Files
helmfile/pkg/agent/doctor/config_test.go
T
yxxhero 9b943adc9e feat: add helmfile doctor command for AI-assisted diff analysis (#2660)
* feat: add `helmfile doctor` command for AI-assisted diff analysis

`helmfile doctor` runs `helmfile diff` and asks an OpenAI-compatible LLM to
summarize the changes and flag risks (data loss, security exposure, breaking
changes, downtime, performance, best-practice issues).

Key design decisions:
- When no LLM is configured, doctor is equivalent to `helmfile diff` with
  one exception: --show-secrets is always forced off (secrets never reach
  stdout, even without an LLM).
- Secrets are ALWAYS redacted via two layers: (1) ShowSecrets() forced to
  false so helm-diff emits <REDACTED> placeholders; (2) a defense-in-depth
  text redactor strips residual secret-looking content (Secret YAML blocks,
  sensitive key/value lines, base64 blobs, JWT tokens) before LLM transmission.
- LLM configuration precedence: env (HELMFILE_LLM_*) < helmfile.yaml (llm:)
  < CLI flags (--llm-*).
- Supports any OpenAI-compatible backend (OpenAI, Azure, One-API, LiteLLM,
  Ollama, etc.) with automatic response_format fallback for backends that
  don't support JSON mode.
- Prompt injection defense: release names and environment values are
  JSON-encoded before insertion into the LLM prompt.
- Exit codes: 0 (success/low-risk), 2 (high-risk gate, bypass with --force),
  1 (other errors). Helm-diff's 'detected changes' exit-2 is swallowed.

New packages:
- pkg/agent/llm: OpenAI-compatible client with JSON response parsing, mock
  client for testing, prompt builder with injection defense.
- pkg/agent/doctor: secret redactor (state machine + regex), report renderer
  (markdown + JSON), config resolver (env < yaml < flag merge).

Testing: 70+ unit tests covering redaction patterns, prompt injection,
response_format fallback, JSON parsing, yaml roundtrip, concurrency safety,
panic recovery, and error propagation. go test -race passes.

Documentation: full doctor section in docs/cli.md, llm: block reference in
docs/configuration.md, updated skills/helmfile for AI agents.

Signed-off-by: yxxhero <aiopsclub@163.com>

* docs: fix doctor equivalence wording per PR review

Per review feedback (PR #2660): the docs claimed doctor is 'equivalent to
helmfile diff — same flags, same output, same exit codes' in the unconfigured
path, but this over-promises because:

  1. doctor --output is the report format (not helm-diff's output format)
  2. helm-diff's --output is exposed as --diff-output in doctor
  3. --show-secrets is silently ignored

Updated all three locations (cli.md, cmd/doctor.go Long + godoc, pkg/app/doctor.go
godoc) to say 'falls back to helmfile diff with --show-secrets forced off' and
explicitly note the --output / --diff-output flag difference.

Signed-off-by: yxxhero <aiopsclub@163.com>

---------

Signed-off-by: yxxhero <aiopsclub@163.com>
2026-06-22 16:52:35 +08:00

102 lines
2.8 KiB
Go

package doctor
import (
"testing"
"time"
"github.com/helmfile/helmfile/pkg/agent/llm"
)
func TestEnvConfig_ReadsEnvVars(t *testing.T) {
t.Setenv("HELMFILE_LLM_BASE_URL", "https://env.example/v1")
t.Setenv("HELMFILE_LLM_API_KEY", "envkey")
t.Setenv("HELMFILE_LLM_MODEL", "envmodel")
t.Setenv("HELMFILE_LLM_TIMEOUT", "90s")
t.Setenv("HELMFILE_LLM_MAX_TOKENS", "2048")
cfg := EnvConfig()
if cfg.BaseURL != "https://env.example/v1" {
t.Errorf("BaseURL = %q", cfg.BaseURL)
}
if cfg.APIKey != "envkey" {
t.Errorf("APIKey = %q", cfg.APIKey)
}
if cfg.Model != "envmodel" {
t.Errorf("Model = %q", cfg.Model)
}
if cfg.Timeout != 90*time.Second {
t.Errorf("Timeout = %v", cfg.Timeout)
}
if cfg.MaxTokens != 2048 {
t.Errorf("MaxTokens = %d", cfg.MaxTokens)
}
}
// TestEnvConfig_NoEnvReturnsEmpty uses t.Setenv with empty values rather than
// os.Unsetenv. t.Setenv automatically restores the prior value via t.Cleanup,
// so it is safe under `go test -parallel` and never leaks state to other
// tests in the same process. Empty string is observationally equivalent to
// an unset variable for os.Getenv callers.
func TestEnvConfig_NoEnvReturnsEmpty(t *testing.T) {
t.Setenv("HELMFILE_LLM_BASE_URL", "")
t.Setenv("HELMFILE_LLM_API_KEY", "")
t.Setenv("HELMFILE_LLM_MODEL", "")
t.Setenv("HELMFILE_LLM_TIMEOUT", "")
t.Setenv("HELMFILE_LLM_MAX_TOKENS", "")
cfg := EnvConfig()
if cfg.IsConfigured() {
t.Errorf("EnvConfig should be empty when no env vars set, got %+v", cfg)
}
}
func TestEnvConfig_IgnoresBogusTimeout(t *testing.T) {
t.Setenv("HELMFILE_LLM_TIMEOUT", "not-a-duration")
t.Setenv("HELMFILE_LLM_MAX_TOKENS", "not-a-number")
cfg := EnvConfig()
if cfg.Timeout != 0 {
t.Errorf("Timeout should be 0 on parse error, got %v", cfg.Timeout)
}
if cfg.MaxTokens != 0 {
t.Errorf("MaxTokens should be 0 on parse error, got %v", cfg.MaxTokens)
}
}
func TestResolveConfig_PreservesLayerPrecedence(t *testing.T) {
env := llm.Config{
BaseURL: "https://env.example",
APIKey: "envkey",
Model: "envmodel",
}
yaml := llm.Config{
BaseURL: "https://yaml.example",
MaxTokens: 1024,
}
flag := llm.Config{
Model: "flagmodel",
MaxTokens: 8192,
}
got := ResolveConfig(env, yaml, flag)
if got.BaseURL != "https://yaml.example" {
t.Errorf("BaseURL = %q, want yaml to override env", got.BaseURL)
}
if got.APIKey != "envkey" {
t.Errorf("APIKey = %q, want env value (no override)", got.APIKey)
}
if got.Model != "flagmodel" {
t.Errorf("Model = %q, want flag value", got.Model)
}
if got.MaxTokens != 8192 {
t.Errorf("MaxTokens = %d, want flag to override yaml", got.MaxTokens)
}
}
func TestResolveConfig_AllEmptyStaysEmpty(t *testing.T) {
got := ResolveConfig(llm.Config{}, llm.Config{}, llm.Config{})
if got.IsConfigured() {
t.Errorf("all-empty resolve should be unconfigured, got %+v", got)
}
}