Fix unbalanced template block in metadata key validation

The batched review suggestion introduced a per-segment DNS subdomain check
for the key prefix, but consumed the 'end' that closed the prefix branch.
That left the block unbalanced, so every template in both charts failed to
parse, and it also moved the name-part check inside the prefix branch where
it would only run for prefixed keys.

Close the prefix branch explicitly and bind kind/path before the range,
since the range rebinds the dot and '.path'/'.kind' are not reachable
inside it. Also correct the segment error message, which described the
253 character limit rather than the constraint that actually failed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Nikola Jokic
2026-09-08 17:23:29 +02:00
co-authored by Copilot App
parent c4e15959eb
commit e4a93fe4ae
3 changed files with 15 additions and 9 deletions
@@ -17,24 +17,27 @@ Expects a dict with "key", "kind" (label|annotation) and "path" (the values path
*/}} */}}
{{- define "validate-metadata-key" -}} {{- define "validate-metadata-key" -}}
{{- $key := .key -}} {{- $key := .key -}}
{{- $kind := .kind -}}
{{- $path := .path -}}
{{- $parts := splitList "/" $key -}} {{- $parts := splitList "/" $key -}}
{{- $name := $key -}} {{- $name := $key -}}
{{- if gt (len $parts) 2 -}} {{- if gt (len $parts) 2 -}}
{{- fail (printf "%s: invalid %s key %q: a qualified name must consist of an optional DNS subdomain prefix followed by a single '/'" .path .kind $key) -}} {{- fail (printf "%s: invalid %s key %q: a qualified name must consist of an optional DNS subdomain prefix followed by a single '/'" $path $kind $key) -}}
{{- end -}} {{- end -}}
{{- if eq (len $parts) 2 -}} {{- if eq (len $parts) 2 -}}
{{- $prefix := index $parts 0 -}} {{- $prefix := index $parts 0 -}}
{{- $name = index $parts 1 -}} {{- $name = index $parts 1 -}}
{{- if or (eq $prefix "") (gt (len $prefix) 253) -}} {{- if or (eq $prefix "") (gt (len $prefix) 253) -}}
{{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain of no more than 253 characters" .path .kind $key $prefix) -}} {{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain of no more than 253 characters" $path $kind $key $prefix) -}}
{{- end -}} {{- end -}}
{{- range $_, $seg := splitList "." $prefix -}} {{- range $_, $seg := splitList "." $prefix -}}
{{- if or (eq $seg "") (gt (len $seg) 63) (not (regexMatch "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$" $seg)) -}} {{- if or (eq $seg "") (gt (len $seg) 63) (not (regexMatch "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$" $seg)) -}}
{{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain of no more than 253 characters" .path .kind $key $prefix) -}} {{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain, so each dot-separated segment must be no more than 63 characters, consist of lowercase alphanumeric characters or '-', and start and end with an alphanumeric character" $path $kind $key $prefix) -}}
{{- end -}}
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
{{- if or (eq $name "") (gt (len $name) 63) (not (regexMatch "^[A-Za-z0-9]([-A-Za-z0-9_.]*[A-Za-z0-9])?$" $name)) -}} {{- if or (eq $name "") (gt (len $name) 63) (not (regexMatch "^[A-Za-z0-9]([-A-Za-z0-9_.]*[A-Za-z0-9])?$" $name)) -}}
{{- fail (printf "%s: invalid %s key %q: the name part must be no more than 63 characters, consist of alphanumeric characters, '-', '_' or '.', and must start and end with an alphanumeric character" .path .kind $key) -}} {{- fail (printf "%s: invalid %s key %q: the name part must be no more than 63 characters, consist of alphanumeric characters, '-', '_' or '.', and must start and end with an alphanumeric character" $path $kind $key) -}}
{{- end -}} {{- end -}}
{{- end }} {{- end }}
@@ -38,7 +38,7 @@ tests:
namespace: "test-namespace" namespace: "test-namespace"
asserts: asserts:
- failedTemplate: - failedTemplate:
errorMessage: '.Values.runner.pod.metadata.labels: invalid label key "Invalid.Prefix/purpose": the prefix "Invalid.Prefix" must be a DNS subdomain of no more than 253 characters' errorMessage: '.Values.runner.pod.metadata.labels: invalid label key "Invalid.Prefix/purpose": the prefix "Invalid.Prefix" must be a DNS subdomain, so each dot-separated segment must be no more than 63 characters, consist of lowercase alphanumeric characters or ''-'', and start and end with an alphanumeric character'
- it: should fail when a resource label value is not a valid Kubernetes label value - it: should fail when a resource label value is not a valid Kubernetes label value
set: set:
@@ -73,24 +73,27 @@ Expects a dict with "key", "kind" (label|annotation) and "path" (the values path
*/}} */}}
{{- define "gha-runner-scale-set.validateMetadataKey" -}} {{- define "gha-runner-scale-set.validateMetadataKey" -}}
{{- $key := .key -}} {{- $key := .key -}}
{{- $kind := .kind -}}
{{- $path := .path -}}
{{- $parts := splitList "/" $key -}} {{- $parts := splitList "/" $key -}}
{{- $name := $key -}} {{- $name := $key -}}
{{- if gt (len $parts) 2 -}} {{- if gt (len $parts) 2 -}}
{{- fail (printf "%s: invalid %s key %q: a qualified name must consist of an optional DNS subdomain prefix followed by a single '/'" .path .kind $key) -}} {{- fail (printf "%s: invalid %s key %q: a qualified name must consist of an optional DNS subdomain prefix followed by a single '/'" $path $kind $key) -}}
{{- end -}} {{- end -}}
{{- if eq (len $parts) 2 -}} {{- if eq (len $parts) 2 -}}
{{- $prefix := index $parts 0 -}} {{- $prefix := index $parts 0 -}}
{{- $name = index $parts 1 -}} {{- $name = index $parts 1 -}}
{{- if or (eq $prefix "") (gt (len $prefix) 253) -}} {{- if or (eq $prefix "") (gt (len $prefix) 253) -}}
{{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain of no more than 253 characters" .path .kind $key $prefix) -}} {{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain of no more than 253 characters" $path $kind $key $prefix) -}}
{{- end -}} {{- end -}}
{{- range $_, $seg := splitList "." $prefix -}} {{- range $_, $seg := splitList "." $prefix -}}
{{- if or (eq $seg "") (gt (len $seg) 63) (not (regexMatch "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$" $seg)) -}} {{- if or (eq $seg "") (gt (len $seg) 63) (not (regexMatch "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$" $seg)) -}}
{{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain of no more than 253 characters" .path .kind $key $prefix) -}} {{- fail (printf "%s: invalid %s key %q: the prefix %q must be a DNS subdomain, so each dot-separated segment must be no more than 63 characters, consist of lowercase alphanumeric characters or '-', and start and end with an alphanumeric character" $path $kind $key $prefix) -}}
{{- end -}}
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
{{- if or (eq $name "") (gt (len $name) 63) (not (regexMatch "^[A-Za-z0-9]([-A-Za-z0-9_.]*[A-Za-z0-9])?$" $name)) -}} {{- if or (eq $name "") (gt (len $name) 63) (not (regexMatch "^[A-Za-z0-9]([-A-Za-z0-9_.]*[A-Za-z0-9])?$" $name)) -}}
{{- fail (printf "%s: invalid %s key %q: the name part must be no more than 63 characters, consist of alphanumeric characters, '-', '_' or '.', and must start and end with an alphanumeric character" .path .kind $key) -}} {{- fail (printf "%s: invalid %s key %q: the name part must be no more than 63 characters, consist of alphanumeric characters, '-', '_' or '.', and must start and end with an alphanumeric character" $path $kind $key) -}}
{{- end -}} {{- end -}}
{{- end }} {{- end }}