Nahum LitvinKubernetes, containers and sandboxes, from the production side
Kubernetes2 min read

My first open source PR was 3 lines

An unhandled AppArmor case, millions of log lines, and a CLA nobody at work could pick.

We ran the Security Profiles Operator to ship AppArmor profiles to our Kubernetes nodes. It worked. It also logged the same error over and over:

getting owner profile: the node status owner is of an unknown kind

Millions of lines of it. The profiles still loaded, so nothing was broken. Just loud.

The operator keeps a status object per node for every profile, and a reconciler looks up which profile owns it. That lookup was a switch on the owner's kind. Seccomp was in it. SELinux was in it, twice. AppArmor wasn't.

So on 30 November 2023 I opened issue #1993 and asked three honest questions: is this important, does it mean something is wrong, and can someone guide me to a fix. An hour later I sent the fix myself as PR #1994:

	case "AppArmorProfile":
		prof = &apparmorapi.AppArmorProfile{}

Plus the import. Three lines.

Writing it took minutes. Getting it merged took 4 days, and none of the delay was the fix itself:

  • The linter failed on import order. Then on a whitespace change I couldn't see. My actual comment on the PR was "I have no idea what fails, can any1 explain?"
  • The CLA bot blocked it. Corporate or individual? Nobody on our internal Slack knew which one I should sign, so the PR sat until someone decided.
  • The e2e tests needed a maintainer to type /ok-to-test and /retest for me, more than once.

Sascha Grunert did all of that: pasted the exact linter diff, retriggered the tests, approved it. It merged on 4 December.

The lesson I took from it: a first PR is mostly about learning the project's machinery, the linter, the CLA, the bots, the slash commands. The code is the small part.

References

Comments