Parent issue: #3964
Related operation cleanup: #4051
Describe the solution you'd like
Gatekeeper should construct and inject the mutation system only when a mutation operation is assigned.
Today setupControllers always calls mutation.NewSystem(...). In addition, pkg/controller/mutators/instances.Adder.Add creates conflict-routing channels and registers the routeConflictEvents runnable before the individual mutator controllers check mutation.Enabled(). A status-only, generate-only, or other non-mutation process therefore receives an unused mutation system and runnable.
Use mutation.Enabled() (or an equivalent single source of truth) to align construction and controller registration with these operations:
mutation-webhook
mutation-controller
mutation-status (which documents mutation-controller as implicit)
Workload expansion must remain correct. expansion.System already supports a nil mutation system and should apply mutators to generated resources only when a mutation-controller operation is present.
Suggested scope:
- Avoid constructing
mutation.System when no mutation operation is assigned.
- Return before registering the mutator conflict-routing runnable when mutation is disabled.
- Inject a non-nil mutation system into every mutation webhook/controller that is registered.
- Wire external-data provider cache and client certificate options into mutation only when the mutation system exists; preserve their validation-client use independently.
- Do not add nil checks that silently hide an invalid operation/dependency combination.
Acceptance criteria:
- Non-mutation operation sets do not create a mutation system or register
routeConflictEvents.
- Each mutation operation still starts the documented mutator ingestion/status/webhook behavior with a non-nil system.
audit or webhook plus mutation-controller still applies mutators to expanded resources.
- Audit/webhook expansion without a mutation operation remains safe and simply does not mutate resultants.
- Focused tests cover mutation-only and representative non-mutation operation sets and fail when unconditional construction/registration is restored.
Environment:
- Gatekeeper version: current
master
- Kubernetes version: not version-specific
Parent issue: #3964
Related operation cleanup: #4051
Describe the solution you'd like
Gatekeeper should construct and inject the mutation system only when a mutation operation is assigned.
Today
setupControllersalways callsmutation.NewSystem(...). In addition,pkg/controller/mutators/instances.Adder.Addcreates conflict-routing channels and registers therouteConflictEventsrunnable before the individual mutator controllers checkmutation.Enabled(). A status-only, generate-only, or other non-mutation process therefore receives an unused mutation system and runnable.Use
mutation.Enabled()(or an equivalent single source of truth) to align construction and controller registration with these operations:mutation-webhookmutation-controllermutation-status(which documents mutation-controller as implicit)Workload expansion must remain correct.
expansion.Systemalready supports a nil mutation system and should apply mutators to generated resources only when a mutation-controller operation is present.Suggested scope:
mutation.Systemwhen no mutation operation is assigned.Acceptance criteria:
routeConflictEvents.auditorwebhookplusmutation-controllerstill applies mutators to expanded resources.Environment:
master