Skip to content

Move dynamic PSS baseline patch to apps/profiles/#3157

Merged
google-oss-prow[bot] merged 5 commits into
kubeflow:masterfrom
akagami-harsh:refactor-pss-baseline
Jun 3, 2025
Merged

Move dynamic PSS baseline patch to apps/profiles/#3157
google-oss-prow[bot] merged 5 commits into
kubeflow:masterfrom
akagami-harsh:refactor-pss-baseline

Conversation

@akagami-harsh

Copy link
Copy Markdown
Member

Pull Request Template for Kubeflow Manifests

✏️ Summary of Changes

Describe the changes you have made, including any refactoring or feature additions.

📦 Dependencies

List any dependencies or related PRs (e.g., "Depends on #123").

🐛 Related Issues

✅ Contributor Checklist

  • I have tested these changes with kustomize. See Installation Prerequisites.
  • All commits are signed-off to satisfy the DCO check.
  • I have considered adding my company to the adopters page to support Kubeflow and help the community, since I expect help from the community for my issue (see 1. and 2.).

You can join the CNCF Slack and access our meetings at the Kubeflow Community website. Our channel on the CNCF Slack is here #kubeflow-platform.

Signed-off-by: Harshvir Potpose <hpotpose62@gmail.com>
@akagami-harsh akagami-harsh force-pushed the refactor-pss-baseline branch from 5b2b4fd to bd67e60 Compare June 3, 2025 18:47
@google-oss-prow google-oss-prow Bot added size/XS and removed size/S labels Jun 3, 2025

resources:
- ../../../../../apps/profiles/upstream/overlays/kubeflow
- ../upstream/overlays/kubeflow

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file must then be used in the /example/kustomization.yaml as well

Comment thread apps/profiles/pss/namespace-labels.yaml Outdated
# deployment to enable PSS for profile namespaces, leads to creation of a new config map
# with just the PSS label and replaces the pre-exisiting labels in the deployed config map.
# PSS (Pod Security Standards) overlay for Kubeflow profiles
# This file extends the base namespace-labels.yaml with PSS baseline label

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please again link apps/profiles/upstream/base/namespace-labels.yaml

@juliusvonkohout

Copy link
Copy Markdown
Member

I think you have to update the GHA workflows "Error: must build at directory: not a valid directory: evalsymlink failure on 'experimental/security/PSS/dynamic/baseline' : lstat /home/runner/work/manifests/manifests/experimental/security/PSS/dynamic/baseline: no such file or directory"

Signed-off-by: Harshvir Potpose <hpotpose62@gmail.com>
Signed-off-by: Harshvir Potpose <hpotpose62@gmail.com>
Signed-off-by: Harshvir Potpose <hpotpose62@gmail.com>
Signed-off-by: Harshvir Potpose <hpotpose62@gmail.com>
@juliusvonkohout

Copy link
Copy Markdown
Member

Thank you

/lgtm
/approve

@google-oss-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: juliusvonkohout

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@google-oss-prow google-oss-prow Bot merged commit 72826fe into kubeflow:master Jun 3, 2025
9 checks passed
@akagami-harsh akagami-harsh deleted the refactor-pss-baseline branch June 4, 2025 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants