Skip to content

fix(data-products): roll out controller 2.4.4 - #4534

Merged
devantler merged 1 commit into
mainfrom
codex/dpc-round11-rollout-4510
Oct 6, 2026
Merged

devantler merged 1 commit into
mainfrom
codex/dpc-round11-rollout-4510

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

The platform still runs the previous controller release. Publishers and consumers need the latest fixes for reliable validation and product handoffs.

What

Roll out the latest Data Product Controller release across the platform's controller, sample product, and UI kit.

Fixes #4510

@devantler

devantler commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Candidate: ec718c5.

The v2.4.4 image and chart manifests were independently hashed and verified with the existing signing-identity, repository, source-commit and tag constraints. The actual published-image smoke job passed, including the offline commands and portable UI host.

Both local and production manifest validation cover all three changed pins. The rendered application layer retains their exact digests; install/upgrade post-render checks, disruption-budget selectors, naming, trial configuration and UI-host controls passed. Independent static review found no actionable candidate issue.

The authenticated 2.4.4 chart's RBAC, service-account, network-policy and DataProduct CRD files also match both the release source and the unchanged 2.4.3 source files byte for byte. This check establishes their declaration parity; mixed-version runtime behavior and rollback are not inferred from it.

All current-head hosted checks passed in CI run 37325612197. Its completed manifest job exercised the rollout-receipt regression successfully, resolving the missing hosted evidence after the local Mac fixture deadline failure. CodeRabbit's substantive review is clean at this exact head, with no unresolved threads or actionable body findings.

User evaluation exercised the authenticated published image's offline catalog/export and preflight commands and portable UI host in successful published-image smoke job 111725584418. The local manifest evaluation observed the intended controller, sample product and UI-host pins together. These establish candidate behavior and manifest effect; production still requires the protected merge-queue deployment, an authoritative receipt, and the user-facing product paths. Queue admission will not be reported as deployment or merge.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 857dd000-8f69-43a1-98f6-e9d0062f0952
📥 Commits

Reviewing files that changed from the base of the PR and between ffb1824 and ec718c5.

📒 Files selected for processing (3)
  • k8s/bases/apps/data-product-controller/deployment-ui-kit.yaml
  • k8s/bases/apps/data-product-controller/helm-release.yaml
  • k8s/bases/apps/data-product-controller/oci-repository.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (1)
Source excerpt: **Let Flagger (or its KEDA `autoscalerRef`) own replicas** — omit the chart's `replicaCount` value and do not pin `/spec/replicas` in a postRenderer, otherwise Flux re-applies the chart's replica count and fights Flagger's s...

📄 CodeRabbit inference engine (docs/progressive-delivery.md)

Files:

  • k8s/bases/apps/data-product-controller/helm-release.yaml
🔇 Additional comments (3)
k8s/bases/apps/data-product-controller/oci-repository.yaml (1)

12-12: LGTM!

Also applies to: 14-14

k8s/bases/apps/data-product-controller/deployment-ui-kit.yaml (1)

46-46: LGTM!

k8s/bases/apps/data-product-controller/helm-release.yaml (1)

57-57: 🩺 Stability & Availability

The warning is unsupported for this app. The repository defines no Flagger Canary or KEDA ScaledObject for either workload, and the PR does not change the replica values.


📝 Walkthrough

Walkthrough

The deployment manifests now pin the data product controller chart, controller image, and ui-kit image to version 2.4.4 with updated digests.

Priority: ⬇️ Low

Priority: ⬇️ Low

Estimated code review effort:

Merge Risk: ⚪ Minimal · up to ec718

This update moves the data product controller, its sample product, and the UI kit to release 2.4.4. No concrete defect was found in the version and digest pins. The change looks ready to merge once the hosted validation and the planned post-merge rollout checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to ec718

The release pins advance together and preserve the visible security controls. No introduced security weakness was established. The new release contents and their compatibility during partial rollout or rollback remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The visible deployment targets the data-product-controller namespace, but Helm is configured to create or replace CRDs during installation and upgrade. Namespace declarations alone therefore do not bound the release's schema impact to that namespace; effective chart permissions were not verified.

Trust Boundaries and Controls

  • observed — Chart content remains digest-pinned and subject to Cosign verification constrained to the publisher's version-tagged chart publication workflow. Controller and UI images are also digest-pinned. These controls constrain artifact substitution but do not establish that authenticated release contents preserve permissions or compatibility.
  • observed — The UI retains its explicit service account with API-token automount disabled, non-root execution, runtime-default seccomp, no privilege escalation, a read-only root filesystem, and all Linux capabilities dropped. The full comparison shows no weakening of these declared controls.

Hardening Proposals

  • proposed — Before promotion, compare the authenticated chart releases for RBAC, secret access, networking, and CRD changes, and establish supported mixed-version and rollback behavior. This would close the release-content and recovery uncertainties; it is not an observed vulnerability.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed For #4510, the GitOps changes pin the controller chart to the v2.4.4 chart digest and pin the controller and separate UI-kit deployment to the same 2.4.4 image digest. The chart keeps the sample produ…
Out of Scope Changes check ✅ Passed The reported changes update only the controller chart, controller image, and UI-kit image pins for the #4510 rollout. These changes directly support the linked issue. No unrelated change is evident.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Title check ✅ Passed The title clearly summarizes the main change: rolling out Data Product Controller 2.4.4.
Description check ✅ Passed The description explains the rollout and its reliability purpose, which relate to the changeset.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler
devantler marked this pull request as ready for review October 5, 2026 16:20
@devantler
devantler added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit 513cf30 Oct 6, 2026
33 checks passed
@devantler
devantler deleted the codex/dpc-round11-rollout-4510 branch October 6, 2026 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

Deploy the data product reliability release

1 participant