From f40667ab8635744649ec148340c3b853292bb3eb Mon Sep 17 00:00:00 2001 From: Richard Wall Date: Tue, 29 Sep 2026 11:24:53 +0000 Subject: [PATCH 1/2] Pin kyverno pod-security policies to release-1.19 kyverno/policies#1544 deleted pod-security/ from its main branch on 2026-09-29. verify-pod-security-standards builds that path without a ref, so it now fails in every project that uses the helm module: Error: evalsymlink failure on '/tmp/kustomize-.../pod-security/enforce' : lstat /tmp/kustomize-.../pod-security: no such file or directory - Build from the release-1.19 branch, which matches the kyverno v1.19 tool version we pin and still has the policies. - The output is byte-for-byte identical to what main produced before the deletion: the same 17 ClusterPolicies. Co-Authored-By: Claude Signed-off-by: Richard Wall --- modules/helm/helm.mk | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/modules/helm/helm.mk b/modules/helm/helm.mk index 7147c95d..22270323 100644 --- a/modules/helm/helm.mk +++ b/modules/helm/helm.mk @@ -128,8 +128,10 @@ shared_verify_targets += verify-helm-unittest $(bin_dir)/scratch/kyverno: @mkdir -p $@ +# Pinned to a release branch because kyverno/policies deleted pod-security/ from main in +# https://github.com/kyverno/policies/pull/1544. Keep it in step with the kyverno tool version. $(bin_dir)/scratch/kyverno/pod-security-policy.yaml: | $(NEEDS_KUSTOMIZE) $(bin_dir)/scratch/kyverno - @$(KUSTOMIZE) build https://github.com/kyverno/policies/pod-security/enforce > $@ + @$(KUSTOMIZE) build "https://github.com/kyverno/policies/pod-security/enforce?ref=release-1.19" > $@ # Extra arguments for kyverno apply. kyverno_apply_extra_args := From ad9e0642cce32fbe61db40104d40f3240b4f3e1f Mon Sep 17 00:00:00 2001 From: Richard Wall Date: Tue, 29 Sep 2026 17:14:38 +0100 Subject: [PATCH 2/2] Pin the kyverno policies commit and put it in the cached file name Pin the commit at the tip of release-1.19 rather than the branch name. The branch can still receive pushes, so pinning it would leave every downstream verify job open to the same silent change that broke it when pod-security/ was deleted from main. The release branch is not a compatibility boundary. The pod-security/ bundle is identical on every release branch from release-1.12 to release-1.19, and each policy declares kyverno 1.6.0 as its minimum version. The branches are snapshots for the kyverno.io website. The comment says so, so nobody bumps this along with the kyverno tool. Put the commit in kyverno_policies_version and in the name of the cached policy file, as the module already does for the chart archive. Bumping the version now builds a new file instead of reusing a stale copy in _bin/scratch. Cite kyverno/policies#1543 and name pod-security-vpol/ as the successor in the comment, so whoever bumps this next knows where the policies went. Co-Authored-By: Claude Fable 5.1 Signed-off-by: Richard Wall --- modules/helm/helm.mk | 27 +++++++++++++++++++++------ 1 file changed, 21 insertions(+), 6 deletions(-) diff --git a/modules/helm/helm.mk b/modules/helm/helm.mk index 22270323..50274318 100644 --- a/modules/helm/helm.mk +++ b/modules/helm/helm.mk @@ -128,10 +128,25 @@ shared_verify_targets += verify-helm-unittest $(bin_dir)/scratch/kyverno: @mkdir -p $@ -# Pinned to a release branch because kyverno/policies deleted pod-security/ from main in -# https://github.com/kyverno/policies/pull/1544. Keep it in step with the kyverno tool version. -$(bin_dir)/scratch/kyverno/pod-security-policy.yaml: | $(NEEDS_KUSTOMIZE) $(bin_dir)/scratch/kyverno - @$(KUSTOMIZE) build "https://github.com/kyverno/policies/pod-security/enforce?ref=release-1.19" > $@ +# The commit of kyverno/policies to build the pod-security policies from. +# Pinned because https://github.com/kyverno/policies/pull/1544 deleted pod-security/ +# from main; it was superseded by the CEL policies in pod-security-vpol/, see +# https://github.com/kyverno/policies/issues/1543. +# +# This is the tip of the release-1.19 branch, one of the last commits that still +# has pod-security/. The branch name does not matter: the pod-security/ bundle is +# identical on every release branch from release-1.12 to release-1.19, and each +# policy declares kyverno 1.6.0 as its minimum version. The release branches are +# snapshots for the kyverno.io website, not compatibility boundaries. So this +# does not need to change when the kyverno tool in modules/tools is bumped. +kyverno_policies_version := ef9843f08d25b3555fe69616f8612c9f915af5d4 + +# The version is part of the file name, so a change to it builds a new file +# instead of reusing a stale cached one. +kyverno_policy_file := $(bin_dir)/scratch/kyverno/pod-security-policy-$(kyverno_policies_version).yaml + +$(kyverno_policy_file): | $(NEEDS_KUSTOMIZE) $(bin_dir)/scratch/kyverno + @$(KUSTOMIZE) build "https://github.com/kyverno/policies/pod-security/enforce?ref=$(kyverno_policies_version)" > $@ # Extra arguments for kyverno apply. kyverno_apply_extra_args := @@ -170,9 +185,9 @@ endif ## security policy rules. ## ## @category [shared] Generate/ Verify -verify-pod-security-standards: $(helm_chart_archive) $(bin_dir)/scratch/kyverno/pod-security-policy.yaml | $(NEEDS_KYVERNO) $(NEEDS_HELM) +verify-pod-security-standards: $(helm_chart_archive) $(kyverno_policy_file) | $(NEEDS_KYVERNO) $(NEEDS_HELM) @$(HELM) template $(helm_chart_archive) $(INSTALL_OPTIONS) \ - | $(KYVERNO) apply $(bin_dir)/scratch/kyverno/pod-security-policy.yaml \ + | $(KYVERNO) apply $(kyverno_policy_file) \ $(kyverno_apply_extra_args) \ --resource - \ --table