fix: [NPM] bound generated namespaceSelector work - #4869
Closed
Isaiah Raya (rayaisaiah) wants to merge 1 commit into
Closed
Isaiah Raya (rayaisaiah) wants to merge 1 commit into
Isaiah Raya (rayaisaiah) wants to merge 1 commit into
Conversation
Flattening a namespaceSelector's multi-value In requirements produces the Cartesian product of their values, and the code had no ceiling on the result. The count is the product of the value counts, so it grows exponentially with the number of such requirements: 19 two-value requirements in one small, valid policy expand to 2^19 selectors. Each one is deep-copied and later becomes its own IPSet and ACL, so a single policy object could exhaust the memory of the NPM DaemonSet on every node and take policy programming down cluster-wide. Compute the product before any allocation and reject the selector once it would exceed maxFlattenedNSSelectors. The check divides instead of multiplying so it cannot overflow, and it runs per requirement, so a single very wide requirement is rejected on the first iteration too. The cap is far above any workable policy since a selector fanning out that wide would already be unusable as rules. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft — split out of #4859, stacked, pending a keep/drop decision.
Reason for Change:
Flattening a namespaceSelector's multi-value
Inrequirements produces the Cartesian product of their values with no ceiling, so a small, valid policy object can expand into hundreds of thousands of internal selectors, each becoming its own IPSet and ACL. This is a resource-exhaustion concern for the shared NPM DaemonSet in a multi-tenant cluster.Change:
Scope is full NPM v2 on Linux and Windows. v1 and NPM Lite are unchanged.
Note: stacked on the negation-only scoping change because the bound counts the generated all-namespaces anchor. Base retargets after the parent merges. Foundational fix; the additional per-port/ACL ceilings and exactness refinements from #4859 are not yet folded in.
Requirements: