Skip to content

fix: [NPM] bound generated namespaceSelector work - #4869

Closed
Isaiah Raya (rayaisaiah) wants to merge 1 commit into
isaiahraya/npm-nsselector-scopefrom
isaiahraya/npm-bound-work
Closed

Isaiah Raya (rayaisaiah) wants to merge 1 commit into
isaiahraya/npm-nsselector-scopefrom
isaiahraya/npm-bound-work

Conversation

@rayaisaiah

Copy link
Copy Markdown
Contributor

Draft — split out of #4859, stacked, pending a keep/drop decision.

Reason for Change:

Flattening a namespaceSelector's multi-value In requirements produces the Cartesian product of their values with no ceiling, so a small, valid policy object can expand into hundreds of thousands of internal selectors, each becoming its own IPSet and ACL. This is a resource-exhaustion concern for the shared NPM DaemonSet in a multi-tenant cluster.

Change:

  • Bound the flattened selector count before any allocation and reject oversized selectors through the controller error path. This is a deliberate limit on large inputs, not an absolute per-cluster bound.

Scope is full NPM v2 on Linux and Windows. v1 and NPM Lite are unchanged.

Note: stacked on the negation-only scoping change because the bound counts the generated all-namespaces anchor. Base retargets after the parent merges. Foundational fix; the additional per-port/ACL ceilings and exactness refinements from #4859 are not yet folded in.

Requirements:

  • uses conventional commit messages
  • includes documentation in this description
  • adds unit tests

Flattening a namespaceSelector's multi-value In requirements produces the
Cartesian product of their values, and the code had no ceiling on the result.
The count is the product of the value counts, so it grows exponentially with the
number of such requirements: 19 two-value requirements in one small, valid
policy expand to 2^19 selectors. Each one is deep-copied and later becomes its
own IPSet and ACL, so a single policy object could exhaust the memory of the NPM
DaemonSet on every node and take policy programming down cluster-wide.

Compute the product before any allocation and reject the selector once it would
exceed maxFlattenedNSSelectors. The check divides instead of multiplying so it
cannot overflow, and it runs per requirement, so a single very wide requirement
is rejected on the first iteration too. The cap is far above any workable policy
since a selector fanning out that wide would already be unusable as rules.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant