Symptom
case-101.sh <NS> labels both <NS> and <NS>-b with
pod-security.kubernetes.io/enforce=restricted at startup (the namespace-setup loop), but its
cleanup trap restores only the Settings it changed — the PSA labels stay behind.
Run against a throwaway consumer namespace (the documented precedent, e.g. e2e-c101) that is
harmless: the labels die with the namespace. Run against gpustack-system, however, the case
permanently switches the operator's own namespace to restricted enforcement. The next DaemonSet
recreate of the privileged model-manager plugin is then refused by PodSecurity (FailedCreate,
restricted:latest violations), the CSI driver unregisters from that node, and every model volume
on it hangs in ContainerCreating.
How this surfaced
During a closure-verification run of case-101 on a real-kubelet cluster, gpustack-system was
passed as <NS>. The case's own kill-plugin row deleted the plugin Pod, every DaemonSet recreate
was denied, and the case's remaining rows on that node timed out one by one. Earlier green runs of
this case all used a dedicated consumer namespace, so the trap was never visible.
Suggested fix (either or both)
- Refuse to run when
<NS> resolves to the system namespace (SYSTEM_NS in
_model-hub-lib.sh), printing the usage line instead.
- Restore the namespace's prior PSA labels — or remove the two labels it set — in the cleanup
trap, so the case is self-recovering even against a pre-existing namespace.
Relates #667
Symptom
case-101.sh <NS>labels both<NS>and<NS>-bwithpod-security.kubernetes.io/enforce=restrictedat startup (the namespace-setup loop), but itscleanup trap restores only the Settings it changed — the PSA labels stay behind.
Run against a throwaway consumer namespace (the documented precedent, e.g.
e2e-c101) that isharmless: the labels die with the namespace. Run against
gpustack-system, however, the casepermanently switches the operator's own namespace to restricted enforcement. The next DaemonSet
recreate of the privileged model-manager plugin is then refused by PodSecurity (
FailedCreate,restricted:latestviolations), the CSI driver unregisters from that node, and every model volumeon it hangs in
ContainerCreating.How this surfaced
During a closure-verification run of case-101 on a real-kubelet cluster,
gpustack-systemwaspassed as
<NS>. The case's own kill-plugin row deleted the plugin Pod, every DaemonSet recreatewas denied, and the case's remaining rows on that node timed out one by one. Earlier green runs of
this case all used a dedicated consumer namespace, so the trap was never visible.
Suggested fix (either or both)
<NS>resolves to the system namespace (SYSTEM_NSin_model-hub-lib.sh), printing the usage line instead.trap, so the case is self-recovering even against a pre-existing namespace.
Relates #667