client

package
v5.3.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 23 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// SourceKindHelmRepository uses spec.chart with a HelmRepository sourceRef.
	SourceKindHelmRepository = helmrelease.SourceKindHelmRepository
	// SourceKindOCIRepository uses spec.chartRef with an OCIRepository reference.
	SourceKindOCIRepository = helmrelease.SourceKindOCIRepository

	// DefaultGiantSwarmHelmRepositoryURL is the default OCI registry for Giant Swarm Helm charts.
	DefaultGiantSwarmHelmRepositoryURL = helmrelease.DefaultRegistryURL
)
View Source
const (
	// ValuesPriorityDefault is the slot an ordinary config layer lands in, the same default
	// app-operator gives an App CR's extraConfigs.
	ValuesPriorityDefault = 25
	// ValuesPriorityUserConfig is the slot the suite's own values file lands in. It is the
	// highest of the standard slots, so a suite's values win over everything merged for it.
	ValuesPriorityUserConfig = 100
)

Values priorities, mirroring the slots app-operator gives an App CR's config layers. They only order the sources relative to each other; the numbers themselves are never sent to the cluster.

Variables

This section is empty.

Functions

func DeleteHelmRelease

func DeleteHelmRelease(ctx context.Context, name, namespace string) error

DeleteHelmRelease deletes a HelmRelease CR and its associated values Secret if present.

func DeleteHelmSource

func DeleteHelmSource(ctx context.Context, cfg HelmReleaseConfig) error

DeleteHelmSource deletes the source CR (HelmRepository or OCIRepository) backing the HelmRelease. InstallHelmRelease always ensures the source, also when SourceURL is empty and the default registry URL is used, so it is always cleaned up here. Leaving it behind pins the next run to this run's chart version, as an existing source is never updated.

func FailureDiagnostics added in v5.3.0

func FailureDiagnostics(format string, args ...any) func() string

FailureDiagnostics returns a Gomega failure description that dumps the state of everything involved in getting an app running before the assertion reports the given message.

A timed-out wait otherwise says only that something never became ready, while the reason (`values-schema-violation`, an image that cannot be pulled, a chart that fails to render) sits in the resource's conditions, its events or a pod's logs. It matters more than it looks on the Flux path: a default app's HelmRelease is created with `remediation.retries: -1`, so a failing upgrade retries forever and nothing but a bounded wait will ever end the suite.

Every kind is dumped regardless of how the app was installed, because a suite asserts on whichever of the two the owner happened to render.

func FailureDiagnosticsIn added in v5.3.0

func FailureDiagnosticsIn(namespace string, format string, args ...any) func() string

FailureDiagnosticsIn is FailureDiagnostics for a wait that polls a namespace of its own.

clustertest's HelmRelease handler reports on the cluster's org namespace, which is where a suite's resources live by default. A suite that sets its own install namespace puts the HelmRelease somewhere else, so that namespace is dumped in place of the org one: the org namespace would describe resources that have nothing to do with the failure while saying nothing about the release that timed out.

The App CR and pod handlers still run either way. An App CR only ever lives in the org namespace, and the pods are the workload itself, so neither follows the HelmRelease.

func InstallApp

func InstallApp(ctx context.Context, app *application.Application)

InstallApp installs the given App then waits for it to be marked as installed. Timeout can be controlled via the provided context

func InstallHelmRelease

func InstallHelmRelease(ctx context.Context, cfg HelmReleaseConfig)

InstallHelmRelease creates a HelmRelease CR and waits for it to become ready. It ensures the HelmRelease namespace exists on the MC. Target and storage namespaces are created by Flux via spec.install.createNamespace. Timeout can be controlled via the provided context.

func IsAllHelmReleasesReady added in v5.2.0

func IsAllHelmReleasesReady(ctx context.Context, c cr.Client, helmReleases []types.NamespacedName) func() (bool, error)

IsAllHelmReleasesReady returns a check function for use with Gomega's Eventually that polls the given list of HelmReleases and returns true once all of them have a Ready=True condition. Its signature mirrors wait.IsAllAppDeployed so call-sites can use either one interchangeably. Every HelmRelease is checked and logged on each poll, so a stuck release is visible.

func IsHelmReleaseReady

func IsHelmReleaseReady(ctx context.Context, name, namespace string) (bool, error)

IsHelmReleaseReady checks if a HelmRelease has the Ready condition set to True. The current status is logged on each call, mirroring the App CR wait conditions. A HelmRelease that doesn't exist yet is not an error, it is simply not ready.

func IsHelmReleaseVersion

func IsHelmReleaseVersion(ctx context.Context, name, namespace, version string) (bool, error)

IsHelmReleaseVersion checks whether the chart version a HelmRelease has actually deployed matches the expected one. A HelmRelease that doesn't exist yet is not an error, it is simply not at the expected version.

func UpdateHelmReleaseValues added in v5.3.0

func UpdateHelmReleaseValues(ctx context.Context, name, namespace, values string) error

UpdateHelmReleaseValues rewrites spec.values on an existing HelmRelease.

Writing the spec bumps metadata.generation, so helm-controller picks the change up straight away. A values Secret referenced through valuesFrom would not: helm-controller does not watch those, so the new values would only land on the next reconcile interval, if at all.

func UpdateHelmReleaseVersion

func UpdateHelmReleaseVersion(ctx context.Context, cfg HelmReleaseConfig, version string)

UpdateHelmReleaseVersion updates the chart version for an existing HelmRelease. For HelmRepository sources, it updates spec.chart.spec.version on the HelmRelease. For OCIRepository sources, it updates spec.ref.tag on the OCIRepository (sourced from cfg).

func WaitForHelmReleaseChildrenDeleted added in v5.3.2

func WaitForHelmReleaseChildrenDeleted(ctx context.Context, name, namespace string) error

WaitForHelmReleaseChildrenDeleted blocks until every HelmRelease and App CR the named HelmRelease installed into its own namespace is gone, or the context expires.

This matters for a HelmRelease installed in-cluster on the MC that itself renders apps for a workload cluster, such as an app bundle. Uninstalling it deletes those children, but each one holds a finalizer until its own uninstall has reached the workload cluster through the cluster's kubeconfig secret. Tearing the cluster down before then leaves the finalizers unable to run and the organization namespace stuck terminating.

func WaitForHelmReleaseDeleted added in v5.3.0

func WaitForHelmReleaseDeleted(ctx context.Context, name, namespace string) error

WaitForHelmReleaseDeleted blocks until the named HelmRelease is gone from the API, or the context expires.

Deleting a HelmRelease only starts the uninstall: helm-controller holds a finalizer until it has run, and anything the release created is still in place until then.

Types

type HelmReleaseConfig

type HelmReleaseConfig struct {
	// Name is the name of the HelmRelease resource.
	Name string
	// Namespace is the namespace where the HelmRelease CR will be created.
	Namespace string
	// TargetNamespace is the namespace where the Helm chart will be installed.
	TargetNamespace string
	// StorageNamespace is the namespace used for Helm storage.
	// If empty, defaults to the HelmRelease namespace.
	StorageNamespace string
	// ReleaseName is the Helm release name. If empty, defaults to the HelmRelease name.
	ReleaseName string
	// ChartName is the name of the chart in the source.
	ChartName string
	// ChartVersion is the version of the chart to install.
	ChartVersion string
	// SourceKind specifies the kind of source reference.
	// Defaults to SourceKindOCIRepository if not set.
	SourceKind SourceKind
	// SourceName is the name of the source reference (HelmRepository or OCIRepository).
	SourceName string
	// SourceNamespace is the namespace of the source reference.
	// If empty, defaults to the HelmRelease namespace.
	SourceNamespace string
	// SourceURL is the URL of the source to create.
	// For SourceKindHelmRepository: an OCI URL ("oci://registry/path") or HTTPS URL.
	// For SourceKindOCIRepository: an OCI URL ("oci://registry/path/chart").
	// If empty, the Giant Swarm registry is used. The framework creates the source CR
	// before installing the HelmRelease either way.
	SourceURL string
	// Values is the raw values YAML to pass to the chart. It is written to a Secret the
	// HelmRelease references in the user config slot, unless InlineValues is set.
	Values string
	// ValuesFrom are additional values sources merged ahead of Values, in App platform order
	// rather than in the order they are given. See ValuesSource.
	ValuesFrom []ValuesSource
	// Interval is the reconciliation interval. Defaults to 5m.
	Interval time.Duration
	// Timeout is the time to wait for Helm operations. Defaults to 5m.
	Timeout time.Duration
	// Retries is the number of retries for install/upgrade remediation. Defaults to 10.
	Retries *int
	// ServiceAccountName is the Kubernetes service account to impersonate when reconciling.
	// Required by clusters with the flux-multi-tenancy Kyverno policy.
	ServiceAccountName string
	// KubeConfigSecretName is the name of the secret containing kubeconfig for remote cluster access.
	// Required when deploying to a workload cluster from the management cluster.
	KubeConfigSecretName string
	// InCluster installs the chart into the cluster the HelmRelease itself lives in, under the
	// impersonated ServiceAccountName and with no kubeConfig. The target namespace is not
	// created by Helm in this case: an impersonated service account is scoped to a namespace
	// that already exists, and Helm's --create-namespace only tolerates AlreadyExists, not the
	// Forbidden it would get back.
	InCluster bool
	// InlineValues writes Values to spec.values instead of to a referenced Secret.
	// helm-controller does not watch valuesFrom sources, so only an inline change reconciles
	// immediately. Use it whenever the values themselves are what a test step changes.
	InlineValues bool
}

HelmReleaseConfig holds the configuration needed to create a HelmRelease CR.

type SourceKind

type SourceKind = helmrelease.SourceKind

SourceKind represents the kind of source reference used by a HelmRelease.

type ValuesSource added in v5.3.0

type ValuesSource struct {
	// Kind is "ConfigMap" or "Secret".
	Kind string
	// Name of the ConfigMap or Secret, which has to live in the HelmRelease's namespace.
	Name string
	// ValuesKey is the data key the values are read from. Defaults to Flux's own default,
	// `values.yaml`. App platform config maps use `values`.
	ValuesKey string
	// Optional tolerates the source not existing. Any other error still fails the release.
	Optional bool
	// Priority orders this source against the others: higher wins. Defaults to
	// ValuesPriorityDefault.
	Priority int
}

ValuesSource is one entry of a HelmRelease's spec.valuesFrom.

Flux merges valuesFrom entries in the order they appear, so the order is what decides which layer wins. It is expressed as a priority here instead, because a caller knows which slot a layer belongs in but not what else is being merged alongside it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL