mirror of
https://github.com/actions-runner-controller/actions-runner-controller.git
synced 2026-10-05 01:14:07 +02:00
Invalid labels supplied through .Values.template.metadata.labels (or the resourceMeta blocks) are not rejected by the API server: they live inside the AutoscalingRunnerSet spec, whose CRD schema only enforces the value type. The invalid value is only caught when the controller creates the runner pod, at which point the EphemeralRunner is marked as failed with ReasonInvalidPodFailure and the scale set never produces runners. Validate every label and annotation map the charts render against the Kubernetes key/value rules so helm install/upgrade fails immediately with the offending values path, key and value. Also render all metadata values as strings. Scalars such as 'true' or '1' were previously emitted as YAML booleans and numbers, which Kubernetes rejects for labels and annotations. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
65 lines
2.7 KiB
YAML
65 lines
2.7 KiB
YAML
{{- if not (kindIs "string" .Values.githubConfigSecret) }}
|
|
{{- $hasCustomResourceMeta := (and .Values.resourceMeta .Values.resourceMeta.githubConfigSecret) }}
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: {{ include "gha-runner-scale-set.githubsecret" . }}
|
|
namespace: {{ include "gha-runner-scale-set.namespace" . }}
|
|
labels:
|
|
{{- $base := include "gha-runner-scale-set.labels" . | fromYaml }}
|
|
{{- $extra := dict "app.kubernetes.io/component" "" }}
|
|
{{- $reserved := merge $base $extra }}
|
|
{{- with .Values.labels }}
|
|
{{- range $k, $v := . }}
|
|
{{- if not (or (hasKey $reserved $k) (hasPrefix "actions.github.com/" $k)) }}
|
|
{{ $k }}: {{ $v | quote }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- if $hasCustomResourceMeta }}
|
|
{{- with .Values.resourceMeta.githubConfigSecret.labels }}
|
|
{{- include "gha-runner-scale-set.stringMap" . | nindent 4 }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- include "gha-runner-scale-set.labels" . | nindent 4 }}
|
|
annotations:
|
|
{{- with .Values.annotations }}
|
|
{{- include "gha-runner-scale-set.stringMap" . | nindent 4 }}
|
|
{{- end }}
|
|
{{- if $hasCustomResourceMeta }}
|
|
{{- with .Values.resourceMeta.githubConfigSecret.annotations }}
|
|
{{- include "gha-runner-scale-set.stringMap" . | nindent 4 }}
|
|
{{- end }}
|
|
{{- end }}
|
|
finalizers:
|
|
- actions.github.com/cleanup-protection
|
|
data:
|
|
{{- $hasToken := false }}
|
|
{{- $hasAppId := false }}
|
|
{{- $hasInstallationId := false }}
|
|
{{- $hasPrivateKey := false }}
|
|
{{- range $secretName, $secretValue := (required "Values.githubConfigSecret is required for setting auth with GitHub server." .Values.githubConfigSecret) }}
|
|
{{- if $secretValue }}
|
|
{{ $secretName }}: {{ $secretValue | toString | b64enc }}
|
|
{{- if eq $secretName "github_token" }}
|
|
{{- $hasToken = true }}
|
|
{{- end }}
|
|
{{- if eq $secretName "github_app_id" }}
|
|
{{- $hasAppId = true }}
|
|
{{- end }}
|
|
{{- if eq $secretName "github_app_installation_id" }}
|
|
{{- $hasInstallationId = true }}
|
|
{{- end }}
|
|
{{- if eq $secretName "github_app_private_key" }}
|
|
{{- $hasPrivateKey = true }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- if and (not $hasToken) (not ($hasAppId)) }}
|
|
{{- fail "A valid .Values.githubConfigSecret is required for setting auth with GitHub server, provide .Values.githubConfigSecret.github_token or .Values.githubConfigSecret.github_app_id." }}
|
|
{{- end }}
|
|
{{- if and $hasAppId (or (not $hasInstallationId) (not $hasPrivateKey)) }}
|
|
{{- fail "A valid .Values.githubConfigSecret is required for setting auth with GitHub server, provide .Values.githubConfigSecret.github_app_installation_id and .Values.githubConfigSecret.github_app_private_key." }}
|
|
{{- end }}
|
|
{{- end}}
|