Skip to content

fix(nvca): set up RBAC before writing the agent config ConfigMap - #2344

Merged
apartha-nv merged 1 commit into
release-src/compute-plane-services/nvca/v3.7from
aparthasarat/v3.7-cherry-pick-2283
Oct 7, 2026
Merged

apartha-nv merged 1 commit into
release-src/compute-plane-services/nvca/v3.7from
aparthasarat/v3.7-cherry-pick-2283

Conversation

@apartha-nv

Copy link
Copy Markdown
Contributor

Why

Cherry-pick of #2283 to the v3.7 release line.

What changed

Cherry-pick of 4187ce0 from main.

Testing

  • go build ./... in src/compute-plane-services/nvca
  • go test ./pkg/operator/reconcile/... (including the regression test TestSetupNVCAAgentInfra_RBACFailureLeavesAgentConfigConfigMapUnwritten) passes

References

Cherry-pick of #2283

Related Pull Requests

#2283

setupNVCAAgentInfra wrote the agent config ConfigMap before setting up
RBAC. newAgentConfigChangedCheck detects pending rollouts by diffing
the desired config against the live ConfigMap in the cluster, not
against NVCFBackend.Status. When a Helm update added the first
allowedExtraKubernetesTypes entry, the operator's own RBAC grant for
the new type was not yet usable, so the ClusterRole update failed with
Forbidden. By that point the ConfigMap had already been written to the
desired state, so every later periodic sync saw "no change" and never
retried RBAC or the Deployment rollout, leaving the agent stuck on the
old configuration until an unrelated change happened to trip a
different rollout check.

Move setupNVCARBAC ahead of setupAgentConfigConfigMap so a transient
RBAC failure leaves the ConfigMap unwritten, keeping the change
detectable and the rollout retryable on the next periodic sync.

(cherry picked from commit 4187ce0)
@apartha-nv
apartha-nv requested a review from a team as a code owner October 7, 2026 07:28
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (1)
  • main

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/nvcf/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 6ac9f1ec-91fd-4721-ae35-6bb2127b0cd4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@apartha-nv
apartha-nv merged commit bf90b50 into release-src/compute-plane-services/nvca/v3.7 Oct 7, 2026
14 checks passed
@apartha-nv
apartha-nv deleted the aparthasarat/v3.7-cherry-pick-2283 branch October 7, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants