Repository navigation
fix(webhook): refuse NetworkRule backends whose port differs from spec.port - #738
abhicodes-007 wants to merge 1 commit into
Conversation
…c.port The datapath never rewrites ports (DSR), so a backend port other than spec.port was admitted and then ignored. Reject at admission with a message that says DSR cannot remap ports, document the constraint on the gateway architecture page, and cover it with a validator test. Fixes datum-cloud#737
|
Abhishek Deepak seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
|
@abhicodes-007, thanks for the fix. Before this can merge, the The email on your commit isn't linked to your GitHub account, so the CLA check may stay pending even after you sign. To fix that, either add that email to your GitHub account under Settings → Emails, or re-author the commit with an email your account already has ( |
|
Thanks for picking this up, @abhicodes-007. We're closing this without merging because the direction changed: port remapping is now supported (see #737), so refusing a backend port that differs from Since #809, galactic-router writes the rule's |
Summary
NetworkRuleValidatornow callsvalidateBackendPortson create/update: anybackends[i].port != spec.portis refused with a DSR cannot-remap message.portmust equal the ruleport.Fixes #737
Test plan
go test ./internal/webhook/— pass