Skip to content

feat: Add default affinity to OPA server Pods - #814

Closed
marc-merino wants to merge 2 commits into
stackabletech:mainfrom
marc-merino:opa-client-pod-affinity
Closed

marc-merino wants to merge 2 commits into
stackabletech:mainfrom
marc-merino:opa-client-pod-affinity

Conversation

@marc-merino

@marc-merino marc-merino commented Sep 28, 2026 •

Copy link
Copy Markdown

Description

When clusterConfig.authorization.opa is configured, prefer to schedule HBase masters and regionservers on nodes with OPA server Pods. The new default pod affinity has weight 50 and selects the configured OPA cluster by the discovery ConfigMap name. REST servers keep their existing affinity because the OPA authorization coprocessors run in master and regionserver processes.

The preference supplements the existing HBase and HDFS affinities. Without OPA authorization, the defaults are unchanged; role and role group affinity overrides continue to take precedence. This scheduling preference does not guarantee co-location or change service routing. It selects OPA Pods in the HBase namespace, and assumes the OPA discovery ConfigMap has the same name as the OpaCluster.

This addresses opa-operator#525 and follows trino-operator#924. Companion Kafka operator PR: kafka-operator#1031.

Definition of Done Checklist

Author

  • Changes are OpenShift compatible (preferred pod affinity only)
  • Changes are offline compatible
  • Release note snippet added
  • Integration tests passed (requires a Kubernetes cluster)

Reviewer

  • Code contains useful comments
  • Unit test cases added for OPA and unchanged defaults
  • Documentation updated
  • Changelog updated

Acceptance

  • Proper release label has been added

Knit-Group: kg_20260928_53b541
Knit-Bundle: opa-client-pod-affinity
Knit-Group: kg_20260928_ef2936
Knit-Bundle: opa-client-pod-affinity
@stackable-cla

stackable-cla Bot commented Sep 28, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant