Files
actions-runner-controller/charts
Nikola JokicandCopilot App 55f1ad560b Validate and coerce listener metadata, and match Kubernetes key rules
Follow-up review of the metadata validation surfaced four gaps:

Listener pod metadata took the same unvalidated, uncoerced path that the
runner pod metadata used to: an invalid label only failed once the
controller created the listener pod, which is the silent failure mode
this change set exists to remove. Both charts now validate it at render
time and route its values through the string coercion.

Values loaded from a values file arrive as float64, so "%v" rendered a
large integer such as 12345678901234 in scientific notation, silently
corrupting the annotation. Integral floats are now formatted without an
exponent, and the remaining sites that quoted metadata values directly
go through the same helper.

A map or list value was flattened into Go's own formatting, producing a
meaningless "map[a:b]" label. Such values are now rejected with the
values path that produced them.

The label key prefix check rejected dot-separated segments longer than
63 characters. Kubernetes only bounds the prefix at 253 characters in
total, so the check was stricter than the API server and would have
rejected keys that already work.

While covering the listener path, the experimental chart turned out to
render invalid YAML whenever listener.podTemplate carried both metadata
and spec: the last metadata value and the following "spec:" key ended up
on the same line. That is fixed here too, with a regression test.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 09:56:58 +02:00
..