mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 07:50:57 +02:00
* feat: add --template-args to enable helm lookup() during template/apply/sync (#1833) Add a --template-args flag to the template, apply, and sync subcommands so extra args (most notably --dry-run=server) can be passed to the helm template invocation, enabling Helm's lookup() function to resolve live cluster values. - template: --template-args reaches both chartify's pre-render helm template and the final helm template output (flagsForTemplate). - apply/sync: --template-args reaches chartify's pre-render helm template. apply/sync already inject --dry-run=server automatically for cluster operations; the flag is an explicit opt-in for the template subcommand or for passing additional flags. - When --dry-run is present in template args, kube-context/kubeconfig are also injected into chartify so lookup() can actually reach the cluster. - Resolves the long-stale PR #1833 rebased onto current main, which already contains the cluster-connectivity infrastructure (issues #2271, #2309, #2355, #2444). - Includes integration test (lookup.sh) covering both chartify and non-chartify scenarios. Signed-off-by: yxxhero <aiopsclub@163.com> * test: make lookup template nil-safe to fix integration CI The lookup() function returns an empty map when the chart is rendered without a cluster connection (notably the helm-diff phase of `helmfile apply`). The original fixture chained `index` over the lookup result, panicking with "index of untyped nil" during apply's diff rendering. Guard every index with `default dict` so the template falls back to "overwritten" when lookup is empty, while still resolving to the live value ("init") when cluster access is available (--dry-run=server via --template-args, or a real helm upgrade). Signed-off-by: yxxhero <aiopsclub@163.com> * feat: enable lookup() during apply/diff via --template-args in helm-diff Thread --template-args into the helm-diff rendering path so that `helmfile apply`/`diff --template-args="--dry-run=server"` resolves Helm's lookup() function during the diff phase too. helm-diff supports `--dry-run=server`, which explicitly "enables the cluster access ... and the lookup template function". Previously --template-args only reached chartify's pre-render (which is a no-op for plain charts due to chartify's early-return when there is no forceNamespace/patches/injections) and the final `helm template` of the `template` subcommand. As a result `helmfile apply` on a lookup chart rendered client-side during the diff phase. Changes: - pkg/state: add TemplateArgs to DiffOpts; append it in appendExtraDiffFlags (reaches every helm-diff invocation: apply, standalone diff, interactive sync), mirroring the existing flagsForTemplate handling. - pkg/config + cmd: add --template-args to the diff/doctor commands and to DiffConfigProvider, so lookup works for `helmfile diff` as well. - pkg/app: populate DiffOpts.TemplateArgs from apply/diff/sync-interactive. - docs/cli.md: correct the previous overpromising wording and document diff support plus the nil-safe lookup guidance. - tests: unit-test the TemplateArgs handling in appendExtraDiffFlags and flagsForTemplate; integration lookup.sh now exercises apply with --template-args="--dry-run=server". Signed-off-by: yxxhero <aiopsclub@163.com> * refactor: de-duplicate chartify template-args logic, add helmDefaults.templateArgs Address review feedback on #2666: 1. Eliminate stale duplicated test helpers (issue_2444_test.go, issue_2355_test.go). Both files intentionally copied the processChartification flag-building logic with explicit SYNC WARNING comments, then drifted out of sync when #2666 refactored the production code (needsKubeConnection gate, user-args merge). Extract the real logic into pure, unit-tested helpers (buildChartifyTemplateArgs, commandRequiresCluster) and delete the copies. 2. Add unit coverage for the new chartify merge path: template + --template-args=--dry-run=server now triggers kubeconfig/kube-context injection (TestTemplateArgsDryRunTriggersKubeInjection, TestTemplateArgsMergedBeforeInjection) — previously only covered by the cluster-dependent integration test. 3. Add a negative integration case (lookup.sh assert_template_fallback) verifying lookup() falls back to the default value WITHOUT --template-args, guarding against a regression that silently always connects to the cluster. 4. Add helmDefaults.templateArgs for parity with diffArgs/syncArgs, so users can enable lookup() support permanently instead of passing the flag on every invocation. CLI --template-args overrides (does not merge with) the default. Resolved via effectiveTemplateArgs, wired into the chartify, flagsForTemplate, and appendExtraDiffFlags paths. 5. Minor: capitalize --template-args help text to match surrounding flags; document helmDefaults.templateArgs precedence in docs/cli.md. Signed-off-by: yxxhero <aiopsclub@163.com> * test: cover helmDefaults->chartify composition; fix helm helm-diff typo Address remaining review nits on #2666: - Add TestHelmDefaultsTemplateArgsReachesChartify, a belt-and-suspenders test for the processChartification composition (effectiveTemplateArgs -> buildChartifyTemplateArgs), closing the last unit-level coverage gap for helmDefaults.templateArgs reaching the chartify path. - Fix pre-existing typo in cmd/bind_diff_flags.go: 'pass args to helm helm-diff' -> 'Pass args to helm-diff' (doubled 'helm', lowercase). Signed-off-by: yxxhero <aiopsclub@163.com> * fix: correct 'helm helm-diff' typo in apply --diff-args help text Sibling of the bind_diff_flags.go fix; the same doubled-'helm' typo and lowercase help existed in cmd/apply.go's --diff-args registration, leaving the apply and diff/doctor help strings inconsistent. Signed-off-by: yxxhero <aiopsclub@163.com> * docs: add helmDefaults.templateArgs to configuration reference The complete helmfile.yaml schema in docs/configuration.md documents diffArgs and syncArgs under helmDefaults but was missing the new templateArgs field added in #2666. Add it beside syncArgs for discoverability, noting the --template-args CLI override. Signed-off-by: yxxhero <aiopsclub@163.com> --------- Signed-off-by: yxxhero <aiopsclub@163.com>
252 lines
9.0 KiB
Go
252 lines
9.0 KiB
Go
package state
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
// TestKubeconfigPassedToChartify verifies that when --kubeconfig is set,
|
|
// it is passed to chartify's internal helm template call.
|
|
// This is a regression test for issue #2444.
|
|
//
|
|
// Background: When using jsonPatches or kustomize patches with helmfile,
|
|
// chartify runs "helm template" internally to render the chart before applying patches.
|
|
// The lookup() helm function requires cluster access (--dry-run=server).
|
|
// Without --kubeconfig being passed to the internal helm template call,
|
|
// it fails to connect to the cluster when the user's kubeconfig is not in the default location.
|
|
//
|
|
// These tests exercise the real HelmState.buildChartifyTemplateArgs method (the pure
|
|
// helper that processChartification delegates to), not a duplicated copy of the logic.
|
|
func TestKubeconfigPassedToChartify(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
helmfileCommand string
|
|
kubeconfig string
|
|
kubeContext string
|
|
expectedFlags []string
|
|
unexpectedFlags []string
|
|
}{
|
|
{
|
|
name: "sync with kubeconfig should pass both kubeconfig and dry-run=server",
|
|
helmfileCommand: "sync",
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
kubeContext: "",
|
|
expectedFlags: []string{"--kubeconfig", "/path/to/kubeconfig", "--dry-run=server"},
|
|
unexpectedFlags: []string{},
|
|
},
|
|
{
|
|
name: "sync with kubeconfig and kube-context should pass both",
|
|
helmfileCommand: "sync",
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
kubeContext: "my-context",
|
|
expectedFlags: []string{"--kubeconfig", "/path/to/kubeconfig", "--kube-context", "my-context", "--dry-run=server"},
|
|
unexpectedFlags: []string{},
|
|
},
|
|
{
|
|
name: "apply with kubeconfig should pass kubeconfig",
|
|
helmfileCommand: "apply",
|
|
kubeconfig: "/custom/kubeconfig",
|
|
kubeContext: "",
|
|
expectedFlags: []string{"--kubeconfig", "/custom/kubeconfig", "--dry-run=server"},
|
|
unexpectedFlags: []string{},
|
|
},
|
|
{
|
|
name: "diff with kubeconfig should pass kubeconfig",
|
|
helmfileCommand: "diff",
|
|
kubeconfig: "/etc/kubeconfig",
|
|
kubeContext: "prod",
|
|
expectedFlags: []string{"--kubeconfig", "/etc/kubeconfig", "--kube-context", "prod", "--dry-run=server"},
|
|
unexpectedFlags: []string{},
|
|
},
|
|
{
|
|
name: "template command should not pass kubeconfig (offline command)",
|
|
helmfileCommand: "template",
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
kubeContext: "",
|
|
expectedFlags: []string{},
|
|
unexpectedFlags: []string{"--kubeconfig", "--dry-run=server"},
|
|
},
|
|
{
|
|
name: "build command should not pass kubeconfig (offline command)",
|
|
helmfileCommand: "build",
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
kubeContext: "",
|
|
expectedFlags: []string{},
|
|
unexpectedFlags: []string{"--kubeconfig", "--dry-run=server"},
|
|
},
|
|
{
|
|
name: "no kubeconfig should not add kubeconfig flag",
|
|
helmfileCommand: "sync",
|
|
kubeconfig: "",
|
|
kubeContext: "my-context",
|
|
expectedFlags: []string{"--kube-context", "my-context", "--dry-run=server"},
|
|
unexpectedFlags: []string{"--kubeconfig"},
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
st := &HelmState{kubeconfig: tt.kubeconfig}
|
|
got := st.buildChartifyTemplateArgs(tt.helmfileCommand, tt.kubeContext, false, "", "")
|
|
|
|
for _, flag := range tt.expectedFlags {
|
|
assert.Truef(t, strings.Contains(got, flag),
|
|
"buildChartifyTemplateArgs() = %q; want to contain %q", got, flag)
|
|
}
|
|
|
|
for _, flag := range tt.unexpectedFlags {
|
|
assert.Falsef(t, strings.Contains(got, flag),
|
|
"buildChartifyTemplateArgs() = %q; want NOT to contain %q", got, flag)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestKubeconfigNotDuplicated verifies that kubeconfig is not duplicated
|
|
// when it already exists in the template args.
|
|
func TestKubeconfigNotDuplicated(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
helmfileCommand string
|
|
kubeconfig string
|
|
existingArgs string
|
|
expectedCount int
|
|
expectedContains string
|
|
}{
|
|
{
|
|
name: "do not duplicate kubeconfig",
|
|
helmfileCommand: "sync",
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
existingArgs: "--kubeconfig /existing/kubeconfig",
|
|
expectedCount: 1,
|
|
expectedContains: "--kubeconfig /existing/kubeconfig",
|
|
},
|
|
{
|
|
name: "add kubeconfig when not present",
|
|
helmfileCommand: "sync",
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
existingArgs: "--some-flag",
|
|
expectedCount: 1,
|
|
expectedContains: "--kubeconfig /path/to/kubeconfig",
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
st := &HelmState{kubeconfig: tt.kubeconfig}
|
|
got := st.buildChartifyTemplateArgs(tt.helmfileCommand, "", false, "", tt.existingArgs)
|
|
|
|
assert.Truef(t, strings.Contains(got, tt.expectedContains),
|
|
"buildChartifyTemplateArgs() = %q; want to contain %q", got, tt.expectedContains)
|
|
|
|
assert.Equalf(t, tt.expectedCount, strings.Count(got, "--kubeconfig"),
|
|
"buildChartifyTemplateArgs() has --kubeconfig %d times; want %d", strings.Count(got, "--kubeconfig"), tt.expectedCount)
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestTemplateArgsDryRunTriggersKubeInjection verifies that when the user passes
|
|
// --template-args="--dry-run=server" to an offline command (e.g. `helmfile template`),
|
|
// the kubeconfig and kube-context ARE injected into chartify's internal helm template
|
|
// so lookup() can actually reach the cluster. Regression test for issue #1833.
|
|
func TestTemplateArgsDryRunTriggersKubeInjection(t *testing.T) {
|
|
st := &HelmState{kubeconfig: "/path/to/kubeconfig"}
|
|
|
|
got := st.buildChartifyTemplateArgs("template", "my-context", false, "--dry-run=server", "")
|
|
|
|
// User-provided arg is preserved
|
|
assert.Contains(t, got, "--dry-run=server")
|
|
// Cluster connection flags are injected even though "template" is offline
|
|
assert.Contains(t, got, "--kubeconfig /path/to/kubeconfig")
|
|
assert.Contains(t, got, "--kube-context my-context")
|
|
// --dry-run=server is NOT duplicated (only the user's copy is present)
|
|
assert.Equal(t, 1, strings.Count(got, "--dry-run"))
|
|
}
|
|
|
|
// TestTemplateArgsMergedBeforeInjection verifies that user-provided template args
|
|
// are merged into chartify's existing template args before the cluster-connectivity
|
|
// injection, so that duplicate --dry-run / --kubeconfig flags are deduplicated.
|
|
func TestTemplateArgsMergedBeforeInjection(t *testing.T) {
|
|
st := &HelmState{kubeconfig: "/path/to/kubeconfig"}
|
|
|
|
got := st.buildChartifyTemplateArgs(
|
|
"sync", "ctx", false,
|
|
"--dry-run=server", // user arg
|
|
"--enable-dns", // existing chartify arg
|
|
)
|
|
|
|
assert.Contains(t, got, "--enable-dns")
|
|
assert.Contains(t, got, "--dry-run=server")
|
|
// kubeconfig injected once, dry-run appears once (not duplicated)
|
|
assert.Equal(t, 1, strings.Count(got, "--dry-run"))
|
|
assert.Equal(t, 1, strings.Count(got, "--kubeconfig"))
|
|
}
|
|
|
|
// TestEffectiveTemplateArgs verifies CLI args take precedence over helmDefaults.templateArgs,
|
|
// mirroring the DiffArgs precedence (switch: CLI wins, else helmDefaults, else empty).
|
|
func TestEffectiveTemplateArgs(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
cliArgs string
|
|
helmDefaults []string
|
|
want string
|
|
}{
|
|
{
|
|
name: "CLI args win over helmDefaults",
|
|
cliArgs: "--dry-run=server",
|
|
helmDefaults: []string{"--enable-dns"},
|
|
want: "--dry-run=server",
|
|
},
|
|
{
|
|
name: "helmDefaults used when CLI empty",
|
|
cliArgs: "",
|
|
helmDefaults: []string{"--dry-run=server", "--enable-dns"},
|
|
want: "--dry-run=server --enable-dns",
|
|
},
|
|
{
|
|
name: "empty when neither set",
|
|
cliArgs: "",
|
|
want: "",
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
st := &HelmState{
|
|
ReleaseSetSpec: ReleaseSetSpec{
|
|
HelmDefaults: HelmSpec{TemplateArgs: tt.helmDefaults},
|
|
},
|
|
}
|
|
assert.Equal(t, tt.want, st.effectiveTemplateArgs(tt.cliArgs))
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestHelmDefaultsTemplateArgsReachesChartify is a belt-and-suspenders test for the
|
|
// composition used by processChartification: it resolves the effective template args
|
|
// (CLI vs helmDefaults) and feeds them to buildChartifyTemplateArgs. Verifies that
|
|
// setting helmDefaults.templateArgs=[--dry-run=server] makes an offline `template`
|
|
// command opt into server-side templating + kube-connection injection end-to-end.
|
|
func TestHelmDefaultsTemplateArgsReachesChartify(t *testing.T) {
|
|
st := &HelmState{
|
|
kubeconfig: "/path/to/kubeconfig",
|
|
ReleaseSetSpec: ReleaseSetSpec{
|
|
HelmDefaults: HelmSpec{TemplateArgs: []string{"--dry-run=server"}},
|
|
},
|
|
}
|
|
|
|
// Mirror processChartification's exact call shape.
|
|
resolved := st.effectiveTemplateArgs("")
|
|
got := st.buildChartifyTemplateArgs("template", "my-context", false, resolved, "")
|
|
|
|
// helmDefaults --dry-run=server is present
|
|
assert.Contains(t, got, "--dry-run=server")
|
|
// ...and triggered kube-connection injection for an otherwise-offline command
|
|
assert.Contains(t, got, "--kubeconfig /path/to/kubeconfig")
|
|
assert.Contains(t, got, "--kube-context my-context")
|
|
// not duplicated
|
|
assert.Equal(t, 1, strings.Count(got, "--dry-run"))
|
|
}
|