 2025
@github-actions

Copy link
Copy Markdown
Contributor

Results of HolmesGPT evals

  • ask_holmes: 32/35 test cases were successful, 1 regressions, 1 setup failures
Test suite Test case Status
ask 01_how_many_pods ✅
ask 02_what_is_wrong_with_pod ✅
ask 04_related_k8s_events ✅
ask 05_image_version ✅
ask 09_crashpod ✅
ask 10_image_pull_backoff ✅
ask 110_k8s_events_image_pull ✅
ask 11_init_containers ✅
ask 13a_pending_node_selector_basic ✅
ask 14_pending_resources ✅
ask 15_failed_readiness_probe ✅
ask 17_oom_kill ❌
ask 19_detect_missing_app_details ✅
ask 20_long_log_file_search ✅
ask 24_misconfigured_pvc ✅
ask 24a_misconfigured_pvc_basic ✅
ask 28_permissions_error 🚧
ask 39_failed_toolset ✅
ask 41_setup_argo ✅
ask 42_dns_issues_steps_new_tools ⚠️
ask 43_current_datetime_from_prompt ✅
ask 45_fetch_deployment_logs_simple ✅
ask 51_logs_summarize_errors ✅
ask 53_logs_find_term ✅
ask 54_not_truncated_when_getting_pods ✅
ask 59_label_based_counting ✅
ask 60_count_less_than ✅
ask 61_exact_match_counting ✅
ask 63_fetch_error_logs_no_errors ✅
ask 79_configmap_mount_issue ✅
ask 83_secret_not_found ✅
ask 86_configmap_like_but_secret ✅
ask 93_calling_datadog[0] ✅
ask 93_calling_datadog[1] ✅
ask 93_calling_datadog[2] ✅

Legend

  • ✅ the test was successful
  • :minus: the test was skipped
  • ⚠️ the test failed but is known to be flaky or known to fail
  • 🚧 the test had a setup failure (not a code regression)
  • 🔧 the test failed due to mock data issues (not a code regression)
  • 🚫 the test was throttled by API rate limits/overload
  • ❌ the test failed and should be fixed before merging the PR

@aantn
aantn enabled auto-merge (squash) October 29, 2025 07:54
@arikalon1 arikalon1 closed this Oct 29, 2025
auto-merge was automatically disabled October 29, 2025 08:18

Pull request was closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants