fix(replacement): correctly apply reject labelSelectors - #6228
fix(replacement): correctly apply reject labelSelectors#6228saitejabandaru-in wants to merge 3 commits into
Conversation
…former and SuffixTransformer
This adds validation for the --output flag to return an error if it's not 'yaml' or 'json', fixing a bug where it would silently fail and output nothing.
Fixes a bug where label and annotation selectors in the 'reject' list of a Replacement were not correctly AND-ed with the resource ID matcher, causing the Replacement filter to unconditionally reject targets based purely on their GVK/Name regardless of their labels. Now, a target is rejected only if it matches both the resource ID (GVK/name/namespace) AND the label/annotation selectors specified in the reject rule. Fixes kubernetes-sigs#6035
|
This PR has multiple commits, and the default merge method is: merge. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Invalid commit message issues detected Invalid commit messagesKeywords which can automatically close issues and hashtag(#) mentions are not allowed.
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: saitejabandaru-in The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
|
Hi @saitejabandaru-in. Thanks for your PR. I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Fixes #6035
Description:
When using a Replacement with a
rejectrule that specifies alabelSelector, the filter was unconditionally rejecting targets purely based on their resource ID (GVK/name/namespace) regardless of their labels.This was caused by the logic being disjointed: the GVK/name/namespace check and the label/annotation check were evaluated separately, effectively OR-ing them instead of AND-ing them together for a single reject rule.
This PR unifies the evaluation logic in
applyReplacementso a target is rejected only if it matches both the resource ID criteria AND the label/annotation criteria of a givenrejectrule.Testing:
Added
TestReplacementTransformerWithRejectLabelSelectorto cover this specific scenario, directly mirroring the user's reproduction case.