Skip to content

fix: ClusterPromotion: react to referenced ConfigMap/Secret changes - #2012

Merged
gianlucam76 merged 1 commit into
projectsveltos:mainfrom
gianlucam76:clusterpromotion
Sep 30, 2026
Merged

gianlucam76 merged 1 commit into
projectsveltos:mainfrom
gianlucam76:clusterpromotion

Conversation

@gianlucam76

Copy link
Copy Markdown
Member

ClusterPromotion now watches the ConfigMaps and Secrets referenced by its ProfileSpec (policyRefs, kustomizationRefs, valuesFrom, patchesFrom).

Each stage ClusterProfile references the same ConfigMap/Secret, so editing it was deployed right away to every stage, bypassing the promotion pipeline (including manual approval). Sveltos ClusterPromotion implementation now creates a copy of each referenced resource per stage and hashes the referenced content. For that to work, the controller must be told when a referenced resource changes.

  • ClusterPromotionReconciler keeps a ReferenceMap (referenced ConfigMap/Secret to the set of ClusterPromotions using it), updated on every reconcile and cleaned on deletion, the same way ClusterSummaryReconciler does it. The ConfigMap/Secret watch only reads the map, so no event is lost to a failed List.
  • RBAC: create/update on ConfigMaps and create/update/delete on Secrets, needed to create and clean up the per-stage copies.
  • Unit test for the reference map.
  • fv test (label Enterprise): a two stage ClusterPromotion referencing a ConfigMap gets deployed, then the ConfigMap is changed and the promotion starts over, updating each stage copy in order.

ClusterPromotion now watches the ConfigMaps and Secrets referenced by its
ProfileSpec (policyRefs, kustomizationRefs, valuesFrom, patchesFrom).

Each stage ClusterProfile references the same ConfigMap/Secret, so editing
it was deployed right away to every stage, bypassing the promotion pipeline
(including manual approval). Sveltos ClusterPromotion implementation now
creates a copy of each referenced resource per stage and hashes the
referenced content. For that to work, the controller must be told
when a referenced resource changes.

- ClusterPromotionReconciler keeps a ReferenceMap (referenced ConfigMap/Secret
  to the set of ClusterPromotions using it), updated on every reconcile and
  cleaned on deletion, the same way ClusterSummaryReconciler does it. The
  ConfigMap/Secret watch only reads the map, so no event is lost to a failed
  List.
- RBAC: create/update on ConfigMaps and create/update/delete on Secrets, needed
  to create and clean up the per-stage copies.
- Unit test for the reference map.
- fv test (label Enterprise): a two stage ClusterPromotion referencing a
  ConfigMap gets deployed, then the ConfigMap is changed and the promotion
  starts over, updating each stage copy in order.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gianlucam76
gianlucam76 merged commit 5c1f019 into projectsveltos:main Sep 30, 2026
12 checks passed
@gianlucam76
gianlucam76 deleted the clusterpromotion branch September 30, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant