Skip to content

fix(kubernetes): wait for OpenShift SCC annotations - #4054

Open
Ygnas wants to merge 1 commit into
NVIDIA:mainfrom
Ygnas:feat/openshift-managed-workspaces
Open

Ygnas wants to merge 1 commit into
NVIDIA:mainfrom
Ygnas:feat/openshift-managed-workspaces

Conversation

@Ygnas

@Ygnas Ygnas commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Fix managed workspace namespace setup on OpenShift by waiting for the SCC allocator to assign namespace annotations before provisioning workspace resources.

Related Issue

No issue required: this is a focused bug fix for managed workspace namespace setup, related to PR #2656 and RFC 0011.

Changes

  • Stop copying SCC UID-range and supplemental-group annotations from the gateway namespace to managed workspace namespaces.
  • Wait for OpenShift to assign the workspace namespace’s MCS, UID-range, and supplemental-group annotations before creating its ServiceAccount.
  • Fail with a clear precondition error if an existing workspace namespace has a UID range but no MCS annotation; that namespace must be recreated for OpenShift to allocate its MCS value.
  • Add driver tests for allocator timing, stale namespaces, and timeout behavior.
  • Document the managed workspace namespace behavior on OpenShift.

Testing

  • mise run pre-commit
  • Unit tests added/updated
  • Validated managed workspace creation on an OpenShift cluster

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Signed-off-by: Ignas Baranauskas <ibaranau@redhat.com>
@Ygnas
Ygnas requested review from a team, derekwaynecarr, mrunalp and sjenning as code owners October 1, 2026 13:44
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@sjenning

sjenning commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

/ok to test 9c5f276

@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

/ok to test 9c5f276

@sjenning, there was an error processing your request: E2

See the following link for more information: https://docs.gha-runners.nvidia.com/cpr/e/2/

@sjenning

sjenning commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

/ok to test 9c5f276

@johntmyers

Copy link
Copy Markdown
Collaborator

@sjenning you will need to trigger the merge

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants