Documentation
¶
Overview ¶
Package objectset finds rendered objects that share one Kubernetes apply identity, so a runtime can refuse the render instead of letting the last write silently overwrite the first.
Two objects with the same API group, kind, namespace and name reach apply as two writes to one object, whatever version of the group each names. Nothing in the kernel notices: kernel.Compiled deliberately carries no platform vocabulary, and Render never reads kind or metadata. This package supplies the missing check in the one place that has both the objects and their provenance, without moving Kubernetes vocabulary into the kernel.
Duplicates takes the render's compiled objects and returns every identity two or more of them share, each row naming the identity and every producing component and transformer in render order. It reads exactly four fields off each value — apiVersion, kind, metadata.namespace, metadata.name — and validates nothing else. A value with no kind or no metadata.name is not a Kubernetes object: it is skipped, never refused, because a frontend that requires manifests already fails at conversion with a better message. DuplicateIdentitiesError turns the rows into the refusal itself, worded once so every runtime says the same thing.
The kernel never calls this package, and a depguard rule in .golangci.yml keeps it that way; a frontend that applies to something other than Kubernetes may skip it entirely. A runtime that does apply to Kubernetes calls it between render and apply, on the []*kernel.Compiled the kernel returned and before any wrapping that would lose the provenance fields: the CLI in its render workflow, so build refuses what apply would, and the operator before it builds inventory entries.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Duplicate ¶
Duplicate is one apply identity that two or more rendered objects share, with every producer of it in render order. Identity is the first-rendered object's, its APIVersion verbatim.
func Duplicates ¶
Duplicates scans a render's compiled objects and returns every apply identity two or more of them share, in the order each identity was first rendered. Two objects share an apply identity when their API group (the part of apiVersion before the first "/", empty for the core group and for an object with no apiVersion), kind, namespace and name match; the version does not distinguish them, because the API server serves one object under every version of its group. A value carrying no kind or no metadata.name is not a Kubernetes object and is skipped; nothing else about the objects is validated. A render whose objects all have distinct identities returns no rows.
type DuplicateIdentitiesError ¶
type DuplicateIdentitiesError struct {
Duplicates []Duplicate
}
DuplicateIdentitiesError is the refusal a runtime raises from the rows Duplicates returned, before apply. The kernel never returns it: it is raised by the frontend that calls the helper.
func (*DuplicateIdentitiesError) Error ¶
func (e *DuplicateIdentitiesError) Error() string
Error names each shared identity once, on its own line, with every component and transformer that produced it, so one wording serves every runtime that applies to Kubernetes. When a row's producers rendered the object under different apiVersions, each producer is followed by its own version, so the reader sees the mismatch that made them one object.
type Identity ¶
Identity names a rendered object by its apiVersion, kind, namespace and name. Namespace is empty for a cluster-scoped object, or for one that names no namespace. A Kubernetes apply addresses an object by group, kind, namespace and name, so two identities that differ only in the version part of APIVersion address one object; Duplicates matches them on the group.