Files
helmfile/cmd
Dominik Schmidtandyxxhero 443cef0dc1 feat: dir= selector for path-based release filtering and traversal skip (#2609)
* feat: add dir= selector for path-based release filtering and traversal skip

Introduce a new selector key `dir=<path>` to the -l/--selector flag with two
effects: it filters releases by the directory of their defining helmfile
relative to the root helmfile (using directory-prefix matching, so
dir=apps/foo matches both apps/foo and apps/foo/sub), and it short-circuits
sub-helmfile traversal when paired with positive dir= constraints, so
non-matching branches in the helmfiles: tree are not parsed, templated, or
fetched.

The motivation is consuming aggregator-style upstreams that the operator
does not control (opendesk being the immediate example), where the user
cannot restructure the helmfile layout but still wants to act on a subset.

The dir label is auto-populated at filter time only; user-facing label
output is unchanged. The label key "dir" is reserved at state load.
Selectors that escape the root via .. or absolute paths, and the bare ".",
are rejected at parse time.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* refactor: use sync.Once for root dir resolution, extract skipForDirFilter

Add a unit test covering the per-entry skip decision: match descends,
sibling skipped, remote never short-circuited.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* cmd: shorten dir selector help text, link to docs

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* docs: highlight selectors inheritance caveat, add bases example for dir label

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* feat: warn instead of fail on user-defined dir label

Hard-failing on an existing dir label is a breaking change. Log a
deprecation warning for now and turn it into an error in a later release.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* refactor: apply go fix modernizers to dir selector code

Upstream CI now fails when go fix would rewrite code. Use maps.Copy in
injectLabel and drop the explicit embedded ReleaseSetSpec in test
literals.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* fix: tighten dir selector edge cases found in review

- Always shadow a user-defined dir label at match time, also when the
  release has no auto-populated value (remote or outside-root helmfiles).
  Previously the user value was matched there despite the warning.
- Skip sibling helmfiles entries that are directories, not only files.
- Warn about a dir label declared in a release template, and warn only
  once when it comes from a bases file.
- Share the root-relative path and at-or-below checks between the release
  filter and the traversal skip; a directory whose name merely starts with
  two dots is no longer treated as escaping the root.
- Log when the root directory cannot be resolved.
- Tests: require for setup steps, t.Chdir, shared app fixture.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* docs: sync dir selector CLI help, document anchor and traversal assumption

docs/cli.md still carried the long help text. Also spell out what the dir
value is relative to, that the traversal skip assumes nested helmfiles
stay below their parent's directory, and that user-defined dir labels are
ignored for releases without an auto-populated value as well.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* fix: complete dir selector values relative to the root helmfile

Completion listed directories relative to the working directory, while
dir values are relative to the root helmfile directory. Resolve the root
from -f or HELMFILE_FILE_PATH with the same logic the app uses, and offer
nothing for values the selector would reject (absolute paths, paths that
escape the root) or for a remote root helmfile.

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>

* refactor(state): flatten nested conditionals in label filter parsing and matching

- LabelFilter.Match: extract labelMatches helper; positive/negative loops
  become single-level guards. Also removes the pre-existing empty
  then-branch (if !ok {} else if) in the negative-label loop and the
  redundant len()>0 guards around the loops
- positiveLabelsCompatibleWith: extract positiveLabelPairCompatible so the
  double loop holds one guard instead of a nested if chain
- ParseLabels: extract parseOneLabel (separator detection, dir= value
  validation, split) so the three-level regex/dir/error nesting becomes
  flat; drop the vestigial trailing 'var err error' return

No behavior change; state/app/cmd tests incl. -race and golangci-lint pass.

Signed-off-by: yxxhero <aiopsclub@163.com>

---------

Signed-off-by: Dominik Schmidt <dev@dominik-schmidt.de>
Signed-off-by: yxxhero <aiopsclub@163.com>
Co-authored-by: yxxhero <aiopsclub@163.com>
2026-10-06 08:21:35 +08:00
..
2026-10-04 08:49:05 +08:00
…
…
…
…
…
…
…
…
2026-10-04 08:49:05 +08:00
…