fix: include query params in HTTP getter cache key (#2399)

* fix: include query params in HTTP getter cache key (#2103)

When helmfile caches remote HTTP files fetched via the "normal" getter
(plain https:// URLs without a git:: prefix), the cache key did not
include query parameters. This caused URLs that differ only in query
params (e.g. ?ref=commit1 vs ?ref=commit2) to share the same cache
directory, silently returning the wrong file version.

The root cause was in Fetch() where the "normal" getter branch
overwrote the cache key with only scheme + host, discarding query
params that were correctly computed earlier.

Fix: extract the query-params suffix into a reusable variable and
apply it in both the default and "normal" getter cache key paths.

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* Update pkg/remote/remote.go

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* Update pkg/remote/remote_test.go

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

---------

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
This commit is contained in:
Aditya Menon
2026-02-14 09:31:53 +08:00
committed by GitHub
co-authored by Copilot
parent 5c43fa6465
commit c6b962dbbf
6 changed files with 303 additions and 13 deletions
+7 -1
View File
@@ -36,7 +36,12 @@ export SOPS_PGP_FP="B2D6D7BBEC03B2E66571C8C00AD18E16CFDEF700"
# FUNCTIONS ----------------------------------------------------------------------------------------------------------
function wait_deploy_ready() {
${kubectl} rollout status deployment ${1}
${kubectl} rollout status deployment ${1} --timeout=300s || {
info "Deployment ${1} rollout timed out, checking pod status:"
${kubectl} get pods -o wide --namespace=${test_ns} 2>/dev/null || true
${kubectl} describe deployment ${1} --namespace=${test_ns} 2>/dev/null | tail -20 || true
fail "Deployment ${1} failed to become ready within 300s"
}
while [ "$(${kubectl} get deploy ${1} -o=jsonpath='{.status.readyReplicas}')" == "0" ]; do
info "Waiting for deployment ${1} to be ready"
sleep 1
@@ -123,6 +128,7 @@ ${kubectl} create namespace ${test_ns} || fail "Could not create namespace ${tes
. ${dir}/test-cases/issue-2297-local-chart-transformers.sh
. ${dir}/test-cases/issue-2309-kube-context-template.sh
. ${dir}/test-cases/issue-2355.sh
. ${dir}/test-cases/issue-2103.sh
# ALL DONE -----------------------------------------------------------------------------------------------------------
+86
View File
@@ -0,0 +1,86 @@
#!/usr/bin/env bash
# Test for issue #2103: HTTP remote cache key should include query parameters.
# Without the fix, two URLs differing only in ?ref= share the same cache and
# the second fetch silently returns stale content from the first.
issue_2103_input_dir="${cases_dir}/issue-2103/input"
issue_2103_tmp_dir=$(mktemp -d)
cleanup_issue_2103() {
kill "${server_pid}" 2>/dev/null || true
rm -rf "${issue_2103_tmp_dir}"
unset HELMFILE_CACHE_HOME HTTP_SERVER_URL
}
trap cleanup_issue_2103 EXIT
test_start "issue-2103: HTTP cache key includes query params"
# --- Start a small HTTP server that returns different YAML per ?ref= ----------
info "Building test HTTP server"
go build -o "${issue_2103_tmp_dir}/server" "${issue_2103_input_dir}/server.go" \
|| fail "Could not build test HTTP server"
"${issue_2103_tmp_dir}/server" > "${issue_2103_tmp_dir}/server_addr.txt" &
server_pid=$!
# Poll until the server writes its address (up to 10 seconds: 20 x 0.5s)
for i in $(seq 1 20); do
if ! kill -0 "${server_pid}" 2>/dev/null; then
fail "Test HTTP server failed to start"
fi
if [ -s "${issue_2103_tmp_dir}/server_addr.txt" ]; then
break
fi
sleep 0.5
done
if [ ! -s "${issue_2103_tmp_dir}/server_addr.txt" ]; then
fail "Test HTTP server did not write its address in time"
fi
server_url=$(cat "${issue_2103_tmp_dir}/server_addr.txt")
info "Test HTTP server running at ${server_url}"
# --- Fetch remote values through helmfile and verify cache has both refs ------
export HTTP_SERVER_URL="${server_url}"
export TEST_NS="${test_ns}"
export HELMFILE_CACHE_HOME="${issue_2103_tmp_dir}/cache"
info "Running helmfile template with two releases using different ?ref= values"
${helmfile} -f "${issue_2103_input_dir}/helmfile.yaml.gotmpl" template \
> "${issue_2103_tmp_dir}/template_output.txt" 2>&1 || {
helmfile_exit_code=$?
info "helmfile template output:"
cat "${issue_2103_tmp_dir}/template_output.txt"
fail "helmfile template failed with exit code ${helmfile_exit_code}"
}
# Verify that two distinct cache directories were created for the two refs.
# With the fix, the cache key includes the query params so each ref gets its own dir.
# Without the fix, both refs would share one cache dir and the second would be stale.
info "Checking cached files for distinct ref values"
cached_commit1=$(find "${issue_2103_tmp_dir}/cache" -type f -name "raw" -exec grep -l "version: commit1" {} \; || true)
cached_commit2=$(find "${issue_2103_tmp_dir}/cache" -type f -name "raw" -exec grep -l "version: commit2" {} \; || true)
if [ -n "${cached_commit1}" ] && [ -n "${cached_commit2}" ]; then
info "Found separate cached files:"
info " commit1: ${cached_commit1}"
info " commit2: ${cached_commit2}"
if [ "${cached_commit1}" = "${cached_commit2}" ]; then
fail "Issue #2103 regression: both refs cached to the same file"
fi
info "Cache keys are distinct — fix is working"
else
info "Cache directory contents:"
find "${issue_2103_tmp_dir}/cache" -type f 2>/dev/null
info "Template output:"
cat "${issue_2103_tmp_dir}/template_output.txt"
fail "Issue #2103 regression: query-param-specific values were not cached separately"
fi
trap - EXIT
test_pass "issue-2103: HTTP cache key includes query params"
@@ -0,0 +1,11 @@
releases:
- name: test-release-commit1
namespace: {{ env "TEST_NS" | default "default" }}
chart: ../../../charts/raw
values:
- {{ env "HTTP_SERVER_URL" }}/api/v4/projects/test/files/values.yaml/raw?ref=commit1
- name: test-release-commit2
namespace: {{ env "TEST_NS" | default "default" }}
chart: ../../../charts/raw
values:
- {{ env "HTTP_SERVER_URL" }}/api/v4/projects/test/files/values.yaml/raw?ref=commit2
@@ -0,0 +1,36 @@
// server.go is a small HTTP server used by the issue-2103 integration test.
// It serves different YAML content based on the "ref" query parameter.
package main
import (
"fmt"
"net"
"net/http"
"os"
)
func main() {
mux := http.NewServeMux()
mux.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) {
ref := r.URL.Query().Get("ref")
if ref == "" {
ref = "unknown"
}
w.Header().Set("Content-Type", "text/plain")
_, _ = fmt.Fprintf(w, "version: %s\n", ref)
})
listener, err := net.Listen("tcp", "127.0.0.1:0")
if err != nil {
fmt.Fprintf(os.Stderr, "Failed to listen: %v\n", err)
os.Exit(1)
}
// Print the address so the test script can capture it.
fmt.Printf("http://%s\n", listener.Addr().String())
if err := http.Serve(listener, mux); err != nil {
fmt.Fprintf(os.Stderr, "Server error: %v\n", err)
os.Exit(1)
}
}