mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 21:09:40 +02:00
Toolchain and CI:
- Bump go directive from 1.26.8 to 1.27.1 (go.mod)
- Use golang:1.27-alpine builder images in all Dockerfiles
- Bump golangci-lint to v2.13.2 (first release with go1.27 support)
- Add CI gate: `go fix -diff` fails when outdated Go patterns are
detected (locally: `make check-modernize`)
Note: darwin binaries now require macOS 13 or later.
Lint fixes required by golangci-lint v2.13.2:
- goconst: ignore tests (all 436 findings were test-only; goconst
got stricter since v2.12 and this option was added for it)
- openai.go: keep deprecated MaxTokens deliberately with a nolint
rationale (max_tokens is the only form universally supported by
OpenAI-compatible backends like One-API, LiteLLM, Ollama shim)
- state.go: drop always-nil flags param from appendChartVersionFlags
(renamed to chartVersionFlags, unparam)
Modernization (go fix ./..., 62 files):
- interface{} -> any, maps.Copy, strings.SplitSeq, range-over-int,
builtin min/max, slices.Contains/ContainsFunc/Sort, WaitGroup.Go,
reflect.Type.Fields(), new(expr)
- exit_error.go: strings.Builder + fmt.Fprintf instead of string
concatenation and WriteString(fmt.Sprintf(...)) (QF1012)
- chart_dependency.go: strings.CutLast for OCI dependency helpers
Signed-off-by: yxxhero <aiopsclub@163.com>
Co-authored-by: Claude <noreply@anthropic.com>
105 lines
2.6 KiB
Go
105 lines
2.6 KiB
Go
package helmexec
|
|
|
|
import (
|
|
"slices"
|
|
"strings"
|
|
)
|
|
|
|
// RedactionProfile selects how aggressively RedactArgs masks secret-bearing
|
|
// command-line arguments.
|
|
type RedactionProfile int
|
|
|
|
const (
|
|
// RedactionLegacy reproduces the historical exit-error behavior
|
|
// byte-for-byte: only the argument *following* a flag whose name starts
|
|
// with "--set" is masked. The goldens in exit_error_test.go pin this
|
|
// output; changing it changes observable error messages.
|
|
RedactionLegacy RedactionProfile = iota
|
|
|
|
// RedactionStrict masks every secret-bearing argument form known today:
|
|
// in addition to the legacy behavior it covers single-argument forms
|
|
// (--set=key=value) and credential flags (--username, --password,
|
|
// --key-file). Used for telemetry span attributes; span visibility must
|
|
// be at least as redacted as error messages.
|
|
RedactionStrict
|
|
)
|
|
|
|
// redactedArg is the placeholder written in place of secret values; its exact
|
|
// bytes are pinned by exit_error_test.go.
|
|
const redactedArg = "*** STRIP ***"
|
|
|
|
// strictNextArgFlags are the flags whose following argument is a secret.
|
|
var strictNextArgFlags = []string{
|
|
"--set",
|
|
"--set-string",
|
|
"--set-file",
|
|
"--set-json",
|
|
"--set-literal",
|
|
"--username",
|
|
"--password",
|
|
"--key-file",
|
|
"--kube-token",
|
|
}
|
|
|
|
// RedactArgs returns a copy of args with secret-bearing values masked
|
|
// according to profile. The input slice is never mutated.
|
|
func RedactArgs(args []string, profile RedactionProfile) []string {
|
|
if len(args) == 0 {
|
|
return args
|
|
}
|
|
|
|
out := make([]string, len(args))
|
|
copy(out, args)
|
|
|
|
for i := range out {
|
|
// The previous token must be read from the ORIGINAL slice: reading
|
|
// the progressively redacted output would let a masked value hide a
|
|
// following secret (e.g. {"--set", "--set-string", "secret"}).
|
|
var prev string
|
|
if i > 0 {
|
|
prev = args[i-1]
|
|
}
|
|
|
|
switch profile {
|
|
case RedactionLegacy:
|
|
if strings.HasPrefix(prev, "--set") {
|
|
out[i] = redactedArg
|
|
}
|
|
case RedactionStrict:
|
|
if isStrictNextArgFlag(prev) {
|
|
out[i] = redactedArg
|
|
} else if flag := strictInlineFlag(out[i]); flag != "" {
|
|
out[i] = flag + "=" + redactedArg
|
|
}
|
|
}
|
|
}
|
|
return out
|
|
}
|
|
|
|
func isStrictNextArgFlag(arg string) bool {
|
|
return slices.Contains(strictNextArgFlags, arg)
|
|
}
|
|
|
|
// strictInlineFlag returns the flag name when arg is a single-argument secret
|
|
// form such as "--set=key=value", or "" otherwise.
|
|
func strictInlineFlag(arg string) string {
|
|
for _, flag := range strictNextArgFlags {
|
|
if strings.HasPrefix(arg, flag+"=") {
|
|
return flag
|
|
}
|
|
}
|
|
return ""
|
|
}
|
|
|
|
func equalArgs(a, b []string) bool {
|
|
if len(a) != len(b) {
|
|
return false
|
|
}
|
|
for i := range a {
|
|
if a[i] != b[i] {
|
|
return false
|
|
}
|
|
}
|
|
return true
|
|
}
|