Removes the chart's `Namespace cozy-system` resource and replaces it with
a pre-install/pre-upgrade Job hook (cozy-system-labeler) that patches the
required labels onto the namespace after `--create-namespace` creates it.
Why: helm v3 has a known chicken-and-egg with charts that ship their own
Namespace:
- WITH `--create-namespace` on the install command, helm pre-creates the
namespace via plain kubectl-create (no helm meta annotations); the
chart's own Namespace apply then fails with `already exists`.
- WITHOUT `--create-namespace`, helm fails immediately because it cannot
write its release-secret to a non-existent namespace.
Until now this was hidden by the 3x retry on `Install Cozystack` in
`.github/workflows/pull-requests.yaml`: first attempt always fails with
the conflict, second attempt sees the existing failed release and takes
the upgrade code path which patch-merges instead of strict-create.
Reproducible on every cold install. Surfaced cleanly when retries on the
install step were dropped.
After this change:
- install commands use `helm upgrade --install --namespace cozy-system
--create-namespace`. Standard pattern, matches kube-prometheus-stack /
argo-cd / cert-manager / others.
- the pre-install hook (SA + ClusterRole + ClusterRoleBinding + Job)
patches `cozystack.io/system=true` and
`pod-security.kubernetes.io/enforce=privileged` onto the namespace
before main resources apply.
- hook-delete-policy=before-hook-creation,hook-succeeded so the RBAC
surface only exists during install/upgrade.
Verified end-to-end on a kind cluster: cold install in 3.3s, upgrade
idempotent, cleanup clean. Image pinned to `alpine/k8s:1.32.0` for the
hook (small, public, includes kubectl).
Signed-off-by: Myasnikov Daniil <myasnikovdaniil2001@gmail.com>
|
||
|---|---|---|
| .. | ||
| apps | ||
| core | ||
| extra | ||
| library | ||
| system | ||
| tests/cozy-lib-tests | ||