Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix: conditional aws-hyperpod namespace creation by GusAntoniassi · Pull Request #422 · aws/sagemaker-hyperpod-cli · GitHub
Skip to content

fix: conditional aws-hyperpod namespace creation - #422

Open
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation
Open

fix: conditional aws-hyperpod namespace creation#422
GusAntoniassi wants to merge 4 commits into
aws:mainfrom
GusAntoniassi:fix/aws-hyperpod-namespace-conditional-creation

Conversation

@GusAntoniassi

Copy link
Copy Markdown

What's changing and why?

Our aws-hyperpod namespace has been created by our internal machinery, to add special permissions and guardrails. Currently, when trying to apply the Helm chart, we have the following error:

Error: Unable to continue with install: Namespace "aws-hyperpod" in namespace "" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "app.kubernetes.io/managed-by": must be set to "Helm"; annotation validation error: missing key "meta.helm.sh/release-name": must be set to "hyperpod-dependencies"; annotation validation error: missing key "meta.helm.sh/release-namespace": must be set to "kube-system"`

We've tried setting namespace.create in values.yaml, but that did not work. Upon further investigation, I saw that the aws-hyperpod-namespace.yaml template was not using these variables at all.

Before/After UX

Before:

# values.yamlnamespace:
name: "aws-hyperpod"create: true

These values were not being used by any subchart, and updating them did not change anything.

After:

deep-health-check:
enabled: truenamespace:
create: truename: aws-hyperpod

These values now govern the creation of the aws-hyperpod namespace.

How was this change tested?

Changes were tested using the helm template command, to validate both current behavior (aws-hyperpod being created by default), and new behavior (flag --set deep-health-check.namespace.create=false disables the aws-hyperpod namespace template).

Are unit tests added?

Not necessary

Are integration tests added?

Not necessary

Reviewer Guidelines

‼️Merge Requirements: PRs with failing integration tests cannot be merged without justification.

One of the following must be true:

  • All automated PR checks pass
  • Failed tests include local run results/screenshots proving they work
  • Changes are documentation-only

@mufaddal-rohawalamufaddal-rohawala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, @GusAntoniassi — the root-cause diagnosis is correct. The top-level namespace block in the parent values.yaml was genuinely dead config, and the deep-health-check RBAC template was already misusing .Values.namespace as a string, so wiring these up is the right call. A few things to address before merge (inline comments):

  1. {{- end }} placement in mpi-operator/templates/rbac.yaml
  2. Missing trailing newline in aws-hyperpod-namespace.yaml
  3. Trailing whitespace in the parent values.yaml

Could you also attach helm template output with deep-health-check.namespace.create set to both true and false so we can confirm the rendered manifests are valid in both states?

Comment threadhelm_chart/HyperPodHelmChart/values.yaml Outdated
@GusAntoniassi
GusAntoniassiforce-pushed the fix/aws-hyperpod-namespace-conditional-creation branch from 2128de9 to 8f12117CompareAugust 28, 2026 14:15
@GusAntoniassi
GusAntoniassideployed to manual-approval August 28, 2026 14:15 — with GitHub Actions Active
@GusAntoniassi

Copy link
Copy Markdown
Author

Thanks for your review @mufaddal-rohawala. I've addressed these changes in the latest commit.

I'm attaching only the deep-health-check templates, let me know if you need the full helm render output too.

deep-health-check.namespace.create=false:
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account
deep-health-check.namespace.create=true:
---
# Source: deep-health-check/templates/aws-hyperpod-namespace.yamlapiVersion: v1kind: Namespacemetadata:
name: aws-hyperpodlabels:
name: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlapiVersion: v1kind: ServiceAccountmetadata:
name: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-rolerules:
- apiGroups:
- ""resources:
- nodesverbs:
- get
- list
- apiGroups:
- ""resources:
- podsverbs:
- get
- list
- patch
---
# Source: deep-health-check/templates/deep-health-check-rbac.yamlkind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1metadata:
name: deep-health-check-service-account-role-bindingroleRef:
apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: deep-health-check-service-account-rolesubjects:
- kind: ServiceAccountname: deep-health-check-service-accountnamespace: aws-hyperpod
---
# Source: deep-health-check/templates/deep-health-check-rbac.yaml# rbac.yaml# service account

@piyushdaftary

Copy link
Copy Markdown
Contributor

@mufaddal-rohawala@mujtaba1747 : Can you please help to review and merge the PR ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@GusAntoniassi@piyushdaftary@mufaddal-rohawala