Skip to content

[EV-6714] Recommend kubernetes.io/metadata.name for namespaceSelector - #3036

Open
ti-afra wants to merge 1 commit into
tigera:mainfrom
ti-afra:labels
Open

ti-afra wants to merge 1 commit into
tigera:mainfrom
ti-afra:labels

Conversation

@ti-afra

@ti-afra ti-afra commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

kubernetes.io/metadata.name is set by Kubernetes on every namespace and is visible in kubectl output and in label pickers. projectcalico.org/name is not, so lead with the Kubernetes label for namespaceSelector.

projectcalico.org/name stays documented. It is still valid for namespaces, and it is the only option for serviceAccountSelector, where Kubernetes has no equivalent automatic label.

Updated Calico, Calico Enterprise, and Calico Cloud.

Copilot AI lite review requested due to automatic review settings September 23, 2026 07:33
@ti-afra
ti-afra requested a review from a team as a code owner September 23, 2026 07:33
@netlify

netlify Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for calico-docs-preview-next ready!

Name Link
🔨 Latest commit bf0bef9
🔍 Latest deploy log https://app.netlify.com/projects/calico-docs-preview-next/deploys/6ab41675bc9a2e0008d5fb65
😎 Deploy Preview https://deploy-preview-3036--calico-docs-preview-next.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview succeeded!

Built without sensitive environment variables

Name Link
🔨 Latest commit bf0bef9
🔍 Latest deploy log https://app.netlify.com/projects/tigera/deploys/6ab4167501777b0008b5071c
😎 Deploy Preview https://deploy-preview-3036--tigera.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 76 (🔴 down 22 from production)
Accessibility: 98 (no change from production)
Best Practices: 92 (no change from production)
SEO: 100 (no change from production)
PWA: -
View the detailed breakdown and full score reports
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Namespace-selector examples remain inconsistent, and label references omit supported global policy resources.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 10 Low severity

Open (10)
What changed in this PR

This PR updates Calico, Calico Enterprise, and Calico Cloud documentation to recommend Kubernetes’ automatic namespace label while retaining the legacy label for compatibility and service-account selection.

Changes:

  • Updates namespace selector examples.
  • Revises label guidance and usage tables.
  • Applies changes across egress gateway and policy documentation.
File Summary
use-cases/​egress-gateways.mdx Updated egress examples; some namespace selectors still use the legacy label.
calico/​network-policy/​get-started/​calico-policy/​calico-labels.mdx Revised label guidance; global policy resources and other references need alignment.
calico-enterprise/​networking/​egress/​egress-gateway-on-prem.mdx Updated on-premises egress examples; legacy namespace selectors remain.
calico-enterprise/​networking/​egress/​egress-gateway-maintenance.mdx Updated maintenance documentation.
calico-enterprise/​networking/​egress/​egress-gateway-azure.mdx Updated Azure egress examples; legacy namespace selectors remain.
calico-enterprise/​networking/​egress/​egress-gateway-aws.mdx Updated AWS egress examples; legacy namespace selectors remain.
calico-enterprise/​network-policy/​policy-best-practices.mdx Updated policy selector guidance.
calico-enterprise/​network-policy/​beginners/​calico-labels.mdx Revised label guidance; global policy resources and other references need alignment.
calico-cloud/​networking/​egress/​egress-gateway-on-prem.mdx Updated on-premises egress examples; legacy namespace selectors remain.
calico-cloud/​networking/​egress/​egress-gateway-maintenance.mdx Updated maintenance documentation.
calico-cloud/​networking/​egress/​egress-gateway-azure.mdx Updated Azure egress examples; legacy namespace selectors remain.
calico-cloud/​networking/​egress/​egress-gateway-aws.mdx Updated AWS egress examples; legacy namespace selectors remain.
calico-cloud/​network-policy/​policy-best-practices.mdx Updated policy selector guidance.
calico-cloud/​network-policy/​beginners/​calico-labels.mdx Revised label guidance; global policy resources and other references need alignment.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread calico-cloud/network-policy/beginners/calico-labels.mdx
Comment thread calico-cloud/networking/egress/egress-gateway-aws.mdx
Comment thread calico-cloud/networking/egress/egress-gateway-azure.mdx
Comment thread calico-cloud/networking/egress/egress-gateway-on-prem.mdx
Comment thread calico-enterprise/network-policy/beginners/calico-labels.mdx
Comment thread calico-enterprise/networking/egress/egress-gateway-aws.mdx
Comment thread calico-enterprise/networking/egress/egress-gateway-azure.mdx
Comment thread calico-enterprise/networking/egress/egress-gateway-on-prem.mdx
Comment thread calico/network-policy/get-started/calico-policy/calico-labels.mdx
Comment thread use-cases/egress-gateways.mdx
Copilot AI review requested due to automatic review settings September 23, 2026 17:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread calico-enterprise/networking/egress/egress-gateway-aws.mdx
Comment thread calico-enterprise/networking/egress/egress-gateway-azure.mdx
Comment thread calico-enterprise/networking/egress/egress-gateway-on-prem.mdx
kubernetes.io/metadata.name is set by Kubernetes on every namespace
and is visible in kubectl output and in label pickers.
projectcalico.org/name is not, so lead with the Kubernetes label for
namespaceSelector.

projectcalico.org/name stays documented. It is still valid for
namespaces, and it is the only option for serviceAccountSelector,
where Kubernetes has no equivalent automatic label.

Updated Calico, Calico Enterprise, and Calico Cloud.
Copilot AI review requested due to automatic review settings September 23, 2026 18:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

| ---------------------------------- | ------------------------------------------------------------ | --------------- | ------ | -------------- |
| `recStatus` | Defines the namespace policy recommendation engine status. | Enabled/Disabled | | Disabled |
| `selector` | Selects the namespaces for generating recommendations. Accepts any [label selector](#selectors) expression. | | | `!(projectcalico.org/name starts with ''tigera-'') && !(projectcalico.org/name starts with ''calico-'') && !(projectcalico.org/name starts with ''kube-'')` |
| `selector` | Selects the namespaces for generating recommendations. Accepts any [label selector](#selectors) expression. | | | `!(kubernetes.io/metadata.name starts with ''tigera-'') && !(kubernetes.io/metadata.name starts with ''calico-'') && !(kubernetes.io/metadata.name starts with ''kube-'')` |
name: deny-app-policy
spec:
namespaceSelector: has(projectcalico.org/name) && projectcalico.org/name not in {"kube-system", "calico-system", "tigera-system"}
namespaceSelector: has(kubernetes.io/metadata.name) && kubernetes.io/metadata.name not in {"kube-system", "calico-system", "tigera-system"}

@ctauchen ctauchen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@ti-afra Thanks! LGTM. What versions does this need to go into? Looks like this is a general repositioning rather than something that reflects code changes. If that's the case, shouldn't it go in all supported versions?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants