ROB-2714 default crd - #1243
ROB-2714 default crd#1243
Conversation
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
WalkthroughThis pull request tightens RBAC security by replacing wildcard resource permissions with explicit, enumerated resource lists across multiple Kubernetes API groups (monitoring, argoproj, flux, kafka, keda, crossplane, istio, gateway, velero, external-secrets) in the Holmes Helm chart. Documentation and configuration values are updated to reflect external-secrets support. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested reviewers
Pre-merge checks❌ Failed checks (1 inconclusive)
✅ Passed checks (2 passed)
📜 Recent review detailsConfiguration used: Organization UI Review profile: CHILL Plan: Pro 📒 Files selected for processing (3)
🧰 Additional context used📓 Path-based instructions (1)docs/**/*.md📄 CodeRabbit inference engine (CLAUDE.md)
Files:
🧠 Learnings (3)📓 Common learnings📚 Learning: 2025-12-25T11:30:26.515ZApplied to files:
📚 Learning: 2025-12-25T11:30:26.515ZApplied to files:
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
🔇 Additional comments (4)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 0
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
helm/holmes/templates/holmesgpt-service-account.yaml (1)
322-396: Addpushsecretsto the External Secrets resources for completeness.The external-secrets.io section is missing
pushsecrets, which is an official CRD in the external-secrets operator. Following the comprehensive approach of other sections (Istio, Gateway API, Velero), add it to the resource list:{{- if .Values.crdPermissions.externalSecrets }} - apiGroups: - external-secrets.io resources: - externalsecrets - secretstores - clustersecretstores - clusterexternalsecrets - pushsecrets verbs: - get - list - watch {{- end }}
📜 Review details
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (3)
docs/data-sources/permissions.mdhelm/holmes/templates/holmesgpt-service-account.yamlhelm/holmes/values.yaml
🧰 Additional context used
📓 Path-based instructions (1)
docs/**/*.md
📄 CodeRabbit inference engine (CLAUDE.md)
When writing MkDocs documentation, always add a blank line between headers/bold text and lists to ensure proper rendering
Files:
docs/data-sources/permissions.md
🧠 Learnings (3)
📓 Common learnings
Learnt from: CR
Repo: HolmesGPT/holmesgpt PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-25T11:30:26.515Z
Learning: Applies to holmes/plugins/toolsets/**/kubernetes* : RBAC permissions must be respected for Kubernetes access
📚 Learning: 2025-12-25T11:30:26.515Z
Learnt from: CR
Repo: HolmesGPT/holmesgpt PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-25T11:30:26.515Z
Learning: Applies to holmes/plugins/toolsets/**/kubernetes* : RBAC permissions must be respected for Kubernetes access
Applied to files:
docs/data-sources/permissions.mdhelm/holmes/templates/holmesgpt-service-account.yaml
📚 Learning: 2025-12-25T11:30:26.515Z
Learnt from: CR
Repo: HolmesGPT/holmesgpt PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-25T11:30:26.515Z
Learning: Applies to tests/llm/**/*.{yaml,yml} : Use ALWAYS use Secrets for scripts in Kubernetes manifests, not inline manifests or ConfigMaps, to prevent code visibility with kubectl describe
Applied to files:
docs/data-sources/permissions.mdhelm/holmes/values.yaml
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
- GitHub Check: build (3.11)
- GitHub Check: build (3.12)
- GitHub Check: build (3.10)
- GitHub Check: llm_evals
- GitHub Check: build
🔇 Additional comments (4)
docs/data-sources/permissions.md (1)
24-24: Documentation updated correctly for externalSecrets.The addition of
externalSecrets: trueto both the Holmes and Robusta Helm Chart examples is consistent with the changes invalues.yamland the RBAC template. The MkDocs formatting follows the coding guidelines with proper spacing between headers and lists.Also applies to: 41-41
helm/holmes/templates/holmesgpt-service-account.yaml (2)
188-209: Excellent security improvement: Prometheus CRDs now use explicit resource lists.Replacing wildcard permissions with explicit resource lists follows least-privilege principles. The comprehensive list covers alertmanagers, prometheuses, prometheusagents, thanosrulers, and related monitoring resources with appropriate read-only verbs.
210-320: LGTM! Comprehensive CRD permissions for Argo, Flux, Kafka, KEDA, and Crossplane.The explicit resource lists for each operator are well-structured:
- Argo: Covers CD, Workflows, Rollouts, and Events resources
- Flux: Properly separates source, kustomize, helm, and notification toolkit API groups
- Kafka (Strimzi): Includes all major Kafka CRDs
- KEDA: Covers scaled objects/jobs and trigger authentications
- Crossplane: Separates pkg and apiextensions groups appropriately
All use read-only verbs consistent with HolmesGPT's analysis requirements.
helm/holmes/values.yaml (1)
42-43: LGTM. New CRD permission flags added consistently.The addition of
veleroandexternalSecretspermission flags aligns with the corresponding RBAC rules in the service account template. These permissions are read-only (get, list, watch verbs only) and remain individually toggleable via the crdPermissions section. This design is documented in the permissions guide as the intended default behavior.
|
Dev Docker images are ready for this commit: Use this tag to pull the image for testing. gcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:2556bd1
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:2556bd1 me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:2556bd1
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:2556bd1Patch Helm values in one line (choose the chart you use):
helm upgrade --install holmesgpt ./helm/holmes \
--set registry=me-west1-docker.pkg.dev/robusta-development/development \
--set image=holmes-dev:2556bd1
helm upgrade --install robusta robusta/robusta \
--reuse-values \
--set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
--set holmes.image=holmes-dev:2556bd1 |
Results of HolmesGPT evals
Legend
|
Signed-off-by: Roi Glinik <groi.tech@gmail.com> Co-authored-by: arik <alon.arik@gmail.com> Signed-off-by: Filip Grebowski <grebowskifilip@gmail.com>
Summary by CodeRabbit
Bug Fixes / Security Improvements
New Features
✏️ Tip: You can customize this high-level summary in your review settings.