mirror of https://github.com/helm/helm
Motivation:
annotateAndMerge (used by helm template's post-render pipeline) parses each
rendered manifest with kyaml, adds a postrenderer.helm.sh/postrender-filename
annotation, and re-serializes all manifests into one merged YAML stream that
is piped to the post-renderer. When a chart resource is written as pure
JSON, kyaml preserves the original flow style ({...}) when re-emitting the
document, but the newly added annotation is inserted using plain YAML syntax
(unquoted key, single-quoted value). The result starts with '{' but is not
valid JSON. k8s.io/apimachinery/pkg/runtime/serializer/yaml's decoder
assumes anything starting with '{' is pure JSON, so a Go post-renderer using
that decoder fails to parse the resource, even though the same manifest
parses fine without a post-renderer. This worked in Helm 3.
Approach:
Clear the flow-style flag recursively on every manifest node before merging,
so annotateAndMerge always emits unambiguous block-style YAML regardless of
whether the source file was JSON or YAML. This also normalizes manifests
that intentionally use flow-style YAML (e.g. metadata: {name: foo}) to block
style when piped through a post-renderer; the resulting YAML is valid and
semantically identical, only its formatting changes. This is a byproduct of
how SetAnnotation can insert block-style content under any ancestor in the
tree, so any flow-style ancestor (not just the document root) could
reproduce the same class of bug.
Validation:
- Added TestAnnotateAndMerge_JSONManifest_DecodableByApimachinery, which
reproduces the issue's exact repro: builds a JSON chart resource, runs it
through annotateAndMerge, and decodes the result with
k8s.io/apimachinery/pkg/runtime/serializer/yaml's
NewDecodingSerializer(unstructured.UnstructuredJSONScheme), the exact
decoder from the report. Verified this test fails on the pre-fix code with
"invalid character 'a' looking for beginning of object key string" and
passes after the fix.
- Added a JSON-manifest case to the existing table-driven TestAnnotateAndMerge.
- go test ./pkg/action/... (all pass)
- go build ./pkg/action/...
- go vet ./pkg/action/...
- golangci-lint run ./pkg/action/... (0 issues)
- make build
- go mod tidy -diff (no diff)
- make test-source-headers
Report: https://github.com/helm/helm/issues/32668
Signed-off-by: Pujitha Paladugu <10557236+pujitha24@users.noreply.github.com>
Assisted-by: claude-sonnet-5 (via Claude Code)
pull/32669/head
parent
7fd3c5e8f2
commit
d5724cf75f
Loading…
Reference in new issue