Conversation
🦋 Changeset detectedLatest commit: 48dd6bc The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
f7cf6b3 to
fa92f63
Compare
|
Please fix the P1 checksum-test failure before merging. The CI unit-test job reports 5 failed, 252 passed, with all five failures in The hard-coded expected hashes differ from CI's rendered hashes (e.g. baseline config expects Rest of the change looks good: annotation merge precedence is preserved, the Secret checksum is correctly guarded on
|
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@wrn14897 thanks for the review. pushed fixes and ran full validation, updated PR description. Chart-version changes intentionally trigger a rollout, following Helm’s checksum convention |
Summary
Motivation
HyperDX consumes
clickstack-configandclickstack-secretthroughenvFrom. Kubernetes resolves those environment variables when a pod starts, so changing only the ConfigMap or Secret duringhelm upgradeleaves existing HyperDX pods with stale startup configuration unless the Deployment pod template also changes.This follows Helm's documented
include ... | sha256sumrollout pattern. The ConfigMap and Secret manifests now share canonical named renderers with the Deployment checksums, ensuring the hashed content cannot drift from the resources Helm applies. Git enforces LF for ClickStack Helm template source, so the standardinclude ... | sha256sumpattern produces identical annotations across checkout platforms without runtime normalization.No new values API is needed: these are chart-managed resources with deterministic rollout behavior. Arbitrary template paths or
tplevaluation in user values would be less safe and would not improve this owned-resource case.Backward compatibility
Existing
hyperdx.deployment.annotationsandhyperdx.deployment.podAnnotationsvalues remain merged with the same precedence. The generatedchecksum/clickstack-configandchecksum/clickstack-secretkeys are chart-reserved and override caller values so stale hashes cannot disable rollouts.checksum/clickstack-secretis omitted whenhyperdx.secrets: null, matching Secret rendering andenvFrombehavior. Externally managed Secret changes still require an explicit rollout because Helm cannot hash resources it does not render.The first upgrade containing this change intentionally performs a one-time HyperDX rollout because the generated annotations are added to the pod template. The checksum covers the full rendered chart-managed resource, including standard chart labels, so a chart-version-only upgrade also intentionally rolls HyperDX; this matches Helm's documented rendered-template checksum pattern.
Tests
Verified with the repository-pinned
helm-unittestplugin v1.0.3:helm unittest --strict -f tests/hyperdx-rollout-checksums_test.yaml charts/clickstack— 6 tests passedhelm unittest charts/clickstack— 31 suites, 257 tests passedhelm templaterenders produce identical checksum annotationshelm lint --strict charts/clickstackgit diff --check