Skip to content

feat: integrate odh-notebook-controller with cluster TLS profile - #836

Merged
jstourac merged 1 commit into
opendatahub-io:mainfrom
ugiordan:RHOAIENG-67672-67673-tls-profile
Jun 19, 2026
Merged

jstourac merged 1 commit into
opendatahub-io:mainfrom
ugiordan:RHOAIENG-67672-67673-tls-profile

Conversation

@ugiordan

@ugiordan ugiordan commented Jun 11, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Integrate controller-runtime-common/pkg/tls TLS profile support into odh-notebook-controller
  • Fetch the cluster APIServer TLS profile at startup (OpenShift only, fail closed on unexpected errors)
  • Apply profile-driven cipher suites and TLS version to webhook and metrics servers
  • Set explicit MinVersion=TLS12 fallback for non-OpenShift clusters
  • Register SecurityProfileWatcher to restart on profile changes
  • Set NextProtos (ALPN) for HTTP/2 support on all TLS endpoints
  • Add RBAC for config.openshift.io/apiservers (get/list/watch)
  • Bump controller-runtime to v0.23.3 (required by controller-runtime-common)

Motivation

OCP 5.0 (GA October 2026) requires all components to honor the centralized TLS profile (OCPSTRAT-2611).

Reference: openshift/cluster-machine-approver #286

Test plan

  • go build ./... passes
  • gofmt clean
  • RBAC manifests regenerated and committed
  • Existing unit tests pass
  • Deploy on OpenShift cluster with Intermediate profile
  • CI green

Ref: RHOAIENG-67673

@openshift-ci
openshift-ci Bot requested review from jesuino and jstourac June 11, 2026 11:17
@coderabbitai

coderabbitai Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR updates Kubernetes/controller-runtime and OpenShift API dependency versions in both notebook-controller and odh-notebook-controller. The webhook registration refactors from fluent chaining to direct argument passing. RBAC permissions are expanded to allow config.openshift.io/apiservers access. The odh-notebook-controller main bootstraps the OpenShift TLS security profile at startup, derives TLS options with explicit NextProtos, applies them to metrics and webhook servers, and registers a SecurityProfileWatcher that cancels the manager context to trigger graceful reload on profile changes. The Notebook CRD schema is extended across all versioned sections with fileKeyRef environment variable sources, restartPolicyRules for container restarts, hostnameOverride for pods, workloadRef for workload identification, and podCertificate for projected volume sources.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~50 minutes

Supply Chain & Security Observations

Dependency Updates (CWE-1324: Weak Supply Chain)

  • Kubernetes/controller-runtime version bumps (v0.33.7 → v0.35.0, v0.21.0 → v0.23.3) and introduction of github.com/openshift/controller-runtime-common as direct requirement are supply-chain entry points. Run CVE/GHSA scans on all k8s.io.\, sigs.k8s.io.\, and github.com/openshift.\* modules before merge. Check go.sum integrity and validate no checksums diverge from trusted sources. Verify structured-merge-diff migration from v4 → v6 does not introduce regressions (breaking schema compatibility is a risk).

Local Replace Directive (CWE-494: Supply Chain)

  • odh-notebook-controller/go.mod adds replace github.com/kubeflow/kubeflow/components/notebook-controller => ../notebook-controller. Confirm this is development-only and never leaks into production builds or container images. CI must reject local replaces in published artifacts.

TLS/Crypto Configuration (CWE-295: Improper Certificate Validation)

  • Bootstrap reads OpenShift API server TLS profile; fallback hardcodes intermediate ciphers + TLS 1.2. Risks: (1) fallback ciphers may be outdated, (2) hardcoded NextProtos could enable weak protocols if misconfigured, (3) bootstrap failure exits immediately (no graceful degradation). Audit cipher suite strength (consult NIST/OWASP TLS guidelines). Verify NextProtos cannot downgrade to SSL/TLS < 1.2. Test fallback path (profile unavailable/404) and ensure no secrets leak in error logs.

SecurityProfileWatcher Context Cancellation (CWE-400: Uncontrolled Resource Consumption)

  • Watcher cancels manager context on every TLS profile change. Risk: rapid profile mutations (transient API glitches, misconfigured policies) could trigger restart loops, exhausting resources or causing DoS. Add debounce/hysteresis on profile changes and implement exponential backoff. Monitor watcher for excessive cancellations.

RBAC Expansion (CWE-276: Incorrect Default Permissions)

  • New RBAC rules grant get/list/watch on config.openshift.io/apiservers. Audit the APIServer schema—ensure no sensitive fields (credentials, keys, secrets) are readable via this resource. Confirm least privilege: is read-only access sufficient, or can access be further scoped (e.g., specific apiserver names)?
🚥 Pre-merge checks | ✅ 8 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Contribution Quality And Spam Detection ⚠️ Warning Two signals from different categories present: (1) CRD schema lacks enum/maxItems constraints on restartPolicyRules fields (CWE-20, pre-existing but propagated), (2) New TLS profile fetch/SecurityP... Add enum/maxItems constraints to CRD restartPolicyRules schema; add unit tests for TLS profile bootstrap, SecurityProfileWatcher, and error paths in main_test.go.
No Sensitive Data In Logs ⚠️ Warning Lines 185 and 198 in components/odh-notebook-controller/main.go log full error objects from Kubernetes API operations that may contain kubeconfig paths, API server addresses, or credentials (CWE-532). Redact error details: use setupLog.Error(err, msg) only for errors guaranteed non-sensitive; wrap sensitive errors with custom error types that exclude paths/credentials from logging.
✅ Passed checks (8 passed)
Check name Status Explanation
Title check ✅ Passed Title directly reflects the main change: integrating TLS profile support into the odh-notebook-controller, which is the primary objective across all modified files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No Hardcoded Secrets ✅ Passed Comprehensive scan of all modified files found no hardcoded secrets, API keys, tokens, passwords, private keys, long base64 strings with credential content, URLs with embedded credentials, or known...
No Weak Cryptography ✅ Passed No weak cryptography detected. PR uses only strong TLS cipher suites (ECDHE+AES-GCM/ChaCha20), enforces TLS 1.2+ minimum, includes no banned primitives (MD5, SHA1, DES, RC4, 3DES, Blowfish, ECB), i...
No Injection Vectors ✅ Passed No injection vectors detected. Code does not use SQL concatenation, shell execution with user input, eval/exec on untrusted data, unsafe deserialization, or dangerouslySetInnerHTML patterns. TLS pr...
No Privileged Containers ✅ Passed No privileged container configurations detected. Dockerfiles use multi-stage builds: USER root only in builder stage (build-time), final runtime stage uses non-root USER 1001:0. Kubernetes manifest...
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 11, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@ugiordan
ugiordan force-pushed the RHOAIENG-67672-67673-tls-profile branch from 604e2d6 to 5a6738c Compare June 11, 2026 11:21
@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 11, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@codecov-commenter

codecov-commenter commented Jun 11, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 63.16%. Comparing base (e242bdb) to head (f2d91be).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #836      +/-   ##
==========================================
- Coverage   63.36%   63.16%   -0.21%     
==========================================
  Files          15       15              
  Lines        2962     2962              
==========================================
- Hits         1877     1871       -6     
- Misses        899      903       +4     
- Partials      186      188       +2     
Flag Coverage Δ
odh-notebook-controller 72.57% <ø> (-0.28%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
...book-controller/controllers/notebook_controller.go 58.51% <ø> (-1.49%) ⬇️
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (2)
components/odh-notebook-controller/main.go (2)

186-188: 💤 Low value

NextProtos override silently discards profile's protocol preferences.

Lines 186-188 unconditionally set NextProtos = ["h2", "http/1.1"] after the profile-based TLS config is applied. This overwrites any NextProtos directives from the TLS profile, which could surprise operators who expect the profile to control all TLS settings.

While the chosen protocols (h2, http/1.1) are appropriate for Kubernetes webhook and metrics servers, the silent override should be documented:

// Force h2 and http/1.1 for webhook/metrics compatibility, overriding profile settings
tlsOpts = append(tlsOpts, func(c *tls.Config) {
	c.NextProtos = []string{"h2", "http/1.1"}
})
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@components/odh-notebook-controller/main.go` around lines 186 - 188, The code
unconditionally overwrites TLS NextProtos by appending a tlsOpts function that
sets c.NextProtos = []string{"h2","http/1.1"}, which silently discards any
profile-provided NextProtos; change this to either preserve profile preferences
or make the override explicit and documented: update the tlsOpts append (the
function that mutates tls.Config.NextProtos) to check for an existing NextProtos
in the config and only set it when empty, or add a clear comment above the
append explaining that NextProtos is intentionally forced for webhook/metrics
compatibility (mentioning NextProtos, tlsOpts and tls.Config to locate the
code).

168-169: 💤 Low value

Bootstrap timeout of 10 seconds may be insufficient in slow environments.

In resource-constrained clusters or during initial cluster startup, the API server may take longer than 10 seconds to respond. This would trigger fallback to implicit defaults (see prior comment) when the profile is actually available.

Consider making the timeout configurable via flag:

flag.DurationVar(&bootstrapTimeout, "tls-profile-fetch-timeout", 10*time.Second,
	"Timeout for fetching OpenShift TLS profile during startup")
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@components/odh-notebook-controller/main.go` around lines 168 - 169, Replace
the hardcoded 10s context timeout used in context.WithTimeout (bootstrapCtx,
bootstrapCancel := context.WithTimeout(context.Background(), 10*time.Second))
with a configurable flag variable (e.g., bootstrapTimeout) so the TLS profile
fetch timeout can be tuned; add a package-level or main-local variable
bootstrapTimeout and register it with flag.DurationVar(&bootstrapTimeout,
"tls-profile-fetch-timeout", 10*time.Second, "Timeout for fetching OpenShift TLS
profile during startup"), ensure flag.Parse() runs before using
bootstrapTimeout, then call context.WithTimeout(context.Background(),
bootstrapTimeout) and keep defer bootstrapCancel() as before.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@components/odh-notebook-controller/go.mod`:
- Line 97: The replace directive currently pointing the module
github.com/kubeflow/kubeflow/components/notebook-controller at a local
filesystem path must be removed and replaced with a versioned reference to
ensure integrity and reproducible builds; update the go.mod replace for the
module github.com/kubeflow/kubeflow/components/notebook-controller to reference
a specific published version or a pseudo-version that includes the commit SHA
(or switch to a fork with a tagged release) so the dependency has a verifiable
checksum in go.sum and cannot be silently substituted by local files.

