Skip to content

fix: skip Pod metadata retries for standalone containers - #1026

Open
devantler wants to merge 8 commits into
kubescape:mainfrom
devantler:codex/standalone-pod-retries-4717
Open

devantler wants to merge 8 commits into
kubescape:mainfrom
devantler:codex/standalone-pod-retries-4717

Conversation

@devantler

@devantler devantler commented Oct 11, 2026 •

Copy link
Copy Markdown

Overview

Standalone containers do not have a Kubernetes Pod to look up. They currently enter the Pod-metadata retry path anyway, which produces misleading errors and delays their monitoring setup.

Skip that lookup when the namespace or Pod name is missing, while retaining runtime monitoring and rule registration. Containers with an addressable Pod still use the existing lookup and error handling, including when their container name is incomplete.

Standalone monitors use the runtime container ID so separate containers do not share an empty Kubernetes identity. Removal retains that original identity even if Kubernetes metadata arrives later.

How to Test

On Linux, run the affected packages with the race detector:

go test -race ./pkg/utils ./pkg/rulemanager ./pkg/containerwatcher/v2 ./pkg/networkstream/v1
go vet ./pkg/utils ./pkg/rulemanager ./pkg/containerwatcher/v2 ./pkg/networkstream/v1

The regressions cover standalone and partial identities, normal Pod error handling, network-stream setup, separate runtime IDs, and removal after metadata enrichment.

Linux validation passed. That fork-only workflow checks out and asserts contribution commit 5d6287e0c14c2f8f64908d9a82f1aa02bd7c9d48; it is not included in this PR. The regressions were also exercised before their fixes. Local Linux tests were not run on my macOS host.

Related issues/PRs

Resolves #1025.

Checklist before requesting a review

  • My code follows the style guidelines of this project.
  • I have commented on the non-obvious identity handling.
  • I have performed a self-review of the complete change.
  • I have added regression tests.
  • New and existing unit tests pass locally with my changes (validated on Linux CI instead).

The template mentions dev, but that branch no longer exists. This targets main, consistent with recent merged code changes.

Summary by CodeRabbit

  • Bug Fixes
    • Standalone containers without complete Kubernetes pod identity are now handled using their runtime identity instead of waiting for Kubernetes workload data.
    • Standalone containers remain independently registered, and their registrations can still be found when metadata changes or they are removed.

Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2ca791e8-34f3-4b89-9c8a-bd297d6e8adf

📥 Commits

Reviewing files that changed from the base of the PR and between 71818df and 5d6287e.


📒 Files selected for processing (8)
  • pkg/containerwatcher/v2/containercallback.go
  • pkg/containerwatcher/v2/containercallback_standalone_test.go
  • pkg/networkstream/v1/network_stream.go
  • pkg/networkstream/v1/network_stream_standalone_test.go
  • pkg/rulemanager/containercallbacks.go
  • pkg/rulemanager/containercallbacks_standalone_test.go
  • pkg/rulemanager/rule_manager.go
  • pkg/utils/container.go

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The change adds a shared predicate for Kubernetes pod identity. The container watcher and network stream use it to gate shared-data work. RuleManager skips the shared-data wait for standalone containers and preserves their registration keys across events.

Changes

Standalone container handling

Layer / File(s) Summary
Pod-identity gates for shared-data lookups
pkg/utils/container.go, pkg/containerwatcher/v2/containercallback.go, pkg/containerwatcher/v2/containercallback_standalone_test.go, pkg/networkstream/v1/network_stream.go, pkg/networkstream/v1/network_stream_standalone_test.go
The new HasKubernetesPodIdentity helper requires a namespace and Pod name. The container watcher skips shared-data lookup without that identity. The network stream skips workload enrichment for those containers. Tests check lookup behavior, entity visibility, and removal.
Standalone rule registration identity
pkg/rulemanager/rule_manager.go, pkg/rulemanager/containercallbacks.go, pkg/rulemanager/containercallbacks_standalone_test.go
RuleManager skips the shared-data wait for containers without pod identity. It tracks standalone registration keys by runtime container ID and reuses or deletes them across events. Tests cover shared-data reads, independent registrations, and removal after metadata enrichment.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: matthyx


Merge Risk: ⚪ Minimal · up to 5d628

The reviewed standalone-container handling has no established issue that needs resolution before merge.

Pre-merge checks | Passed 4 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 28.57% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 8 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: standalone containers skip Kubernetes Pod metadata retries.
Linked Issues check Passed Issue #1025 requires standalone containers to bypass Kubernetes Pod-data waits in the container watcher and rule manager, while preserving monitoring, per-registration removal, host handling, and Pod …
Out of Scope Changes check Passed The changes stay within the linked objective. The network-stream guard prevents the same Kubernetes-only enrichment path for standalone containers. Runtime-key tracking and removal tests support the r…

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Standalone containers enter Kubernetes shared-data retries

1 participant