fix: thread secret annotations and labels through new helm charts

The new config and pull secret helm releases need to honor user-set annotations and labels for `--resource-type secret` so existing scheduler-k3s annotation tests keep passing. The dedicated charts now render `.Values.global.annotations` and `.Values.global.labels` onto their Secret manifest, and the deploy trigger plumbs `SecretAnnotations` and `SecretLabels` from the global annotation/label config. The rollback regression bats test now uses `dokku ps:rebuild` for its second deploy because git push of an unchanged ref is rejected by the dokku remote.
This commit is contained in:
Jose Diaz-Gonzalez
2026-04-29 12:00:21 -04:00
parent ef9bdc0379
commit 7ba453e588
6 changed files with 69 additions and 16 deletions

View File

@@ -17,9 +17,11 @@ type ConfigSecretValues struct {
// ConfigSecretGlobalValues contains the global values for the config secret chart
type ConfigSecretGlobalValues struct {
AppName string `yaml:"app_name"`
Namespace string `yaml:"namespace"`
Secrets map[string]string `yaml:"secrets,omitempty"`
Annotations map[string]string `yaml:"annotations,omitempty"`
AppName string `yaml:"app_name"`
Labels map[string]string `yaml:"labels,omitempty"`
Namespace string `yaml:"namespace"`
Secrets map[string]string `yaml:"secrets,omitempty"`
}
// GetConfigSecretReleaseName returns the helm release name for the config secret
@@ -32,8 +34,17 @@ func GetConfigSecretName(appName string) string {
return fmt.Sprintf("config-%s", appName)
}
// CreateOrUpdateConfigSecretInput contains the inputs to CreateOrUpdateConfigSecret
type CreateOrUpdateConfigSecretInput struct {
AppName string
Env map[string]string
Annotations map[string]string
Labels map[string]string
}
// CreateOrUpdateConfigSecret creates or updates the config env secret helm chart for an app
func CreateOrUpdateConfigSecret(ctx context.Context, appName string, env map[string]string) error {
func CreateOrUpdateConfigSecret(ctx context.Context, input CreateOrUpdateConfigSecretInput) error {
appName := input.AppName
if err := isKubernetesAvailable(); err != nil {
common.LogDebug("kubernetes not available, skipping config secret creation")
return nil
@@ -94,15 +105,17 @@ func CreateOrUpdateConfigSecret(ctx context.Context, appName string, env map[str
}
encodedSecrets := map[string]string{}
for key, value := range env {
for key, value := range input.Env {
encodedSecrets[key] = base64.StdEncoding.EncodeToString([]byte(value))
}
values := &ConfigSecretValues{
Global: ConfigSecretGlobalValues{
AppName: appName,
Namespace: namespace,
Secrets: encodedSecrets,
Annotations: input.Annotations,
AppName: appName,
Labels: input.Labels,
Namespace: namespace,
Secrets: encodedSecrets,
},
}

View File

@@ -17,9 +17,11 @@ type ImagePullSecretValues struct {
// ImagePullSecretGlobalValues contains the global values for the image pull secret chart
type ImagePullSecretGlobalValues struct {
AppName string `yaml:"app_name"`
Namespace string `yaml:"namespace"`
PullSecretBase64 string `yaml:"pull_secret_base64"`
Annotations map[string]string `yaml:"annotations,omitempty"`
AppName string `yaml:"app_name"`
Labels map[string]string `yaml:"labels,omitempty"`
Namespace string `yaml:"namespace"`
PullSecretBase64 string `yaml:"pull_secret_base64"`
}
// GetImagePullSecretReleaseName returns the helm release name for the image pull secret
@@ -32,8 +34,17 @@ func GetImagePullSecretName(appName string) string {
return fmt.Sprintf("pull-secret-%s", appName)
}
// CreateOrUpdateImagePullSecretInput contains the inputs to CreateOrUpdateImagePullSecret
type CreateOrUpdateImagePullSecretInput struct {
AppName string
DockerConfigJSON []byte
Annotations map[string]string
Labels map[string]string
}
// CreateOrUpdateImagePullSecret creates or updates the image pull secret helm chart for an app
func CreateOrUpdateImagePullSecret(ctx context.Context, appName string, dockerConfigJSON []byte) error {
func CreateOrUpdateImagePullSecret(ctx context.Context, input CreateOrUpdateImagePullSecretInput) error {
appName := input.AppName
if err := isKubernetesAvailable(); err != nil {
common.LogDebug("kubernetes not available, skipping image pull secret creation")
return nil
@@ -95,9 +106,11 @@ func CreateOrUpdateImagePullSecret(ctx context.Context, appName string, dockerCo
values := &ImagePullSecretValues{
Global: ImagePullSecretGlobalValues{
Annotations: input.Annotations,
AppName: appName,
Labels: input.Labels,
Namespace: namespace,
PullSecretBase64: base64.StdEncoding.EncodeToString(dockerConfigJSON),
PullSecretBase64: base64.StdEncoding.EncodeToString(input.DockerConfigJSON),
},
}

View File

@@ -6,8 +6,14 @@ metadata:
labels:
app.kubernetes.io/name: config-{{ .Values.global.app_name }}
app.kubernetes.io/part-of: {{ .Values.global.app_name }}
{{- range $k, $v := .Values.global.labels }}
{{ $k }}: {{ $v | quote }}
{{- end }}
annotations:
dokku.com/managed: "true"
{{- range $k, $v := .Values.global.annotations }}
{{ $k }}: {{ $v | quote }}
{{- end }}
{{- with .Values.global.secrets }}
data:
{{- toYaml . | nindent 2 }}

View File

@@ -7,7 +7,13 @@ metadata:
labels:
app.kubernetes.io/name: pull-secret-{{ .Values.global.app_name }}
app.kubernetes.io/part-of: {{ .Values.global.app_name }}
{{- range $k, $v := .Values.global.labels }}
{{ $k }}: {{ $v | quote }}
{{- end }}
annotations:
dokku.com/managed: "true"
{{- range $k, $v := .Values.global.annotations }}
{{ $k }}: {{ $v | quote }}
{{- end }}
data:
.dockerconfigjson: {{ .Values.global.pull_secret_base64 | quote }}

View File

@@ -935,12 +935,22 @@ func TriggerSchedulerDeploy(scheduler string, appName string, imageTag string) e
}
}
if err := CreateOrUpdateConfigSecret(ctx, appName, env.Map()); err != nil {
if err := CreateOrUpdateConfigSecret(ctx, CreateOrUpdateConfigSecretInput{
AppName: appName,
Env: env.Map(),
Annotations: globalAnnotations.SecretAnnotations,
Labels: globalLabels.SecretLabels,
}); err != nil {
return fmt.Errorf("Error syncing config secret: %w", err)
}
if dokkuManagedPullSecret {
if err := CreateOrUpdateImagePullSecret(ctx, appName, dokkuPullSecretBytes); err != nil {
if err := CreateOrUpdateImagePullSecret(ctx, CreateOrUpdateImagePullSecretInput{
AppName: appName,
DockerConfigJSON: dokkuPullSecretBytes,
Annotations: globalAnnotations.SecretAnnotations,
Labels: globalLabels.SecretLabels,
}); err != nil {
return fmt.Errorf("Error syncing image pull secret: %w", err)
}
} else {

View File

@@ -44,7 +44,12 @@ teardown() {
echo "status: $status"
assert_success
run deploy_app python "dokku@$DOKKU_DOMAIN:$TEST_APP"
run /bin/bash -c "dokku ps:rebuild $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "sleep 30"
echo "output: $output"
echo "status: $status"
assert_success