Uh oh!
There was an error while loading. Please reload this page.
Sync develop → main for v1.7.1 chart release (egress-enforcement preflight helm test, inert) - #254
Merged
Merged
Conversation
…250) The mysql-storage-pvc template (PVC + bare-metal hostPath PV backing the per-cluster MySQL state store) had no dedicated suite. Add one covering: - dynamic-PVC-only path (hostPath.enabled=false, managed default) - hostPath PV+PVC pair, claimRef binding, fixed release-scoped path - the helm.sh/resource-policy:keep annotation protecting the state store - access-mode defaulting, pvc size, and storageClass wiring Tests-only; no source/template/values changes. Security invariants unchanged. Co-authored-by: Claude <noreply@anthropic.com>
The logs-pvc template (PV + PVC for client logs) had no dedicated helm-unittest suite. Adds tests/logs_pvc_test.yaml covering the dynamic-provisioning PVC path and the hostPath PV+PVC path. Co-authored-by: Claude <noreply@anthropic.com>
feat(egress-proxy): deploy-time egress-enforcement pre-flight (non-blocking) [client-runtime#104]
Uh oh!
There was an error while loading. Please reload this page.
This was referenced Jun 12, 2026
Merged
…P code [#104] (#255) Bugbot (PR #254): the check treated curl HTTP code 000 as proof of a block, but a TCP connection that succeeds (egress OPEN) then fails TLS verification also yields 000 — so `helm test` could pass on a non-enforcing CNI when probing an IP whose cert doesn't validate (the default 1.1.1.1 without -k). It conflated "TLS failed" with "egress blocked", defeating the check. Key the verdict off TCP reachability via curl's exit code instead of the HTTP status, and add -k so TLS is explicitly irrelevant: exit 28 (timeout) / 7 (connect failed) => egress blocked => test PASSES (exit 0); any other outcome (0 success, or a TLS-/HTTP-layer error such as 35/52/60 — all of which require the TCP connect to have already succeeded) => egress reached => NOT enforced => test FAILS (exit 1). Tests assert the verdict keys on the exit code (rc=$?, -k) and guard against a regression to the old http_code/000 logic. helm-unittest 248/248; lint clean. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 9edd87e. Configure here.
Uh oh!
There was an error while loading. Please reload this page.
This was referenced Jun 15, 2026
Merged
…connect succeeded" [#104] (#256) Bugbot (PR #254): the non-enforcement WARNING ("...reached :443 ... the TCP connect succeeded") was emitted for every non-{7,28} curl exit code, including exit 6 (DNS resolution failure) where no TCP connection was ever attempted — so the failure output could contradict what actually happened and mislead troubleshooting. Split the verdict into a case: 7|28 => TCP never established => egress blocked (pass, exit 0) 6 => INCONCLUSIVE: could not resolve host, no TCP attempted => fail (exit 1) with an accurate message (never claim "enforced" on a DNS failure) else (0, or TLS-/HTTP-layer errors 35/52/56/60 that all require a completed TCP connect) => host reached => NOT enforced (exit 1) Default probe host is an IP, so exit 6 only arises for a hostname probe on a cluster with broken DNS. helm-unittest 248/248; lint clean. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This was referenced Jun 15, 2026
Merged
aptracebloc
approved these changes
Jun 15, 2026
divyasinghds
approved these changes
Jun 15, 2026
Uh oh!
There was an error while loading. Please reload this page.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Release chart v1.7.1 to
main. All changes are additive and inert — no behavioural change on the fleet at upgrade time.Contents (
main1.7.0 →develop1.7.1)helm.sh/hook: testJob, gated on the §8.2 lockdown being enabled (networkPolicy.training.allowExternalHttps=false), that probes direct external egress from atracebloc.io/workload: training-labelled pod and failshelm test(exit 1) if the CNI isn't enforcing egress NetworkPolicy. Dormant by default; as a test hook it never runs on install/upgrade (incl. the hourly auto-upgrade).Release type
Phase-1-class: inert. The enforcement check ships dormant (lockdown default-off) and is a
helm testhook, so the fleet auto-upgrade to 1.7.1 changes nothing operationally — it just makeshelm test <release>available to operators who flip the lockdown.After merge
Publish GitHub Release v1.7.1 tagged on
main→ the release workflow packages the chart to gh-pages → fleet auto-upgrades at:23.Rolls under the §8.2 egress epic (client-runtime#102, client-runtime#104).
🤖 Generated with Claude Code
Note
Low Risk
Additive chart release: enforcement Job is gated off by default and only runs on explicit
helm test; PVC suites are test-only with no production manifest changes.Overview
Releases the client Helm chart as v1.7.1 (
Chart.yamlversion/appVersion bump).Egress lockdown verification (#104): When
networkPolicy.training.allowExternalHttpsis false and a probe host is set, a newhelm.sh/hook: testJob runs a training-labelled curl probe against:443and passes only if TCP egress is blocked (curl exit 7/28); a successful connect fails the test with explicit CNI guidance. The template does not render with default values or whenenforcementProbeHostis empty, so install/upgrade and auto-upgrade stay unchanged.Values/schema: Adds
networkPolicy.training.enforcementProbeHost(default1.1.1.1invalues.yaml) for operators who enable the §8.2 lockdown.Tests only: New helm-unittest suites for the egress check Job,
logs-pvc, andmysql-storage-pvctemplates (PVC/PV naming,keeppolicy, hostPath vs dynamic paths)—no runtime template changes beyond the new check.Reviewed by Cursor Bugbot for commit d70e7ff. Bugbot is set up for automated code reviews on this repo. Configure here.