From c5b569593ea2441511e7cfb16a86402751d5b439 Mon Sep 17 00:00:00 2001 From: Aleksei Sviridkin Date: Wed, 23 Sep 2026 15:33:36 +0300 Subject: [PATCH 1/2] fix(docs): correct hairpin-proxy-protocol tenant disable failure case The tenant disable troubleshooting list named a manual kubectl delete of the HelmRelease object as a way to bypass helm uninstall and skip the chart's pre-delete hook. helm-controller runs the uninstall step (and the hook with it) for any HelmRelease deletion that is not suspended, so a bare object delete does not skip it. The case that actually skips the hook is a HelmRelease that was already suspended at the moment it got deleted, since the uninstall branch is conditioned on the resource not being suspended. Assisted-by: LLM Signed-off-by: Aleksei Sviridkin --- content/en/docs/next/networking/hairpin-proxy-protocol.md | 2 +- content/en/docs/v1.4/networking/hairpin-proxy-protocol.md | 2 +- content/en/docs/v1.5/networking/hairpin-proxy-protocol.md | 2 +- content/en/docs/v1.6/networking/hairpin-proxy-protocol.md | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/content/en/docs/next/networking/hairpin-proxy-protocol.md b/content/en/docs/next/networking/hairpin-proxy-protocol.md index b2c214b9..2e6c1013 100644 --- a/content/en/docs/next/networking/hairpin-proxy-protocol.md +++ b/content/en/docs/next/networking/hairpin-proxy-protocol.md @@ -132,7 +132,7 @@ The host cleanup recipe below is the manual fallback for the rare case where the 1. Set `addons.ouroboros.enabled: false` in the tenant `Kubernetes` CR. Flux runs `helm uninstall` and the chart's pre-delete hook patches `kube-system/coredns-custom` for you. -If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, manual `kubectl delete hr` bypassing helm uninstall), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. +If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, the HelmRelease was suspended when it was deleted so the uninstall step — and the hook with it — is skipped entirely), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. Tenant ingress-nginx is unaffected by toggling `addons.ouroboros` on its own — PROXY-protocol on the tenant ingress is wired manually via `valuesOverride` and stays where the operator put it. diff --git a/content/en/docs/v1.4/networking/hairpin-proxy-protocol.md b/content/en/docs/v1.4/networking/hairpin-proxy-protocol.md index b2c214b9..2e6c1013 100644 --- a/content/en/docs/v1.4/networking/hairpin-proxy-protocol.md +++ b/content/en/docs/v1.4/networking/hairpin-proxy-protocol.md @@ -132,7 +132,7 @@ The host cleanup recipe below is the manual fallback for the rare case where the 1. Set `addons.ouroboros.enabled: false` in the tenant `Kubernetes` CR. Flux runs `helm uninstall` and the chart's pre-delete hook patches `kube-system/coredns-custom` for you. -If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, manual `kubectl delete hr` bypassing helm uninstall), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. +If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, the HelmRelease was suspended when it was deleted so the uninstall step — and the hook with it — is skipped entirely), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. Tenant ingress-nginx is unaffected by toggling `addons.ouroboros` on its own — PROXY-protocol on the tenant ingress is wired manually via `valuesOverride` and stays where the operator put it. diff --git a/content/en/docs/v1.5/networking/hairpin-proxy-protocol.md b/content/en/docs/v1.5/networking/hairpin-proxy-protocol.md index b2c214b9..2e6c1013 100644 --- a/content/en/docs/v1.5/networking/hairpin-proxy-protocol.md +++ b/content/en/docs/v1.5/networking/hairpin-proxy-protocol.md @@ -132,7 +132,7 @@ The host cleanup recipe below is the manual fallback for the rare case where the 1. Set `addons.ouroboros.enabled: false` in the tenant `Kubernetes` CR. Flux runs `helm uninstall` and the chart's pre-delete hook patches `kube-system/coredns-custom` for you. -If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, manual `kubectl delete hr` bypassing helm uninstall), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. +If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, the HelmRelease was suspended when it was deleted so the uninstall step — and the hook with it — is skipped entirely), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. Tenant ingress-nginx is unaffected by toggling `addons.ouroboros` on its own — PROXY-protocol on the tenant ingress is wired manually via `valuesOverride` and stays where the operator put it. diff --git a/content/en/docs/v1.6/networking/hairpin-proxy-protocol.md b/content/en/docs/v1.6/networking/hairpin-proxy-protocol.md index b2c214b9..2e6c1013 100644 --- a/content/en/docs/v1.6/networking/hairpin-proxy-protocol.md +++ b/content/en/docs/v1.6/networking/hairpin-proxy-protocol.md @@ -132,7 +132,7 @@ The host cleanup recipe below is the manual fallback for the rare case where the 1. Set `addons.ouroboros.enabled: false` in the tenant `Kubernetes` CR. Flux runs `helm uninstall` and the chart's pre-delete hook patches `kube-system/coredns-custom` for you. -If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, manual `kubectl delete hr` bypassing helm uninstall), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. +If the chart's pre-delete hook fails to land (controller pod stuck CrashLooping, ConfigMap RBAC drift, Job timeout, the HelmRelease was suspended when it was deleted so the uninstall step — and the hook with it — is skipped entirely), the symptom is a stale rewrite in the tenant `kube-system/coredns-custom` ConfigMap pointing at a Service that is now gone. Recover by running the tenant cleanup recipe below against the tenant admin-kubeconfig. Tenant ingress-nginx is unaffected by toggling `addons.ouroboros` on its own — PROXY-protocol on the tenant ingress is wired manually via `valuesOverride` and stays where the operator put it. From de6b2ddd34bb593b2e0fbb2ff153674886c26290 Mon Sep 17 00:00:00 2001 From: Aleksei Sviridkin Date: Wed, 23 Sep 2026 15:34:10 +0300 Subject: [PATCH 2/2] fix(docs): qualify enabledPackages examples on v1.0 and v1.1 The GPU and NFS driver guides told operators to add the bare component name (gpu-operator, nfs-driver) to bundles.enabledPackages. The platform chart's optional-package helper matches enabledPackages entries against the fully-qualified cozystack. form, so the bare examples add a value the chart never checks and enable nothing. Later doc versions already carry the qualified form; this backports the same fix to v1.0 and v1.1. Assisted-by: LLM Signed-off-by: Aleksei Sviridkin --- content/en/docs/v1.0/storage/nfs.md | 4 ++-- content/en/docs/v1.0/virtualization/gpu.md | 2 +- content/en/docs/v1.1/storage/nfs.md | 4 ++-- content/en/docs/v1.1/virtualization/gpu.md | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/content/en/docs/v1.0/storage/nfs.md b/content/en/docs/v1.0/storage/nfs.md index e4c36d10..15a90e67 100644 --- a/content/en/docs/v1.0/storage/nfs.md +++ b/content/en/docs/v1.0/storage/nfs.md @@ -9,11 +9,11 @@ aliases: ## Enable NFS driver -Add `nfs-driver` to `bundles.enabledPackages` in the [Platform Package]({{% ref "/docs/v1.0/operations/configuration/platform-package" %}}): +Add `cozystack.nfs-driver` to `bundles.enabledPackages` in the [Platform Package]({{% ref "/docs/v1.0/operations/configuration/platform-package" %}}): ```bash kubectl patch packages.cozystack.io cozystack.cozystack-platform --type=json \ - -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "nfs-driver"}]' + -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "cozystack.nfs-driver"}]' ``` Wait a minute for the platform chart to reconcile, then verify the HelmRelease has been created: diff --git a/content/en/docs/v1.0/virtualization/gpu.md b/content/en/docs/v1.0/virtualization/gpu.md index 0705ff79..2cfb2948 100644 --- a/content/en/docs/v1.0/virtualization/gpu.md +++ b/content/en/docs/v1.0/virtualization/gpu.md @@ -36,7 +36,7 @@ Follow these steps: ```bash kubectl patch packages.cozystack.io cozystack.cozystack-platform --type=json \ - -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "gpu-operator"}]' + -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "cozystack.gpu-operator"}]' ``` This will deploy the components (operands). diff --git a/content/en/docs/v1.1/storage/nfs.md b/content/en/docs/v1.1/storage/nfs.md index 2431d96f..18ae3a77 100644 --- a/content/en/docs/v1.1/storage/nfs.md +++ b/content/en/docs/v1.1/storage/nfs.md @@ -9,11 +9,11 @@ aliases: ## Enable NFS driver -Add `nfs-driver` to `bundles.enabledPackages` in the [Platform Package]({{% ref "/docs/v1.1/operations/configuration/platform-package" %}}): +Add `cozystack.nfs-driver` to `bundles.enabledPackages` in the [Platform Package]({{% ref "/docs/v1.1/operations/configuration/platform-package" %}}): ```bash kubectl patch packages.cozystack.io cozystack.cozystack-platform --type=json \ - -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "nfs-driver"}]' + -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "cozystack.nfs-driver"}]' ``` Wait a minute for the platform chart to reconcile, then verify the HelmRelease has been created: diff --git a/content/en/docs/v1.1/virtualization/gpu.md b/content/en/docs/v1.1/virtualization/gpu.md index 4166c62e..93e8b5b9 100644 --- a/content/en/docs/v1.1/virtualization/gpu.md +++ b/content/en/docs/v1.1/virtualization/gpu.md @@ -36,7 +36,7 @@ Follow these steps: ```bash kubectl patch packages.cozystack.io cozystack.cozystack-platform --type=json \ - -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "gpu-operator"}]' + -p '[{"op": "add", "path": "/spec/components/platform/values/bundles/enabledPackages/-", "value": "cozystack.gpu-operator"}]' ``` This will deploy the components (operands).