Skip to content

Conversation

@kevinpthorne
Copy link

@kevinpthorne kevinpthorne commented Dec 30, 2025

Before this PR

init-spock job could not run in a hardened, restricted k8s namespace

After this PR

init-spock runs under a restricted security level by default, with editable values.

@kevinpthorne kevinpthorne marked this pull request as ready for review December 30, 2025 20:54
@kevinpthorne
Copy link
Author

I have a feeling I shouldn't have bumped the version. I'll revert those changes too

@kevinpthorne kevinpthorne force-pushed the kevinpthorne/spock-security-context branch from 38edbe4 to db49e6e Compare December 30, 2025 21:14
@kevinpthorne kevinpthorne force-pushed the kevinpthorne/spock-security-context branch from db49e6e to 2192a1e Compare December 30, 2025 21:14
@kevinpthorne kevinpthorne force-pushed the kevinpthorne/spock-security-context branch from cd6a02b to 498bc49 Compare December 30, 2025 21:41
@kevinpthorne kevinpthorne force-pushed the kevinpthorne/spock-security-context branch from 498bc49 to 909c2ca Compare December 30, 2025 21:41
@kevinpthorne
Copy link
Author

Tested on my local cluster ✅

@kevinpthorne
Copy link
Author

the init job is failing due to not being able to authenticate with the rw host. Looking into why -- hoping its not related to this change.

@kevinpthorne
Copy link
Author

I had a bad hba config - this looks like it works:

🎯 Configuring Spock for nodes:
 - 🖖 Node: test-data | Hostname: pgedge-cluster-test-data-rw
🔎 Found clusters in namespace pgedge: ['pgedge-cluster-test-data']
✅ All CloudNativePG clusters in namespace ready
✅ pgedge-cluster-test-data-rw is accepting connections
👤 Creating user pgedge on test-data
🖖 Created spock node test-data on pgedge-cluster-test-data-rw
🎉 Spock configuration successfully updated

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant