mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 10:11:54 +02:00
* feat: add `helmfile doctor` command for AI-assisted diff analysis `helmfile doctor` runs `helmfile diff` and asks an OpenAI-compatible LLM to summarize the changes and flag risks (data loss, security exposure, breaking changes, downtime, performance, best-practice issues). Key design decisions: - When no LLM is configured, doctor is equivalent to `helmfile diff` with one exception: --show-secrets is always forced off (secrets never reach stdout, even without an LLM). - Secrets are ALWAYS redacted via two layers: (1) ShowSecrets() forced to false so helm-diff emits <REDACTED> placeholders; (2) a defense-in-depth text redactor strips residual secret-looking content (Secret YAML blocks, sensitive key/value lines, base64 blobs, JWT tokens) before LLM transmission. - LLM configuration precedence: env (HELMFILE_LLM_*) < helmfile.yaml (llm:) < CLI flags (--llm-*). - Supports any OpenAI-compatible backend (OpenAI, Azure, One-API, LiteLLM, Ollama, etc.) with automatic response_format fallback for backends that don't support JSON mode. - Prompt injection defense: release names and environment values are JSON-encoded before insertion into the LLM prompt. - Exit codes: 0 (success/low-risk), 2 (high-risk gate, bypass with --force), 1 (other errors). Helm-diff's 'detected changes' exit-2 is swallowed. New packages: - pkg/agent/llm: OpenAI-compatible client with JSON response parsing, mock client for testing, prompt builder with injection defense. - pkg/agent/doctor: secret redactor (state machine + regex), report renderer (markdown + JSON), config resolver (env < yaml < flag merge). Testing: 70+ unit tests covering redaction patterns, prompt injection, response_format fallback, JSON parsing, yaml roundtrip, concurrency safety, panic recovery, and error propagation. go test -race passes. Documentation: full doctor section in docs/cli.md, llm: block reference in docs/configuration.md, updated skills/helmfile for AI agents. Signed-off-by: yxxhero <aiopsclub@163.com> * docs: fix doctor equivalence wording per PR review Per review feedback (PR #2660): the docs claimed doctor is 'equivalent to helmfile diff — same flags, same output, same exit codes' in the unconfigured path, but this over-promises because: 1. doctor --output is the report format (not helm-diff's output format) 2. helm-diff's --output is exposed as --diff-output in doctor 3. --show-secrets is silently ignored Updated all three locations (cli.md, cmd/doctor.go Long + godoc, pkg/app/doctor.go godoc) to say 'falls back to helmfile diff with --show-secrets forced off' and explicitly note the --output / --diff-output flag difference. Signed-off-by: yxxhero <aiopsclub@163.com> --------- Signed-off-by: yxxhero <aiopsclub@163.com>
94 lines
3.2 KiB
Go
94 lines
3.2 KiB
Go
package config
|
|
|
|
import (
|
|
"time"
|
|
|
|
"github.com/helmfile/helmfile/pkg/agent/llm"
|
|
)
|
|
|
|
// DoctorOptions is the doctor-specific options *only* (no diff flags here).
|
|
// Doctor is a strict superset of diff, so the diff flags are sourced via the
|
|
// embedded DiffImpl on DoctorImpl. Keeping the option types separate avoids
|
|
// Go's one-level-only field/method promotion tripping us up when DiffOptions
|
|
// and DoctorOptions both grow fields with the same name (e.g. Output).
|
|
type DoctorOptions struct {
|
|
// LLMBaseURL overrides the OpenAI-compatible endpoint base URL.
|
|
LLMBaseURL string
|
|
// LLMAPIKey authenticates against the endpoint.
|
|
LLMAPIKey string
|
|
// LLMModel is the chat completion model identifier.
|
|
LLMModel string
|
|
// LLMTimeout is the per-request timeout. Parsed from a duration string
|
|
// (e.g. "60s", "2m"). Zero means "use the llm package default".
|
|
LLMTimeout time.Duration
|
|
// LLMMaxTokens caps the completion length. Zero means default.
|
|
LLMMaxTokens int
|
|
|
|
// Force skips the high-risk exit-code-2 gate. Useful when CI wants the
|
|
// report but does not want to block.
|
|
Force bool
|
|
|
|
// ReportFormat selects the doctor report format. "text" (markdown) by
|
|
// default, "json" for structured CI consumption.
|
|
//
|
|
// Named ReportFormat (not Output) to avoid shadowing DiffOptions.Output
|
|
// which is the helm-diff plugin format.
|
|
ReportFormat string
|
|
}
|
|
|
|
// NewDoctorOptions creates a new DoctorOptions.
|
|
func NewDoctorOptions() *DoctorOptions {
|
|
return &DoctorOptions{}
|
|
}
|
|
|
|
// DoctorImpl is the config provider implementation for the doctor command.
|
|
// It embeds DiffImpl so any code that consumes a DiffConfigProvider accepts a
|
|
// DoctorImpl unchanged (doctor IS-A diff for the purposes of helm-diff flags).
|
|
type DoctorImpl struct {
|
|
// DiffImpl satisfies DiffConfigProvider and ConfigProvider by providing
|
|
// GlobalImpl + DiffOptions + all their methods.
|
|
*DiffImpl
|
|
// DoctorOptions carries the doctor-only knobs (LLM endpoint, report format).
|
|
*DoctorOptions
|
|
}
|
|
|
|
// NewDoctorImpl creates a new DoctorImpl. It wires a fresh DiffImpl around the
|
|
// same GlobalImpl so that --global flags behave identically to `helmfile diff`.
|
|
//
|
|
// doctorOpts may be nil; in that case a fresh DoctorOptions is allocated.
|
|
func NewDoctorImpl(g *GlobalImpl, doctorOpts *DoctorOptions) *DoctorImpl {
|
|
if doctorOpts == nil {
|
|
doctorOpts = NewDoctorOptions()
|
|
}
|
|
return &DoctorImpl{
|
|
DiffImpl: NewDiffImpl(g, NewDiffOptions()),
|
|
DoctorOptions: doctorOpts,
|
|
}
|
|
}
|
|
|
|
// FlagLLMConfig returns the LLM configuration sourced from CLI flags only.
|
|
// Empty fields mean "flag not set"; the doctor command merges this on top of
|
|
// env+yaml via ResolveConfig.
|
|
func (t *DoctorImpl) FlagLLMConfig() llm.Config {
|
|
return llm.Config{
|
|
BaseURL: t.LLMBaseURL,
|
|
APIKey: t.LLMAPIKey,
|
|
Model: t.LLMModel,
|
|
Timeout: t.LLMTimeout,
|
|
MaxTokens: t.LLMMaxTokens,
|
|
Temperature: 0, // let doctor/llm default apply
|
|
}
|
|
}
|
|
|
|
// Force returns whether --force was passed.
|
|
func (t *DoctorImpl) Force() bool {
|
|
return t.DoctorOptions.Force
|
|
}
|
|
|
|
// DoctorOutput returns the report format ("text" or "json").
|
|
// Named DoctorOutput to satisfy the DoctorConfigProvider interface; backed by
|
|
// ReportFormat to avoid colliding with DiffOptions.Output (helm-diff format).
|
|
func (t *DoctorImpl) DoctorOutput() string {
|
|
return t.DoctorOptions.ReportFormat
|
|
}
|