aws-samples / aws-samples/sample-openclaw-multi-tenant-platform

Post-review deferred items (from #9/#11 review)

Open
#15 0 comments 0 reactions 0 assignees View on GitHub
area/runtime area/security
Dominant language
Shell
Stars
41
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Deferred non-blocking findings from the #9/#11 review, batched:

- [ ] `SandboxTemplate` hardcodes the `gvisor` toleration — parameterize the
tier-owned scheduling fields (toleration + nodeSelector) from
`sandbox.runtimeClassName` per the ADR-0007 extension contract, with a
rendered-fixture test proving a values-only new tier schedules correctly
- [ ] Conformance script: run in a dedicated `conformance-${RUN_ID}` namespace
with run-scoped PVC names + cleanup trap; add a gVisor × NetworkPolicy
combined probe (allowed 443 + denied non-443 under the gvisor RuntimeClass)
- [ ] Amazon VPC CNI add-on: select an explicitly supported version for the
declared EKS version and document the upgrade procedure (currently floats)
- [ ] Fix EKS version drift in comments (1.34 → 1.35)
- [ ] Evaluate `NETWORK_POLICY_ENFORCING_MODE=strict` with enumerated
startup flows and rollback criteria (ADR-0008 startup-window caveat)

Contributor guide

Open the contributing guide

Research direction

Start with the ADR-0007 extension contract, ADR-0008 startup-window caveat, the SandboxTemplate, and the conformance script. Work through each deferred finding separately, including the rendered-fixture test and gVisor × NetworkPolicy probe; done requires all listed scheduling, namespace cleanup, version, documentation, and rollback criteria items to be addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes, shell
Domain
devops, documentation, infrastructure, security, testing
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.