feat: native CRD support for ExternalSecrets, cert-manager, and Istio resources - #4
Closed
richwalkup wants to merge 3 commits into
Closed
richwalkup wants to merge 3 commits into
richwalkup wants to merge 3 commits into
Conversation
…stio resources Add 12 new top-level keys to the common library chart that provide native support for popular CRDs, replacing the need for rawResources with a cleaner flat spec (no double nesting): - externalSecrets (external-secrets.io/v1) - certificates, certificateIssuers, certificateClusterIssuers (cert-manager.io/v1) - istioVirtualServices, istioGateways, istioDestinationRules, istioServiceEntries, istioSidecars (networking.istio.io/v1) - istioAuthorizationPolicies, istioPeerAuthentications, istioRequestAuthentications (security.istio.io/v1) Each CRD type follows the library's standard pattern with lib, render, and class templates. All changes are purely additive — existing rawResources usage is unaffected. Includes documentation: - Common library CRD reference page - App-template how-to guide with migration instructions - Full production example with ExternalSecret + Istio + cert-manager - Updated mkdocs navigation Amp-Thread-ID: https://ampcode.com/threads/T-019cfd93-9b05-7049-9adf-5c80f7c18c95 Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019cfd93-9b05-7049-9adf-5c80f7c18c95 Co-authored-by: Amp <amp@ampcode.com>
|
I spoke with Rich, and we decided not to implement this at this time. |
Add helm-unittest test suites for externalSecret, certificate, certificateIssuer, certificateClusterIssuer, and all 8 Istio CRD types. Each type has 4 test files covering: - presence (creation, disabling, spec rendering, Helm template support) - metadata name (default, forceRename, prefix, suffix, multiple items) - metadata labels (defaults, custom, global merge) - metadata annotations (defaults, custom, global merge) 48 test suites, 232 tests — all passing. Amp-Thread-ID: https://ampcode.com/threads/T-019cfd93-9b05-7049-9adf-5c80f7c18c95 Co-authored-by: Amp <amp@ampcode.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds 12 new top-level keys to the common library chart that provide native support for popular CRDs. These replace the need for
rawResourceswith a cleaner flatspec:syntax — no doublespec:nesting, andapiVersion/kind/metadata are handled automatically by the chart.New Top-Level Keys
External Secrets Operator
externalSecretsexternal-secrets.io/v1cert-manager
certificatescert-manager.io/v1certificateIssuerscert-manager.io/v1certificateClusterIssuerscert-manager.io/v1Istio
istioVirtualServicesnetworking.istio.io/v1istioGatewaysnetworking.istio.io/v1istioAuthorizationPoliciessecurity.istio.io/v1istioDestinationRulesnetworking.istio.io/v1istioServiceEntriesnetworking.istio.io/v1istioPeerAuthenticationssecurity.istio.io/v1istioRequestAuthenticationssecurity.istio.io/v1istioSidecarsnetworking.istio.io/v1Conversion Example
Before (rawResources):
After (native CRD):
Breaking Changes
None. This PR is purely additive:
_generate.tplandvalues.yaml) — all other changes are new files{}— existing charts produce zero additional outputrawResourcesis completely untouched and continues to work as beforeWhen to Keep Using rawResources
helm.sh/hookannotations (e.g. ArgoCD sync hooks) — native CRD keys do not support hook annotationsImplementation
Each CRD type follows the library's standard 4-file pattern:
lib/<type>/_enabled_<types>.tpl— filter enabled resourceslib/<type>/_getByIdentifier.tpl— lookup by identifierrender/_<types>.tpl— loop and renderclasses/_<type>.tpl— blueprint with apiVersion/kind/metadata/specAll templates use the shared
valuesToObjectanddetermineResourceNameFromValueshelpers, so naming, labels, and annotations follow the same conventions as every other chart resource.Documentation
Testing
Validated by rendering converted values for 5 real argocd apps (adm-service-ingestion, hello-world, e2e-cron, apollo-e2e) using
helm templatewith the test-chart. All native CRD outputs produce identicalspeccontent compared to their rawResources equivalents.