Skip to content

Upstreaming network.IP/CIDR to CEL-go from kubernetes - #1238

Merged
TristonianJones merged 11 commits into
cel-expr:masterfrom
tdesrosi:master
Jun 8, 2026
Merged

TristonianJones merged 11 commits into
cel-expr:masterfrom
tdesrosi:master

Conversation

@tdesrosi

Copy link
Copy Markdown
Contributor

Upstream CIDR and IP-related functions from kubernetes into cel-go

This is part of a broader effort to bring network functions from the kubernetes
project into CEL specifications upstream. This is related directly to
issues/1237.

These are currently locked inside k8s.io/apiserver, but they are generally
useful for any policy engine dealing with network logic (firewalls, access lists, etc.).

@tdesrosi

Copy link
Copy Markdown
Contributor Author

/gcbrun

1 similar comment
@TristonianJones

Copy link
Copy Markdown
Collaborator

/gcbrun

@TristonianJones

Copy link
Copy Markdown
Collaborator

FYI @cici37 @jpbetz

Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go
Comment thread ext/network.go
@TristonianJones

Copy link
Copy Markdown
Collaborator

/gcbrun

Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go
Comment thread ext/network.go
Comment thread ext/network.go Outdated
@TristonianJones

Copy link
Copy Markdown
Collaborator

/gcbrun

Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
@tdesrosi

tdesrosi commented Dec 8, 2025

Copy link
Copy Markdown
Contributor Author

A note about these changes: To maintain strict AST-level compatibility with k8s, I'm going with a split registration pattern (declaring signatures in CompileOptions and bindings in ProgramOptions), rather than bundling them in CompileOptions via cel.Function.

When using the modern cel-go helper cel.Function() to register both the global overload (ip(string)) and the member overload (cidr.ip()) simultaneously, the internal dispatcher validation incorrectly flags the self-referencing overload ID "ip" as a collision (overload already exists).

To resolve this collision with the modern helper, we would be forced to rename the overload ID to something distinct like "ip_string". While functionally equivalent, this breaks strict parity with the Kubernetes AST reference data. If requested, we can go this route (and maintain parity minus the "ip" --> "ip_string" difference in overload IDs).

@TristonianJones

Copy link
Copy Markdown
Collaborator

/gcbrun

@TristonianJones

Copy link
Copy Markdown
Collaborator

A note about these changes: To maintain strict AST-level compatibility with k8s, I'm going with a split registration pattern (declaring signatures in CompileOptions and bindings in ProgramOptions), rather than bundling them in CompileOptions via cel.Function.

Actually, there really isn't any difference here between how the bindings are configured. K8s stages it a little differently, but it's materially identical between the two approaches.

When using the modern cel-go helper cel.Function() to register both the global overload (ip(string)) and the member overload (cidr.ip()) simultaneously, the internal dispatcher validation incorrectly flags the self-referencing overload ID "ip" as a collision (overload already exists).

It looks like the function ip overloads aren't properly configured as the overload_id values don't match those in K8s. Take another look as the two overloads in K8s are cidr_ip and string_to_ip.

It's worth looking at the other overloads as well.

@tdesrosi

Copy link
Copy Markdown
Contributor Author

Thanks Tristan, here's one more pass rechecking overloads and member overloads.

Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go

@TristonianJones TristonianJones left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've raised cel-expr/cel-spec#507 to cel-spec, so shortly after both artifacts are checked in and a new cel-spec release cut, let's enable the conformance tests

Comment thread ext/network.go Outdated
Comment thread ext/network.go
Comment thread ext/network.go Outdated
Comment thread ext/network.go
Comment thread ext/network.go Outdated
Comment thread ext/network.go Outdated
Comment thread ext/network.go
Comment thread ext/network.go Outdated
@jpbetz

jpbetz commented Jan 13, 2026

Copy link
Copy Markdown
Contributor

@lalitc375

Comment thread ext/network.go
@jpbetz

jpbetz commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

@TristonianJones kubernetes/kubernetes#134224 (comment) caught an issue with this library that I recommend addressing before releasing upstream.

@tdesrosi

Copy link
Copy Markdown
Contributor Author

Thanks @jpbetz, I caught myself up on kubernetes/kubernetes#134224 (comment), and I've added isStrictCIDR and isInterfaceAddress to try to address it. Let me know if this is the preferred way to handle this. Thanks!

@jpbetz

jpbetz commented Apr 29, 2026

Copy link
Copy Markdown
Contributor

Thanks @jpbetz, I caught myself up on kubernetes/kubernetes#134224 (comment), and I've added isStrictCIDR and isInterfaceAddress to try to address it. Let me know if this is the preferred way to handle this. Thanks!

Comment thread ext/network.go Outdated
@TristonianJones

Copy link
Copy Markdown
Collaborator

/gcbrun

@TristonianJones

Copy link
Copy Markdown
Collaborator

There appear to be a few negative tests which aren't exercised, but I'll add them in a follow up PR that enables the networking cel-spec tests:

  1. Kubernetes evaluates expressions checking the type names, e.g. type(ip("192.168.0.1")) == net.IP and type(cidr("192.168.0.0/24")) == net.CIDR. Though such tests are absent here, they should be covered in the conformance tests.

  2. Kubernetes verifies compile errors for type mismatches, such as passing a CIDR to isIP: isIP(cidr("192.168.0.0/24")) expecting found no matching overload for 'isIP' applied to '(net.CIDR)'.

@TristonianJones
TristonianJones merged commit 551cdfe into cel-expr:master Jun 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants