Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement allowlist framework for dependencies #1443

Merged
merged 14 commits into from
Aug 12, 2024

Conversation

psschwei
Copy link
Collaborator

@psschwei psschwei commented Aug 6, 2024

Signed-off-by: Paul S. Schweigert paul@paulschweigert.com

Allow operators to specify an allowlist of dependencies and allowed versions.

The allowlist is stored in a config file.

A sample allowlist might look like:

allowlist = { "wheel": ["0.44.0", "0.43.2"] }

which would imply that the wheel package is allowed, but only versions 0.43.2 and 0.44.0 .

For this PR, the allowlist is empty, which means all dependencies are allowed, and it is stored locally. In a future PR, this should move into a Kubernetes configmap so that it can be updated without having to rebuild the container.

Each dependency can optionally specify a list of allowed versions. If the list is empty, then all versions of the dependency are allowed.

An example:

allowlist = { "wheel": [] }

This could also be adapted to store a minimum allowed version instead of listing all allowed versions, depending on requirements.

@psschwei psschwei added the WIP work in progress label Aug 6, 2024
@psschwei
Copy link
Collaborator Author

psschwei commented Aug 6, 2024

still need to add tests for the new functionality...

Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>

Allow operators to specify an allowlist of dependencies and allowed
versions.

The allowlist is stored in a config file.

A sample allowlist might look like:

    allowlist = { "wheel": ["0.44.0", "0.43.2"] }

which would imply that the wheel package is allowed, but only versions
0.43.2 and 0.44.0 .

For this PR, the allowlist is empty, which means all dependencies are
allowed, and it is stored locally. In a future PR, this should move
into a Kubernetes configmap so that it can be updated without having
to rebuild the container.

Each dependency can optionally specify a list of allowed versions. If
the list is empty, then all versions of the dependency are allowed.

An example:

    allowlist = { "wheel": [] }

This could also be adapted to store a minimum allowed version instead
of listing all allowed versions, depending on requirements.
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
@psschwei psschwei force-pushed the limit-dependencies branch from 967f06e to 3d93127 Compare August 7, 2024 20:27
@psschwei psschwei removed the WIP work in progress label Aug 7, 2024
@psschwei
Copy link
Collaborator Author

psschwei commented Aug 7, 2024

ok, this should be ready for review now

Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
gateway/api/v1/serializers.py Show resolved Hide resolved
gateway/api/v1/serializers.py Show resolved Hide resolved
gateway/api/v1/serializers.py Outdated Show resolved Hide resolved
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
Signed-off-by: Paul S. Schweigert <paul@paulschweigert.com>
@Tansito Tansito self-requested a review August 12, 2024 14:48
Copy link
Member

@Tansito Tansito left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM Paul, thank you!

@psschwei psschwei merged commit 932e9f9 into Qiskit:main Aug 12, 2024
10 checks passed
@psschwei psschwei deleted the limit-dependencies branch August 12, 2024 15:19
@psschwei
Copy link
Collaborator Author

xref #369

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants