mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 18:48:12 +02:00
* chore: bump helm release pins * chore: align helm module metadata * chore: finalize helm patch bumps * fix: add --plain-http flag for Helm 3.21+ OCI push in tests Helm 3.21.1 introduced stricter security checks that reject HTTP scheme downgrades when pushing to OCI registries, with the error: "blob upload Location downgrades scheme from https" Previously only Helm 4 required --plain-http for HTTP-only OCI registries. Now Helm 3.21+ also requires this flag. Add a new requiresPlainHTTPForOCI() helper that returns true for both Helm 4.x and Helm 3.21+, and use it in execHelmPush() instead of isHelm4(). * fix: safe fallback in requiresPlainHTTPForOCI when version detection fails Default to true (require --plain-http) when helm version detection fails, since any Helm version that supports helm push also supports the --plain-http flag. This avoids the inconsistent HELMFILE_HELM4 env var fallback which only covered Helm 4. * fix: update snapshot tests for Helm 4.2.1 OCI pull output Helm 4.2.1 now outputs additional 'Pulled:' and 'Digest: sha256:...' lines after each OCI chart pull. The SHA256 digest is non-deterministic because helm packages include build timestamps, so normalize it with a regex placeholder. - Add ociDigestRegex to normalize non-deterministic OCI digest values - Create output-helm4.yaml for 5 tests that lacked Helm 4 snapshots - Update output-helm4.yaml for oci_need and postrenderer to include the new Pulled/Digest lines from Helm dependency pull operations * fix: update ociDigestRegex to match empty digest in Helm 4.2.1 OCI pull output Helm 4.2.1 outputs "Digest: sha256:" (empty hash) when pulling OCI charts. The regex required at least one hex char ([0-9a-f]+), so it did not match and the digest was not normalized to $DIGEST in snapshot tests. Also fix the replacement string: Go regex ReplaceAllString interprets $DIGEST as a capture group reference (resolving to empty). Use $$DIGEST to produce a literal $DIGEST in the output. Signed-off-by: yxxhero <aiopsclub@163.com> --------- Signed-off-by: yxxhero <aiopsclub@163.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: yxxhero <aiopsclub@163.com>
69 lines
2.6 KiB
Makefile
69 lines
2.6 KiB
Makefile
HELM_VERSION ?= v4.2.1
|
|
KUSTOMIZE_VERSION ?= v5.8.0
|
|
K8S_VERSION ?= v1.34.0
|
|
MINIKUBE_VERSION ?= v1.37.0
|
|
SOPS_VERSION ?= v3.10.2
|
|
|
|
# ---
|
|
CHANGE_MINIKUBE_NONE_USER ?= true
|
|
MINIKUBE_WANTUPDATENOTIFICATION ?= false
|
|
MINIKUBE_WANTREPORTERRORPROMPT ?= false
|
|
|
|
VAULT_ADDR := http://127.0.0.1:8200
|
|
VAULT_TOKEN := toor
|
|
|
|
tmp := $(shell mktemp -d)
|
|
HELM_FILENAME := helm-${HELM_VERSION}-linux-amd64.tar.gz
|
|
KUSTOMIZE_FILENAME := kustomize_${KUSTOMIZE_VERSION}_linux_amd64.tar.gz
|
|
|
|
|
|
all: vault sops helm kustomize minikube/destroy minikube
|
|
|
|
helm:
|
|
curl -sSLo $(tmp)/${HELM_FILENAME} "https://get.helm.sh/${HELM_FILENAME}"
|
|
tar zxf $(tmp)/${HELM_FILENAME} --directory ${tmp} linux-amd64/helm
|
|
chmod +x ${tmp}/linux-amd64/helm
|
|
sudo mv ${tmp}/linux-amd64/helm /usr/local/bin/
|
|
.PHONY: helm
|
|
|
|
kustomize:
|
|
curl -sSLo $(tmp)/${KUSTOMIZE_FILENAME} "https://github.com/kubernetes-sigs/kustomize/releases/download/kustomize%2F${KUSTOMIZE_VERSION}/${KUSTOMIZE_FILENAME}"
|
|
tar zxf $(tmp)/${KUSTOMIZE_FILENAME} --directory ${tmp} kustomize
|
|
chmod +x ${tmp}/kustomize
|
|
sudo mv ${tmp}/kustomize /usr/local/bin/
|
|
.PHONY: kustomize
|
|
|
|
minikube/destroy:
|
|
sudo -E minikube delete || true
|
|
sudo -E rm -rf /etc/kubernetes || true
|
|
sudo -E rm -rf $$HOME/.minikube/* || true
|
|
.PHONY: minikube/destroy
|
|
.EXPORT_ALL_VARIABLES: minikube/destroy
|
|
|
|
minikube:
|
|
curl -sSLo ${tmp}/kubectl https://dl.k8s.io/release/${K8S_VERSION}/bin/linux/amd64/kubectl
|
|
chmod +x ${tmp}/kubectl && sudo mv ${tmp}/kubectl /usr/local/bin/
|
|
curl -sSLo ${tmp}/minikube https://storage.googleapis.com/minikube/releases/${MINIKUBE_VERSION}/minikube-linux-amd64
|
|
chmod +x ${tmp}/minikube && sudo mv ${tmp}/minikube /usr/local/bin/
|
|
sudo -E minikube delete || true
|
|
sudo -E rm -rf /etc/kubernetes || true
|
|
sudo -E rm -rf $$HOME/.minikube/* || true
|
|
sudo -E minikube start --vm-driver=none --kubernetes-version=${K8S_VERSION}
|
|
sudo -E minikube update-context
|
|
kubectl wait node/minikube --for=condition=Ready
|
|
.PHONY: minikube
|
|
.EXPORT_ALL_VARIABLES: minikube
|
|
|
|
vault:
|
|
docker kill $$(docker ps -a --filter "name=vault" -q) || true
|
|
docker run -d -p8200:8200 --rm --name vault vault:1.2.0 server -dev -dev-root-token-id=toor
|
|
docker run --rm --network="host" --cap-add IPC_LOCK -e VAULT_ADDR=$$VAULT_ADDR -e VAULT_TOKEN=$$VAULT_TOKEN vault:1.2.0 secrets enable -path=sops transit
|
|
docker run --rm --network="host" --cap-add IPC_LOCK -e VAULT_ADDR=$$VAULT_ADDR -e VAULT_TOKEN=$$VAULT_TOKEN vault:1.2.0 write sops/keys/key type=rsa-4096
|
|
.PHONY: vault
|
|
|
|
sops:
|
|
curl -sSLo $(tmp)/sops "https://github.com/getsops/sops/releases/download/${SOPS_VERSION}/sops-${SOPS_VERSION}.linux.amd64"
|
|
chmod +x $(tmp)/sops
|
|
sudo mv ${tmp}/sops /usr/local/bin/
|
|
.PHONY: sops
|