Skip to content

Keep a membership's or grant's team reference inside the github-config namespace #4525

Description

@devantler

🤖 Generated by the Agentic Engineer

Evidence

Found by the independent review of #4524. The membership and repository-grant rules in restrict-github-team-management require spec.forProvider.teamIdRef.name to be admins or maintainers, on the assumption that the name refers to the Team object in github-config. The provider's reference type also has a namespace field (v0.20.0 CRD), and no rule looks at it. A fixture with teamIdRef: {name: admins, namespace: <another namespace>} passes every team rule under kyverno test.

Not yet verified: whether the provider's reference resolver honours that field for these kinds, and whether a Team object named admins could exist in another namespace that the provider reconciles.

Problem and audience

If the resolver honours it, the allow-listed name stops being a faithful stand-in for the approved team: the reference could resolve to a Team object the team rules never judged. The audience is the maintainer, who relies on these rules to bound the delegated release.

Expected behaviour

A membership or grant in github-config can only reference a Team object in github-config.

Acceptance criteria

  • The resolver's behaviour is established first, from the released source of the provider version production runs.
  • If the field is honoured, teamIdRef.namespace (under forProvider and initProvider) may only be unset or github-config, compared literally, with fixtures that fail without the rule.
  • If it is not honoured, the reason is recorded here and the issue closed.

Same file as #4517; doing both in one change is reasonable.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions