From d697bd4e4a152c82448eaf0d5fd817d82ea090e1 Mon Sep 17 00:00:00 2001 From: Stuart Taylor Date: Tue, 18 Aug 2026 10:37:57 +0100 Subject: [PATCH 1/2] feat(sdm-relay): support priorityClassName on the relay Pod Adds an optional strongdm.deployment.priorityClassName value, rendered into the Deployment pod spec alongside the existing nodeSelector/tolerations. Lets operators protect the relay from preemption/eviction under node pressure (e.g. system-cluster-critical), which matters because losing the relay means losing brokered cluster access. Empty by default, so existing installs are unchanged. values.schema.json and values.test.yaml updated; chart bumped 2.6.4 -> 2.7.0 (minor). --- deployments/sdm-relay/Chart.yaml | 2 +- deployments/sdm-relay/templates/deployment.yaml | 3 +++ deployments/sdm-relay/values.schema.json | 4 ++++ deployments/sdm-relay/values.test.yaml | 2 ++ deployments/sdm-relay/values.yaml | 1 + 5 files changed, 11 insertions(+), 1 deletion(-) diff --git a/deployments/sdm-relay/Chart.yaml b/deployments/sdm-relay/Chart.yaml index 829668f..fa5c8d7 100644 --- a/deployments/sdm-relay/Chart.yaml +++ b/deployments/sdm-relay/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v2 name: sdm-relay kubeVersion: ">= 1.16.0-0" -version: 2.6.5 +version: 2.7.0 description: StrongDM Relay type: application icon: https://raw.githubusercontent.com/strongdm/charts/main/sdm_icon.png diff --git a/deployments/sdm-relay/templates/deployment.yaml b/deployments/sdm-relay/templates/deployment.yaml index 846380a..bb0ef7e 100644 --- a/deployments/sdm-relay/templates/deployment.yaml +++ b/deployments/sdm-relay/templates/deployment.yaml @@ -28,6 +28,9 @@ spec: serviceAccountName: {{ include "strongdm.serviceAccountName" . }} {{- end }} terminationGracePeriodSeconds: 10 + {{- with .Values.strongdm.deployment.priorityClassName }} + priorityClassName: {{ . }} + {{- end }} nodeSelector: {{- with .Values.strongdm.deployment.nodeSelector }} {{- toYaml . | nindent 8 }} diff --git a/deployments/sdm-relay/values.schema.json b/deployments/sdm-relay/values.schema.json index 96ed1b0..e071b1f 100644 --- a/deployments/sdm-relay/values.schema.json +++ b/deployments/sdm-relay/values.schema.json @@ -159,6 +159,10 @@ "tolerations": { "description": "Pod node tolerations.", "type": "array" + }, + "priorityClassName": { + "description": "PriorityClass name for the Pod. Empty (the default) leaves it unset, so the Pod schedules at the cluster's global-default priority.", + "type": "string" } } }, diff --git a/deployments/sdm-relay/values.test.yaml b/deployments/sdm-relay/values.test.yaml index e7eff06..d5d3d9d 100644 --- a/deployments/sdm-relay/values.test.yaml +++ b/deployments/sdm-relay/values.test.yaml @@ -23,3 +23,5 @@ strongdm: baz: false rbac: create: true + deployment: + priorityClassName: system-cluster-critical diff --git a/deployments/sdm-relay/values.yaml b/deployments/sdm-relay/values.yaml index 11ef2bb..fed726b 100644 --- a/deployments/sdm-relay/values.yaml +++ b/deployments/sdm-relay/values.yaml @@ -65,6 +65,7 @@ strongdm: labels: {} # @schema description: Map of labels to add to the Deployment. nodeSelector: {} # @schema description: Pod node selectors. tolerations: [] # @schema description: Pod node tolerations. + priorityClassName: "" # @schema description: PriorityClass name for the Pod. Empty (the default) leaves it unset, so the Pod schedules at the cluster's global-default priority. pod: # @schema description: Pod configuration. annotations: {} # @schema description: Map of annotations to add to Pods. From c62ea8b8dc6d8c9058190c9005f312bff97d35f8 Mon Sep 17 00:00:00 2001 From: Stuart Taylor Date: Wed, 19 Aug 2026 20:52:24 +0100 Subject: [PATCH 2/2] feat(sdm-proxy): support priorityClassName on the proxy Pod Mirrors the sdm-relay change for the proxy chart. Adds an optional strongdm.deployment.priorityClassName value, rendered into the Deployment pod spec alongside the existing nodeSelector/tolerations. Lets operators protect the proxy from preemption/eviction under node pressure (e.g. system-cluster-critical). Empty by default, so existing installs are unchanged. values.schema.json and values.test.yaml updated; chart bumped 2.7.6 -> 2.8.0 (minor). --- deployments/sdm-proxy/Chart.yaml | 2 +- deployments/sdm-proxy/templates/deployment.yaml | 3 +++ deployments/sdm-proxy/values.schema.json | 4 ++++ deployments/sdm-proxy/values.test.yaml | 2 ++ deployments/sdm-proxy/values.yaml | 1 + 5 files changed, 11 insertions(+), 1 deletion(-) diff --git a/deployments/sdm-proxy/Chart.yaml b/deployments/sdm-proxy/Chart.yaml index 697dde2..64fd562 100644 --- a/deployments/sdm-proxy/Chart.yaml +++ b/deployments/sdm-proxy/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v2 name: sdm-proxy kubeVersion: ">= 1.16.0-0" -version: 2.7.6 +version: 2.8.0 description: StrongDM Proxy type: application icon: https://raw.githubusercontent.com/strongdm/charts/main/sdm_icon.png diff --git a/deployments/sdm-proxy/templates/deployment.yaml b/deployments/sdm-proxy/templates/deployment.yaml index 5a15c57..4449504 100644 --- a/deployments/sdm-proxy/templates/deployment.yaml +++ b/deployments/sdm-proxy/templates/deployment.yaml @@ -30,6 +30,9 @@ spec: serviceAccountName: {{ include "strongdm.serviceAccountName" . }} {{- end }} terminationGracePeriodSeconds: 10 + {{- with .Values.strongdm.deployment.priorityClassName }} + priorityClassName: {{ . }} + {{- end }} nodeSelector: {{- with .Values.strongdm.deployment.nodeSelector }} {{- toYaml . | nindent 8 }} diff --git a/deployments/sdm-proxy/values.schema.json b/deployments/sdm-proxy/values.schema.json index e83dd55..504cf3b 100644 --- a/deployments/sdm-proxy/values.schema.json +++ b/deployments/sdm-proxy/values.schema.json @@ -158,6 +158,10 @@ } } } + }, + "priorityClassName": { + "description": "PriorityClass name for the Pod. Empty (the default) leaves it unset, so the Pod schedules at the cluster's global-default priority.", + "type": "string" } } }, diff --git a/deployments/sdm-proxy/values.test.yaml b/deployments/sdm-proxy/values.test.yaml index a261510..65d95ff 100644 --- a/deployments/sdm-proxy/values.test.yaml +++ b/deployments/sdm-proxy/values.test.yaml @@ -25,3 +25,5 @@ strongdm: baz: false rbac: create: true + deployment: + priorityClassName: system-cluster-critical diff --git a/deployments/sdm-proxy/values.yaml b/deployments/sdm-proxy/values.yaml index f62c636..f403f1c 100644 --- a/deployments/sdm-proxy/values.yaml +++ b/deployments/sdm-proxy/values.yaml @@ -61,6 +61,7 @@ strongdm: replicaCount: 2 # @schema description: Number of Pods to run in the deployment. nodeSelector: {} # @schema description: Pod node selectors. tolerations: [] # @schema description: Pod node tolerations. + priorityClassName: "" # @schema description: PriorityClass name for the Pod. Empty (the default) leaves it unset, so the Pod schedules at the cluster's global-default priority. topologySpreadConstraints: # @schema description: Pod spread constraints. Keys in this map are topology keys. See https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/ for more info. kubernetes.io/hostname: maxSkew: 1