Skip to content

Conversation

johejo
Copy link

@johejo johejo commented Oct 11, 2025

What type of PR is this?

/kind cleanup

What this PR does / why we need it:

Only few cloud providers actually need those verbs.

  • create: kwok
  • delete: kwok, huaweicloud

So, it would be better to restrict them to only those providers, following the principle of least privilege.

Which issue(s) this PR fixes:

Special notes for your reviewer:

Related: #5820, #3682

Following scripts were used to find providers using those verbs:

$ rg "Nodes\(\)\.Create" --glob='!*_test.go'
cloudprovider/kwok/kwok_nodegroups.go
84:             _, err := nodeGroup.kubeClient.CoreV1().Nodes().Create(context.Background(), node, v1.CreateOptions{})

$ rg "Nodes\(\)\.Delete" --glob='!*_test.go'
cloudprovider/kwok/kwok_provider.go
163:                    err := kwok.kubeClient.CoreV1().Nodes().Delete(context.Background(), node, v1.DeleteOptions{})

cloudprovider/kwok/kwok_nodegroups.go
118:            err := nodeGroup.kubeClient.CoreV1().Nodes().Delete(context.Background(), node.GetName(), v1.DeleteOptions{})

cloudprovider/huaweicloud/huaweicloud_auto_scaling_group.go
261:            err := kubeClient.CoreV1().Nodes().Delete(context.TODO(), nodeName, metav1.DeleteOptions{})

Does this PR introduce a user-facing change?

NONE

Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.:


@k8s-ci-robot k8s-ci-robot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. release-note-none Denotes a PR that doesn't merit a release note. kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. do-not-merge/needs-area labels Oct 11, 2025
@k8s-ci-robot
Copy link
Contributor

Welcome @johejo!

It looks like this is your first PR to kubernetes/autoscaler 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes/autoscaler has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@k8s-ci-robot k8s-ci-robot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Oct 11, 2025
@k8s-ci-robot
Copy link
Contributor

Hi @johejo. Thanks for your PR.

I'm waiting for a kubernetes member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-ci-robot k8s-ci-robot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed do-not-merge/needs-area labels Oct 11, 2025
@johejo johejo force-pushed the restrict_nodes_verbs_for_ca branch from 9ab8be0 to 65a91cc Compare October 11, 2025 03:41
@johejo johejo marked this pull request as ready for review October 11, 2025 05:42
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Oct 11, 2025
@k8s-ci-robot k8s-ci-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Oct 11, 2025
Only few cloud providers actually need those verbs.

- create: kwok
- delete: kwok, huaweicloud

So, it would be better to restrict them to only those providers, following the principle of least privilege.

Signed-off-by: Mitsuo HEIJO <[email protected]>
@johejo johejo force-pushed the restrict_nodes_verbs_for_ca branch from 65a91cc to 261e611 Compare October 12, 2025 02:40
@k8s-ci-robot k8s-ci-robot added area/cluster-autoscaler and removed needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. labels Oct 12, 2025
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: johejo
Once this PR has been reviewed and has the lgtm label, please assign gjtempleton for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot
Copy link
Contributor

PR needs rebase.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-ci-robot k8s-ci-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Oct 15, 2025
@jackfrancis
Copy link
Contributor

@johejo sorry for the inconvenience, the cluster-autoscaler charts/ directory has been moved into the cluster-autoscaler/ directory of the repo, so you'll have to rebase these changes on top of a commit that has that restructuing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/cluster-autoscaler area/helm-charts cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. release-note-none Denotes a PR that doesn't merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants