spec

package
v2.0.0-alpha.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 23 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ApplyPatches

func ApplyPatches(ctx context.Context, patches []*CompiledPatch, resMeta *ResourceMeta, namespace string, unstruct *unstructured.Unstructured) (*unstructured.Unstructured, error)

ApplyPatches runs every rule whose matcher matches the resource, threading each transform's output into the next, and returns a transformed deep copy; the input is never mutated. namespace is the resource's true namespace.

func CleanUnstruct

Clean an Unstructured object from things like managed fields, non-deterministic runtime data, etc, for diffing, hashing, human-friendly output and so on.

func FindAnnotationOrLabelByKeyPattern

func FindAnnotationOrLabelByKeyPattern(annotationsOrLabels map[string]string, pattern *regexp.Regexp) (key, value string, found bool)

func FindAnnotationsOrLabelsByKeyPattern

func FindAnnotationsOrLabelsByKeyPattern(annotationsOrLabels map[string]string, pattern *regexp.Regexp) (result map[string]string, found bool)

func GVKtoGVR

func GVKtoGVR(gvk schema.GroupVersionKind, mapper meta.RESTMapper) (gvr schema.GroupVersionResource, namespaced bool, err error)

func ID

func ID(name, namespace, group, kind string) string

func IDHuman

func IDHuman(name, namespace, group, kind string) string

func IDWithVersion

func IDWithVersion(name, namespace, group, version, kind string) string

func IsCRD

func IsCRD(groupKind schema.GroupKind) bool

func IsCRDFromGR

func IsCRDFromGR(groupKind schema.GroupResource) bool

func IsHook

func IsHook(annotations map[string]string) bool

func IsNamespace

func IsNamespace(gvk schema.GroupVersionKind) bool

func IsReleaseNamespace

func IsReleaseNamespace(resourceName string, resourceGVK schema.GroupVersionKind, releaseNamespace string) bool

func IsWebhook

func IsWebhook(groupKind schema.GroupKind) bool

func Namespaced

func Namespaced(gvk schema.GroupVersionKind, mapper meta.RESTMapper) (bool, error)

func ParseKubectlResourceStringToGVR

func ParseKubectlResourceStringToGVR(resource string) schema.GroupVersionResource

func ParseKubectlResourceStringtoGVK

func ParseKubectlResourceStringtoGVK(resource string, restMapper meta.RESTMapper) (schema.GroupVersionKind, error)

func ResourceMetaSortHandler

func ResourceMetaSortHandler(r1, r2 *ResourceMeta) bool

func ResourceSpecSortHandler

func ResourceSpecSortHandler(r1, r2 *ResourceSpec) bool

Types

type CleanUnstructOptions

type CleanUnstructOptions struct {
	CleanAnnotations        map[string]string
	CleanHelmShAnnos        bool
	CleanLabels             map[string]string
	CleanManagedFields      bool
	CleanReleaseAnnosLabels bool
	CleanRuntimeData        bool
	CleanWerfIoAnnos        bool
	CleanWerfIoRuntimeAnnos bool
}

type CompiledPatch

type CompiledPatch struct {
	// contains filtered or unexported fields
}

CompiledPatch is a Patch with its jq program compiled once, ready to match and transform many resources.

func CompilePatches

func CompilePatches(patches []Patch) ([]*CompiledPatch, error)

CompilePatches compiles patch rules, returning an error on the first invalid regexp, unsupported type, empty patch body, or invalid jq program.

func CompileRenderPatches

func CompileRenderPatches(patches []Patch, renderContext RenderContext) ([]*CompiledPatch, error)

CompileRenderPatches compiles render patches, additionally exposing the render context as the jq variables $Values, $Release, $Chart and $Capabilities. Diff patches are compiled without them, so a diff patch referencing one fails to compile.

func (*CompiledPatch) Match

func (c *CompiledPatch) Match(resMeta *ResourceMeta, namespace string) bool

Match reports whether the rule matches the resource. namespace is the resource's true namespace (empty only for cluster-scoped resources), passed in because ResourceMeta.Namespace is blanked for release-namespace resources.

type CompiledPatches

type CompiledPatches struct {
	Diff   []*CompiledPatch
	Render []*CompiledPatch
}

CompiledPatches are Patches with their jq programs compiled.

type ExtraMetadataPatcher

type ExtraMetadataPatcher struct {
	// contains filtered or unexported fields
}

func NewExtraMetadataPatcher

func NewExtraMetadataPatcher(annotations, labels map[string]string) *ExtraMetadataPatcher

func (*ExtraMetadataPatcher) Match

func (*ExtraMetadataPatcher) Patch

func (*ExtraMetadataPatcher) Type

type LegacyOnlyTrackJobsPatcher

type LegacyOnlyTrackJobsPatcher struct{}

TODO: get rid of it when patching is implemented or when Kubedog compaitiblity with Helm charts improved

func NewLegacyOnlyTrackJobsPatcher

func NewLegacyOnlyTrackJobsPatcher() *LegacyOnlyTrackJobsPatcher

func (*LegacyOnlyTrackJobsPatcher) Match

func (*LegacyOnlyTrackJobsPatcher) Patch

func (*LegacyOnlyTrackJobsPatcher) Type

type Patch

type Patch struct {
	// Match chooses which resources this rule applies to. An empty matcher
	// matches every resource.
	Match ResourceMatcher `json:"match,omitempty"`
	// Type is the transform kind. Only "jq" is supported; empty defaults to "jq".
	Type PatchType `json:"type,omitempty"`
	// Patch is the jq program: it receives the whole raw resource object and must
	// return exactly one object.
	Patch string `json:"patch,omitempty"`
	// contains filtered or unexported fields
}

Patch is a jq transform applied to every resource its matcher matches.

type PatchType

type PatchType string

PatchType is the transform kind of patch.

const (
	PatchTypeJQ PatchType = "jq"
)

type Patches

type Patches struct {
	// Diff rules affect ONLY drift detection: the transform is applied identically
	// to the live and the dry-apply object before they are compared, so
	// normalized-away fields never produce a diff. They never change what is
	// rendered or applied.
	Diff []Patch
	// Render rules are applied to the rendered resources, so they do change what is
	// released and applied to the cluster.
	Render []Patch
}

Patches are patch rules grouped by the point at which they are applied.

func CollectChartPatches

func CollectChartPatches(chart helmchart.Accessor) (Patches, error)

CollectChartPatches returns every chart-shipped patches.yaml rule in the chart tree, ordered leaf-first and each constrained to its own chart subtree.

func LoadPatchesFiles

func LoadPatchesFiles(paths []string) (Patches, error)

LoadPatchesFiles reads and parses the given patches file paths, returning their rules concatenated in order.

type PatchesFile

type PatchesFile struct {
	DiffPatches   []Patch `json:"diffPatches,omitempty"`
	RenderPatches []Patch `json:"renderPatches,omitempty"`
}

PatchesFile is the on-disk format of a patches file.

type ReleaseMetadataPatcher

type ReleaseMetadataPatcher struct {
	// contains filtered or unexported fields
}

func NewReleaseMetadataPatcher

func NewReleaseMetadataPatcher(releaseName, releaseNamespace string) *ReleaseMetadataPatcher

func (*ReleaseMetadataPatcher) Match

func (*ReleaseMetadataPatcher) Patch

func (*ReleaseMetadataPatcher) Type

type RenderContext

type RenderContext struct {
	Capabilities interface{}
	Chart        interface{}
	Release      interface{}
	Subcharts    map[string]SubchartContext
	Values       interface{}
}

RenderContext is what the chart's templates saw, exposed to render patches as the jq variables $Values, $Release, $Chart and $Capabilities. A rule shipped by a subchart gets that subchart's own Values and Chart, matching what its templates saw; Subcharts is keyed by chart path.

