From 676ca581f197a2913624f637f066be74d49e6b97 Mon Sep 17 00:00:00 2001 From: wallyatgithub <30530146+wallyatgithub@users.noreply.github.com> Date: Mon, 13 Oct 2025 14:38:59 +0800 Subject: [PATCH] deepcopy original before upgradeClientSideFieldManager, as original and target share the same object, and calling Get() on original will change target, and cause target patch data to carry unwanted data loaded from live resource Signed-off-by: wallyatgithub <30530146+wallyatgithub@users.noreply.github.com> --- pkg/kube/client.go | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkg/kube/client.go b/pkg/kube/client.go index 30c014ad5..8a5189d71 100644 --- a/pkg/kube/client.go +++ b/pkg/kube/client.go @@ -736,7 +736,10 @@ func (c *Client) Update(originals, targets ResourceList, options ...ClientUpdate slog.String("gvk", target.Mapping.GroupVersionKind.String())) if updateOptions.upgradeClientSideFieldManager { - patched, err := upgradeClientSideFieldManager(original, updateOptions.dryRun, updateOptions.fieldValidationDirective) + // target and original shares same Object, deep copy original to avoid changing target + copiedOriginal := *original + copiedOriginal.Object = original.Object.DeepCopyObject() + patched, err := upgradeClientSideFieldManager(&copiedOriginal, updateOptions.dryRun, updateOptions.fieldValidationDirective) if err != nil { slog.Debug("Error patching resource to replace CSA field management", slog.Any("error", err)) return err