mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 13:16:12 +02:00
* fix: error on missing secret key when using vals Add HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP environment variable to control whether vals should fail when a referenced key does not exist in the secret map. Previously, when a secret reference like ref+vault://path#/nonexistent-key pointed to a non-existent key, vals would silently return an empty string without error. This could lead to deployments with missing configuration. Default behavior remains backward compatible (returns empty string). Set HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP=true to enable strict mode. Fixes #1563 Signed-off-by: yxxhero <aiopsclub@163.com> * refactor: extract buildValsOptions helper and improve tests - Extract buildValsOptions() to make vals configuration testable - Use t.Setenv instead of manual env save/restore in tests - Test actual vals.Options output including FailOnMissingKeyInMap Addresses PR review comments on #2496 Signed-off-by: yxxhero <aiopsclub@163.com> * fix: use strconv.ParseBool and make tests hermetic - Use strconv.ParseBool for FailOnMissingKeyInMap parsing to support common boolean values like 'TRUE', '1', '0', etc. - Always set env vars explicitly in tests (even to empty string) to prevent flaky tests when env vars are set externally - Add test cases for various boolean formats Signed-off-by: yxxhero <aiopsclub@163.com> * docs: add documentation for vals-related environment variables Add documentation for: - HELMFILE_AWS_SDK_LOG_LEVEL: configure AWS SDK logging for vals - HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP: enable strict mode for secret refs Signed-off-by: yxxhero <aiopsclub@163.com> * fix: improve error handling and case-insensitive comparison - buildValsOptions now returns error for invalid boolean values instead of silently defaulting to false - Use strings.EqualFold for case-insensitive 'off' comparison to handle OFF, Off, etc. - Add test cases for invalid boolean and uppercase OFF - Update docs to mention case-insensitive and error behavior Signed-off-by: yxxhero <aiopsclub@163.com> * fix: normalize log level and improve singleton initialization - Normalize AWS log level 'off' to lowercase for true case-insensitivity - Replace sync.Once with mutex to allow recovery from config errors - Update tests to expect normalized 'off' value - Update docs to clarify when error is raised Signed-off-by: yxxhero <aiopsclub@163.com> --------- Signed-off-by: yxxhero <aiopsclub@163.com>
38 lines
1.9 KiB
Go
38 lines
1.9 KiB
Go
package envvar
|
|
|
|
const (
|
|
DisableInsecureFeatures = "HELMFILE_DISABLE_INSECURE_FEATURES"
|
|
|
|
// use helm status to check if a release exists before installing it
|
|
UseHelmStatusToCheckReleaseExistence = "HELMFILE_USE_HELM_STATUS_TO_CHECK_RELEASE_EXISTENCE"
|
|
|
|
DisableRunnerUniqueID = "HELMFILE_DISABLE_RUNNER_UNIQUE_ID"
|
|
Experimental = "HELMFILE_EXPERIMENTAL" // environment variable for experimental features, expecting "true" lower case
|
|
Environment = "HELMFILE_ENVIRONMENT"
|
|
FilePath = "HELMFILE_FILE_PATH"
|
|
TempDir = "HELMFILE_TEMPDIR"
|
|
UpgradeNoticeDisabled = "HELMFILE_UPGRADE_NOTICE_DISABLED"
|
|
GoYamlV3 = "HELMFILE_GO_YAML_V3"
|
|
CacheHome = "HELMFILE_CACHE_HOME"
|
|
Interactive = "HELMFILE_INTERACTIVE"
|
|
RenderYaml = "HELMFILE_RENDER_YAML" // force helmfile.yaml to be rendered as template regardless of extension, expecting "true" lower case
|
|
|
|
// AWSSDKLogLevel controls AWS SDK logging level
|
|
// Valid values: "off" (default), "minimal", "standard", "verbose", or custom (e.g., "request,response")
|
|
// - "off": No AWS SDK logging (secure default, prevents credential leakage)
|
|
// - "minimal": Log retries only
|
|
// - "standard": Log retries and requests (previous default behavior)
|
|
// - "verbose": Log everything (requests, responses, bodies, signing)
|
|
// - Custom: Comma-separated AWS SDK log modes
|
|
// This is passed to vals Options.AWSLogLevel
|
|
// Can be overridden by AWS_SDK_GO_LOG_LEVEL environment variable
|
|
// See issue #2270 and vals PR #893
|
|
AWSSDKLogLevel = "HELMFILE_AWS_SDK_LOG_LEVEL"
|
|
|
|
// ValsFailOnMissingKeyInMap controls whether vals should fail when a key is missing in a map.
|
|
// When set to "true", vals returns an error if a referenced key does not exist in the secret map.
|
|
// Default is false for backward compatibility (returns empty string for missing keys).
|
|
// See issue #1563
|
|
ValsFailOnMissingKeyInMap = "HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP"
|
|
)
|