* feat(cue/upgrade): auto-remediate legacy CUE syntax at render time
Transparently rewrite CUE templates that use deprecated list arithmetic
(+, *) and conflicting field names (error) so that older definitions
continue to work with CUE ≥ v0.14 (KubeVela ≥ 1.11).
- CUEUpgradeFunc registry with ID, CUE/KubeVela version guards, precheck,
and upgrade function fields
- upgradeListConcatenation: rewrites list1+list2 → list.Concat([list1,list2])
and list*n → list.Repeat(list, n); adds "list" import as needed
- collectAddChain + extractListConcatArgs: flatten left-associative + chains
and existing list.Concat([...]) leaves into a single flat call, so both
fresh chains (a+b+c+d) and partially-upgraded chains produce one
list.Concat([a,b,c,d]) with no nesting across repeated passes
- upgradeErrorFieldLabel: rewrites unquoted `error` field labels to "error"
to avoid conflict with the CUE 0.14 built-in; precheck uses a tighter
\berror\s*: regex to avoid false positives on identifiers like errorMessage
- EnsureCueVersionCompatibility: single entry point used at render time;
LRU cache with TTL eviction, Prometheus metrics, feature flag
- ParseVersion: regex anchored to reject garbage suffixes (e.g. "1.11foo")
while accepting pre-release+build metadata (e.g. "v1.13.0-alpha.1+dev")
- template.go: call EnsureCueVersionCompatibility for every template area
(main, health, custom status, status detail) with correct DefinitionKind
derived from which definition pointer is non-nil
- validate.go: upgrade policy templates before compiling in
validateNoRequiredParameters
- `vela def upgrade FILE [-o OUTPUT]`: upgrades a single .cue file
- `vela def upgrade FILE --validate [--quiet]`: exit 1 if upgrade needed
- `vela def compat definitions` / `vela def compat applications`: scan
cluster definitions/apps for compat issues; output as table or YAML
- Cyclomatic complexity kept below threshold by extracting scanDefinitions,
scanDefRevisions, buildDefCompatReport, scanApplications, scanAppRevision
as standalone functions with options structs
- revisionNum() helper for numeric vN comparison (avoids lexicographic bugs)
- mergeImports() dedup helper shared by ToCUEString and formatCUEString
- ANSI escape sequences replaced with fatih/color for portability
- goconst: "yaml" → outputFormatYAML named constant throughout
- Component, trait, and policy definition validating handlers: removed
spurious obj.Name argument from fmt.Sprintf in warning messages
- FromCUEString: only prepend importString to the stored template when
imports are non-empty; empty importString ("\n") was causing a leading
newline that made yaml.v3 use |2 block scalar on every generated YAML
- gen_sdk testdata: removed unused imports (vela/op, encoding/base64) from
one_of.cue that were exposed by our importString+templateString change
- e2e test: fix flaky trait-order assertion using ContainElements instead
of index-based equality
Upgraded all built-in .cue files that used deprecated list arithmetic:
- vela-templates/definitions/internal/component/cron-task.cue
- vela-templates/definitions/internal/trait/command.cue
- vela-templates/definitions/internal/trait/container-ports.cue
- vela-templates/definitions/internal/trait/env.cue
- vela-templates/definitions/internal/trait/init-container.cue
Removed unused stdlib imports that caused `def gen-api` to fail:
- vela-templates/definitions/internal/workflowstep/apply-deployment.cue
- vela-templates/definitions/internal/workflowstep/apply-terraform-provider.cue
- vela-templates/definitions/internal/workflowstep/build-push-image.cue
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Brian Kane <briankane1@gmail.com>
* fix(cue/upgrade): address PR review comments
- sync.atomic.Pointer for compatCache to fix data race on reinit
- SummaryVec → HistogramVec for both duration metrics (aggregatable
across HA replicas); buckets tuned to sub-millisecond upgrade path
and millisecond render path respectively
- errorFieldLabelRe: extend to match optional (?) and required (!)
field constraint markers before the colon
- cue-compatibility-cache-size: clamp negative values to 0 (disabled)
with warning log; document 0=disabled in flag help; cache put is
no-op when capacity <= 0
- webhook: replace RequiresUpgrade+EnsureCueVersionCompatibility double
parse with single EnsureCueVersionCompatibility call; use string
comparison to detect upgrade and emit warning
- def compat: log warning when ApplicationRevision fetch fails instead
of silently skipping (partial results are preserved)
- e2e: only delete definitions in DeferCleanup if this test created
them (avoid deleting pre-existing shared resources)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Brian Kane <briankane1@gmail.com>
* fix(cue/upgrade): address further PR review comments
- EnsureCueVersionCompatibility: return (string, bool) where bool
indicates semantic upgrades were applied (len(applied)>0), not
string inequality — prevents false-positive warnings from
formatting-only normalisation; update all call sites
- webhook handlers (component, trait, policy): switch from
RequiresUpgrade+EnsureCueVersionCompatibility double-call to single
EnsureCueVersionCompatibility call using wasUpgraded bool; remove
now-unused strings imports
- cache: skip eviction goroutine when capacity==0 (disabled); set
compatCacheCancel=nil on disabled path to avoid stale cancel on
next InitCompatibilityCache call
- e2e: replace boolean ownership tracking with createAndTrack helper
that checks pre-existence via Get before Create, eliminating both
the ambiguous-create leak and the boilerplate booleans
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Brian Kane <briankane1@gmail.com>
* fix: address reviewer comments — cache determinism, e2e ownership race
- cache: store normalised string in compatEntry.upgraded even when no
semantic fixes were applied, so cache-hit and cache-miss paths return
identical output (fixes non-deterministic behaviour flagged in review)
- upgrade: return entry.upgraded on the requiresUpgrade=false cache-hit
path instead of the raw input cueStr
- e2e: replace GET-then-CREATE ownership inference with atomic CREATE-
first pattern; err==nil means we created it (register DeferCleanup),
IsAlreadyExists means it pre-existed (skip cleanup), eliminating the
GET/CREATE race window that could misattribute ownership
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Brian Kane <briankane1@gmail.com>
---------
Signed-off-by: Brian Kane <briankane1@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Refactor(helm): extract type declarations into types.go
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract Provider, constructors, and dry-run
ctx into provider.go
Move the Provider singleton, NewProvider/NewProviderWithConfig
constructors, DefaultCacheTTLConfig, the dry-run context helpers
(WithDryRun/isDryRun), and the small log/cache key utilities out of
helm.go into a dedicated provider.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract chart fetching into chart_fetch.go
Move detectChartSourceType, isMutableVersion, fetchChart
(cache wrapper), fetchChartWithoutCache, determineCacheTTL, and the
three per-source fetchers (fetchOCIChart, fetchURLChart,
fetchRepoChart) out of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract values resolution into values.go
Move mergeValues, loadValuesFromSource,
resolveValuesFromNamespace, loadConfigMapValues, loadSecretValues,
plus the valueSourceMissingError sentinel and
errCrossNamespaceValuesFrom guard out of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract post-renderer and ownership helpers
into postrender.go
Move getActionConfig, velaLabelPostRenderer (struct + Run),
velaOwnerLabels, and isOwnedByVela out of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract manifest parsing into manifest.go
Move parseManifestResources, isClusterScopedGVK,
isClusterScopedKindStaticFallback, isTestResource, cleanResource,
and orderResources out of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract release secret lifecycle into
release_secrets.go
Move validateReleaseHealth, cleanOrphanedReleaseSecrets,
listReleaseSecretNames, labelReleaseSecrets,
deleteReleaseSecretsDirect, and InvalidateRelease out of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract dry-run render into dryrun.go
Move dryRunRender (used by webhook validation) and
getKubeVersion (cluster Kubernetes version capabilities lookup) out
of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): extract release dispatcher into release.go
Move installOrUpgradeChart (dispatcher between install/upgrade
with fingerprint dedup, adoption detection, and publishVersion pin
short-circuit) and computeReleaseFingerprint out of helm.go.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): split install/upgrade into install.go and
upgrade.go with option appliers
Move freshInstall, newInstallAction, and
isRetryableInstallError into install.go. Extract the inline upgrade
block from installOrUpgradeChart into a new performUpgrade function
in upgrade.go.
Introduce applyCommonInstallOptions and
applyCommonUpgradeOptions free functions that own option-to-action
wiring per Helm action type. The asymmetry between the two
(MaxHistory/CleanupOnFail/Recreate live only in the upgrade applier)
is now visible in code and reflects the Helm SDK shape.
No behavior change. All 240 unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Chore(helm): remove Uninstall provider (unused)
The helmchart ComponentDefinition only calls helm.#Render.
Deletion is handled by KubeVela GC and ResourceTracker, never by
helm uninstall, so the Uninstall CUE template and the workflow
provider registration were exercised by tests only.
Touched: UninstallParams/UninstallReturns in types.go, the
Uninstall Go function and its registration in helm.go, the
#Uninstall block in helm.cue, the uninstall registration in
pkg/workflow/providers/helm/helm.go, and the corresponding
helm_test.go cases.
No behavior change for any in-tree caller. All 237 remaining
unit specs remain green.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix(helm): wire includeCRDs and install-path force; drop waitTimeout (#7151)
includeCRDs was a complete no-op: the field was declared on RenderOptionsParams but never read. Wire it through SkipCRDs on both action.Install and action.Upgrade (inverted, since the user-facing field expresses inclusion).
force was wired on upgrade only. action.Install has a Force field in Helm SDK v3.14.4, so wire it there too.
waitTimeout had no backing Helm SDK field (only Timeout exists, covering both connection and wait). Remove the field from RenderOptionsParams and the CUE schema. timeout now documents its dual role.
maxHistory, cleanupOnFail, and recreatePods stay upgrade-only per the Helm SDK shape; CUE comments now state this explicitly.
Tests: 18 new specs covering applyCommonInstallOptions and applyCommonUpgradeOptions (each option, nil opts, unparseable timeout, asymmetry of upgrade-only fields). Suite: 258 of 258 passing.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Refactor(helm): split helm_test.go alongside production files
helm_test.go was a single 2500-line test file. Mirror the production file layout: types_test.go, provider_test.go, chart_fetch_test.go, values_test.go, postrender_test.go, manifest_test.go, release_test.go, release_secrets_test.go, dryrun_test.go, install_test.go (extended with isRetryableInstallError/newInstallAction/freshInstall), upgrade_test.go. helm_test.go now owns only Render-entry tests (matching helm.go after the production split).
No test logic change. Suite remains 258 of 258 passing.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Docs(helm): add one-line responsibility comment to each provider file
Every production .go file in the helm provider now opens with a single descriptive line immediately after the package declaration, so a reader can scan the directory and know what each file owns without opening it.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* chore(helm): fix the helmchart CD
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Test(helm): drop uninstall expectations from workflow provider tests
CI revealed three failing assertions in pkg/workflow/providers/helm: GetTemplate was expected to contain 'uninstall', and GetProviders was expected to expose an uninstall key with a non-nil function. The Uninstall provider was removed earlier in this branch since the native helmchart ComponentDefinition never invoked it, but the workflow-provider tests still referenced it. Update them to assert the render-only surface.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix(helm): address cubic AI review on PR #7154
P0: release.go installOrUpgradeChart only treats driver.ErrReleaseNotFound as a missing release; other Get errors are surfaced rather than silently falling through to freshInstall.
P1: release.go guards existingRelease.Info nil before reading Status. postrender.go isOwnedByVela now matches the full velaCtx triple (AppName + AppNamespace + Name) rather than any non-empty ownership label, so two Applications targeting the same release name in the same namespace do not mis-detect each other as already owned.
P2: values.go deep-clones inline values before CoalesceTables so nested maps cannot be mutated through to the caller. dryrun.go uses the full server GitVersion when present so charts with patch-level kubeVersion constraints validate correctly. install.go isRetryableInstallError now catches 'cannot reuse a name that is still in use' and the dash-hyphen variant. upgrade.go applyCommonUpgradeOptions documents that helm v3 only consults SkipCRDs on the install-mode upgrade path. postrender.go Run no longer short-circuits when only the context is nil, so direct callers still get namespace defaulting.
Tests: remove three non-hermetic / no-cluster tests that did not actually assert their named behaviour. values_test now uses distinct application and release namespaces in the cross-namespace guard scenario, and adds a second positive case for the release-namespace branch. chart_fetch_test fetchOCIChart-with-auth block now captures and restores singleton.KubeClient via BeforeEach/AfterEach to match the sibling fetchURLChart and fetchRepoChart blocks. Suite stays green at 255 specs.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix(helm): preserve numeric types in inline-values deep clone
Cubic flagged the JSON round-trip in deepCloneValues for coercing int to float64. Switch to runtime.DeepCopyJSON which walks the same nested map/slice/scalar shape but preserves Go numeric types. Templates that depend on integer type assertions (e.g. {{ .Values.replicaCount | int }}) now see the original type instead of a coerced float.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix(helm): deep-clone inline values without runtime.DeepCopyJSON
Cubic flagged that runtime.DeepCopyJSON panics on plain int values because the helper only accepts the narrow set of types json.Unmarshal returns. CUE evaluation routinely produces Go int / int32 / int64 values, so the previous switch from json round-tripping to runtime.DeepCopyJSON traded one bug (int->float64 coercion) for another (panic on int).
Replace with a hand-rolled recursive walk that recreates maps and slices and copies scalars by interface assignment. Scalars are immutable in Go, so the interface copy is sufficient. The implementation accepts every type CUE evaluation can produce.
Add five focused unit tests: nil input, int preservation, int64/float64 preservation, nested-map isolation, and slice isolation. Suite at 260 specs.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Test(helm): exercise installOrUpgradeChart with helm fake KubeClient
Codecov patch coverage was failing because the file split moved installOrUpgradeChart into a new file (release.go) with no direct coverage. The previous unit tests were no-cluster smokes that did not assert anything meaningful and were rightly deleted earlier in this branch on cubic feedback.
Add a small seam (actionConfigFactory field on Provider, defaulting to the real cluster getter) so tests can swap in helm SDK kubefake.PrintingKubeClient plus an in-memory release storage driver. Six new specs exercise the dispatcher end-to-end: fresh install, fingerprint dedup short-circuit, chart-version upgrade, values-change upgrade, adoption of vanilla helm releases, and publishVersion pin short-circuit.
Package coverage climbs from ~71% to 82.6%. installOrUpgradeChart goes from 0% to 85.2%. performUpgrade goes from 0% to 90.9%. The remaining gaps (freshInstall retry path, release_secrets cluster helpers) require a real Kubernetes API and are exercised in the e2e suite.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Test(helm): plug the second cluster-leak seam in dispatcher tests
Cubic flagged that the new dispatcher tests still let real Kubernetes calls escape: validateReleaseHealth (started as a goroutine after fingerprint-dedup short-circuit) called p.getActionConfig directly, and labelReleaseSecrets / listReleaseSecretNames / deleteReleaseSecretsDirect built a clientset from p.helmClient.RESTClientGetter().
Add a kubeClientFactory field on Provider next to actionConfigFactory and route all four helpers through it. installProviderWithFake injects a clientsetfake clientset alongside the fake action.Configuration. The release_secrets tests are reworked to use the helper as well, replacing the previous 'should not panic without a real cluster' smokes with assertions against the fake clientset: list filters to vela-owned secrets, label patches missing labels but never overwrites existing ones, delete cleans only matching helm-owned secrets.
Verified the suite emits zero 'Kubernetes cluster unreachable' log lines now. 266 specs green. Also strengthened the adoption test to assert all three app.oam.dev ownership labels.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix(helm): restore corrupt-secret recovery via fall-through-on-any-Get-error
The earlier cubic-driven P0 fix narrowed the dispatcher to fall through to freshInstall only when getAction.Run returned driver.ErrReleaseNotFound. That broke the documented self-healing contract validated by test/e2e-test/helmchart_test.go ('Helmchart Self-Healing / should recover from corrupted Helm release secret'): a corrupted .data.release surfaces from the helm storage driver as a decode error (base64 / gzip / json), not as driver.ErrReleaseNotFound, so the strict check trapped those errors and skipped the orphan-state cleanup path that freshInstall + isRetryableInstallError implement.
Restore the original fall-through-on-any-error behaviour with two safety improvements: (1) non-NotFound errors are now logged at warning level so operators can spot RBAC / transient API failures that the recovery path then addresses (or fails to address); (2) the fingerprint slice in the stale-cache-clear log is bounds-checked so a short cached value cannot panic.
Add a unit regression that wraps the in-memory storage driver in a corruptingDriver returning a synthetic decode error for the named release. Asserts the dispatcher swallows the error, runs fresh install, and repopulates the cache with the new fingerprint. Mirrors the e2e contract at the unit-test layer so a future refactor cannot regress this without breaking both gates.
Suite: 267 of 267 passing.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Test(helm): seed corruption-recovery test at the canonical helm storage key
Cubic flagged that the new corrupt-secret regression seeded the in-memory storage driver at 'rel.v1' while helm SDK derives canonical keys of the form 'sh.helm.release.v1.<name>.v<version>'. The mismatch meant the seeded release never collided with helms install-path probe and the test passed without actually exercising the recovery branch.
Switch the seed key to the canonical form via the same makeKey shape helm SDK uses internally. The corruptingDriver layered on top still returns a synthetic decode error for Get/Query against the named release, so the dispatcher is forced through the swallow-and-fall-through path. Tightened the comment to be explicit about test scope: this unit pins the dispatcher-layer contract, the e2e test pins the end-to-end cleanup. Also relaxed the pre-seeded cache fingerprint to a realistic-length value so the truncation-safe log path exercises cleanly.
Suite: 267 of 267 passing.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Test(helm): drop canonical-key seed from corruption-recovery test
The canonical-key seed made the in-memory storage collide with the key helm SDK derives for the release, which triggered the orphan-state cleanup retry path in freshInstall. Cleanup uses the kubeClientFactory clientset (a fake clientset with no helm release secrets) so it deletes nothing; the storage-driver entry stays put; the retry install then fails with release: already exists. CI confirmed against the previous commit.
Seed only the corruptingDriver this time, no pre-existing release in storage. The dispatcher swallows the synthetic decode error from Get/Query and falls through to a clean fresh install, which is the contract this unit test is meant to pin. The full storage + clientset cleanup loop remains exercised by the e2e Helmchart Self-Healing scenario.
Updated the test comment to be explicit about scope: storage and clientset are intentionally not bridged in the fake setup; that bridging belongs in the e2e test, not here.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
---------
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* feat: kv native helm auth implementation
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: add e2e test cases for helm auth
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* test: remove the env auth gate and improve test cases
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* lint: drop unused []byte return from non-docker secret dispatchers
unparam flagged dispatchBasicAuthSecret, dispatchTLSSecret, and
dispatchOpaqueSecret because the second return value (raw config
bytes) was always nil. Only dispatchDockerConfigJSONSecret actually
needs that slot for the OCI temp credfile. Drop it from the other
three and update resolveAuthOptions plus the unit tests to match.
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: pr review changes
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* style: gofmt/goimports auth.go doc comments
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* chore: remove e2e-auth-images-load-local target
The dedicated target is gone; e2e-test-local now reads the same
.vscode/k3d-preload.txt image list that the VS Code setup task
uses so both flows pull from one source. Empty or missing file
is a no-op.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* chore: inline auth-test image list in e2e-test-local
`.vscode/k3d-preload.txt` is gitignored so it would not exist on a
fresh clone. Inline the three auth-test registry images directly
in the Make target so `make e2e-test-local` is self-contained.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: address PR review comments
- Webhook ValidateCuexTemplate now wraps the context in helm.WithDryRun
so a ComponentDefinition with concrete helm.#Render arguments cannot
trigger a real chart fetch or install during admission validation.
- helmchart audit ConfigMap keeps `helm.oam.dev/chart` as a label when
the source string is a valid Kubernetes label value (alphanumeric +
`.-_`, 1-63 chars); URLs containing `://` or `/` only live in the
annotation. Preserves existing label selectors for repo-style sources
without breaking long OCI/HTTPS URLs.
- helm_test.go capture-and-restore singleton.KubeClient in fetchURLChart
and fetchRepoChart auth Describes so fake clients do not leak into
later tests in the package.
- utils_test.go swap the defer order so singleton.ReloadClients runs
before WorkloadCompiler.Reload, otherwise the compiler reload would
pick up the fake dynamic client and leak fake state.
- e2e.mk pre-load loop separates docker pull and k3d image import with
`;` rather than `&&`. `set -e` does not abort a for-loop body when a
command inside an `&&` chain fails, so the old form could continue
after a failed pull.
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* style: gofmt AfterAll indentation in helmchart_test.go
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: enhance Docker Hub credential handling in auth configuration
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: enhance Docker Hub credential handling in auth configuration
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix(helm-auth): normalize Docker Hub alias for dockerconfigjson Secrets
Cubic flagged that the Docker Hub alias fix in writeOCIRegistryConfigFile
only covered synthesized basic-auth credentials. For verbatim
kubernetes.io/dockerconfigjson Secrets, a user-supplied config keyed
under "registry-1.docker.io" (the OCI pull host) would not be found by
ORAS/Helm, which normalizes to "https://index.docker.io/v1/".
normalizeDockerHubAliases parses the verbatim JSON, and when any of the
three Docker Hub host aliases ("registry-1.docker.io", "index.docker.io",
"docker.io") is keyed but the canonical v1 key is absent, copies the
entry under the canonical key. No-op when:
- the canonical key is already present
- no Docker Hub host is involved
- the JSON is malformed or missing the auths field
Includes 7 new unit specs for the helper covering each alias, the no-op
cases, and malformed input.
Also brings in collateral local-fix changes:
- pkg/webhook/utils/utils_test.go: register the cue.oam.dev/v1alpha1
Package GVK in the fake DynamicClient scheme so
TestValidateCuexTemplate/withCuexPackageImports can resolve the
test/ext package after the WorkloadCompiler switch.
- gofmt field-alignment normalization on auth_test.go and
auth_registry_helpers_test.go (drift caught by check-diff CI).
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix: namespace-default rendered resources, bind chart cache to credentials, surface HTTP 401s clearly, inject auth-test CA in e2e
Four fixes from stress testing the helmchart component:
1. Rendered resources without metadata.namespace landed in vela-system.
Both code paths now default to releaseNamespace for namespaced kinds:
the velaLabelPostRenderer (before helm SDK apply) and
parseManifestResources (before KubeVela's tracker re-applies).
isClusterScopedKind covers CRDs, ClusterRoles, Namespaces, etc.
2. Cached chart bytes survived credential rotation.
computeAuthCacheTag hashes Secret.Type + sorted Data into a 16-char
tag suffixed onto the cache key when auth.secretRef is declared. Any
Secret edit (or different Secret reference) invalidates the cache and
forces a fresh registry call that exercises the new credentials at the
wire. Public charts (no auth) are unaffected.
3. HTTP 401/403 on chart fetch surfaced as YAML/JSON parse errors.
HTTPGetWithOption now rejects non-2xx responses with
'HTTP <status>: <body>' instead of returning the raw body for
downstream parsers to choke on.
4. E2E HTTPS tests against chartmuseum's self-signed cert failed at the
admission webhook. injectAuthTestCA patches vela-core in BeforeSuite
with an init container that combines /etc/ssl/certs/ca-certificates.crt
with testdata/auth/certs/ca.crt into a shared volume and points
SSL_CERT_FILE at it.
Also normalize Docker Hub host aliases on verbatim
kubernetes.io/dockerconfigjson Secrets (cubic comment), and revert
TestValidateCuexTemplate's fake DynamicClient to the empty-scheme form
that lets it wrap every GVK as Unstructured (CI unit test fix).
Finding 3 (options.wait default) is deferred: schema-level defaults
don't materialize for optional fields carried into _options as a
structural copy. Tracked separately.
Issue 2 from the stress matrix (cache + credential rotation) is also
filed upstream as kubevela/kubevela#7150 for a longer-term
credential-bound cache invalidation design.
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix(helm-auth): RESTMapper scope detection + auth tag binds source URL + drop flaky webhook test case
Address cubic P1 review comments and the unit-test CI failure. isClusterScopedKind only matched well-known built-in kinds; isClusterScopedGVK now asks the RESTMapper first so third-party cluster-scoped CRDs are recognised, with the static allowlist as a fallback. computeAuthCacheTag now folds params.Source and params.RepoURL into the hash so a multi-host dockerconfigjson Secret cannot reuse cached bytes across different registries. TestValidateCuexTemplate/withCuexPackageImports relied on cuex.DefaultCompiler.Reload picking up a fake-client-served Package CRD; since ValidateCuexTemplate now uses velacuex.WorkloadCompiler the fake-client setup does not surface the test/ext package, so the case is dropped (covered transitively by the helm provider unit tests and the e2e suite under helm.WithDryRun).
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* style: gofmt import order in helm.go (lint + check-diff)
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix(e2e): correct vela-core selector, alpine bundler, harden rollout wait
The label selector app.kubernetes.io/name=vela-core also matches the
cluster-gateway Deployment, so the init container was being appended to
the wrong workload and the controller pod never picked up the test CA.
Switching to the unique controller.oam.dev/name label fixes the routing,
and the diagnostic message at the empty-list branch is updated to point
operators at the new label.
addVolume and addInitContainer now update in place when an entry with
the same name already exists. Previously they silently skipped, which
meant the first patch on a cluster stuck for the lifetime of that
cluster and a corrected image or args could not be picked up by a
re-run.
busybox:1.36 ships without /etc/ssl/certs/ca-certificates.crt, so the
bundler was silently producing an empty combined.crt. alpine:3.18 ships
the public CA roots, so concatenating the auth-test CA onto the system
bundle produces a usable trust store that the main container reads via
SSL_CERT_FILE.
waitForDeploymentsAvailable used to return as soon as DeploymentAvailable
flipped to True and the new RS reached the desired replica count, which
left a window where old-RS pods still satisfied Available while the
controller container was still running with the previous image. The
check now also requires Status.Replicas == Status.UpdatedReplicas,
AvailableReplicas >= specReplicas and UnavailableReplicas == 0, so the
helper only returns once the rollout is fully complete.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* test(e2e): gate auth-test setup behind KUBEVELA_E2E_AUTH so other suites stay green
webhook-upgrade-check runs the same test/e2e-test suite as the full e2e
job but with ginkgo --focus-file requiredparam_validation_test.go. The
unconditional setupAuthRegistries in BeforeSuite was bringing up the
ChartMuseum / zot / nginx-bearer stack and patching vela-core for a
focus that did not need any of it, and the patched controller never
finished rolling on the upgrade-check cluster (the helm upgrade in that
job is expected to fail, so vela-core is in a stretched state when our
BeforeSuite tries to patch it).
Re-introduce KUBEVELA_E2E_AUTH=1 as the explicit opt-in. BeforeSuite and
AfterSuite only touch the auth registries when the env var is set, the
Helmchart Auth Describe block skips otherwise, and the make e2e-test
and e2e-test-local targets export the env so the full suite still runs
the auth specs. CI workflows that run a focused subset (like
webhook-upgrade-check) inherit the default off behavior and stop paying
the registry-setup cost.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
---------
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
* feat: implement valuesFrom support for helmchart component and update documentation examples
Signed-off-by: Anaswara Suresh <anaswarasuresh2212@gmail.com>
* fix: address cubic review feedback on valuesFrom
Three issues raised by cubic AI review on kubevela#7099:
1. docs/examples/helmchart-valuesfrom/secret-and-inline.yaml —
Expected-result comments used incorrect paths (resources.cpu /
resources.mem) and values (500m) that did not match the actual CM
data. Rewrote the narrative to use the real paths
(resources.limits.cpu / resources.limits.memory) and bundled the
Secret inline in the manifest so the example is self-contained and
the expected output is deterministic.
2. docs/examples/helmchart-valuesfrom/secret-and-inline.yaml —
The Secret was marked optional: true while the narrative required
it for the merged output to match. Bundled the Secret inline and
dropped the optional flag, removing the order/timing ambiguity.
README.md updated to drop the now-redundant "create the Secret
first" instruction.
3. pkg/cue/cuex/providers/helm/helm.go:Render —
After removing the unconditional "default" fallback for
releaseNamespace, Helm could run with an empty namespace when both
Context.AppNamespace and Release.Namespace were unset (non-normal
code paths — direct callers, tests, CLI tooling). Restored the
"default" fallback at the end of the namespace resolution while
keeping the Application-namespace plumbing for tenant-scoped
cross-namespace rejection.
Co-authored-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Anaswara Suresh <anaswarasuresh2212@gmail.com>
* feat: add valuesFrom fingerprinting for helmchart components to trigger workflow restarts on ConfigMap/Secret changes
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* feat: add valuesFrom fingerprinting for helmchart components to trigger workflow restarts on ConfigMap/Secret changes
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* feat: enhance valuesFrom support for helmchart components with fingerprinting and error handling
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* docs: clarify cross-namespace restrictions for valuesFrom in helmchart examples
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* feat: add publishVersion support to Helm provider for stable release management
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* feat: improve error handling for application retrieval in Helm provider
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* ci: retrigger checks
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* feat: add application publishVersion lookup defense in Helm provider tests
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
---------
Signed-off-by: Anaswara Suresh <anaswarasuresh2212@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Anaswara Suresh <anaswarasuresh2212@gmail.com>
Webhook Upgrade Validation / webhook-upgrade-check (push) Failing after 24s
* Fix: Update ingress messages to handle host retrieval more robustly across multiple templates
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: Enhance output handling in k8s-objects template to check for empty objects
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: Ensure policy selection from envBindingPolicies only occurs if the list is not empty
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
---------
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Feat: support to manage the integrations by the CLI and the workflow
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: remove the xml
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: add the unit test for the nacos writer
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add the integration API
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: make the provider commands to be deprecated
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: make the unit test work
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: rename the integration to the config
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: make the unit test cases work
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: refactor the config commands
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add the distribution status for the config
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: sort the import packages
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: refine the code style
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: refine the code style
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: get the content format before render the content
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add some examples
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: the command test cases
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add the definitions of the workflow step
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: add some tests
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: add some tests
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: change the name
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: retry the CI
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: refine some words
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* fix: ref-objects parameter with invalid field definition
which cause validating webhook failed when use ref-objects component
Signed-off-by: jiangshantao <jiangshantao-dbg@qq.com>
* fix: run make reviewable
Signed-off-by: jiangshantao <jiangshantao-dbg@qq.com>
Co-authored-by: jst <jst@meitu.com>
* Feat: add the API for querying the image info
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: the code style
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Add application name to the generated workload
Signed-off-by: Daniel Higuero <daniel@napptive.com>
* Make the PR reviewable
Signed-off-by: Daniel Higuero <daniel@napptive.com>