mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 08:00:19 +02:00
Bump Helm support to 4.2.1 and 3.21.1 (#2635)
* chore: bump helm release pins * chore: align helm module metadata * chore: finalize helm patch bumps * fix: add --plain-http flag for Helm 3.21+ OCI push in tests Helm 3.21.1 introduced stricter security checks that reject HTTP scheme downgrades when pushing to OCI registries, with the error: "blob upload Location downgrades scheme from https" Previously only Helm 4 required --plain-http for HTTP-only OCI registries. Now Helm 3.21+ also requires this flag. Add a new requiresPlainHTTPForOCI() helper that returns true for both Helm 4.x and Helm 3.21+, and use it in execHelmPush() instead of isHelm4(). * fix: safe fallback in requiresPlainHTTPForOCI when version detection fails Default to true (require --plain-http) when helm version detection fails, since any Helm version that supports helm push also supports the --plain-http flag. This avoids the inconsistent HELMFILE_HELM4 env var fallback which only covered Helm 4. * fix: update snapshot tests for Helm 4.2.1 OCI pull output Helm 4.2.1 now outputs additional 'Pulled:' and 'Digest: sha256:...' lines after each OCI chart pull. The SHA256 digest is non-deterministic because helm packages include build timestamps, so normalize it with a regex placeholder. - Add ociDigestRegex to normalize non-deterministic OCI digest values - Create output-helm4.yaml for 5 tests that lacked Helm 4 snapshots - Update output-helm4.yaml for oci_need and postrenderer to include the new Pulled/Digest lines from Helm dependency pull operations * fix: update ociDigestRegex to match empty digest in Helm 4.2.1 OCI pull output Helm 4.2.1 outputs "Digest: sha256:" (empty hash) when pulling OCI charts. The regex required at least one hex char ([0-9a-f]+), so it did not match and the digest was not normalized to $DIGEST in snapshot tests. Also fix the replacement string: Go regex ReplaceAllString interprets $DIGEST as a capture group reference (resolving to empty). Use $$DIGEST to produce a literal $DIGEST in the output. Signed-off-by: yxxhero <aiopsclub@163.com> --------- Signed-off-by: yxxhero <aiopsclub@163.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: yxxhero <aiopsclub@163.com>
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
HELM_VERSION ?= v4.2.0
|
||||
HELM_VERSION ?= v4.2.1
|
||||
KUSTOMIZE_VERSION ?= v5.8.0
|
||||
K8S_VERSION ?= v1.34.0
|
||||
MINIKUBE_VERSION ?= v1.37.0
|
||||
|
||||
@@ -37,7 +37,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
helm-version: [v3.18.6, v3.21.0, v4.2.0]
|
||||
helm-version: [v3.18.6, v3.21.1, v4.2.1]
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
@@ -67,16 +67,16 @@ jobs:
|
||||
env:
|
||||
HELMFILE_HELM4: ${{ startsWith(matrix.helm-version, 'v4') && '1' || '0' }}
|
||||
- name: Archive built binaries
|
||||
if: matrix.helm-version == 'v4.2.0'
|
||||
if: matrix.helm-version == 'v4.2.1'
|
||||
run: tar -cvf built-binaries.tar helmfile diff-yamls dyff
|
||||
- uses: actions/upload-artifact@v7
|
||||
if: matrix.helm-version == 'v4.2.0'
|
||||
if: matrix.helm-version == 'v4.2.1'
|
||||
with:
|
||||
name: built-binaries-${{ github.run_id }}
|
||||
path: built-binaries.tar
|
||||
retention-days: 1
|
||||
- name: Display built binaries
|
||||
if: matrix.helm-version == 'v4.2.0'
|
||||
if: matrix.helm-version == 'v4.2.1'
|
||||
run: ls -l helmfile diff-yamls dyff
|
||||
|
||||
integration_tests:
|
||||
@@ -105,23 +105,23 @@ jobs:
|
||||
plugin-secrets-version: 4.7.4
|
||||
plugin-diff-version: 3.15.8
|
||||
extra-helmfile-flags: '--enable-live-output'
|
||||
- helm-version: v3.21.0
|
||||
- helm-version: v3.21.1
|
||||
kustomize-version: v5.8.0
|
||||
plugin-secrets-version: 4.7.4
|
||||
plugin-diff-version: 3.15.8
|
||||
extra-helmfile-flags: ''
|
||||
- helm-version: v3.21.0
|
||||
- helm-version: v3.21.1
|
||||
kustomize-version: v5.8.0
|
||||
plugin-secrets-version: 4.7.4
|
||||
plugin-diff-version: 3.15.8
|
||||
extra-helmfile-flags: '--enable-live-output'
|
||||
# Helmfile now supports both Helm 3.x and Helm 4.x
|
||||
- helm-version: v4.2.0
|
||||
- helm-version: v4.2.1
|
||||
kustomize-version: v5.8.0
|
||||
plugin-secrets-version: 4.7.4
|
||||
plugin-diff-version: 3.15.8
|
||||
extra-helmfile-flags: ''
|
||||
- helm-version: v4.2.0
|
||||
- helm-version: v4.2.1
|
||||
kustomize-version: v5.8.0
|
||||
plugin-secrets-version: 4.7.4
|
||||
plugin-diff-version: 3.15.8
|
||||
|
||||
Reference in New Issue
Block a user