Skip to content

chore: scaffold benchmark workload namespace and RBAC - #5

Merged
amh1k merged 1 commit into
mainfrom
chore/workload-namespace-rbac
Sep 13, 2026
Merged

amh1k merged 1 commit into
mainfrom
chore/workload-namespace-rbac

Conversation

@amh1k

@amh1k amh1k commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator

Summary

Scaffold Helm infrastructure for future benchmark execution.

  • Default workloads to the release namespace, with an optional custom namespace and opt-in creation.
  • Add coordinator and runner ServiceAccounts, namespace-scoped RBAC, and coordinator environment variables.
  • No benchmark Jobs or credential Secrets are created during installation. Runtime execution and Secret management remain follow-up work.

Behavior to note

  • Chart-created workload namespaces are retained on uninstall via helm.sh/resource-policy: keep and require manual cleanup. Existing namespaces are not owned by the chart.
  • Secret permissions cover the entire workload namespace. With the default shared namespace, the coordinator can also read or delete OpenEverest Secrets. RBAC cannot restrict access by ownership labels or name prefixes; a dedicated workload namespace separates these permissions.

Validation

  • Helm lint passed.
  • Render checks passed for default and custom namespaces.
  • Confirmed both ServiceAccounts were installed in the local k3d cluster.

Closes #3.

Signed-off-by: amh1k <abdulmoizx97@gmail.com>
@amh1k
amh1k force-pushed the chore/workload-namespace-rbac branch from 94ce1a9 to 422c2b3 Compare September 12, 2026 14:55
@amh1k
amh1k merged commit b966950 into main Sep 13, 2026
4 checks passed
@amh1k
amh1k deleted the chore/workload-namespace-rbac branch October 2, 2026 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Scaffold ServiceAccounts and namespace-scoped RBAC for benchmark workloads

1 participant