Find a file
Myasnikov Daniil 3a87485ca1
fix(installer): bootstrap cozy-system via --create-namespace + label hook
Removes the chart's `Namespace cozy-system` resource and replaces it with
a pre-install/pre-upgrade Job hook (cozy-system-labeler) that patches the
required labels onto the namespace after `--create-namespace` creates it.

Why: helm v3 has a known chicken-and-egg with charts that ship their own
Namespace:
  - WITH `--create-namespace` on the install command, helm pre-creates the
    namespace via plain kubectl-create (no helm meta annotations); the
    chart's own Namespace apply then fails with `already exists`.
  - WITHOUT `--create-namespace`, helm fails immediately because it cannot
    write its release-secret to a non-existent namespace.

Until now this was hidden by the 3x retry on `Install Cozystack` in
`.github/workflows/pull-requests.yaml`: first attempt always fails with
the conflict, second attempt sees the existing failed release and takes
the upgrade code path which patch-merges instead of strict-create.
Reproducible on every cold install. Surfaced cleanly when retries on the
install step were dropped.

After this change:
  - install commands use `helm upgrade --install --namespace cozy-system
    --create-namespace`. Standard pattern, matches kube-prometheus-stack /
    argo-cd / cert-manager / others.
  - the pre-install hook (SA + ClusterRole + ClusterRoleBinding + Job)
    patches `cozystack.io/system=true` and
    `pod-security.kubernetes.io/enforce=privileged` onto the namespace
    before main resources apply.
  - hook-delete-policy=before-hook-creation,hook-succeeded so the RBAC
    surface only exists during install/upgrade.

Verified end-to-end on a kind cluster: cold install in 3.3s, upgrade
idempotent, cleanup clean. Image pinned to `alpine/k8s:1.32.0` for the
hook (small, public, includes kubectl).

Signed-off-by: Myasnikov Daniil <myasnikovdaniil2001@gmail.com>
2026-04-28 11:46:33 +05:00
.gemini docs: adopt Conventional Commits across contributing docs 2026-04-13 22:50:08 +03:00
.github ci(pull-requests): keep 3x retry on Prepare environment 2026-04-27 23:36:23 +05:00
api fix(kubernetes): close admin-kubeconfig race on tenant cluster bootstrap (#2413) 2026-04-27 15:31:52 +03:00
cmd feat(operator): make HelmRelease Interval configurable, override to 30s in E2E 2026-04-27 23:15:29 +05:00
dashboards feat(monitoring): add MongoDB Grafana dashboards 2026-03-05 22:47:53 +03:00
docs chore(ci): adopt CNCF/k8s label conventions (#2495) 2026-04-27 13:16:12 +03:00
examples/backups/vmi feat(backups): restore vmi to copy in another namespace 2026-04-09 14:06:33 +04:00
hack fix(e2e): pre-create cozy-system as helm-adoptable namespace 2026-04-28 11:08:17 +05:00
img Cozystack logo for dark GitHub theme (#9) 2024-02-09 11:02:41 +01:00
internal feat(operator): make HelmRelease Interval configurable, override to 30s in E2E 2026-04-27 23:15:29 +05:00
packages fix(installer): bootstrap cozy-system via --create-namespace + label hook 2026-04-28 11:46:33 +05:00
pkg fix(kubernetes): history guard non-empty check + nits from review 2026-04-16 21:50:10 +03:00
tools/openapi-gen [docs] Added openapi generation tool 2026-03-25 15:57:25 +05:00
.coderabbit.yaml [ci] Enable CodeRabbit incremental reviews 2026-04-13 13:32:15 +03:00
.gitignore feat(application): add WorkloadsReady condition and Events tab 2026-04-15 17:20:45 +03:00
.pre-commit-config.yaml [cozystack-api] Implement TenantNamespace, TenantModules, TenantSecret and TenantSecretsTable resources 2025-09-24 18:27:54 +02:00
ADOPTERS.md Update ADOPTERS.md by adding new adopter 2025-12-18 16:45:06 +03:00
AGENTS.md docs(agents): use full path .github/labels.yml in AGENTS.md 2026-04-27 03:30:43 +03:00
CODE_OF_CONDUCT.md Update CODE_OF_CONDUCT.md 2025-10-08 09:43:34 +05:00
CONTRIBUTING.md [docs] Proofread the readme and contributing 2025-04-09 11:09:19 +03:00
CONTRIBUTOR_LADDER.md Update CONTRIBUTOR_LADDER.md 2025-10-08 09:28:27 +05:00
go.mod feat(controller): add BucketClaim support to WorkloadMonitorReconciler 2026-04-17 10:58:47 +03:00
go.sum feat(controller): add BucketClaim support to WorkloadMonitorReconciler 2026-04-17 10:58:47 +03:00
GOVERNANCE.md Create GOVERNANCE.md (#733) 2025-04-01 18:48:14 +02:00
LICENSE Preapare release v0.0.1 2024-02-08 12:04:32 +01:00
MAINTAINERS.md Add Mattia Eleuteri (@mattia-eleuteri) as Maintainer 2026-04-15 23:46:43 +05:00
Makefile build: wire go-unit-tests into make unit-tests 2026-04-16 21:29:49 +03:00
README.md Update README.md 2026-04-16 14:30:51 +05:00
SECURITY.md docs: add SECURITY.md 2026-03-17 02:57:52 +05:00

Cozystack Cozystack

Open Source Apache-2.0 License Support Active GitHub Release GitHub Commit OpenSSF Best Practices

Cozystack

Cozystack is a free platform and framework for building clouds.

Cozystack is a CNCF Sandbox Level Project that was originally built and sponsored by Ænix.

With Cozystack, you can transform a bunch of servers into an intelligent system with a simple REST API for spawning Kubernetes clusters, Database-as-a-Service, virtual machines, load balancers, HTTP caching services, and other services with ease.

Use Cozystack to build your own cloud or provide a cost-effective development environment.

Cozystack user interface

Use-Cases

Documentation

The documentation is located on the cozystack.io website.

Read the Getting Started section for a quick start.

If you encounter any difficulties, start with the troubleshooting guide and work your way through the process that we've outlined.

Versioning

Versioning adheres to the Semantic Versioning principles.
A full list of the available releases is available in the GitHub repository's Release section.

Contributions

Contributions are highly appreciated and very welcomed!

In case of bugs, please check if the issue has already been opened by checking the GitHub Issues section. If it isn't, you can open a new one. A detailed report will help us replicate it, assess it, and work on a fix.

You can express your intention to on the fix on your own. Commits are used to generate the changelog, and their author will be referenced in it.

If you have Feature Requests please use the Discussion's Feature Request section.

Community

You are welcome to join our Telegram group and come to our weekly community meetings. Add them to your Google Calendar or iCal for convenience.

License

Cozystack is licensed under Apache 2.0.
The code is provided as-is with no warranties.

Commercial Support

A list of companies providing commercial support for this project can be found on official site.