feat(helm): scope ClusterRole/ClusterRoleBinding names by release namespace (#2939)

* feat(helm): scope ClusterRole/ClusterRoleBinding names by release namespace

The chart creates cluster-scoped ClusterRole and ClusterRoleBinding
resources with a fixed name derived from the release name. When
multiple Helm releases coexist on the same cluster (multi-tenant),
only one release can own these resources due to Helm ownership
annotations -- the second install fails with a conflict.

Append .Release.Namespace to the ClusterRole and ClusterRoleBinding
names so each release gets its own cluster-scoped resources. The
duplication is harmless (the rules are identical and small) and
eliminates multi-tenant conflicts entirely without requiring external
RBAC management.

Signed-off-by: Brandon Squizzato <bsquizza@redhat.com>

* test(helm): add regression tests for namespace-scoped ClusterRole names

Assert the generated ClusterRole name, ClusterRoleBinding name, and
roleRef all include the release namespace suffix so multi-namespace
installations cannot silently regress to conflicting fixed names.

Signed-off-by: Brandon Squizzato <bsquizza@redhat.com>

---------

Signed-off-by: Brandon Squizzato <bsquizza@redhat.com>
This commit is contained in:
Brandon Squizzato
2026-09-11 17:57:42 +00:00
committed by GitHub
parent 0803c4aa4c
commit 99e83a535e
4 changed files with 40 additions and 3 deletions
@@ -5,7 +5,7 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ include "openshell.fullname" . }}-node-reader
name: {{ include "openshell.fullname" . }}-node-reader-{{ .Release.Namespace }}
labels:
{{- include "openshell.labels" . | nindent 4 }}
rules:
@@ -4,13 +4,13 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ include "openshell.fullname" . }}-node-reader
name: {{ include "openshell.fullname" . }}-node-reader-{{ .Release.Namespace }}
labels:
{{- include "openshell.labels" . | nindent 4 }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ include "openshell.fullname" . }}-node-reader
name: {{ include "openshell.fullname" . }}-node-reader-{{ .Release.Namespace }}
subjects:
- kind: ServiceAccount
name: {{ include "openshell.serviceAccountName" . }}
@@ -9,6 +9,12 @@ release:
namespace: my-namespace
tests:
- it: includes the release namespace in the ClusterRole name
asserts:
- equal:
path: metadata.name
value: openshell-node-reader-my-namespace
- it: grants managed namespace NetworkPolicy apply permissions
set:
server.drivers.kubernetes.workspaceMode: managed
@@ -0,0 +1,31 @@
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
suite: ClusterRoleBinding RBAC
templates:
- templates/clusterrolebinding.yaml
release:
name: openshell
namespace: my-namespace
tests:
- it: includes the release namespace in the ClusterRoleBinding name
asserts:
- equal:
path: metadata.name
value: openshell-node-reader-my-namespace
- it: references the namespace-scoped ClusterRole in roleRef
asserts:
- equal:
path: roleRef.name
value: openshell-node-reader-my-namespace
- it: binds the service account in the release namespace
asserts:
- contains:
path: subjects
content:
kind: ServiceAccount
name: openshell
namespace: my-namespace