Skip to content

feat: native CRD support for ExternalSecrets, cert-manager, and Istio resources - #4

Closed
richwalkup wants to merge 3 commits into
mainfrom
feat/native-crd-support
Closed

richwalkup wants to merge 3 commits into
mainfrom
feat/native-crd-support

Conversation

@richwalkup

Copy link
Copy Markdown

Summary

Adds 12 new top-level keys to the common library chart that provide native support for popular CRDs. These replace the need for rawResources with a cleaner flat spec: syntax — no double spec: nesting, and apiVersion/kind/metadata are handled automatically by the chart.

New Top-Level Keys

External Secrets Operator

Key Kind apiVersion
externalSecrets ExternalSecret external-secrets.io/v1

cert-manager

Key Kind apiVersion
certificates Certificate cert-manager.io/v1
certificateIssuers Issuer cert-manager.io/v1
certificateClusterIssuers ClusterIssuer cert-manager.io/v1

Istio

Key Kind apiVersion
istioVirtualServices VirtualService networking.istio.io/v1
istioGateways Gateway networking.istio.io/v1
istioAuthorizationPolicies AuthorizationPolicy security.istio.io/v1
istioDestinationRules DestinationRule networking.istio.io/v1
istioServiceEntries ServiceEntry networking.istio.io/v1
istioPeerAuthentications PeerAuthentication security.istio.io/v1
istioRequestAuthentications RequestAuthentication security.istio.io/v1
istioSidecars Sidecar networking.istio.io/v1

Conversion Example

Before (rawResources):

rawResources:
  secret:
    apiVersion: external-secrets.io/v1
    kind: ExternalSecret
    spec:
      spec:
        refreshInterval: 1h
        secretStoreRef:
          kind: ClusterSecretStore
          name: onepassword
        target:
          name: "{{ .Release.Name }}-secret"

After (native CRD):

externalSecrets:
  secret:
    spec:
      refreshInterval: 1h
      secretStoreRef:
        kind: ClusterSecretStore
        name: onepassword
      target:
        name: "{{ .Release.Name }}-secret"

Breaking Changes

None. This PR is purely additive:

  • Only 2 existing files modified (_generate.tpl and values.yaml) — all other changes are new files
  • All 12 new keys default to {} — existing charts produce zero additional output
  • rawResources is completely untouched and continues to work as before
  • Native CRD keys are opt-in; migration can happen incrementally

When to Keep Using rawResources

  • Resources that use helm.sh/hook annotations (e.g. ArgoCD sync hooks) — native CRD keys do not support hook annotations
  • CRD types not listed above

Implementation

Each CRD type follows the library's standard 4-file pattern:

  • lib/<type>/_enabled_<types>.tpl — filter enabled resources
  • lib/<type>/_getByIdentifier.tpl — lookup by identifier
  • render/_<types>.tpl — loop and render
  • classes/_<type>.tpl — blueprint with apiVersion/kind/metadata/spec

All templates use the shared valuesToObject and determineResourceNameFromValues helpers, so naming, labels, and annotations follow the same conventions as every other chart resource.

Documentation

  • Common Library > Generated Resources > CRD Resources — reference page for all 12 supported CRDs
  • App Template > How To > Native CRD Resources — usage guide with examples for each type and a rawResources migration walkthrough
  • App Template > Examples > Service with ExternalSecret & Istio — full production example combining ExternalSecret, Istio Gateway/VirtualService/AuthorizationPolicy, cert-manager Certificate, and NetworkPolicy

Testing

Validated by rendering converted values for 5 real argocd apps (adm-service-ingestion, hello-world, e2e-cron, apollo-e2e) using helm template with the test-chart. All native CRD outputs produce identical spec content compared to their rawResources equivalents.

richwalkup and others added 2 commits March 17, 2026 17:18
…stio resources

Add 12 new top-level keys to the common library chart that provide
native support for popular CRDs, replacing the need for rawResources
with a cleaner flat spec (no double nesting):

- externalSecrets (external-secrets.io/v1)
- certificates, certificateIssuers, certificateClusterIssuers (cert-manager.io/v1)
- istioVirtualServices, istioGateways, istioDestinationRules,
  istioServiceEntries, istioSidecars (networking.istio.io/v1)
- istioAuthorizationPolicies, istioPeerAuthentications,
  istioRequestAuthentications (security.istio.io/v1)

Each CRD type follows the library's standard pattern with lib, render,
and class templates. All changes are purely additive — existing
rawResources usage is unaffected.

Includes documentation:
- Common library CRD reference page
- App-template how-to guide with migration instructions
- Full production example with ExternalSecret + Istio + cert-manager
- Updated mkdocs navigation

Amp-Thread-ID: https://ampcode.com/threads/T-019cfd93-9b05-7049-9adf-5c80f7c18c95
Co-authored-by: Amp <amp@ampcode.com>
@nickv2002

Copy link
Copy Markdown

I spoke with Rich, and we decided not to implement this at this time.
The gains in terms of number of lines saved are marginal (see example), but it adds a whole bunch of chart complexity.
We may come back to this later when we want more custom CRD support in the charts.

@nickv2002 nickv2002 closed this Mar 17, 2026
Add helm-unittest test suites for externalSecret, certificate,
certificateIssuer, certificateClusterIssuer, and all 8 Istio CRD types.

Each type has 4 test files covering:
- presence (creation, disabling, spec rendering, Helm template support)
- metadata name (default, forceRename, prefix, suffix, multiple items)
- metadata labels (defaults, custom, global merge)
- metadata annotations (defaults, custom, global merge)

48 test suites, 232 tests — all passing.

Amp-Thread-ID: https://ampcode.com/threads/T-019cfd93-9b05-7049-9adf-5c80f7c18c95
Co-authored-by: Amp <amp@ampcode.com>
@richwalkup richwalkup reopened this Mar 17, 2026
@richwalkup
richwalkup marked this pull request as draft March 17, 2026 22:05
@richwalkup richwalkup closed this Mar 17, 2026
@richwalkup
richwalkup deleted the feat/native-crd-support branch March 17, 2026 23:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants