cozystack/hack
Aleksei Sviridkin 3a698e76d3
fix(cozystack-basics): close namespace-host-label-policy CREATE gap
The policy previously only fired on UPDATE and only when oldObject already
carried namespace.cozystack.io/host, which left two paths unguarded:

  - CREATE of a namespace with the label pre-set.
  - UPDATE that adds the label for the first time (oldObject has no label,
    so the matchCondition was false and the VAP was skipped).

Both paths required namespace create/update on labels, which is normally
cluster-admin-only, but the VAP is meant to be the source of truth for
this label's integrity. Close the gap:

  - operations: [CREATE, UPDATE]
  - matchCondition now fires when either object or oldObject carries the
    label (renamed had-host-label -> touches-host-label).
  - oldHost is computed with a null-safe ternary so CREATE (where
    oldObject is null) evaluates cleanly.

The existing validation (newHost == oldHost || trustedCaller) then
naturally denies first-time label writes from non-trusted callers while
still allowing cozy-system / cozy-cert-manager / flux-system / kube-system
SAs to stamp the label during the tenant chart apply.

Update packages/extra/gateway/README.md layer 5 description to match and
add an e2e test that asserts a namespace CREATE with the label from an
untrusted SA is rejected.

Assisted-By: Claude <noreply@anthropic.com>
Signed-off-by: Aleksei Sviridkin <f@lex.la>
2026-04-24 17:04:04 +03:00
..
e2e-apps fix(cozystack-basics): close namespace-host-label-policy CREATE gap 2026-04-24 17:04:04 +03:00
boilerplate.go.txt Introduce cozystack-controller (#560) 2025-01-09 12:24:51 +01:00
cdi_golden_image_create.sh [vm-default-images] Added new optional package 2026-04-14 19:59:19 +05:00
check-host-runtime.bats test(hack): assert sudo prefix in single-service HINTs, explicit exit code, and glob regression 2026-04-11 14:36:58 +03:00
check-host-runtime.sh fix(hack): wrap du in 'timeout 5s' to prevent preflight stall 2026-04-11 17:07:35 +03:00
check-optional-repos.sh Rename cozypkg to cozyhr 2025-12-25 16:54:22 +01:00
check-readiness.sh Added check-readiness.sh script 2026-03-29 13:16:35 +05:00
collect-images.sh [dx] Refactor collect-images functionality 2025-07-03 14:26:56 +03:00
common-envs.mk fix(build): filter git describe to match only v* tags 2026-04-13 14:25:25 +02:00
cozyreport.sh [ci] Cozyreport improvements 2026-02-11 17:09:47 +03:00
cozytest.sh [tests] Add pre-cleanup, fix port-forward race, fix temp leak 2026-03-23 17:25:01 +03:00
download-dashboards.sh Add monitoring for NATs 2026-02-17 22:54:12 +01:00
e2e-install-cozystack.bats feat(gateway): per-tenant Issuer enables child-tenant ACME, VAP unconditional 2026-04-24 17:03:59 +03:00
e2e-prepare-cluster.bats [ci] Run e2e tests on shared runners 2026-01-20 22:13:16 +01:00
e2e-test-openapi.bats [apps] Refactor apiserver to use typed objects and fix UnstructuredList GVK 2025-12-01 22:06:23 +01:00
helm-unit-tests.sh [ci,dx] Add unit tests for cozy-lib 2025-11-19 17:56:17 +03:00
migrate-to-version-1.0.sh Fixed packages name conversion in migration script 2026-03-03 19:10:39 +05:00
package.mk refactor: move scripts to hack directory 2026-01-15 16:06:56 +01:00
pre-checks.sh Fix osx grep have no -P flag (#438) 2024-10-21 11:59:56 +02:00
update-codegen.sh [docs] Fixed controller-gen markers 2026-03-25 15:57:25 +05:00
update-crd.sh refactor(labels): remove cozystack.io/ui label 2026-01-19 13:59:29 +01:00
upload-assets.sh [docs] Added openapi generation tool 2026-03-25 15:57:25 +05:00
upload-releasenotes.sh Add AI-agent for changelogs generation 2025-11-26 20:18:43 +01:00