Skip to content

fix(deploy): rename hardened Kubernetes manifest to wardnet.yaml - #144

Draft
seonghobae wants to merge 22 commits into
mainfrom
fix/kubernetes-manifest-path-20260901
Draft

seonghobae wants to merge 22 commits into
mainfrom
fix/kubernetes-manifest-path-20260901

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #75 only after this exact bounded slice reaches protected main.

Buyer / operator outcome

This branch is the foundation-first repository-path migration for the hardened Kubernetes asset plus its public/operator documentation landing:

  • move the hardened source asset to deploy/kubernetes/wardnet.yaml without renaming live Kubernetes resource identities;
  • make README/operator/buyer/security references use the canonical repository path;
  • retain a strict stale-path regression with only bounded migration/rollback-history exceptions;
  • add a bounded docs/index.md landing and repository-link validation;
  • preserve the externally provisioned administrator-Secret boundary and current non-production/release truth.

The latest pre-restack source repair, 8d656d313c18c2b304d3e1a563317a967c23e250, only rewrites one iterator closure in tests/kubernetes_manifest_path.rs to satisfy the Rust 1.98 Clippy contract without changing asserted path semantics.

Fresh protected-main adoption — 2026-09-23 KST

Protected truth advanced from the branch's previous second parent a52ccd0a24a727d9349bb32def7713882d8cad1e to main@f8260f1e03836039ff9463dd99fa982e4e270c4b through #155's fail-closed administrator-authentication work.

The branch adopted that complete protected delta non-destructively with two-parent merge commit 447fb6a7cda34e5520005f18a97d78e4f585fb64, preserving predecessor f5383585d3588d7b63b00a11bba61fa0d875743e as first parent and protected f8260f1e... as second parent. All non-overlapping #155 files/blobs are inherited from protected main. The two overlapping documentation paths were resolved causally rather than choosing either side wholesale: the Wardnet README/path-migration rewrite now documents the protected ADMIN_TOKEN / write-capable ADMIN_TOKENS / WAF_IDS_CREDENTIALS_PATH fail-closed non-loopback readiness contract, and docs/deployment/production.md retains both the renamed manifest lifecycle and the same protected recovery guidance.

Fresh compare is behind_by=0, merge base exactly f8260f1e03836039ff9463dd99fa982e4e270c4b, mechanically mergeable, and the protected-main-relative effective delta remains the same 13-path bounded migration slice: AGENTS/CHANGELOG/CLAUDE/README, one core documentation string, the manifest rename, buyer/deployment/doctoring docs, docs/index.md, and three path/deployment/documentation regressions. No force push, destructive rebase, source reconstruction, central-workflow copy, or protected-main bypass was used.

Stack / single-writer decision

This narrower path-only migration is the prerequisite for broad rename PR #114. #114 also renames the same Kubernetes asset and surrounding product/runtime identities, so it remains Draft and must later non-force adopt the protected result of this PR rather than race overlapping rename authority. If this slice is replaced, the successor must prove complete transfer of every unique path/documentation/test delta before #144 can be retired.

Exact-current gate

Current exact head is 447fb6a7cda34e5520005f18a97d78e4f585fb64. All predecessor workflow conclusions are historical after the ancestry movement.

Fresh repository runs for this exact head are queued and therefore not GREEN: CI 35850201935, Fuzz 35850201962, Security Scan 35850201893, SAST Semgrep 35850202001, and CodeQL PR 35850201873. Required central review/security workflows must likewise be read fresh for this unchanged head before any integration decision. Queued evidence does not authorize rerun churn, status synthesis, or bypass.

The generic solo-maintainer approval defect remains canonical central .github#772 work and delegated CodeQL settlement remains .github#1929 work. Wardnet does not copy central workflows or alter product source to manufacture those receipts.

Keep Draft until one unchanged exact current head has terminal then-live repository/security/coverage/package/SBOM/provenance/review/thread/governance evidence and fresh protected-base compatibility. No gate weakening, force push, destructive rebase, mutable foreign dependency, source copy, cross-service SQL, no-op redispatch, predecessor-evidence reuse, self/model approval, or routine administrator bypass.

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

devin-ai-integration[bot]

This comment was marked as resolved.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 75030a2e-29f3-4ab3-ba1e-6792591fc4fc

📥 Commits

Reviewing files that changed from the base of the PR and between 9616b94 and b07e4d2.

📒 Files selected for processing (1)
  • tests/kubernetes_manifest_path.rs

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Kubernetes 매니페스트를 deploy/kubernetes/wardnet.yaml로 추가하고 저장소의 경로 참조를 갱신했습니다. 기존 Kubernetes 리소스와 외부 관리자 시크릿 참조는 유지합니다. 경로 회귀 검사는 이전 파일과 허용되지 않은 레거시 참조를 차단합니다.

Changes

Kubernetes 매니페스트 경로 마이그레이션

Layer / File(s) Summary
새 Kubernetes 매니페스트
deploy/kubernetes/wardnet.yaml
네임스페이스, 2Gi PVC, gateway Deployment, 비선택적 ADMIN_TOKEN Secret 참조, 헬스 프로브, 보안 컨텍스트 및 HTTP Service를 정의합니다.
운영 참조 및 문서 갱신
AGENTS.md, CLAUDE.md, README.md, CHANGELOG.md, crates/waf-ids-core/src/lib.rs, docs/commercial/..., docs/deployment/..., docs/doctoring/..., docs/index.md
매니페스트 경로를 deploy/kubernetes/wardnet.yaml로 변경합니다. README와 문서 랜딩 페이지에 Wardnet의 제품 범위, 운영 정보 및 증거 경계를 반영합니다.
경로 회귀 검증
tests/deployment_manifest.rs, tests/kubernetes_manifest_path.rs, tests/documentation_landing.rs
새 매니페스트를 검사 대상으로 등록합니다. 이전 파일의 부재와 문서 링크의 실제 경로를 검증합니다. 명시적 마이그레이션·롤백 문맥만 레거시 경로를 허용합니다.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to b07e4

This change completes the Wardnet manifest-path migration while retaining controlled migration and rollback references. No concrete current-head merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 4 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed 변경 사항은 이슈 [#75]의 주요 요구사항과 일치합니다. 새 경로를 추가하고 기존 Secret 경계, 리소스 식별자, 프로브, 포트 및 보안 컨텍스트를 유지했습니다. 운영 문서, 구매자 검토 문서, 배포 자산 참조, 회귀 테스트 및 경로 검증을 갱신했습니다. 마이그레이션과 롤백 시 파일 경로와 클러스터 리소스 식별자가 다르다는 점도 문서화했습니다.
Out of Scope Changes check ✅ Passed README 전면 개편, docs/index.md 추가 및 문서 링크 검증은 PR 목표와 이슈 [#75]에 명시된 제품 문서화 및 탐색성 개선 범위에 포함됩니다. 제공된 변경 요약에는 관련 없는 런타임 리소스, API, 패키지 또는 제품 기능 변경이 없습니다.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR 제목은 주요 변경 사항인 hardened Kubernetes manifest의 경로 변경을 정확하고 간결하게 설명합니다.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/kubernetes-manifest-path-20260901

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae enabled auto-merge (squash) September 1, 2026 16:09
coderabbitai[bot]

This comment was marked as resolved.

@seonghobae seonghobae added the bug Something isn't working label Sep 1, 2026 — with ChatGPT Codex Connector
@opencode-agent
opencode-agent Bot disabled auto-merge September 1, 2026 17:01
@seonghobae
seonghobae enabled auto-merge (squash) September 1, 2026 17:30
devin-ai-integration[bot]

This comment was marked as resolved.

@opencode-agent
opencode-agent Bot disabled auto-merge September 1, 2026 18:26
@seonghobae
seonghobae enabled auto-merge (squash) September 1, 2026 18:34
@opencode-agent
opencode-agent Bot disabled auto-merge September 1, 2026 18:55
@seonghobae seonghobae added the documentation Improvements or additions to documentation label Sep 1, 2026 — with ChatGPT Codex Connector
devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

coderabbitai[bot]

This comment was marked as resolved.

@seonghobae seonghobae added the type: bug Defect or incorrect behavior label Sep 2, 2026 — with ChatGPT Codex Connector

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

@opencode-agent
opencode-agent Bot disabled auto-merge September 2, 2026 19:44
cwl-noema-review[bot]
cwl-noema-review Bot previously approved these changes Sep 2, 2026

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The PR correctly renames the hardened Kubernetes manifest from deploy/kubernetes/waf-ids-ai-soc.yaml to deploy/kubernetes/wardnet.yaml and updates all corresponding references in documentation, agent guides, and source code. Crucially, it introduces a structural regression contract in tests/kubernetes_manifest_path.rs to prevent the accidental reintroduction of the legacy path in operational contexts, while allowing it for explicit migration history. It also adds tests/documentation_landing.rs to ensure GitHub Pages links resolve correctly, addressing a previously identified 404 risk.

Reviewed changed lines

  • AGENTS.md:20 (RIGHT): Correctly updates the remediation path for k8s/IaC misconfigs to the new filename.
  • tests/deployment_manifest.rs:651 (RIGHT): Adds a concrete test to ensure the legacy manifest file is physically absent from the distributable tree.
  • tests/kubernetes_manifest_path.rs:78 (RIGHT): Implements a granular allowlist for legacy paths, distinguishing between dangerous operational references (e.g., kubectl apply) and safe historical documentation.
  • tests/documentation_landing.rs:63 (RIGHT): Implements a repository-wide link validator for the landing page to prevent broken links to the main branch.

Adversarial validation

  • tests/kubernetes_manifest_path.rs:145 (RIGHT) falsified: The stale-reference scanner can be bypassed by placing the legacy path in a non-text file. — The scanner explicitly iterates over TEXT_EXTENSIONS; however, the legacy path is a source-tree reference typically found in docs/scripts, which are covered.
  • tests/kubernetes_manifest_path.rs:102 (RIGHT) falsified: The scanner fails if the test file itself contains the legacy path literal as a negative test case. — The test uses runtime fragment concatenation (lines 138-140) to avoid literal matches, ensuring the test file remains subject to the scan without triggering it.
  • Residual risk: low

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: 9616b94ac1ecf70038071a8c9395348694e6312c
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 0 new potential issues.

Devin Review

@seonghobae
seonghobae enabled auto-merge (squash) September 3, 2026 04:34
@opencode-agent
opencode-agent Bot disabled auto-merge September 3, 2026 15:45
@seonghobae
seonghobae marked this pull request as draft September 4, 2026 18:50
@seonghobae seonghobae removed the status: needs-review Open pull request requiring current-head review or checks label Sep 6, 2026
@seonghobae seonghobae removed the documentation Improvements or additions to documentation label Sep 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work status: draft type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rename Kubernetes manifest to wardnet.yaml after external-secret hardening lands

2 participants