[Backport release-1.5] fix(keycloak-configure): patch HelmRelease in release namespace on teardown - #3877
Merged
Merged
Conversation
…ardown The pre-delete teardown Job clears the HelmRelease finalizers as its final step, but targeted a hardcoded namespace that does not match the namespace where the release and its RBAC live. The Job's Role and RoleBinding are created in the release namespace and grant patch on the HelmRelease by release name, so the ServiceAccount was Forbidden to patch the HelmRelease in the hardcoded namespace. The Job errored and retried forever, the HelmRelease stuck in Terminating, and the Helm release wedged in "uninstalling", blocking any teardown or reinstall. Target the release name and namespace so the patch matches the RBAC that grants it. Add a helm-unittest pinning the rendered namespace. Assisted-By: Claude <noreply@anthropic.com> Signed-off-by: Aleksei Sviridkin <f@lex.la> (cherry picked from commit fd568de)
The chart ships tests/delete_test.yaml, but the package Makefile has no `test:` target, and hack/helm-unit-tests.sh runs a package's suite only when `make -C <dir> -n test` succeeds. The suite was therefore never executed on this branch, so the namespace assertion added alongside the teardown fix shipped as dead weight. Add the target in the same form the other packages use. On main the same three lines arrived via an unrelated login-theme commit rather than with the fix itself, which is why the backport landed without them. Verified by mutating the rendered patch back to the pre-fix hardcoded `-n cozy-system`: all three tests go red, so the suite asserts something. Signed-off-by: Myasnikov Daniil <myasnikovdaniil2001@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Backport of #3372 to
release-1.5.