Files
Aditya Menon c71648c060 fix: resolve --validate flag conflict with kustomize in Helm 4 (#2362)
* fix: resolve --validate flag conflict with kustomize in Helm 4

Fixes #2355

In Helm 4, the --validate and --dry-run flags are mutually exclusive.
When using kustomize/chartify charts with helmfile diff --validate,
the code was adding both --validate AND --dry-run=server to the
helm template command, causing the error:

  Error: if any flags in the group [validate dry-run] are set none
  of the others can be; [dry-run validate] were all set

The fix checks if --validate is already set before adding --dry-run=server.
Since --validate already provides server-side validation (it was deprecated
in favor of --dry-run=server in Helm 4), adding --dry-run=server is
redundant when --validate is present.

Changes:
- Add !opts.Validate condition to processChartification() in state.go
- Add comprehensive unit tests for validate/dry-run mutual exclusion
- Add integration test with kustomize chart to prevent regression

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* address review feedback from Copilot

- Add missing test cases for destroy, delete, test, status WITH --validate
- Update integration test to use 'diff' instead of 'template' to properly
  exercise the cluster-requiring code path that triggers --dry-run=server
- Add sync warning comments to the test helper function noting it must be
  kept in sync with processChartification() in state.go

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* add missing 'build with validate' test case

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* address additional review feedback from Copilot

- Fix integration test to capture output and exit code in single execution
  instead of running helmfile twice (more efficient)
- Add detailed documentation explaining why test helper duplication is
  intentional: extracting shared function would require exposing internal
  API and complex refactoring of processChartification dependencies
- Note that integration test exercises actual code path end-to-end

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* fix: correct go doc comment formatting for gci linter

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

* fix: update line number reference from 1497-1523 to 1497-1524

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>

---------

Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>
2026-01-18 13:59:55 +08:00

43 lines
2.3 KiB
Bash
Executable File

#!/usr/bin/env bash
# Regression test for issue #2355: Validate flag does not work when using kustomize after Helm 4 upgrade
#
# Background: In Helm 4, the --validate and --dry-run flags are mutually exclusive.
# When helmfile uses kustomize/chartify, it was incorrectly adding --dry-run=server
# even when --validate was already set, causing:
# Error: if any flags in the group [validate dry-run] are set none of the others can be
issue_2355_input_dir="${cases_dir}/issue-2355/input"
test_start "issue-2355: validate flag with kustomize charts (Helm 4 compatibility)"
# Test 1: helmfile diff --validate with kustomize chart should NOT fail due to validate/dry-run mutual exclusion
# We deliberately use diff here because it is a cluster-requiring command that can trigger --dry-run=server via chartify.
info "Test 1: Running diff --validate with kustomize chart"
error_output=$(${helmfile} -f ${issue_2355_input_dir}/helmfile.yaml diff --validate 2>&1)
exit_code=$?
if [ $exit_code -ne 0 ]; then
# Check if it's the specific mutual exclusion error we're fixing
if echo "$error_output" | grep -q "validate.*dry-run.*were all set"; then
fail "helmfile diff --validate with kustomize failed with mutual exclusion error (issue #2355 not fixed): $error_output"
else
# Other errors might be acceptable (e.g., no cluster connection for validation, or non-zero diff exit codes)
warn "helmfile diff --validate had an error (but not the mutual exclusion issue): $error_output"
fi
fi
# Test 2: Verify that without --validate, the command does not hit the mutual exclusion error
info "Test 2: Running diff without --validate (baseline test for flag interaction)"
error_output=$(${helmfile} -f ${issue_2355_input_dir}/helmfile.yaml diff 2>&1)
exit_code=$?
if [ $exit_code -ne 0 ]; then
if echo "$error_output" | grep -q "validate.*dry-run.*were all set"; then
fail "helmfile diff without --validate failed with mutual exclusion error (issue #2355 not fixed): $error_output"
else
# Non-zero exit codes from diff (e.g., detected differences) or other errors are tolerated here.
warn "helmfile diff without --validate had an error (but not the mutual exclusion issue): $error_output"
fi
fi
test_pass "issue-2355: validate flag with kustomize charts (Helm 4 compatibility)"