type ResourceListsTransformer

type ResourceListsTransformer struct{}

func NewResourceListsTransformer

func NewResourceListsTransformer() *ResourceListsTransformer

func (*ResourceListsTransformer) Match

func (*ResourceListsTransformer) Transform

func (*ResourceListsTransformer) Type

type ResourceMatcher

type ResourceMatcher struct {
	Names       []string          `json:"names,omitempty"`
	Namespaces  []string          `json:"namespaces,omitempty"`
	Groups      []string          `json:"groups,omitempty"`
	Versions    []string          `json:"versions,omitempty"`
	Kinds       []string          `json:"kinds,omitempty"`
	Charts      []string          `json:"charts,omitempty"`
	Labels      map[string]string `json:"labels,omitempty"`
	Annotations map[string]string `json:"annotations,omitempty"`
}

ResourceMatcher matches resources by metadata. Fields AND together; values within a field OR together; an empty field matches everything. String values use the /regex/ convention: a bare value is an exact match (case-insensitive for groups/versions/kinds, case-sensitive for names/namespaces/charts), a value wrapped in slashes is an anchored regexp. Labels and annotations are exact key=value and must all match. Charts matches a resource's originating (sub)chart alias or its full chart-path.

func (*ResourceMatcher) Match

func (s *ResourceMatcher) Match(resMeta *ResourceMeta) bool

func (*ResourceMatcher) Validate

func (s *ResourceMatcher) Validate() error

Validate compiles every /regex/ value and returns the first error, so callers that need fail-closed behavior can reject a bad matcher before matching.

type ResourceMeta

type ResourceMeta struct {
	Name             string                  `json:"name"`
	Namespace        string                  `json:"namespace"`
	GroupVersionKind schema.GroupVersionKind `json:"groupVersionKind"`
	FilePath         string                  `json:"filePath"`
	Annotations      map[string]string       `json:"annotations"`
	Labels           map[string]string       `json:"labels"`
}

Contains basic information about a Kubernetes resource, without its full spec. Very useful for getting, deleting, tracking resources, when you don't care about the resource spec (or when it's not available). If also the resource spec is needed, use ResourceSpec.

func NewResourceMeta

func NewResourceMeta(name, namespace, releaseNamespace, filePath string, gvk schema.GroupVersionKind, annotations, labels map[string]string) *ResourceMeta

func NewResourceMetaFromManifest

func NewResourceMetaFromManifest(manifest, releaseNamespace string) (*ResourceMeta, error)

func NewResourceMetaFromPartialMetadata

func NewResourceMetaFromPartialMetadata(meta *v1.PartialObjectMetadata, releaseNamespace, filePath string) *ResourceMeta

func NewResourceMetaFromUnstructured

func NewResourceMetaFromUnstructured(unstruct *unstructured.Unstructured, releaseNamespace, filePath string) *ResourceMeta

func (*ResourceMeta) ID

func (m *ResourceMeta) ID() string

Uniquely identifies the resource.

func (*ResourceMeta) IDHuman

func (m *ResourceMeta) IDHuman() string

func (*ResourceMeta) IDWithVersion

func (m *ResourceMeta) IDWithVersion() string

type ResourcePatcher

type ResourcePatcher interface {
	Match(ctx context.Context, resourceInfo *ResourcePatcherResourceInfo) (matched bool, err error)
	Patch(ctx context.Context, matchedResourceInfo *ResourcePatcherResourceInfo) (output *unstructured.Unstructured, err error)
	Type() ResourcePatcherType
}

type ResourcePatcherResourceInfo

type ResourcePatcherResourceInfo struct {
	Obj       *unstructured.Unstructured
	Ownership common.Ownership
}

type ResourcePatcherType

type ResourcePatcherType string
const (
	TypeExtraMetadataPatcher    ResourcePatcherType = "extra-metadata-patcher"
	TypeReleaseMetadataPatcher  ResourcePatcherType = "release-metadata-patcher"
	TypeOnlyTrackJobsPatcher    ResourcePatcherType = "only-track-jobs-patcher"
	TypeSecretStringDataPatcher ResourcePatcherType = "secret-string-data-patcher"
)

type ResourceSpec

type ResourceSpec struct {
	*ResourceMeta `json:"resourceMeta"`

	Unstruct *unstructured.Unstructured `json:"unstruct"`
	StoreAs  common.StoreAs             `json:"storeAs"`
}

Contains all generic information about the resource, e.g. its name, namespace, GVK and its spec. Enough to create or update resources, as well as delete, get, etc. Use it when ResourceMeta is not enough and you also need the actual resource spec.

func BuildPatchedResourceSpecs

func BuildPatchedResourceSpecs(ctx context.Context, releaseNamespace string, transformedResources []*ResourceSpec, patchers []ResourcePatcher) ([]*ResourceSpec, error)

Patch ResourceSpecs to make them releasable, after which they can be saved into the Helm release. Don't try to add/delete/expand specs here, use transformers in BuildTransformedResourceSpecs instead.

func BuildRenderPatchedResourceSpecs

func BuildRenderPatchedResourceSpecs(ctx context.Context, releaseNamespace string, resources []*ResourceSpec, patches []*CompiledPatch) ([]*ResourceSpec, error)

Patch ResourceSpecs with render patches, i.e. right after the chart is rendered. Unlike diff patches, the result is what gets released and applied to the cluster, so a patch must not change the resource identity. StoreAs is re-derived, because a patch can add or remove the Helm hook annotation, except for StoreAsNone, which is not releasable at all and must survive patching.

func BuildTransformedResourceSpecs

func BuildTransformedResourceSpecs(ctx context.Context, releaseNamespace string, resources []*ResourceSpec, transformers []ResourceTransformer) ([]*ResourceSpec, error)

Transforms ResourceSpecs, which means specs can be added, deleted, expanded (like Lists). If you just need to modify specs, use patchers in BuildReleasableResourceSpecs instead.

func NewResourceSpec

func NewResourceSpec(unstruct *unstructured.Unstructured, releaseNamespace string, opts ResourceSpecOptions) *ResourceSpec

func NewResourceSpecFromManifest

func NewResourceSpecFromManifest(ctx context.Context, manifest, releaseNamespace string, opts ResourceSpecOptions) (*ResourceSpec, error)

func (*ResourceSpec) SetAnnotations

func (s *ResourceSpec) SetAnnotations(annotations map[string]string)

func (*ResourceSpec) SetLabels

func (s *ResourceSpec) SetLabels(labels map[string]string)

type ResourceSpecOptions

type ResourceSpecOptions struct {
	DropInvalidAnnotationsAndLabels bool
	FilePath                        string
	StoreAs                         common.StoreAs
}

type ResourceTransformer

type ResourceTransformer interface {
	Match(ctx context.Context, resourceInfo *ResourceTransformerResourceInfo) (matched bool, err error)
	Transform(ctx context.Context, matchedResourceInfo *ResourceTransformerResourceInfo) (output []*unstructured.Unstructured, err error)
	Type() ResourceTransformerType
}

type ResourceTransformerResourceInfo

type ResourceTransformerResourceInfo struct {
	Obj *unstructured.Unstructured
}

type ResourceTransformerType

type ResourceTransformerType string
const TypeResourceListsTransformer ResourceTransformerType = "resource-lists-transformer"

type SecretStringDataPatcher

type SecretStringDataPatcher struct{}

func NewSecretStringDataPatcher

func NewSecretStringDataPatcher() *SecretStringDataPatcher

func (*SecretStringDataPatcher) Match

func (*SecretStringDataPatcher) Patch

func (*SecretStringDataPatcher) Type

type SubchartContext

type SubchartContext struct {
	Chart  interface{}
	Values interface{}
}

SubchartContext is the part of the render context that differs per subchart.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL