Skip to content

fix(replacement): correctly apply reject labelSelectors - #6228

Open
saitejabandaru-in wants to merge 3 commits into
kubernetes-sigs:masterfrom
saitejabandaru-in:fix-replacement-reject-labelselector
Open

fix(replacement): correctly apply reject labelSelectors#6228
saitejabandaru-in wants to merge 3 commits into
kubernetes-sigs:masterfrom
saitejabandaru-in:fix-replacement-reject-labelselector

Conversation

@saitejabandaru-in

Copy link
Copy Markdown

Fixes #6035

Description:
When using a Replacement with a reject rule that specifies a labelSelector, the filter was unconditionally rejecting targets purely based on their resource ID (GVK/name/namespace) regardless of their labels.

This was caused by the logic being disjointed: the GVK/name/namespace check and the label/annotation check were evaluated separately, effectively OR-ing them instead of AND-ing them together for a single reject rule.

This PR unifies the evaluation logic in applyReplacement so a target is rejected only if it matches both the resource ID criteria AND the label/annotation criteria of a given reject rule.

Testing:
Added TestReplacementTransformerWithRejectLabelSelector to cover this specific scenario, directly mirroring the user's reproduction case.

Sai Teja Bandaru added 3 commits August 7, 2026 22:47
This adds validation for the --output flag to return an error if it's not 'yaml' or 'json', fixing a bug where it would silently fail and output nothing.
Fixes a bug where label and annotation selectors in the 'reject' list of a
Replacement were not correctly AND-ed with the resource ID matcher, causing
the Replacement filter to unconditionally reject targets based purely on
their GVK/Name regardless of their labels.

Now, a target is rejected only if it matches both the resource ID
(GVK/name/namespace) AND the label/annotation selectors specified in the
reject rule.

Fixes kubernetes-sigs#6035
@kubernetes-prow

Copy link
Copy Markdown
Contributor

This PR has multiple commits, and the default merge method is: merge.
You can request commits to be squashed using the label: tide/merge-method-squash

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow

Copy link
Copy Markdown
Contributor

Invalid commit message issues detected

Invalid commit messages

Keywords which can automatically close issues and hashtag(#) mentions are not allowed.

  • d933e29 fix(replacement): correctly apply reject labelSelectors

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@kubernetes-prow kubernetes-prow Bot added the do-not-merge/invalid-commit-message Indicates that a PR should not merge because it has an invalid commit message. label Aug 16, 2026
@kubernetes-prow
kubernetes-prow Bot requested a review from koba1t August 16, 2026 13:38
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: saitejabandaru-in
Once this PR has been reviewed and has the lgtm label, please assign varshaprasad96 for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@linux-foundation-easycla

Copy link
Copy Markdown

CLA Missing ID

@kubernetes-prow kubernetes-prow Bot added cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Aug 16, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Hi @saitejabandaru-in. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow kubernetes-prow Bot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Aug 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. do-not-merge/invalid-commit-message Indicates that a PR should not merge because it has an invalid commit message. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Replacements / Reject: labelSelector does not filter correctly and applies the Replacement to all

1 participant