-
Notifications
You must be signed in to change notification settings - Fork 24
feat: make operator and data-plane image registry configurable #464
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
WentingWu666666
wants to merge
5
commits into
documentdb:main
Choose a base branch
from
WentingWu666666:developer/wenting-configurable-image-registry
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
5 commits
Select commit
Hold shift + click to select a range
096e78f
feat: make operator and data-plane image registry configurable
wentingwu000 ef9c7b4
fix: address PR review — release-workflow parsing, repository tag gua…
wentingwu000 ab28ab1
fix: fail-fast on invalid image config in Helm chart
wentingwu000 dccb62a
fix: require otel/postgres image repo and tag to be set together
wentingwu000 cf9bfac
fix: keep inline control-plane image tag key so chart-build sed lands…
wentingwu000 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,94 @@ | ||
| {{- define "documentdb-chart.name" -}} | ||
| documentdb-operator | ||
| {{- end -}} | ||
|
|
||
| {{/* | ||
| documentdb.imageRef composes a container image reference from a registry prefix, | ||
| a repository, and an optional tag, following the canonical Docker/containerd | ||
| reference rule for deciding whether the repository already carries a registry | ||
| host: the first path segment is treated as a registry host when it contains a | ||
| "." or ":" (port), or equals "localhost". In that case the repository is used | ||
| verbatim and the registry prefix is ignored (this is also the per-component | ||
| per-registry override path). Otherwise the registry prefix is prepended. | ||
|
|
||
| The repository must be a non-empty host/path only. Rendering fails (naming the | ||
| offending setting via "name") when the repository is empty, when it already | ||
| carries a tag or digest (a ":" or "@" in the final path segment), or when the | ||
| registry prefix would be needed but is empty. The tag is always supplied via the | ||
| component's tag field (or documentDbVersion for the data-plane images) rather | ||
| than embedded in the repository. | ||
|
|
||
| Usage: | ||
| {{ include "documentdb.imageRef" (dict "name" "image.foo.repository" "registry" .Values.image.registry "repo" $repo "tag" $tag) }} | ||
| Pass tag "" to compose a bare repository (host+path, no tag). | ||
| */}} | ||
| {{- define "documentdb.imageRef" -}} | ||
| {{- $name := .name | default "image repository" -}} | ||
| {{- if not .repo -}} | ||
| {{- fail (printf "%s is empty; set it to a host/path (with image.registry) or a full host reference" $name) -}} | ||
| {{- end -}} | ||
| {{- $lastSeg := (splitList "/" .repo) | last -}} | ||
| {{- if or (contains ":" $lastSeg) (contains "@" $lastSeg) -}} | ||
| {{- fail (printf "%s value %q must be a host/path without a tag or digest; set the tag via the component's tag field (or documentDbVersion for data-plane images)" $name .repo) -}} | ||
| {{- end -}} | ||
| {{- $first := (splitList "/" .repo) | first -}} | ||
| {{- $full := .repo -}} | ||
| {{- if not (or (contains "." $first) (contains ":" $first) (eq $first "localhost")) -}} | ||
| {{- if not .registry -}} | ||
| {{- fail (printf "image.registry is empty but %s (%q) is a relative path; set image.registry or use a full host reference in the repository" $name .repo) -}} | ||
| {{- end -}} | ||
| {{- $full = printf "%s/%s" .registry .repo -}} | ||
| {{- end -}} | ||
| {{- if .tag -}} | ||
| {{- printf "%s:%s" $full .tag -}} | ||
| {{- else -}} | ||
| {{- $full -}} | ||
| {{- end -}} | ||
| {{- end -}} | ||
|
|
||
| {{/* | ||
| documentdb.extraImageRef composes an optional override image reference for the | ||
| "extra" images (otel collector, postgres) that carry no fallback tag source. | ||
| Unlike the first-party images (whose tag defaults to Chart.AppVersion or | ||
| documentDbVersion), these have no default tag, so a partial override is always a | ||
| mistake: a repository without a tag would leak a floating ":latest", and a tag | ||
| without a repository would be silently dropped. This helper therefore enforces | ||
| that the component's repository and tag are set together (both or neither): | ||
|
|
||
| - both empty -> returns "" (caller omits the env var; the operator uses its | ||
| compiled-in default for otel, or defers to CNPG for postgres) | ||
| - both set -> returns the composed "registry/repo:tag" reference | ||
| - exactly one -> rendering fails, naming both settings | ||
|
|
||
| Usage: | ||
| {{ include "documentdb.extraImageRef" (dict "registry" .Values.image.registry "repo" $repo "tag" $tag "repoName" "image.otelCollector.repository" "tagName" "image.otelCollector.tag") }} | ||
| */}} | ||
| {{- define "documentdb.extraImageRef" -}} | ||
| {{- if and .repo (not .tag) -}} | ||
| {{- fail (printf "%s is set but %s is empty; pin a tag (%s and %s must be set together)" .repoName .tagName .repoName .tagName) -}} | ||
| {{- end -}} | ||
| {{- if and .tag (not .repo) -}} | ||
| {{- fail (printf "%s is set but %s is empty; set the repository (%s and %s must be set together)" .tagName .repoName .repoName .tagName) -}} | ||
| {{- end -}} | ||
| {{- if .repo -}} | ||
| {{- include "documentdb.imageRef" (dict "name" .repoName "registry" .registry "repo" .repo "tag" .tag) -}} | ||
| {{- end -}} | ||
| {{- end -}} | ||
|
|
||
| {{/* | ||
| documentdb.pullPolicy validates and echoes an image pull policy. An empty value | ||
| yields an empty string (the caller omits the setting and the consumer applies | ||
| its own default); a non-empty value must be one of Always, IfNotPresent, or | ||
| Never, otherwise rendering fails naming the offending setting via "name". | ||
|
|
||
| Usage: | ||
| {{ include "documentdb.pullPolicy" (dict "name" "image.gateway.pullPolicy" "policy" .Values.image.gateway.pullPolicy) }} | ||
| */}} | ||
| {{- define "documentdb.pullPolicy" -}} | ||
| {{- if .policy -}} | ||
| {{- if not (has .policy (list "Always" "IfNotPresent" "Never")) -}} | ||
| {{- fail (printf "%s must be one of Always, IfNotPresent, Never (got %q)" .name .policy) -}} | ||
| {{- end -}} | ||
| {{- .policy -}} | ||
| {{- end -}} | ||
| {{- end -}} | ||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
An empty
image.registryor operator repository renders an invalid image such as/documentdb/...:0.3.0orghcr.io/:0.3.0. Helm reports success and the failure appears later at pod startup. Can we fail rendering with the name of the empty setting?There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed in ab28ab1.
documentdb.imageRefnow fails rendering when the repository is empty, or whenimage.registryis empty but a relative repository needs the prefix — instead of emitting/documentdb/...orghcr.io/:tag. A requirednameargument makes the error name the exact setting, e.g.image.registry is empty but image.documentdbk8soperator.repository ("...") is a relative pathandimage.documentdbk8soperator.repository is empty. This covers all components (they share the helper). Added helm-unittest cases for empty registry and empty repository.