🤖 Generated by the Agentic Engineer
Evidence
Found by the independent review of #4524. The membership and repository-grant rules in restrict-github-team-management require spec.forProvider.teamIdRef.name to be admins or maintainers, on the assumption that the name refers to the Team object in github-config. The provider's reference type also has a namespace field (v0.20.0 CRD), and no rule looks at it. A fixture with teamIdRef: {name: admins, namespace: <another namespace>} passes every team rule under kyverno test.
Not yet verified: whether the provider's reference resolver honours that field for these kinds, and whether a Team object named admins could exist in another namespace that the provider reconciles.
Problem and audience
If the resolver honours it, the allow-listed name stops being a faithful stand-in for the approved team: the reference could resolve to a Team object the team rules never judged. The audience is the maintainer, who relies on these rules to bound the delegated release.
Expected behaviour
A membership or grant in github-config can only reference a Team object in github-config.
Acceptance criteria
Same file as #4517; doing both in one change is reasonable.
Evidence
Found by the independent review of #4524. The membership and repository-grant rules in
restrict-github-team-managementrequirespec.forProvider.teamIdRef.nameto beadminsormaintainers, on the assumption that the name refers to the Team object ingithub-config. The provider's reference type also has anamespacefield (v0.20.0 CRD), and no rule looks at it. A fixture withteamIdRef: {name: admins, namespace: <another namespace>}passes every team rule underkyverno test.Not yet verified: whether the provider's reference resolver honours that field for these kinds, and whether a Team object named
adminscould exist in another namespace that the provider reconciles.Problem and audience
If the resolver honours it, the allow-listed name stops being a faithful stand-in for the approved team: the reference could resolve to a Team object the team rules never judged. The audience is the maintainer, who relies on these rules to bound the delegated release.
Expected behaviour
A membership or grant in
github-configcan only reference a Team object ingithub-config.Acceptance criteria
teamIdRef.namespace(underforProviderandinitProvider) may only be unset orgithub-config, compared literally, with fixtures that fail without the rule.Same file as #4517; doing both in one change is reasonable.