• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

opendefensecloud / solution-arsenal / 37751911677
79%

Build:
DEFAULT BRANCH: main
Ran 08 Oct 2026 09:03AM UTC
Jobs 1
Files 94
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

08 Oct 2026 08:44AM UTC coverage: 78.558% (-0.02%) from 78.58%
37751911677

push

github

web-flow
fix(controller): respect targetRef.namespace for RegistryBindings (#850)

## What
Same-namespace RegistryBindings are now matched on the full Target key,
not just the name.

- `buildPullSecretsLookup` skips bindings whose effective `targetRef`
namespace isn't the Target's namespace
- `mapRegistryBindingToTarget` enqueues `targetRef.namespace` when set,
instead of the binding's namespace
- new helper `registryBindingTargetKey(rb)`
(`cmp.Or(targetRef.namespace, rb.Namespace)`), reused by the follow-up
PRs

Part of #565.

## Why
`buildPullSecretsLookup` lists RegistryBindings by the
`spec.targetRef.name` index only -> a binding `A/rb` with `targetRef:
{name: foo, namespace: B}` gets applied to Target `A/foo`, which then
renders with a pull secret meant for `B/foo`. ReleaseBindings had the
same bug class, covered by the spec at `target_controller_test.go:1328`.

`mapRegistryBindingToTarget` enqueued `rb.Namespace` -> a binding
pointing into another namespace never triggered a reconcile of its
Target. Not visible today because cross-ns RegistryBindings aren't
collected yet, but #565 needs it.

A binding with `targetRef.namespace` set to its own namespace counts as
same-namespace. That's more lenient than ReleaseBindings (only `""`
counts there, `helpers.go:339`), on purpose: rejecting an explicit own
namespace would only surprise people.

## Testing
envtest, red first, then green:

```
make test testargs="--focus='RegistryBinding|mapRegistryBindingToTarget' ./pkg/controller"
Ran 15 of 143 Specs, 15 Passed, 0 Failed
```

Before the fix the new specs failed as expected (leak spec got
`leaked-creds`, map spec got namespace `provider` instead of `user`).
`go vet ./pkg/...` and `make lint` clean.

## Checklist
- [x] Tests added/updated (leak spec, own-namespace spec, map func
specs)
- [x] No breaking changes (or upgrade path documented above)
- [x] Readable commit history (squashed and cleaned up as desired)
- [x] AI code review considered and comments resolved... (continued)

8 of 8 new or added lines in 2 files covered. (100.0%)

5 existing lines in 2 files now uncovered.

5078 of 6464 relevant lines covered (78.56%)

33.77 hits per line

Coverage Regressions

Lines Coverage ∆ File
4
76.75
-0.34% pkg/controller/target_controller.go
1
88.66
-1.03% pkg/discovery/runner.go
Jobs
ID Job ID Ran Files Coverage
1 37751911677.1 08 Oct 2026 09:03AM UTC 94
78.56
GitHub Action Run
Source Files on build 37751911677
  • Tree
  • List 94
  • Changed 4
  • Source Changed 2
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #37751911677
  • 5d6f38ab on github
  • Prev Build on main (#37611577630)
  • Next Build on main (#37796593255)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc