Skip to content

[backport v0.10 - rancher v2.14] reject user operations on rancher-managed resource quota and limit range resources - #1797#1797 - #1798

Merged
andreas-kupries merged 7 commits into
release/v0.10from
extended-quota-enforcement-2.14
Sep 4, 2026
Merged

andreas-kupries merged 7 commits into
release/v0.10from
extended-quota-enforcement-2.14

Conversation

@andreas-kupries

Copy link
Copy Markdown
Contributor

Issue:

rancher/rancher#56774

Companion PR r/rancher rancher/rancher#56804

Problem

The NRQR (Rancher-managed namespace ResourceQuota, identified by label resourcequota.management.cattle.io/default-resource-quota: true) was enforced only at namespace creation time. Any user with RBAC access to resourcequotas could subsequently edit the object directly, fully bypassing project-level enforcement.

The same is true for the LimitRange resource managed by Rancher.

Solution

Added validating webhooks for ResourceQuota and LimitRange objects.
The companion PR modifies Rancher to send its requests using the webhook bypass.
This means that the new validators see only user initiated requests, and only have to reject operations involving the marker label. IOW

  • Reject attempts to create resources bearing the marker label
  • Reject attempts to delete resources bearing the marker label
  • Reject attempts to change resources bearing the marker label
    • This includes changes attempting to strip the marker (demotion to unmanaged)
  • Reject attempts to add a marker to to un-marked resources (i.e. prevent promotion to managed)

Copilot AI and others added 7 commits September 3, 2026 16:52
….github.com>

boilerplate from copilot still present. unit tests and checks completely rewritten

added validators for resource quota to webhook
added docs, extended webhook codegen

the new validator rejects creation, edition, deletion of rancher managed resources.
the new validator further rejects promotion of unmanaged to managed resource, and vice versa.
the managed resource is recognized by its marker label.

the validator is written with the assumption that rancher requests are tagged
with webhook bypass and therefore do not reach the validator.

unit tests.

all of the above for limit range resources as well.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
fix Limitrange typo
fix Resourcequota typo
Co-authored-by: andreas-kupries <577247+andreas-kupries@users.noreply.github.com>
@andreas-kupries
andreas-kupries force-pushed the extended-quota-enforcement-2.14 branch from 9083ae2 to 890b8c3 Compare September 3, 2026 14:53

@snasovich snasovich left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved based on it being the same as #1797

@rohitsuse rohitsuse left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM from Frameworks persepective.

@andreas-kupries
andreas-kupries merged commit 2dd8081 into release/v0.10 Sep 4, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants