Commit Graph
1862 Commits
Author SHA1 Message Date
Nikola JokicandCopilot App 55f1ad560b Validate and coerce listener metadata, and match Kubernetes key rules
Follow-up review of the metadata validation surfaced four gaps:

Listener pod metadata took the same unvalidated, uncoerced path that the
runner pod metadata used to: an invalid label only failed once the
controller created the listener pod, which is the silent failure mode
this change set exists to remove. Both charts now validate it at render
time and route its values through the string coercion.

Values loaded from a values file arrive as float64, so "%v" rendered a
large integer such as 12345678901234 in scientific notation, silently
corrupting the annotation. Integral floats are now formatted without an
exponent, and the remaining sites that quoted metadata values directly
go through the same helper.

A map or list value was flattened into Go's own formatting, producing a
meaningless "map[a:b]" label. Such values are now rejected with the
values path that produced them.

The label key prefix check rejected dot-separated segments longer than
63 characters. Kubernetes only bounds the prefix at 253 characters in
total, so the check was stricter than the API server and would have
rejected keys that already work.

While covering the listener path, the experimental chart turned out to
render invalid YAML whenever listener.podTemplate carried both metadata
and spec: the last metadata value and the following "spec:" key ended up
on the same line. That is fixed here too, with a regression test.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 09:56:58 +02:00
Nikola JokicandCopilot App 824e3b619b Fail with the values path when metadata is not a mapping
The validation helpers ranged over labels/annotations without checking they
were maps, and silently skipped non-map resourceMeta entries. A mis-typed
value therefore escaped validation and failed later with an opaque error
such as 'range can't iterate over oops' or 'can't evaluate field labels in
type interface {}', which is the class of error this validation exists to
replace.

Guard every metadata map with an explicit type check that names the values
path, and run the validation from every template that renders metadata so
the reported error does not depend on which template Helm renders first.

Also add coverage for scalar coercion driven by a values file. SetValues
only ever produces strings, so the existing tests could not exercise the
bool/number values that stringMap is there to handle.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 09:41:19 +02:00
Nikola JokicandCopilot App e4a93fe4ae Fix unbalanced template block in metadata key validation
The batched review suggestion introduced a per-segment DNS subdomain check
for the key prefix, but consumed the 'end' that closed the prefix branch.
That left the block unbalanced, so every template in both charts failed to
parse, and it also moved the name-part check inside the prefix branch where
it would only run for prefixed keys.

Close the prefix branch explicitly and bind kind/path before the range,
since the range rebinds the dot and '.path'/'.kind' are not reachable
inside it. Also correct the segment error message, which described the
253 character limit rather than the constraint that actually failed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-08 17:23:29 +02:00
Nikola JokicandCopilot Autofix powered by AI c4e15959eb Apply batched suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-09-08 17:21:25 +02:00
Nikola JokicandCopilot App c156b81e00 Validate runner metadata labels and annotations at chart render time
Invalid labels supplied through .Values.template.metadata.labels (or the
resourceMeta blocks) are not rejected by the API server: they live inside
the AutoscalingRunnerSet spec, whose CRD schema only enforces the value
type. The invalid value is only caught when the controller creates the
runner pod, at which point the EphemeralRunner is marked as failed with
ReasonInvalidPodFailure and the scale set never produces runners.

Validate every label and annotation map the charts render against the
Kubernetes key/value rules so helm install/upgrade fails immediately with
the offending values path, key and value.

Also render all metadata values as strings. Scalars such as 'true' or '1'
were previously emitted as YAML booleans and numbers, which Kubernetes
rejects for labels and annotations.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-08 17:21:25 +02:00
Nikola Jokic 7c68e1d318 Set listener qps and burst (#4558) 2026-09-08 15:49:58 +02:00
Nikola Jokic bc677d306c Add @actions/actions-runtime to codeowners (#4631) 2026-09-08 15:47:46 +02:00
Nikola Jokic f0d0b1d439 Add guards on timings so we don't publish incorrect metrics (#4621) 2026-09-08 14:32:24 +02:00
Nikola Jokic c3dfb396d3 Fix nil ResourceCache panic in stale scale set tests (#4628) 2026-09-08 12:34:45 +02:00
Nikola Jokic 54147cfa5e Introduce cache for lookups of desired resource state, to reduce the amount of allocations in the controller (#4568) 2026-09-07 13:49:28 +02:00
Junya Okabe 87592be6d3 Remove orphaned testserver package (#4620) 2026-09-07 10:40:28 +02:00
dependabot[bot] a4ac89e2a7 Bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#4562)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-03 16:45:00 +01:00
Diogo Torres 3cfdcf59fe Re-register the runner scale set when it is gone from the Actions service (#4571) 2026-09-03 08:16:06 +01:00
github-actions[bot] 438440e92a Updates: runner to v2.337.0 (#4613)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-31 16:53:02 +01:00
github-actions[bot] a035c5a393 Updates: runner to v2.336.0 (#4578)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-21 15:51:06 +02:00
dependabot[bot]andNikola Jokic 252eb51766 Bump the actions group across 1 directory with 6 updates (#4559)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nikola Jokic <jokicnikola07@gmail.com>
2026-07-15 14:44:09 +02:00
Nikola Jokic 03463c051c Fix deprecated calls (#4570) 2026-07-14 19:34:13 +02:00
Nikola Jokic f6a3d738de Use metrics to display runner statuses instead of status field for EphemeralRunnerSet and AutoscalingRunnerSet (#4557) 2026-07-14 19:31:11 +02:00
Nikola Jokic 368e2f28b8 Use Patch instead of Update (#4533) 2026-07-10 12:34:40 +02:00
Nikola Jokic 2fa72b510f Tag fields with optional allowing patches without issues (#4528) 2026-07-10 12:28:10 +02:00
Junya Okabe 68c0a86188 Mark generated files as linguist-generated (#4536) 2026-07-09 14:22:46 +02:00
Junya Okabe e06294f5de Make controller terminationGracePeriodSeconds configurable and align it with graceful shutdown timeout (#4556) 2026-07-07 00:28:57 +02:00
Junya Okabe 2ee6b3b8e8 Increase e2e wait timeouts to reduce flakiness (#4545) 2026-06-30 15:05:58 +02:00
dependabot[bot] 24686a974e Bump the actions group across 1 directory with 2 updates (#4539)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-27 18:30:32 +02:00
dependabot[bot] c7005c3696 Bump the gomod group across 1 directory with 11 updates (#4529)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-19 13:08:17 +02:00
Nikola Jokic 9c50514160 Fix typo and rename status to phase (#4506) 2026-06-15 12:51:13 +02:00
github-actions[bot] 391bc57773 Updates: runner to v2.335.1 (#4523)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-12 16:28:17 +02:00
Nikola Jokic 767e58e4b1 Upgrade resources in-place, causing 1-1 mapping between autoscaling runner set and ephemeral runner set (#4516) 2026-06-09 13:52:37 +02:00
dependabot[bot] 0acef229e2 Bump the actions group across 1 directory with 6 updates (#4518)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 10:50:43 +02:00
dependabot[bot]andJiaren Wu 0dc5f8a0c2 Bump the gomod group across 1 directory with 9 updates (#4508)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jiaren Wu <jiaren-wu@github.com>
2026-05-30 00:55:53 +02:00
Junya Okabe 631f39bb2a Add context: . to the docker/build-push-action (#4501) 2026-05-25 17:57:05 +02:00
Nikola Jokic 30879de182 Fix patch on autoscaling runner set when creating a runner scale set (#4502) 2026-05-22 17:51:47 +02:00
Nikola Jokic 5ca85bde2d Do not use EqualFold when checking u.Host (#4496) 2026-05-22 17:01:37 +02:00
Francesco RenziandCopilot 9bb16ae49d Prepare 0.14.2 release (#4503)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
gha-runner-scale-set-0.14.2
2026-05-22 12:07:13 +02:00
Nikola Jokic 7638475e3c Bump Go to 1.26.3 (#4504) 2026-05-22 12:04:06 +02:00
Nikola Jokic 8ecfbc63bf Revert "Fix typo and rename status to phase" (#4505) 2026-05-22 11:58:48 +02:00
Nikola Jokic 79ddd38442 Port rate limiter to experimental charts (#4478) 2026-05-22 11:45:09 +02:00
Nikola Jokic dfcbd8344b Fix helm chart validation workflow (#4479) 2026-05-22 11:43:54 +02:00
63ef8241a0 Bump Go to 1.26.2 to fix critical security vulnerabilities (#4491)
Co-authored-by: Dhawal Seth <dseth@linkedin.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-05-22 09:54:37 +01:00
Nikola Jokic 8cb3f49049 Update CODEOWNERS (#4495) 2026-05-13 00:18:57 +02:00
Nikola Jokic 8eb6cbe79f Fix typo and rename status to phase (#4466) 2026-05-13 00:17:08 +02:00
Nikola Jokic e7b6482761 Fix job execution duration when runner assign time is not set (#4472) 2026-05-11 15:57:43 +02:00
Nikola Jokic 081b9ce1ee Fix secret reconciliation updates for the listener pod (#4492) 2026-05-11 15:04:07 +02:00
Nikola Jokic ef48f429b3 Render empty arrays for kubernetes-novolume volumes fields (#4461) 2026-05-11 13:56:01 +02:00
dependabot[bot]andNikola Jokic 9d3ed7cb58 Bump the actions group with 3 updates (#4483)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nikola Jokic <jokicnikola07@gmail.com>
2026-05-11 13:52:41 +02:00
Junya Okabe 0f2a659878 Fix: Detect init container failure in EphemeralRunner controller (#4457) 2026-05-07 13:26:46 +02:00
Junya Okabe 8c84ab2f42 Fix empty GVK in OwnerReferences for modern controllers (#4475) 2026-04-29 19:29:09 +02:00
Junya Okabe 053b8f9ae5 Add health and readiness probes to controller manager (#4459) 2026-04-29 18:08:46 +02:00
Junya Okabe 13a03302c8 Add a flag for enabling pprof on the controller manager (#4449) 2026-04-24 10:03:26 +02:00
Junya Okabe a401686bd5 Add option to disable workqueue bucket rate limiter (#4451) 2026-04-22 23:26:39 +02:00