Files
helmfile/pkg/helmexec/redact.go
T
yxxheroandClaude ad81e4231e build: update Go to 1.27.1 and modernize the codebase (#2798)
Toolchain and CI:
- Bump go directive from 1.26.8 to 1.27.1 (go.mod)
- Use golang:1.27-alpine builder images in all Dockerfiles
- Bump golangci-lint to v2.13.2 (first release with go1.27 support)
- Add CI gate: `go fix -diff` fails when outdated Go patterns are
  detected (locally: `make check-modernize`)

Note: darwin binaries now require macOS 13 or later.

Lint fixes required by golangci-lint v2.13.2:
- goconst: ignore tests (all 436 findings were test-only; goconst
  got stricter since v2.12 and this option was added for it)
- openai.go: keep deprecated MaxTokens deliberately with a nolint
  rationale (max_tokens is the only form universally supported by
  OpenAI-compatible backends like One-API, LiteLLM, Ollama shim)
- state.go: drop always-nil flags param from appendChartVersionFlags
  (renamed to chartVersionFlags, unparam)

Modernization (go fix ./..., 62 files):
- interface{} -> any, maps.Copy, strings.SplitSeq, range-over-int,
  builtin min/max, slices.Contains/ContainsFunc/Sort, WaitGroup.Go,
  reflect.Type.Fields(), new(expr)
- exit_error.go: strings.Builder + fmt.Fprintf instead of string
  concatenation and WriteString(fmt.Sprintf(...)) (QF1012)
- chart_dependency.go: strings.CutLast for OCI dependency helpers

Signed-off-by: yxxhero <aiopsclub@163.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 13:29:02 +08:00

105 lines
2.6 KiB
Go

package helmexec
import (
"slices"
"strings"
)
// RedactionProfile selects how aggressively RedactArgs masks secret-bearing
// command-line arguments.
type RedactionProfile int
const (
// RedactionLegacy reproduces the historical exit-error behavior
// byte-for-byte: only the argument *following* a flag whose name starts
// with "--set" is masked. The goldens in exit_error_test.go pin this
// output; changing it changes observable error messages.
RedactionLegacy RedactionProfile = iota
// RedactionStrict masks every secret-bearing argument form known today:
// in addition to the legacy behavior it covers single-argument forms
// (--set=key=value) and credential flags (--username, --password,
// --key-file). Used for telemetry span attributes; span visibility must
// be at least as redacted as error messages.
RedactionStrict
)
// redactedArg is the placeholder written in place of secret values; its exact
// bytes are pinned by exit_error_test.go.
const redactedArg = "*** STRIP ***"
// strictNextArgFlags are the flags whose following argument is a secret.
var strictNextArgFlags = []string{
"--set",
"--set-string",
"--set-file",
"--set-json",
"--set-literal",
"--username",
"--password",
"--key-file",
"--kube-token",
}
// RedactArgs returns a copy of args with secret-bearing values masked
// according to profile. The input slice is never mutated.
func RedactArgs(args []string, profile RedactionProfile) []string {
if len(args) == 0 {
return args
}
out := make([]string, len(args))
copy(out, args)
for i := range out {
// The previous token must be read from the ORIGINAL slice: reading
// the progressively redacted output would let a masked value hide a
// following secret (e.g. {"--set", "--set-string", "secret"}).
var prev string
if i > 0 {
prev = args[i-1]
}
switch profile {
case RedactionLegacy:
if strings.HasPrefix(prev, "--set") {
out[i] = redactedArg
}
case RedactionStrict:
if isStrictNextArgFlag(prev) {
out[i] = redactedArg
} else if flag := strictInlineFlag(out[i]); flag != "" {
out[i] = flag + "=" + redactedArg
}
}
}
return out
}
func isStrictNextArgFlag(arg string) bool {
return slices.Contains(strictNextArgFlags, arg)
}
// strictInlineFlag returns the flag name when arg is a single-argument secret
// form such as "--set=key=value", or "" otherwise.
func strictInlineFlag(arg string) string {
for _, flag := range strictNextArgFlags {
if strings.HasPrefix(arg, flag+"=") {
return flag
}
}
return ""
}
func equalArgs(a, b []string) bool {
if len(a) != len(b) {
return false
}
for i := range a {
if a[i] != b[i] {
return false
}
}
return true
}