aws-samples / aws-samples/sample-openclaw-multi-tenant-platform
Post-review deferred items (from #9/#11 review)
- Dominant language
- Shell
- Stars
- 41
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
Deferred non-blocking findings from the #9/#11 review, batched:
- [ ] `SandboxTemplate` hardcodes the `gvisor` toleration — parameterize the
tier-owned scheduling fields (toleration + nodeSelector) from
`sandbox.runtimeClassName` per the ADR-0007 extension contract, with a
rendered-fixture test proving a values-only new tier schedules correctly
- [ ] Conformance script: run in a dedicated `conformance-${RUN_ID}` namespace
with run-scoped PVC names + cleanup trap; add a gVisor × NetworkPolicy
combined probe (allowed 443 + denied non-443 under the gvisor RuntimeClass)
- [ ] Amazon VPC CNI add-on: select an explicitly supported version for the
declared EKS version and document the upgrade procedure (currently floats)
- [ ] Fix EKS version drift in comments (1.34 → 1.35)
- [ ] Evaluate `NETWORK_POLICY_ENFORCING_MODE=strict` with enumerated
startup flows and rollback criteria (ADR-0008 startup-window caveat)
Contributor guide
Research direction
Start with the ADR-0007 extension contract, ADR-0008 startup-window caveat, the SandboxTemplate, and the conformance script. Work through each deferred finding separately, including the rendered-fixture test and gVisor × NetworkPolicy probe; done requires all listed scheduling, namespace cleanup, version, documentation, and rollback criteria items to be addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes, shell
- Domain
- devops, documentation, infrastructure, security, testing
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100