renderResources returned *bytes.Buffer, but every caller only ever read
it — .String() in install/upgrade/tests, .Bytes() once in upgrade for
validateManifest (which takes []byte natively). Internally b was used
purely as an io.Writer (five fmt.Fprintf sites, no Grow/Reset/WriteTo).
The *bytes.Buffer type bought nothing on either side; it only forced a
dead "if manifestDoc != nil" guard in install (renderResources always
returned a non-nil buffer, so the guard was always true) and a
string->buffer round-trip (install did bytes.NewBufferString(rel.Manifest)
to feed KubeClient.Build, despite having just held the bytes).
Return []byte instead: b is a []byte written via fmt.Appendf, returns
stay "return hs, b, ...", callers take the bytes directly. install
passes bytes.NewReader(manifest) to Build (no round-trip) and upgrade
hands the slice straight to validateManifest.
Pure mechanical refactor, no behavior change. pkg/action and pkg/cmd
tests pass.
Signed-off-by: 胡玮文 <huweiwen.hww@alibaba-inc.com>