dongjoon-hyun opened a new pull request, #884:
URL: https://github.com/apache/spark-kubernetes-operator/pull/884

   ### What changes were proposed in this pull request?
   
   This PR aims to add a `ValidatingAdmissionPolicy` to the Helm chart, so that 
the `kueue.x-k8s.io/queue-name` label of a started `SparkApplication` or 
`SparkCluster` cannot change.
   
   - It is installed with `operatorRbac.kueue.enabled` and matches the watched 
namespaces.
   - Like Kueue, the label can change only before the resource starts 
(`Submitted` or `ScheduledToRestart`) or while a `SparkCluster` is `Suspended`. 
The operator follows such a change since SPARK-59766.
   - Update the documentation and the `kueue` E2E test.
   
   ### Why are the changes needed?
   
   Currently, the label of a running resource can change while its admitted 
`Workload` keeps the quota in the old queue. Kueue prevents this for its 
built-in integrations with a webhook, but `spark.apache.org` resources are not 
among them. A CRD validation rule cannot access `metadata.labels`.
   
   ### Does this PR introduce _any_ user-facing change?
   
   Yes, but only when `operatorRbac.kueue.enabled` is set. The Kueue 
integration is not released yet. The latest release is 
[1.0.0](https://github.com/apache/spark-kubernetes-operator/releases/tag/1.0.0) 
(2026-07-23).
   
   ### How was this patch tested?
   
   Pass the CIs with the updated `kueue` E2E test. I also verified the policy 
manually on a `kind` cluster (K8s 1.37.0).
   
   ### Was this patch authored or co-authored using generative AI tooling?
   
   Generated-by: Claude Opus 5.5


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to