ParseGitlab indexed the results of splitting the address without bounds
checks, so a malformed (but repo-name-matching) GitLab registry URL crashed
the controller/CLI instead of returning an error. Three inputs panic today:
- https://gitlab.com/catalog -> slice bounds out of range [:-1]
- https://gitlab.com/kubevela/catalog/tree -> index out of range [2]
- https://catalog.gitlab.com/kubevela/foo -> index out of range [1]
Add length/empty guards that return the existing invalid-format error
(errInvalidFormatMsg, consistent with Parse) for the empty owner slice, the
short host split, and the missing tree branch segment. Behaviour for all
currently-valid inputs is unchanged.
Also fix the caller NewAsyncReader, which dereferenced the returned content
before checking the error: on any ParseGitlab error content is nil, so the
assignment nil-panicked before the error could be returned. Move the error
check above the dereference.
Extend TestParseGitlab with the three malformed cases (wantErr).
Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
* feat: kv native helm auth implementation
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: add e2e test cases for helm auth
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* test: remove the env auth gate and improve test cases
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* lint: drop unused []byte return from non-docker secret dispatchers
unparam flagged dispatchBasicAuthSecret, dispatchTLSSecret, and
dispatchOpaqueSecret because the second return value (raw config
bytes) was always nil. Only dispatchDockerConfigJSONSecret actually
needs that slot for the OCI temp credfile. Drop it from the other
three and update resolveAuthOptions plus the unit tests to match.
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: pr review changes
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* style: gofmt/goimports auth.go doc comments
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* chore: remove e2e-auth-images-load-local target
The dedicated target is gone; e2e-test-local now reads the same
.vscode/k3d-preload.txt image list that the VS Code setup task
uses so both flows pull from one source. Empty or missing file
is a no-op.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* chore: inline auth-test image list in e2e-test-local
`.vscode/k3d-preload.txt` is gitignored so it would not exist on a
fresh clone. Inline the three auth-test registry images directly
in the Make target so `make e2e-test-local` is self-contained.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: address PR review comments
- Webhook ValidateCuexTemplate now wraps the context in helm.WithDryRun
so a ComponentDefinition with concrete helm.#Render arguments cannot
trigger a real chart fetch or install during admission validation.
- helmchart audit ConfigMap keeps `helm.oam.dev/chart` as a label when
the source string is a valid Kubernetes label value (alphanumeric +
`.-_`, 1-63 chars); URLs containing `://` or `/` only live in the
annotation. Preserves existing label selectors for repo-style sources
without breaking long OCI/HTTPS URLs.
- helm_test.go capture-and-restore singleton.KubeClient in fetchURLChart
and fetchRepoChart auth Describes so fake clients do not leak into
later tests in the package.
- utils_test.go swap the defer order so singleton.ReloadClients runs
before WorkloadCompiler.Reload, otherwise the compiler reload would
pick up the fake dynamic client and leak fake state.
- e2e.mk pre-load loop separates docker pull and k3d image import with
`;` rather than `&&`. `set -e` does not abort a for-loop body when a
command inside an `&&` chain fails, so the old form could continue
after a failed pull.
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* style: gofmt AfterAll indentation in helmchart_test.go
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: enhance Docker Hub credential handling in auth configuration
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* feat: enhance Docker Hub credential handling in auth configuration
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix(helm-auth): normalize Docker Hub alias for dockerconfigjson Secrets
Cubic flagged that the Docker Hub alias fix in writeOCIRegistryConfigFile
only covered synthesized basic-auth credentials. For verbatim
kubernetes.io/dockerconfigjson Secrets, a user-supplied config keyed
under "registry-1.docker.io" (the OCI pull host) would not be found by
ORAS/Helm, which normalizes to "https://index.docker.io/v1/".
normalizeDockerHubAliases parses the verbatim JSON, and when any of the
three Docker Hub host aliases ("registry-1.docker.io", "index.docker.io",
"docker.io") is keyed but the canonical v1 key is absent, copies the
entry under the canonical key. No-op when:
- the canonical key is already present
- no Docker Hub host is involved
- the JSON is malformed or missing the auths field
Includes 7 new unit specs for the helper covering each alias, the no-op
cases, and malformed input.
Also brings in collateral local-fix changes:
- pkg/webhook/utils/utils_test.go: register the cue.oam.dev/v1alpha1
Package GVK in the fake DynamicClient scheme so
TestValidateCuexTemplate/withCuexPackageImports can resolve the
test/ext package after the WorkloadCompiler switch.
- gofmt field-alignment normalization on auth_test.go and
auth_registry_helpers_test.go (drift caught by check-diff CI).
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix: namespace-default rendered resources, bind chart cache to credentials, surface HTTP 401s clearly, inject auth-test CA in e2e
Four fixes from stress testing the helmchart component:
1. Rendered resources without metadata.namespace landed in vela-system.
Both code paths now default to releaseNamespace for namespaced kinds:
the velaLabelPostRenderer (before helm SDK apply) and
parseManifestResources (before KubeVela's tracker re-applies).
isClusterScopedKind covers CRDs, ClusterRoles, Namespaces, etc.
2. Cached chart bytes survived credential rotation.
computeAuthCacheTag hashes Secret.Type + sorted Data into a 16-char
tag suffixed onto the cache key when auth.secretRef is declared. Any
Secret edit (or different Secret reference) invalidates the cache and
forces a fresh registry call that exercises the new credentials at the
wire. Public charts (no auth) are unaffected.
3. HTTP 401/403 on chart fetch surfaced as YAML/JSON parse errors.
HTTPGetWithOption now rejects non-2xx responses with
'HTTP <status>: <body>' instead of returning the raw body for
downstream parsers to choke on.
4. E2E HTTPS tests against chartmuseum's self-signed cert failed at the
admission webhook. injectAuthTestCA patches vela-core in BeforeSuite
with an init container that combines /etc/ssl/certs/ca-certificates.crt
with testdata/auth/certs/ca.crt into a shared volume and points
SSL_CERT_FILE at it.
Also normalize Docker Hub host aliases on verbatim
kubernetes.io/dockerconfigjson Secrets (cubic comment), and revert
TestValidateCuexTemplate's fake DynamicClient to the empty-scheme form
that lets it wrap every GVK as Unstructured (CI unit test fix).
Finding 3 (options.wait default) is deferred: schema-level defaults
don't materialize for optional fields carried into _options as a
structural copy. Tracked separately.
Issue 2 from the stress matrix (cache + credential rotation) is also
filed upstream as kubevela/kubevela#7150 for a longer-term
credential-bound cache invalidation design.
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix(helm-auth): RESTMapper scope detection + auth tag binds source URL + drop flaky webhook test case
Address cubic P1 review comments and the unit-test CI failure. isClusterScopedKind only matched well-known built-in kinds; isClusterScopedGVK now asks the RESTMapper first so third-party cluster-scoped CRDs are recognised, with the static allowlist as a fallback. computeAuthCacheTag now folds params.Source and params.RepoURL into the hash so a multi-host dockerconfigjson Secret cannot reuse cached bytes across different registries. TestValidateCuexTemplate/withCuexPackageImports relied on cuex.DefaultCompiler.Reload picking up a fake-client-served Package CRD; since ValidateCuexTemplate now uses velacuex.WorkloadCompiler the fake-client setup does not surface the test/ext package, so the case is dropped (covered transitively by the helm provider unit tests and the e2e suite under helm.WithDryRun).
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* style: gofmt import order in helm.go (lint + check-diff)
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* fix(e2e): correct vela-core selector, alpine bundler, harden rollout wait
The label selector app.kubernetes.io/name=vela-core also matches the
cluster-gateway Deployment, so the init container was being appended to
the wrong workload and the controller pod never picked up the test CA.
Switching to the unique controller.oam.dev/name label fixes the routing,
and the diagnostic message at the empty-list branch is updated to point
operators at the new label.
addVolume and addInitContainer now update in place when an entry with
the same name already exists. Previously they silently skipped, which
meant the first patch on a cluster stuck for the lifetime of that
cluster and a corrected image or args could not be picked up by a
re-run.
busybox:1.36 ships without /etc/ssl/certs/ca-certificates.crt, so the
bundler was silently producing an empty combined.crt. alpine:3.18 ships
the public CA roots, so concatenating the auth-test CA onto the system
bundle produces a usable trust store that the main container reads via
SSL_CERT_FILE.
waitForDeploymentsAvailable used to return as soon as DeploymentAvailable
flipped to True and the new RS reached the desired replica count, which
left a window where old-RS pods still satisfied Available while the
controller container was still running with the previous image. The
check now also requires Status.Replicas == Status.UpdatedReplicas,
AvailableReplicas >= specReplicas and UnavailableReplicas == 0, so the
helper only returns once the rollout is fully complete.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
* test(e2e): gate auth-test setup behind KUBEVELA_E2E_AUTH so other suites stay green
webhook-upgrade-check runs the same test/e2e-test suite as the full e2e
job but with ginkgo --focus-file requiredparam_validation_test.go. The
unconditional setupAuthRegistries in BeforeSuite was bringing up the
ChartMuseum / zot / nginx-bearer stack and patching vela-core for a
focus that did not need any of it, and the patched controller never
finished rolling on the upgrade-check cluster (the helm upgrade in that
job is expected to fail, so vela-core is in a stretched state when our
BeforeSuite tries to patch it).
Re-introduce KUBEVELA_E2E_AUTH=1 as the explicit opt-in. BeforeSuite and
AfterSuite only touch the auth registries when the env var is set, the
Helmchart Auth Describe block skips otherwise, and the make e2e-test
and e2e-test-local targets export the env so the full suite still runs
the auth specs. CI workflows that run a focused subset (like
webhook-upgrade-check) inherit the default off behavior and stop paying
the registry-setup cost.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
---------
Signed-off-by: Ayush Kumar <aykumar@guidewire.com>
Signed-off-by: Vishal Kumar <vishal210893@gmail.com>
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Co-authored-by: Vishal Kumar <vishal210893@gmail.com>
Webhook Upgrade Validation / webhook-upgrade-check (push) Failing after 2m0s
- Added GetCUExParameterValue()
function that uses cuex.DefaultCompiler instead
of standard CUE compiler
- Added GetParametersWithCuex() function with cuex support
- Updated GetBaseResourceKinds() to use cuex compiler
- Updated all callers to use cuex-aware functions
Fixes#7012
Signed-off-by: GoGstickGo <janilution@gmail.com>
* feat(env): Add comprehensive unit tests for environment management
This commit introduces a comprehensive suite of unit tests for the environment management functions in `pkg/utils/env`.
Key changes include:
- Refactoring the test setup to use `TestMain` for better test environment control.
- Adding new test cases for `CreateEnv`, `GetEnvByName`, `ListEnvs`, `SetCurrentEnv`, `SetEnvLabels`, and `DeleteEnv`.
These tests improve the overall test coverage and ensure the correctness and reliability of environment-related operations.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* feat(errors): Add unit tests for error handling utilities
This commit introduces new unit tests for the error handling utilities located in `pkg/utils/errors/`.
Specifically, new test files have been added for:
- `crd_test.go`: Tests for CRD-related error checks.
- `list_test.go`: Tests for error list aggregation.
- `reason_test.go`: Tests for specific error reasons like label conflicts and CUE path not found.
- `resourcetracker_test.go`: Tests for resource tracker errors.
These additions improve the test coverage and ensure the robustness of KubeVela's error handling mechanisms.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* refactor(schema): Refactor ui_schema_test.go to use testify/assert and add new test cases
This commit refactors `pkg/utils/schema/ui_schema_test.go` to improve its readability and maintainability.
Key changes include:
- Migrating from Ginkgo/Gomega to testify/assert for assertions.
- Restructuring `TestGetDefaultUIType` into a table-driven test.
- Adding new comprehensive test cases for `Condition_Validate` function.
These changes enhance the test suite for UI schema utilities, making it more robust and easier to extend.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* refactor(system): Refactor system_test.go and add comprehensive unit tests
This commit refactors `pkg/utils/system/system_test.go` to improve its structure, readability, and test coverage.
Key changes include:
- Converting existing tests to a table-driven format using `testify/assert`.
- Adding new comprehensive test cases for:
- `CreateIfNotExist`
- `GetVelaHomeDir`
- `GetDirectoryFunctions` (e.g., `GetCapCenterDir`, `GetCapabilityDir`)
- `InitFunctions` (e.g., `InitCapabilityDir`, `InitCapCenterDir`, `InitDirs`)
- `BindEnvironmentVariables`
These changes enhance the test suite for system utilities, ensuring their correctness and robustness.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* feat(types): Add unit tests for QL types
This commit introduces new unit tests for the types defined in `pkg/utils/types`, specifically focusing on types related to KubeVela Query Language (QL).
New test cases cover:
- `ServiceEndpoint.String()`: Verifies the string representation of service endpoints, including various protocols, ports, and paths.
- `AppliedResource.GroupVersionKind()`: Ensures correct extraction of GroupVersionKind from applied resources.
- `ResourceTreeNode.GroupVersionKind()`: Verifies correct extraction of GroupVersionKind from resource tree nodes.
These tests improve the coverage and reliability of core data structures used in KubeVela.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* feat(util): Add and refactor unit tests for utility functions
This commit introduces new unit tests and refactors existing ones within the `pkg/utils/util` package.
Key changes include:
- **`pkg/utils/util/cmd_test.go`**: Adds comprehensive tests for `IOStreams` and its print functions, as well as `NewDefaultIOStreams` and `NewTestIOStreams`.
- **`pkg/utils/util/factory_test.go`**: Refactors the `GenerateLeaderElectionID` test to a table-driven format and adds new tests for `computeDiscoverCacheDir` and `RestConfigGetter` methods, ensuring the correctness of Kubernetes client configuration and discovery.
These additions and refactorings enhance the test coverage and reliability of core utility functions.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* feat(utils): Add and refactor unit tests for json, jwt, parse, and strings utilities
This commit introduces new unit tests and refactors existing ones across several utility packages within `pkg/utils/`.
Key changes include:
- **`pkg/utils/json`**: Adds tests for `StrictUnmarshal` to ensure proper JSON unmarshaling.
- **`pkg/utils/jwt`**: Adds tests for JWT token subject extraction and certificate subject retrieval.
- **`pkg/utils/parse`**: Expands test coverage for URL parsing functions (`Parse`, `ParseGitlab`).
- **`pkg/utils/strings`**: Refactors existing tests to a table-driven format and adds tests for box drawing string generation.
These additions and refactorings significantly improve the test coverage and reliability of KubeVela's utility functions.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* fix(tests): Address test and error handling issues
This commit addresses several issues identified in unit tests and error handling utilities, improving test reliability and code safety.
Key fixes and improvements include:
- **`pkg/utils/errors`**:
- Added nil check to `IsCuePathNotFound` to prevent panics.
- Corrected `fmt.Errorf` usage to `errors.New` in `reason_test.go` (SA1006 fix).
- Used `assert.EqualError` for clearer error message comparisons in `resourcetracker_test.go`.
- **`pkg/utils/jwt_test.go`**: Marked `generateTestCert` as a test helper using `t.Helper()` for better error reporting.
- **`pkg/utils/system_test.go`**:
- Removed unused `verifyCleanup` field.
- Modified `TestGetVelaHomeDir` to use a temporary home directory, preventing destructive operations on the user's system.
- **`pkg/utils/util/cmd_test.go`**: Swapped `assert.Equal` arguments to follow `expected, actual` convention.
These changes enhance the robustness and correctness of the test suite and related utility functions.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* chore(tests): Apply gofmt and import ordering to test files
This commit applies standard Go formatting (`gofmt`) and corrects import ordering in several test files.
Affected files:
- `pkg/utils/schema/ui_schema_test.go`: Added missing newline at EOF.
- `pkg/utils/system/system_test.go`: Corrected import ordering.
- `pkg/utils/util/factory_test.go`: Corrected import ordering.
These changes ensure consistency with project coding standards.
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
---------
Signed-off-by: Ashvin Bambhaniya <ashvin.bambhaniya@improwised.com>
* Feat: support vela def vet the input "dir" and many cue files
Signed-off-by: Mcduller <1596582524@qq.com>
* Feat: support vela def vet the input "dir" and many cue files
Signed-off-by: Mcduller <1596582524@qq.com>
---------
Signed-off-by: Mcduller <1596582524@qq.com>
* Fix: when taking over an existing resource for the first time, use kubectl last apply anno
Signed-off-by: zxbyoyoyo <596908030@qq.com>
* Fix: '-' || 'skip' return nil
Signed-off-by: zxbyoyoyo <596908030@qq.com>
* Fix: check-diff
Signed-off-by: zxbyoyoyo <596908030@qq.com>
---------
Signed-off-by: zxbyoyoyo <596908030@qq.com>