Files
helmfile/pkg/plugins/vals_test.go
T
yxxhero 472e8c7a2d fix: error on missing secret key when using vals (#2496)
* fix: error on missing secret key when using vals

Add HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP environment variable
to control whether vals should fail when a referenced key does not
exist in the secret map.

Previously, when a secret reference like ref+vault://path#/nonexistent-key
pointed to a non-existent key, vals would silently return an empty string
without error. This could lead to deployments with missing configuration.

Default behavior remains backward compatible (returns empty string).
Set HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP=true to enable strict mode.

Fixes #1563

Signed-off-by: yxxhero <aiopsclub@163.com>

* refactor: extract buildValsOptions helper and improve tests

- Extract buildValsOptions() to make vals configuration testable
- Use t.Setenv instead of manual env save/restore in tests
- Test actual vals.Options output including FailOnMissingKeyInMap

Addresses PR review comments on #2496

Signed-off-by: yxxhero <aiopsclub@163.com>

* fix: use strconv.ParseBool and make tests hermetic

- Use strconv.ParseBool for FailOnMissingKeyInMap parsing to support
  common boolean values like 'TRUE', '1', '0', etc.
- Always set env vars explicitly in tests (even to empty string) to
  prevent flaky tests when env vars are set externally
- Add test cases for various boolean formats

Signed-off-by: yxxhero <aiopsclub@163.com>

* docs: add documentation for vals-related environment variables

Add documentation for:
- HELMFILE_AWS_SDK_LOG_LEVEL: configure AWS SDK logging for vals
- HELMFILE_VALS_FAIL_ON_MISSING_KEY_IN_MAP: enable strict mode for secret refs

Signed-off-by: yxxhero <aiopsclub@163.com>

* fix: improve error handling and case-insensitive comparison

- buildValsOptions now returns error for invalid boolean values
  instead of silently defaulting to false
- Use strings.EqualFold for case-insensitive 'off' comparison
  to handle OFF, Off, etc.
- Add test cases for invalid boolean and uppercase OFF
- Update docs to mention case-insensitive and error behavior

Signed-off-by: yxxhero <aiopsclub@163.com>

* fix: normalize log level and improve singleton initialization

- Normalize AWS log level 'off' to lowercase for true case-insensitivity
- Replace sync.Once with mutex to allow recovery from config errors
- Update tests to expect normalized 'off' value
- Update docs to clarify when error is raised

Signed-off-by: yxxhero <aiopsclub@163.com>

---------

Signed-off-by: yxxhero <aiopsclub@163.com>
2026-03-24 09:42:54 +08:00

259 lines
6.9 KiB
Go

package plugins
import (
"io"
"testing"
"github.com/helmfile/vals"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"github.com/helmfile/helmfile/pkg/envvar"
)
func TestValsInstance(t *testing.T) {
i, err := ValsInstance()
if err != nil {
t.Errorf("unexpected error: %v", err)
}
i2, _ := ValsInstance()
if i != i2 {
t.Error("Instances should be equal")
}
}
func TestBuildValsOptions(t *testing.T) {
tests := []struct {
name string
awsLogLevel string
failOnMissingKey string
expectedLogLevel string
expectedFailOnMissingKey bool
expectedLogOutputDiscarded bool
expectError bool
}{
{
name: "defaults",
awsLogLevel: "",
failOnMissingKey: "",
expectedLogLevel: "off",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: true,
},
{
name: "explicit failOnMissingKey true",
awsLogLevel: "",
failOnMissingKey: "true",
expectedLogLevel: "off",
expectedFailOnMissingKey: true,
expectedLogOutputDiscarded: true,
},
{
name: "failOnMissingKey false",
awsLogLevel: "",
failOnMissingKey: "false",
expectedLogLevel: "off",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: true,
},
{
name: "failOnMissingKey with whitespace",
awsLogLevel: "",
failOnMissingKey: " true ",
expectedLogLevel: "off",
expectedFailOnMissingKey: true,
expectedLogOutputDiscarded: true,
},
{
name: "failOnMissingKey uppercase TRUE",
awsLogLevel: "",
failOnMissingKey: "TRUE",
expectedLogLevel: "off",
expectedFailOnMissingKey: true,
expectedLogOutputDiscarded: true,
},
{
name: "failOnMissingKey numeric 1",
awsLogLevel: "",
failOnMissingKey: "1",
expectedLogLevel: "off",
expectedFailOnMissingKey: true,
expectedLogOutputDiscarded: true,
},
{
name: "failOnMissingKey numeric 0",
awsLogLevel: "",
failOnMissingKey: "0",
expectedLogLevel: "off",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: true,
},
{
name: "failOnMissingKey invalid value",
awsLogLevel: "",
failOnMissingKey: "invalid",
expectError: true,
},
{
name: "aws log level verbose",
awsLogLevel: "verbose",
failOnMissingKey: "",
expectedLogLevel: "verbose",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: false,
},
{
name: "aws log level with whitespace",
awsLogLevel: " minimal ",
failOnMissingKey: "",
expectedLogLevel: "minimal",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: false,
},
{
name: "aws log level OFF uppercase",
awsLogLevel: "OFF",
failOnMissingKey: "",
expectedLogLevel: "off",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: true,
},
{
name: "aws log level Off mixed case",
awsLogLevel: "Off",
failOnMissingKey: "",
expectedLogLevel: "off",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: true,
},
{
name: "aws log level Off mixed case",
awsLogLevel: "Off",
failOnMissingKey: "",
expectedLogLevel: "off",
expectedFailOnMissingKey: false,
expectedLogOutputDiscarded: true,
},
{
name: "both options set",
awsLogLevel: "standard",
failOnMissingKey: "true",
expectedLogLevel: "standard",
expectedFailOnMissingKey: true,
expectedLogOutputDiscarded: false,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
t.Setenv(envvar.AWSSDKLogLevel, tt.awsLogLevel)
t.Setenv(envvar.ValsFailOnMissingKeyInMap, tt.failOnMissingKey)
opts, err := buildValsOptions()
if tt.expectError {
require.Error(t, err)
assert.Contains(t, err.Error(), envvar.ValsFailOnMissingKeyInMap)
return
}
require.NoError(t, err)
assert.Equal(t, tt.expectedLogLevel, opts.AWSLogLevel)
assert.Equal(t, tt.expectedFailOnMissingKey, opts.FailOnMissingKeyInMap)
assert.Equal(t, valsCacheSize, opts.CacheSize)
isDiscarded := opts.LogOutput == io.Discard
assert.Equal(t, tt.expectedLogOutputDiscarded, isDiscarded)
})
}
}
func TestAWSSDKLogLevelConfiguration(t *testing.T) {
tests := []struct {
name string
envValue string
expectedLogLevel string
expectedLogOutput bool
}{
{
name: "no env var defaults to off",
envValue: "",
expectedLogLevel: "off",
expectedLogOutput: true,
},
{
name: "explicit off",
envValue: "off",
expectedLogLevel: "off",
expectedLogOutput: true,
},
{
name: "OFF uppercase",
envValue: "OFF",
expectedLogLevel: "off",
expectedLogOutput: true,
},
{
name: "minimal logging",
envValue: "minimal",
expectedLogLevel: "minimal",
expectedLogOutput: false,
},
{
name: "standard logging",
envValue: "standard",
expectedLogLevel: "standard",
expectedLogOutput: false,
},
{
name: "verbose logging",
envValue: "verbose",
expectedLogLevel: "verbose",
expectedLogOutput: false,
},
{
name: "custom logging",
envValue: "request,response",
expectedLogLevel: "request,response",
expectedLogOutput: false,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
t.Setenv(envvar.AWSSDKLogLevel, tt.envValue)
opts, err := buildValsOptions()
require.NoError(t, err)
assert.Equal(t, tt.expectedLogLevel, opts.AWSLogLevel)
isDiscarded := opts.LogOutput == io.Discard
assert.Equal(t, tt.expectedLogOutput, isDiscarded)
})
}
}
func TestBuildValsOptionsIntegration(t *testing.T) {
t.Run("valid configuration produces working vals options", func(t *testing.T) {
t.Setenv(envvar.AWSSDKLogLevel, "off")
t.Setenv(envvar.ValsFailOnMissingKeyInMap, "true")
opts, err := buildValsOptions()
require.NoError(t, err)
assert.Equal(t, valsCacheSize, opts.CacheSize)
assert.Equal(t, "off", opts.AWSLogLevel)
assert.True(t, opts.FailOnMissingKeyInMap)
assert.Equal(t, io.Discard, opts.LogOutput)
rt, err := vals.New(opts)
require.NoError(t, err)
assert.NotNil(t, rt)
})
}