Merge supplementalGroups when combining pod YAML with builder spec - #2850
Open
amarkdotdev wants to merge 1 commit into
Open
Merge supplementalGroups when combining pod YAML with builder spec#2850amarkdotdev wants to merge 1 commit into
amarkdotdev wants to merge 1 commit into
Conversation
amarkdotdev
force-pushed
the
fix/supplemental-groups-yaml-override
branch
from
July 8, 2026 21:15
6b021f9 to
1f1b028
Compare
amarkdotdev
force-pushed
the
fix/supplemental-groups-yaml-override
branch
from
July 12, 2026 19:19
1f1b028 to
c122a91
Compare
amarkdotdev
force-pushed
the
fix/supplemental-groups-yaml-override
branch
from
July 21, 2026 19:25
c122a91 to
f362607
Compare
jglick
reviewed
Jul 22, 2026
| * Related to jenkinsci/kubernetes-plugin#2444. | ||
| */ | ||
| @WithJenkins | ||
| @ExtendWith(MockitoExtension.class) |
Member
There was a problem hiding this comment.
Avoid Mockito if at all possible.
I see no purpose to this test. Should PodTemplateUtilsTest not be able to cover it?
Member
Author
There was a problem hiding this comment.
moved this into PodTemplateUtilsTest and yanked the mockito test
PodTemplateUtils.combine() only copied runAsUser and runAsGroup into the merged pod securityContext. supplementalGroups configured on the pod template (UI, CasC, or pipeline) were dropped whenever raw pod YAML was present with the Override merge strategy. Add supplementalGroups resolution alongside the existing pod-level security context merge and cover the regression in PodTemplateUtilsTest (no Mockito). Signed-off-by: amarkdotdev <amarkdotdev@users.noreply.github.com>
amarkdotdev
force-pushed
the
fix/supplemental-groups-yaml-override
branch
from
July 27, 2026 20:43
0256698 to
4cb038e
Compare
Member
Author
|
@jglick Dropped |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2849
Summary
supplementalGroupsinPodTemplateUtils.combine(Pod, Pod)alongside existing pod-levelrunAsUser/runAsGrouphandlingPodTemplateUtilsTestandSupplementalGroupsYamlOverrideReproTestProblem
Pod template Supplemental Groups are dropped when raw pod YAML uses Override merge strategy. Jenkins console raw YAML and the live pod both show only:
Test plan
PodTemplateUtilsTest#shouldCombinePodSupplementalGroupsFromTemplateSupplementalGroupsYamlOverrideReproTestmvn verify)