Skip to content

fix(chart): use leaderElection.namespace for leader election RBAC - #476

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes-sigs:mainfrom
DsThakurRawat:fix/helm-leader-election-rbac-namespace
Sep 19, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes-sigs:mainfrom
DsThakurRawat:fix/helm-leader-election-rbac-namespace

Conversation

@DsThakurRawat

Copy link
Copy Markdown
Contributor

What type of PR is this?
/kind bug

What this PR does / why we need it:
When leaderElection.namespace is overridden in values.yaml (for example to kube-system), the chart templated the leader election Role and RoleBinding into the default release namespace rather than honoring the overridden namespace. As a result, the controller could not acquire or renew leader election leases in the target namespace due to missing RBAC permissions.

This PR updates charts/node-readiness-controller/templates/rbac.yaml to:

  1. Use default (include "node-readiness-controller.namespace" .) .Values.leaderElection.namespace for the Role and RoleBinding namespace.
  2. Guard the leader election Role and RoleBinding with {{- if .Values.leaderElection.enabled }}, omitting them when leader election is disabled.
  3. Add unit tests in charts/node-readiness-controller/tests/rbac_test.yaml verifying default release namespace behavior, namespace override behavior, and disabled leader election.

Which issue(s) this PR fixes:
Fixes #473

Special notes for your reviewer:
Verified locally:

  • ./hack/verify-all.sh passed (boilerplate, chart drift, links, govulncheck clean)
  • make test passed (controller 86.3%, webhook 82.4%)
  • make lint passed (0 issues)

Signed-off-by: Divyansh Rawat <divyanshrawatofficial@gmail.com>
@kubernetes-prow kubernetes-prow Bot added the kind/bug Categorizes issue or PR as related to a bug. label Sep 19, 2026
@netlify

netlify Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for node-readiness-controller canceled.

Name Link
🔨 Latest commit 497740d
🔍 Latest deploy log https://app.netlify.com/projects/node-readiness-controller/deploys/6aae579b8449150008762425

@kubernetes-prow kubernetes-prow Bot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Sep 19, 2026
@kubernetes-prow

Copy link
Copy Markdown

Hi @DsThakurRawat. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow kubernetes-prow Bot added needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Sep 19, 2026
@ajaysundark

Copy link
Copy Markdown
Contributor

/ok-to-test
/lgtm

@kubernetes-prow kubernetes-prow Bot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Sep 19, 2026
@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Sep 19, 2026
@ajaysundark

Copy link
Copy Markdown
Contributor

/approve

@kubernetes-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ajaysundark, DsThakurRawat

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 19, 2026
@ajaysundark

Copy link
Copy Markdown
Contributor

Thanks for the fix!

@kubernetes-prow
kubernetes-prow Bot merged commit 191f41c into kubernetes-sigs:main Sep 19, 2026
11 checks passed
@rawadhossain rawadhossain mentioned this pull request Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/bug Categorizes issue or PR as related to a bug. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Helm chart leader election Role and RoleBinding ignore leaderElection.namespace

2 participants