Files
helmfile/pkg/state/issue_2355_test.go
T
yxxhero e3f757d5ed feat: add --template-args flag to template/apply/sync for helm lookup() support (#2666)
* feat: add --template-args to enable helm lookup() during template/apply/sync (#1833)

Add a --template-args flag to the template, apply, and sync subcommands so
extra args (most notably --dry-run=server) can be passed to the helm template
invocation, enabling Helm's lookup() function to resolve live cluster values.

- template: --template-args reaches both chartify's pre-render helm template
  and the final helm template output (flagsForTemplate).
- apply/sync: --template-args reaches chartify's pre-render helm template.
  apply/sync already inject --dry-run=server automatically for cluster
  operations; the flag is an explicit opt-in for the template subcommand or
  for passing additional flags.
- When --dry-run is present in template args, kube-context/kubeconfig are also
  injected into chartify so lookup() can actually reach the cluster.
- Resolves the long-stale PR #1833 rebased onto current main, which already
  contains the cluster-connectivity infrastructure (issues #2271, #2309,
  #2355, #2444).
- Includes integration test (lookup.sh) covering both chartify and
  non-chartify scenarios.

Signed-off-by: yxxhero <aiopsclub@163.com>

* test: make lookup template nil-safe to fix integration CI

The lookup() function returns an empty map when the chart is rendered
without a cluster connection (notably the helm-diff phase of `helmfile
apply`). The original fixture chained `index` over the lookup result,
panicking with "index of untyped nil" during apply's diff rendering.

Guard every index with `default dict` so the template falls back to
"overwritten" when lookup is empty, while still resolving to the live
value ("init") when cluster access is available (--dry-run=server via
--template-args, or a real helm upgrade).

Signed-off-by: yxxhero <aiopsclub@163.com>

* feat: enable lookup() during apply/diff via --template-args in helm-diff

Thread --template-args into the helm-diff rendering path so that
`helmfile apply`/`diff --template-args="--dry-run=server"` resolves
Helm's lookup() function during the diff phase too. helm-diff supports
`--dry-run=server`, which explicitly "enables the cluster access ...
and the lookup template function".

Previously --template-args only reached chartify's pre-render (which is a
no-op for plain charts due to chartify's early-return when there is no
forceNamespace/patches/injections) and the final `helm template` of the
`template` subcommand. As a result `helmfile apply` on a lookup chart
rendered client-side during the diff phase.

Changes:
- pkg/state: add TemplateArgs to DiffOpts; append it in appendExtraDiffFlags
  (reaches every helm-diff invocation: apply, standalone diff, interactive
  sync), mirroring the existing flagsForTemplate handling.
- pkg/config + cmd: add --template-args to the diff/doctor commands and to
  DiffConfigProvider, so lookup works for `helmfile diff` as well.
- pkg/app: populate DiffOpts.TemplateArgs from apply/diff/sync-interactive.
- docs/cli.md: correct the previous overpromising wording and document diff
  support plus the nil-safe lookup guidance.
- tests: unit-test the TemplateArgs handling in appendExtraDiffFlags and
  flagsForTemplate; integration lookup.sh now exercises apply with
  --template-args="--dry-run=server".

Signed-off-by: yxxhero <aiopsclub@163.com>

* refactor: de-duplicate chartify template-args logic, add helmDefaults.templateArgs

Address review feedback on #2666:

1. Eliminate stale duplicated test helpers (issue_2444_test.go, issue_2355_test.go).
   Both files intentionally copied the processChartification flag-building logic
   with explicit SYNC WARNING comments, then drifted out of sync when #2666
   refactored the production code (needsKubeConnection gate, user-args merge).
   Extract the real logic into pure, unit-tested helpers
   (buildChartifyTemplateArgs, commandRequiresCluster) and delete the copies.

2. Add unit coverage for the new chartify merge path: template +
   --template-args=--dry-run=server now triggers kubeconfig/kube-context
   injection (TestTemplateArgsDryRunTriggersKubeInjection,
   TestTemplateArgsMergedBeforeInjection) — previously only covered by the
   cluster-dependent integration test.

3. Add a negative integration case (lookup.sh assert_template_fallback)
   verifying lookup() falls back to the default value WITHOUT --template-args,
   guarding against a regression that silently always connects to the cluster.

4. Add helmDefaults.templateArgs for parity with diffArgs/syncArgs, so users
   can enable lookup() support permanently instead of passing the flag on every
   invocation. CLI --template-args overrides (does not merge with) the default.
   Resolved via effectiveTemplateArgs, wired into the chartify, flagsForTemplate,
   and appendExtraDiffFlags paths.

5. Minor: capitalize --template-args help text to match surrounding flags;
   document helmDefaults.templateArgs precedence in docs/cli.md.

Signed-off-by: yxxhero <aiopsclub@163.com>

* test: cover helmDefaults->chartify composition; fix helm helm-diff typo

Address remaining review nits on #2666:

- Add TestHelmDefaultsTemplateArgsReachesChartify, a belt-and-suspenders test
  for the processChartification composition (effectiveTemplateArgs ->
  buildChartifyTemplateArgs), closing the last unit-level coverage gap for
  helmDefaults.templateArgs reaching the chartify path.

- Fix pre-existing typo in cmd/bind_diff_flags.go: 'pass args to helm helm-diff'
  -> 'Pass args to helm-diff' (doubled 'helm', lowercase).

Signed-off-by: yxxhero <aiopsclub@163.com>

* fix: correct 'helm helm-diff' typo in apply --diff-args help text

Sibling of the bind_diff_flags.go fix; the same doubled-'helm' typo and
lowercase help existed in cmd/apply.go's --diff-args registration, leaving
the apply and diff/doctor help strings inconsistent.

Signed-off-by: yxxhero <aiopsclub@163.com>

* docs: add helmDefaults.templateArgs to configuration reference

The complete helmfile.yaml schema in docs/configuration.md documents
diffArgs and syncArgs under helmDefaults but was missing the new
templateArgs field added in #2666. Add it beside syncArgs for
discoverability, noting the --template-args CLI override.

Signed-off-by: yxxhero <aiopsclub@163.com>

---------

Signed-off-by: yxxhero <aiopsclub@163.com>
2026-06-28 12:19:33 +08:00

138 lines
5.1 KiB
Go

package state
import (
"strings"
"testing"
"github.com/stretchr/testify/assert"
)
// TestValidateAndDryRunMutualExclusion verifies that when --validate is set,
// --dry-run=server is NOT added to TemplateArgs in Helm 4 compatibility.
// This is a regression test for issue #2355.
//
// Background: In Helm 4, the --validate and --dry-run flags are mutually exclusive.
// When helmfile uses kustomize/chartify, it was adding --dry-run=server for cluster-
// requiring commands (like diff, apply) to support the lookup() function. However,
// if --validate is already set, we should NOT add --dry-run=server because:
// 1. They are mutually exclusive in Helm 4
// 2. --validate already provides server-side validation
//
// These tests exercise the real HelmState.buildChartifyTemplateArgs method (the pure
// helper that processChartification delegates to), not a duplicated copy of the logic.
func TestValidateAndDryRunMutualExclusion(t *testing.T) {
tests := []struct {
name string
helmfileCommand string
validate bool
expectedDryRun bool // Should --dry-run=server be added?
}{
// Cluster-requiring commands without --validate should get --dry-run=server
{"diff without validate", "diff", false, true},
{"apply without validate", "apply", false, true},
{"sync without validate", "sync", false, true},
{"destroy without validate", "destroy", false, true},
{"delete without validate", "delete", false, true},
{"test without validate", "test", false, true},
{"status without validate", "status", false, true},
// Cluster-requiring commands WITH --validate should NOT get --dry-run=server
// This is the fix for issue #2355
{"diff with validate", "diff", true, false},
{"apply with validate", "apply", true, false},
{"sync with validate", "sync", true, false},
{"destroy with validate", "destroy", true, false},
{"delete with validate", "delete", true, false},
{"test with validate", "test", true, false},
{"status with validate", "status", true, false},
// Non-cluster commands should never get --dry-run=server
{"template without validate", "template", false, false},
{"template with validate", "template", true, false},
{"lint without validate", "lint", false, false},
{"lint with validate", "lint", true, false},
{"build without validate", "build", false, false},
{"build with validate", "build", true, false},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
st := &HelmState{}
got := st.buildChartifyTemplateArgs(tt.helmfileCommand, "", tt.validate, "", "")
hasDryRun := strings.Contains(got, "--dry-run=server")
assert.Equalf(t, tt.expectedDryRun, hasDryRun,
"buildChartifyTemplateArgs(%q, validate=%v) = %q, hasDryRun=%v; want hasDryRun=%v",
tt.helmfileCommand, tt.validate, got, hasDryRun, tt.expectedDryRun)
})
}
}
// TestDryRunServerWithExistingTemplateArgs verifies that --dry-run=server is
// appended correctly when there are existing template args, and is not duplicated
// when a --dry-run variant is already present.
func TestDryRunServerWithExistingTemplateArgs(t *testing.T) {
tests := []struct {
name string
helmfileCommand string
validate bool
userArgs string
existingArgs string
expectedContains string
shouldHaveDryRun bool
}{
{
name: "append to existing args when validate is false",
helmfileCommand: "diff",
validate: false,
existingArgs: "--some-flag",
expectedContains: "--some-flag",
shouldHaveDryRun: true,
},
{
name: "do not append when validate is true",
helmfileCommand: "diff",
validate: true,
existingArgs: "--some-flag",
expectedContains: "--some-flag",
shouldHaveDryRun: false,
},
{
name: "do not duplicate if dry-run already exists in existing args",
helmfileCommand: "diff",
validate: false,
existingArgs: "--dry-run=client",
expectedContains: "--dry-run=client",
shouldHaveDryRun: false, // Already has --dry-run, should not add server
},
{
name: "do not duplicate if dry-run provided via user template args",
helmfileCommand: "diff",
validate: false,
userArgs: "--dry-run=server",
expectedContains: "--dry-run=server",
shouldHaveDryRun: true, // present once, not duplicated
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
st := &HelmState{}
got := st.buildChartifyTemplateArgs(tt.helmfileCommand, "", tt.validate, tt.userArgs, tt.existingArgs)
if tt.expectedContains != "" {
assert.Containsf(t, got, tt.expectedContains,
"buildChartifyTemplateArgs() = %q; want to contain %q", got, tt.expectedContains)
}
hasDryRunServer := strings.Contains(got, "--dry-run=server")
assert.Equalf(t, tt.shouldHaveDryRun, hasDryRunServer,
"buildChartifyTemplateArgs() = %q; hasDryRunServer=%v, want %v", got, hasDryRunServer, tt.shouldHaveDryRun)
// --dry-run=server should never appear more than once.
assert.LessOrEqualf(t, strings.Count(got, "--dry-run=server"), 1,
"buildChartifyTemplateArgs() = %q; --dry-run=server duplicated", got)
})
}
}