Skip to content

fix(webhook): refuse NetworkRule backends whose port differs from spec.port - #738

Closed
abhicodes-007 wants to merge 1 commit into
datum-cloud:mainfrom
abhicodes-007:fix/737-networkrule-backend-port-match
Closed

abhicodes-007 wants to merge 1 commit into
datum-cloud:mainfrom
abhicodes-007:fix/737-networkrule-backend-port-match

Conversation

@abhicodes-007

Copy link
Copy Markdown

Summary

  • NetworkRuleValidator now calls validateBackendPorts on create/update: any backends[i].port != spec.port is refused with a DSR cannot-remap message.
  • Gateway architecture doc: backend port must equal the rule port.
  • Test: mismatch refused, match admitted.

Fixes #737

Test plan

  • go test ./internal/webhook/ — pass
  • Existing authorize tests still green

…c.port

The datapath never rewrites ports (DSR), so a backend port other than
spec.port was admitted and then ignored. Reject at admission with a
message that says DSR cannot remap ports, document the constraint on the
gateway architecture page, and cover it with a validator test.

Fixes datum-cloud#737
@abhicodes-007
abhicodes-007 requested a review from a team as a code owner October 5, 2026 15:22
@cla-assistant

cla-assistant Bot commented Oct 5, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Abhishek Deepak seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@privateip

Copy link
Copy Markdown
Collaborator

@abhicodes-007, thanks for the fix. Before this can merge, the license/cla check needs you to sign the Contributor License Agreement: https://cla-assistant.io/datum-cloud/galactic?pullRequest=738

The email on your commit isn't linked to your GitHub account, so the CLA check may stay pending even after you sign. To fix that, either add that email to your GitHub account under Settings → Emails, or re-author the commit with an email your account already has (git commit --amend --reset-author) and force-push.

@privateip

Copy link
Copy Markdown
Collaborator

Thanks for picking this up, @abhicodes-007. We're closing this without merging because the direction changed: port remapping is now supported (see #737), so refusing a backend port that differs from spec.port would block a working configuration.

Since #809, galactic-router writes the rule's spec.backendPort into each backend's ServiceVIPBinding, and the backend node's TC program rewrites VIP:port to backend:backendPort. network#29 and network#31 also replaced per-backend ports with a single spec.backendPort on the rule, so this change no longer applies to the current API either.

@privateip privateip closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

NetworkRule backend port is accepted but ignored

2 participants