Repository navigation
fix: ClusterPromotion: react to referenced ConfigMap/Secret changes - #2012
Merged
Merged
Conversation
ClusterPromotion now watches the ConfigMaps and Secrets referenced by its ProfileSpec (policyRefs, kustomizationRefs, valuesFrom, patchesFrom). Each stage ClusterProfile references the same ConfigMap/Secret, so editing it was deployed right away to every stage, bypassing the promotion pipeline (including manual approval). Sveltos ClusterPromotion implementation now creates a copy of each referenced resource per stage and hashes the referenced content. For that to work, the controller must be told when a referenced resource changes. - ClusterPromotionReconciler keeps a ReferenceMap (referenced ConfigMap/Secret to the set of ClusterPromotions using it), updated on every reconcile and cleaned on deletion, the same way ClusterSummaryReconciler does it. The ConfigMap/Secret watch only reads the map, so no event is lost to a failed List. - RBAC: create/update on ConfigMaps and create/update/delete on Secrets, needed to create and clean up the per-stage copies. - Unit test for the reference map. - fv test (label Enterprise): a two stage ClusterPromotion referencing a ConfigMap gets deployed, then the ConfigMap is changed and the promotion starts over, updating each stage copy in order. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ClusterPromotion now watches the ConfigMaps and Secrets referenced by its ProfileSpec (policyRefs, kustomizationRefs, valuesFrom, patchesFrom).
Each stage ClusterProfile references the same ConfigMap/Secret, so editing it was deployed right away to every stage, bypassing the promotion pipeline (including manual approval). Sveltos ClusterPromotion implementation now creates a copy of each referenced resource per stage and hashes the referenced content. For that to work, the controller must be told when a referenced resource changes.