fix(helm): omit podSecurityContext block when value is null - #3034
Open
jgarciao wants to merge 1 commit into
Open
fix(helm): omit podSecurityContext block when value is null#3034jgarciao wants to merge 1 commit into
jgarciao wants to merge 1 commit into
Conversation
The gateway pod template rendered `securityContext:` unconditionally, so
setting `podSecurityContext: null` (e.g. to let OpenShift's SCC assign the
UID/GID range) produced `securityContext: null` instead of omitting the
block. Wrap the block in `{{- with .Values.podSecurityContext }}` so a null
value omits it and an explicit value renders unchanged.
Add a helm-unittest suite covering the default, explicit, and null cases.
Fixes NVIDIA#3033
Signed-off-by: Jorge Garcia Oncins <jgarciao@redhat.com>
jgarciao
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
August 31, 2026 13:41
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The gateway pod template rendered
securityContext:unconditionally, so settingpodSecurityContext: nullproducedsecurityContext: nullinstead of omitting the block. This wraps the block in{{- with .Values.podSecurityContext }}so a null value omits it cleanly — the supported way to let OpenShift's SCC assign the UID/GID range — while an explicit value renders unchanged.Related Issue
Fixes #3033
Changes
deploy/helm/openshell/templates/_gateway-workload.tpl: guard the pod-levelsecurityContextblock with{{- with .Values.podSecurityContext }}so a null value omits it.deploy/helm/openshell/tests/gateway_pod_security_context_test.yaml: new helm-unittest suite covering the default (fsGroup: 1000), an explicit override, and the null-omission case.Testing
mise run pre-commitpassesmise run helm:test— 112 passed, including the newgateway pod securityContextsuite)Checklist