Skip to content

feat: use namespaceSelector/podSelector for the ServiceX backend egress rule - #4

Merged
kratsg merged 1 commit into
mainfrom
feat/servicex-backend-selector-egress
Sep 10, 2026
Merged

kratsg merged 1 commit into
mainfrom
feat/servicex-backend-selector-egress

Conversation

@kratsg

@kratsg kratsg commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

Why

The servicexBackend egress rule assumed an external ServiceX backend and only supported an ipBlock CIDR. In practice the AF deployment's ServiceX runs in the same cluster, and an ipBlock rule targeting its Service ClusterIP never actually worked (this cluster's dataplane evaluates egress after kube-proxy's DNAT rewrites the ClusterIP to a backing pod IP), leaving 0.0.0.0/0 as the only option that functioned -- far broader than intended.

What

Replace it with the same namespaceSelector/podSelector shape already used for the jwks rule right above it. No ipBlock fallback kept -- this chart's only real-world deployment has an in-cluster ServiceX backend.

networkPolicy.egress.servicexBackend.namespaceSelector/podSelector default to empty (matchLabels: {}) since there's no sensible cluster-wide default. NOTES.txt's misconfiguration warning updated to match.

Verification

helm lint/helm template clean both with selectors set (renders the expected namespaceSelector/podSelector rule) and with defaults (renders the new NOTES.txt warning instead of erroring).

🤖 Generated with Claude Code

…ss rule

The servicexBackend egress rule assumed an external ServiceX backend
and only supported an ipBlock CIDR. In practice the AF deployment's
ServiceX runs in the same cluster, and an ipBlock rule targeting its
Service ClusterIP never actually worked (this cluster's dataplane
evaluates egress after kube-proxy's DNAT rewrites the ClusterIP to a
backing pod IP), leaving 0.0.0.0/0 as the only option that functioned
-- far broader than intended.

Replace it with the same namespaceSelector/podSelector shape already
used for the jwks rule above it. No ipBlock fallback: this chart's
only real-world deployment has an in-cluster ServiceX backend, so
there's no reason to carry the external-backend case.

networkPolicy.egress.servicexBackend.namespaceSelector/podSelector
default to empty (matchLabels: {}) since there's no sensible
cluster-wide default -- every deployment's ServiceX namespace/pod
labels differ, same as config.servicexBackendUrl itself. NOTES.txt's
misconfiguration warning updated to match (empty selectors -> the
egress rule selects nothing -> redeem calls are blocked, rather than
the old "still wide open" warning).

Assisted-by: Claude Sonnet 5 <noreply@anthropic.com>
@kratsg
kratsg merged commit 69a7927 into main Sep 10, 2026
4 checks passed
@kratsg
kratsg deleted the feat/servicex-backend-selector-egress branch September 10, 2026 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant