Skip to content

dev - #11

Merged
bonddim merged 4 commits into
mainfrom
dev
Sep 20, 2026
Merged

dev#11
bonddim merged 4 commits into
mainfrom
dev

Conversation

@bonddim

@bonddim bonddim commented Sep 20, 2026

Copy link
Copy Markdown
Owner
  • feat: add headless Service, RBAC, Secret, PVC, Job and CronJob
  • fix: render replicas set from a values file, with unit tests
  • chore(ci): bump pinned action versions

bonddim and others added 4 commits September 20, 2026 15:40
Extend the chart with the standard objects that previously had to be
hand-written through extraObjects:

- Service (headless), opt-in via service.headless.enabled
- Role and RoleBinding, opt-in via rbac.create, bound to the ServiceAccount
- Secret, with tpl-rendered stringData and pre-encoded data
- PersistentVolumeClaim, giving non-StatefulSet workloads a persistence path
- Job and CronJob as workload types, sharing a base.jobSpec define

The headless Service also fixes a dangling reference: a StatefulSet always
emitted serviceName but nothing created that Service, so stable per-pod DNS
never worked. base.headlessServiceName resolves the name and suffixes it so
it cannot collide with the main Service. StatefulSets that leave headless
disabled render exactly as before.

Jobs need a restartPolicy their pod spec did not set, so restartPolicy is now
a value that defaults to Never for job/cronjob. The HPA guard rejects those
workloads alongside daemonset, and base.targetRef maps them for VPA.

Behaviour change: vpa.updatePolicy.updateMode now defaults to "Off"
(recommendation-only) instead of inheriting the controller default of Auto.
Releases already running vpa.enabled=true will stop actively resizing pods
until they set the mode explicitly. The value stays quoted because bare Off
parses as boolean false in YAML.
Comparing .Values.replicas against 0 failed whenever the value came from a
values file: YAML numbers parse as float64, so `eq .Values.replicas 0` errored
with "incompatible types for comparison: float64 and int". Only --set worked,
because it infers int64 -- and a user-supplied values file is this chart's
primary interface, so replicas: 0 broke deployment, statefulset and rollout.

Test for nil directly instead of comparing numbers, and coerce with int when
rendering, so the field is emitted for any numeric type and omitted only when
replicas is genuinely null.

The bug surfaced while adding helm-unittest, which covers the logic that is
not obvious from reading the templates: the autoscaling guards across every
workload and VPA mode, headless Service naming and its agreement with the
StatefulSet, affinity precedence and tpl-rendering, restartPolicy defaulting
for job/cronjob, and the replicas cases above. Assertions are targeted rather
than snapshots, so an intentional change does not rewrite a wall of fixtures.

Tests run via a pre-commit hook mirroring the existing chart-testing one and
a CI step after ct lint, and tests/ is excluded from the packaged chart.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Update actions/checkout, actions/setup-python and docker/login-action to
their current pinned SHAs, and give the publish job full history so the
release step can see prior tags.
@bonddim
bonddim force-pushed the dev branch 2 times, most recently from d62edd6 to 0f756f3 Compare September 20, 2026 15:49
@bonddim
bonddim merged commit 515dc0a into main Sep 20, 2026
2 checks passed
@bonddim
bonddim deleted the dev branch September 20, 2026 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant