Skip to content

Icu 18817 backup - #59

Open
Rkabra7 wants to merge 8 commits into
mainfrom
ICU-18817-backup
Open

Icu 18817 backup#59
Rkabra7 wants to merge 8 commits into
mainfrom
ICU-18817-backup

Conversation

@Rkabra7

@Rkabra7 Rkabra7 commented Jul 7, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds values.openshift.yaml with ready-to-use OpenShift overrides.
Adds an OpenShift Route template to provide TCP passthrough access to the worker proxy port.
Switches the proxy Service to ClusterIP when OpenShift support is enabled, with the Route handling external traffic.
Applies an OpenShift-compatible security context by removing fixed UID/GID settings so SCC can assign values from the namespace range.
Makes PVC storageClass conditional, allowing the cluster default storage class to be used when left unset.
Adds a new openshift: configuration section to values.yaml (disabled by default).
Adds unit tests covering all new OpenShift-specific paths.

Behaviour Changes

recording-storage mount is now always present (all users, not just OpenShift):
Previously, the recording-storage volumeMount was only added when worker.persistence.recording.enabled=true.
It is now always mounted — using a real PVC when recording is enabled, or a non-persistent emptyDir when it is not.
This ensures the worker process always has a writable path at the recording mount point regardless of whether
recording is configured, which prevents startup failures on clusters where the path must exist.

Testing

Tested on OpenShift Local (CRC). The worker successfully authenticated to a self-managed Boundary controller using the OpenShift-specific chart configuration.

  • Issue:
  • Chart/Component:

Checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • Added/updated tests or validation steps (if applicable)

  • Verified local lint/validation

  • No breaking changes, or clearly documented

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

@Rkabra7
Rkabra7 requested a review from a team as a code owner July 7, 2026 12:43
@Rkabra7
Rkabra7 force-pushed the ICU-18817-backup branch 17 times, most recently from 6378907 to 5f173d2 Compare July 14, 2026 18:07
@Rkabra7
Rkabra7 force-pushed the ICU-18817-backup branch from 5f173d2 to 27c9985 Compare July 15, 2026 17:11

@MayukhSobo MayukhSobo left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Route/Service/security-context template logic is solid and well-tested, same as the controller chart PR. A few things worth a look before merge, kept to the important ones only:

Comment thread .github/workflows/test.yml Outdated
Comment thread Makefile Outdated
Comment thread templates/worker-deployment.yaml

@smayukh smayukh left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR! Please review the PR comments.

@hashicorp-cla-app

hashicorp-cla-app Bot commented Jul 31, 2026

Copy link
Copy Markdown

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


1 out of 2 committers have signed the CLA.

  • Rkabra7
  • smayukh

Have you signed the CLA already but the status is still pending? Recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants