Skip to content

Initialize mutation dependencies only for mutation operations #4772

Description

@JaydipGabani

Parent issue: #3964
Related operation cleanup: #4051

Describe the solution you'd like

Gatekeeper should construct and inject the mutation system only when a mutation operation is assigned.

Today setupControllers always calls mutation.NewSystem(...). In addition, pkg/controller/mutators/instances.Adder.Add creates conflict-routing channels and registers the routeConflictEvents runnable before the individual mutator controllers check mutation.Enabled(). A status-only, generate-only, or other non-mutation process therefore receives an unused mutation system and runnable.

Use mutation.Enabled() (or an equivalent single source of truth) to align construction and controller registration with these operations:

  • mutation-webhook
  • mutation-controller
  • mutation-status (which documents mutation-controller as implicit)

Workload expansion must remain correct. expansion.System already supports a nil mutation system and should apply mutators to generated resources only when a mutation-controller operation is present.

Suggested scope:

  • Avoid constructing mutation.System when no mutation operation is assigned.
  • Return before registering the mutator conflict-routing runnable when mutation is disabled.
  • Inject a non-nil mutation system into every mutation webhook/controller that is registered.
  • Wire external-data provider cache and client certificate options into mutation only when the mutation system exists; preserve their validation-client use independently.
  • Do not add nil checks that silently hide an invalid operation/dependency combination.

Acceptance criteria:

  • Non-mutation operation sets do not create a mutation system or register routeConflictEvents.
  • Each mutation operation still starts the documented mutator ingestion/status/webhook behavior with a non-nil system.
  • audit or webhook plus mutation-controller still applies mutators to expanded resources.
  • Audit/webhook expansion without a mutation operation remains safe and simply does not mutate resultants.
  • Focused tests cover mutation-only and representative non-mutation operation sets and fail when unconditional construction/registration is restored.

Environment:

  • Gatekeeper version: current master
  • Kubernetes version: not version-specific

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions