mirror of https://github.com/helm/helm
Motivation:
installCRDs() selected its CRD-establishment waiter using the
release's WaitStrategy. Under kube.HookOnlyStrategy, that waiter's
Wait() is a no-op by design, intended to skip waiting on general
chart resources such as Deployments. That no-op also silently
skipped the unrelated CRD establishment check, which exists so
custom resources depending on freshly-installed CRDs aren't
processed before the API server recognizes the new CRD types. Helm 3
performed this CRD establishment wait unconditionally, regardless of
the release's wait flag/strategy. Under HookOnlyStrategy this can
intermittently produce an install failure such as:
no matches for kind "ServiceMonitor" in version "monitoring.coreos.com/v1"
when a chart installs CRDs and dependent custom resources in the
same release, if the CRDs have not finished being established by the
time Helm processes the custom resources.
Approach:
In installCRDs(), compute a local crdWaitStrategy that substitutes
kube.StatusWatcherStrategy for the CRD-establishment wait only when
i.WaitStrategy is HookOnlyStrategy. i.WaitStrategy itself is left
untouched, so every other waiter-selection call site (the
general-resource wait later in Install.RunWithContext, and the
equivalents in rollback.go/upgrade.go) keeps HookOnlyStrategy's
existing no-op behavior for general resources. This mirrors the
promotion to StatusWatcherStrategy already used elsewhere in this
file for HookOnlyStrategy combined with RollbackOnFailure.
Validation:
- go build ./...
- go test ./pkg/action/... ./pkg/kube/...
- golangci-lint run ./pkg/action/... ./pkg/kube/... (0 issues)
- go vet ./pkg/action/... ./pkg/kube/... (clean)
- go mod tidy -diff (empty)
- make build && make test-coverage PKG="./pkg/action/... ./pkg/kube/..."
- Added TestInstallCRDs_HookOnlyStrategyStillWaitsForEstablishment, a
targeted unit test with a fake kube.Interface that mimics the real
no-op hookOnlyWaiter versus a genuine wait attempt. Verified via
git stash that this test fails on the pre-fix code ("An error is
expected but got nil") and passes after the fix.
This was validated at the unit level with a fake Kubernetes client,
not against a live cluster.
Report: https://github.com/helm/helm/issues/32671
Signed-off-by: Pujitha Paladugu <10557236+pujitha24@users.noreply.github.com>
Assisted-by: claude-sonnet-5 (via Claude Code)
pull/32672/head
parent
7fd3c5e8f2
commit
79784204ea
Loading…
Reference in new issue