cozystack/internal
Andrei Kvapil 28985ed0a8
fix(operator): resolve namespace privileged flag by checking all Packages (#2046)
## What this PR does

Fixes a race condition where multiple Packages sharing the same
namespace could overwrite each other's PodSecurity Admission labels via
Server-Side Apply.

When two PackageSources deploy to the same namespace (e.g.
`cozystack.linstor` and `cozystack.linstor-scheduler` both use
`cozy-linstor`), each Package only knew about its own components. If a
Package without `privileged: true` reconciled the namespace, SSA would
remove the `pod-security.kubernetes.io/enforce=privileged` label set by
the other Package.

On Talos clusters (which default to `baseline` PodSecurity enforcement),
this caused privileged pods like LINSTOR satellites to be rejected.

The fix makes each Package check ALL PackageSources and their active
Packages when reconciling a namespace. A namespace is set to
`privileged` if ANY Package has a component with `privileged: true` in
it. This ensures a consistent, holistic decision regardless of
reconciliation order.

### Release note

```release-note
[platform] Fixed namespace PodSecurity label race condition when multiple Packages share a namespace
```
2026-02-14 02:02:28 +01:00
..
backupcontroller refactor: rename mysql application to mariadb 2026-02-12 15:15:20 +01:00
controller [platform] Make cozystack-api reconciliation always use Deployment 2026-02-14 01:59:40 +01:00
cozyvaluesreplicator Improve Reconcile function 2026-01-06 18:53:17 +03:00
fluxinstall Fix tolerations for uninitialized nodes 2026-01-19 14:20:02 +01:00
lineagecontrollerwebhook refactor(api): rename CozystackResourceDefinition to ApplicationDefinition 2026-01-15 22:35:56 +01:00
operator fix(operator): resolve namespace privileged flag by checking all Packages 2026-02-13 17:09:12 +01:00
shared/crdmem refactor(api): rename CozystackResourceDefinition to ApplicationDefinition 2026-01-15 22:35:56 +01:00
sse [kubeovn] Implement the KubeOVN plunger 2025-09-11 02:11:58 +03:00
telemetry fix(telemetry): use APIReader instead of cached client in operator 2026-01-27 18:06:30 +01:00
template [backups] Add templating of velero backups 2026-01-04 13:31:15 +03:00