Documentation
¶
Index ¶
- func CompareSnapshots(ctx context.Context, before, after *Snapshot) (*diff.DiffResult, error)
- func PrintHelmReleases(hrs []HelmReleaseInfo, out io.Writer)
- func PrintKustomizations(ks []KustomizationInfo, out io.Writer)
- type DiffRunOptions
- type DiffRunResult
- type ExpansionError
- type GetResourcesOutput
- type HelmReleaseInfo
- type HelmReleaseItem
- type KustomizationInfo
- type KustomizationItem
- type NormalizationDiagnosis
- type NormalizationFinding
- type ObjectRef
- type Opt
- func WithClusterPaths(clusterPaths map[string][]string) Opt
- func WithCrossplane(configuration json.RawMessage) Opt
- func WithExcludeCRDs() Opt
- func WithFilterConfig(fc *filter.FilterConfig) Opt
- func WithFilterFile(f *os.File) Opt
- func WithFilterYAML(f string) Opt
- func WithFluxKS() Opt
- func WithGitRepo() Opt
- func WithHelm(settings *config.HelmSettings) Opt
- func WithHelmReleaseFilter(name string) Opt
- func WithLocalOnly() Opt
- func WithLogger(log logr.Logger) Opt
- func WithPaths(paths []string, recursive bool) Opt
- func WithPluginHost(host *pluginhost.Host) Opt
- func WithPlugins(commands []plugin.Command) Opt
- func WithSOPSDecrypt() Opt
- func WithSort() Opt
- func WithStrictInputs() Opt
- type Preview
- func (p *Preview) Close() error
- func (p *Preview) DetectPermadiffs(ctx context.Context, path string, out io.Writer) error
- func (p *Preview) DiagnoseNormalization(ctx context.Context, path string) (*NormalizationDiagnosis, error)
- func (p *Preview) Diff(ctx context.Context, a, b string, out io.Writer) error
- func (p *Preview) DiffResult(ctx context.Context, a, b string, out io.Writer) (result *diff.DiffResult, resultErr error)
- func (p *Preview) GenerateInitConfig(ctx context.Context, path, destPath string) error
- func (p *Preview) ListHelmReleases(ctx context.Context, path string) ([]HelmReleaseInfo, error)
- func (p *Preview) ListKustomizations(ctx context.Context, path string) ([]KustomizationInfo, error)
- func (p *Preview) Render(ctx context.Context, path string, out io.Writer) error
- func (p *Preview) RenderJSON(ctx context.Context, path string, out io.Writer) error
- func (p *Preview) RenderSnapshot(ctx context.Context, path string) (*Snapshot, error)
- func (p *Preview) RunDiff(ctx context.Context, opts DiffRunOptions) (run *DiffRunResult, runErr error)
- func (p *Preview) Test(ctx context.Context, path string, out io.Writer) error
- func (p *Preview) TestJSON(ctx context.Context, path string) (*TestResult, error)
- type Snapshot
- type TestIssue
- type TestResult
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CompareSnapshots ¶
CompareSnapshots compares complete inventories without rendering or mutating them. Cluster identity is retained even when resource IDs are identical across clusters.
func PrintHelmReleases ¶
func PrintHelmReleases(hrs []HelmReleaseInfo, out io.Writer)
PrintHelmReleases writes a table of HelmReleases to out.
func PrintKustomizations ¶
func PrintKustomizations(ks []KustomizationInfo, out io.Writer)
PrintKustomizations writes a table of Flux Kustomizations to out.
Types ¶
type DiffRunOptions ¶
type DiffRunOptions struct {
RetainSnapshots bool
LeftPath string
RightPath string
DiffWriter io.Writer
Policies *config.PolicyConfig
PolicyBaseDir string
AI *config.AIConfig
AIAssessor ai.Assessor
}
DiffRunOptions describes one complete rendered manifest diff run.
type DiffRunResult ¶
type DiffRunResult struct {
Before, After *Snapshot
Complete bool
Result *diff.DiffResult
Summary diff.ResultSummary
DiffText string
Warnings []string
PolicyResult *policy.Result
AIAssessment *ai.Assessment
}
DiffRunResult is the domain result used by CLI and GitHub Action adapters.
type ExpansionError ¶
ExpansionError is returned when one or more non-fatal errors were encountered during expansion (e.g. a HelmRelease whose chart could not be resolved). The render/diff output is still produced but may be incomplete.
func (*ExpansionError) Error ¶
func (e *ExpansionError) Error() string
type GetResourcesOutput ¶
type GetResourcesOutput struct {
Items any `json:"items"`
}
GetResourcesOutput is the JSON envelope for listing Flux resources.
func HelmReleasesToJSON ¶
func HelmReleasesToJSON(hrs []HelmReleaseInfo) *GetResourcesOutput
HelmReleasesToJSON converts HelmReleaseInfo slices to a JSON-serializable envelope.
func KustomizationsToJSON ¶
func KustomizationsToJSON(ks []KustomizationInfo) *GetResourcesOutput
KustomizationsToJSON converts KustomizationInfo slices to a JSON-serializable envelope.
type HelmReleaseInfo ¶
type HelmReleaseInfo struct {
Name string
Namespace string
Chart string
Version string
SourceKind string
SourceName string
}
HelmReleaseInfo holds extracted fields from a HelmRelease CR.
type HelmReleaseItem ¶
type HelmReleaseItem struct {
ObjectRef ObjectRef `json:"objectRef"`
Chart string `json:"chart,omitempty"`
Version string `json:"version,omitempty"`
SourceRef *ObjectRef `json:"sourceRef,omitempty"`
}
HelmReleaseItem is the JSON representation of a HelmRelease.
type KustomizationInfo ¶
type KustomizationInfo struct {
Name string
Namespace string
Path string
SourceKind string
SourceName string
}
KustomizationInfo holds extracted fields from a Flux Kustomization CR.
type KustomizationItem ¶
type KustomizationItem struct {
ObjectRef ObjectRef `json:"objectRef"`
Path string `json:"path,omitempty"`
SourceRef *ObjectRef `json:"sourceRef,omitempty"`
}
KustomizationItem is the JSON representation of a Flux Kustomization.
type NormalizationDiagnosis ¶
type NormalizationDiagnosis struct {
Findings []NormalizationFinding
}
func (NormalizationDiagnosis) FieldDiffs ¶
func (d NormalizationDiagnosis) FieldDiffs() []diff.FieldDiff
type NormalizationFinding ¶
type ObjectRef ¶
type ObjectRef struct {
APIVersion string `json:"apiVersion"`
Kind string `json:"kind"`
Name string `json:"name"`
Namespace string `json:"namespace,omitempty"`
}
ObjectRef mirrors the Kubernetes ObjectReference shape.
type Opt ¶
Opt is a functional option for configuring Preview.
func WithClusterPaths ¶
WithClusterPaths configures explicit per-cluster paths. This overrides any paths set via WithPaths.
func WithCrossplane ¶
func WithCrossplane(configuration json.RawMessage) Opt
WithCrossplane enables the Crossplane plugin with trusted runtime configuration. A nil configuration uses plugin defaults. Local-only restrictions still apply.
func WithExcludeCRDs ¶
func WithExcludeCRDs() Opt
WithExcludeCRDs strips CustomResourceDefinitions from rendered output.
func WithFilterConfig ¶
func WithFilterConfig(fc *filter.FilterConfig) Opt
WithFilterConfig configures filters from a parsed FilterConfig.
func WithFilterFile ¶
WithFilterFile configures filters from a YAML file.
func WithFilterYAML ¶
WithFilterYAML configures filters from a raw YAML string.
func WithFluxKS ¶
func WithFluxKS() Opt
WithFluxKS enables discovery of paths from Flux Kustomization resources in the Flux plugin. WithGitRepo enables acquisition of their external sources.
func WithGitRepo ¶
func WithGitRepo() Opt
WithGitRepo enables GitRepository acquisition in the Flux plugin.
func WithHelm ¶
func WithHelm(settings *config.HelmSettings) Opt
WithHelm enables Helm rendering with neutral settings. Empty settings use the Flux plugin's Helm environment defaults.
func WithHelmReleaseFilter ¶
WithHelmReleaseFilter filters diff output to only resources from the specified HelmRelease (matched by the helm.toolkit.fluxcd.io/name label).
func WithLocalOnly ¶
func WithLocalOnly() Opt
WithLocalOnly rejects remote acquisition and filesystem references outside the current source root and implies WithStrictInputs. This is not an OS sandbox. The bundled renderer enforces this policy; Kustomize execution plugins remain disabled.
func WithPaths ¶
WithPaths configures the paths to render and whether to recurse into subdirectories. If any path contains a cluster prefix (e.g. "kube:clusters/kube"), the preview switches to cluster mode automatically.
func WithPluginHost ¶
func WithPluginHost(host *pluginhost.Host) Opt
WithPluginHost borrows persistent processes from the caller. Each render still opens and closes fresh sessions, and Close never closes the borrowed host. The caller owns host shutdown and must keep it alive throughout rendering. Executable selection belongs to the host; WithPlugins and WithCrossplane cannot be combined with this option.
func WithPlugins ¶
WithPlugins selects executables from trusted invocation configuration. It replaces the default Flux command; it is never inferred from resource metadata.
func WithSOPSDecrypt ¶
func WithSOPSDecrypt() Opt
WithSOPSDecrypt enables decryption of SOPS-encrypted secrets before diffing or rendering. Requires access to the appropriate decryption keys.
func WithSort ¶
func WithSort() Opt
WithSort enables deterministic output sorting by (kind, namespace, name).
func WithStrictInputs ¶
func WithStrictInputs() Opt
WithStrictInputs rejects known unsupported Flux rendering inputs rather than silently omitting them. It does not restrict source acquisition or local paths.
type Preview ¶
type Preview struct {
// contains filtered or unexported fields
}
Preview renders and diffs Flux GitOps resources.
func (*Preview) Close ¶
Close releases owned plugin processes after rendering stops. Borrowed hosts remain alive until their owner closes them.
func (*Preview) DetectPermadiffs ¶
DetectPermadiffs renders the same path twice and compares the results to find non-deterministic output. It generates a filter config that can be used to normalize these fields in subsequent diff/render runs. Each render pass uses a fresh evaluation while reusing the plugin processes.
func (*Preview) DiagnoseNormalization ¶
func (p *Preview) DiagnoseNormalization(ctx context.Context, path string) (*NormalizationDiagnosis, error)
DiagnoseNormalization renders twice and returns non-deterministic fields with cluster context.
func (*Preview) Diff ¶
Diff computes and writes the diff between two repository paths. If a HelmRelease filter is set, only resources from that release are included.
func (*Preview) DiffResult ¶
func (p *Preview) DiffResult(ctx context.Context, a, b string, out io.Writer) (result *diff.DiffResult, resultErr error)
DiffResult computes and writes the diff between two repository paths, returning structured change metadata alongside the rendered diff text. An ExpansionError with only Warnings accompanies a complete comparison; expansion errors suppress all changes because either side may be incomplete.
func (*Preview) GenerateInitConfig ¶
GenerateInitConfig renders the repo twice to detect permadiffs and writes a complete .fmp.yaml config file to destPath.
func (*Preview) ListHelmReleases ¶
ListHelmReleases discovers and lists HelmReleases from the repo at path.
func (*Preview) ListKustomizations ¶
ListKustomizations discovers and lists Flux Kustomizations from the repo at path.
func (*Preview) RenderJSON ¶
RenderJSON renders the resources at path and writes JSON output.
func (*Preview) RenderSnapshot ¶
RenderSnapshot loads path and returns the exact inventory used for comparison. On failure the returned snapshot is incomplete and the error describes why.
func (*Preview) RunDiff ¶
func (p *Preview) RunDiff(ctx context.Context, opts DiffRunOptions) (run *DiffRunResult, runErr error)
RunDiff renders both sides, computes the rendered manifest diff, and applies policy checks. Incomplete renders return an error and a result with Complete=false, diagnostics, no authoritative changes, and no policy or AI assessment.
type Snapshot ¶
type Snapshot struct {
Clusters map[string]*render.Render
// Logical preserves unnamed composed resources without adding invented names
// to the named Kubernetes inventory.
Logical map[string][]plugin.Resource
Evidence map[string][]json.RawMessage
Complete bool
Warnings []string
}
Snapshot is a detached render inventory, keyed by cluster ("" for unclustered input). Incomplete snapshots must not be used to infer additions or deletions.
type TestIssue ¶
type TestIssue struct {
Message string `json:"message"`
}
TestIssue describes a single warning or error encountered during testing.
type TestResult ¶
type TestResult struct {
Status string `json:"status"`
Warnings []TestIssue `json:"warnings,omitempty"`
Errors []TestIssue `json:"errors,omitempty"`
}
TestResult is the JSON representation of a test run.