Skip to content

ci: harden Helm validation tooling#175

Merged
edgard merged 1 commit intomasterfrom
codex-helm4-hardening
Apr 15, 2026
Merged

ci: harden Helm validation tooling#175
edgard merged 1 commit intomasterfrom
codex-helm4-hardening

Conversation

@edgard
Copy link
Copy Markdown
Owner

@edgard edgard commented Apr 15, 2026

Summary

  • pin CI tool versions for Task, Helm, OpenTofu, and Pluto
  • render Helm apps with the Tuppr Kubernetes target version
  • isolate Helm config/cache/data during rendered validation

Tests

  • task test
  • task lint
  • helmfile -f bootstrap/helmfile.yaml.gotmpl build

Pin CI tools that otherwise float to broad or latest versions, reducing drift between local validation and pull-request checks. Rendered Helm validation now uses the repo Kubernetes target version and temp Helm state so lint output does not depend on a developer or runner Helm configuration.
@edgard edgard force-pushed the codex-helm4-hardening branch from 3683318 to 04c27d1 Compare April 15, 2026 11:01
@edgard edgard merged commit b96a49c into master Apr 15, 2026
3 checks passed
@edgard edgard deleted the codex-helm4-hardening branch April 15, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant