Skip to content

chore: remove agentic target NS ref - #336

Merged
asamal4 merged 1 commit into
lightspeed-core:mainfrom
asamal4:rm-agentic-tns-ref
Oct 6, 2026
Merged

asamal4 merged 1 commit into
lightspeed-core:mainfrom
asamal4:rm-agentic-tns-ref

Conversation

@asamal4

@asamal4 asamal4 commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Description

remove agentic target NS ref, this is no longer used for agentic run spec

Type of change

  • Refactor
  • New feature
  • Bug fix
  • CVE fix
  • Optimization
  • Documentation Update
  • Configuration Update
  • Bump-up service version
  • Bump-up dependent library
  • Bump-up library or tool used for development (does not change the final image)
  • CI configuration change
  • Unit tests improvement

Tools used to create PR

Identify any AI code assistants used in this PR (for transparency and review context)

  • Assisted-by: (e.g., Claude, CodeRabbit, Ollama, etc., N/A if not used)
  • Generated by: (e.g., tool name and version; N/A if not used)

Related Tickets & Documents

  • Related Issue #
  • Closes #

Checklist before requesting a review

  • I have performed a self-review of my code.
  • PR has passed all pre-merge test jobs.
  • If it is a core feature, I have added thorough tests.

Testing

  • Please provide detailed steps to perform tests related to this code change.
  • How were the fix/results from this change verified? Please provide relevant screenshots or results.

Summary by CodeRabbit

  • Documentation
    • Updated the AgenticRun evaluation examples to omit the targetNamespaces setting.
  • Bug Fixes
    • Updated evaluation configurations and tests to reflect that AgenticRun specifications no longer include a namespace restriction.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: lightspeed-core/lightspeed-evaluation/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ebc40a7d-c981-4236-8d83-5791bed6c651
📥 Commits

Reviewing files that changed from the base of the PR and between 86e1d92 and 7e76017.

📒 Files selected for processing (4)
  • README.md
  • docs/agentic_lightspeed_evaluation.md
  • tests/integration/test_evaluation_data_openshift_agentic_run.yaml
  • tests/unit/pipeline/evaluation/test_openshift_agentic_run_driver.py
💤 Files with no reviewable changes (3)
  • README.md
  • tests/unit/pipeline/evaluation/test_openshift_agentic_run_driver.py
  • tests/integration/test_evaluation_data_openshift_agentic_run.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

AgenticRun examples and evaluation test specifications no longer include targetNamespaces. The unit test also removes its assertion for that field.

Changes

AgenticRun namespace configuration

Layer / File(s) Summary
Remove targetNamespaces from examples and tests
README.md, docs/agentic_lightspeed_evaluation.md, tests/integration/test_evaluation_data_openshift_agentic_run.yaml, tests/unit/pipeline/evaluation/test_openshift_agentic_run_driver.py
The documentation examples and integration specifications no longer set targetNamespaces. The unit test no longer supplies or asserts the field; its request assertion remains.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: rioloc

Merge Risk: ⚪ Minimal · up to 7e760

The examples and integration requests still name their intended namespaces. No concrete merge-blocking behavior from omitting the field is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 7e760

The changes are limited to examples and tests, with no verified increase in execution privileges. However, the supported operator behavior when targetNamespaces is omitted has not been established. The namespace containing an AgenticRun does not by itself establish which workloads it can access.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The examples identify intended workload namespaces, but neither request text nor AgenticRun metadata.namespace proves an execution authorization boundary. Maximum accessible namespaces, assets, and cluster resources cannot be determined without the deployed operator and its credentials/RBAC; cluster-wide exposure is not established.

Security Findings and Attack Paths

  • observed — The supplied security assessment retains no verified finding. Its namespace-scope candidate is deferred because the supported operator policy for omitted targetNamespaces is unavailable. Neither attacker reachability nor a cross-namespace authorization bypass has been verified.

Trust Boundaries and Controls

  • inferred — The relevant unresolved boundary is between evaluation-supplied intent/specification and operator-executed workload actions. The unchanged driver constrains placement of control resources, but does not establish whether targetNamespaces previously enforced workload scope, supplied a hint, or was ignored. Its omission therefore cannot yet be classified as either weakened authorization or harmless compatibility cleanup.

Resilience and Maintainability Implications

  • observed — The unchanged client generates a fresh run name per invocation and attempts configured cleanup on normal terminal outcomes and handled polling, approval, or timeout failures. Apply failure returns before cleanup, and the lifecycle has no encompassing finally block for interruption. Deletion of an AgenticRun is not evidence of rollback, deduplication, or containment of workload effects. Whether omission changes those operator-side guarantees remains unresolved rather than a verified PR regression.

Hardening Proposals

  • proposed — Validate the omission against the supported operator revision, including schema/defaulting, execution identity, effective RBAC, and cancellation/cleanup semantics. Document the enforced workload boundary separately from resource placement and natural-language namespace hints; do not assume restoring an obsolete field would enforce authorization.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: removing the agentic target namespace reference.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@asamal4
asamal4 merged commit e3dcc50 into lightspeed-core:main Oct 6, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants