preview

package
v0.2.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: GPL-3.0 Imports: 28 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CompareSnapshots

func CompareSnapshots(ctx context.Context, before, after *Snapshot) (*diff.DiffResult, error)

CompareSnapshots compares complete inventories without rendering or mutating them. Cluster identity is retained even when resource IDs are identical across clusters.

func PrintHelmReleases

func PrintHelmReleases(hrs []HelmReleaseInfo, out io.Writer)

PrintHelmReleases writes a table of HelmReleases to out.

func PrintKustomizations

func PrintKustomizations(ks []KustomizationInfo, out io.Writer)

PrintKustomizations writes a table of Flux Kustomizations to out.

Types

type DiffRunOptions

type DiffRunOptions struct {
	RetainSnapshots bool
	LeftPath        string
	RightPath       string
	DiffWriter      io.Writer
	Policies        *config.PolicyConfig
	PolicyBaseDir   string
	AI              *config.AIConfig
	AIAssessor      ai.Assessor
}

DiffRunOptions describes one complete rendered manifest diff run.

type DiffRunResult

type DiffRunResult struct {
	Before, After *Snapshot
	Complete      bool
	Result        *diff.DiffResult
	Summary       diff.ResultSummary
	DiffText      string
	Warnings      []string
	PolicyResult  *policy.Result
	AIAssessment  *ai.Assessment
}

DiffRunResult is the domain result used by CLI and GitHub Action adapters.

type ExpansionError

type ExpansionError struct {
	Errors   []error
	Warnings []error
}

ExpansionError is returned when one or more non-fatal errors were encountered during expansion (e.g. a HelmRelease whose chart could not be resolved). The render/diff output is still produced but may be incomplete.

func (*ExpansionError) Error

func (e *ExpansionError) Error() string

type GetResourcesOutput

type GetResourcesOutput struct {
	Items any `json:"items"`
}

GetResourcesOutput is the JSON envelope for listing Flux resources.

func HelmReleasesToJSON

func HelmReleasesToJSON(hrs []HelmReleaseInfo) *GetResourcesOutput

HelmReleasesToJSON converts HelmReleaseInfo slices to a JSON-serializable envelope.

func KustomizationsToJSON

func KustomizationsToJSON(ks []KustomizationInfo) *GetResourcesOutput

KustomizationsToJSON converts KustomizationInfo slices to a JSON-serializable envelope.

type HelmReleaseInfo

type HelmReleaseInfo struct {
	Name       string
	Namespace  string
	Chart      string
	Version    string
	SourceKind string
	SourceName string
}

HelmReleaseInfo holds extracted fields from a HelmRelease CR.

type HelmReleaseItem

type HelmReleaseItem struct {
	ObjectRef ObjectRef  `json:"objectRef"`
	Chart     string     `json:"chart,omitempty"`
	Version   string     `json:"version,omitempty"`
	SourceRef *ObjectRef `json:"sourceRef,omitempty"`
}

HelmReleaseItem is the JSON representation of a HelmRelease.

type KustomizationInfo

type KustomizationInfo struct {
	Name       string
	Namespace  string
	Path       string
	SourceKind string
	SourceName string
}

KustomizationInfo holds extracted fields from a Flux Kustomization CR.

type KustomizationItem

type KustomizationItem struct {
	ObjectRef ObjectRef  `json:"objectRef"`
	Path      string     `json:"path,omitempty"`
	SourceRef *ObjectRef `json:"sourceRef,omitempty"`
}

KustomizationItem is the JSON representation of a Flux Kustomization.

type NormalizationDiagnosis

type NormalizationDiagnosis struct {
	Findings []NormalizationFinding
}

func (NormalizationDiagnosis) FieldDiffs

func (d NormalizationDiagnosis) FieldDiffs() []diff.FieldDiff

type NormalizationFinding

type NormalizationFinding struct {
	Cluster string
	Diff    diff.FieldDiff
}

type ObjectRef

type ObjectRef struct {
	APIVersion string `json:"apiVersion"`
	Kind       string `json:"kind"`
	Name       string `json:"name"`
	Namespace  string `json:"namespace,omitempty"`
}

ObjectRef mirrors the Kubernetes ObjectReference shape.

type Opt

type Opt func(p *Preview) error

Opt is a functional option for configuring Preview.

func WithClusterPaths

func WithClusterPaths(clusterPaths map[string][]string) Opt

WithClusterPaths configures explicit per-cluster paths. This overrides any paths set via WithPaths.

func WithCrossplane

func WithCrossplane(configuration json.RawMessage) Opt

WithCrossplane enables the Crossplane plugin with trusted runtime configuration. A nil configuration uses plugin defaults. Local-only restrictions still apply.

func WithExcludeCRDs

func WithExcludeCRDs() Opt

WithExcludeCRDs strips CustomResourceDefinitions from rendered output.

func WithFilterConfig

func WithFilterConfig(fc *filter.FilterConfig) Opt

WithFilterConfig configures filters from a parsed FilterConfig.

func WithFilterFile

func WithFilterFile(f *os.File) Opt

WithFilterFile configures filters from a YAML file.

func WithFilterYAML

func WithFilterYAML(f string) Opt

WithFilterYAML configures filters from a raw YAML string.

func WithFluxKS

func WithFluxKS() Opt

WithFluxKS enables discovery of paths from Flux Kustomization resources in the Flux plugin. WithGitRepo enables acquisition of their external sources.

func WithGitRepo

func WithGitRepo() Opt

WithGitRepo enables GitRepository acquisition in the Flux plugin.

func WithHelm

func WithHelm(settings *config.HelmSettings) Opt

WithHelm enables Helm rendering with neutral settings. Empty settings use the Flux plugin's Helm environment defaults.

func WithHelmReleaseFilter

func WithHelmReleaseFilter(name string) Opt

WithHelmReleaseFilter filters diff output to only resources from the specified HelmRelease (matched by the helm.toolkit.fluxcd.io/name label).

func WithLocalOnly

func WithLocalOnly() Opt

WithLocalOnly rejects remote acquisition and filesystem references outside the current source root and implies WithStrictInputs. This is not an OS sandbox. The bundled renderer enforces this policy; Kustomize execution plugins remain disabled.

func WithLogger

func WithLogger(log logr.Logger) Opt

WithLogger sets the logger for the Preview.

func WithPaths

func WithPaths(paths []string, recursive bool) Opt

WithPaths configures the paths to render and whether to recurse into subdirectories. If any path contains a cluster prefix (e.g. "kube:clusters/kube"), the preview switches to cluster mode automatically.

func WithPluginHost

func WithPluginHost(host *pluginhost.Host) Opt

WithPluginHost borrows persistent processes from the caller. Each render still opens and closes fresh sessions, and Close never closes the borrowed host. The caller owns host shutdown and must keep it alive throughout rendering. Executable selection belongs to the host; WithPlugins and WithCrossplane cannot be combined with this option.

func WithPlugins

func WithPlugins(commands []plugin.Command) Opt

WithPlugins selects executables from trusted invocation configuration. It replaces the default Flux command; it is never inferred from resource metadata.

func WithSOPSDecrypt

func WithSOPSDecrypt() Opt

WithSOPSDecrypt enables decryption of SOPS-encrypted secrets before diffing or rendering. Requires access to the appropriate decryption keys.

func WithSort

func WithSort() Opt

WithSort enables deterministic output sorting by (kind, namespace, name).

func WithStrictInputs

func WithStrictInputs() Opt

WithStrictInputs rejects known unsupported Flux rendering inputs rather than silently omitting them. It does not restrict source acquisition or local paths.

type Preview

type Preview struct {
	// contains filtered or unexported fields
}

Preview renders and diffs Flux GitOps resources.

func New

func New(opts ...Opt) (*Preview, error)

New creates a new Preview with the given options.

func (*Preview) Close

func (p *Preview) Close() error

Close releases owned plugin processes after rendering stops. Borrowed hosts remain alive until their owner closes them.

func (*Preview) DetectPermadiffs

func (p *Preview) DetectPermadiffs(ctx context.Context, path string, out io.Writer) error

DetectPermadiffs renders the same path twice and compares the results to find non-deterministic output. It generates a filter config that can be used to normalize these fields in subsequent diff/render runs. Each render pass uses a fresh evaluation while reusing the plugin processes.

func (*Preview) DiagnoseNormalization

func (p *Preview) DiagnoseNormalization(ctx context.Context, path string) (*NormalizationDiagnosis, error)

DiagnoseNormalization renders twice and returns non-deterministic fields with cluster context.

func (*Preview) Diff

func (p *Preview) Diff(ctx context.Context, a, b string, out io.Writer) error

Diff computes and writes the diff between two repository paths. If a HelmRelease filter is set, only resources from that release are included.

func (*Preview) DiffResult

func (p *Preview) DiffResult(ctx context.Context, a, b string, out io.Writer) (result *diff.DiffResult, resultErr error)

DiffResult computes and writes the diff between two repository paths, returning structured change metadata alongside the rendered diff text. An ExpansionError with only Warnings accompanies a complete comparison; expansion errors suppress all changes because either side may be incomplete.

func (*Preview) GenerateInitConfig

func (p *Preview) GenerateInitConfig(ctx context.Context, path, destPath string) error

GenerateInitConfig renders the repo twice to detect permadiffs and writes a complete .fmp.yaml config file to destPath.

func (*Preview) ListHelmReleases

func (p *Preview) ListHelmReleases(ctx context.Context, path string) ([]HelmReleaseInfo, error)

ListHelmReleases discovers and lists HelmReleases from the repo at path.

func (*Preview) ListKustomizations

func (p *Preview) ListKustomizations(ctx context.Context, path string) ([]KustomizationInfo, error)

ListKustomizations discovers and lists Flux Kustomizations from the repo at path.

func (*Preview) Render

func (p *Preview) Render(ctx context.Context, path string, out io.Writer) error

Render renders the resources at path and writes the YAML output.

func (*Preview) RenderJSON

func (p *Preview) RenderJSON(ctx context.Context, path string, out io.Writer) error

RenderJSON renders the resources at path and writes JSON output.

func (*Preview) RenderSnapshot

func (p *Preview) RenderSnapshot(ctx context.Context, path string) (*Snapshot, error)

RenderSnapshot loads path and returns the exact inventory used for comparison. On failure the returned snapshot is incomplete and the error describes why.

func (*Preview) RunDiff

func (p *Preview) RunDiff(ctx context.Context, opts DiffRunOptions) (run *DiffRunResult, runErr error)

RunDiff renders both sides, computes the rendered manifest diff, and applies policy checks. Incomplete renders return an error and a result with Complete=false, diagnostics, no authoritative changes, and no policy or AI assessment.

func (*Preview) Test

func (p *Preview) Test(ctx context.Context, path string, out io.Writer) error

Test validates that all Kustomizations build and HelmReleases render. Returns nil on success, or an error describing the failure.

func (*Preview) TestJSON

func (p *Preview) TestJSON(ctx context.Context, path string) (*TestResult, error)

TestJSON validates resources and returns a structured test result.

type Snapshot

type Snapshot struct {
	Clusters map[string]*render.Render
	// Logical preserves unnamed composed resources without adding invented names
	// to the named Kubernetes inventory.
	Logical  map[string][]plugin.Resource
	Evidence map[string][]json.RawMessage
	Complete bool
	Warnings []string
}

Snapshot is a detached render inventory, keyed by cluster ("" for unclustered input). Incomplete snapshots must not be used to infer additions or deletions.

type TestIssue

type TestIssue struct {
	Message string `json:"message"`
}

TestIssue describes a single warning or error encountered during testing.

type TestResult

type TestResult struct {
	Status   string      `json:"status"`
	Warnings []TestIssue `json:"warnings,omitempty"`
	Errors   []TestIssue `json:"errors,omitempty"`
}

TestResult is the JSON representation of a test run.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL