Skip to content

fix: remove finalizer when validation label is removed from pod - #179

Merged
miyunari merged 2 commits into
sigstore:mainfrom
sampras343:security-hardening-2
Sep 14, 2026
Merged

miyunari merged 2 commits into
sigstore:mainfrom
sampras343:security-hardening-2

Conversation

@sampras343

@sampras343 sampras343 commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #180

Summary

  • Remove the validation.ml.sigstore.dev/finalizer from pods when the validation.ml.sigstore.dev/ml label is removed
  • Previously the finalizer was left behind, preventing the pod from being garbage-collected

Fix

In the label-absent branch of PodReconciler.Reconcile(), check for and remove the finalizer before cleaning up tracking. This matches the deletion path behavior.

Test plan

  • New unit test: pod with finalizer but no label — verifies finalizer is removed and tracking is cleaned up
  • 9/9 controller specs pass (was 8, added 1)
  • go build ./... passes

When a user removes the validation.ml.sigstore.dev/ml label from a
running pod, the PodReconciler now removes the finalizer before
cleaning up tracking. Previously the finalizer was left behind,
preventing the pod from being garbage-collected until an explicit
deletion event.

Signed-off-by: Sachin Sampras M <sampras343@gmail.com>
Signed-off-by: Sachin Sampras M <sampras343@gmail.com>

@miyunari miyunari left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sampras343 may I ask, why does it need a finalizer at all?

@miyunari
miyunari merged commit ed2c0d7 into sigstore:main Sep 14, 2026
5 checks passed
@sampras343

Copy link
Copy Markdown
Contributor Author

@sampras343 may I ask, why does it need a finalizer at all?

My understanding is that the finalizer currently serves as a signal to distinguish injected pods from uninjected ones in the StatusTracker (pods with label but not mutated by the webhook). It also ensures the reconciler sees the deletion event before the pod is garbage collected.

Now that I'm thinking, both uses could potentially be replaced. The injected-at annotation already marks injection, and the NotFound path in the reconciler already handles cleanup without needing to delay deletion.

Do you think removing the finalizer entirely make sense?
@miyunari

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Finalizer leak when validation label is removed from a running pod

2 participants