In `@components/odh-notebook-controller/main.go`:
- Around line 176-178: When the TLS profile fetch fails (the err != nil branch),
explicitly set a hardened fallback TLS configuration instead of relying on
implicit Go defaults: update the err != nil block (where setupLog.Info is
called) to append a tls.Options setter to tlsOpts that sets c.MinVersion =
tls.VersionTLS12 and a conservative CipherSuites list (e.g., ECDHE AES-GCM
suites), and adjust the log to say "using hardened defaults"; reference tlsOpts
and the err != nil branch in main.go to locate where to add this fallback.
- Around line 298-314: The TLS profile watcher currently calls cancel()
immediately in tlspkg.SecurityProfileWatcher.OnProfileChange which can cause
restart storms; modify the OnProfileChange handler to debounce restarts (e.g.,
start or reset a single timer/AfterFunc for ~30s) and only call cancel() when
that timer fires, ensuring you guard the timer with a small mutex or an atomic
flag to avoid concurrent timers; update the handler attached to
watcher.SetupWithManager(mgr) so rapid successive profile changes reset the
debounce timer instead of immediately calling cancel().
- Around line 164-189: The OpenShift TLS profile returned by
tlspkg.FetchAPIServerTLSProfile is used directly in
tlspkg.NewTLSConfigFromProfile (building tlsOpts) without validating minimum TLS
version, disallowed ciphers, or InsecureSkipVerify/certificate verification
settings; add a validateTLSProfile(profile) helper and call it after
FetchAPIServerTLSProfile and before NewTLSConfigFromProfile to enforce:
MinTLSVersion is TLS1.2 or TLS1.3, profile.Ciphers does not include
NULL/EXPORT/MD5/SHA1/RC4/3DES patterns, and any settings that would disable
certificate verification (e.g., InsecureSkipVerify) are rejected; on validation
failure log via setupLog.Error and fall back to secure defaults (do not append
tlsConfigFn) so the webhook/metrics servers never run with an insecure profile.

---

Nitpick comments:
In `@components/odh-notebook-controller/main.go`:
- Around line 186-188: The code unconditionally overwrites TLS NextProtos by
appending a tlsOpts function that sets c.NextProtos = []string{"h2","http/1.1"},
which silently discards any profile-provided NextProtos; change this to either
preserve profile preferences or make the override explicit and documented:
update the tlsOpts append (the function that mutates tls.Config.NextProtos) to
check for an existing NextProtos in the config and only set it when empty, or
add a clear comment above the append explaining that NextProtos is intentionally
forced for webhook/metrics compatibility (mentioning NextProtos, tlsOpts and
tls.Config to locate the code).
- Around line 168-169: Replace the hardcoded 10s context timeout used in
context.WithTimeout (bootstrapCtx, bootstrapCancel :=
context.WithTimeout(context.Background(), 10*time.Second)) with a configurable
flag variable (e.g., bootstrapTimeout) so the TLS profile fetch timeout can be
tuned; add a package-level or main-local variable bootstrapTimeout and register
it with flag.DurationVar(&bootstrapTimeout, "tls-profile-fetch-timeout",
10*time.Second, "Timeout for fetching OpenShift TLS profile during startup"),
ensure flag.Parse() runs before using bootstrapTimeout, then call
context.WithTimeout(context.Background(), bootstrapTimeout) and keep defer
bootstrapCancel() as before.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 57e7e600-e30b-4246-bdb7-4ffe59af6ebd

📥 Commits

Reviewing files that changed from the base of the PR and between 6b8377f and 604e2d6.

⛔ Files ignored due to path filters (2)
  • components/notebook-controller/go.sum is excluded by !**/*.sum, !**/*.sum
  • components/odh-notebook-controller/go.sum is excluded by !**/*.sum, !**/*.sum
📒 Files selected for processing (5)
  • components/notebook-controller/api/v1beta1/notebook_webhook.go
  • components/notebook-controller/go.mod
  • components/odh-notebook-controller/controllers/notebook_controller.go
  • components/odh-notebook-controller/go.mod
  • components/odh-notebook-controller/main.go

Comment thread components/odh-notebook-controller/go.mod
Comment thread components/odh-notebook-controller/main.go
Comment thread components/odh-notebook-controller/main.go Outdated
Comment thread components/odh-notebook-controller/main.go
@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 11, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 11, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@ugiordan
ugiordan force-pushed the RHOAIENG-67672-67673-tls-profile branch from 60a7e33 to 7cadeea Compare June 11, 2026 12:18
@openshift-ci openshift-ci Bot removed the size/l label Jun 11, 2026
@ugiordan ugiordan changed the title feat: integrate notebook controllers with central TLS profile for OCP 5.0 compliance feat: integrate odh-notebook-controller with central TLS profile Jun 11, 2026
@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 11, 2026
@openshift-ci openshift-ci Bot added the size/xl label Jun 18, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@ugiordan
ugiordan force-pushed the RHOAIENG-67672-67673-tls-profile branch from 7e68e35 to a7b58dc Compare June 18, 2026 10:49
@openshift-ci openshift-ci Bot added size/xl and removed size/xl labels Jun 18, 2026

@jstourac jstourac left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this. I put some comments and replied to the ones from coderabbitai.

Do you plan to rebase this against main so that only true changes brought in by this PR are shown here?

Comment thread components/odh-notebook-controller/go.mod
Comment thread components/odh-notebook-controller/main.go
Comment thread components/odh-notebook-controller/main.go
Comment thread components/odh-notebook-controller/main.go Outdated
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@ugiordan
ugiordan force-pushed the RHOAIENG-67672-67673-tls-profile branch from a7b58dc to 4931cd0 Compare June 18, 2026 11:11
@openshift-ci openshift-ci Bot added size/xl and removed size/xl labels Jun 18, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@ugiordan
ugiordan force-pushed the RHOAIENG-67672-67673-tls-profile branch from 4931cd0 to 8bd8822 Compare June 18, 2026 14:51
@openshift-ci openshift-ci Bot removed the size/xl label Jun 18, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

1 similar comment
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

Comment thread components/odh-notebook-controller/go.mod Outdated
Read the cluster TLS profile from apiservers.config.openshift.io/cluster
at startup. Apply MinVersion, CipherSuites, and NextProtos to webhook
and metrics server TLS configs. Fail closed on unexpected errors.
Use Intermediate defaults on non-OpenShift clusters.

Signed-off-by: Ugo Giordano <ugiordan@redhat.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Ugo Giordano <ugiordan@redhat.com>
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@jstourac

jstourac commented Jun 19, 2026 •

Copy link
Copy Markdown
Member

I just tried on my OCP 4.21.18 cluster. I installed a very recent RHOAI 3.5.0-ea.2 nightly build and updated the operator CSV so that it incorporates nbc builds from this PR:

quay.io/opendatahub/kubeflow-notebook-controller:odh-pr-836
quay.io/opendatahub/odh-notebook-controller:odh-pr-836

I also added apiservers resource for the config.openshift.io apiGroup in the odh-notebook-controller-manager-role clusterrole (annotation opendatahub.io/managed="false" has to be set).

Then the odh-kf-notebook-controller seem to work just fine and nothing extraordinary is seen in its log.
The odh-notebook-controller seem to be also happy without any problem. I tried to create a workbench. Stop it and start it again. All seem good.

I haven't noticed any specific error with regards the events as was identified by the cursor dependency bump analysis shared above. So, hopefully this is good too (though, I don't have OCP 4.19 cluster at the moment!).

@jstourac jstourac left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @ugiordan . Let's try to get this in so it's part of the EA2.

/lgtm
/approve

@openshift-ci

openshift-ci Bot commented Jun 19, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jstourac

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ugiordan

Copy link
Copy Markdown
Member Author

FTR - cursors assessment for the dependency bumps and ocp4.19 compatibility - IMHO only Risk 2 is worth to check and verify:

Dependency Compatibility Analysis: OpenShift 4.19

OpenShift 4.19 ships Kubernetes 1.32. Here's the version mapping:

Dependency main branch This PR K8s equivalent OCP 4.19 target
k8s.io/* v0.33.7 v0.35.2 k8s 1.35 k8s 1.32
controller-runtime v0.21.0 v0.23.3 k8s 1.35 k8s 1.32
The main branch was already 1 minor version ahead (k8s 1.33 vs 1.32). This PR bumps it to 3 minor versions ahead (k8s 1.35 vs 1.32).

Risk 1 (MEDIUM): Misleading go.mod comment

The comment on line 15 says:

	// Used versions of Kubernetes API that are compatible with what OpenShift 4.19 is based on.

This is misleading. k8s.io v0.35.x targets Kubernetes 1.35, not 1.32. The client-go compatibility matrix labels this as +-, meaning:

  • + client-go may have APIs/features the OCP 4.19 cluster doesn't support
  • - the cluster may have features the client can't use

For the stable resources this controller uses (Pods, ConfigMaps, Secrets, Routes, Notebooks CRD, etc.), this is generally safe. But the comment should be updated to accurately reflect the version and the reason for the skew.

Risk 2 (HIGH): Events API migration in controller-runtime v0.23

This is the most concrete regression risk I found. controller-runtime v0.23 has this breaking change:

Events: Migration to the new events API. Using the new GetEventRecorderFor requires updating your rbac for events to use the events.k8s.io apiGroup rather than the "" (core) apiGroup.

The controller uses mgr.GetEventRecorderFor():

		EventRecorder: mgr.GetEventRecorderFor("odh-notebook-controller"),

But the RBAC marker is still set to the core API group:

// +kubebuilder:rbac:groups="",resources=events,verbs=create;patch

And the generated role.yaml only grants events access under "":

- apiGroups:
  - ""
  resources:
  - events
  verbs:
  - create
  - patch

With controller-runtime v0.23, GetEventRecorderFor now creates events.k8s.io/v1 Events instead of core/v1 Events. Without the RBAC update, the controller will get permission denied when trying to emit events (e.g., the MLflowClusterRolePending warning event in notebook_mlflow.go). CI may pass because envtest typically doesn't enforce RBAC, but this would fail in a real cluster.

Fix needed: The RBAC marker should be updated to:

// +kubebuilder:rbac:groups=events.k8s.io,resources=events,verbs=create;patch

And the RBAC manifests should be regenerated.

Risk 3 (LOW): structured-merge-diff v4 to v6

This is a major version change (sigs.k8s.io/structured-merge-diff/v4 → v6). While it's an indirect dependency, it underpins how controller-runtime handles server-side apply and strategic merge patches internally. This has been well-tested upstream but is worth noting as a potential source of subtle behavioral differences in how objects are patched.

Risk 4 (LOW): PriorityQueue enabled by default

controller-runtime v0.23 enables the priority queue by default. Reconciliation items are now processed by priority (with FIFO within the same priority) rather than pure FIFO. This won't cause bugs but could change the order in which notebooks are reconciled under load.

Risk 5 (LOW): gogo/protobuf removal

The PR drops github.com/gogo/protobuf because k8s.io v0.35 completed the migration to standard google/protobuf. This transition has been extensively tested upstream, but it changes the serialization path for all Kubernetes API objects.

Summary

Risk Severity Action
Events RBAC mismatch HIGH RBAC marker must be updated + manifests regenerated
Misleading go.mod comment MEDIUM Update comment to reflect actual version and rationale
3-version k8s skew (1.35 vs 1.32) LOW-MEDIUM Acceptable for stable APIs used, but should be acknowledged
structured-merge-diff v4→v6 LOW Transitive, well-tested upstream
PriorityQueue default change LOW No action needed, behavioral only
gogo/protobuf removal LOW No action needed, transparent
The Events RBAC issue is the most actionable finding -- it would cause runtime failures on a real cluster when the controller tries to emit Kubernetes events.

Great analysis, thanks.

Risk 1 (go.mod comment): Fixed.

Risk 2 (Events RBAC): Verified, not an issue for us. We call GetEventRecorderFor() which returns a deprecatedRecorder that still uses core/v1 Events via corev1.EventSource. The new events.k8s.io API is only used by GetEventRecorder() (without "For"), which we don't call. Current RBAC is correct.

Risks 3-5: All transitive from the CR v0.23.3 bump. structured-merge-diff v6, gogo/protobuf removal, and PriorityQueue default are all pulled in by CR v0.23.3 and k8s v0.35. We don't configure any custom queue settings and don't directly depend on gogo/protobuf. Nothing actionable on our side.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants