Avoid RBAC errors when Operator can't list or watch Secrets#2793
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 084333630d
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ResourceAttributes: &authorizationv1.ResourceAttributes{ | ||
| Verb: verb, | ||
| Resource: "secrets", | ||
| }, |
There was a problem hiding this comment.
Scope Secret RBAC check to watched namespaces
canListWatchSecrets builds a SelfSubjectAccessReview without resourceAttributes.namespace, which Kubernetes interprets as an all-namespaces check for namespaced resources. In namespace-scoped deployments (for example when WATCH_NAMESPACE/DD_AGENT_WATCH_NAMESPACE limits cache scope and RBAC is granted per namespace), this returns denied even though list/watch is allowed in the watched namespace(s), so secretAccessEnabled is set to false and Secret-backed Helm releases are never processed. This is a functional regression for namespace-scoped RBAC setups.
Useful? React with 👍 / 👎.
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #2793 +/- ##
==========================================
+ Coverage 38.78% 38.85% +0.07%
==========================================
Files 309 309
Lines 26852 27080 +228
==========================================
+ Hits 10414 10522 +108
- Misses 15658 15776 +118
- Partials 780 782 +2
Flags with carried forward coverage won't be shown. Click here to find out more.
... and 3 files with indirect coverage changes Continue to review full report in Codecov by Sentry.
🚀 New features to boost your workflow:
|
| credsManager := config.NewCredentialManagerWithDecryptor(mgr.GetClient(), secrets.NewSecretBackend()) | ||
| // Get call on a cached client initializes informer which requires list and watch permissions. | ||
| // If RBAC restricts list and watch permissions, the informer will log errors and may cause crash loops. | ||
| // Passing Reader avoids informer initialization. |
There was a problem hiding this comment.
nit: This is not really true. What bypasses the initialization is the direct call using mgr.GetAPIReader() which returns a client.Reader instead of client.Client leading to these changes. Which is fine as we don't issue writes, only need read.
* Avoid RBAC errors when Operator can't list or watch Secrets * improve comment (cherry picked from commit 444f938)
…2800) * Avoid RBAC errors when Operator can't list or watch Secrets * improve comment (cherry picked from commit 444f938) Co-authored-by: levan-m <[email protected]>
What does this PR do?
Fixes bug reported in #2791.
Motivation
Additional Notes
Anything else we should know when reviewing?
Minimum Agent Versions
Are there minimum versions of the Datadog Agent and/or Cluster Agent required?
Describe your test plan
kubectl get clusterrole operator-datadog-operator -o json \ | jq ' .rules |= map( if (.resources // [] | index("secrets")) != null then .resources |= map(select(. != "secrets")) else . end ) | .rules += [{"apiGroups":[""],"resources":["secrets"],"verbs":["create","delete","get","patch","update"]}] ' \ | kubectl apply -f - kubectl rollout restart deployment/operator-datadog-operatorObserver errors
..."logger":"klog","msg":"Failed to watch","logger":"UnhandledError","reflector":"pkg/mod/k8s.io/[email protected]/tools/cache/reflector.go:285","type":"*v1.Secret","error":"failed to list *v1.Secret: secrets is forbidden: User \"system:serviceaccount:default:operator-datadog-operator\" cannot list resource \"secrets\" in API group \"\" inUpdate to fixed image; after restart Operator should log
{"level":"INFO","ts":"2026-03-20T19:23:55.561Z","logger":"metadata.helm","msg":"No permission to list/watch Secrets, Helm metadata collection from Secrets will be disabled"}Checklist
bug,enhancement,refactoring,documentation,tooling, and/ordependenciesqa/skip-qalabel