use existing kubeClient when saving helper logs#502
Merged
Conversation
Signed-off-by: sceneryback <afterbreeze@hotmail.com>
Contributor
Author
|
/assign |
Contributor
Author
|
Hi @derekbit please take a look |
derekbit
approved these changes
Jun 10, 2025
derekbit
left a comment
Member
There was a problem hiding this comment.
LGTM. Thanks for contribution.
blake-hamm
added a commit
to blake-hamm/bhamm-lab
that referenced
this pull request
Jun 9, 2026
…provisioner.git to v0.0.36 (#176) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [https://github.com/rancher/local-path-provisioner.git](https://github.com/rancher/local-path-provisioner) | patch | `v0.0.31` → `v0.0.36` | --- ### Release Notes <details> <summary>rancher/local-path-provisioner (https://github.com/rancher/local-path-provisioner.git)</summary> ### [`v0.0.36`](https://github.com/rancher/local-path-provisioner/releases/tag/v0.0.36): Local Path Provisioner v0.0.36 [Compare Source](rancher/local-path-provisioner@v0.0.35...v0.0.36) #### Security Fixes - Fixed [HelperPod Template Injection](GHSA-7fxv-8wr2-mfc4), a high-severity HelperPod template injection vulnerability. A user with permission to edit the `local-path-config` ConfigMap could manipulate `helperPod.yaml` and cause the provisioner to create unsafe HelperPods during PVC provisioning or cleanup operations. This release adds HelperPod template validation to reject unsafe security-sensitive fields such as privileged containers, `hostPath` volumes, and dangerous pod security settings. #### What's Changed - chore(ci): bump aquasecurity/trivy-action to v0.35.0 by [@​macedogm](https://github.com/macedogm) in [#​563](rancher/local-path-provisioner#563) - chore: remove trivy-scan.yaml by [@​derekbit](https://github.com/derekbit) in [#​565](rancher/local-path-provisioner#565) - chore: pin GH actions to commit sha by [@​c3y1huang](https://github.com/c3y1huang) in [#​564](rancher/local-path-provisioner#564) - chore: use registry.suse.com/bci/golang by [@​derekbit](https://github.com/derekbit) in [#​566](rancher/local-path-provisioner#566) - chore: remove dapper by [@​derekbit](https://github.com/derekbit) in [#​567](rancher/local-path-provisioner#567) - chore: revert to golang:1.26.1-alpine image by [@​derekbit](https://github.com/derekbit) in [#​568](rancher/local-path-provisioner#568) - chore: update to golang 1.26.2 by [@​derekbit](https://github.com/derekbit) in [#​570](rancher/local-path-provisioner#570) - fix: update dockerfile by [@​derekbit](https://github.com/derekbit) in [#​574](rancher/local-path-provisioner#574) - chore: pin kind, kubectl and kustomize versins by [@​derekbit](https://github.com/derekbit) in [#​575](rancher/local-path-provisioner#575) - fix: qualify image references to avoid short-name resolution and Docker Hub rate limits by [@​bejaratommy](https://github.com/bejaratommy) in [#​573](rancher/local-path-provisioner#573) - helm: make debug logging configurable via values by [@​bejaratommy](https://github.com/bejaratommy) in [#​572](rancher/local-path-provisioner#572) - fix: add helper pod template validation by [@​derekbit](https://github.com/derekbit) in [#​576](rancher/local-path-provisioner#576) - fix: relax helper pod template validation by [@​derekbit](https://github.com/derekbit) in [#​577](rancher/local-path-provisioner#577) #### New Contributors - [@​c3y1huang](https://github.com/c3y1huang) made their first contribution in [#​564](rancher/local-path-provisioner#564) - [@​bejaratommy](https://github.com/bejaratommy) made their first contribution in [#​573](rancher/local-path-provisioner#573) **Full Changelog**: <rancher/local-path-provisioner@v0.0.35...v0.0.36> ### [`v0.0.35`](https://github.com/rancher/local-path-provisioner/releases/tag/v0.0.35): Local Path Provisioner v0.0.35 [Compare Source](rancher/local-path-provisioner@v0.0.34...v0.0.35) #### What's Changed - Add FOSSA scanning workflow by [@​macedogm](https://github.com/macedogm) in [#​551](rancher/local-path-provisioner#551) - Build linux/ppc64le images through build on GitHub Actions by [@​kishen-v](https://github.com/kishen-v) in [#​554](rancher/local-path-provisioner#554) - updated golang to 1.26.0 by [@​jgoodall](https://github.com/jgoodall) in [#​557](rancher/local-path-provisioner#557) - feat: Allow custom node affinity keys by [@​ipantchev](https://github.com/ipantchev) in [#​559](rancher/local-path-provisioner#559) - chore: update golang to 1.26.1 by [@​derekbit](https://github.com/derekbit) in [#​561](rancher/local-path-provisioner#561) - chore(release): bump to v0.0.35 by [@​derekbit](https://github.com/derekbit) in [#​562](rancher/local-path-provisioner#562) #### New Contributors - [@​macedogm](https://github.com/macedogm) made their first contribution in [#​551](rancher/local-path-provisioner#551) - [@​jgoodall](https://github.com/jgoodall) made their first contribution in [#​557](rancher/local-path-provisioner#557) - [@​ipantchev](https://github.com/ipantchev) made their first contribution in [#​559](rancher/local-path-provisioner#559) **Full Changelog**: <rancher/local-path-provisioner@v0.0.34...v0.0.35> ### [`v0.0.34`](https://github.com/rancher/local-path-provisioner/releases/tag/v0.0.34): Local Path Provisioner v0.0.34 [Compare Source](rancher/local-path-provisioner@v0.0.33...v0.0.34) #### What's Changed - fix: mitigate the impact of enforcing a pathPattern prefix by [@​mantissahz](https://github.com/mantissahz) in [#​547](rancher/local-path-provisioner#547) - fix: read allowUnsafePathPattern from storageclass annotations by [@​derekbit](https://github.com/derekbit) in [#​548](rancher/local-path-provisioner#548) - chore(release): bump to v0.0.34 by [@​derekbit](https://github.com/derekbit) in [#​549](rancher/local-path-provisioner#549) - feat: allow specifying additional annotations on StorageClass by [@​utkuozdemir](https://github.com/utkuozdemir) in [#​550](rancher/local-path-provisioner#550) #### New Contributors - [@​utkuozdemir](https://github.com/utkuozdemir) made their first contribution in [#​550](rancher/local-path-provisioner#550) **Full Changelog**: <rancher/local-path-provisioner@v0.0.33...v0.0.34> ### [`v0.0.33`](https://github.com/rancher/local-path-provisioner/releases/tag/v0.0.33): Local Path Provisioner v0.0.33 [Compare Source](rancher/local-path-provisioner@v0.0.32...v0.0.33) #### What's Changed - fix: don't try to clean up pvs on nodes that are gone by [@​marcusramberg](https://github.com/marcusramberg) in [#​480](rancher/local-path-provisioner#480) - upgrade go to 1.24.6 by [@​lizzzcai](https://github.com/lizzzcai) in [#​521](rancher/local-path-provisioner#521) - bump go 1.25 by [@​farazkhawaja](https://github.com/farazkhawaja) in [#​526](rancher/local-path-provisioner#526) - add storageClass.allowedTopologies in helm chart by [@​lizzzcai](https://github.com/lizzzcai) in [#​522](rancher/local-path-provisioner#522) - fix(chart): correct ServiceAccount namespace in ClusterRoleBinding by [@​J3m3](https://github.com/J3m3) in [#​528](rancher/local-path-provisioner#528) - Add common labels to helperPod config map template by [@​michaeldvinci](https://github.com/michaeldvinci) in [#​519](rancher/local-path-provisioner#519) - chore: update pod\_test.go by [@​derekbit](https://github.com/derekbit) in [#​531](rancher/local-path-provisioner#531) - fix: give clusterrole update on pvc by [@​marcusramberg](https://github.com/marcusramberg) in [#​530](rancher/local-path-provisioner#530) - Add support for s390x architecture by [@​SanyogDeshmukh](https://github.com/SanyogDeshmukh) in [#​534](rancher/local-path-provisioner#534) - feat: add priorityClassName support for provisioner and helper pods by [@​dibaro](https://github.com/dibaro) in [#​525](rancher/local-path-provisioner#525) - fix: prohibit the reference path in pathPattern by [@​mantissahz](https://github.com/mantissahz) in [#​542](rancher/local-path-provisioner#542) - chore: explicitly set `hostUsers` by [@​jcpunk](https://github.com/jcpunk) in [#​541](rancher/local-path-provisioner#541) - fix: podDisruptionBudget renders correctly in all cases by [@​jcpunk](https://github.com/jcpunk) in [#​540](rancher/local-path-provisioner#540) - chore(release): bump to 0.0.33 by [@​derekbit](https://github.com/derekbit) in [#​543](rancher/local-path-provisioner#543) #### New Contributors - [@​marcusramberg](https://github.com/marcusramberg) made their first contribution in [#​480](rancher/local-path-provisioner#480) - [@​lizzzcai](https://github.com/lizzzcai) made their first contribution in [#​521](rancher/local-path-provisioner#521) - [@​farazkhawaja](https://github.com/farazkhawaja) made their first contribution in [#​526](rancher/local-path-provisioner#526) - [@​J3m3](https://github.com/J3m3) made their first contribution in [#​528](rancher/local-path-provisioner#528) - [@​michaeldvinci](https://github.com/michaeldvinci) made their first contribution in [#​519](rancher/local-path-provisioner#519) - [@​SanyogDeshmukh](https://github.com/SanyogDeshmukh) made their first contribution in [#​534](rancher/local-path-provisioner#534) - [@​dibaro](https://github.com/dibaro) made their first contribution in [#​525](rancher/local-path-provisioner#525) **Full Changelog**: <rancher/local-path-provisioner@v0.0.32...v0.0.33> ### [`v0.0.32`](https://github.com/rancher/local-path-provisioner/releases/tag/v0.0.32): Local Path Provisioner v0.0.32 [Compare Source](rancher/local-path-provisioner@v0.0.31...v0.0.32) #### What's Changed - fix: helm install command by [@​antonengelhardt](https://github.com/antonengelhardt) in [#​468](rancher/local-path-provisioner#468) - feat: add ability to set custom namespace by [@​tzabbi](https://github.com/tzabbi) in [#​478](rancher/local-path-provisioner#478) - fix: multiple paths is not true random (fix [#​342](rancher/local-path-provisioner#342)) by [@​tulequ](https://github.com/tulequ) in [#​496](rancher/local-path-provisioner#496) - Build local-path-provisioner for ppc64le by [@​kishen-v](https://github.com/kishen-v) in [#​492](rancher/local-path-provisioner#492) - build(deps): bump golang.org/x/net from 0.34.0 to 0.38.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​488](rancher/local-path-provisioner#488) - helm: add location for setting PodDisruptionBudget by [@​jcpunk](https://github.com/jcpunk) in [#​490](rancher/local-path-provisioner#490) - use existing kubeClient when saving helper logs by [@​sceneryback](https://github.com/sceneryback) in [#​502](rancher/local-path-provisioner#502) - fix: do not override nodeName, if exists by [@​BohdanTkachenko](https://github.com/BohdanTkachenko) in [#​499](rancher/local-path-provisioner#499) - Allow overriding kubeclient burst and qps settings by [@​badstreff](https://github.com/badstreff) in [#​503](rancher/local-path-provisioner#503) - chore: typo by [@​ldicarlo](https://github.com/ldicarlo) in [#​507](rancher/local-path-provisioner#507) - chore: update dependencies by [@​derekbit](https://github.com/derekbit) in [#​506](rancher/local-path-provisioner#506) - Fix helper pod tolerations by [@​sbocinec](https://github.com/sbocinec) in [#​486](rancher/local-path-provisioner#486) - Change default nodePathMap value in storageClassConfigs in values.yml to \[] by [@​Birkenstab](https://github.com/Birkenstab) in [#​510](rancher/local-path-provisioner#510) - Helm: Add abbility to set additional tolerations to helper pod via values by [@​verdel](https://github.com/verdel) in [#​511](rancher/local-path-provisioner#511) - OCI based helm chart build workflow added by [@​supu2](https://github.com/supu2) in [#​501](rancher/local-path-provisioner#501) - fix: rename workflows by [@​derekbit](https://github.com/derekbit) in [#​512](rancher/local-path-provisioner#512) - fix: rename workflows by [@​derekbit](https://github.com/derekbit) in [#​513](rancher/local-path-provisioner#513) - fix: fix chart tag by [@​derekbit](https://github.com/derekbit) in [#​514](rancher/local-path-provisioner#514) - fix: fix Invalid Semantic Version by [@​derekbit](https://github.com/derekbit) in [#​515](rancher/local-path-provisioner#515) - chore(release): bump to v0.0.32 by [@​derekbit](https://github.com/derekbit) in [#​516](rancher/local-path-provisioner#516) #### New Contributors - [@​antonengelhardt](https://github.com/antonengelhardt) made their first contribution in [#​468](rancher/local-path-provisioner#468) - [@​tzabbi](https://github.com/tzabbi) made their first contribution in [#​478](rancher/local-path-provisioner#478) - [@​tulequ](https://github.com/tulequ) made their first contribution in [#​496](rancher/local-path-provisioner#496) - [@​kishen-v](https://github.com/kishen-v) made their first contribution in [#​492](rancher/local-path-provisioner#492) - [@​dependabot](https://github.com/dependabot)\[bot] made their first contribution in [#​488](rancher/local-path-provisioner#488) - [@​jcpunk](https://github.com/jcpunk) made their first contribution in [#​490](rancher/local-path-provisioner#490) - [@​sceneryback](https://github.com/sceneryback) made their first contribution in [#​502](rancher/local-path-provisioner#502) - [@​BohdanTkachenko](https://github.com/BohdanTkachenko) made their first contribution in [#​499](rancher/local-path-provisioner#499) - [@​badstreff](https://github.com/badstreff) made their first contribution in [#​503](rancher/local-path-provisioner#503) - [@​ldicarlo](https://github.com/ldicarlo) made their first contribution in [#​507](rancher/local-path-provisioner#507) - [@​Birkenstab](https://github.com/Birkenstab) made their first contribution in [#​510](rancher/local-path-provisioner#510) - [@​verdel](https://github.com/verdel) made their first contribution in [#​511](rancher/local-path-provisioner#511) - [@​supu2](https://github.com/supu2) made their first contribution in [#​501](rancher/local-path-provisioner#501) **Full Changelog**: <rancher/local-path-provisioner@v0.0.31...v0.0.32> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTYuMiIsInVwZGF0ZWRJblZlciI6IjQzLjIxNi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: Renovate Bot <renovate@bhamm-lab.com> Reviewed-on: https://codeberg.org/blake-hamm/bhamm-lab/pulls/176
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
when saving helper logs, there is no need to create a new kubeClient. Just use the existing one in provisioner